ComboFix 12-01-21.02 - SlavoK 22.01.2012 16:43:21.11.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1190 [GMT 1:00]
Running from: c:\documents and settings\SlavoK\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-12-22 to 2012-01-22 )))))))))))))))))))))))))))))))
.
.
2012-01-22 16:45 . 2012-01-22 16:45 512 ----a-w- C:\Physical0MBR.bin
2012-01-22 13:11 . 2012-01-22 13:14 -------- d-----w- c:\program files\Common Files\Symantec Shared
2012-01-22 13:11 . 2012-01-22 13:11 -------- d-----w- c:\program files\Symantec
2012-01-22 13:11 . 2012-01-22 13:11 60872 ----a-w- c:\windows\system32\S32EVNT1.DLL
2012-01-22 13:11 . 2012-01-22 13:11 127096 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-01-22 13:10 . 2012-01-22 13:10 -------- d-----w- c:\windows\system32\drivers\NIS
2012-01-22 13:10 . 2012-01-22 13:10 -------- d-----w- c:\program files\Norton Internet Security
2012-01-22 13:10 . 2012-01-22 13:10 -------- d-----w- c:\program files\Windows Sidebar
2012-01-22 13:10 . 2012-01-22 13:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2012-01-22 13:10 . 2012-01-22 13:10 -------- d-----w- c:\program files\NortonInstaller
2012-01-21 23:20 . 2012-01-21 23:20 -------- d--h--w- c:\windows\system32\GroupPolicy
2012-01-21 17:08 . 2012-01-21 17:12 -------- d-----w- C:\UsbFix
2012-01-21 16:38 . 2012-01-21 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2012-01-21 16:27 . 2012-01-21 16:27 -------- d-----w- C:\VundoFix Backups
2012-01-21 15:25 . 2001-08-17 12:28 794654 -c--a-w- c:\windows\system32\dllcache\usr1801.sys
2012-01-21 15:24 . 2008-04-13 23:10 43904 -c--a-w- c:\windows\system32\dllcache\sbp2port.sys
2012-01-21 15:23 . 2008-04-13 23:16 49024 -c--a-w- c:\windows\system32\dllcache\mstape.sys
2012-01-21 15:22 . 2001-08-17 21:36 45056 -c--a-w- c:\windows\system32\dllcache\icam5com.dll
2012-01-21 15:21 . 2001-08-17 11:12 24618 -c--a-w- c:\windows\system32\dllcache\fa410nd5.sys
2012-01-21 15:20 . 2008-04-13 23:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2012-01-21 15:19 . 2001-08-17 12:52 22400 -c--a-w- c:\windows\system32\dllcache\asc3350p.sys
2012-01-21 08:20 . 2011-09-20 18:22 553880 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2012-01-06 22:59 . 2012-01-06 22:59 -------- d-----w- c:\program files\CDisplay
2012-01-06 22:56 . 2012-01-06 22:57 -------- d-----w- c:\documents and settings\SlavoK\Application Data\Comical
2011-12-26 13:12 . 2011-12-26 13:12 -------- d-----w- c:\documents and settings\SlavoK\Application Data\Trine2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-21 17:12 . 2012-01-21 17:12 3296 ----a-w- C:\UsbFix_Upload_Me_SLAVOK2.zip
2012-01-06 22:56 . 2011-08-12 12:34 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-10 14:24 . 2009-05-05 18:09 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-23 16:45 . 2011-11-23 16:45 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-11-23 16:45 . 2010-05-21 13:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-28 08:00 . 2011-11-07 14:05 74752 ----a-w- c:\windows\system32\ff_vfw.dll
2007-02-13 15:22 . 2010-01-09 13:34 947472 ----a-w- c:\program files\msjava.dll
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-21_19.37.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-01-22 12:33 . 2012-01-22 12:33 16384 c:\windows\temp\Perflib_Perfdata_748.dat
+ 2012-01-22 13:13 . 2012-01-22 13:13 16384 c:\windows\temp\Perflib_Perfdata_144.dat
+ 2012-01-22 13:10 . 2011-08-02 18:22 31864 c:\windows\system32\drivers\NIS\1301000.01C\srtspx.sys
+ 2012-01-22 13:10 . 2011-06-06 17:03 2801 c:\windows\system32\drivers\NIS\1301000.01C\SymVTcer.dat
+ 2012-01-22 13:10 . 2011-07-25 18:18 344184 c:\windows\system32\drivers\NIS\1301000.01C\symtdiv.sys
+ 2012-01-22 13:10 . 2011-07-25 18:18 387192 c:\windows\system32\drivers\NIS\1301000.01C\symtdi.sys
+ 2012-01-22 13:10 . 2011-07-25 18:18 314488 c:\windows\system32\drivers\NIS\1301000.01C\symnets.sys
+ 2012-01-22 13:10 . 2011-07-28 19:20 897656 c:\windows\system32\drivers\NIS\1301000.01C\SymEFA.sys
+ 2012-01-22 13:10 . 2011-07-25 18:18 340088 c:\windows\system32\drivers\NIS\1301000.01C\SymDS.sys
+ 2012-01-22 13:10 . 2011-08-02 18:22 566904 c:\windows\system32\drivers\NIS\1301000.01C\srtsp.sys
+ 2012-01-22 13:10 . 2011-07-25 18:15 149624 c:\windows\system32\drivers\NIS\1301000.01C\Ironx86.sys
+ 2012-01-22 13:10 . 2011-08-08 15:38 132744 c:\windows\system32\drivers\NIS\1301000.01C\ccSetx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 73728]
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe" [2005-07-21 192512]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-08 13851752]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoAutorun"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyPictures"= 01000000
"NoRecentDocsNetHood"= 01000000
"NoSMMyDocs"= 01000000
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 03:42 110592 ----a-w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2010-08-25 22:12 1753192 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"i:\\driver\\usb\\–Ľ‡‘Š•†‘Í€ŚŽ"=
"e:\\Games\\Blur\\Blur.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\SlavoK\\Application Data\\MSJ-Driver-4532-56324-6224\\winrsnbc.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"e:\\Games\\Split Second\\SplitSecond.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1828:TCP"= 1828:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.5.2008 17:01 722416]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1301000.01C\SymDS.sys [22.1.2012 14:10 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1301000.01C\SymEFA.sys [22.1.2012 14:10 897656]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20110723.001\BHDrvx86.sys [22.1.2012 14:10 815736]
R1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NIS\1301000.01C\ccSetx86.sys [22.1.2012 14:10 132744]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1301000.01C\Ironx86.sys [22.1.2012 14:10 149624]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [21.1.2012 9:45 652872]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe [22.1.2012 14:10 138760]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20110726.001\IDSXpx86.sys [22.1.2012 14:10 356280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5.5.2009 19:09 20464]
S1 7dd362c4;7dd362c4;c:\windows\system32\drivers\7dd362c4.sys --> c:\windows\system32\drivers\7dd362c4.sys [?]
S1 d0c3a864;d0c3a864;c:\windows\system32\drivers\d0c3a864.sys --> c:\windows\system32\drivers\d0c3a864.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 xwoarh;xwoarh; [x]
S3 FIXUSTOR;FIXUSTOR;c:\windows\system32\drivers\fixustor.sys [5.4.2010 18:22 12416]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [8.5.2010 9:37 36608]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [24.2.2005 12:29 508288]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [8.5.2010 9:37 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [8.5.2010 9:37 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [8.5.2010 9:37 121856]
S3 USTOR2K;USB Mass Storage Windows Driver;c:\windows\system32\drivers\ustor2k.sys [5.4.2010 18:17 28928]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S3 zlportio;zlportio;\??\e:\games\UltraStar Deluxe\zlportio.sys --> e:\games\UltraStar Deluxe\zlportio.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 12518850
*NewlyCreated* - BHDRVX86
*NewlyCreated* - CCSET_NIS
*NewlyCreated* - EECTRL
*NewlyCreated* - ERASERUTILDRV11113
*NewlyCreated* - ERASERUTILDRVI13
*NewlyCreated* - IDSXPX86
*NewlyCreated* - NAVENG
*NewlyCreated* - NAVEX15
*NewlyCreated* - NIS
*NewlyCreated* - SRTSP
*NewlyCreated* - SRTSPX
*NewlyCreated* - SYMDS
*NewlyCreated* - SYMEFA
*NewlyCreated* - SYMEVENT
*NewlyCreated* - SYMIRON
*NewlyCreated* - SYMTDI
*Deregistered* - 12518850
*Deregistered* - EraserUtilDrv11113
*Deregistered* - EraserUtilDrvI13
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
Trusted Zone: sony.com\launchpad.patch.station
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\SlavoK\Application Data\Mozilla\Firefox\Profiles\ne6hvnge.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.sk/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: Usage Stat: {6236BA26-C117-4007-928C-DE0716C7FA96} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}
FF - Ext: U Flv: {7645f4b1-1f19-13dd-2d6b-0200600c2a56} - %profile%\extensions\{7645f4b1-1f19-13dd-2d6b-0200600c2a56}
FF - Ext: {7645f4b1-1f19-13dd-2d6b-0200600c2a56}: {7645f4b1-1f19-13dd-2d6b-0200600c2a56} - %profile%\extensions\{7645f4b1-1f19-13dd-2d6b-0200600c2a56}
FF - Ext: KFD Flv: {8675f4b3-2f19-11ed-2d6b-0800600c0a16} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
FF - Ext: {8675f4b3-2f19-11ed-2d6b-0800600c0a16}: {8675f4b3-2f19-11ed-2d6b-0800600c0a16} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a16}
FF - Ext: VFD Flv: {8675f4b3-2f19-11ed-2d6b-0800600c0a17} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a17}
FF - Ext: {8675f4b3-2f19-11ed-2d6b-0800600c0a17}: {8675f4b3-2f19-11ed-2d6b-0800600c0a17} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a17}
FF - Ext: VFD Flv: {8675f4b3-2f19-11ed-2d6b-0800600c0a18} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a18}
FF - Ext: {8675f4b3-2f19-11ed-2d6b-0800600c0a18}: {8675f4b3-2f19-11ed-2d6b-0800600c0a18} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a18}
FF - Ext: Feedback module: {8675f4b3-2f19-11ed-2d6b-0800600c0a19} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a19}
FF - Ext: {8675f4b3-2f19-11ed-2d6b-0800600c0a19}: {8675f4b3-2f19-11ed-2d6b-0800600c0a19} - %profile%\extensions\{8675f4b3-2f19-11ed-2d6b-0800600c0a19}
FF - Ext: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - %profile%\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-22 16:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\19.1.0.28\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1454471165-1604221776-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1454471165-1604221776-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:0f,27,0f,82,b0,d4,0b,0a,7d,c0,e3,0b,81,91,24,99,5f,59,d5,63,84,
aa,5e,af,9c,93,fb,22,76,a9,11,0a,e6,84,cf,01,a5,f6,c3,8e,f6,bc,54,93,8f,e0,\
"rkeysecu"=hex:dc,e3,9b,b6,8f,b8,8b,dc,7e,0c,78,9f,d6,5d,b5,98
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3964)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
Completion time: 2012-01-22 16:55:14
ComboFix-quarantined-files.txt 2012-01-22 15:55
ComboFix2.txt 2012-01-21 19:54
.
Pre-Run: 1 060 610 048 bytes free
Post-Run: 1 036 980 224 voľných bajtov
.
- - End Of File - - 807951B31B43FD03E11A4857893DDF63