biba5 píše:
fzamrza vo vsetkych verziach kedze sa aktualizuje ,stiahla som si mozillu a je to zatial dobre DIK ZA POMOC
,momentalne mi avast nahlasilrootkit pra o kontrolu loguComboFix 08-12-15.01 - pici novakova 2008-12-16 1:02:04.1 - NTFSx86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.1014.630 [GMT 1:00]
Running from: c:\documents and settings\pici novakova\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.
2008-12-14 20:47 . 2008-12-14 20:48 <DIR> d-------- c:\program files\Winamp
2008-12-14 20:47 . 2008-12-14 20:55 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Winamp
2008-12-14 20:47 . 2007-03-08 00:51 129,784 --------- c:\windows\system32\pxafs.dll
2008-12-14 20:47 . 2007-03-08 00:51 43,528 --------- c:\windows\system32\drivers\PxHelp20.sys
2008-12-14 20:47 . 2007-03-08 00:51 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-12-14 20:47 . 2007-03-08 00:51 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-12-14 15:36 . 2008-12-14 15:36 <DIR> d-------- c:\windows\system32\logs
2008-12-14 15:35 . 2008-12-14 15:47 <DIR> d-------- c:\program files\BitDefender
2008-12-14 15:35 . 2008-12-14 15:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\BitDefender
2008-12-14 15:34 . 2008-12-14 15:34 <DIR> d-------- c:\windows\system32\URTTEMP
2008-12-14 15:31 . 2008-12-14 15:47 <DIR> d-------- c:\program files\Common Files\BitDefender
2008-12-14 14:56 . 2008-12-14 14:56 <DIR> d-------- c:\program files\Google
2008-12-14 14:56 . 2008-12-15 16:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2008-12-13 08:07 . 2008-12-13 08:07 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Pointstone
2008-12-13 05:53 . 2008-12-13 08:14 <DIR> d-------- c:\program files\Pointstone
2008-12-13 05:53 . 2008-12-13 10:52 <DIR> d-------- c:\program files\Common Files\Pointstone
2008-12-10 23:17 . 2008-12-11 06:20 <DIR> d-------- c:\program files\Total Video Player
2008-12-10 21:21 . 2008-12-10 21:21 43 --a------ c:\windows\system32\blue.SITENAME
2008-12-10 21:20 . 2008-12-10 21:22 455 --a------ c:\windows\VFO.VST
2008-12-10 21:14 . 2004-07-02 16:28 84,992 --a------ c:\windows\system32\ATL70.DLL
2008-12-10 21:14 . 2008-12-11 06:23 1,196 --a------ c:\windows\VFO.INI
2008-12-10 21:13 . 2008-12-10 21:13 <DIR> d-------- c:\windows\Downloaded Installations
2008-12-10 21:13 . 2003-11-21 16:48 65,536 --a------ c:\windows\system32\MFC71DEU.DLL
2008-12-10 21:13 . 2003-11-21 16:48 61,440 --a------ c:\windows\system32\MFC71ITA.DLL
2008-12-10 21:13 . 2003-11-21 16:48 61,440 --a------ c:\windows\system32\MFC71FRA.DLL
2008-12-10 21:13 . 2003-11-21 16:48 61,440 --a------ c:\windows\system32\MFC71ESP.DLL
2008-12-10 21:13 . 2003-11-21 16:48 57,344 --a------ c:\windows\system32\MFC71ENU.DLL
2008-12-10 21:13 . 2003-11-21 16:48 49,152 --a------ c:\windows\system32\MFC71KOR.DLL
2008-12-10 21:13 . 2003-11-21 16:48 49,152 --a------ c:\windows\system32\MFC71JPN.DLL
2008-12-10 21:13 . 2003-11-21 16:48 45,056 --a------ c:\windows\system32\MFC71CHT.DLL
2008-12-10 21:13 . 2003-11-21 16:48 40,960 --a------ c:\windows\system32\MFC71CHS.DLL
2008-12-10 21:12 . 2008-12-10 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Pinnacle Studio
2008-12-10 21:11 . 2008-12-10 21:15 <DIR> d-------- c:\program files\Pinnacle
2008-12-10 21:11 . 2008-12-10 21:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\Pinnacle
2008-12-10 20:54 . 2005-02-09 11:59 14,165 --a------ c:\windows\system32\drivers\Pclepci.sys
2008-12-09 23:30 . 2008-10-23 13:36 286,720 -----c--- c:\windows\system32\dllcache\gdi32.dll
2008-12-09 20:27 . 2008-12-15 20:16 69 --a------ c:\windows\NeroDigital.ini
2008-12-09 17:33 . 2008-12-09 17:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Ahead
2008-12-09 17:33 . 2001-03-08 18:30 24,064 --------- c:\windows\system32\msxml3a.dll
2008-12-09 17:11 . 2008-12-09 17:11 <DIR> d-------- c:\documents and settings\pici novakova\WINDOWS
2008-12-09 17:11 . 1998-02-06 22:37 299,520 --a------ c:\windows\uninst.exe
2008-12-09 16:00 . 2008-12-09 16:00 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Media Player Classic
2008-12-09 15:53 . 2008-12-09 17:46 <DIR> d-------- c:\program files\AviSynth 2.5
2008-12-09 15:53 . 2004-03-09 16:45 152,848 --a------ c:\windows\system32\Comdlg32.ocx
2008-12-09 15:34 . 2008-12-09 15:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\CyberLink
2008-12-09 15:30 . 2008-12-09 15:48 <DIR> d-------- c:\program files\CyberLink
2008-12-07 19:51 . 2008-12-07 19:51 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Thinstall
2008-12-06 16:02 . 2008-12-06 16:02 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\URSoft
2008-12-05 21:05 . 2008-12-15 20:39 <DIR> d-------- C:\games
2008-12-03 16:59 . 2008-12-05 20:05 <DIR> d-------- c:\program files\Alcohol Soft
2008-12-03 16:59 . 2005-04-25 10:43 159,616 --a------ c:\windows\system32\drivers\Vax347b.sys
2008-12-03 16:59 . 2004-04-30 09:33 5,248 --a------ c:\windows\system32\drivers\Vax347s.sys
2008-12-03 16:58 . 2005-07-05 16:47 40,448 --a------ c:\documents and settings\pici novakova\trial_setup.exe
2008-12-03 10:58 . 2008-12-03 10:58 <DIR> d-------- c:\program files\Enlight
2008-12-02 11:26 . 2008-12-02 11:26 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\DAEMON Tools
2008-12-02 11:26 . 2008-12-02 11:26 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-02 11:21 . 2008-12-15 20:28 <DIR> d-------- C:\totalcmd
2008-12-02 11:21 . 2008-12-15 20:41 930 --a------ c:\windows\wincmd.ini
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\UC.PIF
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\RAR.PIF
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\PKZIP.PIF
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\PKUNZIP.PIF
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\NOCLOSE.PIF
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\LHA.PIF
2008-12-02 11:21 . 2008-08-08 07:04 545 --a------ c:\windows\ARJ.PIF
2008-12-01 17:57 . 2008-12-01 17:57 <DIR> d-------- c:\program files\Trymedia
2008-11-29 21:31 . 2008-11-29 21:31 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-29 20:35 . 2008-11-29 20:35 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Gaijin Ent
2008-11-29 10:44 . 2008-11-29 10:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Astar Games
2008-11-29 08:02 . 2008-11-30 16:00 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Oberon Games
2008-11-29 08:02 . 2008-11-30 16:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Oberon Games
2008-11-28 19:53 . 2008-11-28 19:53 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Zylom
2008-11-28 19:53 . 2008-11-28 19:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Zylom
2008-11-28 19:53 . 2008-12-05 16:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\GameHouse
2008-11-28 18:07 . 2008-11-28 18:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sandlot Games
2008-11-28 18:06 . 2008-11-28 18:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\NeoEdge Networks
2008-11-28 17:34 . 2008-11-28 17:45 <DIR> d-------- c:\program files\Shockwave.com
2008-11-22 12:15 . 2008-11-22 12:15 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Teleca
2008-11-22 12:14 . 2008-11-22 12:14 <DIR> d-------- c:\documents and settings\pici novakova\Application Data\Sony Ericsson
2008-11-22 12:09 . 2008-11-22 12:27 <DIR> d-------- c:\program files\Common Files\Teleca Shared
2008-11-22 12:09 . 2008-12-11 06:24 <DIR> d-------- c:\program files\Common Files\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 18:53 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-14 15:02 --------- d-----w c:\program files\Opera
2008-12-14 14:17 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-13 07:13 --------- d-----w c:\documents and settings\pici novakova\Application Data\Check Identical Files
2008-12-11 05:23 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-10 02:10 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-09 16:48 --------- d-----w c:\program files\Ahead
2008-11-30 16:10 --------- d-----w c:\documents and settings\pici novakova\Application Data\PlayFirst
2008-11-30 16:10 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-11-29 20:31 --------- d-----w c:\program files\Lavasoft
2008-11-29 17:44 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-11 14:46 --------- d-----w c:\documents and settings\pici novakova\Application Data\Skype
2008-11-11 14:31 --------- d-----w c:\documents and settings\pici novakova\Application Data\skypePM
2008-10-30 16:36 --------- d-----w c:\documents and settings\pici novakova\Application Data\Go-Go Gourmet Chef of the Year
2008-10-29 10:44 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-04-16 09:41 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-20 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-20 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-20 138008]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 c:\windows\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1136:UDP"= 1136:UDP:Windows Media Format SDK (Opera.exe)
"1137:UDP"= 1137:UDP:Windows Media Format SDK (Opera.exe)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-03-30 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-03-30 20560]
R2 BcmSqlStartupSvc;Spúšacia služba produktu Business Contact Manager SQL Server;"c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 30312]
R3 PSched;QoS Packet Scheduler;c:\windows\system32\DRIVERS\psched.sys [2006-02-28 69120]
S3 CnxEtP;Conexant AccessRunner USB ADSL Adapter Filter Driver;c:\windows\system32\DRIVERS\CnxEtP.sys [2008-02-17 131072]
S3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\DRIVERS\CnxEtU.sys [2008-02-17 614272]
S3 CnxTgNP;Conexant AccessRunner ADSL WAN PPPoE Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNP.sys [2008-02-17 60416]
S3 FXDrv32;FXDrv32;\??\D:\FXDrv32.sys []
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [2008-02-26 29183504]
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.daemon-search.com/startpage
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\pici novakova\Application Data\Mozilla\Firefox\Profiles\31ln2572.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1439.6872\npCIDetect13.dll
FF - plugin: c:\program files\TV JOJ Media Player\np_JOJ_netscape_player.dll
FF - plugin: c:\program files\TV JOJ Media Player\npplugin_netscape.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-16 01:03:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-16 1:05:17
ComboFix-quarantined-files.txt 2008-12-16 00:04:38
Pre-Run: 31 709 184 000 bytes free
Post-Run: 20 adresárov, 31,700,570,112 voľných bajtov
192 --- E O F --- 2008-12-15 20:10:48