ComboFix 11-10-28.04 - prolimit 28.10.2011 17:47:18.4.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.712 [GMT 2:00]
Spuštěný z: c:\documents and settings\prolimit\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\prolimit\Plocha\CFScript.txt
.
FILE ::
"c:\windows\system32\drivers\cpuz135_x32.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\cpuz135_x32.sys
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_CPUZ135
-------\Service_cpuz135
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-28 do 2011-10-28 )))))))))))))))))))))))))))))))
.
.
2011-10-28 00:09 . 2011-10-28 00:09 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\Auslogics
2011-10-28 00:09 . 2011-10-28 00:09 -------- d-----w- c:\program files\Auslogics
2011-10-27 10:24 . 2006-07-01 20:42 43008 ----a-w- c:\windows\system32\drivers\AmdK8.sys
2011-10-27 10:24 . 2011-10-27 10:24 -------- d-----w- c:\program files\AMD
2011-10-27 09:40 . 2011-10-27 09:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-27 09:40 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-26 20:08 . 2009-11-02 15:47 11520 ----a-w- c:\windows\system32\drivers\gMouUsb.sys
2011-10-26 20:08 . 2009-11-02 15:43 20480 ----a-w- c:\windows\system32\drivers\gHidPnp.sys
2011-10-26 20:07 . 2011-10-26 20:07 -------- d-----w- C:\Genius
2011-10-26 20:06 . 2011-10-26 20:06 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\InstallShield
2011-10-26 10:22 . 2011-10-26 10:22 -------- d-----w- c:\windows\system32\oodag
2011-10-26 10:21 . 2011-10-26 10:21 -------- d-----w- c:\documents and settings\prolimit\Local Settings\Data aplikací\O&O
2011-10-26 10:20 . 2011-10-26 10:20 -------- d-----w- c:\program files\Microsoft Bootvis
2011-10-25 23:05 . 2011-10-25 23:05 -------- d-----w- c:\program files\MSXML 4.0
2011-10-24 15:53 . 2011-10-24 15:53 -------- d-----r- c:\program files\Skype
2011-10-14 12:26 . 2011-10-25 18:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-10-14 12:19 . 2011-10-14 12:19 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\SUPERAntiSpyware.com
2011-10-14 12:18 . 2011-10-14 12:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-10-14 12:18 . 2011-10-14 12:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2011-10-09 09:59 . 2011-10-09 13:56 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\Wippien
2011-10-09 09:59 . 2007-06-27 13:23 23904 ----a-w- c:\windows\system32\drivers\wip0202.sys
2011-10-09 09:28 . 2011-10-09 09:28 -------- d-----w- c:\program files\TeamViewer
2011-10-08 08:36 . 1997-06-06 13:52 11264 ----a-w- c:\windows\system32\SPORDER.DLL
2011-10-08 08:30 . 2011-10-08 08:37 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\Hide IP NG
2011-10-08 08:28 . 2011-10-08 08:39 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\HideIP
2011-10-08 08:24 . 2011-10-08 08:37 -------- d-----w- c:\program files\IP Changer Premium
2011-10-07 09:01 . 2011-10-07 09:01 -------- d-----w- c:\windows\OPTIONS
2011-10-06 19:16 . 2011-10-06 19:17 -------- d-----w- c:\program files\SpeedFan
2011-10-04 14:22 . 2011-10-04 14:22 -------- d-----w- c:\program files\Windows Media Connect 2
2011-10-04 13:53 . 2008-09-10 16:58 270336 ----a-w- c:\windows\system32\CMRMDRV3.exe
2011-10-04 13:45 . 2008-09-11 09:10 278528 ----a-w- c:\windows\CmiPCIUninstall.exe
2011-10-04 13:44 . 2011-10-04 13:52 -------- d-----w- c:\program files\C-Media PCI Audio Device
2011-10-04 13:44 . 2009-03-18 09:34 1512960 ----a-w- c:\windows\system32\drivers\cmudax3.sys
2011-10-04 13:44 . 2007-02-26 18:30 36864 ----a-w- c:\windows\system32\cmudax3.DLL
2011-10-02 12:53 . 2006-05-03 09:57 520192 ------w- c:\windows\system32\ati2sgag.exe
2011-10-02 12:53 . 2011-10-02 12:54 -------- d-----w- c:\program files\ATI Technologies
2011-10-02 12:43 . 2004-05-15 03:27 15195 ----a-w- c:\windows\system32\delrad.exe
2011-10-02 12:36 . 2011-10-02 12:36 -------- d-----w- c:\documents and settings\prolimit\Data aplikací\atitray
2011-10-02 12:30 . 2011-10-02 12:30 472576 ----a-w- c:\windows\Radeon Omega Drivers v4.8.442 Uninstall.exe
2011-10-02 12:30 . 2011-10-02 12:30 -------- d-----w- c:\program files\Radeon Omega Drivers
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:20 . 2011-06-02 08:55 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 09:41 . 2007-10-09 12:03 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2001-10-25 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2001-10-25 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-15 16:55 . 2011-04-09 11:20 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-09-09 09:12 . 2008-04-14 06:51 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 14:10 . 2008-04-14 05:45 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-14 06:52 668160 ----a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-14 06:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-09-05 13:56 . 2008-04-14 06:50 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:55 . 2008-04-14 05:50 370176 ----a-w- c:\windows\system32\html.iec
2011-08-29 10:44 . 2011-03-14 20:49 17488 ----a-w- c:\windows\gdrv.sys
2011-08-17 13:49 . 2008-04-13 22:49 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-12 11:51 . 2011-01-14 13:19 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-08-08 07:49 . 2011-08-08 07:49 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2011-08-08 07:49 . 2011-08-08 07:49 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2011-08-08 07:49 . 2011-08-08 07:49 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2011-09-30 18:48 . 2011-03-22 19:51 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"GreyMSIAds"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Hlavní panel ATI CATALYST.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Hlavní panel ATI CATALYST.lnk
backup=c:\windows\pss\Hlavní panel ATI CATALYST.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cli]
2006-01-02 14:41 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dxdllreg]
2002-12-11 23:14 46592 ----a-w- c:\windows\system32\dxdllreg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 00:41 49152 ----a-w- d:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ioCentre]
2009-09-03 09:30 61440 ----a-w- c:\genius\ioCentre\gTaskBar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
2008-04-14 06:52 171008 ----a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2011-01-12 10:07 2729800 ----a-w- d:\program files\OO Software\Defrag\oodtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-09-12 10:35 17351304 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SlimDrivers]
2011-09-07 09:32 27473760 ----a-w- d:\program files\SlimDrivers\SlimDrivers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-08-02 07:27 1242448 ----a-w- c:\program files\Steam\steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-04-08 10:59 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"wuauserv"=2 (0x2)
"Schedule"=2 (0x2)
"OODefragAgent"=2 (0x2)
"helpsvc"=2 (0x2)
"GeniusMouseService"=2 (0x2)
"BthServ"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"!SASCORE"=2 (0x2)
"CryptSvc"=2 (0x2)
"ATI Smart"=2 (0x2)
"LCS"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\active152\\counter-strike\\hl.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58689:TCP"= 58689:TCP:Pando Media Booster
"58689:UDP"= 58689:UDP:Pando Media Booster
"26293:TCP"= 26293:TCP:BitComet 26293 TCP
"26293:UDP"= 26293:UDP:BitComet 26293 UDP
"58347:TCP"= 58347:TCP:Pando Media Booster
"58347:UDP"= 58347:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.12.2010 12:06 642560]
R1 atitray;atitray;c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [2.10.2011 14:30 17952]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [26.10.2011 22:08 20480]
R3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [26.10.2011 22:08 11520]
R3 MouseCap;MouseCapture Driver;c:\windows\system32\drivers\MouseCap.sys [8.8.2005 14:44 6640]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [8.8.2011 9:42 27632]
S1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [10.11.2006 15:08 24064]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [26.8.2011 8:29 136176]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [8.8.2011 9:49 13224]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [26.8.2011 8:29 136176]
S3 NLNdisMP;NLNdisMP; [x]
S3 NLNdisPT;NetLimiter Ndis Protocol Service; [x]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [19.8.2011 19:40 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [19.8.2011 19:40 11104]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [8.8.2011 9:32 90408]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [8.8.2011 9:32 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [8.8.2011 9:32 122024]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [8.8.2011 9:32 115368]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [8.8.2011 9:32 25768]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [8.8.2011 9:32 111784]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [8.8.2011 9:32 117544]
S3 skfilt;skfilt;c:\windows\system32\drivers\skfilt.sys [15.3.2011 7:36 1670016]
S3 USBPNPA;USB PnP Sound Device Interface; [x]
S3 wip0202;Wippien Network Adapter;c:\windows\system32\drivers\wip0202.sys [9.10.2011 11:59 23904]
S4 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
S4 AODService;AODService; [x]
S4 GeniusMouseService;GeniusMouseService;c:\genius\ioCentre\GMouseService.exe [26.10.2011 22:08 12288]
S4 OODefragAgent;O&O Defrag Agent;d:\program files\OO Software\Defrag\oodag.exe [12.1.2011 12:06 2335560]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://nix.cz/IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 212.158.124.142 192.168.1.1
TCP: Interfaces\{9370BAAC-8365-48D3-B655-EA61841021C3}: NameServer = 212.158.124.142
FF - ProfilePath - c:\documents and settings\prolimit\Data aplikací\Mozilla\Firefox\Profiles\j26hh4ac.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: network.proxy.http - 213.168.187.130
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.type - 4
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-10-28 17:55
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(900)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3492)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2011-10-28 17:57:39 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-28 15:57
ComboFix2.txt 2011-10-27 14:13
.
Před spuštěním: 8 031 780 864
Po spuštění: 7 979 851 776
.
- - End Of File - - 5D226F22B55B095BE5526067388BD3C5
i7-2700K, GB Z77M-D3H, MSI R9 380 Gaming 4G, 1x4GB 1x8GB 1600 Kingstone, 256GB SSD (Intel), 1TB 2,5" WD Black, NZXT S340 + Be Quiet! Pure Power L8-530W + 6xF12 LS