log z ComboFix - kontrola
Napsal: 03 úno 2011 14:44
Dobry den, prosim zadam o kontrolu logu z ComboFix.
Projel sem disk Nodem ktery smazal dost trojanu ale nechal tam "c:\windows\system32\userinit.exe" Win32/Injector.EMK
Pote sem pustil ComboFix a ten snad uz tu havet smazal.
Mrknete prosim na log jestli tam neni jeste neco spatneho. Diky
ComboFix 11-01-31.02 - Jirka 03.02.2011 14:22:27.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.530 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jirka\Plocha\!venca\ComboFix.exe
AV: ESET Smart Security 4.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Vytvořen nový Bod Obnovení
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jirka\community.exe
c:\documents and settings\Jirka\dexe.exe
c:\documents and settings\Jirka\know_file.exe
c:\documents and settings\Jirka\secupdat.dat
c:\documents and settings\Jirka\starter.exe
c:\documents and settings\Jirka\stay_wait.exe
c:\program files\ICQ6.5\ICQLRun.exe
c:\windows\ndl.dl
c:\windows\system32\driVERs\mfwet.sys
c:\windows\system32\secupdat.dat
c:\windows\wibrf.jpg
c:\windows\wiybr.png
F:\AUTORUN.INF
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Service_cdfss
-------\Legacy_mfwet
-------\Service_mfwet
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-03 do 2011-02-03 )))))))))))))))))))))))))))))))
.
2012-06-11 15:33 . 2007-01-05 17:34 -------- d-----w- c:\windows\OvtCam
2012-06-11 15:33 . 2005-09-30 08:56 18972 ------w- c:\windows\system32\ov530ext.ax
2012-06-11 15:33 . 2005-09-30 08:42 40960 ------w- c:\windows\system32\ov530ext.dll
2012-06-11 15:33 . 2005-03-15 16:04 161792 ------w- c:\windows\system32\drivers\ov530vid.sys
2012-06-11 15:33 . 2004-11-08 23:37 25177 ------w- c:\windows\system32\drivers\ov530cmd.sys
2012-06-11 15:33 . 2004-08-05 16:34 61440 ------w- c:\windows\ov530dib.dll
2012-06-11 15:33 . 2004-07-20 00:50 16440 ------w- c:\windows\system32\ov530usd.dll
2012-06-11 15:31 . 2004-08-03 21:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2012-06-11 15:31 . 2004-08-03 21:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-06-09 19:12 . 2010-12-12 13:06 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2012-06-09 19:07 . 2012-06-09 19:07 -------- d-----w- c:\program files\THQ
2011-02-03 13:05 . 2011-02-03 13:06 -------- d-----w- c:\program files\Ultimate Process Manager
2011-02-03 11:17 . 2011-02-03 11:17 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2011-02-03 10:42 . 2011-02-03 10:42 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2011-01-27 19:07 . 2004-08-17 13:49 24576 ----a-w- c:\windows\system32\stu2.exe
2011-01-23 14:44 . 2011-01-23 14:44 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-01-23 14:44 . 2011-02-03 10:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Norton
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 11:27 . 2004-08-17 13:49 1033728 ----a-w- c:\windows\explorer.exe
2010-12-05 16:22 . 2009-12-13 20:31 421888 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2007-10-10 282624]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-04-26 111928]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-11 149280]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\Jirka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Xfire.lnk - f:\games\Xfire\Xfire.exe [2005-1-26 1074176]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Aktualizovat ESET licenci.lnk - c:\program files\ESET\MiNODLogin\MiNODLogin.exe [2010-10-18 125952]
Nokia Ovi Suite.lnk - c:\program files\Nokia\Ovi\Suite\RunLauncher.exe [2008-7-25 951600]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ pdboot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\dbeng6.exe"=
"c:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Jirka\\temp\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymedia.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymediaserver.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [12.1.2006 11:56 102528]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21.5.2006 11:11 721904]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
R3 axvdkbus;axvdkbus;c:\windows\system32\drivers\axvdkbus.sys [25.2.2003 19:43 8672]
R3 axvodka;axvodka;c:\windows\system32\drivers\axvodka.sys [27.2.2003 17:50 102272]
R3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;c:\windows\system32\drivers\yukonx86.sys [21.4.2009 17:57 176256]
S0 rykrj;rykrj; [x]
S0 tcwhwlcn;tcwhwlcn;c:\windows\system32\drivers\ltnnvajp.sys --> c:\windows\system32\drivers\ltnnvajp.sys [?]
S1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\Drivers\spyemrg.sys --> c:\windows\system32\Drivers\spyemrg.sys [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3.10.2010 20:23 136176]
S2 PDSched;PDScheduler;c:\program files\Raxco\PerfectDisk\PDSched.exe [29.11.2005 10:16 241731]
S2 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
S3 ATWPKT;ATWPKT;c:\windows\system32\drivers\atwpkt.sys [24.11.2007 17:42 19140]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [3.8.2009 12:34 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [3.8.2009 12:34 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [3.8.2009 12:34 38784]
S3 ceskecfh;ceskecfh;\??\c:\windows\System32\Drivers\ceskecfh.sys --> c:\windows\System32\Drivers\ceskecfh.sys [?]
S3 cjqxxerl;cjqxxerl;\??\c:\windows\System32\Drivers\cjqxxerl.sys --> c:\windows\System32\Drivers\cjqxxerl.sys [?]
S3 idrmkl;idrmkl;\??\c:\docume~1\Jirka\LOCALS~1\Temp\idrmkl.sys --> c:\docume~1\Jirka\LOCALS~1\Temp\idrmkl.sys [?]
S3 lgkdlfil;lgkdlfil;\??\c:\windows\System32\Drivers\lgkdlfil.sys --> c:\windows\System32\Drivers\lgkdlfil.sys [?]
S3 mwutcjja;mwutcjja;\??\c:\windows\System32\Drivers\mwutcjja.sys --> c:\windows\System32\Drivers\mwutcjja.sys [?]
S3 nnhfsbjo;nnhfsbjo;\??\c:\windows\System32\Drivers\nnhfsbjo.sys --> c:\windows\System32\Drivers\nnhfsbjo.sys [?]
S3 ophrjwtw;ophrjwtw;\??\c:\windows\System32\Drivers\ophrjwtw.sys --> c:\windows\System32\Drivers\ophrjwtw.sys [?]
S3 ovt530;Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [11.6.2012 16:33 161792]
S3 uutnnfqh;uutnnfqh;\??\c:\windows\System32\Drivers\uutnnfqh.sys --> c:\windows\System32\Drivers\uutnnfqh.sys [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [21.5.2006 11:12 223128]
.
Obsah adresáře 'Naplánované úlohy'
2011-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 19:23]
2011-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 19:23]
2011-02-03 c:\windows\Tasks\User_Feed_Synchronization-{B3AF53D2-76D4-4C5E-A210-2800E1467E69}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Jirka\Data aplikací\Mozilla\Firefox\Profiles\wp4bids6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/skinit/icq/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Noia 2.0 (eXtreme): {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} - %profile%\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-userini - c:\windows\system32\userini.exe
HKLM-Run-adobe_pdf - c:\documents and settings\jirka\dexe.exe
HKLM-Run-userini - c:\windows\system32\userini.exe
HKLM-Explorer_Run-userini - c:\windows\system32\userini.exe
AddRemove-RoadRash - c:\electronicarts\RoadRash\DeIsL2.isu
AddRemove-CrazyFrog2 - e:\jiricek\Nová složka (2)\CrazyFrog2\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-03 14:28
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-515967899-573735546-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-515967899-573735546-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:8c,94,59,f6,0e,95,34,01,d1,50,27,b6,e6,11,5c,ad,90,59,9a,b9,a8,
1b,d0,b0,fe,22,1f,ad,52,49,43,f3,c5,0b,00,e3,3e,1a,db,58,e2,81,be,82,18,af,\
"rkeysecu"=hex:ee,a4,03,d2,52,f7,ca,7b,9e,85,0f,23,80,91,15,d1
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1280)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3924)
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
f:\games\Xfire\xfire_conure_11237.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\bgsvcgen.exe
c:\opel inst\BHROOT\BIN\NT611SVC.EXE
c:\opel inst\BHROOT\BIN\monitor.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\opel inst\BHROOT\BIN\PORTMAP.EXE
c:\bhroot\BIN\DBMANG.EXE
c:\windows\Mixer.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Celkový čas: 2011-02-03 14:36:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-03 13:36
Před spuštěním: Volných bajtů: 11 375 607 808
Po spuštění: Volných bajtů: 11 356 180 480
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - BA2CA1AC09A44D48FB3E20545E119E17
Projel sem disk Nodem ktery smazal dost trojanu ale nechal tam "c:\windows\system32\userinit.exe" Win32/Injector.EMK
Pote sem pustil ComboFix a ten snad uz tu havet smazal.
Mrknete prosim na log jestli tam neni jeste neco spatneho. Diky
ComboFix 11-01-31.02 - Jirka 03.02.2011 14:22:27.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.530 [GMT 1:00]
Spuštěný z: c:\documents and settings\Jirka\Plocha\!venca\ComboFix.exe
AV: ESET Smart Security 4.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Vytvořen nový Bod Obnovení
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jirka\community.exe
c:\documents and settings\Jirka\dexe.exe
c:\documents and settings\Jirka\know_file.exe
c:\documents and settings\Jirka\secupdat.dat
c:\documents and settings\Jirka\starter.exe
c:\documents and settings\Jirka\stay_wait.exe
c:\program files\ICQ6.5\ICQLRun.exe
c:\windows\ndl.dl
c:\windows\system32\driVERs\mfwet.sys
c:\windows\system32\secupdat.dat
c:\windows\wibrf.jpg
c:\windows\wiybr.png
F:\AUTORUN.INF
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Service_cdfss
-------\Legacy_mfwet
-------\Service_mfwet
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-03 do 2011-02-03 )))))))))))))))))))))))))))))))
.
2012-06-11 15:33 . 2007-01-05 17:34 -------- d-----w- c:\windows\OvtCam
2012-06-11 15:33 . 2005-09-30 08:56 18972 ------w- c:\windows\system32\ov530ext.ax
2012-06-11 15:33 . 2005-09-30 08:42 40960 ------w- c:\windows\system32\ov530ext.dll
2012-06-11 15:33 . 2005-03-15 16:04 161792 ------w- c:\windows\system32\drivers\ov530vid.sys
2012-06-11 15:33 . 2004-11-08 23:37 25177 ------w- c:\windows\system32\drivers\ov530cmd.sys
2012-06-11 15:33 . 2004-08-05 16:34 61440 ------w- c:\windows\ov530dib.dll
2012-06-11 15:33 . 2004-07-20 00:50 16440 ------w- c:\windows\system32\ov530usd.dll
2012-06-11 15:31 . 2004-08-03 21:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2012-06-11 15:31 . 2004-08-03 21:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-06-09 19:12 . 2010-12-12 13:06 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2012-06-09 19:07 . 2012-06-09 19:07 -------- d-----w- c:\program files\THQ
2011-02-03 13:05 . 2011-02-03 13:06 -------- d-----w- c:\program files\Ultimate Process Manager
2011-02-03 11:17 . 2011-02-03 11:17 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2011-02-03 10:42 . 2011-02-03 10:42 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2011-01-27 19:07 . 2004-08-17 13:49 24576 ----a-w- c:\windows\system32\stu2.exe
2011-01-23 14:44 . 2011-01-23 14:44 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-01-23 14:44 . 2011-02-03 10:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Norton
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 11:27 . 2004-08-17 13:49 1033728 ----a-w- c:\windows\explorer.exe
2010-12-05 16:22 . 2009-12-13 20:31 421888 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 57344]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2007-10-10 282624]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-04-26 111928]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-11 149280]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\Jirka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Xfire.lnk - f:\games\Xfire\Xfire.exe [2005-1-26 1074176]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Aktualizovat ESET licenci.lnk - c:\program files\ESET\MiNODLogin\MiNODLogin.exe [2010-10-18 125952]
Nokia Ovi Suite.lnk - c:\program files\Nokia\Ovi\Suite\RunLauncher.exe [2008-7-25 951600]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ pdboot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\dbeng6.exe"=
"c:\\Program Files\\Ubisoft\\Crytek\\Far Cry\\Bin32\\FarCry.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Jirka\\temp\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymedia.exe"=
"c:\\Program Files\\Nokia\\Nokia Home Media Server\\Media Server\\twonkymediaserver.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [12.1.2006 11:56 102528]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21.5.2006 11:11 721904]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14.5.2009 15:47 731840]
R3 axvdkbus;axvdkbus;c:\windows\system32\drivers\axvdkbus.sys [25.2.2003 19:43 8672]
R3 axvodka;axvodka;c:\windows\system32\drivers\axvodka.sys [27.2.2003 17:50 102272]
R3 yukonx86;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter;c:\windows\system32\drivers\yukonx86.sys [21.4.2009 17:57 176256]
S0 rykrj;rykrj; [x]
S0 tcwhwlcn;tcwhwlcn;c:\windows\system32\drivers\ltnnvajp.sys --> c:\windows\system32\drivers\ltnnvajp.sys [?]
S1 SpyEmrg;Spy Emergency Driver;c:\windows\system32\Drivers\spyemrg.sys --> c:\windows\system32\Drivers\spyemrg.sys [?]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3.10.2010 20:23 136176]
S2 PDSched;PDScheduler;c:\program files\Raxco\PerfectDisk\PDSched.exe [29.11.2005 10:16 241731]
S2 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
S3 ATWPKT;ATWPKT;c:\windows\system32\drivers\atwpkt.sys [24.11.2007 17:42 19140]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [3.8.2009 12:34 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [3.8.2009 12:34 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [3.8.2009 12:34 38784]
S3 ceskecfh;ceskecfh;\??\c:\windows\System32\Drivers\ceskecfh.sys --> c:\windows\System32\Drivers\ceskecfh.sys [?]
S3 cjqxxerl;cjqxxerl;\??\c:\windows\System32\Drivers\cjqxxerl.sys --> c:\windows\System32\Drivers\cjqxxerl.sys [?]
S3 idrmkl;idrmkl;\??\c:\docume~1\Jirka\LOCALS~1\Temp\idrmkl.sys --> c:\docume~1\Jirka\LOCALS~1\Temp\idrmkl.sys [?]
S3 lgkdlfil;lgkdlfil;\??\c:\windows\System32\Drivers\lgkdlfil.sys --> c:\windows\System32\Drivers\lgkdlfil.sys [?]
S3 mwutcjja;mwutcjja;\??\c:\windows\System32\Drivers\mwutcjja.sys --> c:\windows\System32\Drivers\mwutcjja.sys [?]
S3 nnhfsbjo;nnhfsbjo;\??\c:\windows\System32\Drivers\nnhfsbjo.sys --> c:\windows\System32\Drivers\nnhfsbjo.sys [?]
S3 ophrjwtw;ophrjwtw;\??\c:\windows\System32\Drivers\ophrjwtw.sys --> c:\windows\System32\Drivers\ophrjwtw.sys [?]
S3 ovt530;Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [11.6.2012 16:33 161792]
S3 uutnnfqh;uutnnfqh;\??\c:\windows\System32\Drivers\uutnnfqh.sys --> c:\windows\System32\Drivers\uutnnfqh.sys [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [21.5.2006 11:12 223128]
.
Obsah adresáře 'Naplánované úlohy'
2011-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 19:23]
2011-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-03 19:23]
2011-02-03 c:\windows\Tasks\User_Feed_Synchronization-{B3AF53D2-76D4-4C5E-A210-2800E1467E69}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Jirka\Data aplikací\Mozilla\Firefox\Profiles\wp4bids6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/skinit/icq/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Noia 2.0 (eXtreme): {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} - %profile%\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
Toolbar-Locked - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-userini - c:\windows\system32\userini.exe
HKLM-Run-adobe_pdf - c:\documents and settings\jirka\dexe.exe
HKLM-Run-userini - c:\windows\system32\userini.exe
HKLM-Explorer_Run-userini - c:\windows\system32\userini.exe
AddRemove-RoadRash - c:\electronicarts\RoadRash\DeIsL2.isu
AddRemove-CrazyFrog2 - e:\jiricek\Nová složka (2)\CrazyFrog2\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-03 14:28
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-515967899-573735546-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-515967899-573735546-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:8c,94,59,f6,0e,95,34,01,d1,50,27,b6,e6,11,5c,ad,90,59,9a,b9,a8,
1b,d0,b0,fe,22,1f,ad,52,49,43,f3,c5,0b,00,e3,3e,1a,db,58,e2,81,be,82,18,af,\
"rkeysecu"=hex:ee,a4,03,d2,52,f7,ca,7b,9e,85,0f,23,80,91,15,d1
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1280)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3924)
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
f:\games\Xfire\xfire_conure_11237.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
c:\windows\system32\bgsvcgen.exe
c:\opel inst\BHROOT\BIN\NT611SVC.EXE
c:\opel inst\BHROOT\BIN\monitor.exe
c:\windows\system32\crypserv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\opel inst\BHROOT\BIN\PORTMAP.EXE
c:\bhroot\BIN\DBMANG.EXE
c:\windows\Mixer.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Celkový čas: 2011-02-03 14:36:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-03 13:36
Před spuštěním: Volných bajtů: 11 375 607 808
Po spuštění: Volných bajtů: 11 356 180 480
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - BA2CA1AC09A44D48FB3E20545E119E17