Pomalé vypínání
Napsal: 07 říj 2015 21:23
Zdravím a prosím o pomoc či radu.
Poslední dobou se mi počítač dlouhou dobu vypíná, respektive ukládá nastavení...
Uz jsem to nechal projet vím možným: AVAST, Ccleaner, ATFcleaner, TFC, AdwareCleaner, JRT, RogueCleaner, Rkill, TDSkiller, Combofix (někde jsem vyčetl, že tady byste mi mohli poradit s jeho logem - proto kopie níže).
Nakonec jsem to projel FRST (Launcher mi nešel stáhnout, ani po vypnutí antiviru, stáhnutí souboru je blokováno přímo Firefoxem)a teď prosím o pomoc:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-10-2015
Ran by Greggy (administrator) on DOUPE (07-10-2015 22:04:36)
Running from C:\Documents and Settings\Greggy\Plocha
Loaded Profiles: Greggy (Available Profiles: Greggy & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 6 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Creative Technology Ltd.) C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
(ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [18790432 2010-01-19] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-19] (AVAST Software)
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [amd_dc_opt] => C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2006-11-17] (AMD)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [155648 2003-09-30] (Scansoft, Inc.)
HKLM\...\Run: [AVFX Engine] => C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe [20480 2006-10-19] (Creative Technology Ltd.)
HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [69632 2006-03-21] (ScanSoft, Inc.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1361088 2015-08-07] (COMODO)
HKLM\...\Run: [ProductUpdater] => C:\Program Files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [62464 2015-07-28] ()
HKU\S-1-5-21-1606980848-602162358-839522115-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6495144 2015-10-01] (Piriform Ltd)
HKU\S-1-5-21-1606980848-602162358-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-18\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Policies\Explorer: [ClearRecentDocsOnExit] 0x01
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-19] (AVAST Software)
CHR HKU\S-1-5-21-1606980848-602162358-839522115-1003\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.226.248.1 213.226.252.252 192.168.1.1
Tcpip\..\Interfaces\{540B0ADC-8CBE-4A37-9ED4-AE08D34395E3}: [DhcpNameServer] 213.226.248.1 213.226.252.252 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1606980848-602162358-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1606980848-602162358-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM -> Default = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}
URLSearchHook: HKU\S-1-5-21-1606980848-602162358-839522115-1003 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-07] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-07] (Oracle Corporation)
Toolbar: HKU\.DEFAULT -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2014-02-25] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-1606980848-602162358-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2014-02-25] (Společnost Microsoft)
DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Greggy\Data aplikací\Mozilla\Firefox\Profiles\om8a4b8d.default
FF Homepage: hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-24] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1219160.dll [2015-07-23] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-07] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files\Sony\Media Go\npmediago.dll [No File]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1606980848-602162358-839522115-1003: @facebook.com/FBPlugin,version=1.0.3 -> C:\Documents and Settings\Greggy\Data aplikací\Facebook\npfbplugin_1_0_3.dll [2010-06-09] ( )
FF Plugin HKU\S-1-5-21-1606980848-602162358-839522115-1003: sony.com/MediaGoDetector -> C:\Program Files\Sony\Media Go\npMediaGoDetector.dll [2014-01-16] (Sony Network Entertainment International LLC)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-19]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-19] (AVAST Software)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4353840 2015-09-07] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1664704 2015-08-07] (COMODO)
S2 Freemake Improver; C:\Documents and Settings\All Users\Data aplikací\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-07-28] (Freemake) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-05] (Nero AG) [File not signed]
S4 NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG) [File not signed]
S4 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [633856 2011-06-08] (Nokia) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2014-01-19] (Creative)
S1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36352 2005-03-09] (Advanced Micro Devices)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-09-19] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-09-19] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-09-19] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-09-19] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [789296 2015-09-19] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [434184 2015-09-19] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-09-19] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-09-19] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-09-19] (AVAST Software)
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [271360 2007-09-04] () [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [15808 2015-08-05] (COMODO)
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [631872 2015-08-05] (COMODO)
R1 cmdHlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30144 2015-08-05] (COMODO)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-02-18] (Disc Soft Ltd)
S3 go4X1394; C:\WINDOWS\System32\Drivers\go4X1394.sys [113664 2005-11-29] (BridgeCo AG) [File not signed]
S3 go4XWDM; C:\WINDOWS\System32\Drivers\go4XWDM.sys [28672 2005-11-29] (BridgeCo AG) [File not signed]
R0 Inspect; C:\WINDOWS\System32\DRIVERS\inspect.sys [105664 2015-08-05] (COMODO)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [18048 2007-09-04] () [File not signed]
U4 Messenger; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2014-01-19] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [52736 2006-03-22] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [168040 2014-01-19] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [18944 2006-03-22] (NVIDIA Corporation)
S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-03-01] (VSO Software) [File not signed]
S3 rockusb27; C:\WINDOWS\System32\DRIVERS\rockusb27.sys [35072 2008-05-06] (Fuzhou Rockchip Electronics Co,Ltd.) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [324096 2013-11-04] (Duplex Secure Ltd.)
U4 Alerter; no ImagePath
U5 Browser; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S3 catchme; \??\C:\9_antv_frwl_log_ComboFix\catchme.sys [X]
S3 dtscsi; \SystemRoot\System32\Drivers\dtscsi.sys [X]
S3 EagleNT; no ImagePath
S3 EagleXNt; no ImagePath
S3 eiqhwmef; no ImagePath
S3 GMSIPCI; \??\L:\INSTALL\GMSIPCI.SYS [X]
S4 IntelIde; no ImagePath
S3 Netaapl; system32\DRIVERS\netaapl.sys [X]
U5 Netlogon; C:\WINDOWS\system32\lsass.exe [13312 2008-04-14] (Microsoft Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-07 22:04 - 2015-10-07 22:04 - 00014389 _____ C:\Documents and Settings\Greggy\Plocha\FRST.txt
2015-10-07 22:03 - 2015-10-07 22:04 - 00000000 ____D C:\FRST
2015-10-07 13:00 - 2015-10-07 13:00 - 01697792 _____ (Farbar) C:\Documents and Settings\Greggy\Plocha\FRST.exe
2015-10-07 12:42 - 2015-10-07 22:04 - 00000000 ____D C:\Documents and Settings\Greggy\Local Settings\temp
2015-10-07 12:42 - 2015-10-07 12:42 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2015-10-07 12:42 - 2015-10-07 12:42 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\temp
2015-10-07 12:42 - 2015-10-07 12:42 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\temp
2015-10-07 12:41 - 2015-10-07 12:41 - 00015057 _____ C:\ComboFix.txt
2015-10-07 10:43 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2015-10-07 10:43 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2015-10-07 10:43 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2015-10-07 10:37 - 2015-10-07 10:39 - 00003992 _____ C:\Documents and Settings\Greggy\Plocha\Rkill.txt
2015-10-07 09:53 - 2015-10-07 09:53 - 00121560 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-07 09:53 - 2015-10-07 09:53 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-06 09:17 - 2015-10-06 09:32 - 34335744 _____ C:\Documents and Settings\Greggy\Plocha\Dvojky_vedle_v2.xls
2015-10-03 22:02 - 2015-10-03 22:37 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-09-29 11:59 - 2015-09-29 11:59 - 00000000 ____D C:\Documents and Settings\Greggy\Nabídka Start\Programy\CDROMEK
2015-09-19 17:22 - 2015-09-19 17:21 - 00313472 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-09-19 17:21 - 2015-09-19 17:21 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-07 22:04 - 2007-08-30 18:12 - 00000000 ____D C:\Documents and Settings\Greggy\Plocha
2015-10-07 22:00 - 2014-01-19 01:22 - 00014080 _____ C:\WINDOWS\system32\nvAppTimestamps
2015-10-07 21:50 - 2014-01-19 11:26 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-10-07 21:49 - 2007-08-30 19:59 - 01370332 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-07 21:45 - 2015-03-16 23:40 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
2015-10-07 21:45 - 2015-03-16 23:40 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
2015-10-07 21:45 - 2014-05-24 19:41 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-10-07 21:44 - 2014-05-24 19:41 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-10-07 21:44 - 2014-03-11 23:55 - 00032634 _____ C:\WINDOWS\SchedLgU.Txt
2015-10-07 21:44 - 2007-08-30 18:11 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-07 19:41 - 2007-08-30 18:12 - 00000324 __SHC C:\Documents and Settings\Greggy\ntuser.ini
2015-10-07 19:41 - 2007-08-30 18:12 - 00000000 ____D C:\Documents and Settings\Greggy
2015-10-07 19:41 - 2007-08-30 18:07 - 01645857 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-07 16:42 - 2013-06-14 16:12 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-07 12:42 - 2009-07-08 14:25 - 00000000 ____D C:\Qoobox
2015-10-07 12:37 - 2001-10-25 14:00 - 00000296 _____ C:\WINDOWS\system.ini
2015-10-07 10:45 - 2007-08-30 18:12 - 00000000 ____D C:\Documents and Settings\Greggy\Data aplikací
2015-10-07 10:37 - 2014-09-27 14:50 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\RogueKiller
2015-10-07 10:10 - 2014-09-27 14:50 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-10-07 09:54 - 2007-08-30 19:58 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-10-07 09:54 - 2007-08-30 19:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-10-07 09:43 - 2015-01-17 12:11 - 00000000 ____D C:\AdwCleaner
2015-10-07 09:31 - 2014-05-16 18:19 - 00000000 ____D C:\Documents and Settings\Greggy\Plocha\Cleaning
2015-10-07 00:38 - 2009-12-08 03:13 - 00000000 ____D C:\Program Files\The KMPlayer
2015-10-06 13:12 - 2014-01-18 17:14 - 00065536 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-10-06 13:12 - 2014-01-18 17:14 - 00065536 _____ C:\WINDOWS\system32\config\EventForwarding-Operational.Evt
2015-10-06 13:12 - 2013-01-14 02:31 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2015-10-06 13:12 - 2013-01-10 23:33 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2015-10-06 12:19 - 2015-03-16 23:28 - 00065536 _____ C:\WINDOWS\system32\config\COMODO I.evt
2015-10-06 09:33 - 2015-01-03 17:19 - 00000000 ____D C:\Documents and Settings\Greggy\Plocha\Statistika
2015-10-06 09:32 - 2015-01-24 22:51 - 15767040 _____ C:\Documents and Settings\Greggy\Plocha\Statistika_17_do50.xls
2015-10-04 20:45 - 2015-07-16 23:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-04 20:45 - 2001-10-25 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-10-03 11:04 - 2011-06-14 23:04 - 00000000 ___RD C:\Documents and Settings\Greggy\Dokumenty\Hudba
2015-10-03 11:04 - 2007-08-30 18:12 - 00000000 ___RD C:\Documents and Settings\Greggy\Dokumenty\Obrázky
2015-10-03 11:04 - 2007-08-30 18:12 - 00000000 ___RD C:\Documents and Settings\Greggy\Dokumenty
2015-10-03 11:04 - 2007-08-30 18:03 - 00000000 ___RD C:\Documents and Settings\All Users\Dokumenty\Filmy
2015-10-03 11:02 - 2007-10-16 18:25 - 00000116 _____ C:\WINDOWS\NeroDigital.ini
2015-10-01 20:50 - 2007-08-30 20:37 - 00000000 ____D C:\Documents and Settings\Greggy\Data aplikací\uTorrent
2015-10-01 20:49 - 2012-07-14 01:54 - 00000682 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2015-10-01 20:49 - 2011-05-11 23:07 - 00000000 ____D C:\Program Files\CCleaner
2015-09-29 19:56 - 2013-03-26 10:27 - 00093824 _____ C:\test
2015-09-29 11:59 - 2015-02-16 16:46 - 00000000 ____D C:\Program Files\Centauri
2015-09-29 11:59 - 2007-08-30 18:12 - 00000000 ___RD C:\Documents and Settings\Greggy\Nabídka Start\Programy
2015-09-24 22:38 - 2007-10-09 20:09 - 00000000 ____D C:\Documents and Settings\Greggy\Local Settings\Data aplikací\Adobe
2015-09-24 00:02 - 2013-06-14 16:12 - 00780488 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-09-24 00:02 - 2013-06-14 16:12 - 00142536 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-09-21 10:50 - 2007-08-30 18:12 - 00000000 ___HD C:\Documents and Settings\Greggy\Local Settings\Data aplikací
2015-09-20 17:00 - 2013-01-10 03:57 - 03121070 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1606980848-602162358-839522115-1003-0.dat
2015-09-20 17:00 - 2013-01-10 03:57 - 00155238 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2015-09-20 17:00 - 2007-08-30 18:11 - 00000178 __SHC C:\Documents and Settings\LocalService\ntuser.ini
2015-09-19 17:22 - 2007-08-30 18:15 - 00026144 _____ (Microsoft Corporation) C:\WINDOWS\system32\spupdsvc.exe
2015-09-19 17:21 - 2015-07-22 18:52 - 00157888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2015-09-19 17:21 - 2014-05-05 12:41 - 00024016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00789296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00434184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00208664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00076000 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00057888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00055200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00049776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-09-19 10:10 - 2014-09-06 12:34 - 00000000 ____D C:\Program Files\Speccy
2015-09-18 18:34 - 2015-01-06 22:34 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
==================== Files in the root of some directories =======
2007-11-12 10:52 - 2009-12-08 02:39 - 0000067 ____C () C:\Documents and Settings\Greggy\Data aplikací\AVSDVDPlayer.m3u
2009-12-08 03:15 - 2009-12-08 03:15 - 0000097 ____C () C:\Documents and Settings\Greggy\Data aplikací\AVSMediaPlayer.m3u
2007-10-16 10:59 - 2012-05-16 19:44 - 0081920 ____C () C:\Documents and Settings\Greggy\Data aplikací\ezpinst.exe
2010-02-28 23:35 - 2013-11-20 09:32 - 0087608 _____ () C:\Documents and Settings\Greggy\Data aplikací\inst.exe
2007-10-16 10:59 - 2013-11-20 09:32 - 0007887 ____C () C:\Documents and Settings\Greggy\Data aplikací\pcouffin.cat
2007-10-16 10:59 - 2013-11-20 09:32 - 0001144 ____C () C:\Documents and Settings\Greggy\Data aplikací\pcouffin.inf
2007-10-16 10:59 - 2013-11-20 09:32 - 0000055 ____C () C:\Documents and Settings\Greggy\Data aplikací\pcouffin.log
2007-10-16 10:59 - 2013-11-20 09:32 - 0047360 ____C (VSO Software) C:\Documents and Settings\Greggy\Data aplikací\pcouffin.sys
2010-02-28 23:36 - 2012-05-09 12:51 - 0001041 ____C () C:\Documents and Settings\Greggy\Data aplikací\vso_ts_preview.xml
2007-08-31 15:55 - 2013-11-09 17:06 - 0068608 ____C () C:\Documents and Settings\Greggy\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
COMBOFIX
ComboFix 15-10-06.01 - Greggy 07.10.2015 10:46:12.6.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1295 [GMT 2:00]
Spuštěný z: c:\documents and settings\Greggy\Plocha\Cleaning\9_antv_frwl_log_ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Greggy\WINDOWS
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\unin0411.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-09-07 do 2015-10-07 )))))))))))))))))))))))))))))))
.
.
2015-10-07 07:53 . 2015-10-07 07:53 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-10-07 07:53 . 2015-10-07 07:53 121560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-09-19 15:22 . 2015-09-19 15:21 313472 ----a-w- c:\windows\system32\aswBoot.exe
2015-09-19 15:21 . 2015-09-19 15:21 43112 ----a-w- c:\windows\avastSS.scr
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-10-07 08:10 . 2014-09-27 12:50 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-09-23 22:02 . 2013-06-14 14:12 780488 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2015-09-23 22:02 . 2013-06-14 14:12 142536 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-09-19 15:22 . 2007-08-30 16:15 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2015-09-19 15:21 . 2014-01-19 09:09 57888 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2015-09-19 15:21 . 2015-07-22 16:52 157888 ----a-w- c:\windows\system32\drivers\aswStmXP.sys
2015-09-19 15:21 . 2014-05-05 10:41 24016 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-09-19 15:21 . 2014-01-19 09:09 208664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-09-19 15:21 . 2014-01-19 09:09 76000 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-09-19 15:21 . 2014-01-19 09:09 49776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-09-19 15:21 . 2014-01-19 09:09 434184 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-09-19 15:21 . 2014-01-19 09:09 55200 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2015-09-19 15:21 . 2014-01-19 09:09 789296 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-09-03 11:52 . 2015-01-30 11:27 445472 ----a-w- c:\windows\system32\guard32.dll
2015-08-07 19:52 . 2014-10-17 14:21 96352 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-08-07 19:52 . 2014-10-17 14:22 146432 ----a-w- c:\windows\system32\javacpl.cpl
2015-08-05 00:30 . 2015-01-30 11:27 105664 ----a-w- c:\windows\system32\drivers\inspect.sys
2015-08-05 00:30 . 2015-01-30 11:27 30144 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2015-08-05 00:30 . 2015-01-30 11:27 631872 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2015-08-05 00:30 . 2015-01-30 11:27 15808 ----a-w- c:\windows\system32\drivers\cmderd.sys
2015-08-05 00:29 . 2015-01-30 11:27 33496 ----a-w- c:\windows\system32\cmdcsr.dll
2015-08-05 00:27 . 2015-01-30 11:27 288448 ----a-w- c:\windows\system32\cmdvrt32.dll
2015-08-05 00:26 . 2015-01-30 11:27 40640 ----a-w- c:\windows\system32\cmdkbd32.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-09-19 15:21 696120 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2015-10-01 6495144]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-01-19 18790432]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-09-19 6134544]
"NvMediaCenter"="NvMCTray.dll" [2014-02-08 376096]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-10-19 20480]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2015-08-07 1361088]
"ProductUpdater"="c:\program files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe" [2015-07-28 62464]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SW24"=c:\windows\system32\sw24.exe
"nwiz"=nwiz.exe /install
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [19.1.2014 11:09 49776]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [19.1.2014 11:09 208664]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [19.1.2014 11:09 789296]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19.1.2014 11:09 434184]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [30.1.2015 13:27 15808]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [30.1.2015 13:27 631872]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [30.1.2015 13:27 30144]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [18.2.2014 19:22 243128]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [5.5.2014 12:41 24016]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [19.1.2014 11:09 76000]
R3 aswStmXP;Avast StreamFilter Driver;c:\windows\system32\drivers\aswStmXP.sys [22.7.2015 18:52 157888]
S2 Freemake Improver;Freemake Improver;c:\documents and settings\All Users\Data aplikací\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [10.1.2013 23:24 108032]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [19.1.2014 1:29 1691480]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [30.1.2015 13:27 1664704]
S3 EagleXNt;EagleXNt; [x]
S3 eiqhwmef;eiqhwmef; [x]
S3 go4X1394;go4X1394;c:\windows\system32\drivers\go4X1394.sys [23.1.2010 17:00 113664]
S3 go4XWDM;go4XWDM;c:\windows\system32\drivers\go4XWDM.sys [23.1.2010 17:00 28672]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys --> c:\windows\system32\DRIVERS\netaapl.sys [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [16.10.2007 10:59 47360]
S3 rockusb27;Driver for Emgeton E9 Cult Device;c:\windows\system32\drivers\rockusb27.sys [28.12.2010 19:50 35072]
.
Obsah adresáře 'Naplánované úlohy'
.
2015-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-14 22:02]
.
2015-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2015-10-07 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2015-09-19 15:21]
.
2015-10-07 c:\windows\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-01-30 19:45]
.
2015-10-07 c:\windows\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-01-30 19:45]
.
2014-03-15 c:\windows\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-10 23:28]
.
2014-03-15 c:\windows\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-10 23:28]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.226.248.1 213.226.252.252 192.168.1.1
FF - ProfilePath - c:\documents and settings\Greggy\Data aplikací\Mozilla\Firefox\Profiles\om8a4b8d.default\
FF - prefs.js: browser.startup.homepage - about:homeabout:home
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-10-07 11:10
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-602162358-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e9,7d,81,a8,fe,8f,14,d4,e5,1c,91,b4,0c,94,c4,83,ae,12,5c,9c,32,df,e6,
ae,ed,21,f1,9b,a4,4a,40,51,b3,29,ce,e4,3e,fd,a0,85,7a,59,41,5f,4c,23,c7,4d,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\COMODO\CIS\Installer\Sym_Cam\CIS]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\CmdAgent\Mode\Configurations]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\CmdAgent\Mode\Data]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\CmdAgent\Mode\Options]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\Software\COMODO\Cam]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\Software\COMODO\Firewall Pro]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(1004)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
c:\windows\system32\mswsock.dll
c:\windows\System32\wshtcpip.dll
.
- - - - - - - > 'explorer.exe'(632)
c:\windows\system32\guard32.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\WS2HELP.dll
c:\windows\system32\WSOCK32.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\MPR.dll
.
- - - - - - - > 'csrss.exe'(792)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\COMODO\COMODO Internet Security\cavwp.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RunDLL32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2015-10-07 12:41:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-10-07 10:41
.
Před spuštěním: 4 058 247 168
Po spuštění: 3 981 135 872
.
- - End Of File - - 6AE28195B90A8BD41161DC15D449CDD2
413FC2A0C716421B3158746D63736515
Poslední dobou se mi počítač dlouhou dobu vypíná, respektive ukládá nastavení...
Uz jsem to nechal projet vím možným: AVAST, Ccleaner, ATFcleaner, TFC, AdwareCleaner, JRT, RogueCleaner, Rkill, TDSkiller, Combofix (někde jsem vyčetl, že tady byste mi mohli poradit s jeho logem - proto kopie níže).
Nakonec jsem to projel FRST (Launcher mi nešel stáhnout, ani po vypnutí antiviru, stáhnutí souboru je blokováno přímo Firefoxem)a teď prosím o pomoc:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:07-10-2015
Ran by Greggy (administrator) on DOUPE (07-10-2015 22:04:36)
Running from C:\Documents and Settings\Greggy\Plocha
Loaded Profiles: Greggy (Available Profiles: Greggy & Administrator)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 6 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Creative Technology Ltd.) C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
(ScanSoft, Inc.) C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\WINDOWS\system32\wbem\unsecapp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [18790432 2010-01-19] (Realtek Semiconductor Corp.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-19] (AVAST Software)
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [amd_dc_opt] => C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2006-11-17] (AMD)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [SSBkgdUpdate] => C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [155648 2003-09-30] (Scansoft, Inc.)
HKLM\...\Run: [AVFX Engine] => C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe [20480 2006-10-19] (Creative Technology Ltd.)
HKLM\...\Run: [OpwareSE4] => C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe [69632 2006-03-21] (ScanSoft, Inc.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1361088 2015-08-07] (COMODO)
HKLM\...\Run: [ProductUpdater] => C:\Program Files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [62464 2015-07-28] ()
HKU\S-1-5-21-1606980848-602162358-839522115-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6495144 2015-10-01] (Piriform Ltd)
HKU\S-1-5-21-1606980848-602162358-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-18\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Policies\Explorer: [ClearRecentDocsOnExit] 0x01
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-19] (AVAST Software)
CHR HKU\S-1-5-21-1606980848-602162358-839522115-1003\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.226.248.1 213.226.252.252 192.168.1.1
Tcpip\..\Interfaces\{540B0ADC-8CBE-4A37-9ED4-AE08D34395E3}: [DhcpNameServer] 213.226.248.1 213.226.252.252 192.168.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1606980848-602162358-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1606980848-602162358-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKLM -> Default = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}
URLSearchHook: HKU\S-1-5-21-1606980848-602162358-839522115-1003 - Modul přiřazení adres URL - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-07] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-07] (Oracle Corporation)
Toolbar: HKU\.DEFAULT -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2014-02-25] (Společnost Microsoft)
Toolbar: HKU\S-1-5-21-1606980848-602162358-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2014-02-25] (Společnost Microsoft)
DPF: {31435657-9980-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2000-04-19] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Documents and Settings\Greggy\Data aplikací\Mozilla\Firefox\Profiles\om8a4b8d.default
FF Homepage: hxxps://www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-24] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw_1219160.dll [2015-07-23] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-07] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files\Sony\Media Go\npmediago.dll [No File]
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1606980848-602162358-839522115-1003: @facebook.com/FBPlugin,version=1.0.3 -> C:\Documents and Settings\Greggy\Data aplikací\Facebook\npfbplugin_1_0_3.dll [2010-06-09] ( )
FF Plugin HKU\S-1-5-21-1606980848-602162358-839522115-1003: sony.com/MediaGoDetector -> C:\Program Files\Sony\Media Go\npMediaGoDetector.dll [2014-01-16] (Sony Network Entertainment International LLC)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-01-19]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-03-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-19] (AVAST Software)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [4353840 2015-09-07] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1664704 2015-08-07] (COMODO)
S2 Freemake Improver; C:\Documents and Settings\All Users\Data aplikací\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-07-28] (Freemake) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S3 NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [774144 2007-01-05] (Nero AG) [File not signed]
S4 NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [262144 2006-12-23] (Nero AG) [File not signed]
S4 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [633856 2011-06-08] (Nokia) [File not signed]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 61883; C:\WINDOWS\System32\DRIVERS\61883.sys [48128 2008-04-13] (Microsoft Corporation)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2014-01-19] (Creative)
S1 AmdK8; C:\WINDOWS\System32\DRIVERS\AmdK8.sys [36352 2005-03-09] (Advanced Micro Devices)
R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-09-19] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [76000 2015-09-19] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-09-19] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-09-19] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [789296 2015-09-19] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [434184 2015-09-19] (AVAST Software)
R3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [157888 2015-09-19] (AVAST Software)
S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-09-19] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [208664 2015-09-19] (AVAST Software)
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [271360 2007-09-04] () [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [15808 2015-08-05] (COMODO)
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [631872 2015-08-05] (COMODO)
R1 cmdHlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30144 2015-08-05] (COMODO)
R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-02-18] (Disc Soft Ltd)
S3 go4X1394; C:\WINDOWS\System32\Drivers\go4X1394.sys [113664 2005-11-29] (BridgeCo AG) [File not signed]
S3 go4XWDM; C:\WINDOWS\System32\Drivers\go4XWDM.sys [28672 2005-11-29] (BridgeCo AG) [File not signed]
R0 Inspect; C:\WINDOWS\System32\DRIVERS\inspect.sys [105664 2015-08-05] (COMODO)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [18048 2007-09-04] () [File not signed]
U4 Messenger; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2014-01-19] (Creative Technology Ltd.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 NVENETFD; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [52736 2006-03-22] (NVIDIA Corporation)
R0 nvgts; C:\WINDOWS\System32\DRIVERS\nvgts.sys [168040 2014-01-19] (NVIDIA Corporation)
R3 nvnetbus; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [18944 2006-03-22] (NVIDIA Corporation)
S3 pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [47360 2010-03-01] (VSO Software) [File not signed]
S3 rockusb27; C:\WINDOWS\System32\DRIVERS\rockusb27.sys [35072 2008-05-06] (Fuzhou Rockchip Electronics Co,Ltd.) [File not signed]
R0 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [324096 2013-11-04] (Duplex Secure Ltd.)
U4 Alerter; no ImagePath
U5 Browser; C:\WINDOWS\system32\svchost.exe [14336 2008-04-14] (Microsoft Corporation)
S3 catchme; \??\C:\9_antv_frwl_log_ComboFix\catchme.sys [X]
S3 dtscsi; \SystemRoot\System32\Drivers\dtscsi.sys [X]
S3 EagleNT; no ImagePath
S3 EagleXNt; no ImagePath
S3 eiqhwmef; no ImagePath
S3 GMSIPCI; \??\L:\INSTALL\GMSIPCI.SYS [X]
S4 IntelIde; no ImagePath
S3 Netaapl; system32\DRIVERS\netaapl.sys [X]
U5 Netlogon; C:\WINDOWS\system32\lsass.exe [13312 2008-04-14] (Microsoft Corporation)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-07 22:04 - 2015-10-07 22:04 - 00014389 _____ C:\Documents and Settings\Greggy\Plocha\FRST.txt
2015-10-07 22:03 - 2015-10-07 22:04 - 00000000 ____D C:\FRST
2015-10-07 13:00 - 2015-10-07 13:00 - 01697792 _____ (Farbar) C:\Documents and Settings\Greggy\Plocha\FRST.exe
2015-10-07 12:42 - 2015-10-07 22:04 - 00000000 ____D C:\Documents and Settings\Greggy\Local Settings\temp
2015-10-07 12:42 - 2015-10-07 12:42 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2015-10-07 12:42 - 2015-10-07 12:42 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\temp
2015-10-07 12:42 - 2015-10-07 12:42 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\temp
2015-10-07 12:41 - 2015-10-07 12:41 - 00015057 _____ C:\ComboFix.txt
2015-10-07 10:43 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2015-10-07 10:43 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2015-10-07 10:43 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2015-10-07 10:43 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2015-10-07 10:37 - 2015-10-07 10:39 - 00003992 _____ C:\Documents and Settings\Greggy\Plocha\Rkill.txt
2015-10-07 09:53 - 2015-10-07 09:53 - 00121560 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-10-07 09:53 - 2015-10-07 09:53 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-10-06 09:17 - 2015-10-06 09:32 - 34335744 _____ C:\Documents and Settings\Greggy\Plocha\Dvojky_vedle_v2.xls
2015-10-03 22:02 - 2015-10-03 22:37 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-09-29 11:59 - 2015-09-29 11:59 - 00000000 ____D C:\Documents and Settings\Greggy\Nabídka Start\Programy\CDROMEK
2015-09-19 17:22 - 2015-09-19 17:21 - 00313472 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-09-19 17:21 - 2015-09-19 17:21 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-07 22:04 - 2007-08-30 18:12 - 00000000 ____D C:\Documents and Settings\Greggy\Plocha
2015-10-07 22:00 - 2014-01-19 01:22 - 00014080 _____ C:\WINDOWS\system32\nvAppTimestamps
2015-10-07 21:50 - 2014-01-19 11:26 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job
2015-10-07 21:49 - 2007-08-30 19:59 - 01370332 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-07 21:45 - 2015-03-16 23:40 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
2015-10-07 21:45 - 2015-03-16 23:40 - 00000440 _____ C:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
2015-10-07 21:45 - 2014-05-24 19:41 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-10-07 21:44 - 2014-05-24 19:41 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-10-07 21:44 - 2014-03-11 23:55 - 00032634 _____ C:\WINDOWS\SchedLgU.Txt
2015-10-07 21:44 - 2007-08-30 18:11 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-07 19:41 - 2007-08-30 18:12 - 00000324 __SHC C:\Documents and Settings\Greggy\ntuser.ini
2015-10-07 19:41 - 2007-08-30 18:12 - 00000000 ____D C:\Documents and Settings\Greggy
2015-10-07 19:41 - 2007-08-30 18:07 - 01645857 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-07 16:42 - 2013-06-14 16:12 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-07 12:42 - 2009-07-08 14:25 - 00000000 ____D C:\Qoobox
2015-10-07 12:37 - 2001-10-25 14:00 - 00000296 _____ C:\WINDOWS\system.ini
2015-10-07 10:45 - 2007-08-30 18:12 - 00000000 ____D C:\Documents and Settings\Greggy\Data aplikací
2015-10-07 10:37 - 2014-09-27 14:50 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\RogueKiller
2015-10-07 10:10 - 2014-09-27 14:50 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-10-07 09:54 - 2007-08-30 19:58 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2015-10-07 09:54 - 2007-08-30 19:58 - 00000000 ____D C:\Documents and Settings\All Users\Nabídka Start\Programy
2015-10-07 09:43 - 2015-01-17 12:11 - 00000000 ____D C:\AdwCleaner
2015-10-07 09:31 - 2014-05-16 18:19 - 00000000 ____D C:\Documents and Settings\Greggy\Plocha\Cleaning
2015-10-07 00:38 - 2009-12-08 03:13 - 00000000 ____D C:\Program Files\The KMPlayer
2015-10-06 13:12 - 2014-01-18 17:14 - 00065536 _____ C:\WINDOWS\system32\config\WindowsPowerShell.evt
2015-10-06 13:12 - 2014-01-18 17:14 - 00065536 _____ C:\WINDOWS\system32\config\EventForwarding-Operational.Evt
2015-10-06 13:12 - 2013-01-14 02:31 - 00065536 _____ C:\WINDOWS\system32\config\Internet.evt
2015-10-06 13:12 - 2013-01-10 23:33 - 00065536 _____ C:\WINDOWS\system32\config\TuneUp.evt
2015-10-06 12:19 - 2015-03-16 23:28 - 00065536 _____ C:\WINDOWS\system32\config\COMODO I.evt
2015-10-06 09:33 - 2015-01-03 17:19 - 00000000 ____D C:\Documents and Settings\Greggy\Plocha\Statistika
2015-10-06 09:32 - 2015-01-24 22:51 - 15767040 _____ C:\Documents and Settings\Greggy\Plocha\Statistika_17_do50.xls
2015-10-04 20:45 - 2015-07-16 23:37 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-10-04 20:45 - 2001-10-25 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-10-03 11:04 - 2011-06-14 23:04 - 00000000 ___RD C:\Documents and Settings\Greggy\Dokumenty\Hudba
2015-10-03 11:04 - 2007-08-30 18:12 - 00000000 ___RD C:\Documents and Settings\Greggy\Dokumenty\Obrázky
2015-10-03 11:04 - 2007-08-30 18:12 - 00000000 ___RD C:\Documents and Settings\Greggy\Dokumenty
2015-10-03 11:04 - 2007-08-30 18:03 - 00000000 ___RD C:\Documents and Settings\All Users\Dokumenty\Filmy
2015-10-03 11:02 - 2007-10-16 18:25 - 00000116 _____ C:\WINDOWS\NeroDigital.ini
2015-10-01 20:50 - 2007-08-30 20:37 - 00000000 ____D C:\Documents and Settings\Greggy\Data aplikací\uTorrent
2015-10-01 20:49 - 2012-07-14 01:54 - 00000682 _____ C:\Documents and Settings\All Users\Plocha\CCleaner.lnk
2015-10-01 20:49 - 2011-05-11 23:07 - 00000000 ____D C:\Program Files\CCleaner
2015-09-29 19:56 - 2013-03-26 10:27 - 00093824 _____ C:\test
2015-09-29 11:59 - 2015-02-16 16:46 - 00000000 ____D C:\Program Files\Centauri
2015-09-29 11:59 - 2007-08-30 18:12 - 00000000 ___RD C:\Documents and Settings\Greggy\Nabídka Start\Programy
2015-09-24 22:38 - 2007-10-09 20:09 - 00000000 ____D C:\Documents and Settings\Greggy\Local Settings\Data aplikací\Adobe
2015-09-24 00:02 - 2013-06-14 16:12 - 00780488 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-09-24 00:02 - 2013-06-14 16:12 - 00142536 ____C (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-09-21 10:50 - 2007-08-30 18:12 - 00000000 ___HD C:\Documents and Settings\Greggy\Local Settings\Data aplikací
2015-09-20 17:00 - 2013-01-10 03:57 - 03121070 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1606980848-602162358-839522115-1003-0.dat
2015-09-20 17:00 - 2013-01-10 03:57 - 00155238 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2015-09-20 17:00 - 2007-08-30 18:11 - 00000178 __SHC C:\Documents and Settings\LocalService\ntuser.ini
2015-09-19 17:22 - 2007-08-30 18:15 - 00026144 _____ (Microsoft Corporation) C:\WINDOWS\system32\spupdsvc.exe
2015-09-19 17:21 - 2015-07-22 18:52 - 00157888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStmXP.sys
2015-09-19 17:21 - 2014-05-05 12:41 - 00024016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00789296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00434184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00208664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00076000 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00057888 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswTdi.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00055200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr.sys
2015-09-19 17:21 - 2014-01-19 11:09 - 00049776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-09-19 10:10 - 2014-09-06 12:34 - 00000000 ____D C:\Program Files\Speccy
2015-09-18 18:34 - 2015-01-06 22:34 - 00000284 _____ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
==================== Files in the root of some directories =======
2007-11-12 10:52 - 2009-12-08 02:39 - 0000067 ____C () C:\Documents and Settings\Greggy\Data aplikací\AVSDVDPlayer.m3u
2009-12-08 03:15 - 2009-12-08 03:15 - 0000097 ____C () C:\Documents and Settings\Greggy\Data aplikací\AVSMediaPlayer.m3u
2007-10-16 10:59 - 2012-05-16 19:44 - 0081920 ____C () C:\Documents and Settings\Greggy\Data aplikací\ezpinst.exe
2010-02-28 23:35 - 2013-11-20 09:32 - 0087608 _____ () C:\Documents and Settings\Greggy\Data aplikací\inst.exe
2007-10-16 10:59 - 2013-11-20 09:32 - 0007887 ____C () C:\Documents and Settings\Greggy\Data aplikací\pcouffin.cat
2007-10-16 10:59 - 2013-11-20 09:32 - 0001144 ____C () C:\Documents and Settings\Greggy\Data aplikací\pcouffin.inf
2007-10-16 10:59 - 2013-11-20 09:32 - 0000055 ____C () C:\Documents and Settings\Greggy\Data aplikací\pcouffin.log
2007-10-16 10:59 - 2013-11-20 09:32 - 0047360 ____C (VSO Software) C:\Documents and Settings\Greggy\Data aplikací\pcouffin.sys
2010-02-28 23:36 - 2012-05-09 12:51 - 0001041 ____C () C:\Documents and Settings\Greggy\Data aplikací\vso_ts_preview.xml
2007-08-31 15:55 - 2013-11-09 17:06 - 0068608 ____C () C:\Documents and Settings\Greggy\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
COMBOFIX
ComboFix 15-10-06.01 - Greggy 07.10.2015 10:46:12.6.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1295 [GMT 2:00]
Spuštěný z: c:\documents and settings\Greggy\Plocha\Cleaning\9_antv_frwl_log_ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Greggy\WINDOWS
c:\windows\iun6002.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\unin0411.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-09-07 do 2015-10-07 )))))))))))))))))))))))))))))))
.
.
2015-10-07 07:53 . 2015-10-07 07:53 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-10-07 07:53 . 2015-10-07 07:53 121560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-09-19 15:22 . 2015-09-19 15:21 313472 ----a-w- c:\windows\system32\aswBoot.exe
2015-09-19 15:21 . 2015-09-19 15:21 43112 ----a-w- c:\windows\avastSS.scr
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-10-07 08:10 . 2014-09-27 12:50 35064 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2015-09-23 22:02 . 2013-06-14 14:12 780488 -c--a-w- c:\windows\system32\FlashPlayerApp.exe
2015-09-23 22:02 . 2013-06-14 14:12 142536 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-09-19 15:22 . 2007-08-30 16:15 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2015-09-19 15:21 . 2014-01-19 09:09 57888 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2015-09-19 15:21 . 2015-07-22 16:52 157888 ----a-w- c:\windows\system32\drivers\aswStmXP.sys
2015-09-19 15:21 . 2014-05-05 10:41 24016 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-09-19 15:21 . 2014-01-19 09:09 208664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-09-19 15:21 . 2014-01-19 09:09 76000 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-09-19 15:21 . 2014-01-19 09:09 49776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-09-19 15:21 . 2014-01-19 09:09 434184 ----a-w- c:\windows\system32\drivers\aswSP.sys
2015-09-19 15:21 . 2014-01-19 09:09 55200 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2015-09-19 15:21 . 2014-01-19 09:09 789296 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-09-03 11:52 . 2015-01-30 11:27 445472 ----a-w- c:\windows\system32\guard32.dll
2015-08-07 19:52 . 2014-10-17 14:21 96352 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-08-07 19:52 . 2014-10-17 14:22 146432 ----a-w- c:\windows\system32\javacpl.cpl
2015-08-05 00:30 . 2015-01-30 11:27 105664 ----a-w- c:\windows\system32\drivers\inspect.sys
2015-08-05 00:30 . 2015-01-30 11:27 30144 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2015-08-05 00:30 . 2015-01-30 11:27 631872 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2015-08-05 00:30 . 2015-01-30 11:27 15808 ----a-w- c:\windows\system32\drivers\cmderd.sys
2015-08-05 00:29 . 2015-01-30 11:27 33496 ----a-w- c:\windows\system32\cmdcsr.dll
2015-08-05 00:27 . 2015-01-30 11:27 288448 ----a-w- c:\windows\system32\cmdvrt32.dll
2015-08-05 00:26 . 2015-01-30 11:27 40640 ----a-w- c:\windows\system32\cmdkbd32.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-09-19 15:21 696120 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2015-10-01 6495144]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-01-19 18790432]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-09-19 6134544]
"NvMediaCenter"="NvMCTray.dll" [2014-02-08 376096]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-13 59720]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 155648]
"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-10-19 20480]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cistray.exe" [2015-08-07 1361088]
"ProductUpdater"="c:\program files\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe" [2015-07-28 62464]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SoftwareSASGeneration"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"SW24"=c:\windows\system32\sw24.exe
"nwiz"=nwiz.exe /install
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [19.1.2014 11:09 49776]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [19.1.2014 11:09 208664]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [19.1.2014 11:09 789296]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19.1.2014 11:09 434184]
R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [30.1.2015 13:27 15808]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [30.1.2015 13:27 631872]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [30.1.2015 13:27 30144]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [18.2.2014 19:22 243128]
R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [5.5.2014 12:41 24016]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [19.1.2014 11:09 76000]
R3 aswStmXP;Avast StreamFilter Driver;c:\windows\system32\drivers\aswStmXP.sys [22.7.2015 18:52 157888]
S2 Freemake Improver;Freemake Improver;c:\documents and settings\All Users\Data aplikací\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [10.1.2013 23:24 108032]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [19.1.2014 1:29 1691480]
S3 cmdvirth;COMODO Virtual Service Manager;c:\program files\COMODO\COMODO Internet Security\cmdvirth.exe [30.1.2015 13:27 1664704]
S3 EagleXNt;EagleXNt; [x]
S3 eiqhwmef;eiqhwmef; [x]
S3 go4X1394;go4X1394;c:\windows\system32\drivers\go4X1394.sys [23.1.2010 17:00 113664]
S3 go4XWDM;go4XWDM;c:\windows\system32\drivers\go4XWDM.sys [23.1.2010 17:00 28672]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys --> c:\windows\system32\DRIVERS\netaapl.sys [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [16.10.2007 10:59 47360]
S3 rockusb27;Driver for Emgeton E9 Cult Device;c:\windows\system32\drivers\rockusb27.sys [28.12.2010 19:50 35072]
.
Obsah adresáře 'Naplánované úlohy'
.
2015-10-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-14 22:02]
.
2015-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2015-10-07 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2015-09-19 15:21]
.
2015-10-07 c:\windows\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-01-30 19:45]
.
2015-10-07 c:\windows\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job
- c:\program files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-01-30 19:45]
.
2014-03-15 c:\windows\Tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-10 23:28]
.
2014-03-15 c:\windows\Tasks\Přihlášení k oznamování konce poskytování služeb pro Microsoft Windows XP.job
- c:\windows\system32\xp_eos.exe [2014-03-10 23:28]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 213.226.248.1 213.226.252.252 192.168.1.1
FF - ProfilePath - c:\documents and settings\Greggy\Data aplikací\Mozilla\Firefox\Profiles\om8a4b8d.default\
FF - prefs.js: browser.startup.homepage - about:homeabout:home
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-10-07 11:10
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-602162358-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e9,7d,81,a8,fe,8f,14,d4,e5,1c,91,b4,0c,94,c4,83,ae,12,5c,9c,32,df,e6,
ae,ed,21,f1,9b,a4,4a,40,51,b3,29,ce,e4,3e,fd,a0,85,7a,59,41,5f,4c,23,c7,4d,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_19_0_0_185_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\COMODO\CIS\Installer\Sym_Cam\CIS]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\CmdAgent\Mode\Configurations]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\CmdAgent\Mode\Data]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\CmdAgent\Mode\Options]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\Software\COMODO\Cam]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\System\Software\COMODO\Firewall Pro]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,59,00,53,00,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(1004)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
c:\windows\system32\mswsock.dll
c:\windows\System32\wshtcpip.dll
.
- - - - - - - > 'explorer.exe'(632)
c:\windows\system32\guard32.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\windows\system32\msi.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\WS2HELP.dll
c:\windows\system32\WSOCK32.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\MPR.dll
.
- - - - - - - > 'csrss.exe'(792)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\COMODO\COMODO Internet Security\cavwp.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RunDLL32.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2015-10-07 12:41:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-10-07 10:41
.
Před spuštěním: 4 058 247 168
Po spuštění: 3 981 135 872
.
- - End Of File - - 6AE28195B90A8BD41161DC15D449CDD2
413FC2A0C716421B3158746D63736515