Re: Prosím o kontrolu(IRCBot)
Napsal: 10 črc 2012 10:59
Ahoj,tady to je,snad je to ono,když jsem přesouval ten script tak to pak spustilo ComboFix,tak snad to tak mělo být,dík
ComboFix 12-07-08.02 - Inna 10.07.2012 11:44:02.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3582.3022 [GMT 2:00]
Spuštěný z: c:\documents and settings\Inna\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Inna\Plocha\CFScript.txt
AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
FILE ::
"c:\documents and settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\searchplugins\askcom.xml"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Nakažená kopie c:\windows\system32\drivers\tcpip.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-10 do 2012-07-10 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-29 17:30 . 2011-12-14 22:09 477240 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-06-27 09:53 . 2012-03-31 13:21 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-27 09:53 . 2011-12-14 06:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-26 19:24 . 2012-06-26 19:23 4375385 ----a-w- c:\windows\REGBK00.ZIP
2012-06-04 15:35 . 2011-12-14 03:18 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-04 15:35 . 2009-08-06 18:23 222448 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 13:19 . 2011-12-14 04:20 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2011-12-14 04:20 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2011-12-14 03:18 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2011-12-14 03:18 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2011-12-14 04:20 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2011-12-14 04:20 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2011-12-14 03:18 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2011-12-14 03:18 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2006-03-02 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2011-12-14 03:18 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2011-12-14 03:18 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2012-01-18 14:57 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2012-01-18 14:57 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2006-03-02 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2006-03-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:55 . 2006-03-02 12:00 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:44 . 2006-03-02 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-03-02 12:00 385024 ------w- c:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-17 15:45 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-04 17:29 . 2012-01-02 10:19 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-02 13:46 . 2011-12-14 03:17 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-24 22:34 . 2012-06-23 20:44 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-30_23.28.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-10 09:49 . 2012-07-10 09:49 16384 c:\windows\temp\Perflib_Perfdata_514.dat
- 2011-02-19 21:03 . 2011-02-19 21:03 51024 c:\windows\system32\vcomp100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 51024 c:\windows\system32\vcomp100.dll
+ 2009-06-30 14:36 . 2009-06-30 14:36 93184 c:\windows\system32\spool\drivers\w32x86\3\CSD_IRIVER_PLUS4_DRV.DLL
+ 2012-07-10 07:03 . 2012-07-10 07:02 82432 c:\windows\system32\msxml4r.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 81744 c:\windows\system32\mfcm100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 43344 c:\windows\system32\mfc100kor.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100chs.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 36176 c:\windows\system32\mfc100chs.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100fra.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 64336 c:\windows\system32\mfc100fra.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 63824 c:\windows\system32\mfc100esn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 63824 c:\windows\system32\mfc100esn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 55120 c:\windows\system32\mfc100enu.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100deu.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 64336 c:\windows\system32\mfc100deu.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 40960 c:\windows\system32\MAMACExtract.dll
+ 2008-12-24 13:22 . 2010-02-11 00:48 14727 c:\windows\system32\drivers\D7.sys
+ 2008-10-09 15:13 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D35.SYS
+ 2009-01-19 17:39 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D31.sys
+ 2008-06-26 15:48 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D28.sys
+ 2009-07-15 14:33 . 2010-02-11 00:48 14729 c:\windows\system32\drivers\D150.sys
+ 2009-03-26 07:45 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D100.sys
+ 2011-12-14 03:18 . 2012-06-02 13:19 35864 c:\windows\system32\dllcache\wups.dll
+ 2012-07-10 07:03 . 2012-07-10 07:02 77824 c:\windows\system32\csdlocalmon.dll
+ 2009-06-30 13:31 . 2009-06-30 13:31 53248 c:\windows\system32\csd_iriver_plus4_lib.dll
+ 2009-06-30 14:13 . 2009-06-30 14:13 69632 c:\windows\system32\CSD_IRIVER_PLUS4_GEN.DLL
+ 2011-12-14 03:20 . 2012-07-01 10:57 76487 c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2011-12-14 03:20 . 2011-12-14 03:20 76487 c:\windows\pchealth\helpctr\OfflineCache\index.dat
+ 2012-07-10 07:05 . 2012-07-10 07:05 25728 c:\windows\MetaUSBDriver\Meta\i386\metaadb.sys
+ 2012-07-10 07:05 . 2012-07-10 07:05 31744 c:\windows\MetaUSBDriver\Meta\amd64\metaadb.sys
+ 2012-07-10 07:03 . 2012-07-10 07:03 65536 c:\windows\Installer\{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}\IRiverShortCut2_4BCC38153EEE40BBB5CB6AFE3A13AFD4.exe
+ 2012-07-10 07:03 . 2012-07-10 07:03 65536 c:\windows\Installer\{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}\IRiverShortCut1_83CAD25F27EF41FFA9AB9C9F0F65F2C7.exe
+ 2011-12-14 03:20 . 2012-07-01 10:57 2378 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2011-12-14 03:20 . 2012-07-01 10:57 8972 c:\windows\pchealth\helpctr\Config\Cntstore.bin
+ 2011-12-14 06:36 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\UNIRES.DLL
+ 2011-12-14 06:36 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL
+ 2011-12-14 06:36 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\UNIDRV.DLL
+ 2009-05-15 09:20 . 2009-05-15 09:20 159744 c:\windows\system32\nbirv4svr.exe
+ 2009-05-15 09:20 . 2009-05-15 09:20 135168 c:\windows\system32\nbirv4src.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 258048 c:\windows\system32\nbirv4ogf.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 360448 c:\windows\system32\nbirv4ctl.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 118784 c:\windows\system32\nbirv4aef.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 773968 c:\windows\system32\msvcr100.dll
- 2011-02-18 22:40 . 2011-02-18 22:40 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 421200 c:\windows\system32\msvcp100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 421200 c:\windows\system32\msvcp100.dll
+ 2006-03-02 12:00 . 2008-06-20 11:59 361600 c:\windows\system32\drivers\tcpip.sys
- 2006-03-02 12:00 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys
+ 2011-12-14 03:18 . 2012-06-02 13:19 577048 c:\windows\system32\dllcache\wuapi.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 138056 c:\windows\system32\atl100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 138056 c:\windows\system32\atl100.dll
+ 2012-07-10 07:05 . 2012-07-10 07:05 238408 c:\windows\MetaUSBDriver\Meta\Uninstall.exe
+ 2012-07-10 07:05 . 2012-07-10 07:05 107136 c:\windows\MetaUSBDriver\Meta\i386\metaumsg.sys
+ 2012-07-10 07:05 . 2012-07-10 07:05 121856 c:\windows\MetaUSBDriver\Meta\amd64\metaumsg.sys
+ 2012-07-10 07:03 . 2012-07-10 07:03 110592 c:\windows\Installer\{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}\ARPPRODUCTICON.exe
+ 2012-07-10 07:03 . 2012-07-10 07:02 1286152 c:\windows\system32\msxml4.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 4422992 c:\windows\system32\mfc100u.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 4422992 c:\windows\system32\mfc100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 4397384 c:\windows\system32\mfc100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 4397384 c:\windows\system32\mfc100.dll
+ 2012-07-10 07:05 . 2012-07-10 07:05 1419232 c:\windows\MetaUSBDriver\Meta\i386\WdfCoInstaller01005.dll
+ 2012-07-10 07:05 . 2012-07-10 07:05 1919968 c:\windows\MetaUSBDriver\Meta\amd64\WdfCoInstaller01005.dll
+ 2011-06-28 19:27 . 2011-06-28 19:27 4028928 c:\windows\Installer\427a0.msp
+ 2012-07-10 07:03 . 2012-07-10 07:03 4800512 c:\windows\Installer\3097e7.msi
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JulaPan"="JulaPan.Exe" [2008-06-24 421888]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-05 98304]
"combofix"="c:\combofix\CF27077.3XE" [2012-07-10 390144]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\AutorunsDisabled
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-10-14 291896]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\36X Raid Configurer]
2007-11-19 03:28 1966080 ------r- c:\windows\system32\xRaidSetup.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALCMTR.EXE]
2008-06-19 08:20 57344 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ------r- c:\windows\alcwzrd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVI]
2007-07-26 14:05 20480 ----a-w- c:\program files\GIGABYTE\ET6\ETcall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2012-05-22 06:13 980920 ----a-w- c:\progra~1\Eraser\Eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
2007-03-20 06:36 36864 ------r- c:\windows\RaidTool\xInsIDE.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetLimiter]
2004-03-31 13:23 823296 ----a-w- c:\program files\NetLimiter\NetLimiter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-07-23 08:51 16804864 ------r- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ------r- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThreatFire]
2010-01-14 14:08 378128 ----a-w- c:\program files\ThreatFire\TFTray.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\nbirv4svr.exe"=
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [25.3.2012 17:49 28552]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [30.3.2012 11:37 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [30.3.2012 11:37 59664]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [7.10.2011 19:48 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.10.2011 19:48 31704]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [13.2.2012 13:28 100368]
R3 JULA_01;Service for Juli@ 1;c:\windows\system32\drivers\JulaWdm.sys [24.6.2008 11:21 22912]
R3 JULA_AA;Service for Juli@ Audio Driver (EWDM);c:\windows\system32\drivers\Jula.sys [24.6.2008 11:20 29600]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [14.12.2011 6:17 60255]
R3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [14.12.2011 6:17 549421]
S3 etdrv;etdrv;c:\windows\etdrv.sys [14.1.2012 16:47 17488]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [29.6.2012 9:00 22344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [23.6.2012 22:44 113120]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2.8.2005 23:10 32512]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [1.9.2010 10:30 15544]
S3 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [14.10.2011 8:01 994360]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [30.3.2012 11:37 33552]
S4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
S4 ADExchange;ArcSoft Exchange Service;c:\program files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [16.9.2011 20:13 39528]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [29.6.2012 9:00 654408]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.12.2011 0:09 477240]
S4 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?]
.
.
------- Doplňkový sken -------
.
mSearch Bar = hxxp://www.google.com/ie
LSP: c:\program files\NetLimiter\nl_lsp.dll
FF - ProfilePath - c:\documents and settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-10 11:51
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'lsass.exe'(756)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(3132)
c:\windows\system32\guard32.dll
c:\windows\system32\webcheck.dll
.
- - - - - - - > 'csrss.exe'(656)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\windows\system32\JulaPan.Exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2012-07-10 11:52:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-07-10 09:52
ComboFix2.txt 2012-07-09 19:30
ComboFix3.txt 2012-06-30 23:35
.
Před spuštěním: Volných bajtů: 42 851 028 992
Po spuštění: Volných bajtů: 42 831 159 296
.
- - End Of File - - F5189DE77064E9E93FEA187855236436
ComboFix 12-07-08.02 - Inna 10.07.2012 11:44:02.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3582.3022 [GMT 2:00]
Spuštěný z: c:\documents and settings\Inna\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Inna\Plocha\CFScript.txt
AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
FILE ::
"c:\documents and settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\searchplugins\askcom.xml"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Nakažená kopie c:\windows\system32\drivers\tcpip.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-06-10 do 2012-07-10 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-29 17:30 . 2011-12-14 22:09 477240 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-06-27 09:53 . 2012-03-31 13:21 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-27 09:53 . 2011-12-14 06:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-26 19:24 . 2012-06-26 19:23 4375385 ----a-w- c:\windows\REGBK00.ZIP
2012-06-04 15:35 . 2011-12-14 03:18 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-04 15:35 . 2009-08-06 18:23 222448 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 13:19 . 2011-12-14 04:20 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2011-12-14 04:20 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2011-12-14 03:18 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2011-12-14 03:18 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2011-12-14 04:20 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2011-12-14 04:20 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2011-12-14 03:18 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2011-12-14 03:18 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2006-03-02 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2011-12-14 03:18 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2011-12-14 03:18 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 13:19 . 2012-01-18 14:57 17648 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 13:18 . 2012-01-18 14:57 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-05-31 13:22 . 2006-03-02 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2006-03-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:55 . 2006-03-02 12:00 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:44 . 2006-03-02 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2006-03-02 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-03-02 12:00 385024 ------w- c:\windows\system32\html.iec
2012-05-05 03:14 . 2006-03-02 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2004-08-17 15:45 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-04 17:29 . 2012-01-02 10:19 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-02 13:46 . 2011-12-14 03:17 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-24 22:34 . 2012-06-23 20:44 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-30_23.28.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-10 09:49 . 2012-07-10 09:49 16384 c:\windows\temp\Perflib_Perfdata_514.dat
- 2011-02-19 21:03 . 2011-02-19 21:03 51024 c:\windows\system32\vcomp100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 51024 c:\windows\system32\vcomp100.dll
+ 2009-06-30 14:36 . 2009-06-30 14:36 93184 c:\windows\system32\spool\drivers\w32x86\3\CSD_IRIVER_PLUS4_DRV.DLL
+ 2012-07-10 07:03 . 2012-07-10 07:02 82432 c:\windows\system32\msxml4r.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 81744 c:\windows\system32\mfcm100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 81744 c:\windows\system32\mfcm100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 60752 c:\windows\system32\mfc100rus.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 43344 c:\windows\system32\mfc100kor.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 43344 c:\windows\system32\mfc100kor.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 62288 c:\windows\system32\mfc100ita.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100cht.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 36176 c:\windows\system32\mfc100chs.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 36176 c:\windows\system32\mfc100chs.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100fra.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 64336 c:\windows\system32\mfc100fra.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 63824 c:\windows\system32\mfc100esn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 63824 c:\windows\system32\mfc100esn.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 55120 c:\windows\system32\mfc100enu.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 55120 c:\windows\system32\mfc100enu.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 64336 c:\windows\system32\mfc100deu.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 64336 c:\windows\system32\mfc100deu.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 40960 c:\windows\system32\MAMACExtract.dll
+ 2008-12-24 13:22 . 2010-02-11 00:48 14727 c:\windows\system32\drivers\D7.sys
+ 2008-10-09 15:13 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D35.SYS
+ 2009-01-19 17:39 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D31.sys
+ 2008-06-26 15:48 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D28.sys
+ 2009-07-15 14:33 . 2010-02-11 00:48 14729 c:\windows\system32\drivers\D150.sys
+ 2009-03-26 07:45 . 2010-02-11 00:48 14728 c:\windows\system32\drivers\D100.sys
+ 2011-12-14 03:18 . 2012-06-02 13:19 35864 c:\windows\system32\dllcache\wups.dll
+ 2012-07-10 07:03 . 2012-07-10 07:02 77824 c:\windows\system32\csdlocalmon.dll
+ 2009-06-30 13:31 . 2009-06-30 13:31 53248 c:\windows\system32\csd_iriver_plus4_lib.dll
+ 2009-06-30 14:13 . 2009-06-30 14:13 69632 c:\windows\system32\CSD_IRIVER_PLUS4_GEN.DLL
+ 2011-12-14 03:20 . 2012-07-01 10:57 76487 c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2011-12-14 03:20 . 2011-12-14 03:20 76487 c:\windows\pchealth\helpctr\OfflineCache\index.dat
+ 2012-07-10 07:05 . 2012-07-10 07:05 25728 c:\windows\MetaUSBDriver\Meta\i386\metaadb.sys
+ 2012-07-10 07:05 . 2012-07-10 07:05 31744 c:\windows\MetaUSBDriver\Meta\amd64\metaadb.sys
+ 2012-07-10 07:03 . 2012-07-10 07:03 65536 c:\windows\Installer\{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}\IRiverShortCut2_4BCC38153EEE40BBB5CB6AFE3A13AFD4.exe
+ 2012-07-10 07:03 . 2012-07-10 07:03 65536 c:\windows\Installer\{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}\IRiverShortCut1_83CAD25F27EF41FFA9AB9C9F0F65F2C7.exe
+ 2011-12-14 03:20 . 2012-07-01 10:57 2378 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2011-12-14 03:20 . 2012-07-01 10:57 8972 c:\windows\pchealth\helpctr\Config\Cntstore.bin
+ 2011-12-14 06:36 . 2008-03-13 04:52 761344 c:\windows\system32\spool\drivers\w32x86\3\UNIRES.DLL
+ 2011-12-14 06:36 . 2008-07-06 12:06 744960 c:\windows\system32\spool\drivers\w32x86\3\UNIDRVUI.DLL
+ 2011-12-14 06:36 . 2008-07-06 12:06 373248 c:\windows\system32\spool\drivers\w32x86\3\UNIDRV.DLL
+ 2009-05-15 09:20 . 2009-05-15 09:20 159744 c:\windows\system32\nbirv4svr.exe
+ 2009-05-15 09:20 . 2009-05-15 09:20 135168 c:\windows\system32\nbirv4src.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 258048 c:\windows\system32\nbirv4ogf.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 360448 c:\windows\system32\nbirv4ctl.dll
+ 2009-05-15 09:20 . 2009-05-15 09:20 118784 c:\windows\system32\nbirv4aef.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 773968 c:\windows\system32\msvcr100.dll
- 2011-02-18 22:40 . 2011-02-18 22:40 773968 c:\windows\system32\msvcr100.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 421200 c:\windows\system32\msvcp100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 421200 c:\windows\system32\msvcp100.dll
+ 2006-03-02 12:00 . 2008-06-20 11:59 361600 c:\windows\system32\drivers\tcpip.sys
- 2006-03-02 12:00 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys
+ 2011-12-14 03:18 . 2012-06-02 13:19 577048 c:\windows\system32\dllcache\wuapi.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 138056 c:\windows\system32\atl100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 138056 c:\windows\system32\atl100.dll
+ 2012-07-10 07:05 . 2012-07-10 07:05 238408 c:\windows\MetaUSBDriver\Meta\Uninstall.exe
+ 2012-07-10 07:05 . 2012-07-10 07:05 107136 c:\windows\MetaUSBDriver\Meta\i386\metaumsg.sys
+ 2012-07-10 07:05 . 2012-07-10 07:05 121856 c:\windows\MetaUSBDriver\Meta\amd64\metaumsg.sys
+ 2012-07-10 07:03 . 2012-07-10 07:03 110592 c:\windows\Installer\{5E7F8D38-6FFF-424E-B68B-354ACA64B91C}\ARPPRODUCTICON.exe
+ 2012-07-10 07:03 . 2012-07-10 07:02 1286152 c:\windows\system32\msxml4.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 4422992 c:\windows\system32\mfc100u.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 4422992 c:\windows\system32\mfc100u.dll
+ 2011-06-10 23:58 . 2011-06-10 23:58 4397384 c:\windows\system32\mfc100.dll
- 2011-02-19 21:03 . 2011-02-19 21:03 4397384 c:\windows\system32\mfc100.dll
+ 2012-07-10 07:05 . 2012-07-10 07:05 1419232 c:\windows\MetaUSBDriver\Meta\i386\WdfCoInstaller01005.dll
+ 2012-07-10 07:05 . 2012-07-10 07:05 1919968 c:\windows\MetaUSBDriver\Meta\amd64\WdfCoInstaller01005.dll
+ 2011-06-28 19:27 . 2011-06-28 19:27 4028928 c:\windows\Installer\427a0.msp
+ 2012-07-10 07:03 . 2012-07-10 07:03 4800512 c:\windows\Installer\3097e7.msi
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JulaPan"="JulaPan.Exe" [2008-06-24 421888]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-12-05 98304]
"combofix"="c:\combofix\CF27077.3XE" [2012-07-10 390144]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\AutorunsDisabled
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-10-14 291896]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\36X Raid Configurer]
2007-11-19 03:28 1966080 ------r- c:\windows\system32\xRaidSetup.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALCMTR.EXE]
2008-06-19 08:20 57344 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ------r- c:\windows\alcwzrd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyTuneVI]
2007-07-26 14:05 20480 ----a-w- c:\program files\GIGABYTE\ET6\ETcall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2012-05-22 06:13 980920 ----a-w- c:\progra~1\Eraser\Eraser.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
2007-03-20 06:36 36864 ------r- c:\windows\RaidTool\xInsIDE.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetLimiter]
2004-03-31 13:23 823296 ----a-w- c:\program files\NetLimiter\NetLimiter.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-07-23 08:51 16804864 ------r- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ------r- c:\windows\SoundMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThreatFire]
2010-01-14 14:08 378128 ----a-w- c:\program files\ThreatFire\TFTray.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\nbirv4svr.exe"=
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [25.3.2012 17:49 28552]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [30.3.2012 11:37 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [30.3.2012 11:37 59664]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [7.10.2011 19:48 494968]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.10.2011 19:48 31704]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [13.2.2012 13:28 100368]
R3 JULA_01;Service for Juli@ 1;c:\windows\system32\drivers\JulaWdm.sys [24.6.2008 11:21 22912]
R3 JULA_AA;Service for Juli@ Audio Driver (EWDM);c:\windows\system32\drivers\Jula.sys [24.6.2008 11:20 29600]
R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [14.12.2011 6:17 60255]
R3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [14.12.2011 6:17 549421]
S3 etdrv;etdrv;c:\windows\etdrv.sys [14.1.2012 16:47 17488]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [29.6.2012 9:00 22344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [23.6.2012 22:44 113120]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2.8.2005 23:10 32512]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [1.9.2010 10:30 15544]
S3 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\psia.exe [14.10.2011 8:01 994360]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [30.3.2012 11:37 33552]
S4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
S4 ADExchange;ArcSoft Exchange Service;c:\program files\Common Files\ArcSoft\esinter\Bin\eservutil.exe [16.9.2011 20:13 39528]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [29.6.2012 9:00 654408]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [15.12.2011 0:09 477240]
S4 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?]
.
.
------- Doplňkový sken -------
.
mSearch Bar = hxxp://www.google.com/ie
LSP: c:\program files\NetLimiter\nl_lsp.dll
FF - ProfilePath - c:\documents and settings\Inna\Data aplikací\Mozilla\Firefox\Profiles\se8ddhvg.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-10 11:51
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'lsass.exe'(756)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(3132)
c:\windows\system32\guard32.dll
c:\windows\system32\webcheck.dll
.
- - - - - - - > 'csrss.exe'(656)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
c:\windows\system32\JulaPan.Exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2012-07-10 11:52:55 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-07-10 09:52
ComboFix2.txt 2012-07-09 19:30
ComboFix3.txt 2012-06-30 23:35
.
Před spuštěním: Volných bajtů: 42 851 028 992
Po spuštění: Volných bajtů: 42 831 159 296
.
- - End Of File - - F5189DE77064E9E93FEA187855236436