ComboFix 11-11-02.01 - Administrator 02.11.2011 15:58:03.7.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.511.231 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Plocha\CFScript.txt..txt
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-02 to 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 04:09 . 2008-04-14 04:22 152064 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2011-11-02 04:09 . 2008-04-13 19:54 88192 -c--a-w- c:\windows\system32\dllcache\irda.sys
2011-11-02 04:07 . 2008-04-13 19:39 206976 -c--a-w- c:\windows\system32\dllcache\dot4.sys
2011-11-01 22:22 . 2011-11-01 22:22 -------- d-----w- C:\TDSSKiller_Quarantine
2011-11-01 21:38 . 2011-11-01 21:38 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-11-01 20:03 . 2010-11-29 16:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-01 20:03 . 2010-11-29 16:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-01 19:38 . 2011-11-01 19:39 -------- d-----w- C:\rsit
2011-11-01 14:30 . 2011-11-01 14:30 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\TuneUp Software
2011-11-01 14:28 . 2011-11-01 14:31 -------- d-----w- c:\documents and settings\All Users\Data aplikací\TuneUp Software
2011-10-31 23:15 . 2011-10-31 23:15 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\SUPERAntiSpyware.com
2011-10-31 23:14 . 2011-10-31 23:14 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2011-10-31 23:07 . 2011-10-31 23:07 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2011-10-31 23:07 . 2011-10-31 23:07 60416 ----a-w- c:\windows\ALCFDRTM.VER
2011-10-31 23:07 . 2011-10-31 23:07 -------- d-----w- c:\windows\system32\Lang
2011-10-31 21:54 . 2011-03-18 00:24 69120 ----a-w- c:\windows\system32\zlcomm.dll
2011-10-31 21:54 . 2011-03-18 00:24 104448 ----a-w- c:\windows\system32\zlcommdb.dll
2011-10-31 21:54 . 2011-03-18 00:24 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2011-10-31 21:54 . 2011-10-31 21:56 -------- d-----w- c:\windows\system32\ZoneLabs
2011-10-31 21:41 . 2011-11-02 14:51 -------- d-----w- c:\windows\Internet Logs
2011-10-30 06:11 . 2011-10-30 07:11 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Google
2011-10-29 19:31 . 2011-10-29 19:31 -------- d-----w- c:\program files\Windows Sidebar
2011-10-29 19:31 . 2011-10-30 05:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Norton
2011-10-26 07:41 . 2011-10-30 12:55 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Opera
2011-10-26 06:10 . 2011-10-26 07:23 -------- d-----w- c:\program files\Google
2011-10-25 15:47 . 2011-10-25 15:47 -------- d-----w- c:\program files\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-30 23:21 . 2011-10-30 23:18 5777519 ----a-w- c:\windows\REGBK00.ZIP
2011-10-24 21:37 . 2011-05-30 11:17 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 09:41 . 2008-07-29 18:59 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-12 12:50 . 2010-08-02 15:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-09 09:12 . 2002-09-20 18:03 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-08-22 23:41 . 2002-09-20 18:05 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:41 . 2002-09-20 18:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 23:41 . 2002-09-20 18:04 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 11:56 . 2008-07-07 14:42 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2002-08-29 02:01 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-09 13:24 . 2011-08-09 13:24 154136 ----a-w- c:\windows\system32\drivers\eamon.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-01_20.21.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-10-25 12:00 . 2008-04-14 03:21 49152 c:\windows\system32\mqupgrd.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 95744 c:\windows\system32\mqsec.dll
- 2002-09-20 18:04 . 2009-06-25 18:37 95744 c:\windows\system32\mqsec.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 16896 c:\windows\system32\mqise.dll
- 2002-09-20 18:04 . 2009-06-25 18:37 16896 c:\windows\system32\mqise.dll
+ 2001-10-25 12:00 . 2008-04-14 03:21 47616 c:\windows\system32\mqdscli.dll
+ 2001-10-25 12:00 . 2008-04-14 03:22 19968 c:\windows\system32\mqbkup.exe
- 2001-10-25 12:00 . 2009-06-22 11:49 19968 c:\windows\system32\mqbkup.exe
+ 2008-07-07 16:04 . 2008-04-13 19:45 56576 c:\windows\system32\drivers\swmidi.sys
+ 2002-08-29 01:45 . 2008-04-13 18:39 92544 c:\windows\system32\drivers\mqac.sys
+ 2001-10-25 12:00 . 2008-04-14 03:22 16896 c:\windows\system32\dllcache\upnpcont.exe
- 2011-04-24 08:47 . 2001-10-24 10:24 66048 c:\windows\system32\dllcache\s3legacy.dll
+ 2011-04-24 08:47 . 2001-10-24 11:24 66048 c:\windows\system32\dllcache\s3legacy.dll
- 2011-04-24 09:02 . 2001-08-17 19:52 40448 c:\windows\system32\dllcache\ql1240.sys
+ 2011-04-24 09:02 . 2001-08-17 20:52 40448 c:\windows\system32\dllcache\ql1240.sys
- 2011-04-24 09:02 . 2001-08-17 19:52 45312 c:\windows\system32\dllcache\ql12160.sys
+ 2011-04-24 09:02 . 2001-08-17 20:52 45312 c:\windows\system32\dllcache\ql12160.sys
+ 2011-05-05 07:25 . 2008-04-14 03:21 61440 c:\windows\system32\dllcache\kmsvc.dll
+ 2002-09-20 17:40 . 2008-04-14 02:29 24576 c:\windows\system32\dllcache\kbdclass.sys
- 2011-04-24 08:57 . 2001-08-17 19:49 23552 c:\windows\system32\dllcache\irmk7.sys
+ 2011-04-24 08:57 . 2001-08-17 20:49 23552 c:\windows\system32\dllcache\irmk7.sys
+ 2008-07-07 15:57 . 2008-04-13 18:54 11264 c:\windows\system32\dllcache\irenum.sys
- 2011-04-24 08:56 . 2001-08-17 20:06 38528 c:\windows\system32\dllcache\ibmvcap.sys
+ 2011-04-24 08:56 . 2001-08-17 21:06 38528 c:\windows\system32\dllcache\ibmvcap.sys
+ 2011-04-24 08:56 . 2001-08-17 19:11 28700 c:\windows\system32\dllcache\ibmexmp.sys
- 2011-04-24 08:56 . 2001-08-17 18:11 28700 c:\windows\system32\dllcache\ibmexmp.sys
- 2011-04-24 08:55 . 2001-10-24 10:24 68608 c:\windows\system32\dllcache\hpgt53tk.dll
+ 2011-04-24 08:55 . 2001-10-24 11:24 68608 c:\windows\system32\dllcache\hpgt53tk.dll
- 2011-04-24 08:54 . 2001-08-17 18:10 25159 c:\windows\system32\dllcache\elnk3.sys
+ 2011-04-24 08:54 . 2001-08-17 19:10 25159 c:\windows\system32\dllcache\elnk3.sys
+ 2011-04-24 08:54 . 2001-08-17 19:11 70174 c:\windows\system32\dllcache\el98xn5.sys
- 2011-04-24 08:54 . 2001-08-17 18:11 70174 c:\windows\system32\dllcache\el98xn5.sys
+ 2001-10-25 12:00 . 2008-04-14 03:22 64000 c:\windows\system32\dllcache\drvqry.exe
+ 2008-07-07 16:00 . 2004-08-03 21:08 60288 c:\windows\system32\dllcache\drmk.sys
+ 2001-10-25 12:00 . 2008-04-14 03:21 23552 c:\windows\system32\dllcache\dpmodemx.dll
+ 2001-10-25 12:00 . 2008-04-14 03:22 29696 c:\windows\system32\dllcache\dplaysvr.exe
+ 2011-04-24 08:53 . 2001-08-17 19:12 28062 c:\windows\system32\dllcache\dp83820.sys
- 2011-04-24 08:53 . 2001-08-17 18:12 28062 c:\windows\system32\dllcache\dp83820.sys
+ 2011-04-24 08:53 . 2001-10-24 10:43 23808 c:\windows\system32\dllcache\dot4usb.sys
- 2011-04-24 08:53 . 2001-10-24 09:43 23808 c:\windows\system32\dllcache\dot4usb.sys
+ 2011-04-24 08:53 . 2001-08-17 20:47 12928 c:\windows\system32\dllcache\dot4prt.sys
- 2011-04-24 08:53 . 2001-08-17 19:47 12928 c:\windows\system32\dllcache\dot4prt.sys
+ 2002-08-29 01:58 . 2008-04-13 19:14 63744 c:\windows\system32\dllcache\cdfs.sys
- 2011-04-24 08:50 . 2001-08-17 19:12 60416 c:\windows\system32\dllcache\brserwdm.sys
+ 2011-04-24 08:50 . 2001-08-17 20:12 60416 c:\windows\system32\dllcache\brserwdm.sys
- 2011-04-24 08:50 . 2001-10-24 09:49 39552 c:\windows\system32\dllcache\brparwdm.sys
+ 2011-04-24 08:50 . 2001-10-24 10:49 39552 c:\windows\system32\dllcache\brparwdm.sys
+ 2011-04-24 08:50 . 2001-08-17 20:12 12160 c:\windows\system32\dllcache\brfiltlo.sys
- 2011-04-24 08:50 . 2001-08-17 19:12 12160 c:\windows\system32\dllcache\brfiltlo.sys
- 2011-04-24 08:50 . 2001-10-24 10:24 12800 c:\windows\system32\dllcache\brevif.dll
+ 2011-04-24 08:50 . 2001-10-24 11:24 12800 c:\windows\system32\dllcache\brevif.dll
+ 2011-04-24 08:50 . 2001-10-24 11:24 19456 c:\windows\system32\dllcache\brbidiif.dll
- 2011-04-24 08:50 . 2001-10-24 10:24 19456 c:\windows\system32\dllcache\brbidiif.dll
+ 2011-11-01 21:41 . 2011-11-01 21:41 10134 c:\windows\Installer\{CDE29BFE-2E17-47BE-95DA-10198320A0B9}\callmsi.exe
- 2011-04-25 16:26 . 2011-11-01 07:50 4212 c:\windows\system32\zllictbl.dat
+ 2011-04-25 16:26 . 2011-11-02 05:11 4212 c:\windows\system32\zllictbl.dat
- 2001-10-25 12:00 . 2009-06-22 11:49 4608 c:\windows\system32\mqsvc.exe
+ 2001-10-25 12:00 . 2008-04-14 03:22 4608 c:\windows\system32\mqsvc.exe
+ 2001-10-25 12:00 . 2001-10-25 12:00 4463 c:\windows\system32\dllcache\oembios.dat
+ 2011-05-05 07:25 . 2008-04-14 03:18 6144 c:\windows\system32\dllcache\kbdax2.dll
+ 2011-04-24 08:56 . 2001-10-24 11:23 9728 c:\windows\system32\dllcache\ibmsgnet.dll
- 2011-04-24 08:56 . 2001-10-24 10:23 9728 c:\windows\system32\dllcache\ibmsgnet.dll
+ 2011-04-24 08:54 . 2001-08-17 20:53 7296 c:\windows\system32\dllcache\elmsmc.sys
- 2011-04-24 08:54 . 2001-08-17 19:53 7296 c:\windows\system32\dllcache\elmsmc.sys
+ 2008-07-07 16:04 . 2004-08-03 21:07 2944 c:\windows\system32\dllcache\drmkaud.sys
+ 2001-10-25 12:00 . 2008-04-14 03:10 3072 c:\windows\system32\dllcache\dpnaddr.dll
- 2011-04-24 08:53 . 2001-08-17 19:47 8704 c:\windows\system32\dllcache\dot4scan.sys
+ 2011-04-24 08:53 . 2001-08-17 20:47 8704 c:\windows\system32\dllcache\dot4scan.sys
+ 2011-04-24 08:51 . 2001-08-17 20:52 7680 c:\windows\system32\dllcache\cd20xrnt.sys
- 2011-04-24 08:51 . 2001-08-17 19:52 7680 c:\windows\system32\dllcache\cd20xrnt.sys
- 2011-04-24 08:50 . 2001-10-24 10:24 9728 c:\windows\system32\dllcache\brserif.dll
+ 2011-04-24 08:50 . 2001-10-24 11:24 9728 c:\windows\system32\dllcache\brserif.dll
+ 2011-04-24 08:50 . 2001-10-24 11:24 5120 c:\windows\system32\dllcache\brscnrsm.dll
- 2011-04-24 08:50 . 2001-10-24 10:24 5120 c:\windows\system32\dllcache\brscnrsm.dll
- 2011-04-24 08:50 . 2001-10-24 10:24 9728 c:\windows\system32\dllcache\brcoinst.dll
+ 2011-04-24 08:50 . 2001-10-24 11:24 9728 c:\windows\system32\dllcache\brcoinst.dll
- 2011-09-17 15:51 . 2011-11-01 20:05 2836 c:\windows\system32\d3d9caps.dat
+ 2011-09-17 15:51 . 2011-11-02 04:50 2836 c:\windows\system32\d3d9caps.dat
+ 2002-09-20 18:04 . 2008-04-14 03:21 170496 c:\windows\system32\Setup\msmqocm.dll
- 2002-09-20 18:04 . 2009-06-25 18:37 489472 c:\windows\system32\mqutil.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 489472 c:\windows\system32\mqutil.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 187392 c:\windows\system32\mqtrig.dll
- 2001-10-25 12:00 . 2009-06-22 11:49 117248 c:\windows\system32\mqtgsvc.exe
+ 2001-10-25 12:00 . 2008-04-14 03:22 117248 c:\windows\system32\mqtgsvc.exe
+ 2002-09-20 18:04 . 2008-04-14 03:21 517632 c:\windows\system32\mqsnap.dll
+ 2001-10-25 12:00 . 2008-04-14 03:21 123904 c:\windows\system32\mqrtdep.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 177152 c:\windows\system32\mqrt.dll
- 2002-09-20 18:04 . 2009-06-25 18:37 177152 c:\windows\system32\mqrt.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 663040 c:\windows\system32\mqqm.dll
+ 2001-10-25 12:00 . 2008-04-14 03:21 225280 c:\windows\system32\mqoa.dll
- 2001-10-25 12:00 . 2009-06-25 18:37 225280 c:\windows\system32\mqoa.dll
+ 2002-09-20 18:04 . 2008-04-14 03:21 138240 c:\windows\system32\mqad.dll
- 2002-09-20 18:04 . 2009-06-25 18:37 138240 c:\windows\system32\mqad.dll
- 2011-11-01 20:00 . 2011-11-01 20:00 138056 c:\windows\system32\FNTCACHE.DAT
+ 2011-11-02 05:18 . 2011-11-02 05:18 138056 c:\windows\system32\FNTCACHE.DAT
+ 2011-08-04 08:20 . 2011-08-04 08:20 103112 c:\windows\system32\drivers\epfwtdir.sys
+ 2011-08-04 08:20 . 2011-08-04 08:20 118104 c:\windows\system32\drivers\ehdrv.sys
+ 2002-09-20 18:04 . 2008-04-14 03:22 186368 c:\windows\system32\dllcache\upnphost.dll
- 2011-04-24 09:00 . 2001-08-17 18:50 198144 c:\windows\system32\dllcache\nv3.sys
+ 2011-04-24 09:00 . 2001-08-17 19:50 198144 c:\windows\system32\dllcache\nv3.sys
+ 2011-04-24 09:00 . 2001-10-24 11:24 123776 c:\windows\system32\dllcache\nv3.dll
- 2011-04-24 09:00 . 2001-10-24 10:24 123776 c:\windows\system32\dllcache\nv3.dll
+ 2011-04-24 09:00 . 2004-08-17 14:45 132695 c:\windows\system32\dllcache\netwlan5.sys
- 2011-04-24 09:00 . 2004-08-17 13:45 132695 c:\windows\system32\dllcache\netwlan5.sys
+ 2008-07-07 16:04 . 2004-08-03 21:07 171776 c:\windows\system32\dllcache\kmixer.sys
+ 2001-10-25 12:00 . 2008-04-14 03:21 151552 c:\windows\system32\dllcache\keymgr.dll
+ 2002-09-20 18:04 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
- 2009-06-25 08:27 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
- 2010-01-29 15:01 . 2011-05-02 15:32 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-07-07 14:13 . 2011-05-02 15:32 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-07-07 14:13 . 2008-04-14 03:21 274432 c:\windows\system32\dllcache\inetcfg.dll
+ 2008-07-07 14:13 . 2009-03-08 12:09 638816 c:\windows\system32\dllcache\iexplore.exe
- 2009-03-08 12:09 . 2009-03-08 12:09 638816 c:\windows\system32\dllcache\iexplore.exe
- 2011-04-24 08:56 . 2001-08-17 18:12 109085 c:\windows\system32\dllcache\ibmtrp.sys
+ 2011-04-24 08:56 . 2001-08-17 19:12 109085 c:\windows\system32\dllcache\ibmtrp.sys
- 2011-04-24 08:56 . 2001-08-17 18:12 100936 c:\windows\system32\dllcache\ibmtok.sys
+ 2011-04-24 08:56 . 2001-08-17 19:12 100936 c:\windows\system32\dllcache\ibmtok.sys
+ 2008-07-07 14:11 . 2009-02-09 10:56 473600 c:\windows\system32\dllcache\fastprox.dll
- 2011-05-11 17:58 . 2009-02-09 10:56 473600 c:\windows\system32\dllcache\fastprox.dll
+ 2002-09-20 18:03 . 2008-04-14 03:21 185344 c:\windows\system32\dllcache\els.dll
- 2011-04-24 08:54 . 2001-10-24 09:48 173568 c:\windows\system32\dllcache\el99xn51.sys
+ 2011-04-24 08:54 . 2001-10-24 10:48 173568 c:\windows\system32\dllcache\el99xn51.sys
+ 2002-09-20 18:03 . 2008-04-14 03:21 375296 c:\windows\system32\dllcache\dpnet.dll
+ 2001-10-25 12:00 . 2008-04-14 03:21 229888 c:\windows\system32\dllcache\dplayx.dll
- 2011-05-05 07:25 . 2008-04-14 03:19 102912 c:\windows\system32\dllcache\dpcdll.dll
+ 2002-09-20 17:55 . 2008-04-14 03:19 102912 c:\windows\system32\dllcache\dpcdll.dll
+ 2011-05-05 07:22 . 2008-04-14 03:21 651264 c:\windows\system32\dllcache\dot3ui.dll
- 2011-04-24 08:53 . 2001-08-17 18:14 952007 c:\windows\system32\dllcache\diwan.sys
+ 2011-04-24 08:53 . 2001-08-17 19:14 952007 c:\windows\system32\dllcache\diwan.sys
+ 2002-09-20 18:03 . 2008-04-14 03:21 113664 c:\windows\system32\dllcache\dgnet.dll
+ 2001-10-25 12:00 . 2008-04-14 03:21 151552 c:\windows\system32\dllcache\cdfview.dll
+ 2011-11-01 21:41 . 2011-11-01 21:41 105624 c:\windows\Installer\{CDE29BFE-2E17-47BE-95DA-10198320A0B9}\egui.exe
+ 2008-07-07 14:42 . 2008-04-14 03:21 2113536 c:\windows\system32\dllcache\dxdiagn.dll
+ 2002-09-20 18:05 . 2008-04-14 03:22 1298432 c:\windows\system32\dllcache\dxdiag.exe
+ 2008-07-07 14:42 . 2008-04-14 03:21 1689088 c:\windows\system32\dllcache\d3d9.dll
+ 2001-10-25 12:00 . 2008-04-14 03:21 2091520 c:\windows\system32\dllcache\cdosys.dll
+ 2011-11-01 21:41 . 2011-11-01 21:41 1033728 c:\windows\Installer\539d7a.msi
+ 2001-10-25 12:00 . 2001-10-25 12:00 13107200 c:\windows\system32\dllcache\oembios.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="d:\firewally\ZoneAlarm\zlclient.exe" [2011-03-18 1043968]
"egui"="d:\antiviry\Eset\egui.exe" [2011-09-22 3080264]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\antiviry\SuperAntiSpywer\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- d:\antiviry\SuperAntiSpywer\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS\0ssbtsr\0SsiEfr.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-10-30 07:09 136176 ----atw- c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"sp_rssrv"=2 (0x2)
"cmdAgent"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"d:\\My Download Files\\Subory\\Skype\\Phone\\Skype.exe"=
"d:\\My Download Files\\Subory\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Administrator\\Plocha\\Skype.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 9:20 118104]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [4.8.2011 9:20 103112]
R1 SASDIFSV;SASDIFSV;d:\antiviry\SuperAntiSpywer\sasdifsv.sys [22.7.2011 17:27 12880]
R1 SASKUTIL;SASKUTIL;d:\antiviry\SuperAntiSpywer\SASKUTIL.SYS [12.7.2011 22:55 67664]
R2 ekrn;ESET Service;d:\antiviry\Eset\ekrn.exe [22.9.2011 12:03 974944]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14.5.2007 9:26 508288]
R3 S3SAVAGE4;S3SAVAGE4;c:\windows\system32\drivers\s3savg4m.sys [10.8.2000 13:03 84704]
S2 !SASCORE;SAS Core Service;d:\antiviry\SuperAntiSpywer\SASCore.exe [12.8.2011 0:38 116608]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S3 PRODIGY;PRODIGY;c:\windows\system32\drivers\prodigy.sys [15.5.2011 11:55 32377]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [12.6.2011 15:08 27064]
S3 S3SAVAGE4M;S3SAVAGE4M;c:\windows\system32\drivers\s3sav4m.sys [7.7.2008 17:00 77824]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-02 c:\windows\Tasks\PandaUSBVaccine.job
- e:\panda\Panda USB Vaccine\RunInteractiveWin.exe [2011-04-13 14:45]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://
www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://
www.google.com/ie
TCP: DhcpNameServer = 192.168.100.1
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-02 16:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1957994488-1677128483-854245398-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6e,58,b7,0d,55,62,69,4c,b3,c9,46,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b3,22,01,3a,f3,8c,ea,4d,8d,d2,45,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,fe,94,e8,f9,a9,65,49,b0,f4,f4,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(720)
d:\antiviry\SuperAntiSpywer\SASWINLO.DLL
.
- - - - - - - > 'explorer.exe'(2368)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-11-02 16:13:01
ComboFix-quarantined-files.txt 2011-11-02 15:12
ComboFix2.txt 2011-11-01 20:25
.
Pre-Run: 440 655 872
Post-Run: 422 006 784
.
- - End Of File - - 6C6AA907D29ABF29280780F025301C2B