ComboFix 11-06-01.07 - Administrator 03.06.2011 1:40.2.2 - x86 MINIMAL
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
c:\documents and settings\All Users\Data aplikací\5FF7.tmp
c:\documents and settings\All Users\Data aplikací\78DE.tmp
c:\documents and settings\All Users\Data aplikací\86D8.tmp
c:\documents and settings\All Users\Data aplikací\C87F.tmp
c:\documents and settings\All Users\Data aplikací\defender.exe
c:\documents and settings\Erunis\Data aplikací\1E905CF431FD4FC5FC53ADA3073153F0
c:\documents and settings\Erunis\Data aplikací\1E905CF431FD4FC5FC53ADA3073153F0\enemies-names.txt
c:\documents and settings\Erunis\Data aplikací\1E905CF431FD4FC5FC53ADA3073153F0\local.ini
c:\documents and settings\Erunis\Data aplikací\1E905CF431FD4FC5FC53ADA3073153F0\lss700dbgg.exe
c:\documents and settings\Erunis\Data aplikací\1E905CF431FD4FC5FC53ADA3073153F0\upd_debug.exe
c:\documents and settings\Erunis\Data aplikací\Adobe\plugs
c:\documents and settings\Erunis\Data aplikací\Adobe\shed
c:\documents and settings\Erunis\Data aplikací\PriceGong
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\1.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\a.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\b.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\c.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\d.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\e.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\f.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\g.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\h.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\i.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\J.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\k.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\l.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\m.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\mru.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\n.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\o.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\p.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\q.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\r.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\s.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\t.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\u.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\v.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\w.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\x.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\y.xml
c:\documents and settings\Erunis\Data aplikací\PriceGong\Data\z.xml
c:\documents and settings\Erunis\Local Settings\Data aplikací\{1452B0C7-9A9A-4FE1-A0D9-DAF95680DD06}
c:\documents and settings\Erunis\Local Settings\Data aplikací\{1452B0C7-9A9A-4FE1-A0D9-DAF95680DD06}\chrome.manifest
c:\documents and settings\Erunis\Local Settings\Data aplikací\{1452B0C7-9A9A-4FE1-A0D9-DAF95680DD06}\chrome\content\_cfg.js
c:\documents and settings\Erunis\Local Settings\Data aplikací\{1452B0C7-9A9A-4FE1-A0D9-DAF95680DD06}\chrome\content\overlay.xul
c:\documents and settings\Erunis\Local Settings\Data aplikací\{1452B0C7-9A9A-4FE1-A0D9-DAF95680DD06}\install.rdf
c:\documents and settings\NetworkService\Local Settings\Data aplikací\ata.exe
c:\windows\mpicshsr.dll
c:\windows\ujuzocij.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-05-02 do 2011-06-02 )))))))))))))))))))))))))))))))
.
.
2011-06-05 20:17 . 2011-06-05 20:17 -------- d-----w- c:\windows\system32\LogFiles
2011-06-04 19:16 . 2004-08-17 13:49 25600 ----a-w- c:\documents and settings\LocalService\Data aplikací\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-06-02 23:06 . 2011-06-02 23:06 -------- d-----w- c:\program files\trend micro
2011-06-02 23:06 . 2011-06-02 23:06 -------- d-----w- C:\rsit
2011-06-02 01:38 . 2011-06-02 02:33 -------- d-----w- c:\documents and settings\Administrator
2011-05-31 23:35 . 2011-06-01 18:21 -------- d-----w- c:\documents and settings\Erunis\Local Settings\Data aplikací\NPE
2011-05-31 02:18 . 2011-05-31 02:18 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2011-05-30 22:02 . 2011-05-30 22:02 181760 ----a-w- c:\documents and settings\All Users\Data aplikací\mgrparseboot.exe
2011-05-30 21:52 . 2011-05-30 21:52 -------- d-----w- C:\Adobe
2011-05-30 21:18 . 2011-05-30 21:18 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2011-05-30 01:35 . 2011-06-01 23:31 0 ----a-w- c:\windows\Bxudexuguje.bin
2011-05-28 20:22 . 2011-06-02 01:17 -------- d-----w- c:\documents and settings\Erunis\Data aplikací\go
2011-05-28 20:22 . 2011-06-02 01:17 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Easybits GO
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 19:00 . 2009-12-23 21:05 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-17 141848]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1032192]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-06-09 870920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-12-21 39424]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-21 30192]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-01 149280]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 SMR162;Symantec SMR Utility Service 1.6.2;c:\windows\System32\drivers\SMR162.SYS [x]
R1 aswSP;avast! Self Protection; [x]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 136176]
R2 LGScsiCommandService;LG SCSI command service;c:\windows\system32\LGScsiCommandService.exe [2010-04-12 47616]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-21 30192]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 136176]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-25 691696]
S3 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2008-05-13 51288]
S3 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2008-06-12 43608]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MDMXSDK
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 18:16]
.
2011-05-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 18:16]
.
.
------- Doplňkový sken -------
.
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath -
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-Imukogoloputu - c:\windows\ujuzocij.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-03 01:46
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: Hitachi_HTS543232L9A300 rev.FB4OC40C -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
error: Read Zařízení připojené k systému nefunguje.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A54553B
\Driver\atapi -> 0x8a6e81f8
user & kernel MBR OK
.
**************************************************************************
.
Celkový čas: 2011-06-03 01:48:21
ComboFix-quarantined-files.txt 2011-06-02 23:48
.
Před spuštěním: 2 402 934 784
Po spuštění: 2 360 459 264
.
- - End Of File - - 63D1253797D41B82DD1E749ABDD8063F