ComboFix 11-03-14.05 - petr.vondrak 15.03.2011 9:13.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1029.18.247.122 [GMT 1:00]
Running from: c:\documents and settings\petr.vondrak\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Panda Titanium 2006 Antivirus + Antispyware *Disabled/Updated* {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}
FW: Panda Titanium 2006 Personal Firewall *Enabled* {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\_004623_.tmp.dll
c:\windows\system32\_004624_.tmp.dll
c:\windows\system32\_004625_.tmp.dll
c:\windows\system32\_004626_.tmp.dll
c:\windows\system32\_004633_.tmp.dll
c:\windows\system32\_004634_.tmp.dll
c:\windows\system32\_004635_.tmp.dll
c:\windows\system32\_004636_.tmp.dll
c:\windows\system32\_004638_.tmp.dll
c:\windows\system32\_004639_.tmp.dll
c:\windows\system32\_004640_.tmp.dll
c:\windows\system32\_004641_.tmp.dll
c:\windows\system32\_004642_.tmp.dll
c:\windows\system32\_004643_.tmp.dll
c:\windows\system32\_004644_.tmp.dll
c:\windows\system32\_004645_.tmp.dll
c:\windows\system32\_004646_.tmp.dll
c:\windows\system32\_004647_.tmp.dll
c:\windows\system32\_004648_.tmp.dll
c:\windows\system32\_004649_.tmp.dll
c:\windows\system32\_004650_.tmp.dll
c:\windows\system32\_004651_.tmp.dll
c:\windows\system32\_004652_.tmp.dll
c:\windows\system32\_004653_.tmp.dll
c:\windows\system32\_004654_.tmp.dll
c:\windows\system32\_004655_.tmp.dll
c:\windows\system32\_004656_.tmp.dll
c:\windows\system32\_004657_.tmp.dll
c:\windows\system32\_004658_.tmp.dll
c:\windows\system32\_004659_.tmp.dll
c:\windows\system32\_004660_.tmp.dll
c:\windows\system32\_004661_.tmp.dll
c:\windows\system32\_004662_.tmp.dll
c:\windows\system32\_004663_.tmp.dll
c:\windows\system32\_004664_.tmp.dll
c:\windows\system32\_004665_.tmp.dll
c:\windows\system32\_004666_.tmp.dll
c:\windows\system32\_004667_.tmp.dll
c:\windows\system32\_004668_.tmp.dll
c:\windows\system32\_004669_.tmp.dll
c:\windows\system32\_004670_.tmp.dll
c:\windows\system32\_004671_.tmp.dll
c:\windows\system32\_004672_.tmp.dll
c:\windows\system32\_004673_.tmp.dll
c:\windows\system32\_004674_.tmp.dll
c:\windows\system32\_004675_.tmp.dll
c:\windows\system32\_004676_.tmp.dll
c:\windows\system32\_004677_.tmp.dll
c:\windows\system32\_004678_.tmp.dll
c:\windows\system32\_004679_.tmp.dll
c:\windows\system32\_004681_.tmp.dll
c:\windows\system32\_004682_.tmp.dll
c:\windows\system32\_004683_.tmp.dll
c:\windows\system32\_004684_.tmp.dll
c:\windows\system32\_004686_.tmp.dll
c:\windows\system32\_004687_.tmp.dll
c:\windows\system32\_004688_.tmp.dll
c:\windows\system32\_004689_.tmp.dll
c:\windows\system32\_004690_.tmp.dll
c:\windows\system32\_004691_.tmp.dll
c:\windows\system32\_004692_.tmp.dll
c:\windows\system32\_004693_.tmp.dll
c:\windows\system32\_004694_.tmp.dll
c:\windows\system32\_004696_.tmp.dll
c:\windows\system32\_004697_.tmp.dll
c:\windows\system32\_004698_.tmp.dll
c:\windows\system32\_004699_.tmp.dll
c:\windows\system32\_004701_.tmp.dll
c:\windows\system32\_004703_.tmp.dll
c:\windows\system32\_004704_.tmp.dll
c:\windows\system32\_004705_.tmp.dll
c:\windows\system32\_004706_.tmp.dll
c:\windows\system32\_004707_.tmp.dll
c:\windows\system32\_004708_.tmp.dll
c:\windows\system32\_004709_.tmp.dll
c:\windows\system32\_004710_.tmp.dll
c:\windows\system32\_004712_.tmp.dll
c:\windows\system32\_004713_.tmp.dll
c:\windows\system32\_004714_.tmp.dll
c:\windows\system32\_004715_.tmp.dll
c:\windows\system32\_004716_.tmp.dll
c:\windows\system32\_004717_.tmp.dll
c:\windows\system32\_004718_.tmp.dll
c:\windows\system32\_004719_.tmp.dll
c:\windows\system32\_004720_.tmp.dll
c:\windows\system32\_004721_.tmp.dll
c:\windows\system32\_004722_.tmp.dll
c:\windows\system32\_004723_.tmp.dll
c:\windows\system32\_004724_.tmp.dll
c:\windows\system32\_004725_.tmp.dll
c:\windows\system32\_004726_.tmp.dll
c:\windows\system32\_004727_.tmp.dll
c:\windows\system32\_004729_.tmp.dll
c:\windows\system32\_004730_.tmp.dll
c:\windows\system32\_004731_.tmp.dll
c:\windows\system32\_004732_.tmp.dll
c:\windows\system32\_004734_.tmp.dll
c:\windows\system32\_004736_.tmp.dll
c:\windows\system32\_004737_.tmp.dll
c:\windows\system32\_004738_.tmp.dll
c:\windows\system32\_004739_.tmp.dll
c:\windows\system32\_004740_.tmp.dll
c:\windows\system32\_004741_.tmp.dll
c:\windows\system32\_004742_.tmp.dll
c:\windows\system32\_004743_.tmp.dll
c:\windows\system32\_004745_.tmp.dll
c:\windows\system32\_004746_.tmp.dll
c:\windows\system32\_004747_.tmp.dll
c:\windows\system32\_004748_.tmp.dll
c:\windows\system32\_004749_.tmp.dll
c:\windows\system32\_004750_.tmp.dll
c:\windows\system32\_004751_.tmp.dll
c:\windows\system32\_004752_.tmp.dll
c:\windows\system32\_004754_.tmp.dll
c:\windows\system32\_004755_.tmp.dll
c:\windows\system32\_004756_.tmp.dll
c:\windows\system32\_004759_.tmp.dll
c:\windows\system32\_004760_.tmp.dll
c:\windows\system32\_004764_.tmp.dll
c:\windows\system32\_004765_.tmp.dll
c:\windows\system32\_004767_.tmp.dll
c:\windows\system32\_004769_.tmp.dll
c:\windows\system32\_004770_.tmp.dll
c:\windows\system32\_004772_.tmp.dll
c:\windows\system32\_004773_.tmp.dll
c:\windows\system32\_004774_.tmp.dll
c:\windows\system32\_004775_.tmp.dll
c:\windows\system32\_004778_.tmp.dll
c:\windows\system32\_004779_.tmp.dll
c:\windows\system32\_004780_.tmp.dll
c:\windows\system32\_004781_.tmp.dll
c:\windows\system32\_004782_.tmp.dll
c:\windows\system32\_004787_.tmp.dll
c:\windows\system32\_004789_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-02-15 to 2011-03-15 )))))))))))))))))))))))))))))))
.
.
2011-03-15 06:53 . 2011-03-15 06:53 -------- d-----w- c:\documents and settings\petr.vondrak\Data aplikací\Malwarebytes
2011-03-15 06:53 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-15 06:53 . 2011-03-15 06:53 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-03-15 06:52 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-15 06:52 . 2011-03-15 06:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-15 06:34 . 2011-03-15 08:00 -------- d-----w- c:\program files\Trojan Remover
2011-03-14 19:05 . 2011-03-14 19:05 -------- d-----w- c:\program files\trend micro
2011-03-14 19:05 . 2011-03-14 19:05 -------- d-----w- C:\rsit
2011-03-14 18:10 . 2011-03-14 18:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PC Tools
2011-03-11 17:26 . 2011-02-23 14:54 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-03-11 17:26 . 2011-02-23 14:56 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-03-11 17:26 . 2011-02-23 14:55 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-03-11 17:26 . 2011-02-23 14:55 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-03-11 17:25 . 2011-02-23 14:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-03-11 17:25 . 2011-02-23 14:55 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-03-11 17:25 . 2011-02-23 14:55 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-03-11 17:25 . 2011-02-23 14:54 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-03-11 17:24 . 2011-02-23 15:04 40648 ----a-w- c:\windows\avastSS.scr
2011-03-11 17:24 . 2011-02-23 15:04 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-03-11 17:24 . 2011-03-11 17:24 -------- d-----w- c:\program files\AVAST Software
2011-03-11 17:24 . 2011-03-11 17:24 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-03-09 20:35 . 2011-03-09 20:35 319488 --sha-w- c:\documents and settings\petr.vondrak\Local Settings\Data aplikací\spf.exe
2011-03-04 13:52 . 2011-03-04 13:52 -------- d-----w- C:\Multi Protocol Programming System
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-21 14:44 . 2004-08-18 12:00 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-18 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 14:04 . 2009-05-22 07:14 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-18 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:52 . 2004-08-18 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2004-08-18 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2004-08-18 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2009-05-22 07:14 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-18 12:00 385024 ----a-w- c:\windows\system32\html.iec
2007-11-19 20:40 . 2007-11-19 20:40 2082304 ----a-w- c:\program files\winpos.exe
2007-01-10 08:28 . 2007-01-10 08:28 541184 ----a-w- c:\program files\CALC.exe
2005-02-21 10:18 . 2005-02-21 10:18 1057792 ----a-w- c:\program files\UNINST.exe
1999-06-23 08:06 . 1999-06-23 08:06 126976 ----a-w- c:\program files\dzip32.dll
1999-06-23 08:06 . 1999-06-23 08:06 110592 ----a-w- c:\program files\DUNZIP32.DLL
2007-05-15 19:47 . 2007-08-14 13:30 66672 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-05-15 19:47 . 2007-08-14 13:30 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-05-15 19:47 . 2007-08-14 13:30 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-05-15 19:47 . 2007-08-14 13:30 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-05-15 19:47 . 2007-08-14 13:30 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC7D27FB-CA10-4CE3-B312-8A164671FD03}]
2007-11-24 14:52 82432 ----a-w- c:\program files\NetCentrum\Turbo\bho.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-05-14 1479680]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-21 39408]
"Spyware Doctor with AntiVirus"="c:\documents and settings\petr.vondrak\Plocha\sdasetup_aff.exe" [2011-03-14 513032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143872]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-18 44544]
.
c:\documents and settings\petr.vondrak\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ACSnews.lnk - c:\auto-diagnostika b\ADnews.exe [2010-12-26 733184]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-6-9 24576]
Wireless Utility.lnk - c:\program files\EDIMAX\Common\RaUI.exe [2010-6-12 1601536]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sremcon.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Service Manager.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgrWired]
2004-12-09 12:58 86016 ----a-w- c:\program files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2010-10-21 06:39 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-11-16 16:11 536576 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-11-16 16:11 98304 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\PandaFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11.3.2011 18:25 371544]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.3.2011 18:26 301528]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.3.2011 18:26 19544]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\axtmvflt.sys [14.10.2009 13:09 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\axtmvmdm.sys [14.10.2009 13:09 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\axtmvprt.sys [14.10.2009 13:09 38784]
S3 ComFiltr;Panda Anti-Dialer;\??\c:\windows\system32\DRIVERS\COMFiltr.sys --> c:\windows\system32\DRIVERS\COMFiltr.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [15.3.2011 7:53 38224]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-21 06:40]
.
2011-03-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-21 06:40]
.
2011-03-15 c:\windows\Tasks\User_Feed_Synchronization-{BB3E2E65-FD0E-4F32-B16D-5E591D8013D4}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://
www.google.com/search?q={searchTerms}&s ... f8&oe=utf8
uStart Page = hxxp://
www.seznam.cz/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {{141D2E4F-F313-4991-B61A-EE5D6D849361} -
http://bleskove.centrum.cz
IE: {{2A5CFB1C-AAA2-4760-8462-1B61CF74B7D8} -
http://www.centrum.cz
IE: {{2BCB61BF-DC41-4738-A149-BDAAAD7FF0BD} -
http://www.xchat.cz
IE: {{2E01031B-AB09-4455-823D-25F1A1C11F48} -
http://aktualne.centrum.cz
IE: {{2F741D0A-150E-40F9-A602-1B2421475F1D} -
http://slovniky.centrum.cz
IE: {{309176E6-E204-40A0-8D13-7F19C0498C40} -
http://www.supermapy.cz
IE: {{49681216-5BF4-41A2-AAFA-129A6BD625DA} -
http://mp3.centrum.cz/
IE: {{8B6E8E01-D262-4980-8C27-B8B2802285C1} -
http://www.zena.cz
IE: {{8FD64249-590C-4FBC-B181-12A6BAF516AF} -
http://www.fotoalba.cz
IE: {{A5050656-2286-454F-A489-C605ED1B461C} -
http://pocasi.centrum.cz
IE: {{BC78516C-9DC9-40C5-A91E-74593222EF89} -
http://sportplus.centrum.cz
IE: {{DAE865E8-970E-4931-A172-119CB56BBAF5} -
http://www.digitalne.cz/
IE: {{FC29EB7D-EDBA-4299-AEE4-D1BDC70EFA15} -
http://www.stahuj.cz/
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: microsoft.com\
www.update
DPF: {50E43D86-A74D-11D0-98CE-004005249458} - hxxps://
www.mojebanka.cz/jars/confwiz/MVSGif.cab
FF - ProfilePath - c:\documents and settings\petr.vondrak\Data aplikací\Mozilla\Firefox\Profiles\freo347o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://
www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.centrum.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - prefs.js: browser.startup.homepage - hxxp://
www.daemon-search.com/startpage|http://www.centrum.cz/
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: network.proxy.type - 1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{11D54ACE-09A9-11D4-8ACE-00C04F542830} - (no file)
WebBrowser-{015407A9-D183-4379-8452-DFD7C2297902} - (no file)
HKLM-Run-snpstd - c:\windows\vsnpstd.exe
SafeBoot-Wdf01000.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-Samsung PanelMgr - c:\windows\Samsung\PanelMgr\SSMMgr.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-15 09:33
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3921266920-1397699539-1127604013-1012\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{155D7918-A08E-BBD4-39E6-CB9A486B6D7D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"cbppndlabgificbfgnfgfoegdgpollnhklphld"=hex:6a,61,63,62,6b,70,68,67,6a,66,62,
62,65,6e,70,69,62,62,64,61,00,00
"bbfplknlgfopnipnojpaakgdbccjfomeimbl"=hex:6a,61,63,62,6b,70,68,67,6a,66,62,62,
65,6e,70,69,62,62,64,61,00,00
"iappndlabgificbfgn"=hex:61,61,00,7f
"hafplknlgfopnipn"=hex:61,61,00,7f
"iadpfifcjlkidbmkbf"=hex:61,61,00,7f
.
[HKEY_USERS\S-1-5-21-3921266920-1397699539-1127604013-1012\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7678CED7-A910-74B8-45C4-715440CC6670}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"dbcllbblegcnakhiejngjeanlpacpaoakaehjcgf"=hex:69,61,62,6e,64,69,67,6f,62,66,
67,61,65,62,6b,66,63,69,00,00
"cbikbhdmncjchcidfodekcogjnpapngnfdjebc"=hex:69,61,62,6e,64,69,67,6f,62,66,67,
61,65,62,6b,66,63,69,00,00
.
[HKEY_USERS\S-1-5-21-3921266920-1397699539-1127604013-1012\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{774311BE-CDA0-C376-91BD-012A1B39287B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"dbkedcnliiombbbblbpgfimpigaioaiehnhpbdea"=hex:6a,61,6f,70,65,64,70,67,69,6f,
62,66,6a,6a,67,70,68,65,66,66,00,16
"cbefjncmiodnhgdcimfongfgjemdjfmopkjknc"=hex:6a,61,6f,70,64,64,6d,67,64,67,6e,
66,6e,64,67,6a,67,61,6d,6d,00,16
"iakedcnliiombbbblb"=hex:61,61,00,00
"haefjncmiodnhgdc"=hex:61,61,00,00
"iaoflmkdaddgjbgelm"=hex:61,61,00,00
.
[HKEY_USERS\S-1-5-21-3921266920-1397699539-1127604013-1012\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D09D58F2-F5D7-F7F2-B969-FD4AC48032AD}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"dbehnpkiecengjfhlilmoijalebophleamebadim"=hex:6a,61,61,70,6c,62,70,6e,63,67,
63,63,67,70,6f,65,6c,63,66,61,00,dd
"cbkhkeinjhdomgoegeebnjomommldfliglamco"=hex:6a,61,61,70,69,62,63,6f,62,67,62,
65,68,6d,70,6a,70,63,68,6e,00,dd
"iaehnpkiecengjfhli"=hex:61,61,00,00
"hakhkeinjhdomgoe"=hex:61,61,00,00
"iaafedolcbcbjnhial"=hex:61,61,00,00
.
[HKEY_USERS\S-1-5-21-3921266920-1397699539-1127604013-1012\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F99519FF-8CF8-4ED6-3C94-C48C2C68A5C0}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"dbpdpgjnifokebaencdiflgkmdgmckjlhlgnkkkg"=hex:69,61,6a,67,68,6f,6f,67,68,61,
69,6f,6f,65,70,65,6c,6a,00,00
"cbfdndfnpaddhihoodplinjidnnhbkeeoiccjf"=hex:69,61,6a,67,68,6f,6f,67,68,61,69,
6f,6f,65,70,65,6c,6a,00,00
"dbpdpgjnifokebaencdiflgkmdgmckjlhlgnomoh"=hex:69,61,6a,67,68,6f,6f,67,68,61,
69,6f,6f,65,70,65,6c,6a,00,00
"cbfdndfnpaddhihoodplinjidnnhbkeeoiobmg"=hex:6a,61,64,67,66,69,69,63,66,68,62,
66,64,68,6f,6d,6c,69,6d,67,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1b,80,bd,80,d9,b9,5e,d0,d8,67,0c,1a,9b,3f,78,82,db,0e,46,3b,ae,
bb,7e,39,8e,da,65,c6,4f,52,85,69,52,6d,48,8b,7e,d0,d2,8d,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e5461ba5-a8b2-4460-b838-4532f7f12e20}]
@Denied: (Full) (Everyone)
"Model"=dword:0000015b
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,ab,9e,50,1b,eb,77,d1,ab,fc,6c,7d,0c,e4,64,14,e0,75,31,85,e2,32,10,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-03-15 09:41:38
ComboFix-quarantined-files.txt 2011-03-15 08:41
.
Pre-Run: Volných bajtů: 19 258 753 024
Post-Run: Volných bajtů: 19 627 823 104
.
Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
- - End Of File - - A7A26BCB1B3CDC420DEFBEB403977286