ComboFix 13-09-23.02 - PC 23.09.2013 18:57:03.5.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.662 [GMT 2:00]
Spuštěný z: c:\documents and settings\PC\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\PC\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ESET
c:\program files\ESET\ESET Online Scanner\esets_apiA.dll
c:\program files\ESET\ESET Online Scanner\esets_apiW.dll
c:\program files\ESET\ESET Online Scanner\esets_apiW_a.dll
c:\program files\ESET\ESET Online Scanner\ESETSmartInstaller.exe
c:\program files\ESET\ESET Online Scanner\log.txt
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\continuous\nod2BFC.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\continuous\nod6B95.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\http_update.eset.com\update.ver
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\lastupd.ver
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod02E1.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod05B9.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod0B18.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod160C.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod3069.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod3169.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod3613.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod3839.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod4037.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod4876.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod5A2F.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod6266.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod675C.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod6A77.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod6D26.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod7127.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\nod798A.nup
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\oldfiles\em002_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\oldfiles\em023_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\temp\em002_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\temp\em023_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\data\updfiles\upd.ver
c:\program files\ESET\ESET Online Scanner\Modules\em000_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em001_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em002_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em003_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em004_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em005_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em006_32.dat
c:\program files\ESET\ESET Online Scanner\Modules\em023_32.dat
c:\program files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
c:\program files\ESET\ESET Online Scanner\OnlineCmdLineScannerA.exe
c:\program files\ESET\ESET Online Scanner\OnlineScanner.cab
c:\program files\ESET\ESET Online Scanner\OnlineScanner.inf
c:\program files\ESET\ESET Online Scanner\OnlineScanner.ocx
c:\program files\ESET\ESET Online Scanner\OnlineScanner64.ocx
c:\program files\ESET\ESET Online Scanner\OnlineScannerApp.exe
c:\program files\ESET\ESET Online Scanner\OnlineScannerLang.dll
c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
c:\program files\ESET\ESET Online Scanner\unicows.dll
c:\program files\Skype\Updater
c:\program files\Skype\Updater\Updater.dll
c:\program files\Skype\Updater\Updater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SKYPEUPDATE
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-08-23 do 2013-09-23 )))))))))))))))))))))))))))))))
.
.
2013-09-22 21:51 . 2013-09-22 21:51 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-09-22 21:51 . 2013-09-22 21:51 -------- d-----w- c:\documents and settings\PC\Local Settings\Data aplikací\eSupport.com
2013-09-22 17:29 . 2010-02-10 19:20 77824 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2013-09-22 17:29 . 2010-02-10 19:20 32768 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2013-09-22 17:29 . 2010-02-10 19:20 221184 ----a-w- c:\program files\Common Files\InstallShield\IScript\IScript.dll
2013-09-22 17:29 . 2010-02-10 19:20 217088 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2013-09-22 17:29 . 2010-02-10 19:20 212992 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2013-09-22 17:21 . 2013-09-22 17:21 -------- d-----w- c:\program files\CPUID
2013-09-22 12:50 . 2013-09-22 12:50 -------- d-----w- c:\windows\ERUNT
2013-09-21 23:14 . 2013-09-22 12:34 -------- d-----w- C:\AdwCleaner
2013-09-21 22:58 . 2013-09-21 22:58 -------- d-----w- c:\documents and settings\PC\Data aplikací\Malwarebytes
2013-09-21 22:58 . 2013-09-21 22:58 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2013-09-21 22:12 . 2013-09-21 22:12 -------- d-----w- c:\program files\Trend Micro
2013-09-17 08:58 . 2013-06-18 14:21 91544 ----a-w- c:\program files\Mozilla Firefox\updated\nssdbm3.dll
2013-09-05 14:04 . 2013-09-05 14:04 209272 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-09-05 14:04 . 2013-09-05 14:04 209272 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
2013-08-28 18:14 . 2013-08-28 18:20 -------- d-----w- c:\program files\Mozilla Thunderbird
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-22 13:53 . 2012-09-07 12:23 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-22 13:53 . 2012-08-17 23:39 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-08-09 01:56 . 2006-03-02 12:00 386560 ----a-w- c:\windows\system32\themeui.dll
2013-08-08 06:09 . 2006-03-02 12:00 1877760 ----a-w- c:\windows\system32\win32k.sys
2013-08-08 06:05 . 2006-03-02 12:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2006-03-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2006-03-02 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2006-03-02 12:00 18944 ----a-w- c:\windows\system32\corpol.dll
2013-08-08 00:02 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2006-03-02 12:00 1289216 ----a-w- c:\windows\system32\ole32.dll
2013-08-02 23:48 . 2006-10-18 20:47 1543680 ------w- c:\windows\system32\wmvdecod.dll
2013-07-10 10:37 . 2006-03-02 12:00 406016 ----a-w- c:\windows\system32\usp10.dll
2013-07-04 07:34 . 2004-08-17 15:45 2072320 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-07-04 07:34 . 2006-03-02 12:00 2195712 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-06-27 21:30 . 2013-05-13 17:18 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-27 21:30 . 2011-12-22 18:00 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-06-27 21:30 . 2011-12-22 18:00 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2009-03-31 20:47 . 2013-04-11 22:17 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 577536]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"DivXMediaServer"="c:\program files\DivX\DivX Media Server\DivXMediaServer.exe" [2013-04-15 450560]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2013-02-13 02:37 1263952 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 21:32 53248 ------w- c:\program files\REGSHAVE\REGSHAVE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2013-06-21 07:58 19875432 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd3]
2006-09-19 08:07 827392 ----a-w- c:\windows\vsnpstd3.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
2009-02-20 15:55 326656 ----a-w- c:\windows\tsnpstd3.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"N360"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [13.5.2013 19:18 49376]
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [13.5.2013 19:18 175176]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19.5.2010 22:43 691696]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [22.12.2011 20:00 770344]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [22.12.2011 20:00 369584]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [14.5.2009 18:07 759048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [22.12.2011 20:00 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [13.5.2013 19:18 66336]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [22.9.2013 23:51 23456]
.
Obsah adresáře 'Naplánované úlohy'
.
2013-09-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-07 13:53]
.
2013-09-23 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-02 08:58]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.bing.comTCP: DhcpNameServer = 192.168.100.1
DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} -
hxxp://games.bigfishgames.com/en_fashio ... 0.0.21.cabDPF: {055B4212-4C81-448E-AFA9-C3CA4AAE8F95} -
hxxp://games.bigfishgames.com/en_dairy- ... 0.0.15.cabDPF: {21BB8360-F943-447E-98F3-3C22345375A7} -
hxxp://games.bigfishgames.com/en_chocol ... 0.0.13.cabDPF: {6C7CAD20-85AA-475A-AC0D-303C4A9A69CE} -
hxxp://games.bigfishgames.com/en_great- ... 0.0.12.cabDPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -
hxxp://game.zylom.com/activex/zylomgamesplayer.cabDPF: {D40F5876-A494-4124-8161-82625BB28C06} -
hxxp://games.bigfishgames.com/en_chocol ... 0.0.10.cabDPF: {FCB28D51-A017-46B2-9FB3-F7BFD53B2E42} -
hxxp://games.bigfishgames.com/en_chocol ... .0.0.6.cabFF - ProfilePath - c:\documents and settings\PC\Data aplikací\Mozilla\Firefox\Profiles\wjfurlfy.default\
FF - prefs.js: browser.startup.homepage -
www.seznam.czFF - ExtSQL: 2013-08-29 19:34; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\documents and settings\PC\Data aplikacĂÂ\Mozilla\Firefox\Profiles\wjfurlfy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2013-09-23 19:05
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3692)
c:\program files\RocketDock\RocketDock.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\bgsvcgen.exe
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Celkový čas: 2013-09-23 19:08:35 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-09-23 17:08
ComboFix2.txt 2013-09-23 16:18
ComboFix3.txt 2013-09-23 12:39
ComboFix4.txt 2013-09-22 20:15
ComboFix5.txt 2013-09-23 16:55
.
Před spuštěním: Volných bajtů: 65 662 832 640
Po spuštění: Volných bajtů: 65 558 188 032
.
- - End Of File - - F95161FF66E542F14859CE9D97D1B657
413FC2A0C716421B3158746D63736515