Posílám, co mě to vytvořilo.
ComboFix 09-05-08.03 - Vlastimil Palla 09.05.2009 9:29.2 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.247.79 [GMT 2:00]
Spuštěný z: c:\documents and settings\Vlastimil Palla\Plocha\ComboFix.exe
AV: Eset NOD32 Antivirus 2.0 *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-04-09 do 2009-05-09 )))))))))))))))))))))))))))))))
.
2011-06-18 14:58 . 2008-10-16 13:08 34328 -c--a-w c:\windows\system32\dllcache\wups.dll
2011-06-18 14:58 . 2008-10-16 13:08 34328 ----a-w c:\windows\system32\wups.dll
2011-06-18 14:43 . 2011-06-18 14:42 114688 ----a-w c:\windows\system32\nms32.dll
2011-06-18 14:43 . 2011-06-18 14:42 245760 ----a-w c:\windows\system32\imon.dll
2011-06-18 14:43 . 2011-06-18 14:42 300048 ----a-w c:\windows\system32\drivers\amon.sys
2011-06-18 14:42 . 2008-02-09 04:27 -------- d-----w c:\program files\ESET
2009-05-08 11:44 . 2009-05-08 11:44 -------- d-----w C:\_OTMoveIt
2009-05-08 08:21 . 2009-05-08 08:22 -------- d-----w C:\rsit
2009-04-26 16:04 . 2009-04-26 16:04 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-04-26 10:50 . 2009-04-26 10:50 -------- d-----w c:\program files\Media Access Startup
2009-04-26 10:49 . 2009-04-26 10:49 -------- d-----w c:\program files\Nice Prosper
2009-04-26 10:49 . 2009-04-26 10:49 -------- d-----w c:\program files\Internet Saving Optimizer
2009-04-26 10:48 . 2009-04-26 10:48 -------- d-----w c:\program files\DoubleD
2009-04-23 19:51 . 2009-04-23 19:51 0 ----a-w c:\windows\nsreg.dat
2009-04-22 11:58 . 2009-04-22 11:58 -------- d-----w c:\windows\Sun
2009-04-21 16:37 . 2009-04-26 16:04 -------- d-----w c:\program files\SUPERAntiSpyware
2009-04-15 18:02 . 2009-04-15 18:02 -------- d-----w c:\program files\CCleaner
2009-04-15 17:14 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 17:14 . 2009-03-06 14:23 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-15 17:14 . 2009-02-09 11:25 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-15 17:14 . 2009-02-09 10:56 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 17:14 . 2009-02-09 10:56 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 17:14 . 2009-02-09 10:56 684032 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 17:14 . 2009-02-09 10:56 728064 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 17:14 . 2009-02-09 10:56 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 17:14 . 2009-02-09 10:56 709632 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 17:13 . 2008-04-21 21:15 216576 -c----w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 11:13 . 2006-08-13 20:38 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-18 17:27 . 2009-03-18 15:31 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-15 18:02 . 2001-10-25 14:00 49636 ----a-w c:\windows\system32\perfc005.dat
2009-04-15 18:02 . 2001-10-25 14:00 316120 ----a-w c:\windows\system32\perfh005.dat
2009-04-11 10:18 . 2008-02-25 17:24 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-09 17:15 . 2008-05-17 08:46 -------- d-----w c:\program files\Azureus
2009-04-06 13:32 . 2009-03-18 15:31 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2009-03-18 15:31 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-30 14:44 . 2009-03-30 13:39 -------- d-----w c:\program files\CIGLER SOFTWARE
2009-03-30 14:16 . 2008-10-14 19:55 -------- d-----w c:\program files\RegCleaner
2009-03-29 11:07 . 2009-03-29 11:07 626688 ----a-w c:\windows\system32\msvcr80.dll
2009-03-29 11:07 . 2009-03-29 11:07 548864 ----a-w c:\windows\system32\msvcp80.dll
2009-03-29 11:07 . 2009-03-29 11:07 28672 ----a-w c:\windows\system32\eEmpty.exe
2009-03-11 16:00 . 2008-10-20 15:21 -------- d-----w c:\program files\ICQ6Toolbar
2009-03-10 18:41 . 2009-03-10 18:27 -------- d-----w c:\program files\ICQ6.5
2009-03-10 18:34 . 2008-10-20 15:17 -------- d-----w c:\program files\ICQ6
2009-03-06 14:23 . 2002-09-20 18:04 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-20 08:12 . 2002-09-20 18:05 667136 ----a-w c:\windows\system32\wininet.dll
2009-02-20 08:12 . 2005-06-18 13:52 81920 ------w c:\windows\system32\ieencode.dll
2009-02-10 17:09 . 2002-09-20 17:12 2068224 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:07 . 2002-09-20 17:41 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:26 . 2002-09-20 17:12 2191232 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:25 . 2001-10-25 14:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:56 . 2002-09-20 18:04 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:56 . 2002-09-20 18:04 728064 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:56 . 2002-09-20 18:03 684032 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:56 . 2002-09-20 18:03 709632 ----a-w c:\windows\system32\ntdll.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2002-03-21 67584]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-03-01 172792]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-12-14 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-12-14 118784]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2005-01-01 847872]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-02-09 65024]
"EssSpkPhone"="essspk.exe" - c:\windows\essspk.exe [2001-10-19 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 09:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave2"= serwvdrv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15.1.2009 16:17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15.1.2009 16:17 55024]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [29.8.2002 3:35 69120]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15.1.2009 16:17 7408]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - Browser
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - helpsvc
*Deregistered* - ICQ Service
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NOD32krn
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Schedule
*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - WS2IFSL
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{572BF76C-9EFF-4e1e-93DE-72EF1E91B3DF} - {DB7FBFE3-82CB-49E0-9C41-39C2A80B4966} - c:\program files\Eurotran2002i\e11.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Vlastimil Palla\Data aplikací\Mozilla\Firefox\Profiles\z83d2awu.default\
FF - prefs.js: browser.startup.homepage - hxxp://mystart.icanseek.com/seek.jsp|
http://www.seznam.cz/
FF - component: c:\program files\Internet Saving Optimizer\2.2.0.2880\FF\components\NPFFAddOn.dll
FF - component: c:\program files\Media Access Startup\1.0.0.610\FF\components\HPFFAddOn.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-09 09:43
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(520)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'lsass.exe'(576)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
- - - - - - - > 'explorer.exe'(3076)
c:\program files\CursorXP\CurXP0.dll
.
Celkový čas: 2009-05-09 9:48
ComboFix-quarantined-files.txt 2009-05-09 07:48
Před spuštěním: Volných bajtů: 34 205 618 176
Po spuštění: Volných bajtů: 34 221 731 840
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
206 --- E O F --- 2009-04-15 17:36
ROOTREPEAL (c) AD, 2007-2008
==================================================
Scan Time: 2009/05/09 10:12
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF0B1E000 Size: 98304 File Visible: No
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF9A58000 Size: 8192 File Visible: No
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEFC18000 Size: 45056 File Visible: No
Status: -
SSDT
-------------------
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xf0bfff20