ComboFix 11-05-22.02 - Lucie 23.05.2011 21:54:11.2.1 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2302.1994 [GMT 2:00]
Spuštěný z: c:\documents and settings\Lucie\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Lucie\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\cb_102.ico
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_101.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-04-23 do 2011-05-23 )))))))))))))))))))))))))))))))
.
.
2011-05-23 17:39 . 2011-05-09 20:46 6962000 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\mpengine.dll
2011-05-23 16:43 . 2011-05-23 16:44 -------- d-----w- c:\program files\trend micro
2011-05-23 16:43 . 2011-05-23 16:44 -------- d-----w- C:\rsit
2011-05-04 09:40 . 2011-05-04 09:40 -------- d-----w- c:\windows\Sun
2011-05-03 21:39 . 2011-05-23 18:02 -------- d-----w- c:\documents and settings\Lucie\Local Settings\Data aplikací\AskToolbar
2011-04-26 18:30 . 2011-04-26 18:31 -------- d-----w- c:\documents and settings\Lucie\Data aplikací\BSplayer
2011-04-26 18:30 . 2011-04-26 18:30 -------- d-----w- c:\documents and settings\Lucie\Data aplikací\BSplayer Pro
2011-04-26 18:30 . 2011-04-26 18:30 -------- d-----w- c:\program files\Webteh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-09 20:46 . 2011-04-16 23:43 6962000 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-04-14 19:06 . 2011-04-14 19:07 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-14 19:06 . 2011-04-14 19:07 411368 ----a-w- c:\windows\system32\deploytk.dll
2011-04-12 20:25 . 2011-04-12 20:25 319488 ----a-w- c:\windows\HideWin.exe
2011-04-10 13:49 . 2011-04-12 19:47 359016 ----a-w- c:\windows\vncutil.exe
2011-04-10 13:48 . 2011-04-12 19:47 56936 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2011-04-10 13:48 . 2011-04-12 19:47 129640 ----a-w- c:\windows\RtkAudioService.exe
2011-04-10 13:48 . 2011-04-12 19:47 1395800 ----a-w- c:\windows\system32\drivers\Monfilt.sys
2011-04-10 13:48 . 2011-04-12 19:47 1691480 ----a-w- c:\windows\system32\drivers\Ambfilt.sys
2011-04-10 13:48 . 2011-04-12 19:47 1284712 ----a-w- c:\windows\RtlExUpd.dll
2011-03-25 23:48 . 2011-03-25 23:48 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-03-14 17:26 . 2011-04-12 19:57 356352 ----a-w- c:\windows\EMCRI.dll
2011-03-14 17:26 . 2011-04-11 05:16 74752 ----a-w- c:\windows\system32\drivers\ESM7SK.sys
2011-03-14 17:26 . 2011-04-11 05:16 40064 ----a-w- c:\windows\system32\drivers\ESD7SK.sys
2011-03-14 17:26 . 2011-04-11 05:16 61056 ----a-w- c:\windows\system32\drivers\EMS7SK.sys
2011-03-14 16:45 . 2011-04-12 19:47 86016 ----a-w- c:\windows\SoundMan.exe
2011-03-14 16:45 . 2011-04-12 19:47 266240 ----a-w- c:\windows\system32\RTSndMgr.cpl
2011-03-14 16:45 . 2011-04-12 19:47 1826816 ----a-w- c:\windows\SkyTel.exe
2011-03-14 16:45 . 2011-04-12 19:47 1196032 ----a-w- c:\windows\RtlUpd.exe
2011-03-14 16:45 . 2011-04-12 19:47 9715200 ----a-w- c:\windows\RTLCPL.exe
2011-03-14 16:45 . 2011-04-12 19:47 4707328 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2011-03-14 16:45 . 2011-04-12 19:47 16861184 ----a-w- c:\windows\RTHDCPL.exe
2011-03-14 16:45 . 2011-04-12 20:26 69632 ----a-w- c:\windows\Alcmtr.exe
2011-03-14 16:45 . 2011-04-12 19:47 2165760 ----a-w- c:\windows\MicCal.exe
2011-03-14 16:45 . 2011-04-12 19:47 299008 ----a-w- c:\windows\system32\ALSndMgr.cpl
2011-03-14 16:45 . 2011-04-12 19:47 2808832 ----a-w- c:\windows\alcwzrd.exe
2011-03-14 16:45 . 2011-04-12 20:26 49152 ----a-w- c:\windows\system32\ChCfg.exe
2011-03-14 16:41 . 2011-04-11 05:03 77824 ----a-w- c:\windows\system32\Oemdspif.dll
2011-03-14 16:41 . 2011-04-11 05:03 24064 ----a-w- c:\windows\system32\ativcoxx.dll
2011-03-14 16:41 . 2011-04-11 05:03 1408000 ----a-w- c:\windows\system32\ativvaxx.dll
2011-03-14 16:41 . 2011-04-11 05:03 17408 ----a-w- c:\windows\system32\atitvo32.dll
2011-03-14 16:41 . 2011-04-11 05:03 114688 ----a-w- c:\windows\system32\atipdlxx.dll
2011-03-14 16:41 . 2011-04-11 05:03 5033984 ----a-w- c:\windows\system32\atioglxx.dll
2011-03-14 16:41 . 2011-04-11 05:03 6684672 ----a-w- c:\windows\system32\atioglx1.dll
2011-03-14 16:41 . 2011-04-11 05:03 151552 ----a-w- c:\windows\system32\atikvmag.dll
2011-03-14 16:41 . 2011-04-11 05:03 307200 ----a-w- c:\windows\system32\atiiiexx.dll
2011-03-14 16:41 . 2011-04-11 05:03 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2011-03-14 16:41 . 2011-04-11 05:03 2693280 ----a-w- c:\windows\system32\ati3duag.dll
2011-03-14 16:41 . 2011-04-11 05:03 1540096 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-03-14 16:41 . 2011-04-11 05:03 405504 ----a-w- c:\windows\system32\ati2evxx.exe
2011-03-14 16:41 . 2011-04-11 05:03 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2011-03-14 16:41 . 2011-04-11 05:03 61440 ----a-w- c:\windows\system32\ati2evxx.dll
2011-03-14 16:41 . 2011-04-11 05:03 41984 ----a-w- c:\windows\system32\ati2edxx.dll
2011-03-14 16:41 . 2011-04-11 05:03 40960 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-03-14 16:41 . 2011-04-11 05:03 258048 ----a-w- c:\windows\system32\ati2dvag.dll
2011-03-14 16:41 . 2011-04-11 05:03 282624 ----a-w- c:\windows\system32\ati2cqag.dll
2011-03-07 05:33 . 2011-04-12 19:16 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:43 . 2006-03-02 12:00 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:53 . 2006-03-02 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-23_18.43.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-03-02 12:00 . 2011-05-23 18:42 67312 c:\windows\system32\perfc009.dat
+ 2006-03-02 12:00 . 2011-05-23 19:56 67312 c:\windows\system32\perfc009.dat
- 2006-03-02 12:00 . 2011-05-23 18:42 77872 c:\windows\system32\perfc005.dat
+ 2006-03-02 12:00 . 2011-05-23 19:56 77872 c:\windows\system32\perfc005.dat
+ 2006-03-02 12:00 . 2011-05-23 19:56 432356 c:\windows\system32\perfh009.dat
- 2006-03-02 12:00 . 2011-05-23 18:42 432356 c:\windows\system32\perfh009.dat
+ 2006-03-02 12:00 . 2011-05-23 19:56 428750 c:\windows\system32\perfh005.dat
- 2006-03-02 12:00 . 2011-05-23 18:42 428750 c:\windows\system32\perfh005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2011-03-14 16861184]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2011-03-14 53248]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="c:\program files\ICQ7.4\ICQ.exe" silent loginmode=4
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.4\\ICQ.exe"=
.
S1 MpKsl376f36cf;MpKsl376f36cf;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DF4B4737-A42F-4309-843D-873E0FC05DDA}\MpKsl376f36cf.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DF4B4737-A42F-4309-843D-873E0FC05DDA}\MpKsl376f36cf.sys [?]
S1 MpKsl52ca8c9b;MpKsl52ca8c9b;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\MpKsl52ca8c9b.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\MpKsl52ca8c9b.sys [?]
S1 MpKsl5c2e8a45;MpKsl5c2e8a45;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CAB4DFBC-50BC-4241-9D74-32DCE894C8FE}\MpKsl5c2e8a45.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{CAB4DFBC-50BC-4241-9D74-32DCE894C8FE}\MpKsl5c2e8a45.sys [?]
S1 MpKsl67cae7e5;MpKsl67cae7e5;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{01DC669D-516A-45ED-9C63-3531CA4E6837}\MpKsl67cae7e5.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{01DC669D-516A-45ED-9C63-3531CA4E6837}\MpKsl67cae7e5.sys [?]
S1 MpKsl771bc2ad;MpKsl771bc2ad;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E4CEFCA8-AFCC-4615-8791-5F6A17361AE1}\MpKsl771bc2ad.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E4CEFCA8-AFCC-4615-8791-5F6A17361AE1}\MpKsl771bc2ad.sys [?]
S1 MpKsla50eda38;MpKsla50eda38;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{ABA3552E-295B-48A3-9513-348B663D2D84}\MpKsla50eda38.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{ABA3552E-295B-48A3-9513-348B663D2D84}\MpKsla50eda38.sys [?]
S1 MpKslbc144582;MpKslbc144582;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E4CEFCA8-AFCC-4615-8791-5F6A17361AE1}\MpKslbc144582.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{E4CEFCA8-AFCC-4615-8791-5F6A17361AE1}\MpKslbc144582.sys [?]
S1 MpKsld5e8b226;MpKsld5e8b226;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{EDEA5D9F-D532-4EED-897A-06DA314A5EEC}\MpKsld5e8b226.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{EDEA5D9F-D532-4EED-897A-06DA314A5EEC}\MpKsld5e8b226.sys [?]
S1 MpKsle3d17329;MpKsle3d17329;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\MpKsle3d17329.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\MpKsle3d17329.sys [?]
S1 MpKslf7cb13bc;MpKslf7cb13bc;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\MpKslf7cb13bc.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{34AABE5C-DA2C-4994-B55F-B6E977531CCE}\MpKslf7cb13bc.sys [?]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [30.9.2010 17:54 1051968]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [12.4.2011 21:47 1691480]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [24.2.2010 14:41 10064]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MDMXSDK
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - c:\program files\ICQ7.4\ICQ.exe
FF - ProfilePath - c:\documents and settings\Lucie\Data aplikací\Mozilla\Firefox\Profiles\xjr3uqyq.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-23 21:57
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2011-05-23 21:59:00
ComboFix-quarantined-files.txt 2011-05-23 19:58
ComboFix2.txt 2011-05-23 18:45
.
Před spuštěním: Volných bajtů: 89 755 406 336
Po spuštění: Volných bajtů: 89 744 502 784
.
- - End Of File - - 16CC411036B540CE954774DE4F61A7E6