ComboFix 10-07-08.02 - GTX 10.07.2010 13:52:01.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.511.216 [GMT 2:00]
Running from: c:\documents and settings\GTX\My Documents\Preberanie\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\daemon.dll
.
((((((((((((((((((((((((( Files Created from 2010-06-10 to 2010-07-10 )))))))))))))))))))))))))))))))
.
2010-07-10 11:41 . 2010-07-10 11:41 -------- d-----w- c:\documents and settings\GTX\Application Data\AVG9
2010-07-08 21:31 . 2010-07-08 21:31 -------- d-----w- c:\program files\CleanUp!
2010-07-08 21:29 . 2010-07-08 21:29 184174 ----a-w- C:\UsbFix_Upload_Me_ERATHIA.zip
2010-07-08 21:26 . 2010-07-08 21:29 -------- d-----w- C:\UsbFix
2010-07-08 19:04 . 2010-07-08 19:04 63488 ----a-w- c:\documents and settings\GTX\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-08 19:04 . 2010-07-08 19:04 52224 ----a-w- c:\documents and settings\GTX\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-08 19:04 . 2010-07-08 19:04 117760 ----a-w- c:\documents and settings\GTX\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-08 19:03 . 2010-07-08 19:04 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-08 18:41 . 2010-07-08 18:42 -------- d-----w- C:\rsit
2010-07-08 17:35 . 2010-07-08 17:35 -------- d-----w- C:\$AVG
2010-07-08 13:36 . 2010-07-08 13:36 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-08 13:36 . 2010-07-08 13:36 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-08 13:36 . 2010-07-08 13:36 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-08 13:36 . 2010-07-08 13:36 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-07-08 13:36 . 2010-07-10 10:20 -------- d-----w- c:\windows\system32\drivers\Avg
2010-07-08 13:33 . 2010-07-08 13:33 -------- d-----w- c:\program files\AVG
2010-07-08 13:32 . 2010-07-08 13:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-07-08 12:49 . 2010-07-08 13:00 -------- d-----w- c:\program files\VITSOFT
2010-07-05 19:12 . 2010-07-05 19:12 -------- d-----w- c:\documents and settings\GTX\DoctorWeb
2010-07-05 17:50 . 2010-07-05 18:11 -------- d-----w- c:\documents and settings\GTX\Application Data\AusLogics
2010-07-05 17:48 . 2010-07-05 17:57 -------- d-----w- c:\program files\Auslogics
2010-07-05 15:17 . 2010-07-05 15:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2010-07-05 15:16 . 2010-07-05 15:16 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-07-05 14:36 . 2010-07-05 14:38 -------- d-----w- c:\documents and settings\GTX\.gimp-2.6
2010-07-04 17:10 . 2010-07-04 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Panda Security
2010-07-04 17:07 . 2010-07-04 17:07 -------- d-----w- c:\documents and settings\GTX\Application Data\Malwarebytes
2010-07-04 17:07 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-04 17:07 . 2010-07-04 17:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-04 17:07 . 2010-07-04 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-04 17:07 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-04 16:47 . 2010-07-04 16:47 -------- d-----w- c:\program files\CCleaner
2010-07-04 16:45 . 2007-08-31 10:52 56496 ----a-w- c:\windows\system32\wbhelp2.dll
2010-07-04 16:45 . 2007-08-31 10:52 33968 ----a-w- c:\windows\system32\anim.dll
2010-07-04 16:45 . 2004-12-07 08:11 258352 ----a-w- c:\windows\system32\unicows.dll
2010-07-04 16:45 . 2001-08-24 06:25 1706800 ----a-w- c:\windows\system32\gdiplus.dll
2010-07-04 16:45 . 1999-11-22 13:50 4608 ----a-w- c:\windows\system32\W95INF32.DLL
2010-07-04 16:45 . 1999-11-22 13:50 2272 ----a-w- c:\windows\system32\W95INF16.DLL
2010-06-17 16:32 . 2010-06-17 16:32 -------- d-----w- c:\documents and settings\GTX\Application Data\Unity
2010-06-17 16:29 . 2010-06-17 16:29 -------- d-----w- c:\documents and settings\GTX\Local Settings\Application Data\Unity
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-09 15:45 . 2010-03-05 17:18 67872 ----a-w- c:\documents and settings\GTX\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-08 19:03 . 2010-04-05 08:54 -------- d-----w- c:\documents and settings\GTX\Application Data\SUPERAntiSpyware.com
2010-07-08 18:42 . 2010-04-05 08:50 -------- d-----w- c:\program files\Trend Micro
2010-07-08 13:21 . 2010-04-07 17:29 -------- d-----w- c:\program files\Panda Security
2010-07-06 17:07 . 2010-04-05 08:42 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-06 14:30 . 2010-05-15 17:40 -------- d-----w- c:\program files\SweetIM
2010-07-06 14:30 . 2010-05-15 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SweetIM
2010-07-05 16:57 . 2010-03-05 16:54 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-05 08:09 . 2010-04-06 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\COMODO
2010-07-04 16:32 . 2010-03-07 15:52 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-04 15:59 . 2010-04-05 08:30 -------- d-----w- c:\program files\VS Revo Group
2010-05-31 11:27 . 2010-03-05 20:27 -------- d-----w- c:\documents and settings\GTX\Application Data\Skype
2010-05-29 16:44 . 2010-05-27 23:31 5104 ----a-w- C:\NanoRepository.bin
2010-05-23 14:39 . 2010-05-23 14:39 503808 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4d42e1e7-n\msvcp71.dll
2010-05-23 14:39 . 2010-05-23 14:39 499712 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4d42e1e7-n\jmc.dll
2010-05-23 14:39 . 2010-05-23 14:39 12800 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-49aff5b7-n\decora-d3d.dll
2010-05-23 14:39 . 2010-05-23 14:39 61440 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-49aff5b7-n\decora-sse.dll
2010-05-23 14:39 . 2010-05-23 14:39 348160 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4d42e1e7-n\msvcr71.dll
2010-05-19 18:40 . 2010-03-05 20:28 -------- d-----w- c:\documents and settings\GTX\Application Data\skypePM
2010-05-19 18:38 . 2010-03-05 20:33 -------- d-----w- c:\documents and settings\GTX\Application Data\ICQ
2010-05-18 17:41 . 2010-04-08 13:50 -------- d-----w- c:\documents and settings\GTX\Application Data\Image Zone Express
2010-05-18 17:23 . 2010-03-07 17:26 -------- d-----w- c:\documents and settings\GTX\Application Data\Microgaming
2010-05-15 19:24 . 2010-03-05 20:26 -------- d-----r- c:\program files\Skype
2010-05-14 17:41 . 2010-04-20 16:01 -------- d-----w- c:\documents and settings\GTX\Application Data\Hamachi
2010-05-07 10:55 . 2010-05-07 10:55 255472 ----a-w- c:\documents and settings\GTX\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-04-24 17:57 . 2010-04-08 13:39 108615 ----a-w- c:\windows\hpoins08.dat
2010-04-22 15:35 . 2010-04-22 15:36 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-21 17:23 . 2010-04-21 17:12 2493 ----a-w- c:\program files\system.log.txt
2010-04-20 16:00 . 2010-04-20 16:00 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-04-18 11:50 . 2010-04-18 11:50 61440 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-444e16a2-n\decora-sse.dll
2010-04-18 11:50 . 2010-04-18 11:50 12800 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-444e16a2-n\decora-d3d.dll
2010-04-18 11:50 . 2010-04-18 11:50 503808 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-54e95e7b-n\msvcp71.dll
2010-04-18 11:50 . 2010-04-18 11:50 499712 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-54e95e7b-n\jmc.dll
2010-04-18 11:50 . 2010-04-18 11:50 348160 ----a-w- c:\documents and settings\GTX\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-54e95e7b-n\msvcr71.dll
2006-11-06 16:28 . 2010-04-21 17:10 19574784 ----a-w- c:\program files\medieval2.exe
2010-04-05 08:45 . 2010-04-05 08:45 23 --sha-w- c:\windows\system32\edacded0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-04-26 589824]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-08 2065760]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\GTX\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-08 13:36 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 13:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-05-07 18:24 136176 ----atw- c:\documents and settings\GTX\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2010-03-28 12:39 133368 ----a-w- c:\program files\ICQ7.0\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\InterVideo\\DVD5\\WinDVD.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Documents and Settings\\GTX\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 pnpshark;pnpshark;c:\windows\system32\drivers\pnpshark.sys [2.10.2003 4:16 119552]
R0 st3shark;st3shark;c:\windows\system32\drivers\st3shark.sys [27.9.2003 15:37 5504]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8.7.2010 15:36 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8.7.2010 15:36 243024]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [8.7.2010 15:34 308136]
.
Contents of the 'Scheduled Tasks' folder
2010-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-602162358-839522115-1003Core.job
- c:\documents and settings\GTX\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-07 18:24]
2010-07-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-602162358-839522115-1003UA.job
- c:\documents and settings\GTX\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-07 18:24]
.
.
------- Supplementary Scan -------
.
uSearchAssistant = hxxp://
www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
FF - ProfilePath - c:\documents and settings\GTX\Application Data\Mozilla\Firefox\Profiles\ijo9zjr3.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - component: c:\documents and settings\GTX\Application Data\Mozilla\Firefox\Profiles\ijo9zjr3.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\GTX\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\GTX\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\GTX\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-10 13:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82161C70]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf86b9fc3
\Driver\ACPI -> ACPI.sys @ 0xf853ccb8
\Driver\atapi -> 0x82161c70
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577d44
ParseProcedure -> ntkrnlpa.exe @ 0x80576964
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80577d44
ParseProcedure -> ntkrnlpa.exe @ 0x80576964
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf83a6bc3
PacketIndicateHandler -> NDIS.sys @ 0xf83b2b21
SendHandler -> NDIS.sys @ 0xf83a6d33
Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(556)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2010-07-10 13:58:34
ComboFix-quarantined-files.txt 2010-07-10 11:58
Pre-Run: 7 866 998 784 bytes free
Post-Run: 7 862 308 864 voľných bajtov
- - End Of File - - 89F84C75384C6727B69EAF3AD0FC37F0