ComboFix 14-02-05.02 - Asus 12.02.2014 15:04:24.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.363 [GMT 1:00]
Spuštěný z: x:\dokumenty\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Asus\Plocha\CFScript.txt.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\system32\XDva405.sys"
"c:\windows\system32\XDva406.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\msstp.vbe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA405
-------\Legacy_XDVA406
-------\Service_XDva405
-------\Service_XDva406
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-01-12 do 2014-02-12 )))))))))))))))))))))))))))))))
.
.
2014-02-12 14:15 . 2014-02-12 14:15 40392 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A52DF267-9693-4321-AF67-4CC342C24740}\MpKslf5f1cabd.sys
2014-02-10 13:02 . 2013-12-04 02:57 7760024 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A52DF267-9693-4321-AF67-4CC342C24740}\mpengine.dll
2014-02-09 11:14 . 2014-02-11 19:13 -------- d-----w- C:\Nether-World
2014-02-09 06:26 . 2013-12-04 02:57 7760024 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-02-09 06:26 . 2014-02-09 06:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Caphyon
2014-02-09 06:19 . 2014-02-11 19:49 -------- d-----w- c:\program files\QuadCoreM2
2014-02-08 21:47 . 2014-02-08 21:47 -------- d-----w- c:\documents and settings\Asus\Data aplikací\Quadcore Games
2014-02-06 21:08 . 2014-02-08 21:45 -------- d-----w- c:\documents and settings\Asus\Data aplikací\vlc
2014-02-06 16:49 . 2014-02-06 16:49 -------- d-----w- c:\program files\VideoLAN
2014-02-05 20:24 . 2014-02-07 16:25 -------- d-----w- C:\AdwCleaner
2014-02-05 15:34 . 2014-02-05 15:34 3544968 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2014-02-04 19:03 . 2014-02-04 19:03 -------- d-----w- C:\rsit
2014-01-31 18:29 . 2014-01-31 18:29 -------- d-----w- c:\program files\Sony
2014-01-31 18:08 . 2014-01-31 18:08 -------- d-----w- c:\documents and settings\Asus\Data aplikací\Sony Creative Software Inc
2014-01-31 17:05 . 2014-01-31 17:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Sony
2014-01-31 17:05 . 2014-01-31 17:05 -------- d-----w- c:\documents and settings\Asus\Data aplikací\Publish Providers
2014-01-31 17:04 . 2014-01-31 17:04 -------- d-----w- c:\documents and settings\Asus\Local Settings\Data aplikací\Sony
2014-01-31 16:24 . 2014-01-31 18:21 -------- d-----w- c:\documents and settings\Asus\Data aplikací\Sony
2014-01-29 17:35 . 2014-01-29 17:35 -------- d-----w- c:\windows\system32\AGEIA
2014-01-24 16:07 . 2014-02-06 18:35 -------- d-----w- c:\documents and settings\Asus\Data aplikací\DivX
2014-01-24 16:05 . 2014-02-06 17:23 -------- d-----w- c:\program files\Common Files\DivX Shared
2014-01-24 15:54 . 2014-02-06 17:25 -------- d-----w- c:\program files\DivX
2014-01-24 15:52 . 2014-02-06 17:25 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DivX
2014-01-23 15:28 . 2014-01-23 15:29 -------- d-----w- c:\documents and settings\Asus\Local Settings\Data aplikací\Akamai
2014-01-23 12:51 . 2014-01-31 07:28 -------- d-----w- c:\documents and settings\Asus\Local Settings\Data aplikací\Warframe
2014-01-22 17:46 . 2014-01-22 17:46 -------- d-----w- c:\windows\system32\Printing_Admin_Scripts
2014-01-22 17:38 . 2014-01-22 17:38 -------- d-----w- c:\documents and settings\Asus\Data aplikací\TunkDesign
2014-01-22 17:31 . 2014-01-22 17:31 -------- d-----w- c:\documents and settings\Asus\Data aplikací\Merver
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-05 15:35 . 2012-07-25 17:20 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-02-05 15:35 . 2012-03-22 20:02 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-01-19 07:32 . 2012-03-23 15:37 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-01-01 12:34 . 2014-01-01 12:03 19200 ----a-w- c:\windows\system32\drivers\wstcodec.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 18944 ----a-w- c:\windows\system32\drivers\wpdusb.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 12032 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 4352 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 34560 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 25471 ----a-w- c:\windows\system32\drivers\watv10nt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 22271 ----a-w- c:\windows\system32\drivers\watv06nt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 14208 ----a-w- c:\windows\system32\drivers\wacompen.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 11935 ----a-w- c:\windows\system32\drivers\wadv11nt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 11871 ----a-w- c:\windows\system32\drivers\wadv09nt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 11807 ----a-w- c:\windows\system32\drivers\wadv07nt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 11295 ----a-w- c:\windows\system32\drivers\wadv08nt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 1068216 ----a-w- c:\windows\system32\drivers\wcmvcam.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 81664 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 52480 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 42240 ----a-w- c:\windows\system32\drivers\viaagp.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 58112 ----a-w- c:\windows\system32\drivers\vdmindvd.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 26368 ----a-w- c:\windows\system32\drivers\usbstor.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 20992 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 17792 ----a-w- c:\windows\system32\drivers\vcsvad.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 17152 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 15872 ----a-w- c:\windows\system32\drivers\usbintel.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 14976 ----a-w- c:\windows\system32\drivers\usbscan.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 144128 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2014-01-01 12:34 . 2014-01-01 12:03 123008 ----a-w- c:\windows\system32\drivers\usbvideo.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 59520 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 5376 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 30336 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 25728 ----a-w- c:\windows\system32\drivers\usbcamd2.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 25600 ----a-w- c:\windows\system32\drivers\usbcamd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 66048 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 44672 ----a-w- c:\windows\system32\drivers\uagp35.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 384768 ----a-w- c:\windows\system32\drivers\update.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12928 ----a-w- c:\windows\system32\drivers\usb8023x.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12288 ----a-w- c:\windows\system32\drivers\tunmp.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 51712 ----a-w- c:\windows\system32\drivers\tosdvd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 40840 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 21896 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 21376 ----a-w- c:\windows\system32\drivers\tsbvcap.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 19072 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12040 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 361600 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 14976 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 56576 ----a-w- c:\windows\system32\drivers\swmidi.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 49408 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 4352 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 15232 ----a-w- c:\windows\system32\drivers\streamip.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12367616 ----a-w- c:\windows\system32\drivers\StkCPipe.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 73344 ----a-w- c:\windows\system32\drivers\sr.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 357888 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 1260672 ----a-w- c:\windows\system32\drivers\StkCMini.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 982272 ----a-w- c:\windows\system32\drivers\smserial.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 6272 ----a-w- c:\windows\system32\drivers\splitter.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 5888 ----a-w- c:\windows\system32\drivers\smbali.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 25344 ----a-w- c:\windows\system32\drivers\sonydcam.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 14592 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 95424 ----a-w- c:\windows\system32\drivers\slnthal.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 404990 ----a-w- c:\windows\system32\drivers\slntamr.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 13240 ----a-w- c:\windows\system32\drivers\slwdmsup.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 129535 ----a-w- c:\windows\system32\drivers\slnt7554.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 40960 ----a-w- c:\windows\system32\drivers\sisagp.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 11392 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 11136 ----a-w- c:\windows\system32\drivers\slip.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 11904 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 11008 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 10240 ----a-w- c:\windows\system32\drivers\sffp_mmc.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 64256 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 15744 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 96384 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 79232 ----a-w- c:\windows\system32\drivers\sdbus.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 34816 ----a-w- c:\windows\system32\drivers\RTSTOR.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 208600 ----a-w- c:\windows\system32\drivers\RtsUStor.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 20480 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 166912 ----a-w- c:\windows\system32\drivers\s3gnbm.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 5888 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 30592 ----a-w- c:\windows\system32\drivers\rndismpx.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 30592 ----a-w- c:\windows\system32\drivers\rndismp.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 203136 ----a-w- c:\windows\system32\drivers\rmcast.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 59136 ----a-w- c:\windows\system32\drivers\rfcomm.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 58496 ----a-w- c:\windows\system32\drivers\redbook.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 4224 ----a-w- c:\windows\system32\drivers\rdpcdd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 196224 ----a-w- c:\windows\system32\drivers\rdpdr.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 13776 ----a-w- c:\windows\system32\drivers\recagent.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12032 ----a-w- c:\windows\system32\drivers\riodrv.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 12032 ----a-w- c:\windows\system32\drivers\rio8drv.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 34432 ----a-w- c:\windows\system32\drivers\rawwan.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 175744 ----a-w- c:\windows\system32\drivers\rdbss.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 51328 ----a-w- c:\windows\system32\drivers\rasl2tp.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 48384 ----a-w- c:\windows\system32\drivers\raspptp.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 16512 ----a-w- c:\windows\system32\drivers\raspti.sys.bak
2014-01-01 12:33 . 2014-01-01 12:03 8832 ----a-w- c:\windows\system32\drivers\rasacd.sys.bak
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . D9F19E78F98834CB411D6AD3C68D181A . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2006-03-02 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\documents and settings\Asus\Local Settings\Data aplikací\Akamai\netsession_win.exe" [2013-06-05 4489472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-16 8478720]
"ATKHOTKEY"="c:\program files\ATK Hotkey\Hcontrol.exe" [2007-07-12 225280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-10-23 948440]
"RTHDCPL"="RTHDCPL.EXE" [2012-06-06 20065936]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-12-23 450560]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2013-12-31 13:07 64104 ----a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update]
2007-11-30 10:20 51768 -c--a-w- c:\program files\ASUS\ASUS Live Update\ALU.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 03:22 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2007-08-16 12:19 81920 -c--a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-08-16 12:19 1626112 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2012-06-06 13:00 20065936 ------w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2006-11-22 16:31 630784 -c--a-w- c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\Asus\\Local Settings\\Data aplikací\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\java.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.1737\\Agent.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.2045\\Agent.exe"=
"x:\\Vietcong\\Vietcong\\Play Vietcong.exe"=
"x:\\Vietcong\\Vietcong\\vcded.exe"=
"c:\\Documents and Settings\\Asus\\Data aplikací\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Documents and Settings\\Asus\\Data aplikací\\uTorrent\\updates\\3.3.1_30017.exe"=
"c:\\Documents and Settings\\Asus\\Local Settings\\Data aplikací\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"x:\\HMT2P.PvM\\HammerMT2 Server 2 v3.5\\binary.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"x:\\Counter-Strike 1.6\\Counter-Strike 1.6 Non-Steam\\hl.exe"=
"c:\\Program Files\\NCWest\\NCLauncher\\NCUpdateHelper.exe"=
"x:\\Playworld 3 2013\\Playworld3.exe"=
"x:\\WorldOfExtinction\\WolrdOfExtinction.exe"=
"c:\\Program Files\\DivX\\DivX Media Server\\DivXMediaServer.exe"=
"c:\\Program Files\\QuadCoreM2\\pack\\core.bin"=
"x:\\Nether-World\\nether-world.bin"=
"c:\\Nether-World\\nether-world.bin"=
"x:\\CelestialWorld\\mt2.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
"1039:TCP"= 1039:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 MpKslf5f1cabd;MpKslf5f1cabd;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{A52DF267-9693-4321-AF67-4CC342C24740}\MpKslf5f1cabd.sys [12.2.2014 15:15 40392]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:\windows\system32\StkCSrv.exe [22.3.2012 23:27 24576]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [13.11.2013 19:00 208600]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\system32\drivers\StkCMini.sys [22.3.2012 23:27 1260672]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [31.7.2013 18:42 17792]
S2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\wcmvcam.sys [15.4.2012 22:32 1068216]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [13.2.2013 16:01 1691480]
S3 BRDriver;BRDriver; [x]
S3 BRSptSvc;BitRaider Mini-Support Service;c:\documents and settings\All Users\Data aplikací\BitRaider\BRSptSvc.exe [5.8.2013 6:32 476936]
S3 dump_wmimmc;dump_wmimmc; [x]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 vtany;vtany; [x]
S3 WinRing0_1_2_0;WinRing0_1_2_0;x:\razer game booster\Driver\WinRing0.sys [26.12.2013 20:05 14416]
S3 xsherlock;xsherlock;c:\windows\system32\xsherlock.xem [28.4.2012 17:17 670816]
S4 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.130\McCHSvc.exe [6.9.2013 18:29 235216]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSLF5F1CABD
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 11:47 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-05 12:38 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-02-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-25 15:35]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.com
uDefault_Search_URL = hxxp://
www.google.com
mStart Page = hxxp://
www.google.com
mSearch Bar = hxxp://
www.google.com
uInternet Settings,ProxyOverride = <local>
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{a9ff5a45-b433-4940-9299-de737a9c11f6} - {0de094f5-e894-48c7-b16f-338d64674721} -
TCP: Interfaces\{F7DF02FB-297A-4668-BC96-16FA16E0FAC9}: NameServer = 109.231.191.1,109.231.191.3
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2014-02-12 15:16
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrueSight]
"ImagePath"="\??\"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xsherlock]
"ImagePath"="c:\windows\system32\xsherlock.xem"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2544)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wdfmgr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATK Hotkey\WDC.exe
.
**************************************************************************
.
Celkový čas: 2014-02-12 15:19:35 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-02-12 14:19
ComboFix2.txt 2014-02-10 19:45
.
Před spuštěním: 5 470 162 944
Po spuštění: 5 357 555 712
.
- - End Of File - - AF4317A6F2739AC61B00DE8CA062D08E
413FC2A0C716421B3158746D63736515