
ale po tomto scripte,..mi strasne moc zadrha pc,.robi si co chce



ComboFix 09-01-17.04 - admin 2009-01-18 15:31:35.4 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1007.606 [GMT 1:00]
Körs frĺn: c:\documents and settings\admin\Desktop\ComboFix.exe
Använda kommandoväxlar :: c:\documents and settings\admin\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Outdated)
* Skapade en ny ĺterställningspunkt
* Resident AV is active
FILE ::
c:\windows\system32\szbvrzregz.exe
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\szbvrzregz.exe
.
(((((((((((((((((((((((( Filer Skapade frĺn 2008-12-18 till 2009-01-18 ))))))))))))))))))))))))))))))
.
2009-01-18 00:27 . 2009-01-18 11:30 280 --a------ c:\windows\emm386n.dl
2009-01-18 00:25 . 2009-01-18 00:25 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-17 22:38 . 2009-01-17 22:39 9,123 --a------ C:\ResetTeaTimer.bat
2009-01-17 20:16 . 2009-01-17 20:16 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-17 20:16 . 2009-01-17 20:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-17 20:16 . 2009-01-17 20:16 <DIR> d-------- c:\documents and settings\admin\Application Data\Malwarebytes
2009-01-17 20:16 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-17 20:16 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-17 16:48 . 2009-01-17 16:48 <DIR> d-------- c:\program files\Trend Micro
2009-01-17 00:38 . 2009-01-17 00:43 <DIR> d-------- c:\program files\360desktop
2009-01-17 00:38 . 2009-01-17 00:38 <DIR> d-------- c:\documents and settings\admin\Application Data\360desktop
2009-01-16 20:07 . 2009-01-17 00:09 <DIR> d---s---- c:\documents and settings\Administrator
2009-01-16 19:37 . 2009-01-16 19:37 380,764 --a------ c:\program files\TU2009v8_0_2000_35CZ.zip
2009-01-16 19:31 . 2009-01-16 19:31 <DIR> d-------- c:\documents and settings\admin\Application Data\TuneUp Software
2009-01-16 19:30 . 2009-01-17 00:10 <DIR> d-------- c:\program files\TuneUp Utilities 2009
2009-01-16 19:30 . 2009-01-16 19:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-01-15 12:52 . 2009-01-17 10:59 <DIR> d-------- c:\program files\Pivot Stickfigure Animator
2009-01-12 14:11 . 2009-01-12 14:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2009-01-12 14:10 . 2009-01-12 14:39 <DIR> d-------- c:\program files\Easy CD-DA Extractor 12
2009-01-12 12:42 . 2009-01-12 12:42 <DIR> d-------- c:\windows\Easy CD-DA Extractor 12
2009-01-10 10:22 . 2009-01-10 10:22 <DIR> d--hs---- c:\windows\ftpcache
2009-01-10 07:12 . 2009-01-10 07:12 <DIR> d-------- c:\documents and settings\admin\Application Data\Playrix Entertainment
2009-01-10 07:11 . 2009-01-10 07:11 <DIR> d-------- c:\windows\Fishdom
2009-01-10 07:11 . 2009-01-10 07:12 <DIR> d-------- c:\program files\Fishdom
2009-01-08 14:20 . 2009-01-08 14:20 4,096 --a------ c:\windows\d3dx.dat
2009-01-08 10:51 . 2009-01-08 10:51 <DIR> d-------- c:\program files\CCleaner
2009-01-08 06:27 . 2009-01-08 06:27 330 --a------ c:\windows\CDPlayer.ini
2009-01-07 12:17 . 2009-01-17 11:45 <DIR> d-------- C:\My Music
2009-01-07 12:14 . 2009-01-07 12:15 <DIR> d-------- c:\program files\MediaMonkey
2009-01-05 23:14 . 2009-01-08 11:52 599 --a------ c:\windows\TRNCOM.INI
2009-01-03 15:51 . 2009-01-03 15:51 <DIR> d-------- c:\documents and settings\admin\Application Data\Jane s Hotel Family Hero
2009-01-03 13:22 . 2009-01-03 13:22 <DIR> d-------- c:\program files\Outsim
2009-01-03 13:22 . 2002-07-07 23:14 1,294,336 --a------ c:\windows\system32\vorbis.acm
2009-01-03 13:22 . 2006-06-20 09:56 225,280 --a------ c:\windows\system32\rewire.dll
2009-01-03 13:20 . 2009-01-03 13:23 <DIR> d-------- c:\program files\Image-Line
2009-01-03 13:06 . 2009-01-16 08:04 <DIR> d-------- C:\Download Bitlord
2009-01-03 12:55 . 2009-01-03 12:55 <DIR> d-------- c:\documents and settings\admin\Application Data\Sony
2009-01-03 12:52 . 2009-01-03 12:52 <DIR> d-------- c:\program files\Sony Setup
2009-01-03 12:50 . 2009-01-03 12:50 <DIR> d-------- c:\program files\Acoustica Shared Effects
2009-01-03 12:50 . 2009-01-03 13:24 <DIR> d-------- c:\program files\Acoustica Beatcraft
2009-01-02 12:51 . 2009-01-02 13:05 <DIR> d-------- c:\program files\Rockstar Games
2009-01-02 12:24 . 2009-01-02 13:23 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2009-01-02 08:19 . 2009-01-07 09:10 <DIR> d-------- c:\documents and settings\admin\Application Data\GlarySoft
2009-01-01 18:44 . 2009-01-01 18:44 <DIR> d-------- c:\documents and settings\admin\Application Data\CyberLink
2009-01-01 11:10 . 2009-01-01 11:10 3,731 --a------ c:\windows\wtran32.INI
2008-12-31 16:46 . 2009-01-17 23:09 2,839 --a------ c:\windows\wdict32.INI
2008-12-31 16:09 . 2008-12-31 16:09 <DIR> d-------- c:\program files\PC Translator
2008-12-29 10:07 . 2008-12-29 10:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\VirtualFarm
2008-12-29 09:23 . 2008-12-29 09:23 <DIR> d-------- c:\windows\INDSOFT
2008-12-29 09:21 . 2008-12-29 09:21 <DIR> d-------- c:\documents and settings\admin\Application Data\Astro Gemini Software
2008-12-29 09:21 . 2007-11-06 14:16 106,496 --a------ c:\windows\system32\Astro Gemini Screensaver Manager.scr
2008-12-27 20:00 . 2008-12-27 20:00 <DIR> d-------- c:\program files\Glary Utilities
2008-12-27 12:35 . 2008-04-14 06:12 91,136 --a------ c:\windows\system32\kswdmcap.ax
2008-12-27 12:35 . 2008-04-14 06:12 91,136 --a--c--- c:\windows\system32\dllcache\kswdmcap.ax
2008-12-27 12:35 . 2008-04-14 06:12 61,952 --a------ c:\windows\system32\kstvtune.ax
2008-12-27 12:35 . 2008-04-14 06:12 61,952 --a--c--- c:\windows\system32\dllcache\kstvtune.ax
2008-12-27 12:35 . 2008-04-14 06:12 53,760 --a------ c:\windows\system32\vfwwdm32.dll
2008-12-27 12:35 . 2008-04-14 06:12 53,760 --a--c--- c:\windows\system32\dllcache\vfwwdm32.dll
2008-12-27 12:35 . 2008-04-14 06:12 43,008 --a------ c:\windows\system32\ksxbar.ax
2008-12-27 12:35 . 2008-04-14 06:12 43,008 --a--c--- c:\windows\system32\dllcache\ksxbar.ax
2008-12-27 12:35 . 2008-04-14 06:12 28,672 --a------ c:\windows\system32\vidcap.ax
2008-12-27 12:35 . 2008-04-14 06:12 28,672 --a--c--- c:\windows\system32\dllcache\vidcap.ax
2008-12-27 12:33 . 2008-12-27 12:33 <DIR> d-------- c:\windows\PixArt
2008-12-27 12:33 . 2008-12-27 12:33 <DIR> d-------- c:\windows\Cache
2008-12-27 12:33 . 2008-12-27 12:33 <DIR> d-------- c:\windows\Album
2008-12-27 12:33 . 2008-12-27 12:33 <DIR> d-------- c:\program files\VideoCAM GE111
2008-12-27 12:33 . 2008-12-27 12:33 <DIR> d-------- c:\program files\Common Files\PCCamera
2008-12-27 12:32 . 2008-12-27 12:32 <DIR> d-------- c:\windows\Downloaded Installations
2008-12-27 08:01 . 2008-12-05 18:48 499,712 --a------ c:\windows\system32\msvcp71.dll
2008-12-27 08:01 . 2008-12-05 18:48 348,160 --a------ c:\windows\system32\msvcr71.dll
2008-12-26 08:22 . 2008-04-14 00:45 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-12-26 08:22 . 2008-04-14 00:45 32,128 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2008-12-25 08:42 . 2009-01-17 08:55 <DIR> d-------- c:\windows\SxsCaPendDel
2008-12-25 08:09 . 2008-12-27 08:04 <DIR> d-------- c:\windows\system32\Adobe
2008-12-24 14:38 . 2008-12-24 14:38 <DIR> d-------- c:\program files\Opera
2008-12-24 14:38 . 2008-12-24 14:38 0 --a------ c:\windows\nsreg.dat
2008-12-24 14:37 . 2008-12-24 14:38 7,848,496 --a------ C:\Firefox Setup 3.0.5.exe
2008-12-24 14:36 . 2008-12-24 14:36 7,408,904 --a------ C:\Opera_963_int_Setup.exe
2008-12-24 12:13 . 2009-01-17 22:36 <DIR> d-------- c:\program files\Conduit
2008-12-24 12:12 . 2009-01-03 13:05 <DIR> d-------- c:\program files\BitLord
2008-12-24 12:12 . 2008-12-24 12:12 3,096,064 --a------ C:\BitLord_1.01.exe
2008-12-24 11:39 . 2009-01-17 12:13 69 --a------ c:\windows\NeroDigital.ini
2008-12-23 20:46 . 2009-01-18 11:03 <DIR> d-------- c:\program files\Taskbar Shuffle
2008-12-23 20:43 . 2008-12-23 20:43 <DIR> d-------- c:\program files\Fractalis Software
2008-12-23 20:32 . 2009-01-18 15:01 <DIR> d-------- c:\documents and settings\admin\Application Data\skypePM
2008-12-23 20:32 . 2008-12-23 20:32 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-23 20:30 . 2008-12-23 20:30 <DIR> d-------- c:\program files\Skype
2008-12-23 20:30 . 2008-12-23 20:30 <DIR> d-------- c:\program files\Common Files\Skype
2008-12-23 20:30 . 2008-12-23 20:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2008-12-23 20:30 . 2009-01-18 15:28 <DIR> d-------- c:\documents and settings\admin\Application Data\Skype
2008-12-22 22:59 . 2008-12-22 22:59 <DIR> d-------- c:\windows\system32\sk-SK
2008-12-22 22:41 . 2008-12-22 22:42 <DIR> d-------- c:\windows\system32\URTTemp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 23:26 --------- d-----w c:\program files\Zoner
2009-01-17 22:14 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-17 22:12 --------- d-----w c:\program files\SpywareBlaster
2009-01-17 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-14 15:48 --------- d-----w c:\documents and settings\admin\Application Data\Vso
2009-01-07 11:05 --------- d-----w c:\program files\Winamp
2008-12-30 07:37 --------- d-----w c:\program files\CD Audio MP3 Converter
2008-12-27 05:53 --------- d-----w c:\program files\DVDFab Platinum 3
2008-12-25 07:42 --------- d-----w c:\program files\Common Files\Adobe
2008-12-22 19:49 737,280 ----a-w c:\windows\iun6002.exe
2008-12-22 19:49 --------- d-----w c:\program files\Codec Pack - All In 1
2008-12-22 19:41 --------- d-----w c:\program files\Realtek
2008-12-22 19:39 --------- d-----w c:\program files\S3
2008-12-22 19:38 --------- d-----w c:\program files\VIA
2008-12-22 19:30 --------- d-----w c:\program files\microsoft frontpage
2008-12-22 19:26 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-22 18:42 --------- d-----w c:\documents and settings\admin\Application Data\IsolatedStorage
2008-12-22 18:03 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-22 18:03 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-22 16:41 --------- d-----w c:\program files\Symantec
2008-12-22 16:41 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-22 16:39 --------- d-----w c:\documents and settings\admin\Application Data\Zoner
2008-12-22 16:37 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-22 16:37 --------- d-----w c:\program files\CyberLink
2008-12-22 16:37 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-12-22 16:36 --------- d-----w c:\program files\Webteh
2008-12-22 16:36 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-22 16:35 --------- d-----w c:\documents and settings\admin\Application Data\Ahead
2008-12-22 16:33 --------- d-----w c:\program files\Microsoft.NET
2008-12-22 16:33 --------- d-----w c:\program files\Microsoft Works
2008-12-22 16:31 87,608 ----a-w c:\documents and settings\admin\Application Data\ezpinst.exe
2008-12-22 16:31 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-12-22 16:31 47,360 ----a-w c:\documents and settings\admin\Application Data\pcouffin.sys
2008-12-22 16:31 --------- d-----w c:\program files\Common Files\Ahead
2008-12-22 16:30 --------- d-----w c:\program files\Nero
2008-12-22 16:27 --------- d-----w c:\program files\ESET
2008-12-22 16:27 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-17_22.45.45,50 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-10 16:46:33 88,590 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-01-17 23:30:29 88,590 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Taskbar Shuffle"="c:\program files\Taskbar Shuffle\taskbarshuffle.exe" [2008-04-16 818176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Norton Ghost 9.0"="c:\program files\Symantec\Norton Ghost\Agent\GhostTray.exe" [2004-07-29 1122304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"VTTimer"="VTTimer.exe" [2006-09-21 c:\windows\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2007-09-30 c:\windows\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-02 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-17 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-07-29 138780]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2008-12-16 21656]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-07-01 34312]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-07-29 46779]
R3 PAC207;VideoCAM GE111;c:\windows\system32\drivers\PFC027.sys [2005-04-08 162176]
R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2008-04-14 69120]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2006-11-10 603648]
R4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
.
Innehĺllet i mappen 'Schemalagda aktiviteter'
2009-01-18 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe []
2009-01-18 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-29 14:28]
.
.
------- Extra genomsökning -------
.
uStart Page = hxxp://www.zoznam.sk/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\wsinwa0q.default\
---- FIREFOX POLICY ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-18 15:32:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
genomsökningen avslutades lyckosamt
dolda filer: 0
**************************************************************************
.
Sluttid: 2009-01-18 15:33:21
ComboFix-quarantined-files.txt 2009-01-18 14:33:18
ComboFix2.txt 2009-01-18 14:16:52
ComboFix3.txt 2009-01-18 13:35:21
ComboFix4.txt 2009-01-17 21:46:30
Före genomsökningen: 22 164 160 512 bytes free
Efter genomsökningen: 12 adresárov, 22,154,334,208 voľných bajtov
231 --- E O F --- 2009-01-14 17:26:06