ComboFix 10-03-29.04 - Danieli 31.03.2010 20:01:06.5.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.767.470 [GMT 2:00]
Spuštěný z: c:\documents and settings\Danieli\Dokumenty\soft\Combofix\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-28 do 2010-03-31 )))))))))))))))))))))))))))))))
.
2010-03-28 08:45 . 2010-03-29 19:50 -------- d-----w- c:\program files\trend micro
2010-03-28 08:45 . 2010-03-28 08:45 -------- d-----w- C:\rsit
2010-03-27 05:37 . 2010-03-28 08:03 -------- d-----w- c:\program files\Ultimate Process Manager
2010-03-25 17:12 . 2010-03-25 17:12 -------- d-----w- c:\documents and settings\Danieli\kbpki
2010-03-25 17:11 . 2010-03-25 17:11 -------- d-----w- c:\windows\Sun
2010-03-25 17:11 . 2010-03-25 17:11 -------- d-----w- c:\program files\Common Files\Java
2010-03-25 17:10 . 2010-03-25 17:10 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-25 17:10 . 2010-03-25 17:10 -------- d-----w- c:\program files\Java
2010-03-25 16:44 . 2010-03-25 16:44 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-03-25 16:44 . 2010-03-26 15:35 -------- d-----w- c:\program files\Spyware Terminator
2010-03-21 07:27 . 2010-03-21 07:27 -------- d-----w- c:\program files\MSXML 4.0
2010-03-20 10:04 . 2010-03-20 10:04 390144 ----a-w- c:\windows\system32\CF12253.exe
2010-03-20 09:08 . 2010-03-20 09:10 -------- d-----w- c:\program files\Common Files\Ahead
2010-03-20 09:08 . 2010-03-20 09:08 -------- d-----w- c:\program files\Nero
2010-03-20 08:26 . 2010-03-20 08:31 -------- d-----w- c:\program files\Avanquest update
2010-03-20 08:26 . 2010-03-20 08:31 -------- d-----w- c:\program files\Sony Ericsson
2010-03-19 20:44 . 2008-01-09 11:28 27632 ----a-w- c:\windows\system32\drivers\seehcri.sys
2010-03-19 20:44 . 2010-03-20 08:39 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-03-19 20:44 . 2010-03-19 20:44 -------- d-----w- c:\windows\system32\LogFiles
2010-03-19 20:23 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-19 20:22 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-19 20:22 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-19 20:20 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-19 20:20 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-19 20:19 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-19 20:19 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-19 20:13 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-03-19 20:13 . 2009-12-09 10:11 2191360 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-03-19 20:13 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-03-19 20:13 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-03-19 20:13 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-03-19 20:13 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-03-19 20:13 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-03-19 20:13 . 2009-02-09 10:56 709632 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-03-19 20:13 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-03-19 20:13 . 2009-12-09 10:11 2147328 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-03-19 20:12 . 2009-12-09 10:11 2025984 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-03-19 20:10 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-19 20:10 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-19 20:09 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-03-19 20:09 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-19 20:08 . 2008-04-11 19:06 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-19 20:07 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-03-19 20:00 . 2010-01-05 09:57 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2010-03-19 20:00 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2010-03-19 20:00 . 2009-12-31 15:33 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2010-03-19 20:00 . 2010-01-05 09:58 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-19 20:00 . 2010-01-05 09:58 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-03-19 20:00 . 2010-01-05 09:57 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2010-03-19 20:00 . 2010-01-05 09:58 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-19 20:00 . 2010-01-05 09:58 6067200 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-03-19 19:59 . 2008-04-21 21:15 216576 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-03-19 19:56 . 2010-03-21 19:24 -------- d--h--w- c:\windows\$hf_mig$
2010-03-19 19:55 . 2008-10-15 16:38 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-19 19:50 . 2010-03-20 09:49 -------- d-----w- c:\program files\COMODO
2010-03-19 19:46 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-19 19:46 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-19 19:46 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-19 19:46 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-19 19:46 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-19 19:46 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-19 19:46 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-19 19:45 . 2010-03-09 11:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-19 19:45 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-19 19:45 . 2010-03-19 19:45 -------- d-----w- c:\program files\Alwil Software
2010-03-19 19:43 . 2010-03-19 19:43 -------- d-----w- c:\program files\CCleaner
2010-03-19 19:29 . 2010-03-19 19:29 -------- d-----w- c:\program files\Ad Muncher
2010-03-19 13:40 . 2010-03-19 13:40 -------- d-----w- c:\program files\Opera
2010-03-19 13:17 . 2008-04-13 23:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-03-19 13:08 . 2010-03-19 13:08 -------- d-----w- c:\windows\Profiles
2010-03-19 13:08 . 2010-03-19 13:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-19 13:07 . 2010-03-19 13:07 -------- d-----w- c:\documents and settings\Danieli\WINDOWS
2010-03-19 12:59 . 2006-02-23 11:39 11264 ----a-r- c:\windows\system32\drivers\xfilt.sys
2010-03-19 12:59 . 2006-02-23 11:38 9728 ----a-r- c:\windows\system32\drivers\videX32.sys
2010-03-19 12:58 . 2010-03-19 12:58 -------- d-----w- c:\program files\VIA
2010-03-19 12:56 . 2010-03-19 12:56 -------- d-----w- c:\windows\system32\Lang
2010-03-19 12:54 . 2006-06-16 19:56 83968 ----a-r- c:\windows\system32\drivers\Rtnicxp.sys
2010-03-19 12:54 . 2010-03-19 12:54 -------- d-----w- c:\windows\OPTIONS
2010-03-19 12:52 . 2006-07-21 08:14 86016 ------r- c:\windows\SoundMan.exe
2010-03-19 12:52 . 2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
2010-03-19 12:52 . 2006-12-16 05:10 1191936 ------r- c:\windows\RtlUpd.exe
2010-03-19 12:52 . 2006-05-04 08:35 9709568 ------r- c:\windows\RTLCPL.exe
2010-03-19 12:52 . 2006-12-21 08:26 4405248 ------r- c:\windows\system32\drivers\RtkHDAud.sys
2010-03-19 12:52 . 2006-12-19 03:12 16062464 ------r- c:\windows\RTHDCPL.exe
2010-03-19 12:52 . 2006-10-11 09:42 2157568 ------r- c:\windows\MicCal.exe
2010-03-19 12:52 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
2010-03-19 12:52 . 2006-05-04 08:26 2808832 ------r- c:\windows\alcwzrd.exe
2010-03-19 12:52 . 2010-03-19 12:52 -------- d-----w- c:\program files\Realtek
2010-03-19 12:52 . 2006-12-16 03:29 499712 ------r- c:\windows\RtlExUpd.dll
2010-03-19 12:51 . 2004-08-13 10:56 5810 ----a-r- c:\windows\system32\drivers\ASACPI.sys
2010-03-19 12:50 . 2006-10-11 11:33 10288 ----a-w- c:\windows\system32\drivers\ASUSHWIO.SYS
2010-03-19 12:49 . 2010-03-19 12:49 0 ----a-w- c:\windows\ativpsrm.bin
2010-03-19 12:46 . 2007-12-20 21:02 307200 ----a-r- c:\windows\system32\atiiiexx.dll
2010-03-19 12:46 . 2007-12-20 21:09 368640 ----a-r- c:\windows\system32\ATIDEMGX.dll
2010-03-19 12:46 . 2007-12-20 20:35 887724 ----a-r- c:\windows\system32\ativva6x.dat
2010-03-19 12:46 . 2007-12-20 20:35 3107788 ----a-r- c:\windows\system32\ativva5x.dat
2010-03-19 12:46 . 2007-12-20 20:35 3107788 ----a-r- c:\windows\system32\ativvaxx.dat
2010-03-19 12:46 . 2007-11-27 13:34 160289 ----a-r- c:\windows\system32\atiicdxx.dat
2010-03-19 12:45 . 2010-03-19 12:46 -------- d-----w- c:\program files\ATI Technologies
2010-03-19 12:45 . 2010-03-20 08:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-19 12:44 . 2010-03-19 12:51 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-19 12:42 . 2003-10-03 15:28 45056 ----a-w- c:\windows\system32\vusetup.dll
2010-03-19 12:42 . 2003-08-04 13:29 11392 ----a-w- c:\windows\system32\drivers\vulfntr.sys
2010-03-19 12:42 . 2003-08-04 13:29 6912 ----a-w- c:\windows\system32\drivers\vulfnth.sys
2010-03-19 12:42 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-03-19 12:30 . 2007-08-13 17:54 33792 -c--a-w- c:\windows\system32\dllcache\custsat.dll
2010-03-19 12:28 . 2008-04-13 21:06 144384 ------w- c:\windows\system32\drivers\hdaudbus.sys
2010-03-19 12:28 . 2008-04-13 23:10 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2010-03-19 11:30 . 2010-03-19 20:14 -------- d-----w- c:\windows\system32\cs-cz
2010-03-19 11:30 . 2010-03-19 12:33 -------- d-----w- c:\windows\system32\cs
2010-03-19 11:30 . 2010-03-19 12:33 -------- d-----w- c:\windows\l2schemas
2010-03-19 11:30 . 2010-03-19 12:33 -------- d-----w- c:\windows\system32\bits
2010-03-19 11:21 . 2009-12-14 07:10 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-03-19 11:09 . 2008-04-14 07:52 32768 ----a-w- c:\windows\system32\asr_pfu.exe
2010-03-19 11:07 . 2010-03-19 12:05 -------- d-----w- c:\windows\ServicePackFiles
2010-03-19 10:02 . 2001-08-17 21:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-21 12:58 . 2001-10-25 12:00 46196 ----a-w- c:\windows\system32\perfc005.dat
2010-03-21 12:58 . 2001-10-25 12:00 309990 ----a-w- c:\windows\system32\perfh005.dat
2010-03-19 12:35 . 2010-03-19 09:09 86327 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2010-03-19 12:35 . 2010-03-19 09:09 2740 ----a-w- c:\windows\PCHEALTH\HELPCTR\PackageStore\SkuStore.bin
2010-03-19 09:51 . 2010-03-19 09:10 8972 ----a-w- c:\windows\PCHEALTH\HELPCTR\Config\Cntstore.bin
2010-03-19 09:10 . 2010-03-19 09:10 -------- d-----w- c:\program files\microsoft frontpage
2010-03-19 09:07 . 2010-03-19 09:07 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-05 09:58 . 2010-03-19 09:44 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 09:57 . 2010-03-19 11:09 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 09:57 . 2010-03-19 09:44 17408 ----a-w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((( SnapShot_2010-03-27_20.51.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-31 16:16 . 2010-03-31 16:16 16384 c:\windows\temp\Perflib_Perfdata_46c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-03-25 3037696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-19 16062464]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"Ad Muncher"="c:\program files\Ad Muncher\AdMunch.exe" [2010-03-19 779776]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19.3.2010 21:46 162640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.3.2010 18:44 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19.3.2010 21:46 19024]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [19.3.2010 22:44 27632]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [20.3.2010 10:31 90112]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [19.3.2010 22:39 90536]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [19.3.2010 22:39 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [19.3.2010 22:39 122152]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [19.3.2010 22:39 115496]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [19.3.2010 22:39 25768]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [19.3.2010 22:39 111912]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [19.3.2010 22:39 117672]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
IE: Block frame with Ad Muncher -
http://www.admuncher.com/request_will_b ... u_ie_frame
IE: Block image with Ad Muncher -
http://www.admuncher.com/request_will_b ... u_ie_image
IE: Block link with Ad Muncher -
http://www.admuncher.com/request_will_b ... nu_ie_link
IE: Don't filter page with Ad Muncher -
http://www.admuncher.com/request_will_b ... ie_exclude
IE: Report page to the Ad Muncher developers -
http://www.admuncher.com/request_will_b ... _ie_report
TCP: {AE6A23A8-E659-40CE-9090-445CED41B590} = 62.129.50.20,85.135.32.100
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-31 20:05
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(596)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2868)
c:\program files\Ad Muncher\AM30400.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-31 20:07:54
ComboFix-quarantined-files.txt 2010-03-31 18:07
ComboFix2.txt 2010-03-27 20:55
ComboFix3.txt 2010-03-20 10:12
ComboFix4.txt 2010-03-20 07:52
ComboFix5.txt 2010-03-31 17:59
Před spuštěním: Volných bajtů: 29 128 409 088
Po spuštění: Volných bajtů: 30 183 694 336
- - End Of File - - A1206A3FAF3BD28F70B10ADF6B6AA559