To islo strasne dlho a som musel ist prec.Skusil som este raz combofix,ked to nevadi ///ComboFix 11-11-26.04 - Administrator 26.11.2011 21:14:29.9.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.511.301 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\windows\CSC\d6
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\drivers\etc\lmhosts
.
.
((((((((((((((((((((((((( Files Created from 2011-10-26 to 2011-11-26 )))))))))))))))))))))))))))))))
.
.
2011-11-26 19:05 . 2011-11-26 19:05 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\SUPERAntiSpyware.com
2011-11-26 19:03 . 2011-11-26 19:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2011-11-26 19:03 . 2011-11-26 19:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERSetup
2011-11-26 15:43 . 2011-11-26 15:43 -------- d-----w- c:\documents and settings\Administrator\DoctorWeb
2011-11-26 15:33 . 2011-11-26 15:33 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Avira
2011-11-26 15:20 . 2011-10-19 15:56 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-26 15:20 . 2011-10-19 15:56 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-11-26 15:20 . 2011-10-19 15:56 134344 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-26 15:20 . 2011-11-26 15:20 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avira
2011-11-26 13:29 . 2011-11-26 13:29 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\COMODO
2011-11-26 13:09 . 2008-04-14 03:22 24576 ----a-w- c:\windows\system32\wsock32.dlb
2011-11-26 13:09 . 2008-07-14 04:09 205560 ----a-w- c:\windows\UNBOC.EXE
2011-11-26 13:09 . 2008-07-14 04:09 212728 ----a-w- c:\windows\CMDLIC.DLL
2011-11-26 13:09 . 2011-11-26 13:09 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BOC427
2011-11-26 13:04 . 2011-11-26 13:05 -------- d-----w- c:\documents and settings\NetworkService\Data aplikací\Comodo
2011-11-26 13:03 . 2011-11-26 13:03 77568 ----a-w- c:\windows\system32\cmfdll32.dll
2011-11-26 12:50 . 2011-11-26 13:40 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Comodo
2011-11-26 12:44 . 2011-11-26 12:44 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Thunderbird
2011-11-26 12:44 . 2011-11-26 12:44 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Thunderbird
2011-11-26 12:01 . 2011-11-26 12:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Mozilla
2011-11-25 23:45 . 2011-11-25 23:45 12872 ----a-w- c:\windows\system32\bootdelete.exe
2011-11-25 23:40 . 2011-11-26 05:26 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-25 23:39 . 2011-11-25 23:45 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Hitman Pro
2011-11-25 19:02 . 2011-11-26 13:24 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Comodo
2011-11-25 19:02 . 2011-11-26 14:41 -------- d-----w- c:\program files\COMODO
2011-11-25 18:59 . 2011-11-26 14:24 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Comodo Downloader
2011-11-25 18:33 . 2011-06-21 10:24 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-11-25 18:27 . 2011-11-25 18:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Webroot
2011-11-24 15:07 . 2011-11-25 16:35 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\ESET
2011-11-24 15:07 . 2011-11-25 16:35 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\ESET
2011-11-24 15:06 . 2011-11-24 15:06 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\ESET
2011-11-23 20:25 . 2011-11-25 19:23 -------- d-----w- c:\program files\Lavalys
2011-11-23 20:03 . 2011-11-23 20:03 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Sierra Wireless
2011-11-23 19:44 . 2000-01-01 00:00 49024 ----a-w- c:\windows\system32\drivers\sisidex.sys
2011-11-23 19:44 . 2000-01-01 00:00 139264 ----a-w- c:\windows\system32\IDEproperty.dll
2011-11-23 19:44 . 2000-01-01 00:00 9472 ----a-w- c:\windows\system32\drivers\sisperf.sys
2011-11-23 19:43 . 1998-01-23 13:08 304640 ----a-w- c:\windows\IsUn041b.exe
2011-11-23 19:42 . 2000-01-01 00:00 4096 ----a-w- c:\windows\system32\drivers\siside.sys
2011-11-23 19:41 . 2004-08-03 21:41 11868 ----a-w- c:\windows\system32\drivers\mdmxsdk.sys
2011-11-23 19:41 . 2008-04-14 04:21 86016 ----a-w- c:\windows\system32\mdmxsdk.dll
2011-11-23 18:07 . 2011-11-26 14:50 65216 ----a-w- c:\windows\system32\drivers\sfi.dat
2011-11-21 15:46 . 2011-11-21 15:46 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Malwarebytes
2011-11-21 15:46 . 2011-11-21 15:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-07 19:46 . 2011-11-07 20:51 133208 ----a-w- c:\windows\system32\drivers\01981899.sys
2011-11-05 06:34 . 2011-11-05 06:34 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-04 15:18 . 2011-11-26 09:17 -------- d-----w- c:\program files\Defraggler
2011-11-03 18:15 . 2011-11-03 18:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\CheckPoint
2011-11-03 05:26 . 2011-11-03 05:26 -------- d-----w- c:\program files\Sun
2011-11-03 05:18 . 2011-11-03 05:29 -------- d-----w- c:\documents and settings\Administrator\.nbi
2011-11-03 04:07 . 2011-11-03 04:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Office Genuine Advantage
2011-11-02 04:09 . 2008-04-14 04:22 152064 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2011-11-02 04:09 . 2008-04-13 19:54 88192 -c--a-w- c:\windows\system32\dllcache\irda.sys
2011-11-02 04:07 . 2008-04-13 19:39 206976 -c--a-w- c:\windows\system32\dllcache\dot4.sys
2011-11-01 14:30 . 2011-11-01 14:30 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\TuneUp Software
2011-10-31 23:07 . 2011-10-31 23:07 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2011-10-31 23:07 . 2011-10-31 23:07 60416 ----a-w- c:\windows\ALCFDRTM.VER
2011-10-31 23:07 . 2011-10-31 23:07 -------- d-----w- c:\windows\system32\Lang
2011-10-29 19:31 . 2011-10-29 19:31 -------- d-----w- c:\program files\Windows Sidebar
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-05 06:34 . 2010-08-02 15:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-30 23:21 . 2011-10-30 23:18 5777519 ----a-w- c:\windows\REGBK00.ZIP
2011-10-24 21:37 . 2011-05-30 11:17 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-07 17:48 . 2011-10-07 17:48 97760 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-10-07 17:48 . 2011-10-07 17:48 492768 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:48 . 2011-10-07 17:48 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:48 . 2011-10-07 17:48 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47 . 2011-10-07 17:47 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-07 17:47 . 2011-10-07 17:47 300200 ----a-w- c:\windows\system32\guard32.dll
2011-09-26 09:41 . 2008-07-29 18:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2002-09-20 18:03 602112 ----a-w- c:\windows\system32\crypt32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="d:\firewally\Comodo Firewall\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 2497352]
"COMODO Memory Firewall"="d:\firewally\Comodo Memory Firewall\cmf.exe" [2011-11-26 2236160]
"avgnt"="d:\antiviry\Avira\Avira\AntiVir Desktop\avgnt.exe" [2011-10-19 258512]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\antiviry\SuperantiSpywer\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- d:\antiviry\SuperantiSpywer\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-10-12 16:18 4615552 ----a-w- d:\antiviry\SuperantiSpywer\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"sp_rssrv"=2 (0x2)
"cmdAgent"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"d:\\My Download Files\\Subory\\Skype\\Phone\\Skype.exe"=
"d:\\My Download Files\\Subory\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
R0 01981899;01981899;c:\windows\system32\drivers\01981899.sys [7.11.2011 20:46 133208]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [26.11.2011 16:20 36000]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [7.10.2011 18:48 492768]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.10.2011 18:48 31704]
R1 SASDIFSV;SASDIFSV;d:\antiviry\SuperantiSpywer\sasdifsv.sys [22.7.2011 17:27 12880]
R1 SASKUTIL;SASKUTIL;d:\antiviry\SuperantiSpywer\SASKUTIL.SYS [12.7.2011 22:55 67664]
R2 !SASCORE;SAS Core Service;d:\antiviry\SuperantiSpywer\SASCore.exe [12.8.2011 0:38 116608]
R2 AntiVirSchedulerService;Avira Scheduler;d:\antiviry\Avira\Avira\AntiVir Desktop\sched.exe [26.11.2011 16:20 86224]
R2 cmfd;cmfd;d:\firewally\Comodo Memory Firewall\cmfd.sys [26.11.2011 14:03 11768]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14.5.2007 9:26 508288]
R3 S3SAVAGE4;S3SAVAGE4;c:\windows\system32\drivers\s3savg4m.sys [10.8.2000 13:03 84704]
S2 BOCore;BOCore;d:\firewally\Comodo BoClean\BOCore.exe [26.11.2011 14:09 73464]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S3 PRODIGY;PRODIGY;c:\windows\system32\drivers\prodigy.sys [15.5.2011 11:55 32377]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [12.6.2011 15:08 27064]
S3 S3SAVAGE4M;S3SAVAGE4M;c:\windows\system32\drivers\s3sav4m.sys [7.7.2008 17:00 77824]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - !SASCORE
*NewlyCreated* - ANTIVIRSCHEDULERSERVICE
*NewlyCreated* - ANTIVIRSERVICE
*NewlyCreated* - AVGNTFLT
*NewlyCreated* - AVIPBB
*NewlyCreated* - LTHNQ
*NewlyCreated* - WMWXFQQP
*Deregistered* - hswd00007516
*Deregistered* - lthnq
*Deregistered* - wmwxfqqp
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-26 c:\windows\Tasks\PandaUSBVaccine.job
- e:\panda\Panda USB Vaccine\RunInteractiveWin.exe [2011-04-13 14:45]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://
www.google.com
mStart Page = about:blank
uSearchAssistant = hxxp://
www.google.com/ie
TCP: DhcpNameServer = 192.168.100.1
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\2dawriia.default\
FF - prefs.js: browser.startup.homepage - gmail.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-26 21:27
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1957994488-1677128483-854245398-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6e,58,b7,0d,55,62,69,4c,b3,c9,46,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b3,22,01,3a,f3,8c,ea,4d,8d,d2,45,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,fe,94,e8,f9,a9,65,49,b0,f4,f4,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\guard32.dll
.
- - - - - - - > 'lsass.exe'(804)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'csrss.exe'(712)
c:\windows\system32\cmdcsr.dll
.
Completion time: 2011-11-26 21:33:36
ComboFix-quarantined-files.txt 2011-11-26 20:33
.
Pre-Run: 961 257 472
Post-Run: 903 147 520
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 01A0F6062C81232E11FDCE651EEE5642
vadi./////