ComboFix 10-03-03.09 - Marťaska 06.03.2010 12:46:58.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.503.225 [GMT 1:00]
Spuštěný z: c:\documents and settings\Marťaska.BUDULIN\Plocha\ComboFix.exe
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\temp
c:\recycler\S-1-5-21-1757981266-1957994488-725345543-1005
c:\recycler\S-1-5-21-1935655697-879983540-839522115-1005
c:\recycler\S-1-5-21-1935655697-879983540-839522115-500
c:\recycler\S-1-5-21-484763869-329068152-725345543-1004
c:\recycler\S-1-5-21-484763869-329068152-725345543-1005
c:\recycler\S-1-5-21-746137067-682003330-1133161676-1005
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-06 do 2010-03-06 )))))))))))))))))))))))))))))))
.
2010-03-06 11:04 . 2010-03-06 11:23 -------- d-----w- c:\program files\trend micro
2010-03-06 11:04 . 2010-03-06 11:04 -------- d-----w- C:\rsit
2010-03-06 10:31 . 2010-03-06 10:31 95 ----a-w- c:\windows\rafazon.bat
2010-03-06 09:54 . 2009-12-30 10:20 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2010-03-06 09:54 . 2010-03-06 09:54 -------- d-----w- c:\program files\VS Revo Group
2010-03-05 20:14 . 2010-03-05 20:14 -------- d--h--w- c:\windows\system32\CTF
2010-03-04 16:18 . 2010-03-05 16:55 -------- d-----w- c:\program files\Lineage II
2010-03-04 13:43 . 2010-03-04 13:43 -------- d-----w- C:\logs
2010-03-03 13:03 . 2010-03-03 13:58 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Lx_cats
2010-03-03 13:01 . 2007-11-28 17:51 40960 ----a-w- c:\windows\system32\lxdnvs.dll
2010-03-03 13:01 . 2008-02-15 04:52 348160 ----a-w- c:\windows\system32\lxdncoin.dll
2010-03-03 13:01 . 2008-02-27 11:05 115200 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdndrpp.dll
2010-03-03 13:00 . 2008-04-13 19:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-03-03 13:00 . 2008-04-13 19:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-03-03 12:59 . 2001-10-24 11:25 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-03-03 12:59 . 2001-10-24 11:25 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2010-03-03 12:58 . 2007-11-21 00:02 782336 ----a-w- c:\windows\system32\lxdndrs.dll
2010-03-03 12:58 . 2007-11-20 23:44 81920 ----a-w- c:\windows\system32\lxdncaps.dll
2010-03-03 12:58 . 2007-10-02 22:51 69632 ----a-w- c:\windows\system32\lxdncnv4.dll
2010-03-03 12:57 . 2007-11-01 14:29 45056 ----a-w- c:\windows\system32\LXF3PMON.DLL
2010-03-03 12:57 . 2007-11-01 14:28 32768 ----a-w- c:\windows\system32\LXF3FXPU.DLL
2010-03-03 12:56 . 2007-12-10 19:33 12288 ----a-w- c:\windows\system32\LXF3PMRC.DLL
2010-03-03 12:56 . 2007-08-27 17:44 53248 ----a-w- c:\windows\system32\lxf3oem.dll
2010-03-03 12:56 . 2007-05-02 02:05 98345 ----a-w- c:\windows\system32\IMHOST32.DLL
2010-03-03 12:56 . 2007-05-02 02:05 339968 ----a-w- c:\windows\system32\IMGMAN32.DLL
2010-03-03 12:56 . 2010-03-03 12:58 -------- d-----w- c:\program files\Lexmark Fax Solutions
2010-03-03 12:55 . 2010-03-03 12:56 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2010-03-03 12:53 . 2010-03-03 13:04 -------- d-----w- c:\program files\Lexmark 2600 Series
2010-03-03 12:16 . 2010-03-03 12:18 -------- d-----w- c:\program files\TO2SSM
2010-03-03 12:08 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-03 12:07 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-03 12:07 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-03 12:07 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-03-03 12:07 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-03-03 12:07 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-03-03 12:07 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-03-03 12:07 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-03-03 12:07 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-03-03 12:07 . 2009-02-09 10:56 709632 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-03-03 12:07 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-03-03 12:06 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-03 12:06 . 2010-03-03 12:17 -------- d-----w- c:\program files\Common Files\Motive
2010-03-03 12:04 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-03 12:02 . 2008-04-21 21:15 216576 -c----w- c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-05 20:16 . 2008-04-25 18:31 -------- d-----w- c:\program files\Alwil Software
2010-03-05 20:03 . 2008-06-15 17:34 -------- d-----w- c:\program files\ICQ6
2010-03-05 11:53 . 2004-08-18 12:00 74426 ----a-w- c:\windows\system32\perfc005.dat
2010-03-05 11:53 . 2004-08-18 12:00 401726 ----a-w- c:\windows\system32\perfh005.dat
2010-03-04 16:18 . 2008-04-25 18:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-04 10:08 . 2008-04-26 10:10 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-04 10:08 . 2008-04-28 19:28 -------- d-----w- c:\program files\SuperAntiSpyware
2010-03-04 10:04 . 2008-04-26 10:18 -------- d-----w- c:\program files\Canon
2010-03-03 12:55 . 2010-03-03 12:54 -------- d-----w- c:\program files\Lexmark Toolbar
2010-01-05 09:58 . 2004-08-18 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 09:57 . 2004-08-18 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 09:57 . 2004-08-18 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2004-08-18 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-17 07:42 . 2008-06-15 16:18 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-18 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2008-05-25 19:36 . 2008-05-25 19:35 101852 ----a-w- c:\program files\Uninst.isu
2002-04-03 13:01 . 2008-05-25 19:35 286720 ----a-w- c:\program files\PanoViewer.dll
2002-04-02 13:19 . 2008-05-25 19:35 53248 ----a-w- c:\program files\UPanoRc.dll
2002-03-01 14:33 . 2008-05-25 19:35 36864 ----a-w- c:\program files\QTVREXP.dll
2000-10-24 12:24 . 2008-05-25 19:35 20480 ----a-w- c:\program files\u32sn.dll
1999-05-21 15:15 . 2008-05-25 19:35 86016 ----a-w- c:\program files\NPUPano.dll
1999-05-10 13:00 . 2008-05-25 19:35 57344 ----a-w- c:\program files\u32Scan.dll
1999-04-30 14:00 . 2008-05-25 19:35 98304 ----a-w- c:\program files\UPjpeg.dll
1999-04-27 08:50 . 2008-05-25 19:35 32768 ----a-w- c:\program files\UPConst.dll
1999-04-23 20:06 . 2008-05-25 19:35 493401 ----a-w- c:\program files\UPANO.HLP
1999-04-23 20:03 . 2008-05-25 19:35 2328 ----a-w- c:\program files\upano.cnt
1999-03-16 21:05 . 2008-05-25 19:35 33280 ----a-w- c:\program files\IS32Inst.dll
1999-03-10 07:57 . 2008-05-25 19:35 15404 ----a-w- c:\program files\README.HLP
1999-03-10 07:57 . 2008-05-25 19:35 66518 ----a-w- c:\program files\UPVIEWER.HLP
1999-03-05 09:22 . 2008-05-25 19:35 500224 ----a-w- c:\program files\U32CFG.DLL
1999-02-09 20:16 . 2008-05-25 19:35 53248 ----a-w- c:\program files\Stitch.dll
1999-02-09 20:15 . 2008-05-25 19:35 819200 ----a-w- c:\program files\Bmp800.dll
1999-02-09 20:15 . 2008-05-25 19:35 921600 ----a-w- c:\program files\Bmp1024.dll
1999-02-09 09:10 . 2008-05-25 19:35 147456 ----a-w- c:\program files\U32PRINT.DLL
1999-02-08 12:37 . 2008-05-25 19:35 2980 ----a-w- c:\program files\MUp.WAV
1999-02-08 12:36 . 2008-05-25 19:35 1138 ----a-w- c:\program files\MOver.wav
1999-02-08 12:36 . 2008-05-25 19:35 3896 ----a-w- c:\program files\MDown.WAV
1999-02-01 15:14 . 2008-05-25 19:35 69632 ----a-w- c:\program files\u32txEx.dll
1999-02-01 15:14 . 2008-05-25 19:35 118784 ----a-w- c:\program files\U32tx.dll
1999-02-01 15:13 . 2008-05-25 19:35 143360 ----a-w- c:\program files\U32CVT.DLL
1999-02-01 15:12 . 2008-05-25 19:35 139264 ----a-w- c:\program files\u32Clips.dll
1999-02-01 15:11 . 2008-05-25 19:35 53248 ----a-w- c:\program files\U32MISC.DLL
1999-02-01 15:10 . 2008-05-25 19:35 167936 ----a-w- c:\program files\U32FIDO.DLL
1999-02-01 15:10 . 2008-05-25 19:35 28672 ----a-w- c:\program files\u32Spy.dll
1999-02-01 15:09 . 2008-05-25 19:35 122880 ----a-w- c:\program files\u32File.dll
1999-02-01 15:09 . 2008-05-25 19:35 32768 ----a-w- c:\program files\scanres.dll
1999-02-01 15:09 . 2008-05-25 19:35 126976 ----a-w- c:\program files\U32COMM.DLL
1999-02-01 15:08 . 2008-05-25 19:35 212992 ----a-w- c:\program files\U32BASE.DLL
1998-06-11 18:38 . 2008-05-25 19:35 4528 ----a-w- c:\program files\SETBROWS.EXE
1996-09-11 12:33 . 2008-05-25 19:35 48640 ----a-w- c:\program files\INETWH32.DLL
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-01-28 21:56 135168 ------w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-02 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-02 126976]
"SoundMan"="SOUNDMAN.EXE" [2005-12-14 577536]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2008-08-15 1473536]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2009-01-29 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2009-01-29 16040]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2009-01-29 320168]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnjswx.exe"=
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [3.3.2010 14:01 98984]
S3 PAC207;USB PC Cam Plus;c:\windows\system32\drivers\PFC027.sys [24.2.2005 11:29 162176]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [6.3.2010 10:54 27064]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]
2008-04-14 03:22 58187 ---h--w- c:\windows\system32\CTF\svghost.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.qip.ru
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Marťaska.BUDULIN\Data aplikací\Mozilla\Firefox\Profiles\h97c8ko9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-divxd&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - http:/
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?ei=UTF-8&fr=ytff-divxd&p=
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Notify-AtiExtEvent - (no file)
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\UninstFl.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-06 12:54
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(2512)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-06 12:58:41
ComboFix-quarantined-files.txt 2010-03-06 11:58
Před spuštěním: Volných bajtů: 13 968 326 656
Po spuštění: Volných bajtů: 14 829 621 248
- - End Of File - - 7D3689AD2E49AE5C70A3A47D7E49B937