Dobry Den
Tu je novy log z oprav v combofixe>
ComboFix 11-08-03.03 - Stanley Basta . 08. 2011 22:01:15.17.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.421.1033.18.2047.1511 [GMT 2:00]
Running from: c:\documents and settings\Stanley Basta\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Stanley Basta\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Disabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
file zipped: c:\windows\000213_.tmp
file zipped: c:\windows\002469_.tmp
file zipped: c:\windows\002679_.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Stanley Basta\WINDOWS
c:\windows\000213_.tmp
c:\windows\002469_.tmp
c:\windows\002679_.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-07-03 to 2011-08-03 )))))))))))))))))))))))))))))))
.
.
2011-08-03 19:16 . 1998-07-17 11:36 140800 ----a-w- c:\windows\system32\tm20dec.ax
2011-08-03 19:05 . 2011-08-03 19:18 -------- d-----w- c:\program files\Final Fantasy VII
2011-08-03 15:56 . 2002-06-06 12:38 139264 ----a-w- c:\windows\system32\eax.dll
2011-08-02 20:57 . 2011-08-03 16:04 -------- d-----w- c:\program files\Mafia
2011-08-02 20:50 . 2002-08-29 17:33 319488 ----a-r- c:\windows\system32\MafiaSetup.exe
2011-08-02 18:35 . 2011-08-02 18:41 -------- d-----w- c:\program files\Common Files\InterVideo
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-07-23 18:42 . 2011-07-23 18:42 131072 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-07-23 18:42 . 2011-07-23 18:42 -------- d-----w- c:\program files\QuickTime
2011-07-23 18:41 . 2011-07-23 18:41 -------- d-----w- c:\program files\Apple Software Update
2011-07-23 18:41 . 2011-07-23 18:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-07-23 18:41 . 2011-07-23 18:41 -------- d-----w- c:\program files\Common Files\Ulead
2011-07-23 18:40 . 2011-07-23 18:40 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2011-07-21 23:06 . 2004-08-03 22:56 2897920 ------w- c:\windows\system32\xpsp2res.dll
2011-07-18 22:00 . 2011-07-18 22:00 -------- d-----w- c:\documents and settings\Stanley Basta\Application Data\Malwarebytes
2011-07-18 22:00 . 2011-07-18 22:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-07-18 21:42 . 2011-07-18 21:42 -------- d-----w- c:\program files\MSXML 4.0
2011-07-18 17:02 . 2011-07-18 17:04 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2011-07-18 16:36 . 2011-07-18 16:36 -------- d-----w- c:\program files\MSXML 6.0
2011-07-18 16:27 . 2011-07-18 16:27 -------- d-----r- C:\AHCache
2011-07-18 14:58 . 2011-07-18 14:58 -------- d-----w- c:\documents and settings\Stanley Basta\Application Data\Corel
2011-07-18 14:58 . 2011-07-18 15:13 88 --sh--r- c:\documents and settings\All Users\Application Data\3B71C8433D.sys
2011-07-18 14:58 . 2011-07-18 15:13 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2011-07-18 14:55 . 2011-07-18 15:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel
2011-07-17 20:54 . 2011-07-17 20:33 77859 ----a-w- c:\windows\wnaspi32.dll
2011-07-17 18:34 . 2011-07-17 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-07-17 18:20 . 2011-07-22 18:02 -------- d-----w- c:\program files\K-Lite Codec Pack
2011-07-17 18:14 . 2011-07-17 20:33 77859 ----a-w- c:\windows\system32\wnaspi32.dll
2011-07-17 13:12 . 2004-08-03 22:56 218112 ----a-w- c:\windows\system32\wbem\wmiprvse.exe
2011-07-17 12:03 . 2004-08-03 22:56 221184 ----a-w- c:\windows\system32\wmpns.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-03 16:04 . 2001-08-23 12:00 11376 ----a-w- c:\windows\system32\drivers\secdrv.sys
2011-07-31 16:21 . 2011-05-16 17:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-21 10:04 . 2011-01-12 16:12 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-08-03_16.22.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-03 20:05 . 2011-08-03 20:05 16384 c:\windows\temp\Perflib_Perfdata_244.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\reset]
regedit [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-03 22:56 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-03 22:56 1667584 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-01 13:57 282624 ----a-w- c:\program files\QuickTime\qttask.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Documents and Settings\\Stanley Basta\\Desktop\\utorrent.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
.
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14. 5. 2009 15:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14. 5. 2009 15:49 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14. 5. 2009 15:47 731840]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
S4 AMService;AMService;c:\windows\TEMP\modx\setup.exe run --> c:\windows\TEMP\modx\setup.exe run [?]
S4 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [23. 9. 2010 9:51 247608]
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 12:21]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 85.237.225.250 213.151.200.30 213.151.208.161 213.151.200.31 213.151.208.162
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Final Fantasy VII - c:\program files\Final Fantasy VII\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-03 22:05
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(1796)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-08-03 22:07:48 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-03 20:07
ComboFix2.txt 2011-08-03 19:00
ComboFix3.txt 2011-07-20 21:22
ComboFix4.txt 2011-07-18 20:55
ComboFix5.txt 2011-08-03 20:00
.
Pre-Run: 27 779 039 232 bytes free
Post-Run: 27 765 641 216 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 814A3BCC4FC49C477B532E08113C4E5D
Upload was successful