ROOTKIT
Napsal: 08 bře 2010 10:41
Dobrý den, NOD mi hlásí přítomnost rootkitu. Prosím o pomoc.
-----------------------------------------------------------------------------------------------
ComboFix 10-03-07.04 - Hoodie Tonez 08.03.2010 9:35.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.532 [GMT 1:00]
Spuštěný z: c:\documents and settings\Hoodie Tonez\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Data aplikacˇ\ajadumapum.vbs
c:\documents and settings\Hoodie Tonez\Data aplikacˇ\egyl.reg
c:\documents and settings\Hoodie Tonez\Dokumenty\cc_20100307_202120.reg
c:\documents and settings\Hoodie Tonez\Local Settings\Data aplikacˇ\qineq.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-08 do 2010-03-08 )))))))))))))))))))))))))))))))
.
2010-03-06 18:09 . 2008-04-13 18:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-03-06 18:09 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-03-06 18:09 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-03-06 18:09 . 2008-04-13 18:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-03-06 18:09 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\drivers\Changer.sys
2010-03-06 09:09 . 2010-03-06 09:09 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-06 07:44 . 2010-03-06 07:45 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-17 15:05 . 2010-02-17 15:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-02-17 15:03 . 2010-02-17 15:07 -------- d-----w- c:\program files\ICQ6.5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-08 08:34 . 2004-08-18 12:00 90056 ----a-w- c:\windows\system32\perfc005.dat
2010-03-08 08:34 . 2004-08-18 12:00 455388 ----a-w- c:\windows\system32\perfh005.dat
2010-03-08 08:14 . 2009-03-16 10:00 -------- d-----w- c:\program files\Common Files\Motive
2010-03-07 19:19 . 2009-11-10 12:20 -------- d-----w- c:\program files\CCleaner
2010-03-06 07:39 . 2006-09-16 12:08 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-03-04 12:14 . 2006-11-12 13:20 -------- d-----w- c:\program files\Nová složka
2010-02-26 09:23 . 2007-01-06 16:52 16 -c--a-w- c:\windows\msocreg32.dat
2010-02-17 15:04 . 2008-02-29 07:32 -------- d-----w- c:\program files\ICQ6
2010-02-03 11:39 . 2010-02-03 11:39 -------- d-----w- c:\program files\Bethesda Softworks
2010-02-03 11:39 . 2006-01-26 15:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-21 08:27 . 2010-01-21 08:27 -------- d-----w- c:\program files\CAPCOM
2010-01-15 06:24 . 2008-03-05 15:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-14 08:20 . 2010-01-11 12:49 -------- d-----w- c:\program files\Codemasters
2010-01-11 13:25 . 2010-01-11 13:25 -------- d-----w- c:\program files\BRS
2010-01-11 13:25 . 2010-01-11 13:24 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-11 13:23 . 2010-01-11 13:23 -------- d-----w- c:\program files\OpenAL
2010-01-11 13:23 . 2006-09-13 14:11 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-01-11 13:23 . 2006-09-13 14:11 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-11 12:47 . 2010-01-11 12:47 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-01-11 12:47 . 2010-01-11 12:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-11 12:47 . 2006-09-18 19:29 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-10 16:17 . 2010-01-10 16:17 -------- d-----w- c:\program files\uTorrent
2009-12-31 16:50 . 2004-08-18 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 07:55 . 2009-12-30 07:55 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-22 05:09 . 2004-08-18 12:00 668160 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2004-08-18 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2006-01-26 15:20 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-18 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-12 14:15 . 2005-10-14 09:56 178176 ----a-w- c:\windows\system32\unrar.dll
2009-12-09 10:11 . 2004-08-18 12:00 2147328 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:11 . 2004-08-17 15:45 2025984 ------w- c:\windows\system32\ntkrnlpa.exe
2008-05-31 15:38 . 2008-05-29 14:32 1222 ----a-w- c:\program files\Nový objekt - Textový dokument (5).txt
2007-04-18 20:54 . 2008-02-11 12:58 16083128 ----a-w- c:\program files\Dreamweaver2.exe
.
((((((((((((((((((((((((((((( SnapShot_2010-03-07_19.11.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-18 12:00 . 2010-03-07 19:00 78744 c:\windows\system32\perfc009.dat
+ 2004-08-18 12:00 . 2010-03-08 08:34 78744 c:\windows\system32\perfc009.dat
+ 2008-01-22 14:30 . 2008-04-13 18:46 19200 c:\windows\system32\dllcache\wstcodec.sys
+ 2006-01-26 15:49 . 2008-04-13 18:45 26368 c:\windows\system32\dllcache\usbstor.sys
+ 2008-04-28 14:57 . 2008-04-13 18:45 15104 c:\windows\system32\dllcache\usbscan.sys
+ 2006-12-16 19:03 . 2008-04-13 18:45 32128 c:\windows\system32\dllcache\usbccgp.sys
+ 2006-12-16 19:03 . 2008-04-13 18:45 60032 c:\windows\system32\dllcache\usbaudio.sys
+ 2006-01-26 15:20 . 2008-04-14 03:23 21896 c:\windows\system32\dllcache\tdtcp.sys
+ 2006-01-26 15:20 . 2008-04-14 03:23 12040 c:\windows\system32\dllcache\tdpipe.sys
+ 2006-01-26 15:43 . 2008-04-13 18:45 56576 c:\windows\system32\dllcache\swmidi.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 15232 c:\windows\system32\dllcache\streamip.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 11136 c:\windows\system32\dllcache\slip.sys
+ 2004-08-18 12:00 . 2008-04-13 18:40 11392 c:\windows\system32\dllcache\sfloppy.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 10880 c:\windows\system32\dllcache\ndisip.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 85248 c:\windows\system32\dllcache\nabtsfec.sys
+ 2004-08-17 15:43 . 2008-04-14 02:06 30080 c:\windows\system32\dllcache\modem.sys
+ 2006-01-26 16:17 . 2008-04-13 18:54 11264 c:\windows\system32\dllcache\irenum.sys
+ 2004-08-18 12:00 . 2008-04-13 18:57 20864 c:\windows\system32\dllcache\ipinip.sys
+ 2004-08-18 12:00 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\ip6fw.sys
+ 2004-08-18 12:00 . 2008-04-13 18:40 20480 c:\windows\system32\dllcache\flpydisk.sys
+ 2004-08-18 12:00 . 2008-04-13 18:40 27392 c:\windows\system32\dllcache\fdc.sys
+ 2006-01-26 15:43 . 2008-04-13 18:45 52864 c:\windows\system32\dllcache\dmusic.sys
+ 2001-08-17 21:52 . 2004-08-18 12:00 18688 c:\windows\system32\dllcache\cdaudio.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 17024 c:\windows\system32\dllcache\ccdecode.sys
+ 2004-08-18 12:00 . 2008-04-13 18:51 59904 c:\windows\system32\dllcache\atmarpc.sys
+ 2004-08-18 12:00 . 2008-04-13 18:57 14336 c:\windows\system32\dllcache\asyncmac.sys
+ 2006-01-26 15:28 . 2010-03-08 08:12 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-01-26 15:28 . 2010-03-06 18:09 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-01-26 15:28 . 2010-03-08 08:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-01-26 15:28 . 2010-03-06 18:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-03-08 08:12 . 2010-03-08 08:12 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-03-06 18:08 . 2010-03-06 18:09 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-01-26 15:43 . 2008-04-13 18:45 6272 c:\windows\system32\dllcache\splitter.sys
+ 2008-01-22 14:30 . 2008-04-13 18:39 5504 c:\windows\system32\dllcache\mstee.sys
+ 2006-01-26 15:42 . 2008-04-13 18:39 4992 c:\windows\system32\dllcache\mspqm.sys
+ 2006-01-26 15:42 . 2008-04-13 18:39 5376 c:\windows\system32\dllcache\mspclock.sys
+ 2006-01-26 15:42 . 2008-04-13 18:39 7552 c:\windows\system32\dllcache\mskssrv.sys
+ 2006-01-26 15:43 . 2008-04-13 18:45 2944 c:\windows\system32\dllcache\drmkaud.sys
- 2004-08-18 12:00 . 2010-03-07 19:00 458954 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2010-03-08 08:34 458954 c:\windows\system32\perfh009.dat
+ 2006-01-26 15:20 . 2008-04-14 03:23 139656 c:\windows\system32\dllcache\rdpwd.sys
- 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
+ 2004-08-18 12:00 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
+ 2006-01-26 15:43 . 2008-04-13 16:39 142592 c:\windows\system32\dllcache\aec.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"CTHelper"="CTHELPER.EXE" [2005-08-07 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-08-07 18944]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"RCSystem"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 122880]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-28 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-09-15 917504]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-02 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-02 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-02 455168]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 15691264]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200]
"SxgTkBar"="SxgTkBar.exe" [2001-07-11 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-06 524632]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2009-01-16 1473536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Hoodie Tonez\Nabˇdka Start\Programy\Po spuçtŘnˇ\
winesm32.exe [2008-4-14 49664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=ma_cmidn.dll
"midi3"=ma_cmidn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\CAPCOM\\STREETFIGHTERIV\\StreetFighterIV.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [26.1.2006 16:44 25067]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [27.6.2009 14:16 64160]
R0 pe3ah4nb;DiRT Environment Driver (pe3ah4nb);c:\windows\system32\drivers\pe3ah4nb.sys [11.6.2007 12:11 64880]
R0 ps6ah4nb;DiRT Synchronization Driver (ps6ah4nb);c:\windows\system32\drivers\ps6ah4nb.sys [11.6.2007 12:10 55160]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [20.12.2006 10:11 11264]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [17.2.2010 16:05 222968]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [17.12.2006 0:52 33792]
R3 SOFTXG;YAMAHA XG WDM SoftSynthesizer;c:\windows\system32\drivers\sxgxgwdm.sys [7.1.2007 16:26 966784]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.9.2006 20:29 691696]
S2 ODBC service;ODBC service; [x]
S2 pr2ah4nb;DiRT Drivers Auto Removal (pr2ah4nb);c:\windows\system32\pr2ah4nb.exe svc --> c:\windows\system32\pr2ah4nb.exe svc [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 20:06 1029456]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [18.9.2006 20:34 223128]
.
Obsah adresáře 'Naplánované úlohy'
2009-09-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:58]
2010-03-08 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:19]
2008-09-12 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:19]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uInternet Connection Wizard,ShellNext = hxxp://www.quick.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: imon.dll
FF - ProfilePath - c:\documents and settings\Hoodie Tonez\Data aplikací\Mozilla\Firefox\Profiles\xd04mr5c.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-08 09:47
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\imon.dll
.
Celkový čas: 2010-03-08 09:51:43
ComboFix-quarantined-files.txt 2010-03-08 08:51
ComboFix2.txt 2010-03-07 19:12
ComboFix3.txt 2009-11-13 09:01
ComboFix4.txt 2009-11-10 10:56
Před spuštěním: 1 729 523 712
Po spuštění: 1 692 905 472
- - End Of File - - 6392C6FF177FC60B529E2BB187FF2A4A
-----------------------------------------------------------------------------------------------
ComboFix 10-03-07.04 - Hoodie Tonez 08.03.2010 9:35.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.532 [GMT 1:00]
Spuštěný z: c:\documents and settings\Hoodie Tonez\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Data aplikacˇ\ajadumapum.vbs
c:\documents and settings\Hoodie Tonez\Data aplikacˇ\egyl.reg
c:\documents and settings\Hoodie Tonez\Dokumenty\cc_20100307_202120.reg
c:\documents and settings\Hoodie Tonez\Local Settings\Data aplikacˇ\qineq.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-08 do 2010-03-08 )))))))))))))))))))))))))))))))
.
2010-03-06 18:09 . 2008-04-13 18:40 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-03-06 18:09 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-03-06 18:09 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-03-06 18:09 . 2008-04-13 18:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-03-06 18:09 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\drivers\Changer.sys
2010-03-06 09:09 . 2010-03-06 09:09 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-06 07:44 . 2010-03-06 07:45 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-17 15:05 . 2010-02-17 15:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-02-17 15:03 . 2010-02-17 15:07 -------- d-----w- c:\program files\ICQ6.5
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-08 08:34 . 2004-08-18 12:00 90056 ----a-w- c:\windows\system32\perfc005.dat
2010-03-08 08:34 . 2004-08-18 12:00 455388 ----a-w- c:\windows\system32\perfh005.dat
2010-03-08 08:14 . 2009-03-16 10:00 -------- d-----w- c:\program files\Common Files\Motive
2010-03-07 19:19 . 2009-11-10 12:20 -------- d-----w- c:\program files\CCleaner
2010-03-06 07:39 . 2006-09-16 12:08 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-03-04 12:14 . 2006-11-12 13:20 -------- d-----w- c:\program files\Nová složka
2010-02-26 09:23 . 2007-01-06 16:52 16 -c--a-w- c:\windows\msocreg32.dat
2010-02-17 15:04 . 2008-02-29 07:32 -------- d-----w- c:\program files\ICQ6
2010-02-03 11:39 . 2010-02-03 11:39 -------- d-----w- c:\program files\Bethesda Softworks
2010-02-03 11:39 . 2006-01-26 15:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-21 08:27 . 2010-01-21 08:27 -------- d-----w- c:\program files\CAPCOM
2010-01-15 06:24 . 2008-03-05 15:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-14 08:20 . 2010-01-11 12:49 -------- d-----w- c:\program files\Codemasters
2010-01-11 13:25 . 2010-01-11 13:25 -------- d-----w- c:\program files\BRS
2010-01-11 13:25 . 2010-01-11 13:24 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-11 13:23 . 2010-01-11 13:23 -------- d-----w- c:\program files\OpenAL
2010-01-11 13:23 . 2006-09-13 14:11 445016 ----a-w- c:\windows\system32\wrap_oal.dll
2010-01-11 13:23 . 2006-09-13 14:11 109144 ----a-w- c:\windows\system32\OpenAL32.dll
2010-01-11 12:47 . 2010-01-11 12:47 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-01-11 12:47 . 2010-01-11 12:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-11 12:47 . 2006-09-18 19:29 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-10 16:17 . 2010-01-10 16:17 -------- d-----w- c:\program files\uTorrent
2009-12-31 16:50 . 2004-08-18 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 07:55 . 2009-12-30 07:55 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-22 05:09 . 2004-08-18 12:00 668160 ------w- c:\windows\system32\wininet.dll
2009-12-22 05:09 . 2004-08-18 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2006-01-26 15:20 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-18 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-12 14:15 . 2005-10-14 09:56 178176 ----a-w- c:\windows\system32\unrar.dll
2009-12-09 10:11 . 2004-08-18 12:00 2147328 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-09 10:11 . 2004-08-17 15:45 2025984 ------w- c:\windows\system32\ntkrnlpa.exe
2008-05-31 15:38 . 2008-05-29 14:32 1222 ----a-w- c:\program files\Nový objekt - Textový dokument (5).txt
2007-04-18 20:54 . 2008-02-11 12:58 16083128 ----a-w- c:\program files\Dreamweaver2.exe
.
((((((((((((((((((((((((((((( SnapShot_2010-03-07_19.11.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-18 12:00 . 2010-03-07 19:00 78744 c:\windows\system32\perfc009.dat
+ 2004-08-18 12:00 . 2010-03-08 08:34 78744 c:\windows\system32\perfc009.dat
+ 2008-01-22 14:30 . 2008-04-13 18:46 19200 c:\windows\system32\dllcache\wstcodec.sys
+ 2006-01-26 15:49 . 2008-04-13 18:45 26368 c:\windows\system32\dllcache\usbstor.sys
+ 2008-04-28 14:57 . 2008-04-13 18:45 15104 c:\windows\system32\dllcache\usbscan.sys
+ 2006-12-16 19:03 . 2008-04-13 18:45 32128 c:\windows\system32\dllcache\usbccgp.sys
+ 2006-12-16 19:03 . 2008-04-13 18:45 60032 c:\windows\system32\dllcache\usbaudio.sys
+ 2006-01-26 15:20 . 2008-04-14 03:23 21896 c:\windows\system32\dllcache\tdtcp.sys
+ 2006-01-26 15:20 . 2008-04-14 03:23 12040 c:\windows\system32\dllcache\tdpipe.sys
+ 2006-01-26 15:43 . 2008-04-13 18:45 56576 c:\windows\system32\dllcache\swmidi.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 15232 c:\windows\system32\dllcache\streamip.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 11136 c:\windows\system32\dllcache\slip.sys
+ 2004-08-18 12:00 . 2008-04-13 18:40 11392 c:\windows\system32\dllcache\sfloppy.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 10880 c:\windows\system32\dllcache\ndisip.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 85248 c:\windows\system32\dllcache\nabtsfec.sys
+ 2004-08-17 15:43 . 2008-04-14 02:06 30080 c:\windows\system32\dllcache\modem.sys
+ 2006-01-26 16:17 . 2008-04-13 18:54 11264 c:\windows\system32\dllcache\irenum.sys
+ 2004-08-18 12:00 . 2008-04-13 18:57 20864 c:\windows\system32\dllcache\ipinip.sys
+ 2004-08-18 12:00 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\ip6fw.sys
+ 2004-08-18 12:00 . 2008-04-13 18:40 20480 c:\windows\system32\dllcache\flpydisk.sys
+ 2004-08-18 12:00 . 2008-04-13 18:40 27392 c:\windows\system32\dllcache\fdc.sys
+ 2006-01-26 15:43 . 2008-04-13 18:45 52864 c:\windows\system32\dllcache\dmusic.sys
+ 2001-08-17 21:52 . 2004-08-18 12:00 18688 c:\windows\system32\dllcache\cdaudio.sys
+ 2008-01-22 14:30 . 2008-04-13 18:46 17024 c:\windows\system32\dllcache\ccdecode.sys
+ 2004-08-18 12:00 . 2008-04-13 18:51 59904 c:\windows\system32\dllcache\atmarpc.sys
+ 2004-08-18 12:00 . 2008-04-13 18:57 14336 c:\windows\system32\dllcache\asyncmac.sys
+ 2006-01-26 15:28 . 2010-03-08 08:12 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-01-26 15:28 . 2010-03-06 18:09 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-01-26 15:28 . 2010-03-08 08:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-01-26 15:28 . 2010-03-06 18:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-03-08 08:12 . 2010-03-08 08:12 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-03-06 18:08 . 2010-03-06 18:09 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-01-26 15:43 . 2008-04-13 18:45 6272 c:\windows\system32\dllcache\splitter.sys
+ 2008-01-22 14:30 . 2008-04-13 18:39 5504 c:\windows\system32\dllcache\mstee.sys
+ 2006-01-26 15:42 . 2008-04-13 18:39 4992 c:\windows\system32\dllcache\mspqm.sys
+ 2006-01-26 15:42 . 2008-04-13 18:39 5376 c:\windows\system32\dllcache\mspclock.sys
+ 2006-01-26 15:42 . 2008-04-13 18:39 7552 c:\windows\system32\dllcache\mskssrv.sys
+ 2006-01-26 15:43 . 2008-04-13 18:45 2944 c:\windows\system32\dllcache\drmkaud.sys
- 2004-08-18 12:00 . 2010-03-07 19:00 458954 c:\windows\system32\perfh009.dat
+ 2004-08-18 12:00 . 2010-03-08 08:34 458954 c:\windows\system32\perfh009.dat
+ 2006-01-26 15:20 . 2008-04-14 03:23 139656 c:\windows\system32\dllcache\rdpwd.sys
- 2009-10-20 16:20 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
+ 2004-08-18 12:00 . 2009-10-20 16:20 265728 c:\windows\system32\dllcache\http.sys
+ 2006-01-26 15:43 . 2008-04-13 16:39 142592 c:\windows\system32\dllcache\aec.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"CTHelper"="CTHELPER.EXE" [2005-08-07 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-08-07 18944]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"RCSystem"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 122880]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-28 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2006-09-15 917504]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2006-03-02 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-02 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-03-02 455168]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-09 15691264]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200]
"SxgTkBar"="SxgTkBar.exe" [2001-07-11 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2006-06-19 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-05-12 831488]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-06 524632]
"TO2SSM_McciTrayApp"="c:\program files\TO2SSM\McciTrayApp.exe" [2009-01-16 1473536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Hoodie Tonez\Nabˇdka Start\Programy\Po spuçtŘnˇ\
winesm32.exe [2008-4-14 49664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=ma_cmidn.dll
"midi3"=ma_cmidn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\CAPCOM\\STREETFIGHTERIV\\StreetFighterIV.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [26.1.2006 16:44 25067]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [27.6.2009 14:16 64160]
R0 pe3ah4nb;DiRT Environment Driver (pe3ah4nb);c:\windows\system32\drivers\pe3ah4nb.sys [11.6.2007 12:11 64880]
R0 ps6ah4nb;DiRT Synchronization Driver (ps6ah4nb);c:\windows\system32\drivers\ps6ah4nb.sys [11.6.2007 12:10 55160]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [20.12.2006 10:11 11264]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [17.2.2010 16:05 222968]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [17.12.2006 0:52 33792]
R3 SOFTXG;YAMAHA XG WDM SoftSynthesizer;c:\windows\system32\drivers\sxgxgwdm.sys [7.1.2007 16:26 966784]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.9.2006 20:29 691696]
S2 ODBC service;ODBC service; [x]
S2 pr2ah4nb;DiRT Drivers Auto Removal (pr2ah4nb);c:\windows\system32\pr2ah4nb.exe svc --> c:\windows\system32\pr2ah4nb.exe svc [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9.3.2009 20:06 1029456]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [18.9.2006 20:34 223128]
.
Obsah adresáře 'Naplánované úlohy'
2009-09-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:58]
2010-03-08 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:19]
2008-09-12 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 11:19]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
uInternet Connection Wizard,ShellNext = hxxp://www.quick.cz/
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: imon.dll
FF - ProfilePath - c:\documents and settings\Hoodie Tonez\Data aplikací\Mozilla\Firefox\Profiles\xd04mr5c.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-08 09:47
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\imon.dll
.
Celkový čas: 2010-03-08 09:51:43
ComboFix-quarantined-files.txt 2010-03-08 08:51
ComboFix2.txt 2010-03-07 19:12
ComboFix3.txt 2009-11-13 09:01
ComboFix4.txt 2009-11-10 10:56
Před spuštěním: 1 729 523 712
Po spuštění: 1 692 905 472
- - End Of File - - 6392C6FF177FC60B529E2BB187FF2A4A