PC spamuje
Napsal: 15 úno 2010 20:29
Mam od zname notebook. Poskytovatel internetu ji ustrihl protoze spamuje. Po kontrole NODem, spybotem a combofixem je problem stale stejny. Spamy rozesila neco pomoci services.exe
Muzete mi prosim pomoci? prikladam vypisy z logu hijackthis a combofix.
Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:56:08, on 15.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\OpenVPN\bin\openvpnserv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\BUtilityBar\BisonBar.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\Documents and Settings\pipalovam\Plocha\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cs.intl.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cs.intl.acer.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [BisonBar] C:\WINDOWS\BUtilityBar\BisonBar.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\UltraVNC\WinVNC.exe
--
End of file - 6350 bytes
Combofix:
ComboFix 10-02-12.01 - pipalovam 15.02.2010 19:58:19.6.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.990.679 [GMT 1:00]
Spuštěný z: c:\documents and settings\pipalovam\Plocha\ComboFix.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-15 do 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-02-15 15:48 . 2010-02-15 15:48 -------- d-----w- c:\program files\MSXML 4.0
2010-02-15 15:48 . 2010-02-15 15:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-15 15:47 . 2010-02-15 15:47 -------- d-----w- c:\windows\system32\cs
2010-02-15 15:47 . 2010-02-15 15:47 -------- d-----w- c:\windows\system32\bits
2010-02-15 15:45 . 2010-02-15 15:45 -------- d-----w- c:\windows\EHome
2010-02-15 13:53 . 2010-02-15 15:49 -------- d-----w- c:\program files\NetLimiter 2 Monitor
2010-02-12 14:00 . 2008-10-15 16:38 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-02-12 14:00 . 2009-07-31 04:35 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-02-12 13:58 . 2008-04-21 21:15 216576 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-02-12 13:57 . 2009-08-13 15:24 512000 ------w- c:\windows\system32\dllcache\jscript.dll
2010-02-12 09:46 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2010-02-12 09:46 . 2009-02-09 11:26 2191232 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-02-12 09:46 . 2009-03-06 14:23 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2010-02-12 09:46 . 2009-02-09 11:25 111104 ------w- c:\windows\system32\dllcache\services.exe
2010-02-12 09:46 . 2009-02-09 10:56 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2010-02-12 09:46 . 2009-02-09 10:56 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2010-02-12 09:45 . 2009-02-09 10:56 684032 ------w- c:\windows\system32\dllcache\advapi32.dll
2010-02-12 09:45 . 2009-02-09 10:56 728064 ------w- c:\windows\system32\dllcache\lsasrv.dll
2010-02-12 09:45 . 2009-02-09 10:56 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-02-12 09:45 . 2009-02-09 10:56 709632 ------w- c:\windows\system32\dllcache\ntdll.dll
2010-02-12 09:45 . 2009-02-09 11:26 2147328 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-12 09:45 . 2009-02-09 11:26 2025984 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-12 09:44 . 2009-06-21 21:48 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-02-12 09:42 . 2009-12-04 18:22 455424 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-12 09:36 . 2009-07-10 13:28 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-02-10 08:45 . 2009-07-31 09:05 1372672 ------w- c:\windows\system32\dllcache\msxml6.dll
2010-02-10 08:45 . 2008-04-14 07:00 80896 ------w- c:\windows\system32\dllcache\msxml6r.dll
2010-02-10 08:45 . 2007-06-26 10:30 22060 ------w- c:\windows\system32\dllcache\npds.zip
2010-02-10 08:45 . 2007-06-26 10:26 403 ------w- c:\windows\system32\dllcache\npdrmv2.zip
2010-02-10 08:42 . 2010-02-10 08:42 -------- d-----w- c:\windows\ServicePackFiles
2010-02-10 08:42 . 2008-04-14 07:52 294912 ------w- c:\windows\system32\dllcache\dlimport.exe
2010-02-08 07:49 . 2010-02-15 19:05 792064 ----a-w- c:\windows\system32\drivers\utbkgze.sys
2010-02-05 17:45 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\mstee.sys
2010-02-05 17:39 . 2008-04-13 23:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-15 13:53 . 2006-06-02 16:20 93252 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 13:53 . 2006-06-02 16:20 449770 ----a-w- c:\windows\system32\perfh005.dat
2010-02-10 08:47 . 2006-06-02 15:54 2684 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-02-10 08:47 . 2006-06-02 15:54 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-14 10:12 . 2009-12-03 14:11 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-04 13:01 . 2010-01-04 12:58 -------- d-----w- c:\program files\PDFCreator
2010-01-04 13:00 . 2010-01-04 13:00 14290 ----a-w- c:\program files\settings.dat
2010-01-04 13:00 . 2010-01-04 13:00 253116 ----a-w- c:\windows\PDFCreator_Toolbar_Uninstaller_4734.exe
2010-01-04 13:00 . 2010-01-04 13:00 -------- d-----w- c:\program files\PDFCreator Toolbar
2009-12-27 20:16 . 2009-12-27 20:16 -------- d-----w- c:\program files\Fotolab
2009-12-04 20:07 . 2009-12-04 20:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-04 18:22 . 2004-08-18 19:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 15:18 . 2006-06-02 15:54 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-03 10:28 . 2009-12-03 10:28 0 ----a-w- c:\windows\nsreg.dat
2009-12-02 16:51 . 2005-03-10 11:12 1054 ----a-w- c:\windows\CLEANUP.CMD
2009-12-02 16:49 . 2004-06-25 16:13 842 ----a-w- c:\windows\HotFix.bat
2009-11-20 13:26 . 2009-11-20 13:26 25984 ----a-w- c:\windows\system32\drivers\tap0901.sys
.
((((((((((((((((((((((((((((( SnapShot_2010-02-15_13.46.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-15 15:50 . 2010-02-15 15:50 16384 c:\windows\Temp\Perflib_Perfdata_e0.dat
+ 2010-02-15 15:51 . 2010-02-15 15:51 16384 c:\windows\Temp\Perflib_Perfdata_810.dat
- 2006-06-02 16:20 . 2010-02-11 12:49 81658 c:\windows\system32\perfc009.dat
+ 2006-06-02 16:20 . 2010-02-15 13:53 81658 c:\windows\system32\perfc009.dat
+ 2007-04-23 16:08 . 2007-04-23 16:08 81688 c:\windows\system32\drivers\nltdi.sys
- 2006-06-02 16:20 . 2010-02-11 12:49 451912 c:\windows\system32\perfh009.dat
+ 2006-06-02 16:20 . 2010-02-15 13:53 451912 c:\windows\system32\perfh009.dat
+ 2004-05-04 09:53 . 2004-05-04 09:53 1645320 c:\windows\system32\GDIPLUS.DLL
+ 2010-02-15 15:19 . 2010-02-15 15:49 10714204 c:\windows\system32\Restore\rstrlog.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-04-14 53248]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2006-04-27 151552]
"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-03-31 204800]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 16248320]
"SkyTel"="SkyTel.EXE" [2006-05-15 2879488]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-06-22 602112]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"BisonBar"="c:\windows\BUtilityBar\BisonBar.exe" [2006-09-08 245760]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 421888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-18 208952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\AutorunsDisabled
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2006-3-27 45056]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\- KARAT -\\DeltaCopy\\rsync.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [23.4.2007 17:08 81688]
R2 uvnc_service;uvnc_service;c:\program files\UltraVNC\winvnc.exe [3.12.2009 13:37 1589704]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
S4 Yahoo! Zimbra Desktop Service;Yahoo! Zimbra Desktop Service;c:\documents and settings\pipalovam\Local Settings\Application Data\Zimbra\zdesktop\zdesktop.exe [3.12.2009 15:00 139264]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - utbkgze
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = hxxp://cs.intl.acer.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://cs.intl.acer.yahoo.com/
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\pipalovam\Data aplikací\Mozilla\Firefox\Profiles\qq12mw0e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.idnes.cz/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-15 20:05
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\utbkgze]
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1076)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-02-15 20:07:50
ComboFix-quarantined-files.txt 2010-02-15 19:07
ComboFix2.txt 2010-02-15 13:48
ComboFix3.txt 2010-02-11 15:51
ComboFix4.txt 2010-02-11 15:31
ComboFix5.txt 2010-02-15 18:57
Před spuštěním: Volných bajtů: 40 328 359 936
Po spuštění: Volných bajtů: 40 293 552 128
- - End Of File - - 36990E6FD32D487C32FBC49BB2EA80C4
Diky!
Muzete mi prosim pomoci? prikladam vypisy z logu hijackthis a combofix.
Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:56:08, on 15.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\OpenVPN\bin\openvpnserv.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\BUtilityBar\BisonBar.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\Documents and Settings\pipalovam\Plocha\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://cs.intl.acer.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cs.intl.acer.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [BisonBar] C:\WINDOWS\BUtilityBar\BisonBar.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: uvnc_service - UltraVNC - C:\Program Files\UltraVNC\WinVNC.exe
--
End of file - 6350 bytes
Combofix:
ComboFix 10-02-12.01 - pipalovam 15.02.2010 19:58:19.6.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.990.679 [GMT 1:00]
Spuštěný z: c:\documents and settings\pipalovam\Plocha\ComboFix.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-15 do 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-02-15 15:48 . 2010-02-15 15:48 -------- d-----w- c:\program files\MSXML 4.0
2010-02-15 15:48 . 2010-02-15 15:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-15 15:47 . 2010-02-15 15:47 -------- d-----w- c:\windows\system32\cs
2010-02-15 15:47 . 2010-02-15 15:47 -------- d-----w- c:\windows\system32\bits
2010-02-15 15:45 . 2010-02-15 15:45 -------- d-----w- c:\windows\EHome
2010-02-15 13:53 . 2010-02-15 15:49 -------- d-----w- c:\program files\NetLimiter 2 Monitor
2010-02-12 14:00 . 2008-10-15 16:38 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-02-12 14:00 . 2009-07-31 04:35 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2010-02-12 13:58 . 2008-04-21 21:15 216576 ------w- c:\windows\system32\dllcache\wordpad.exe
2010-02-12 13:57 . 2009-08-13 15:24 512000 ------w- c:\windows\system32\dllcache\jscript.dll
2010-02-12 09:46 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2010-02-12 09:46 . 2009-02-09 11:26 2191232 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-02-12 09:46 . 2009-03-06 14:23 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2010-02-12 09:46 . 2009-02-09 11:25 111104 ------w- c:\windows\system32\dllcache\services.exe
2010-02-12 09:46 . 2009-02-09 10:56 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2010-02-12 09:46 . 2009-02-09 10:56 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2010-02-12 09:45 . 2009-02-09 10:56 684032 ------w- c:\windows\system32\dllcache\advapi32.dll
2010-02-12 09:45 . 2009-02-09 10:56 728064 ------w- c:\windows\system32\dllcache\lsasrv.dll
2010-02-12 09:45 . 2009-02-09 10:56 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-02-12 09:45 . 2009-02-09 10:56 709632 ------w- c:\windows\system32\dllcache\ntdll.dll
2010-02-12 09:45 . 2009-02-09 11:26 2147328 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-12 09:45 . 2009-02-09 11:26 2025984 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-12 09:44 . 2009-06-21 21:48 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-02-12 09:42 . 2009-12-04 18:22 455424 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-12 09:36 . 2009-07-10 13:28 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-02-10 08:45 . 2009-07-31 09:05 1372672 ------w- c:\windows\system32\dllcache\msxml6.dll
2010-02-10 08:45 . 2008-04-14 07:00 80896 ------w- c:\windows\system32\dllcache\msxml6r.dll
2010-02-10 08:45 . 2007-06-26 10:30 22060 ------w- c:\windows\system32\dllcache\npds.zip
2010-02-10 08:45 . 2007-06-26 10:26 403 ------w- c:\windows\system32\dllcache\npdrmv2.zip
2010-02-10 08:42 . 2010-02-10 08:42 -------- d-----w- c:\windows\ServicePackFiles
2010-02-10 08:42 . 2008-04-14 07:52 294912 ------w- c:\windows\system32\dllcache\dlimport.exe
2010-02-08 07:49 . 2010-02-15 19:05 792064 ----a-w- c:\windows\system32\drivers\utbkgze.sys
2010-02-05 17:45 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\mstee.sys
2010-02-05 17:39 . 2008-04-13 23:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-15 13:53 . 2006-06-02 16:20 93252 ----a-w- c:\windows\system32\perfc005.dat
2010-02-15 13:53 . 2006-06-02 16:20 449770 ----a-w- c:\windows\system32\perfh005.dat
2010-02-10 08:47 . 2006-06-02 15:54 2684 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-02-10 08:47 . 2006-06-02 15:54 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-14 10:12 . 2009-12-03 14:11 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-04 13:01 . 2010-01-04 12:58 -------- d-----w- c:\program files\PDFCreator
2010-01-04 13:00 . 2010-01-04 13:00 14290 ----a-w- c:\program files\settings.dat
2010-01-04 13:00 . 2010-01-04 13:00 253116 ----a-w- c:\windows\PDFCreator_Toolbar_Uninstaller_4734.exe
2010-01-04 13:00 . 2010-01-04 13:00 -------- d-----w- c:\program files\PDFCreator Toolbar
2009-12-27 20:16 . 2009-12-27 20:16 -------- d-----w- c:\program files\Fotolab
2009-12-04 20:07 . 2009-12-04 20:07 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-04 18:22 . 2004-08-18 19:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 15:18 . 2006-06-02 15:54 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-03 10:28 . 2009-12-03 10:28 0 ----a-w- c:\windows\nsreg.dat
2009-12-02 16:51 . 2005-03-10 11:12 1054 ----a-w- c:\windows\CLEANUP.CMD
2009-12-02 16:49 . 2004-06-25 16:13 842 ----a-w- c:\windows\HotFix.bat
2009-11-20 13:26 . 2009-11-20 13:26 25984 ----a-w- c:\windows\system32\drivers\tap0901.sys
.
((((((((((((((((((((((((((((( SnapShot_2010-02-15_13.46.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-15 15:50 . 2010-02-15 15:50 16384 c:\windows\Temp\Perflib_Perfdata_e0.dat
+ 2010-02-15 15:51 . 2010-02-15 15:51 16384 c:\windows\Temp\Perflib_Perfdata_810.dat
- 2006-06-02 16:20 . 2010-02-11 12:49 81658 c:\windows\system32\perfc009.dat
+ 2006-06-02 16:20 . 2010-02-15 13:53 81658 c:\windows\system32\perfc009.dat
+ 2007-04-23 16:08 . 2007-04-23 16:08 81688 c:\windows\system32\drivers\nltdi.sys
- 2006-06-02 16:20 . 2010-02-11 12:49 451912 c:\windows\system32\perfh009.dat
+ 2006-06-02 16:20 . 2010-02-15 13:53 451912 c:\windows\system32\perfh009.dat
+ 2004-05-04 09:53 . 2004-05-04 09:53 1645320 c:\windows\system32\GDIPLUS.DLL
+ 2010-02-15 15:19 . 2010-02-15 15:49 10714204 c:\windows\system32\Restore\rstrlog.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-04-14 53248]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2006-04-27 151552]
"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-03-31 204800]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-18 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-27 16248320]
"SkyTel"="SkyTel.EXE" [2006-05-15 2879488]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-06-22 602112]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"BisonBar"="c:\windows\BUtilityBar\BisonBar.exe" [2006-09-08 245760]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 413696]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-30 421888]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-18 208952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\AutorunsDisabled
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2006-3-27 45056]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\- KARAT -\\DeltaCopy\\rsync.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [23.4.2007 17:08 81688]
R2 uvnc_service;uvnc_service;c:\program files\UltraVNC\winvnc.exe [3.12.2009 13:37 1589704]
S2 eLock2BurnerLockDriver;eLock2BurnerLockDriver;\??\c:\windows\system32\eLock2BurnerLockDriver.sys --> c:\windows\system32\eLock2BurnerLockDriver.sys [?]
S2 eLock2FSCTLDriver;eLock2FSCTLDriver;\??\c:\windows\system32\eLock2FSCTLDriver.sys --> c:\windows\system32\eLock2FSCTLDriver.sys [?]
S4 Yahoo! Zimbra Desktop Service;Yahoo! Zimbra Desktop Service;c:\documents and settings\pipalovam\Local Settings\Application Data\Zimbra\zdesktop\zdesktop.exe [3.12.2009 15:00 139264]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - utbkgze
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = hxxp://cs.intl.acer.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://cs.intl.acer.yahoo.com/
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\pipalovam\Data aplikací\Mozilla\Firefox\Profiles\qq12mw0e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.idnes.cz/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-15 20:05
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\utbkgze]
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1076)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-02-15 20:07:50
ComboFix-quarantined-files.txt 2010-02-15 19:07
ComboFix2.txt 2010-02-15 13:48
ComboFix3.txt 2010-02-11 15:51
ComboFix4.txt 2010-02-11 15:31
ComboFix5.txt 2010-02-15 18:57
Před spuštěním: Volných bajtů: 40 328 359 936
Po spuštění: Volných bajtů: 40 293 552 128
- - End Of File - - 36990E6FD32D487C32FBC49BB2EA80C4
Diky!