do navodu dopiste aj vypnutie Avastu (aj po restarte) pre ComboFix
a na stranke
http://www.bleepingcomputer.com/pf.php pisu, aby som dal vediet, ze subor som odoslal na kontrolu. Subor, co vytvoril ComboFix.
ComboFix 11-03-05.02 - Mato . 03. 2011 20:34:44.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.1790.1370 [GMT 1:00]
Running from: c:\documents and settings\Mato\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mato\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
file zipped: C:\~GLHTTP1.TMP
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\~GLHTTP1.TMP
.
.
((((((((((((((((((((((((( Files Created from 2011-02-06 to 2011-03-06 )))))))))))))))))))))))))))))))
.
.
2011-03-05 20:30 . 2011-03-05 20:31 -------- d-----w- C:\rsit
2011-02-26 19:25 . 2011-02-26 19:25 -------- d-----w- C:\ATI
2011-02-25 22:52 . 2011-02-25 22:52 -------- d-----r- C:\AHCache
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-26 23:05 . 2008-11-09 18:24 17252352 ----a-w- c:\windows\system32\atioglxx.dll
2011-01-26 22:52 . 2008-11-09 18:24 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-01-26 22:41 . 2008-11-09 18:24 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2011-01-26 22:32 . 2008-11-09 18:24 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2011-01-26 22:31 . 2008-11-09 18:24 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2011-01-26 22:31 . 2008-11-09 18:24 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2011-01-26 22:31 . 2008-11-09 18:24 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-01-26 22:31 . 2008-11-09 18:24 188416 ----a-w- c:\windows\system32\ati2evxx.dll
2011-01-26 22:30 . 2008-11-09 18:24 638976 ----a-w- c:\windows\system32\ati2evxx.exe
2011-01-26 22:28 . 2008-11-09 18:24 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2011-01-26 22:23 . 2008-11-09 18:24 651264 ----a-w- c:\windows\system32\atikvmag.dll
2011-01-26 22:21 . 2008-11-09 18:24 196608 ----a-w- c:\windows\system32\atiadlxx.dll
2011-01-26 22:21 . 2008-11-09 18:24 483328 ----a-w- c:\windows\system32\atiok3x2.dll
2011-01-26 22:21 . 2008-11-09 18:24 17408 ----a-w- c:\windows\system32\atitvo32.dll
2011-01-26 22:12 . 2008-11-09 18:24 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2011-01-26 22:12 . 2008-11-09 18:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-01-21 14:44 . 2004-08-04 01:07 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-04 01:07 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-08-04 01:07 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-04 01:07 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 22:15 . 2004-08-04 01:07 667136 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 22:15 . 2004-08-04 01:07 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-12-20 22:15 . 2004-08-04 01:07 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 17:26 . 2004-08-04 01:07 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 15:30 . 2004-08-04 01:07 369664 ----a-w- c:\windows\system32\html.iec
2010-12-09 17:27 . 2010-12-09 17:27 99688 ----a-w- c:\windows\system32\BtMmHook.dll
2010-12-09 17:27 . 2010-12-09 17:27 2860384 ----a-w- c:\windows\system32\btwicons.dll
2010-12-09 17:27 . 2010-12-09 17:27 972144 ----a-w- c:\windows\system32\BTNeighborhood.dll
2010-12-09 17:27 . 2010-12-09 17:27 439648 ----a-w- c:\windows\system32\btcss.dll
2010-12-09 17:27 . 2010-12-09 17:27 242976 ----a-w- c:\windows\system32\btwhidcs.dll
2010-12-09 17:27 . 2010-12-09 17:27 218464 ----a-w- c:\windows\system32\btsec.dll
2010-12-09 17:27 . 2010-12-09 17:27 181616 ----a-w- c:\windows\system32\BtWiaExt.dll
2010-12-09 17:27 . 2010-12-09 17:27 1799528 ----a-w- c:\windows\system32\BtWizard.dll
2010-12-09 17:27 . 2010-12-09 17:27 177496 ----a-w- c:\windows\system32\btsendto_ie.dll
2010-12-09 17:27 . 2010-12-09 17:27 83232 ----a-w- c:\windows\system32\btprn2k.dll
2010-12-09 17:27 . 2010-12-09 17:27 361808 ----a-w- c:\windows\system32\btosif_ol.dll
2010-12-09 17:27 . 2010-12-09 17:27 333144 ----a-w- c:\windows\system32\btosif_notes.dll
2010-12-09 17:27 . 2010-12-09 17:27 288088 ----a-w- c:\windows\system32\btsendto_office.dll
2010-12-09 17:27 . 2010-12-09 17:27 169304 ----a-w- c:\windows\system32\btsendto_wab.dll
2010-12-09 17:27 . 2010-12-09 17:27 165152 ----a-w- c:\windows\system32\btosif_olx.dll
2010-12-09 17:27 . 2010-12-09 17:27 157016 ----a-w- c:\windows\system32\btsendto_notes.dll
2010-12-09 17:27 . 2010-12-09 17:27 128288 ----a-w- c:\windows\system32\bthcrpui.dll
2010-12-09 17:27 . 2010-12-09 17:27 91504 ----a-w- c:\windows\system32\BtAudioHelper.dll
2010-12-09 17:27 . 2010-12-09 17:27 804176 ----a-w- c:\windows\system32\BTChooser.dll
2010-12-09 17:27 . 2010-12-09 17:27 58720 ----a-w- c:\windows\system32\btdev.dll
2010-12-09 17:27 . 2010-12-09 17:27 341328 ----a-w- c:\windows\system32\btsendto.dll
2010-12-09 17:27 . 2010-12-09 17:27 29984 ----a-w- c:\windows\system32\BtXpShell.dll
2010-12-09 17:27 . 2010-12-09 17:27 243024 ----a-w- c:\windows\system32\btosif.dll
2010-12-09 17:27 . 2010-12-09 17:27 173392 ----a-w- c:\windows\system32\btwpimif.dll
2010-12-09 17:27 . 2010-12-09 17:27 128360 ----a-w- c:\windows\system32\bt2k_ins.dll
2010-12-09 17:27 . 2010-12-09 17:27 128288 ----a-w- c:\windows\system32\btbigbmp.dll
2010-12-09 17:27 . 2010-12-09 17:27 111904 ----a-w- c:\windows\system32\BTXPPanel.dll
2010-12-09 17:27 . 2010-12-09 17:27 111904 ----a-w- c:\windows\system32\bthcrp.dll
2010-12-09 17:27 . 2010-12-09 17:27 99616 ----a-w- c:\windows\system32\btrezxp.dll
2010-12-09 17:27 . 2010-12-09 17:27 628000 ----a-w- c:\windows\system32\WidcommSdk.dll
2010-12-09 17:27 . 2010-12-09 17:27 570720 ----a-w- c:\windows\system32\btins.dll
2010-12-09 17:27 . 2010-12-09 17:27 54560 ----a-w- c:\windows\system32\BTNCopy.dll
2010-12-09 17:27 . 2010-12-09 17:27 529760 ----a-w- c:\windows\system32\wbtapi.dll
2010-12-09 17:27 . 2010-12-09 17:27 296272 ----a-w- c:\windows\system32\btbip.dll
2010-12-09 17:27 . 2010-12-09 17:27 1127760 ----a-w- c:\windows\system32\btrez.dll
2010-12-09 17:27 . 2010-12-09 17:27 30040 ----a-w- c:\windows\BtwIEProxy.exe
2010-12-09 17:20 . 2010-12-09 17:20 401467 ----a-w- c:\windows\system32\btcpl.cpl
2010-12-09 15:15 . 2004-08-04 01:07 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-08-04 01:07 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2004-08-04 01:07 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-03 22:59 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-07 11:14 . 2010-12-07 11:14 51200 ----a-w- c:\windows\system32\OpenCL.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-06_12.20.19 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 01:07 . 2011-03-06 12:11 76460 c:\windows\system32\perfc009.dat
+ 2004-08-04 01:07 . 2011-03-06 19:37 76460 c:\windows\system32\perfc009.dat
+ 2004-08-04 01:07 . 2011-03-06 19:37 457854 c:\windows\system32\perfh009.dat
- 2004-08-04 01:07 . 2011-03-06 12:11 457854 c:\windows\system32\perfh009.dat
+ 2011-03-06 14:41 . 2011-02-04 16:34 37443528 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TMCC"="c:\program files\T-Mobile Communication Center\TMCC.exe" [2010-06-21 770048]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"SmartRAM"="d:\ine\net\iobit_toolbox (1)\Tools\Suo10_SmartRAM.exe" [2010-09-26 817496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-12 19521056]
"NetWorx"="c:\program files\NetWorx\networx.exe" [2011-02-11 2771968]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-09-02 1043968]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-12-9 636256]
Toddler Keys.lnk - c:\windows\Installer\{7339E7E7-FB6A-46EC-8303-D31E655EF617}\_154754de.exe [2011-2-19 766]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [27. 2. 2011 12:57 14776]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [25. 2. 2011 11:30 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19. 2. 2011 14:49 301528]
R1 networx;networx;c:\windows\system32\drivers\networx.sys [19. 2. 2011 14:39 51640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [6. 3. 2011 0:10 142592]
R2 AODService;AODService;c:\program files\AMD\OverDrive\AODAssist.exe [1. 7. 2010 4:45 136616]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19. 2. 2011 14:49 19544]
R2 FMMService;Mobility Manager Service;c:\progra~1\T-MOBI~1\drivers\113F4D~1\FMMSER~1.EXE [19. 2. 2011 14:33 40960]
R2 FOFDM DHCP Timing;FOFDM DHCP Timing;c:\progra~1\T-MOBI~1\FOFDMD~1.EXE [19. 2. 2011 14:33 81920]
R2 FOFDMUpgrade;FOFDM Upgrade;c:\progra~1\T-MOBI~1\FOFDMU~1.EXE [19. 2. 2011 14:33 188416]
R2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [26. 2. 2011 0:05 821592]
R3 AODDriver2;AODDriver2;c:\program files\AMD\OverDrive\i386\AODDriver2.sys [1. 7. 2010 4:38 36864]
R3 FlrnUSB;Leadtek USB Network Interface;c:\windows\system32\drivers\LtkUSB.sys [19. 2. 2011 14:33 42984]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [19. 2. 2011 16:07 27632]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 13:16 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [19. 2. 2011 14:22 1691480]
S3 ATICDSDr;ATICDSDr;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\ATICDSDr.sys --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\ATICDSDr.sys [?]
S3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [26. 2. 2011 0:05 239344]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [19. 2. 2011 16:07 13224]
S3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\RegFilter.sys [26. 2. 2011 0:05 41200]
S3 Sony Ericsson PCCompanion;Sony Ericsson PCCompanion;c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [22. 2. 2011 0:26 155344]
S3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\Drivers\wxp_x86\UrlFilter.sys [26. 2. 2011 0:05 24200]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4. 8. 2004 2:07 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 13:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-682003330-1801674531-1003Core.job
- c:\documents and settings\Mato\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-02-19 18:23]
.
2011-03-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-682003330-1801674531-1003UA.job
- c:\documents and settings\Mato\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-02-19 18:23]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: Crawler Search - tbr:iemenu
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
FF - ProfilePath - c:\documents and settings\Mato\Application Data\Mozilla\Firefox\Profiles\zkzwa64f.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-06 20:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2011-03-06 20:44:11
ComboFix-quarantined-files.txt 2011-03-06 19:44
ComboFix2.txt 2011-03-06 13:40
.
Pre-Run: 22 487 101 440 bytes free
Post-Run: 22 468 956 160 bytes free
.
- - End Of File - - A1F70D7E3C17B08BDF25E45808A02F3F