ComboFix 10-04-10.02 - Hruškovi 11.04.2010 15:28:45.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.607 [GMT 2:00]
Spuštěný z: c:\documents and settings\Hruškovi.HRU-B98B4D53D62\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Hruškovi.HRU-B98B4D53D62\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100411-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows.0\System32\Drivers\eylhgqno.sys"
"c:\windows.0\System32\Drivers\otigsizt.sys"
"c:\windows.0\System32\Drivers\xldzdmvz.sys"
"e:\ntglm7x.sys"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SETUPNTGLM7X
-------\Service_eylhgqno
-------\Service_otigsizt
-------\Service_SetupNTGLM7X
-------\Service_xldzdmvz
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-11 do 2010-04-11 )))))))))))))))))))))))))))))))
.
2010-04-10 20:39 . 2010-03-29 22:46 38224 ----a-w- c:\windows.0\system32\drivers\mbamswissarmy.sys
2010-04-10 20:39 . 2010-04-10 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-10 20:39 . 2010-03-29 22:45 20824 ----a-w- c:\windows.0\system32\drivers\mbam.sys
2010-04-10 19:52 . 2010-04-11 12:45 -------- d-----w- C:\UsbFix
2010-04-10 19:13 . 2010-04-10 19:14 -------- d-----w- C:\rsit
2010-04-10 19:13 . 2010-04-10 19:13 -------- d-----w- c:\program files\trend micro
2010-04-07 20:57 . 2010-04-07 20:57 -------- d-----w- c:\program files\Traction Software
2010-04-03 15:50 . 2010-04-03 15:50 151552 --sh--r- c:\windows.0\Windows3.exe
2010-03-21 18:22 . 2010-02-12 10:03 293376 ------w- c:\windows.0\system32\browserchoice.exe
2010-03-14 20:49 . 2010-03-14 20:49 -------- d-----w- c:\program files\Windows Media Connect 2
2010-03-14 20:48 . 2010-03-14 21:28 -------- d-----w- c:\windows.0\system32\drivers\UMDF
2010-03-14 20:48 . 2010-03-14 20:48 -------- d-----w- c:\windows.0\system32\LogFiles
2010-03-14 20:33 . 2010-03-14 20:42 -------- d-----w- c:\program files\Common Files\ArcSoft
2010-03-14 20:31 . 2010-03-14 20:31 -------- d-----w- c:\program files\Philips
2010-03-14 20:31 . 2010-03-14 20:46 -------- d-----w- C:\temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 19:40 . 2006-03-02 11:00 83652 ----a-w- c:\windows.0\system32\perfc005.dat
2010-04-10 19:40 . 2006-03-02 11:00 440316 ----a-w- c:\windows.0\system32\perfh005.dat
2010-04-07 20:57 . 2004-12-30 11:23 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-06 12:06 . 2010-03-06 11:23 104283 ----a-w- c:\windows.0\hpoins04.dat
2010-02-27 20:17 . 2010-02-27 20:16 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-02-27 20:17 . 2010-02-27 20:17 691696 ----a-w- c:\windows.0\system32\drivers\sptd.sys
2010-02-27 20:01 . 2010-02-27 20:01 108144 ----a-w- c:\windows.0\system32\CmdLineExt.dll
2010-02-27 19:06 . 2007-11-16 18:19 -------- d-----w- c:\program files\Google
2010-02-27 18:58 . 2010-02-27 18:58 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-02-27 18:58 . 2010-02-27 18:58 -------- d-----w- c:\program files\USB TV
2010-02-27 18:09 . 2004-12-30 12:34 -------- d-----w- c:\program files\Common Files\ACD Systems
2010-02-27 18:02 . 2010-02-27 18:02 -------- d-----w- c:\program files\Common Files\STORMWARE Shared
2010-02-27 17:51 . 2009-09-28 18:06 -------- d-----w- c:\program files\Winamp
2010-02-27 17:44 . 2009-09-28 17:25 -------- d-----w- c:\program files\IrfanView
2010-02-27 17:18 . 2010-02-27 17:18 -------- d-----w- c:\program files\Vimicro
2010-02-27 16:40 . 2010-02-27 16:40 -------- d-----w- c:\program files\Alwil Software
2010-02-27 16:36 . 2004-12-30 12:34 -------- d-----w- c:\program files\ACD Systems
2010-02-27 16:04 . 2010-02-27 15:52 -------- d-----w- c:\program files\Your Uninstaller
2010-02-25 06:18 . 2006-03-02 11:00 916480 ------w- c:\windows.0\system32\wininet.dll
2010-02-04 09:01 . 2010-02-27 19:40 74072 ----a-w- c:\windows.0\system32\XAPOFX1_4.dll
2010-02-04 09:01 . 2010-02-27 19:40 528216 ----a-w- c:\windows.0\system32\XAudio2_6.dll
2010-02-04 09:01 . 2010-02-27 19:40 238936 ----a-w- c:\windows.0\system32\xactengine3_6.dll
2010-02-04 09:01 . 2010-02-27 19:40 22360 ----a-w- c:\windows.0\system32\X3DAudio1_7.dll
2005-10-01 20:37 . 2005-10-01 20:37 21893536 ----a-w- c:\program files\AdbeRdr70_cze_full.exe
2005-10-01 19:54 . 2005-10-01 19:54 12139928 ----a-w- c:\program files\AdbeRdr60_cze.exe
.
------- Sigcheck -------
[-] 2008-04-14 . 56A6034E7764E23D9114223EB3523925 . 1571840 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\sfcfiles.dll
[-] 2007-11-15 . 6C19977562424D6FF61CFCA59B6B67D6 . 1548288 . . [5.1.2600.2180] . . c:\windows.0\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-04-11_07.53.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-11 13:46 . 2010-04-11 13:46 16384 c:\windows.0\Temp\Perflib_Perfdata_4e4.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Ptipbmf"="ptipbmf.dll" [2003-06-05 118784]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2009-10-04 589824]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"BigDog305"="c:\windows.0\VM305_STI.EXE" [2007-04-09 57344]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users.WINDOWS.0\Nabˇdka Start\Programy\Po spuçtŘnˇ\
BDARemote.lnk - c:\program files\USB TV\EM28XX\BDARemote.exe [2010-2-27 81997]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
Philips GoGear VIBE Device Manager.lnk - c:\program files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe [2010-3-14 1701224]
Rychl‚ spuçtŘnˇ aplikace HP Image Zone.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-29 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2006-03-02 11:00 15360 ------w- c:\windows.0\system32\ctfmon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
R0 sptd;sptd;c:\windows.0\system32\drivers\sptd.sys [27.2.2010 22:17 691696]
R1 aswSP;avast! Self Protection;c:\windows.0\system32\drivers\aswSP.sys [27.2.2010 18:41 114768]
R2 aswFsBlk;aswFsBlk;c:\windows.0\system32\drivers\aswFsBlk.sys [27.2.2010 18:41 20560]
S3 ZSMC0305;A4 TECH PC Camera V;c:\windows.0\system32\drivers\usbVM305.sys [27.2.2010 19:19 391688]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://
www.google.com/ie
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Hruškovi.HRU-B98B4D53D62\Data aplikací\Mozilla\Firefox\Profiles\rio1y4o0.default\
FF - prefs.js: browser.search.selectedEngine - WebHledani
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://
www.webhledani.cz/results.aspx?i=42&tp=ab&q=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-11 15:47
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog305 = c:\windows.0\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)?????????????????0?????????@??????????????
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8656D1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7630fc3
\Driver\ACPI -> ACPI.sys @ 0xf73a8cb8
\Driver\atapi -> 0x8656d1f8
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf720ebc3
PacketIndicateHandler -> NDIS.sys @ 0xf721ab21
SendHandler -> NDIS.sys @ 0xf720ed33
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1600)
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows.0\system32\msi.dll
c:\windows.0\system32\webcheck.dll
c:\windows.0\system32\WPDShServiceObj.dll
c:\windows.0\system32\PortableDeviceTypes.dll
c:\windows.0\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows.0\SOUNDMAN.EXE
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Celkový čas: 2010-04-11 15:53:43 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-04-11 13:53
ComboFix2.txt 2010-04-11 12:42
ComboFix3.txt 2010-04-11 07:58
Před spuštěním: 2 556 342 272
Po spuštění: 2 410 708 992
- - End Of File - - 580EFCF2A54D82BF90DD3F26701F7E0F