Avira AntiVir neustale hlasi napadeni C:\windows\system32\kernel32.dll
trojan TR/Patched.BQ
(nikde jsem ho nenasel)....predem diky
ComboFix 08-03-18.1 - Administrator 2008-03-19 22:16:14.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.0.1250.1.1029.18.681 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\Dvbpws.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-19 to 2008-03-19 )))))))))))))))))))))))))))))))
.
2008-03-11 19:24 . 2001-12-19 15:47 49,152 --------- C:\WINDOWS\system32\TempDel.EXE
2008-03-11 19:24 . 2002-06-03 23:01 8,734 --a------ C:\WINDOWS\system32\WFSch.ICO
2008-03-11 19:21 . 2001-09-17 10:29 286,720 --a------ C:\WINDOWS\system32\msh263.drv
2008-03-11 19:21 . 2001-09-17 10:29 50,176 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-03-11 19:21 . 2001-09-17 10:28 45,568 --a------ C:\WINDOWS\system32\iyuv_32.dll
2008-03-11 19:21 . 2001-09-17 10:28 8,192 --a------ C:\WINDOWS\system32\tsbyuv.dll
2008-03-11 19:19 . 2008-03-11 19:19 <DIR> d-------- C:\WINDOWS\system32\DX9
2008-03-11 19:19 . 2004-03-12 12:34 197,908 --a------ C:\WINDOWS\system32\drivers\wf88vcap.sys
2008-03-11 19:19 . 2004-03-12 12:34 34,422 --a------ C:\WINDOWS\system32\drivers\wf88tune.sys
2008-03-11 19:19 . 2004-03-12 12:34 10,405 --a------ C:\WINDOWS\system32\drivers\WF88XBAR.sys
2008-03-11 19:19 . 2002-06-03 22:52 2,238 --a------ C:\WINDOWS\system32\WFDRV.ico
2008-03-11 18:19 . 2004-12-23 17:27 27,392 --a------ C:\WINDOWS\system32\drivers\ULCDRHlp.sys
2008-03-11 18:14 . 2001-08-18 06:24 135,040 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-03-11 18:14 . 2001-08-17 22:01 57,344 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-03-10 23:28 . 2008-03-10 23:28 <DIR> d-------- C:\Program Files\Common Files\NSV
2008-03-10 20:11 . 2001-08-17 21:52 33,664 --a------ C:\WINDOWS\system32\drivers\disk.sys
2008-03-10 16:33 . 2007-01-19 12:49 393,088 --a------ C:\WINDOWS\system32\drivers\wfeaglxt.sys
2008-03-07 16:12 . 2008-03-07 16:12 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\HP
2008-03-07 16:11 . 2006-05-08 22:09 614,400 -ra------ C:\WINDOWS\system32\hpxp4370.dll
2008-03-07 16:11 . 2006-05-08 22:04 430,080 -ra------ C:\WINDOWS\system32\hp4370co.dll
2008-03-07 16:11 . 2001-08-17 21:53 13,824 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-07 16:08 . 2008-03-07 16:08 <DIR> d-------- C:\Program Files\Common Files\Sonic Shared
2008-03-07 16:08 . 2008-03-07 16:08 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\Sonic
2008-03-07 16:07 . 2008-03-07 16:07 <DIR> d-------- C:\Program Files\Common Files\HP
2008-03-07 16:05 . 2008-03-07 16:05 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-03-07 16:03 . 2008-03-07 16:03 <DIR> d-------- C:\Documents and Settings\All Users\Data aplikací\HP
2008-03-07 16:01 . 2008-03-07 16:03 <DIR> d-------- C:\Program Files\HP
2008-03-07 15:59 . 2008-03-07 16:11 111,573 --a------ C:\WINDOWS\hpgins15.dat
2008-03-07 15:59 . 2006-05-18 19:09 282 --------- C:\WINDOWS\hpgmdl15.dat
2008-03-06 20:52 . 2008-03-06 20:52 <DIR> d-------- C:\Documents and Settings\LocalService\Dokumenty
2008-03-06 11:00 . 2008-03-19 12:52 <DIR> d-------- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2008-03-05 21:57 . 2008-03-05 21:57 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-02-22 13:57 . 2008-02-22 13:57 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-02-19 16:58 . 2008-02-19 16:58 <DIR> d-------- C:\Program Files\Vimicro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 11:52 --------- d-----w C:\Program Files\Spyware Terminator
2008-03-18 13:43 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2008-03-12 09:49 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2008-03-11 18:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-11 18:24 --------- d-----w C:\Program Files\WinFast
2008-03-07 15:03 --------- d-----w C:\Program Files\Hewlett-Packard
2008-03-05 14:54 --------- d-----w C:\Program Files\Java
2008-02-19 15:58 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-12 18:59 --------- d-----w C:\Documents and Settings\Administrator\Data aplikací\Autodesk
2008-02-11 17:16 --------- d-----w C:\Program Files\Smart Projects
2008-02-11 17:12 223,128 ----a-w C:\WINDOWS\system32\drivers\dtscsi.sys
2008-02-11 17:12 --------- d-----w C:\Program Files\DAEMON Tools
2008-02-11 17:09 89,984 ----a-w C:\WINDOWS\system32\drivers\sptd7165.sys
2008-02-11 17:09 643,072 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-02-10 21:29 --------- d-----w C:\Program Files\HD Tune
2008-02-08 21:28 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-20 17:35 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-01-20 17:35 --------- d-----w C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2007-12-19 18:06 50,000 ----a-w C:\Documents and Settings\Administrator\Data aplikací\GDIPFONTCACHEV1.DAT
2006-02-19 02:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-09-20 13:00 13312]
"SetDefaultMIDI"="MIDIDef.exe" [2006-08-11 14:42 25600 C:\WINDOWS\MIDIDEF.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-10-29 16:50 4620288]
"nwiz"="nwiz.exe" [2004-10-29 16:50 921600 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-10-29 16:50 86016]
"CtxfiReg"="CTXFIREG.exe" [2006-08-11 14:53 42496 C:\WINDOWS\system32\CTXFIREG.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 10:03 57344]
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 18:06 45056]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-07 17:05 196608]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-15 17:25 249896]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-03-05 21:57 2957824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"OODefragTray"="C:\WINDOWS\System32\oodtray.exe" [2007-05-11 02:08 2512392]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-12-10 15:57 133016]
"BigDog305"="C:\WINDOWS\VM305_STI.exe" [2005-08-05 15:15 61440]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"WinFast Schedule"="C:\Program Files\WinFast\WFTVFM\WFWIZ.exe" [2004-05-07 15:33 163840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-09-20 13:00 13312]
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2007-07-18 14:22]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2007-08-09 13:04]
R1 fwdrv;Firewall Driver;C:\WINDOWS\System32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\System32\drivers\khips.sys [2007-04-26 10:21]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\System32\drivers\sp_rsdrv2.sys [2008-03-05 21:57]
R2 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;"C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe" [2007-08-28 13:16]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 10:21]
R2 WF23880;WinFast TV2000/DV2000 WDM Video Capture.;C:\WINDOWS\System32\drivers\wf88vcap.sys [2004-03-12 12:34]
R2 WF88XBAR;WinFast TV2000/DV2000 WDM Crossbar.;C:\WINDOWS\System32\drivers\WF88XBAR.sys [2004-03-12 12:34]
R2 WFTUNE;WinFast TV2000/DV2000 WDM Tuner.;C:\WINDOWS\System32\drivers\WF88TUNE.sys [2004-03-12 12:34]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\System32\DRIVERS\psched.sys [2001-09-20 13:00]
R3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2003-09-10 09:53]
S3 C-Dilla;C-Dilla;C:\WINDOWS\System32\drivers\CDANT.SYS [2007-12-15 16:27]
S3 WFLR6654;WinFast DTV1800 H (Video);C:\WINDOWS\System32\drivers\wfeaglxt.sys [2007-01-19 12:49]
S3 ZSMC0305;VIMICRO USB PC Camera V;C:\WINDOWS\System32\Drivers\usbVM305.sys [2006-04-05 14:14]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-19 22:20:13
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-19 22:21:40
ComboFix-quarantined-files.txt 2008-03-19 21:21:35
Logfile of HijackThis v1.99.1
Scan saved at 22:25:51, on 19.3.2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\System32\oodtray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\VM305_STI.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\oodag.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\WinFast\WFTVFM\WFTV.exe
C:\WINDOWS\explorer.exe
D:\Miranda IM\miranda32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
C:\Documents and Settings\Administrator\Plocha\hijackthis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL0
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\System32\oodtray.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera V
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file://C:\Program Files\AutoCAD 2002 Cz\InstFred.ocx
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) - file://C:\Program Files\AutoCAD 2002 Cz\AcDcToday.ocx
O16 - DPF: {AE563723-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002 Cz\InstBanr.ocx
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) -
http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.adobe.com/pub/shockwa ... wflash.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) - file://C:\Program Files\AutoCAD 2002 Cz\AcPreview.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
EDIT: virustotal.com hlasi: Výsledek: 2/32 (6.25%)
