Zapomnel sem napsat ze mi vse funguje jako predtim. Jeste pro jistotu combofix...
ComboFix 08-11-06.01 - uživatel 2008-11-07 16:06:05.5 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.241 [GMT 1:00]
Spuštěný z: c:\documents and settings\uživatel\Plocha\ComboFix.exe
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\uživatel\Data aplikací\inst.exe
c:\recycled\Recycled
c:\windows\jestertb.dll
c:\windows\system32\MSINET.oca
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GRANDE48
((((((((((((((((((((((((( Soubory vytvořené od 2008-10-07 do 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-04 21:33 . 2008-11-04 21:33 393,414 --a------ c:\windows\system32\prfh0405.dat
2008-11-04 21:33 . 2008-11-04 21:33 69,836 --a------ c:\windows\system32\prfc0405.dat
2008-10-29 20:58 . 2008-11-04 21:34 <DIR> d-------- c:\documents and settings\uživatel\Data aplikací\uTorrent
2008-10-17 19:45 . 2008-10-19 18:43 <DIR> d-------- c:\program files\BitComet
2008-10-11 09:30 . 2008-10-11 09:30 <DIR> d-------- c:\documents and settings\uživatel\Data aplikací\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 20:23 --------- d-----w c:\program files\Torrents
2008-10-30 17:00 --------- d-----w c:\program files\Winamp
2008-10-29 20:39 --------- d-----w c:\program files\PeerGuardian2
2008-10-29 19:58 --------- d-----w c:\program files\uTorrent
2008-10-29 19:55 --------- d---a-w c:\documents and settings\All Users\Data aplikací\TEMP
2008-10-04 10:36 --------- d-----w c:\program files\Avast4
2008-10-03 13:07 --------- d-----w c:\program files\Azureus
2008-10-03 13:06 --------- d-----w c:\documents and settings\uživatel\Data aplikací\Azureus
2008-10-01 18:08 --------- d-----w c:\documents and settings\uživatel\Data aplikací\Vso
2008-09-11 15:09 --------- d-----w c:\documents and settings\All Users\Data aplikací\DVD Shrink
2008-09-11 15:07 --------- d-----w c:\program files\DVD Shrink
2008-09-11 13:51 --------- d-----w c:\documents and settings\uživatel\Data aplikací\dvdcss
2008-07-15 12:16 47,360 ----a-w c:\documents and settings\uživatel\Data aplikací\pcouffin.sys
2008-04-03 16:26 241 ----a-w c:\documents and settings\uživatel\SR.vbs
2008-04-03 16:26 241 ----a-w c:\documents and settings\uživatel\SR.vbs
2007-04-30 15:25 81,920 ----a-w c:\documents and settings\uživatel\Data aplikací\ezpinst.exe
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-01-20 11:29 945 --sha-w c:\windows\system32\mmf.sys
2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2007-12-17 13:43 27,648 --sh--w c:\windows\system32\Smab0.dll
2008-02-04 19:26 151,040 --sh--w c:\windows\system32\VistaUltm.dll
2008-05-10 21:16 4,868,128 --sha-w c:\windows\system32\drivers\fidbox.dat
.
------- Sigcheck -------
2005-03-14 02:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2001-10-25 13:00 327168 e7774698bb0d14b0710a9a31e209f9b6 c:\windows\$NtServicePackUninstall$\tcpip.sys
2004-08-03 22:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB893066$\tcpip.sys
2004-08-03 22:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\ServicePackFiles\i386\TCPIP.SYS
2005-03-14 01:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\SoftwareDistribution\Download\465d74f489a08daa339a96fd1eedeb4e\sp2gdr\tcpip.sys
2005-03-14 02:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\SoftwareDistribution\Download\465d74f489a08daa339a96fd1eedeb4e\sp2qfe\tcpip.sys
2008-01-24 15:21 359808 f91e8f4c501f2128d7a92f723b6d6577 c:\windows\system32\dllcache\TCPIP.SYS
2008-01-24 15:21 359808 f91e8f4c501f2128d7a92f723b6d6577 c:\windows\system32\drivers\TCPIP.SYS
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXSUPMON"="c:\windows\system32\LXSUPMON.EXE" [2002-01-28 885760]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-20 213936]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"COMODO Firewall Pro"="c:\program files\Comodo\Firewall\CPF.exe" [2008-04-21 1115728]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoAutoTrayNotify"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2005-12-20 21:57 176128 c:\progra~1\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"VIDC.I420"= i420vfw.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.divxa32"= divxa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^GPRSpeed Plus Client.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\GPRSpeed Plus Client.lnk
backup=c:\windows\pss\GPRSpeed Plus Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^uživatel^Nabídka Start^Programy^Po spuštění^RollerCoaster Tycoon 3 Registration.lnk]
path=c:\documents and settings\uživatel\Nabídka Start\Programy\Po spuštění\RollerCoaster Tycoon 3 Registration.lnk
backup=c:\windows\pss\RollerCoaster Tycoon 3 Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^uživatel^Nabídka Start^Programy^Po spuštění^Ubisoft register.lnk]
path=c:\documents and settings\uživatel\Nabídka Start\Programy\Po spuštění\Ubisoft register.lnk
backup=c:\windows\pss\Ubisoft register.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2008-07-19 15:38 78008 c:\program files\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-17 14:49 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-03 23:29 165784 c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP]
--a------ 2006-03-22 23:13 1591808 c:\program files\FreeRAM XP Pro\FreeRAM XP Pro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-09 17:53 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2004-01-28 22:42 565248 c:\windows\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2004-09-16 13:39 69632 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32krn"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"c:\\Program Files\\FirefoxPortable\\FirefoxPortable.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Hry\\Worms Armageddon\\wa.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\SopCast\\sopvod.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"44724:TCP"= 44724:TCP:pan port
"61541:TCP"= 61541:TCP:@xpsp2res.dll,-22004
"23892:TCP"= 23892:TCP:BitComet 23892 TCP
"23892:UDP"= 23892:UDP:BitComet 23892 UDP
"57333:TCP"= 57333:TCP:BitComet 57333 TCP
"57333:UDP"= 57333:UDP:BitComet 57333 UDP
"17222:TCP"= 17222:TCP:@xpsp2res.dll,-22004
"21285:TCP"= 21285:TCP:@xpsp2res.dll,-22004
"18784:TCP"= 18784:TCP:@xpsp2res.dll,-22004
"11935:TCP"= 11935:TCP:@xpsp2res.dll,-22004
"5307:TCP"= 5307:TCP:@xpsp2res.dll,-22004
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 LicCtrlService;LicCtrl Service;rundll32.exe c:\windows\mmfs.dll,Service [ ]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2008-05-08 2368]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\DRIVERS\psched.sys [2004-08-03 69120]
R3 usbhub;Ovladač standardního rozbočovače USB;c:\windows\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [ ]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);c:\windows\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);c:\windows\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
S3 aswArKrn;aswArKrn;c:\docume~1\UIVATE~1\LOCALS~1\Temp\aswArKrn.sys [ ]
S3 DrvFltIp;DrvFltIp;c:\documents and settings\uživatel\Local Settings\TEMP\DrvFltIp [ ]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [ ]
S3 usb2vcom;USB Data Cable;c:\windows\system32\DRIVERS\usb2vcom.sys [2005-08-06 28704]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB;c:\windows\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f72c2d0d-4fbc-11db-8aa0-0011098da354}]
\Shell\AutoRun\command - H:\autorun.exe
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
HKLM-Explorer_Run-mshgm - c:\windows\system32\ctlaicmbc.sys
MSConfigStartUp-AVG7_CC - c:\progra~1\Grisoft\AVG Free\avgcc.exe
MSConfigStartUp-InCD - c:\program files\Nero\Nero 7\InCD\InCD.exe
MSConfigStartUp-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\qttask.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-SecurDisc - c:\program files\Nero\Nero 7\InCD\NBHGui.exe
MSConfigStartUp-Trickler - c:\program files\divx\divx pro codec\gain_trickler_3202.exe
.
------- Doplňkový sken -------
.
FireFox -: Profile - c:\documents and settings\uživatel\Data aplikací\Mozilla\Firefox\Profiles\whjwj3pz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
http://www.google.com" onclick="window.open(this.href);return false;
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net" onclick="window.open(this.href);return false;
Rootkit scan 2008-11-07 16:07:46
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\ASFWHide]
"ImagePath"="\??\c:\documents and settings\uživatel\Local Settings\TEMP\ASFWHide"
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\DrvFltIp]
"ImagePath"="\??\c:\documents and settings\uživatel\Local Settings\TEMP\DrvFltIp"
.
Celkový čas: 2008-11-07 16:08:36
ComboFix-quarantined-files.txt 2008-11-07 15:08:32
Před spuštěním: Volných bajtů: 12,539,625,472
Po spuštění: Volných bajtů: 12,522,827,776
218