Dobry den prajem. Ziadam Vas o pomoc s mojim pocitacom lebo neustale viac a viac seka (mechanicky som ho cistil). Uz som ho kontroloval cez spybota, spyware terminator, avasta, CCleaner ,ale nic nepomaha. Taktiez mi prestaly uplne ist niektore hry. Predom Vam dakujem za pomoc.
Tu je log z RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Jozef at 2010-12-10 21:26:20
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 6 GB (15%) free of 40 GB
Total RAM: 2559 MB (77% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:26, on 2010-12-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\II\tunesi\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
E:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ICQ7.2\ICQ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jozef.JOZEF\Desktop\RSIT(2).exe
C:\Program Files\trend micro\Jozef.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://facebook.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.forumswatcher.com/search.htm
O2 - BHO: freevideomaster Toolbar - {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files\freevideomaster\tbfre2.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll
O3 - Toolbar: freevideomaster Toolbar - {01dfd24d-73eb-497f-8dfd-7ea79365af4a} - C:\Program Files\freevideomaster\tbfre2.dll
O3 - Toolbar: Sopcast Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "D:\II\tunesi\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {89F434A7-4A49-4394-AC02-007480331AE2} (NetmarbleSystemIDInfo Class) - http://download.netmarble.net/ActiveX/N ... .0.0.1.cab
O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_v1004 Class) - http://www.netgame.com/mplugin/mglaunch_USAv1005.cab
O16 - DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} (GlbNetmarbleWebMessenger Class) - http://nmweb.cdn.global.netmarble.com/M ... senger.cab
O16 - DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} (glbNMDownloadCtrl Class) - http://nmweb.cdn.global.netmarble.com/M ... loader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9EFCD7D1-3D1D-4730-A761-0A18FEE2255C}: NameServer = 80.87.208.29 80.87.208.166
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - E:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe
--
End of file - 7926 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
freevideomaster Toolbar - C:\Program Files\freevideomaster\tbfre2.dll [2010-10-18 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
MHTBPos00 Class - C:\Program Files\Family Toolbar\tbcore3.dll [2009-05-07 2642432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2008-07-16 1266992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-10-18 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Sopcast Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-17 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-07-17 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2008-07-16 1266992]
{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - Family Toolbar - C:\Program Files\Family Toolbar\tbcore3.dll [2009-05-07 2642432]
{01dfd24d-73eb-497f-8dfd-7ea79365af4a} - freevideomaster Toolbar - C:\Program Files\freevideomaster\tbfre2.dll [2010-10-18 3908192]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Sopcast Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-09-28 1400712]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2007-04-16 577536]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-09-07 2838912]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-09-08 421888]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-09 98304]
"iTunesHelper"=D:\II\tunesi\iTunesHelper.exe [2010-11-17 421160]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2008-07-07 167936]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
C:\WINDOWS\INSTAL~1\{322BC~1\ICON1F~1.EXE [2009-03-01 10752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-07-10 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"E:\buvkove hlúposti\Hry\RPG\Allods Online\bin\Launcher.exe"="E:\buvkove hlúposti\Hry\RPG\Allods Online\bin\Launcher.exe:*:Enabled:Allods Launcher"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ"
"E:\buvkove hlúposti\Programy\torrenty\utorrent.exe"="E:\buvkove hlúposti\Programy\torrenty\utorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\SJLabs\SJphone\SJphone.exe"="C:\Program Files\SJLabs\SJphone\SJphone.exe:*:Disabled:SJphone"
"D:\TV sport\StreamTorrent 1.0\StreamTorrent.exe"="D:\TV sport\StreamTorrent 1.0\StreamTorrent.exe:*:Enabled:StreamTorrent Media Player"
"E:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\Garena.exe"="E:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\Garena.exe:*:Disabled:Garena"
"C:\Documents and Settings\Jozef.JOZEF\Games\Tom Clancy's H.A.W.X\HAWX.exe"="C:\Documents and Settings\Jozef.JOZEF\Games\Tom Clancy's H.A.W.X\HAWX.exe:*:Enabled:Tom_Clancy's_H.A.W.X_1"
"C:\Documents and Settings\Jozef.JOZEF\Games\Tom Clancy's H.A.W.X\HAWX_dx10.exe"="C:\Documents and Settings\Jozef.JOZEF\Games\Tom Clancy's H.A.W.X\HAWX_dx10.exe:*:Enabled:Tom_Clancy's_H.A.W.X_2"
"E:\buvkove hlúposti\Hry\Akčné\Tom Clancy's H.A.W.X\HAWX.exe"="E:\buvkove hlúposti\Hry\Akčné\Tom Clancy's H.A.W.X\HAWX.exe:*:Disabled:HAWX"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe"="C:\Nexon\NEXON_EU_Downloader\NEXON_EU_Downloader_Engine.exe:*:Enabled:NEXON_EU_Downloader_Engine"
"E:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\Ranked Gaming Client\rgc.exe"="E:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\Ranked Gaming Client\rgc.exe:*:Disabled:rgc"
"E:\buvkove hlúposti\Hry\RPG\BLC\Binary\BloodlineChampionsLoader.exe"="E:\buvkove hlúposti\Hry\RPG\BLC\Binary\BloodlineChampionsLoader.exe:*:Disabled:BloodlineChampionsLoader"
"E:\buvkove hlúposti\Hry\Stratégie\LoL\air\LolClient.exe"="E:\buvkove hlúposti\Hry\Stratégie\LoL\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"E:\buvkove hlúposti\Hry\Stratégie\LoL\game\League of Legends.exe"="E:\buvkove hlúposti\Hry\Stratégie\LoL\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"E:\buvkove hlúposti\Hry\RPG\BF\Bootstrapper.exe"="E:\buvkove hlúposti\Hry\RPG\BF\Bootstrapper.exe:*:Enabled:BattleForge™ Launcher"
"E:\buvkove hlúposti\Hry\RPG\BF\BattleForge.exe"="E:\buvkove hlúposti\Hry\RPG\BF\BattleForge.exe:*:Enabled:BattleForge™"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Disabled:bittorrent"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Disabled:BitLord"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\buvkove hlúposti\Programy\Spyware Terminator\SpywareTerminatorUpdate.exe"="E:\buvkove hlúposti\Programy\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Disabled:Spyware Terminator Update Support"
"D:\II\tunesi\iTunes.exe"="D:\II\tunesi\iTunes.exe:*:Enabled:iTunes"
"E:\buvkove hlúposti\Hry\Stratégie\LoL\lol.launcher.exe"="E:\buvkove hlúposti\Hry\Stratégie\LoL\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"E:\buvkove hlúposti\Hry\RPG\League of Legends\lol.launcher.exe"="E:\buvkove hlúposti\Hry\RPG\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"E:\buvkove hlúposti\Hry\RPG\League of Legends\air\LolClient.exe"="E:\buvkove hlúposti\Hry\RPG\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"E:\buvkove hlúposti\Hry\RPG\League of Legends\game\League of Legends.exe"="E:\buvkove hlúposti\Hry\RPG\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"E:\buvkove hlúposti\Hry\Stratégie\Riot Games\League of Legends\lol.launcher.exe"="E:\buvkove hlúposti\Hry\Stratégie\Riot Games\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"E:\buvkove hlúposti\Hry\Stratégie\Riot Games\League of Legends\air\LolClient.exe"="E:\buvkove hlúposti\Hry\Stratégie\Riot Games\League of Legends\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"E:\buvkove hlúposti\Hry\Stratégie\Riot Games\League of Legends\game\League of Legends.exe"="E:\buvkove hlúposti\Hry\Stratégie\Riot Games\League of Legends\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"E:\buvkove hlúposti\Hry\RPG\lol\air\LolClient.exe"="E:\buvkove hlúposti\Hry\RPG\lol\air\LolClient.exe:*:Enabled:League of Legends Lobby"
"E:\buvkove hlúposti\Hry\RPG\lol\game\League of Legends.exe"="E:\buvkove hlúposti\Hry\RPG\lol\game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Disabled:Java(TM) Platform SE binary"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\buvkove hlúposti\Hry\Exteel\System\Exteel.exe"="E:\buvkove hlúposti\Hry\Exteel\System\Exteel.exe:*:Enabled:Exteel"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2010-12-06 15:46:18 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 01:29:21 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-04 17:02:13 ----A---- C:\WINDOWS\Vxopib.exe
2010-12-04 15:28:49 ----A---- C:\WINDOWS\Vxopia.exe
2010-12-04 11:22:05 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 10:44:17 ----D---- C:\Program Files\Babylon
2010-12-03 18:50:30 ----D---- C:\Program Files\Common Files\FreeCause
2010-12-02 09:13:21 ----D---- C:\Program Files\iPod
2010-11-27 23:57:03 ----A---- C:\WINDOWS\PEV.exe
2010-11-27 23:57:03 ----A---- C:\WINDOWS\MBR.exe
2010-11-27 23:48:11 ----A---- C:\WINDOWS\system32\CF25050.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\zip.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\SWSC.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\SWREG.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\sed.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\NIRCMD.exe
2010-11-27 23:35:16 ----A---- C:\WINDOWS\grep.exe
2010-11-27 23:33:57 ----A---- C:\WINDOWS\system32\CF22189.exe
2010-11-27 23:33:13 ----D---- C:\Qoobox
2010-11-27 19:14:54 ----D---- C:\Program Files\trend micro
2010-11-27 18:28:19 ----A---- C:\WINDOWS\system32\drivers\vtquinntnyti.sys
2010-11-27 16:57:20 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2010-11-27 16:57:10 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 16:56:46 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 12:31:46 ----D---- C:\WINDOWS\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 09:56:50 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\HandBrake
2010-11-14 21:29:18 ----D---- C:\Program Files\ConduitEngine
2010-11-14 21:29:18 ----A---- C:\WINDOWS\system32\ConduitEngine.tmp
======List of files/folders modified in the last 1 months======
2010-12-10 21:14:05 ----D---- C:\Program Files\Common Files\Akamai
2010-12-10 20:28:38 ----D---- C:\WINDOWS\Temp
2010-12-10 20:23:39 ----D---- C:\Program Files\Mozilla Firefox
2010-12-10 20:12:56 ----D---- C:\WINDOWS
2010-12-10 14:36:02 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-12-10 13:26:38 ----D---- C:\WINDOWS\system32\config
2010-12-10 12:22:23 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\ICQ
2010-12-10 11:10:57 ----D---- C:\WINDOWS\system32
2010-12-10 01:16:23 ----D---- C:\WINDOWS\system32\CatRoot2
2010-12-10 00:38:54 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\uTorrent
2010-12-09 15:46:15 ----SHD---- C:\WINDOWS\Installer
2010-12-09 15:46:15 ----HD---- C:\Config.Msi
2010-12-09 15:46:11 ----D---- C:\WINDOWS\WinSxS
2010-12-07 21:28:35 ----D---- C:\Program Files\Pando Networks
2010-12-07 20:21:45 ----D---- C:\WINDOWS\Prefetch
2010-12-07 17:46:04 ----D---- C:\WINDOWS\system32\DirectX
2010-12-07 17:46:03 ----HD---- C:\WINDOWS\inf
2010-12-07 17:26:12 ----HD---- C:\Program Files\InstallShield Installation Information
2010-12-07 17:23:45 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-12-07 17:23:35 ----D---- C:\WINDOWS\Debug
2010-12-07 17:21:53 ----D---- C:\Program Files\Common Files
2010-12-07 17:21:53 ----D---- C:\Program Files\Adobe
2010-12-06 21:55:54 ----D---- C:\WINDOWS\Logs
2010-12-06 20:57:14 ----D---- C:\Program Files\Internet Explorer
2010-12-06 20:55:08 ----D---- C:\WINDOWS\system32\en-us
2010-12-06 20:55:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-12-06 01:27:47 ----D---- C:\WINDOWS\system32\drivers
2010-12-06 00:00:12 ----SD---- C:\WINDOWS\Tasks
2010-12-05 23:00:57 ----D---- C:\Program Files\Winamp
2010-12-05 22:34:40 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\Mumble
2010-12-05 19:02:21 ----RD---- C:\Program Files
2010-12-05 18:31:55 ----D---- C:\temp
2010-12-04 11:58:51 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\Media Player Classic
2010-12-04 09:56:03 ----D---- C:\WINDOWS\pss
2010-12-02 09:13:20 ----D---- C:\Program Files\Common Files\Apple
2010-12-02 09:09:11 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-12-02 09:09:11 ----D---- C:\WINDOWS\system32\CatRoot
2010-11-29 15:44:31 ----D---- C:\Documents and Settings
2010-11-28 13:39:40 ----D---- C:\Program Files\SpeedFan
2010-11-27 23:33:58 ----D---- C:\WINDOWS\ERDNT
2010-11-27 22:55:02 ----D---- C:\WINDOWS\Minidump
2010-11-27 13:36:15 ----D---- C:\WINDOWS\system32\drivers\etc
2010-11-27 12:31:33 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-11-27 12:06:04 ----D---- C:\Program Files\Enigma Software Group
2010-11-24 20:31:10 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\Skype
2010-11-24 20:07:13 ----D---- C:\Documents and Settings\Jozef.JOZEF\Application Data\skypePM
2010-11-20 18:24:38 ----RSD---- C:\WINDOWS\assembly
2010-11-20 18:24:35 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-11-14 21:29:14 ----D---- C:\Program Files\freevideomaster
2010-11-11 08:56:19 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-09-07 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-09-07 165584]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-09-07 46672]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-07-07 56108]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2008-12-25 5632]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-09-07 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-09-07 100176]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-04-25 4030144]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-09-07 23376]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-07-10 4407808]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-06 49920]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-06 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-06 21568]
R3 LCcfltr;Logitech USB Filter Driver; C:\WINDOWS\System32\Drivers\LCcFltr.Sys [2002-11-08 14156]
R3 LHidUsb;Logitech USB Receiver device driver; C:\WINDOWS\System32\Drivers\LHidUsb.Sys [2002-11-08 41420]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 RT2400;Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2400.sys [2003-08-01 50432]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 WMIBIOS;%WMIBIOS.ServiceName%; C:\WINDOWS\System32\Drivers\wmibios.sys [2002-10-15 18272]
R3 WMIINFO;WMIINFO Driver; C:\WINDOWS\System32\Drivers\wmiinfo.sys [2002-05-13 21184]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Gigabit Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\yukonwxp.sys [2003-12-23 174464]
S2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys []
S2 npkcrypt;npkcrypt; \??\E:\buvkove hlúposti\Hry\RPG\Maple Story\npkcrypt.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\D:\II\tunesi\converter\free3\MediaCoder\SysInfo.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp []
S3 GGSAFERDriver;GGSAFER Driver; \??\E:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys []
S3 huadio;huadio; \??\c:\huadio.tmp []
S3 itchfltr;iTouch Keyboard Filter; C:\WINDOWS\System32\Drivers\itchfltr.sys [2002-11-15 12640]
S3 Mkd2kfNt;Mkd2kfNt; C:\WINDOWS\system32\drivers\Mkd2kfNt.sys [2008-10-17 131072]
S3 Mkd2Nadr;Mkd2Nadr; C:\WINDOWS\system32\drivers\Mkd2Nadr.sys [2008-10-17 79104]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-06-25 35088]
S3 npkcusb;npkcusb; \??\E:\buvkove hlúposti\Hry\RPG\Maple Story\npkcusb.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2010-09-28 41984]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 XDva276;XDva276; \??\C:\WINDOWS\system32\XDva276.sys []
S3 XDva296;XDva296; \??\C:\WINDOWS\system32\XDva296.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-10-14 717296]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Akamai;Akamai NetSession Interface; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-10-16 37664]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-07-10 602112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-07-27 345376]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; E:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe [2010-11-27 496128]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-09-07 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-11-17 820008]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-07-09 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2010-09-08 3992184]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2010-06-25 117264]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 vtquinntnyti;vtquinntnyti; C:\WINDOWS\system32\drivers\vtquinntnyti.sys [2010-11-27 8576]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Strasne mi rube komp
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Rudy
- Site Admin
- Příspěvky: 119429
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Strasne mi rube komp
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Strasne mi rube komp
ComboFix 10-12-09.04 - Jozef 2010-12-10 22:29:28.5.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.2559.2001 [GMT 1:00]
Running from: c:\documents and settings\Jozef.JOZEF\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jozef.JOZEF\Desktop\[Torrentsworld.net] - (PSP) NBA Live 10 (decrypted and working on GEN-B2) [ResourceRg Games by KloWn].torrent
c:\documents and settings\Jozef.JOZEF\My Documents\cc_20101127_230055.reg
c:\documents and settings\Jozef.JOZEF\My Documents\cc_20101127_230702.reg
c:\windows\system32\drivers\vtquinntnyti.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Legacy_vtquinntnyti
-------\Service_vtquinntnyti
((((((((((((((((((((((((( Files Created from 2010-11-10 to 2010-12-10 )))))))))))))))))))))))))))))))
.
2010-12-10 20:36 . 2010-12-10 21:33 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\PMB Files
2010-12-10 20:35 . 2010-12-10 20:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-12-06 14:46 . 2010-12-10 14:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 00:29 . 2010-12-06 00:29 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-05 22:15 . 2010-12-10 19:23 555104 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2010-12-04 16:02 . 2010-12-04 14:30 257024 ----a-w- c:\windows\Vxopib.exe
2010-12-04 14:28 . 2010-12-04 14:28 257024 ----a-w- c:\windows\Vxopia.exe
2010-12-04 10:22 . 2010-12-04 10:22 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 09:44 . 2010-08-08 11:46 142336 ----a-w- c:\program files\Mozilla Firefox\BabyFox.dll
2010-12-04 09:44 . 2010-12-04 09:44 -------- d-----w- c:\program files\Babylon
2010-12-03 17:50 . 2010-12-04 11:16 -------- d-----w- c:\program files\Common Files\FreeCause
2010-12-02 08:13 . 2010-12-02 08:13 -------- d-----w- c:\program files\iPod
2010-11-29 14:44 . 2010-11-29 14:46 -------- d-----w- c:\documents and settings\Administrator.JOZEF
2010-11-27 22:48 . 2010-11-27 22:47 389120 ----a-w- c:\windows\system32\CF25050.exe
2010-11-27 22:33 . 2010-11-27 22:33 389120 ----a-w- c:\windows\system32\CF22189.exe
2010-11-27 18:14 . 2010-12-10 20:26 -------- d-----w- c:\program files\trend micro
2010-11-27 15:57 . 2010-11-27 15:57 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-11-27 15:57 . 2010-12-05 22:17 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 15:56 . 2010-12-05 22:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 11:31 . 2010-11-27 17:37 -------- d-----w- c:\windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\HandBrake
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\HandBrake
2010-11-14 20:29 . 2010-11-14 21:35 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 -------- d-----w- c:\program files\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 14:44 . 2009-07-02 12:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2009-07-02 12:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-18 10:23 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\freevideomaster\tbfre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 20:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01dfd24d-73eb-497f-8dfd-7ea79365af4a}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-09 98304]
"iTunesHelper"="d:\ii\tunesi\iTunesHelper.exe" [2010-11-17 421160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\SJphone.lnk
backup=c:\windows\pss\SJphone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\buvkove hlúposti\\Hry\\RPG\\Allods Online\\bin\\Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\buvkove hlúposti\\Programy\\torrenty\\utorrent.exe"=
"c:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"d:\\TV sport\\StreamTorrent 1.0\\StreamTorrent.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\GG\\Garena\\Garena.exe"=
"e:\\buvkove hlúposti\\Hry\\Akčné\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\Ranked Gaming Client\\rgc.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\Bootstrapper.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\BattleForge.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\buvkove hlúposti\\Programy\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"d:\\II\\tunesi\\iTunes.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\lol\\air\\LolClient.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\lol\\game\\League of Legends.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"8370:TCP"= 8370:TCP:League of Legends Launcher
"8370:UDP"= 8370:UDP:League of Legends Launcher
"8372:TCP"= 8372:TCP:League of Legends Launcher
"8372:UDP"= 8372:UDP:League of Legends Launcher
"58469:TCP"= 58469:TCP:Pando Media Booster
"58469:UDP"= 58469:UDP:Pando Media Booster
"57968:TCP"= 57968:TCP:Pando Media Booster
"57968:UDP"= 57968:UDP:Pando Media Booster
"8376:TCP"= 8376:TCP:League of Legends Launcher
"8376:UDP"= 8376:UDP:League of Legends Launcher
"8377:TCP"= 8377:TCP:League of Legends Launcher
"8377:UDP"= 8377:UDP:League of Legends Launcher
"8378:TCP"= 8378:TCP:League of Legends Launcher
"8378:UDP"= 8378:UDP:League of Legends Launcher
"8394:TCP"= 8394:TCP:League of Legends Launcher
"8394:UDP"= 8394:UDP:League of Legends Launcher
"8379:TCP"= 8379:TCP:League of Legends Launcher
"8379:UDP"= 8379:UDP:League of Legends Launcher
"6899:TCP"= 6899:TCP:League of Legends Launcher
"6899:UDP"= 6899:UDP:League of Legends Launcher
"6995:TCP"= 6995:TCP:League of Legends Launcher
"6995:UDP"= 6995:UDP:League of Legends Launcher
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"6937:TCP"= 6937:TCP:League of Legends Launcher
"6937:UDP"= 6937:UDP:League of Legends Launcher
"6917:TCP"= 6917:TCP:League of Legends Launcher
"6917:UDP"= 6917:UDP:League of Legends Launcher
"6961:TCP"= 6961:TCP:League of Legends Launcher
"6961:UDP"= 6961:UDP:League of Legends Launcher
"6920:TCP"= 6920:TCP:League of Legends Launcher
"6920:UDP"= 6920:UDP:League of Legends Launcher
"6952:TCP"= 6952:TCP:League of Legends Launcher
"6952:UDP"= 6952:UDP:League of Legends Launcher
"6992:TCP"= 6992:TCP:League of Legends Launcher
"6992:UDP"= 6992:UDP:League of Legends Launcher
"6929:TCP"= 6929:TCP:League of Legends Launcher
"6929:UDP"= 6929:UDP:League of Legends Launcher
"6906:TCP"= 6906:TCP:League of Legends Launcher
"6906:UDP"= 6906:UDP:League of Legends Launcher
"6957:TCP"= 6957:TCP:League of Legends Launcher
"6957:UDP"= 6957:UDP:League of Legends Launcher
"6955:TCP"= 6955:TCP:League of Legends Launcher
"6955:UDP"= 6955:UDP:League of Legends Launcher
"6970:TCP"= 6970:TCP:League of Legends Launcher
"6970:UDP"= 6970:UDP:League of Legends Launcher
"6946:TCP"= 6946:TCP:League of Legends Launcher
"6946:UDP"= 6946:UDP:League of Legends Launcher
"6898:TCP"= 6898:TCP:League of Legends Launcher
"6898:UDP"= 6898:UDP:League of Legends Launcher
"6936:TCP"= 6936:TCP:League of Legends Launcher
"6936:UDP"= 6936:UDP:League of Legends Launcher
"6886:TCP"= 6886:TCP:League of Legends Launcher
"6886:UDP"= 6886:UDP:League of Legends Launcher
"1044:TCP"= 1044:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"56690:TCP"= 56690:TCP:Pando Media Booster
"56690:UDP"= 56690:UDP:Pando Media Booster
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-05-11 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-11-27 142592]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [2006-02-28 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-05-11 17744]
R3 RT2400;Wireless Driver;c:\windows\system32\drivers\RT2400.sys [2006-09-27 50432]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2008-09-18 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2008-09-18 21184]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp --> c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys --> e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys [?]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 itchfltr;iTouch Keyboard Filter;c:\windows\system32\drivers\itchfltr.sys [2009-04-12 12640]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-18 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-18 79104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 XDva276;XDva276;\??\c:\windows\system32\XDva276.sys --> c:\windows\system32\XDva276.sys [?]
S3 XDva296;XDva296;\??\c:\windows\system32\XDva296.sys --> c:\windows\system32\XDva296.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-10-14 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-10 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 20:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://facebook.com/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: {9EFCD7D1-3D1D-4730-A761-0A18FEE2255C} = 80.87.208.29 80.87.208.166
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNMWebMessenger.cab
DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNetmarbleDownloader.cab
FF - ProfilePath - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxps://www1.dsidata.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15000&locale=en_EU&apn_uid=&apn_ptnrs=PV&apn_sauid=&apn_dtid=&q=
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: d:\ii\tunesi\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Sopcast Ask Toolbar: toolbar@ask.com - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\toolbar@ask.com
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
AddRemove-Grand Theft Auto - d:\ostatné\gta\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-10 22:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2456)
c:\windows\system32\WININET.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
e:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe
c:\windows\SOUNDMAN.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2010-12-10 22:50:36 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-10 21:50
ComboFix2.txt 2009-12-20 21:38
Pre-Run: 6,461,743,104 bytes free
Post-Run: 6,403,592,192 voľných bajtov
- - End Of File - - D5F4A65BA6D427F341AD5AED9EAC6B21
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.2559.2001 [GMT 1:00]
Running from: c:\documents and settings\Jozef.JOZEF\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jozef.JOZEF\Desktop\[Torrentsworld.net] - (PSP) NBA Live 10 (decrypted and working on GEN-B2) [ResourceRg Games by KloWn].torrent
c:\documents and settings\Jozef.JOZEF\My Documents\cc_20101127_230055.reg
c:\documents and settings\Jozef.JOZEF\My Documents\cc_20101127_230702.reg
c:\windows\system32\drivers\vtquinntnyti.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Legacy_vtquinntnyti
-------\Service_vtquinntnyti
((((((((((((((((((((((((( Files Created from 2010-11-10 to 2010-12-10 )))))))))))))))))))))))))))))))
.
2010-12-10 20:36 . 2010-12-10 21:33 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\PMB Files
2010-12-10 20:35 . 2010-12-10 20:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-12-06 14:46 . 2010-12-10 14:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 00:29 . 2010-12-06 00:29 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-05 22:15 . 2010-12-10 19:23 555104 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2010-12-04 16:02 . 2010-12-04 14:30 257024 ----a-w- c:\windows\Vxopib.exe
2010-12-04 14:28 . 2010-12-04 14:28 257024 ----a-w- c:\windows\Vxopia.exe
2010-12-04 10:22 . 2010-12-04 10:22 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 09:44 . 2010-08-08 11:46 142336 ----a-w- c:\program files\Mozilla Firefox\BabyFox.dll
2010-12-04 09:44 . 2010-12-04 09:44 -------- d-----w- c:\program files\Babylon
2010-12-03 17:50 . 2010-12-04 11:16 -------- d-----w- c:\program files\Common Files\FreeCause
2010-12-02 08:13 . 2010-12-02 08:13 -------- d-----w- c:\program files\iPod
2010-11-29 14:44 . 2010-11-29 14:46 -------- d-----w- c:\documents and settings\Administrator.JOZEF
2010-11-27 22:48 . 2010-11-27 22:47 389120 ----a-w- c:\windows\system32\CF25050.exe
2010-11-27 22:33 . 2010-11-27 22:33 389120 ----a-w- c:\windows\system32\CF22189.exe
2010-11-27 18:14 . 2010-12-10 20:26 -------- d-----w- c:\program files\trend micro
2010-11-27 15:57 . 2010-11-27 15:57 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-11-27 15:57 . 2010-12-05 22:17 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 15:56 . 2010-12-05 22:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 11:31 . 2010-11-27 17:37 -------- d-----w- c:\windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\HandBrake
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\HandBrake
2010-11-14 20:29 . 2010-11-14 21:35 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 -------- d-----w- c:\program files\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 14:44 . 2009-07-02 12:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2009-07-02 12:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-18 10:23 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\freevideomaster\tbfre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 20:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01dfd24d-73eb-497f-8dfd-7ea79365af4a}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-09 98304]
"iTunesHelper"="d:\ii\tunesi\iTunesHelper.exe" [2010-11-17 421160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\SJphone.lnk
backup=c:\windows\pss\SJphone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\buvkove hlúposti\\Hry\\RPG\\Allods Online\\bin\\Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\buvkove hlúposti\\Programy\\torrenty\\utorrent.exe"=
"c:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"d:\\TV sport\\StreamTorrent 1.0\\StreamTorrent.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\GG\\Garena\\Garena.exe"=
"e:\\buvkove hlúposti\\Hry\\Akčné\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\Ranked Gaming Client\\rgc.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\Bootstrapper.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\BattleForge.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\buvkove hlúposti\\Programy\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"d:\\II\\tunesi\\iTunes.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\lol\\air\\LolClient.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\lol\\game\\League of Legends.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"8370:TCP"= 8370:TCP:League of Legends Launcher
"8370:UDP"= 8370:UDP:League of Legends Launcher
"8372:TCP"= 8372:TCP:League of Legends Launcher
"8372:UDP"= 8372:UDP:League of Legends Launcher
"58469:TCP"= 58469:TCP:Pando Media Booster
"58469:UDP"= 58469:UDP:Pando Media Booster
"57968:TCP"= 57968:TCP:Pando Media Booster
"57968:UDP"= 57968:UDP:Pando Media Booster
"8376:TCP"= 8376:TCP:League of Legends Launcher
"8376:UDP"= 8376:UDP:League of Legends Launcher
"8377:TCP"= 8377:TCP:League of Legends Launcher
"8377:UDP"= 8377:UDP:League of Legends Launcher
"8378:TCP"= 8378:TCP:League of Legends Launcher
"8378:UDP"= 8378:UDP:League of Legends Launcher
"8394:TCP"= 8394:TCP:League of Legends Launcher
"8394:UDP"= 8394:UDP:League of Legends Launcher
"8379:TCP"= 8379:TCP:League of Legends Launcher
"8379:UDP"= 8379:UDP:League of Legends Launcher
"6899:TCP"= 6899:TCP:League of Legends Launcher
"6899:UDP"= 6899:UDP:League of Legends Launcher
"6995:TCP"= 6995:TCP:League of Legends Launcher
"6995:UDP"= 6995:UDP:League of Legends Launcher
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"6937:TCP"= 6937:TCP:League of Legends Launcher
"6937:UDP"= 6937:UDP:League of Legends Launcher
"6917:TCP"= 6917:TCP:League of Legends Launcher
"6917:UDP"= 6917:UDP:League of Legends Launcher
"6961:TCP"= 6961:TCP:League of Legends Launcher
"6961:UDP"= 6961:UDP:League of Legends Launcher
"6920:TCP"= 6920:TCP:League of Legends Launcher
"6920:UDP"= 6920:UDP:League of Legends Launcher
"6952:TCP"= 6952:TCP:League of Legends Launcher
"6952:UDP"= 6952:UDP:League of Legends Launcher
"6992:TCP"= 6992:TCP:League of Legends Launcher
"6992:UDP"= 6992:UDP:League of Legends Launcher
"6929:TCP"= 6929:TCP:League of Legends Launcher
"6929:UDP"= 6929:UDP:League of Legends Launcher
"6906:TCP"= 6906:TCP:League of Legends Launcher
"6906:UDP"= 6906:UDP:League of Legends Launcher
"6957:TCP"= 6957:TCP:League of Legends Launcher
"6957:UDP"= 6957:UDP:League of Legends Launcher
"6955:TCP"= 6955:TCP:League of Legends Launcher
"6955:UDP"= 6955:UDP:League of Legends Launcher
"6970:TCP"= 6970:TCP:League of Legends Launcher
"6970:UDP"= 6970:UDP:League of Legends Launcher
"6946:TCP"= 6946:TCP:League of Legends Launcher
"6946:UDP"= 6946:UDP:League of Legends Launcher
"6898:TCP"= 6898:TCP:League of Legends Launcher
"6898:UDP"= 6898:UDP:League of Legends Launcher
"6936:TCP"= 6936:TCP:League of Legends Launcher
"6936:UDP"= 6936:UDP:League of Legends Launcher
"6886:TCP"= 6886:TCP:League of Legends Launcher
"6886:UDP"= 6886:UDP:League of Legends Launcher
"1044:TCP"= 1044:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"56690:TCP"= 56690:TCP:Pando Media Booster
"56690:UDP"= 56690:UDP:Pando Media Booster
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-05-11 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-11-27 142592]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [2006-02-28 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-05-11 17744]
R3 RT2400;Wireless Driver;c:\windows\system32\drivers\RT2400.sys [2006-09-27 50432]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2008-09-18 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2008-09-18 21184]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp --> c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys --> e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys [?]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 itchfltr;iTouch Keyboard Filter;c:\windows\system32\drivers\itchfltr.sys [2009-04-12 12640]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-18 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-18 79104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 XDva276;XDva276;\??\c:\windows\system32\XDva276.sys --> c:\windows\system32\XDva276.sys [?]
S3 XDva296;XDva296;\??\c:\windows\system32\XDva296.sys --> c:\windows\system32\XDva296.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-10-14 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-10 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 20:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://facebook.com/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: {9EFCD7D1-3D1D-4730-A761-0A18FEE2255C} = 80.87.208.29 80.87.208.166
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNMWebMessenger.cab
DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNetmarbleDownloader.cab
FF - ProfilePath - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxps://www1.dsidata.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15000&locale=en_EU&apn_uid=&apn_ptnrs=PV&apn_sauid=&apn_dtid=&q=
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: d:\ii\tunesi\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Sopcast Ask Toolbar: toolbar@ask.com - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\toolbar@ask.com
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
AddRemove-Grand Theft Auto - d:\ostatné\gta\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-10 22:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2456)
c:\windows\system32\WININET.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
e:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe
c:\windows\SOUNDMAN.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2010-12-10 22:50:36 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-10 21:50
ComboFix2.txt 2009-12-20 21:38
Pre-Run: 6,461,743,104 bytes free
Post-Run: 6,403,592,192 voľných bajtov
- - End Of File - - D5F4A65BA6D427F341AD5AED9EAC6B21
- Rudy
- Site Admin
- Příspěvky: 119429
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Strasne mi rube komp
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:

Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.KillAll::
Collect::
c:\windows\Vxopib.exe
c:\windows\Vxopia.exe
c:\windows\system32\XDva276.sys
c:\windows\system32\XDva296.sys
Driver::
Akamai
XDva276
XDva296
Registry::
[-HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Strasne mi rube komp
Hmm vypada to lepsie dana hra mi uz ide a pride mi ze aj pocitac ide o poznanie lepsie...
Tu je novy log:
ComboFix 10-12-09.04 - Jozef 2010-12-11 1:59.6.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.2559.2028 [GMT 1:00]
Running from: c:\documents and settings\Jozef.JOZEF\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jozef.JOZEF\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
file zipped: c:\windows\Vxopia.exe
file zipped: c:\windows\Vxopib.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Vxopia.exe
c:\windows\Vxopib.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AKAMAI
-------\Legacy_XDVA276
-------\Legacy_XDVA296
-------\Service_Akamai
-------\Service_XDva276
-------\Service_XDva296
((((((((((((((((((((((((( Files Created from 2010-11-11 to 2010-12-11 )))))))))))))))))))))))))))))))
.
2010-12-10 22:09 . 2010-12-10 22:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-12-10 20:36 . 2010-12-10 22:30 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\PMB Files
2010-12-10 20:35 . 2010-12-10 22:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-12-06 14:46 . 2010-12-10 14:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 00:29 . 2010-12-06 00:29 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-05 22:15 . 2010-12-10 19:23 555104 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2010-12-04 10:22 . 2010-12-04 10:22 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 09:44 . 2010-08-08 11:46 142336 ----a-w- c:\program files\Mozilla Firefox\BabyFox.dll
2010-12-04 09:44 . 2010-12-04 09:44 -------- d-----w- c:\program files\Babylon
2010-12-03 17:50 . 2010-12-04 11:16 -------- d-----w- c:\program files\Common Files\FreeCause
2010-12-02 08:13 . 2010-12-02 08:13 -------- d-----w- c:\program files\iPod
2010-11-29 14:44 . 2010-11-29 14:46 -------- d-----w- c:\documents and settings\Administrator.JOZEF
2010-11-27 22:48 . 2010-11-27 22:47 389120 ----a-w- c:\windows\system32\CF25050.exe
2010-11-27 22:33 . 2010-11-27 22:33 389120 ----a-w- c:\windows\system32\CF22189.exe
2010-11-27 18:14 . 2010-12-10 20:26 -------- d-----w- c:\program files\trend micro
2010-11-27 15:57 . 2010-11-27 15:57 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-11-27 15:57 . 2010-12-05 22:17 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 15:56 . 2010-12-05 22:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 11:31 . 2010-11-27 17:37 -------- d-----w- c:\windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\HandBrake
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\HandBrake
2010-11-14 20:29 . 2010-11-14 21:35 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 -------- d-----w- c:\program files\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 14:44 . 2009-07-02 12:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2009-07-02 12:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-18 10:23 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\freevideomaster\tbfre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 20:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01dfd24d-73eb-497f-8dfd-7ea79365af4a}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-09 98304]
"iTunesHelper"="d:\ii\tunesi\iTunesHelper.exe" [2010-11-17 421160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\SJphone.lnk
backup=c:\windows\pss\SJphone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\buvkove hlúposti\\Hry\\RPG\\Allods Online\\bin\\Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\buvkove hlúposti\\Programy\\torrenty\\utorrent.exe"=
"c:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"d:\\TV sport\\StreamTorrent 1.0\\StreamTorrent.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\GG\\Garena\\Garena.exe"=
"e:\\buvkove hlúposti\\Hry\\Akčné\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\Ranked Gaming Client\\rgc.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\Bootstrapper.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\BattleForge.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\buvkove hlúposti\\Programy\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"d:\\II\\tunesi\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\air\\LolClient.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\game\\League of Legends.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-05-11 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-11-27 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-05-11 17744]
R3 RT2400;Wireless Driver;c:\windows\system32\drivers\RT2400.sys [2006-09-27 50432]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2008-09-18 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2008-09-18 21184]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp --> c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys --> e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys [?]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 itchfltr;iTouch Keyboard Filter;c:\windows\system32\drivers\itchfltr.sys [2009-04-12 12640]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-18 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-18 79104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-10-14 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-11 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 20:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://facebook.com/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: {9EFCD7D1-3D1D-4730-A761-0A18FEE2255C} = 80.87.208.29 80.87.208.166
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNMWebMessenger.cab
DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNetmarbleDownloader.cab
FF - ProfilePath - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxps://www1.dsidata.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15000&locale=en_EU&apn_uid=&apn_ptnrs=PV&apn_sauid=&apn_dtid=&q=
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: d:\ii\tunesi\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Sopcast Ask Toolbar: toolbar@ask.com - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\toolbar@ask.com
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-11 02:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3588)
c:\windows\system32\WININET.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
e:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe
c:\windows\SOUNDMAN.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-12-11 02:18:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-11 01:18
ComboFix2.txt 2010-12-10 21:50
ComboFix3.txt 2009-12-20 21:38
Pre-Run: 7,189,344,256 bytes free
Post-Run: 7,204,810,752 voľných bajtov
- - End Of File - - 07FBF73BCAE21629F115B460DEA0BF9C
Tu je novy log:
ComboFix 10-12-09.04 - Jozef 2010-12-11 1:59.6.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.2559.2028 [GMT 1:00]
Running from: c:\documents and settings\Jozef.JOZEF\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jozef.JOZEF\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
file zipped: c:\windows\Vxopia.exe
file zipped: c:\windows\Vxopib.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Vxopia.exe
c:\windows\Vxopib.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AKAMAI
-------\Legacy_XDVA276
-------\Legacy_XDVA296
-------\Service_Akamai
-------\Service_XDva276
-------\Service_XDva296
((((((((((((((((((((((((( Files Created from 2010-11-11 to 2010-12-11 )))))))))))))))))))))))))))))))
.
2010-12-10 22:09 . 2010-12-10 22:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-12-10 20:36 . 2010-12-10 22:30 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\PMB Files
2010-12-10 20:35 . 2010-12-10 22:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-12-06 14:46 . 2010-12-10 14:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 00:29 . 2010-12-06 00:29 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-05 22:15 . 2010-12-10 19:23 555104 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2010-12-04 10:22 . 2010-12-04 10:22 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 09:44 . 2010-08-08 11:46 142336 ----a-w- c:\program files\Mozilla Firefox\BabyFox.dll
2010-12-04 09:44 . 2010-12-04 09:44 -------- d-----w- c:\program files\Babylon
2010-12-03 17:50 . 2010-12-04 11:16 -------- d-----w- c:\program files\Common Files\FreeCause
2010-12-02 08:13 . 2010-12-02 08:13 -------- d-----w- c:\program files\iPod
2010-11-29 14:44 . 2010-11-29 14:46 -------- d-----w- c:\documents and settings\Administrator.JOZEF
2010-11-27 22:48 . 2010-11-27 22:47 389120 ----a-w- c:\windows\system32\CF25050.exe
2010-11-27 22:33 . 2010-11-27 22:33 389120 ----a-w- c:\windows\system32\CF22189.exe
2010-11-27 18:14 . 2010-12-10 20:26 -------- d-----w- c:\program files\trend micro
2010-11-27 15:57 . 2010-11-27 15:57 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-11-27 15:57 . 2010-12-05 22:17 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 15:56 . 2010-12-05 22:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 11:31 . 2010-11-27 17:37 -------- d-----w- c:\windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\HandBrake
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\HandBrake
2010-11-14 20:29 . 2010-11-14 21:35 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 -------- d-----w- c:\program files\ConduitEngine
2010-11-14 20:29 . 2010-11-14 20:29 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 14:44 . 2009-07-02 12:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2009-07-02 12:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-18 10:23 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\freevideomaster\tbfre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-09-28 20:44 1400712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01dfd24d-73eb-497f-8dfd-7ea79365af4a}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-09-28 1400712]
"{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-09 98304]
"iTunesHelper"="d:\ii\tunesi\iTunesHelper.exe" [2010-11-17 421160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\SJphone.lnk
backup=c:\windows\pss\SJphone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\buvkove hlúposti\\Hry\\RPG\\Allods Online\\bin\\Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\buvkove hlúposti\\Programy\\torrenty\\utorrent.exe"=
"c:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"d:\\TV sport\\StreamTorrent 1.0\\StreamTorrent.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\GG\\Garena\\Garena.exe"=
"e:\\buvkove hlúposti\\Hry\\Akčné\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\Ranked Gaming Client\\rgc.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\Bootstrapper.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\BattleForge.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\buvkove hlúposti\\Programy\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"d:\\II\\tunesi\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\air\\LolClient.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\game\\League of Legends.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-05-11 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-11-27 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-05-11 17744]
R3 RT2400;Wireless Driver;c:\windows\system32\drivers\RT2400.sys [2006-09-27 50432]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2008-09-18 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2008-09-18 21184]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp --> c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys --> e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys [?]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 itchfltr;iTouch Keyboard Filter;c:\windows\system32\drivers\itchfltr.sys [2009-04-12 12640]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-18 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-18 79104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-10-14 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-12-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-11 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-09-28 20:44]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://facebook.com/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: {9EFCD7D1-3D1D-4730-A761-0A18FEE2255C} = 80.87.208.29 80.87.208.166
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNMWebMessenger.cab
DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNetmarbleDownloader.cab
FF - ProfilePath - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxps://www1.dsidata.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15000&locale=en_EU&apn_uid=&apn_ptnrs=PV&apn_sauid=&apn_dtid=&q=
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: d:\ii\tunesi\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Sopcast Ask Toolbar: toolbar@ask.com - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\toolbar@ask.com
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-11 02:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(656)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3588)
c:\windows\system32\WININET.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
e:\buvkove hlúposti\Programy\Spyware Terminator\sp_rsser.exe
c:\windows\SOUNDMAN.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-12-11 02:18:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-11 01:18
ComboFix2.txt 2010-12-10 21:50
ComboFix3.txt 2009-12-20 21:38
Pre-Run: 7,189,344,256 bytes free
Post-Run: 7,204,810,752 voľných bajtov
- - End Of File - - 07FBF73BCAE21629F115B460DEA0BF9C
- Rudy
- Site Admin
- Příspěvky: 119429
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Strasne mi rube komp
Ještě jednou spusťte CF tímto skriptem:
Folder::
c:\program files\Ask.com
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Strasne mi rube komp
Dobře tu je nový log:
ComboFix 10-12-09.04 - Jozef 2010-12-15 21:04:33.7.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.2559.2022 [GMT 1:00]
Running from: c:\documents and settings\Jozef.JOZEF\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jozef.JOZEF\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Ask.com
c:\program files\Ask.com\cb_e3.ico
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_e2.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
.
((((((((((((((((((((((((( Files Created from 2010-11-15 to 2010-12-15 )))))))))))))))))))))))))))))))
.
2010-12-15 15:50 . 2010-12-15 15:50 -------- d-----w- c:\windows\LastGood
2010-12-12 14:06 . 2010-12-12 14:06 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-12-10 22:09 . 2010-12-10 22:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-12-10 20:36 . 2010-12-10 22:30 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\PMB Files
2010-12-10 20:35 . 2010-12-10 22:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-12-06 14:46 . 2010-12-10 14:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 00:29 . 2010-12-06 00:29 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-05 22:15 . 2010-12-10 19:23 555104 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2010-12-04 10:22 . 2010-12-04 10:22 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 09:44 . 2010-08-08 11:46 142336 ----a-w- c:\program files\Mozilla Firefox\BabyFox.dll
2010-12-04 09:44 . 2010-12-04 09:44 -------- d-----w- c:\program files\Babylon
2010-12-03 17:50 . 2010-12-04 11:16 -------- d-----w- c:\program files\Common Files\FreeCause
2010-12-02 08:13 . 2010-12-02 08:13 -------- d-----w- c:\program files\iPod
2010-11-29 14:44 . 2010-11-29 14:46 -------- d-----w- c:\documents and settings\Administrator.JOZEF
2010-11-27 22:48 . 2010-11-27 22:47 389120 ----a-w- c:\windows\system32\CF25050.exe
2010-11-27 22:33 . 2010-11-27 22:33 389120 ----a-w- c:\windows\system32\CF22189.exe
2010-11-27 18:14 . 2010-12-10 20:26 -------- d-----w- c:\program files\trend micro
2010-11-27 15:57 . 2010-11-27 15:57 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-11-27 15:57 . 2010-12-05 22:17 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 15:56 . 2010-12-05 22:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 11:31 . 2010-11-27 17:37 -------- d-----w- c:\windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\HandBrake
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\HandBrake
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-14 20:29 . 2010-11-14 20:29 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2010-09-28 14:44 . 2009-07-02 12:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2009-07-02 12:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-18 10:23 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\freevideomaster\tbfre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01dfd24d-73eb-497f-8dfd-7ea79365af4a}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-09 98304]
"iTunesHelper"="d:\ii\tunesi\iTunesHelper.exe" [2010-11-17 421160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\SJphone.lnk
backup=c:\windows\pss\SJphone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\buvkove hlúposti\\Hry\\RPG\\Allods Online\\bin\\Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\buvkove hlúposti\\Programy\\torrenty\\utorrent.exe"=
"c:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"d:\\TV sport\\StreamTorrent 1.0\\StreamTorrent.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\GG\\Garena\\Garena.exe"=
"e:\\buvkove hlúposti\\Hry\\Akčné\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\Ranked Gaming Client\\rgc.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\Bootstrapper.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\BattleForge.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"e:\\buvkove hlúposti\\Programy\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"d:\\II\\tunesi\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\air\\LolClient.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"6964:TCP"= 6964:TCP:League of Legends Launcher
"6964:UDP"= 6964:UDP:League of Legends Launcher
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-05-11 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-11-27 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-05-11 17744]
R3 RT2400;Wireless Driver;c:\windows\system32\drivers\RT2400.sys [2006-09-27 50432]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2008-09-18 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2008-09-18 21184]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp --> c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys --> e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys [?]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 itchfltr;iTouch Keyboard Filter;c:\windows\system32\drivers\itchfltr.sys [2009-04-12 12640]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-18 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-18 79104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-10-14 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://facebook.com/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: {9EFCD7D1-3D1D-4730-A761-0A18FEE2255C} = 80.87.208.29 80.87.208.166
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNMWebMessenger.cab
DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNetmarbleDownloader.cab
FF - ProfilePath - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxps://www1.dsidata.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15000&locale=en_EU&apn_uid=&apn_ptnrs=PV&apn_sauid=&apn_dtid=&q=
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: d:\ii\tunesi\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Sopcast Ask Toolbar: toolbar@ask.com - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\toolbar@ask.com
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-15 21:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-12-15 21:17:57
ComboFix-quarantined-files.txt 2010-12-15 20:17
ComboFix2.txt 2010-12-11 01:18
ComboFix3.txt 2010-12-10 21:50
ComboFix4.txt 2009-12-20 21:38
Pre-Run: 6,528,368,640 bytes free
Post-Run: 6,473,220,096 voľných bajtov
- - End Of File - - C6068A1E880AE1454A5165A18C499613
ComboFix 10-12-09.04 - Jozef 2010-12-15 21:04:33.7.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1033.18.2559.2022 [GMT 1:00]
Running from: c:\documents and settings\Jozef.JOZEF\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jozef.JOZEF\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Ask.com
c:\program files\Ask.com\cb_e3.ico
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_e2.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
.
((((((((((((((((((((((((( Files Created from 2010-11-15 to 2010-12-15 )))))))))))))))))))))))))))))))
.
2010-12-15 15:50 . 2010-12-15 15:50 -------- d-----w- c:\windows\LastGood
2010-12-12 14:06 . 2010-12-12 14:06 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-12-10 22:09 . 2010-12-10 22:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-12-10 20:36 . 2010-12-10 22:30 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\PMB Files
2010-12-10 20:35 . 2010-12-10 22:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\PMB Files
2010-12-06 14:46 . 2010-12-10 14:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\xml_param
2010-12-06 00:29 . 2010-12-06 00:29 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Digiarty
2010-12-05 22:15 . 2010-12-10 19:23 555104 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2010-12-04 10:22 . 2010-12-04 10:22 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\BabylonToolbar
2010-12-04 09:44 . 2010-08-08 11:46 142336 ----a-w- c:\program files\Mozilla Firefox\BabyFox.dll
2010-12-04 09:44 . 2010-12-04 09:44 -------- d-----w- c:\program files\Babylon
2010-12-03 17:50 . 2010-12-04 11:16 -------- d-----w- c:\program files\Common Files\FreeCause
2010-12-02 08:13 . 2010-12-02 08:13 -------- d-----w- c:\program files\iPod
2010-11-29 14:44 . 2010-11-29 14:46 -------- d-----w- c:\documents and settings\Administrator.JOZEF
2010-11-27 22:48 . 2010-11-27 22:47 389120 ----a-w- c:\windows\system32\CF25050.exe
2010-11-27 22:33 . 2010-11-27 22:33 389120 ----a-w- c:\windows\system32\CF22189.exe
2010-11-27 18:14 . 2010-12-10 20:26 -------- d-----w- c:\program files\trend micro
2010-11-27 15:57 . 2010-11-27 15:57 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-11-27 15:57 . 2010-12-05 22:17 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\Spyware Terminator
2010-11-27 15:56 . 2010-12-05 22:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spyware Terminator
2010-11-27 11:31 . 2010-11-27 17:37 -------- d-----w- c:\windows\3636C9237AD64DE3978A09609AEE8ECF.TMP
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\HandBrake
2010-11-25 08:56 . 2010-11-25 08:56 -------- d-----w- c:\documents and settings\Jozef.JOZEF\Application Data\HandBrake
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-14 20:29 . 2010-11-14 20:29 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2010-09-28 14:44 . 2009-07-02 12:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-09-28 14:44 . 2009-07-02 12:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-09-18 10:23 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2006-02-28 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2006-02-28 12:00 953856 ------w- c:\windows\system32\mfc40u.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\freevideomaster\tbfre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01dfd24d-73eb-497f-8dfd-7ea79365af4a}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
"{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}"= "c:\program files\freevideomaster\tbfre2.dll" [2010-10-18 3908192]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CLASSES_ROOT\clsid\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-09 98304]
"iTunesHelper"="d:\ii\tunesi\iTunesHelper.exe" [2010-11-17 421160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^SJphone.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\SJphone.lnk
backup=c:\windows\pss\SJphone.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-07-07 07:34 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\buvkove hlúposti\\Hry\\RPG\\Allods Online\\bin\\Launcher.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\buvkove hlúposti\\Programy\\torrenty\\utorrent.exe"=
"c:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"d:\\TV sport\\StreamTorrent 1.0\\StreamTorrent.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\GG\\Garena\\Garena.exe"=
"e:\\buvkove hlúposti\\Hry\\Akčné\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"e:\\buvkove hlúposti\\Hry\\Stratégie\\Warcrafty\\Warcraft 3FT\\Warcraft III\\Ranked Gaming Client\\rgc.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\Bootstrapper.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\BF\\BattleForge.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"e:\\buvkove hlúposti\\Programy\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"d:\\II\\tunesi\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\air\\LolClient.exe"=
"e:\\buvkove hlúposti\\Hry\\RPG\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"6964:TCP"= 6964:TCP:League of Legends Launcher
"6964:UDP"= 6964:UDP:League of Legends Launcher
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-05-11 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-11-27 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-05-11 17744]
R3 RT2400;Wireless Driver;c:\windows\system32\drivers\RT2400.sys [2006-09-27 50432]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2008-09-18 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2008-09-18 21184]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp --> c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp [?]
S3 GGSAFERDriver;GGSAFER Driver;\??\e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys --> e:\buvkove hlúposti\Hry\Stratégie\Warcrafty\Warcraft 3FT\Warcraft III\GG\Garena\safedrv.sys [?]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 itchfltr;iTouch Keyboard Filter;c:\windows\system32\drivers\itchfltr.sys [2009-04-12 12640]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [2009-11-18 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [2009-11-18 79104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2008-10-14 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-12-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004Core.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
2010-12-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-879983540-839522115-1004UA.job
- c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-12 13:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://facebook.com/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: {9EFCD7D1-3D1D-4730-A761-0A18FEE2255C} = 80.87.208.29 80.87.208.166
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNMWebMessenger.cab
DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} - hxxp://nmweb.cdn.global.netmarble.com/Messaging/GlbNetmarbleDownloader.cab
FF - ProfilePath - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=15627
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxps://www1.dsidata.sk/
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=SPC2&o=15000&locale=en_EU&apn_uid=&apn_ptnrs=PV&apn_sauid=&apn_dtid=&q=
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Jozef.JOZEF\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGPPlugin.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: d:\ii\tunesi\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Sopcast Ask Toolbar: toolbar@ask.com - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\toolbar@ask.com
FF - Extension: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Extension: SOE Web Installer: {000F1EA4-5E08-4564-A29B-29076F63A37A} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\documents and settings\Jozef.JOZEF\Application Data\Mozilla\Firefox\Profiles\sqlkys7w.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-15 21:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\JOZEF~1.JOZ\LOCALS~1\Temp\SIG369.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\huadio]
"ImagePath"="\??\c:\huadio.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-12-15 21:17:57
ComboFix-quarantined-files.txt 2010-12-15 20:17
ComboFix2.txt 2010-12-11 01:18
ComboFix3.txt 2010-12-10 21:50
ComboFix4.txt 2009-12-20 21:38
Pre-Run: 6,528,368,640 bytes free
Post-Run: 6,473,220,096 voľných bajtov
- - End Of File - - C6068A1E880AE1454A5165A18C499613
- Rudy
- Site Admin
- Příspěvky: 119429
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Strasne mi rube komp
Log již vypadá čistý. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.