Re: Prosím o kontrolu logu
Napsal: 13 bře 2013 10:33
Všetko prebehlo hladko, tu je log :
ComboFix 13-03-11.01 - Ferko 13.03.2013 10:16:19.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.2038.1295 [GMT 1:00]
Running from: c:\documents and settings\Ferko\Plocha\ComboFix.exe
Command switches used :: c:\documents and settings\Ferko\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1645522239-1957994488-682003330-1003.job"
"c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1645522239-1957994488-682003330-1003.job"
.
.
((((((((((((((((((((((((( Files Created from 2013-02-13 to 2013-03-13 )))))))))))))))))))))))))))))))
.
.
2013-03-12 15:16 . 2008-01-09 19:16 56976 ----a-w- c:\windows\system32\O2Icon_2.dll
2013-03-12 15:16 . 2013-03-12 15:16 -------- d-----w- c:\windows\system32\SDA
2013-03-12 15:16 . 2013-03-12 15:16 -------- d-----w- c:\program files\O2Micro Flash Memory Card Driver
2013-03-12 15:11 . 2010-02-25 00:39 675840 ----a-w- c:\windows\system32\NETwLc32.dll
2013-03-12 15:11 . 2010-10-07 12:11 6609920 ----a-w- c:\windows\system32\drivers\NETwLx32.sys
2013-03-12 15:11 . 2010-02-25 00:37 2756608 ----a-w- c:\windows\system32\NETwLr32.dll
2013-03-12 14:58 . 2013-03-12 14:58 -------- d-----w- c:\program files\Synaptics
2013-03-12 14:58 . 2011-09-14 23:11 1048576 ----a-w- c:\windows\system32\syndata.bin
2013-03-12 14:57 . 2012-08-28 23:04 175416 ----a-w- c:\windows\system32\SynTPAPI.dll
2013-03-12 14:57 . 2012-08-28 23:04 142648 ----a-w- c:\windows\system32\SynTPCo14.dll
2013-03-12 14:57 . 2012-08-28 23:04 535864 ----a-w- c:\windows\system32\SynCOM.dll
2013-03-12 14:57 . 2012-08-28 23:04 342712 ----a-w- c:\windows\system32\drivers\SynTP.sys
2013-03-12 14:51 . 2013-03-12 14:57 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DriverGenius
2013-03-12 14:50 . 2013-03-12 14:50 -------- d-----w- c:\program files\Driver-Soft
2013-03-08 16:59 . 2013-03-08 17:02 -------- d-----w- c:\program files\Euro Truck Simulator 2
2013-03-04 21:10 . 2013-03-04 21:10 -------- d-----w- C:\rsit
2013-03-01 21:48 . 2013-03-01 21:48 -------- d-----w- c:\documents and settings\Ferko\Data aplikací\RealNetworks
2013-03-01 21:47 . 2013-03-01 21:47 -------- d-----w- c:\program files\RealNetworks
2013-03-01 21:47 . 2013-03-01 21:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\RealNetworks
2013-03-01 21:46 . 2013-03-01 21:46 -------- d-----w- c:\program files\Common Files\xing shared
2013-02-19 07:39 . 2013-02-19 07:39 -------- d-----w- c:\documents and settings\Administrator
2013-02-17 21:04 . 2013-02-17 21:04 512 ----a-w- C:\PhysicalMBR.bin
2013-02-16 15:05 . 2013-02-16 15:05 -------- d-----w- c:\documents and settings\Ferko\Data aplikací\Malwarebytes
2013-02-16 15:05 . 2013-02-16 15:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-02-16 15:05 . 2013-02-16 15:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-16 15:05 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-15 22:04 . 2013-02-15 22:04 208448 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2013-02-15 07:01 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-15 07:01 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-15 07:01 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-15 07:01 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-15 07:01 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-15 07:01 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-15 07:01 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-15 07:01 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-15 07:00 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-02-15 07:00 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-02-15 07:00 . 2013-02-15 07:00 -------- d-----w- c:\program files\AVAST Software
2013-02-15 07:00 . 2013-02-15 07:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2013-02-13 06:00 . 2013-02-13 06:00 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 06:00 . 2011-01-26 10:07 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-13 06:00 . 2012-10-24 18:47 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-13 06:00 . 2011-01-26 10:07 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-09 11:00 . 2012-04-09 06:13 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-09 11:00 . 2011-05-22 15:16 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-26 03:55 . 2004-08-17 13:49 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-07 07:26 . 2004-08-17 13:45 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 07:26 . 2004-08-17 15:45 2029568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 10:10 . 2004-08-17 13:44 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2004-08-17 13:49 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2004-08-17 13:49 1294848 ----a-w- c:\windows\system32\quartz.dll
2012-12-26 20:37 . 2004-08-17 13:49 832512 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:37 . 2004-08-17 13:49 1830912 ------w- c:\windows\system32\inetcpl.cpl
2012-12-26 20:37 . 2004-08-17 13:49 78336 ------w- c:\windows\system32\ieencode.dll
2012-12-26 20:37 . 2004-08-17 13:49 17408 ------w- c:\windows\system32\corpol.dll
2012-12-16 12:23 . 2004-08-17 13:48 290560 ----a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-25 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-25 137752]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2008-05-09 1773568]
"ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2006-08-03 639040]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2005-07-07 135168]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2009-09-21 1392640]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-09-21 1206544]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-12-16 4375032]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-12-16 962128]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-12-16 165144]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2011-04-01 80840]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2012-08-28 2350392]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2013-03-01 295072]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
2008-11-11 13:33 184320 ----a-w- c:\windows\system32\FpWinlogonNp.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2006-08-03 01:20 188482 ----a-w- c:\windows\system32\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Acrobat Speed Launcher"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"OrderReminder"=c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"NokiaMusic FastStart"="c:\program files\Nokia\Nokia Music Player\NokiaMusicPlayer.exe" /command:faststart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AC3Filter\\ac3config.exe"=
"c:\\Documents and Settings\\Ferko\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 7\\PCSuite.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.7\\ICQ.exe"=
"%windir%\explorer.exe"= %windir%\explorer.exe
"c:\\Documents and Settings\\Ferko\\Local Settings\\Data aplikací\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [20.2.2006 16:01 29056]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.2.2011 13:10 717296]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [4.9.2007 0:14 6528]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [15.2.2013 8:01 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [15.2.2013 8:01 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15.2.2013 8:01 21256]
R2 Authentec memory manager;Authentec memory manager service;system32\TAMSvr.exe --> system32\TAMSvr.exe [?]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [29.11.2012 20:31 38608]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [1.2.2008 12:18 732160]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [12.3.2013 16:11 6609920]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [27.2.2006 15:00 48472]
R3 QIOMem;Generic IO & Memory Access;c:\windows\system32\drivers\QIOMem.sys [29.5.2007 9:01 6912]
S2 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [11.11.2008 14:33 151552]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [12.11.2011 15:34 137472]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [12.11.2011 15:34 8576]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 13:37 517096]
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-11 08:58]
.
2013-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-11 08:58]
.
2013-03-13 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1645522239-1957994488-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-03-13 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1645522239-1957994488-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Previesť cieľ odkazu do formátu Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Previesť do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Pridať cieľ odkazu do existujúceho súboru PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Pridať do existujúceho súboru PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Ferko\Data aplikací\Mozilla\Firefox\Profiles\l744lzug.default\
FF - ExtSQL: 2013-02-15 08:00; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Driver Genius - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-13 10:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SynTPEnh = %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1876)
c:\windows\system32\FpWinLogonNp.dll
c:\windows\system32\LgNotify.dll
.
- - - - - - - > 'explorer.exe'(3480)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\TAMSvr.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Java\jre7\bin\jqs.exe
d:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2013-03-13 10:31:19 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-13 09:31
ComboFix2.txt 2013-03-12 11:10
.
Pre-Run: Volných bajtů: 29 869 334 528
Post-Run: Volných bajtů: 29 851 144 192
.
- - End Of File - - 07E862DB14856B41FDDC6AE356456780
ComboFix 13-03-11.01 - Ferko 13.03.2013 10:16:19.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.2038.1295 [GMT 1:00]
Running from: c:\documents and settings\Ferko\Plocha\ComboFix.exe
Command switches used :: c:\documents and settings\Ferko\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1645522239-1957994488-682003330-1003.job"
"c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1645522239-1957994488-682003330-1003.job"
.
.
((((((((((((((((((((((((( Files Created from 2013-02-13 to 2013-03-13 )))))))))))))))))))))))))))))))
.
.
2013-03-12 15:16 . 2008-01-09 19:16 56976 ----a-w- c:\windows\system32\O2Icon_2.dll
2013-03-12 15:16 . 2013-03-12 15:16 -------- d-----w- c:\windows\system32\SDA
2013-03-12 15:16 . 2013-03-12 15:16 -------- d-----w- c:\program files\O2Micro Flash Memory Card Driver
2013-03-12 15:11 . 2010-02-25 00:39 675840 ----a-w- c:\windows\system32\NETwLc32.dll
2013-03-12 15:11 . 2010-10-07 12:11 6609920 ----a-w- c:\windows\system32\drivers\NETwLx32.sys
2013-03-12 15:11 . 2010-02-25 00:37 2756608 ----a-w- c:\windows\system32\NETwLr32.dll
2013-03-12 14:58 . 2013-03-12 14:58 -------- d-----w- c:\program files\Synaptics
2013-03-12 14:58 . 2011-09-14 23:11 1048576 ----a-w- c:\windows\system32\syndata.bin
2013-03-12 14:57 . 2012-08-28 23:04 175416 ----a-w- c:\windows\system32\SynTPAPI.dll
2013-03-12 14:57 . 2012-08-28 23:04 142648 ----a-w- c:\windows\system32\SynTPCo14.dll
2013-03-12 14:57 . 2012-08-28 23:04 535864 ----a-w- c:\windows\system32\SynCOM.dll
2013-03-12 14:57 . 2012-08-28 23:04 342712 ----a-w- c:\windows\system32\drivers\SynTP.sys
2013-03-12 14:51 . 2013-03-12 14:57 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DriverGenius
2013-03-12 14:50 . 2013-03-12 14:50 -------- d-----w- c:\program files\Driver-Soft
2013-03-08 16:59 . 2013-03-08 17:02 -------- d-----w- c:\program files\Euro Truck Simulator 2
2013-03-04 21:10 . 2013-03-04 21:10 -------- d-----w- C:\rsit
2013-03-01 21:48 . 2013-03-01 21:48 -------- d-----w- c:\documents and settings\Ferko\Data aplikací\RealNetworks
2013-03-01 21:47 . 2013-03-01 21:47 -------- d-----w- c:\program files\RealNetworks
2013-03-01 21:47 . 2013-03-01 21:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\RealNetworks
2013-03-01 21:46 . 2013-03-01 21:46 -------- d-----w- c:\program files\Common Files\xing shared
2013-02-19 07:39 . 2013-02-19 07:39 -------- d-----w- c:\documents and settings\Administrator
2013-02-17 21:04 . 2013-02-17 21:04 512 ----a-w- C:\PhysicalMBR.bin
2013-02-16 15:05 . 2013-02-16 15:05 -------- d-----w- c:\documents and settings\Ferko\Data aplikací\Malwarebytes
2013-02-16 15:05 . 2013-02-16 15:05 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-02-16 15:05 . 2013-02-16 15:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-16 15:05 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-15 22:04 . 2013-02-15 22:04 208448 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2013-02-15 07:01 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-15 07:01 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-15 07:01 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-02-15 07:01 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-15 07:01 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-15 07:01 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2013-02-15 07:01 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2013-02-15 07:01 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2013-02-15 07:00 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2013-02-15 07:00 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-02-15 07:00 . 2013-02-15 07:00 -------- d-----w- c:\program files\AVAST Software
2013-02-15 07:00 . 2013-02-15 07:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2013-02-13 06:00 . 2013-02-13 06:00 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-13 06:00 . 2011-01-26 10:07 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-13 06:00 . 2012-10-24 18:47 861088 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-13 06:00 . 2011-01-26 10:07 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-09 11:00 . 2012-04-09 06:13 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-09 11:00 . 2011-05-22 15:16 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-26 03:55 . 2004-08-17 13:49 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-07 07:26 . 2004-08-17 13:45 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 07:26 . 2004-08-17 15:45 2029568 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 10:10 . 2004-08-17 13:44 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2004-08-17 13:49 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2004-08-17 13:49 1294848 ----a-w- c:\windows\system32\quartz.dll
2012-12-26 20:37 . 2004-08-17 13:49 832512 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:37 . 2004-08-17 13:49 1830912 ------w- c:\windows\system32\inetcpl.cpl
2012-12-26 20:37 . 2004-08-17 13:49 78336 ------w- c:\windows\system32\ieencode.dll
2012-12-26 20:37 . 2004-08-17 13:49 17408 ------w- c:\windows\system32\corpol.dll
2012-12-16 12:23 . 2004-08-17 13:48 290560 ----a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-25 141848]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-25 137752]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2008-05-09 1773568]
"ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2006-08-03 639040]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2005-07-07 135168]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2009-09-21 1392640]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-09-21 1206544]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-12-16 4375032]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-12-16 962128]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-12-16 165144]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2011-04-01 80840]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2012-08-28 2350392]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2013-03-01 295072]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
2008-11-11 13:33 184320 ----a-w- c:\windows\system32\FpWinlogonNp.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2006-08-03 01:20 188482 ----a-w- c:\windows\system32\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Acrobat Speed Launcher"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"OrderReminder"=c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
"NokiaMusic FastStart"="c:\program files\Nokia\Nokia Music Player\NokiaMusicPlayer.exe" /command:faststart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AC3Filter\\ac3config.exe"=
"c:\\Documents and Settings\\Ferko\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 7\\PCSuite.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.7\\ICQ.exe"=
"%windir%\explorer.exe"= %windir%\explorer.exe
"c:\\Documents and Settings\\Ferko\\Local Settings\\Data aplikací\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [20.2.2006 16:01 29056]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.2.2011 13:10 717296]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [4.9.2007 0:14 6528]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [15.2.2013 8:01 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [15.2.2013 8:01 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [15.2.2013 8:01 21256]
R2 Authentec memory manager;Authentec memory manager service;system32\TAMSvr.exe --> system32\TAMSvr.exe [?]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [29.11.2012 20:31 38608]
R3 CnxtHdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDAud.sys [1.2.2008 12:18 732160]
R3 NETwLx32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [12.3.2013 16:11 6609920]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [27.2.2006 15:00 48472]
R3 QIOMem;Generic IO & Memory Access;c:\windows\system32\drivers\QIOMem.sys [29.5.2007 9:01 6912]
S2 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [11.11.2008 14:33 151552]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [12.11.2011 15:34 137472]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [12.11.2011 15:34 8576]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 13:37 517096]
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-11 08:58]
.
2013-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-11 08:58]
.
2013-03-13 c:\windows\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1645522239-1957994488-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
2013-03-13 c:\windows\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1645522239-1957994488-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-11-30 14:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.sk/
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Previesť cieľ odkazu do formátu Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Previesť do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Pridať cieľ odkazu do existujúceho súboru PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Pridať do existujúceho súboru PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Ferko\Data aplikací\Mozilla\Firefox\Profiles\l744lzug.default\
FF - ExtSQL: 2013-02-15 08:00; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Driver Genius - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-03-13 10:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SynTPEnh = %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1876)
c:\windows\system32\FpWinLogonNp.dll
c:\windows\system32\LgNotify.dll
.
- - - - - - - > 'explorer.exe'(3480)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\TAMSvr.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Java\jre7\bin\jqs.exe
d:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2013-03-13 10:31:19 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-13 09:31
ComboFix2.txt 2013-03-12 11:10
.
Pre-Run: Volných bajtů: 29 869 334 528
Post-Run: Volných bajtů: 29 851 144 192
.
- - End Of File - - 07E862DB14856B41FDDC6AE356456780