ComboFix 08-10-27.01 - lacko 2008-10-27 20:59:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.703 [GMT 1:00]
Použité ovládací přepínače :: C:\Documents and Settings\lacko\Plocha\CFScript.txt.txt
* Vytvořen nový Bod Obnovení
* Resident AV is active
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
FILE ::
C:\WINDOWS\system32\ddcDvwxu.dll
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Data aplikací\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\cbXPGWqQ.dll
C:\WINDOWS\system32\ddcDvwxu.dll
----- BITS: Možné infikované stránky -----
hxxp://
www.thematurevideo.net" onclick="window.open(this.href);return false;
.
((((((((((((((((((((((((( Soubory vytvořené od 2008-09-27 do 2008-10-27 )))))))))))))))))))))))))))))))
.
2009-04-29 16:50 . 2008-05-04 22:20 <DIR> d-------- C:\Program Files\HD Tune Pro
2008-10-27 18:57 . 2008-10-27 18:57 398,802 --a------ C:\WINDOWS\system32\prfh0405.dat
2008-10-27 18:57 . 2008-10-27 18:57 73,440 --a------ C:\WINDOWS\system32\prfc0405.dat
2008-10-27 14:08 . 2008-04-19 12:41 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-10-27 14:08 . 2008-04-19 12:34 <DIR> d--h----- C:\Documents and Settings\Administrator\Šablony
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-10-27 14:08 . 2008-04-19 14:29 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-10-27 14:08 . 2008-10-27 14:08 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-27 14:06 . 2008-10-27 14:06 28,061 --a------ C:\WINDOWS\system32\ddcDvwxu.zip
2008-10-24 16:31 . 2008-04-28 14:53 805,400 -ra------ C:\WINDOWS\system32\tmp2F2.tmp
2008-10-24 15:10 . 2008-10-24 15:10 0 --a------ C:\as.dat
2008-10-23 14:18 . 2008-10-23 14:18 <DIR> d-------- C:\Program Files\Deep Silver
2008-10-21 13:20 . 2008-10-21 13:26 <DIR> d-------- C:\WINDOWS\NKCCDViewerSetting
2008-10-18 18:21 . 2008-10-18 20:59 <DIR> dr------- C:\AUTOŠKOLA
2008-10-17 17:21 . 2008-10-17 17:21 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Last.fm
2008-10-17 17:18 . 2008-10-17 17:18 <DIR> d-------- C:\Program Files\Last.fm
2008-10-07 14:04 . 2008-10-14 15:59 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\TrackMania
2008-10-07 13:58 . 2008-10-07 16:33 <DIR> d-------- C:\Program Files\TmNationsForever
2008-10-04 14:51 . 2008-10-04 14:51 <DIR> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 20:06 --------- d---a-w C:\Documents and Settings\All Users\Data aplikací\TEMP
2008-10-27 19:40 --------- d-----w C:\Program Files\Mozilla Firefox3
2008-10-27 19:32 38,498 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-10-27 19:14 --------- d-----w C:\Documents and Settings\lacko\Data aplikací\uTorrent
2008-10-26 15:53 --------- d-----w C:\Program Files\AIMP2
2008-10-23 13:30 279,712 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-10-23 13:30 25,888 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-10-19 15:42 --------- d-----w C:\Documents and Settings\lacko\Data aplikací\dvdcss
2008-10-18 16:28 --------- d-----w C:\Program Files\Flash FLV to Video Audio Converter
2008-09-24 12:47 --------- d-----w C:\Program Files\Gothic III
2008-09-24 12:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-14 23:45 --------- d-----w C:\Documents and Settings\lacko\Data aplikací\LimeWire
2008-09-09 20:45 --------- d-----w C:\Program Files\SpeedFan
2008-09-09 13:45 --------- d-----w C:\Program Files\Euro Truck Simulator
2008-09-09 13:38 --------- d-----w C:\Program Files\18 Wheels of Steel Haulin
2008-09-09 13:32 --------- d-----w C:\Program Files\phenomedia
2008-09-08 14:44 --------- d-----w C:\Program Files\GameShadow
2008-09-08 14:36 --------- d-----w C:\Program Files\Eidos
2008-08-31 16:56 --------- d-----w C:\Program Files\GameTop.com
2008-08-31 16:12 167,317 ----a-w C:\WINDOWS\San Andreas Tools Uninstaller.exe
2008-08-31 16:12 --------- d-----w C:\Program Files\San Andreas Tools
2008-08-30 15:55 --------- d-----w C:\Program Files\Sanny Builder 3
2008-08-28 17:45 --------- d-----w C:\Program Files\Common Files\Futuremark Shared
2008-08-11 14:21 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-08-06 09:21 45,056 ----a-w C:\WINDOWS\system32\UTSCSI.EXE
.
------- Sigcheck -------
2005-09-03 00:55 661504 5e7263b2ee473b8edbab9a7d578018f0 C:\WINDOWS\$hf_mig$\KB896688\SP2QFE\wininet.dll
2006-01-09 19:04 663040 fd4554fa8c83594a63325d2d827c3712 C:\WINDOWS\$hf_mig$\KB912945\SP2QFE\wininet.dll
2006-01-09 19:08 659456 1b28e6c7a9034a7e798d79d035de3de1 C:\WINDOWS\$NtUninstallKB912945$\wininet.dll
2006-01-09 19:04 663040 fd4554fa8c83594a63325d2d827c3712 C:\WINDOWS\$NtUninstallKB918899$\wininet.dll
2006-06-23 12:26 1225216 a886e193e41188dca0dacc3aa2960c17 C:\WINDOWS\system32\wininet.dll
2006-06-23 12:26 1225216 a886e193e41188dca0dacc3aa2960c17 C:\WINDOWS\system32\dllcache\wininet.dll
2005-04-07 19:48 1881088 6df495956bdab96dbec93a2135174910 C:\WINDOWS\explorer.exe
2004-08-18 13:00 1032704 53114d57ab73a406ac7f602227781a99 C:\WINDOWS\$NtUninstallKB884883$\explorer.exe
2005-04-07 19:48 1881088 6df495956bdab96dbec93a2135174910 C:\WINDOWS\system32\dllcache\explorer.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 15360]
"Fraps"="C:\FRAPS\FRAPS.EXE" [2008-01-14 3182248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AMD_Display"="C:\Program Files\AMD\AMD Power Monitor\AMD_PwrMon.exe" [2007-12-17 1445888]
"WheelMouse"="C:\Program Files\A4Tech\Mouse\Amoumain.exe" [2006-12-26 196608]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
"MusicToQIP"="C:\qip8050\MusicToQIP.exe" [2007-04-10 359936]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-19 949376]
"RivaTuner"="C:\Program Files\RivaTuner v2.08\RivaTuner.exe" [2008-03-10 2691072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 C:\WINDOWS\SOUNDMAN.EXE]
"nwiz"="nwiz.exe" [2007-12-05 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
C:\Documents and Settings\lacko\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Core Temp.lnk - D:\Core Temp.exe [2008-04-19 223760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
[HKLM\~\startupfolder\C:^Documents and Settings^lacko^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^lacko^Nabídka Start^Programy^Po spuštění^RivaTuner.lnk]
backup=C:\WINDOWS\pss\RivaTuner.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 00:41 8523776 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 12:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
-ra------ 2006-01-20 12:34 544768 C:\WINDOWS\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrA"=2 (0x2)
"NMIndexingService"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"UxTuneUp"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"Crypkey License"=2 (0x2)
"bgsvcgen"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"OM_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"OM_Monitor"=C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
R1 atitray;atitray;C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [2008-04-14 17952]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2006-07-18 284184]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2006-07-18 91672]
R1 SysTool;SysTool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\SysTool.sys [2006-11-10 24064]
R1 VBoxDrv;VirtualBox Service;C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2008-05-31 55520]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2008-05-31 42048]
R3 ALSysIO;ALSysIO;C:\DOCUME~1\lacko\LOCALS~1\Temp\ALSysIO.sys [ ]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-18 69120]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-18 31616]
R3 usbhub;Ovladač standardního rozbočovače USB;C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-09-01 59264]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB;C:\WINDOWS\system32\DRIVERS\usbohci.sys [2006-04-19 17152]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-18 26496]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2007-10-16 22640]
S3 RTCore32;RTCore32;D:\RightMark Memory Analyzer\RTCore32.sys [2005-05-25 4608]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-05-01 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-05-01 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-05-01 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-05-01 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-05-01 18704]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-05-01 86560]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-05-01 90800]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]
S4 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-29 306432]
S4 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-18 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40fd7ca8-810e-11dd-a6a1-0015f2f2be15}]
\Shell\AutoRun\command - setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f63e4c5-3253-11dd-a64b-0015f2f2be15}]
\Shell\Auto\command - activexdebugger32.exe f
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f
\Shell\explore\Command - activexdebugger32.exe f
\Shell\open\Command - activexdebugger32.exe f
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa717787-268c-11dd-a632-0015f2f2be15}]
\Shell\AutoRun\command - M:\USBNB.exe
*Newly Created Service* - ALSYSIO
.
Obsah adresáře 'Naplánované úlohy'
2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2007-12-28 13:49]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
BHO-{DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ddcDvwxu.dll
ShellExecuteHooks-{DD153FDB-E2FB-40D2-8E36-F21C36B51DAD} - C:\WINDOWS\system32\ddcDvwxu.dll
Notify-ddcDvwxu - ddcDvwxu.dll
MSConfigStartUp-Google Update - C:\Documents and Settings\lacko\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net" onclick="window.open(this.href);return false;
Rootkit scan 2008-10-27 21:06:26
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
PROCES: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2008-10-27 21:09:56 - počítač byl restartován
ComboFix-quarantined-files.txt 2008-10-27 20:09:49
Před spuštěním: Volných bajtů: 72,069,988,352
Po spuštění: Volných bajtů: 72,124,907,520
240