ComboFix 12-08-17.03 - robinek 18.08.2002 16:48:24.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1594 [GMT 2:00]
Spuštěný z: c:\documents and settings\robinek\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\documents and settings\robinek\WINDOWS
c:\windows\system\WINSPOOL.DRV
c:\windows\system32\TZLog.log
.
Nakažená kopie c:\windows\system32\msgsvc.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\system volume information\_restore{B4A9F4A0-F8ED-480E-BB7C-798D1F5A89DE}\RP109\A0177206.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2002-07-18 do 2002-08-18 )))))))))))))))))))))))))))))))
.
.
2012-05-02 10:00 . 2002-08-18 14:31 -------- d-----w- C:\World_of_Tanks
2012-03-09 12:58 . 2012-03-09 12:58 -------- d-----w- C:\SG Interactive
2012-01-25 08:11 . 2012-01-25 08:11 116 ----a-w- C:\user.js
2011-12-03 20:42 . 2011-12-03 20:42 -------- d-----w- C:\$AVG
2011-10-26 10:12 . 2011-10-26 10:13 -------- d-----w- C:\TruckRace
2011-09-23 13:14 . 2011-09-23 13:14 -------- d-----w- C:\TEXCACHE
2011-09-03 16:12 . 2002-08-18 14:26 -------- d-----r- C:\Program Files
2011-09-03 16:06 . 2011-09-03 14:24 -------- d-----w- C:\Documents and Settings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-03 17:21 . 2002-01-27 10:42 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-03 17:21 . 2002-01-27 10:42 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-03 17:21 . 2002-01-27 10:42 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-03 17:21 . 2002-01-27 10:42 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-03 17:21 . 2002-01-27 10:41 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 17:21 . 2002-01-27 10:41 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-03 17:21 . 2002-01-27 10:41 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-03 17:21 . 2002-01-27 10:41 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-03 17:21 . 2002-01-27 10:41 41224 ----a-w- c:\windows\avastSS.scr
2012-07-03 17:21 . 2002-01-27 10:41 227648 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-14 14:30 . 2011-09-03 14:19 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-01-29 14:45 . 2001-10-25 14:00 143422 ----a-w- c:\windows\system32\l3codecx.ax
2009-11-27 16:40 . 2001-10-25 14:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:40 . 2001-10-24 12:25 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-21 16:46 . 2004-08-17 13:49 470528 ----a-w- c:\windows\apppatch\aclayers.dll
2009-10-15 17:22 . 2001-10-25 14:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-10-12 13:54 . 2004-08-17 13:49 69632 ----a-w- c:\windows\system32\raschap.dll
2009-03-08 03:34 . 2004-08-17 13:49 236544 ----a-w- c:\windows\system32\webcheck.dll
2009-03-08 03:22 . 2001-10-25 14:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-02-06 16:54 . 2001-10-25 14:00 35328 ----a-w- c:\windows\system32\sc.exe
2008-05-08 12:28 . 2001-10-25 14:00 202752 ----a-w- c:\windows\system32\drivers\rmcast.sys
2004-08-17 13:49 . 2011-09-03 14:19 150528 ----a-w- c:\windows\pchealth\UploadLB\Binaries\UploadM.exe
2004-08-17 13:49 . 2011-09-03 14:19 159232 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
2004-08-17 13:49 . 2011-09-03 14:19 768512 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpCtr.exe
2004-08-17 13:49 . 2011-09-03 14:19 18944 ----a-w- c:\windows\pchealth\helpctr\binaries\HscUpd.exe
2004-08-17 13:49 . 2004-08-17 13:49 601088 ----a-w- c:\windows\system32\autochk.exe
2004-08-17 13:49 . 2011-09-03 14:19 726078 ----a-w- c:\windows\srchasst\srchui.dll
2004-08-17 13:49 . 2004-08-17 13:49 33280 ----a-w- c:\windows\help\sstub.dll
2004-08-17 13:49 . 2004-08-17 13:49 279040 ----a-w- c:\windows\help\tshoot.dll
2004-08-17 13:49 . 2011-09-03 14:19 58434 ----a-w- c:\windows\srchasst\srchctls.dll
2004-08-17 13:49 . 2004-08-17 13:49 34816 ----a-w- c:\windows\help\sniffpol.dll
2004-08-17 13:49 . 2011-09-03 14:19 38912 ----a-w- c:\windows\pchealth\helpctr\binaries\pchsvc.dll
2004-08-17 13:49 . 2011-09-03 14:19 102400 ----a-w- c:\windows\pchealth\helpctr\binaries\pchshell.dll
2004-08-17 13:49 . 2011-09-03 14:19 378368 ----a-w- c:\windows\pchealth\helpctr\binaries\msinfo.dll
2004-08-17 13:49 . 2011-09-03 14:19 3166208 ----a-w- c:\windows\srchasst\msgr3en.dll
2004-08-17 13:49 . 2004-08-17 13:49 512029 ----a-w- c:\windows\system32\msexch40.dll
2004-08-17 13:49 . 2004-08-17 13:49 244736 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2004-08-17 13:49 . 2004-08-17 13:49 1852416 ----a-w- c:\windows\apppatch\AcGenral.dll
2004-08-17 13:49 . 2004-08-17 13:49 137728 ----a-w- c:\windows\apppatch\AcLua.dll
2004-08-17 13:49 . 2004-08-17 13:49 116224 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2012-07-14 00:17 . 2012-06-14 09:16 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{51a86bb3-6602-4c85-92a5-130ee4864f13}"= "c:\program files\BrotherSoft_Extreme\prxtbBrot.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{51a86bb3-6602-4c85-92a5-130ee4864f13}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51a86bb3-6602-4c85-92a5-130ee4864f13}]
2011-05-09 08:49 176936 ----a-w- c:\program files\BrotherSoft_Extreme\prxtbBrot.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{51a86bb3-6602-4c85-92a5-130ee4864f13}"= "c:\program files\BrotherSoft_Extreme\prxtbBrot.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{51a86bb3-6602-4c85-92a5-130ee4864f13}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{51A86BB3-6602-4C85-92A5-130EE4864F13}"= "c:\program files\BrotherSoft_Extreme\prxtbBrot.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{51a86bb3-6602-4c85-92a5-130ee4864f13}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 17:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-29 17148552]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-06-26 3906432]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2002-08-18 895376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-07-03 98304]
"4StoryPrePatch"="c:\program files\Gameforge4D\4Story_CZ\PrePatch.exe" [2012-05-08 327680]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2009-03-02 10:14 57344 ----a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 15:42 2808832 ----a-w- c:\windows\ALCWZRD.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-05-04 14:05 311296 ----a-r- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-03-02 15:01 17530368 ----a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2012-07-03 22:48 98304 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 11:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\NexonEU\\NGM\\NGM.exe"=
"c:\\Program Files\\LunaRis-Online\\Lunaris.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"d:\\FIFA11\\Game\\fifa.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Ski Region Simulator 2012 Demo\\SkiRegionSimulator2012.exe"=
"c:\\Program Files\\Ski Region Simulator 2012 Demo\\game.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\World_of_Tanks\\WOTLauncher.exe"=
"c:\\World_of_Tanks\\WorldOfTanks.exe"=
"c:\\Documents and Settings\\robinek\\Plocha\\Counter-Strike 1.6 Non-Steam\\hl.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56596:TCP"= 56596:TCP:Pando Media Booster
"56596:UDP"= 56596:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [3.12.2011 20:46 721904]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [27.1.2002 12:41 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [27.1.2002 12:42 353688]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27.1.2002 12:42 21256]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [30.5.2012 13:56 3048136]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.1.2002 12:42 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15.2.2012 14:30 158856]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [25.11.2011 22:23 20160]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [3.9.2011 16:38 1684736]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27.1.2002 12:42 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [3.2.2002 16:40 113120]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;\??\c:\program files\MSI\Live Update 5\msibios32_100507.sys --> c:\program files\MSI\Live Update 5\msibios32_100507.sys [?]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;\??\c:\program files\MSI\Live Update 5\NTIOLib.sys --> c:\program files\MSI\Live Update 5\NTIOLib.sys [?]
S3 XDva392;XDva392;\??\c:\windows\system32\XDva392.sys --> c:\windows\system32\XDva392.sys [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2002-08-18 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2002-01-27 17:21]
.
2002-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2002-01-27 10:42]
.
2002-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2002-01-27 10:42]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
TCP: Interfaces\{FBD3A997-345F-46B2-9D12-1C66F7BA7C9C}: NameServer = 172.27.1.1
FF - ProfilePath - c:\documents and settings\robinek\Data aplikací\Mozilla\Firefox\Profiles\oqeqxnrs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?SSPV=FFOB1&ctid=CT2304157&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - XfireXO Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?SSPV=FFOB1&ctid=CT2304157&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=2&cc=&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.softonic_i.hmpg - true
FF - user.js: extensions.softonic_i.hmpgUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=13&cc=
FF - user.js: extensions.softonic_i.dfltSrch - true
FF - user.js: extensions.softonic_i.srchPrvdr - Search the web (Softonic)
FF - user.js: extensions.softonic_i.keyWordUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=2&cc=&q=
FF - user.js: extensions.softonic_i.dnsErr - true
FF - user.js: extensions.softonic_i.newTabUrl - hxxp://search.softonic.com/MON00005/tb_v1?SearchSource=15&cc=
FF - user.js: extensions.softonic_i.newTab - false
FF - user.js: extensions.softonic_i.tlbrSrchUrl - hxxp://search.softonic.com/MON00001/tb_v1?SearchSource=1&cc=&q=
FF - user.js: extensions.softonic_i.id - e03d3de5000000000000001d9206c498
FF - user.js: extensions.softonic_i.instlDay - 15364
FF - user.js: extensions.softonic_i.vrsn - 1.5.11.5
FF - user.js: extensions.softonic_i.vrsni - 1.5.11.5
FF - user.js: extensions.softonic_i.vrsnTs - 1.5.11.59:11
FF - user.js: extensions.softonic_i.prtnrId - softonic
FF - user.js: extensions.softonic_i.prdct - softonic
FF - user.js: extensions.softonic_i.aflt - orgnl
FF - user.js: extensions.softonic_i.smplGrp - eng7
FF - user.js: extensions.softonic_i.tlbrId - eng7
FF - user.js: extensions.softonic_i.instlRef - MON00001
FF - user.js: extensions.softonic_i.dfltLng -
FF - user.js: extensions.softonic_i.excTlbr - false
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Attack on Pearl Harbor Demo - c:\documents and settings\robinek\Plocha\Attack on Pearl Harbor Demo\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2002-08-18 17:00
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1177238915-73586283-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:d2,5d,a9,54,0a,2b,14,fd,6b,26,5c,6d,29,60,3c,0e,8e,4b,c8,31,88,
da,0f,02,18,b6,76,8c,8f,3f,04,91,d8,52,6d,f5,1a,c5,73,c8,48,57,f0,f4,1c,89,\
"rkeysecu"=hex:3e,8f,8b,bf,dd,c1,0d,2f,e7,da,5f,a3,91,0c,7c,75
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(820)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(216)
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\browselc.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\internet explorer\iexplore.exe
.
**************************************************************************
.
Celkový čas: 2002-08-18 17:05:34 - počítač byl restartován
ComboFix-quarantined-files.txt 2002-08-18 15:05
.
Před spuštěním: Volných bajtů: 67 041 267 712
Po spuštění: Volných bajtů: 73 619 193 856
.
- - End Of File - - 16DAADD1C3F9E652DDCA1C432DF88294
dekuji