ComboFix 09-02-28.01 - Dzimb0 2009-03-01 21:16:45.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.2045.1450 [GMT 1:00]
Running from: c:\documents and settings\Dzimb0\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
FW: COMODO Firewall *enabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-02-01 to 2009-03-01 )))))))))))))))))))))))))))))))
.
2009-02-20 20:36 . 2009-02-20 21:11 <DIR> d-------- C:\Downloads
2009-02-20 09:28 . 2009-02-20 09:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\TrackMania
2009-02-15 19:25 . 2009-02-15 19:26 <DIR> d-------- c:\documents and settings\Dzimb0\Application Data\jabbim
2009-02-07 16:57 . 2009-02-07 16:57 <DIR> dr-h----- c:\documents and settings\Dzimb0\Application Data\SecuROM
2009-02-03 17:13 . 2003-03-19 05:05 89,088 --a------ c:\windows\system32\ATL71.DLL
2009-02-01 15:16 . 2009-02-01 15:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-01 20:20 --------- d-----w c:\documents and settings\Dzimb0\Application Data\uTorrent
2009-03-01 20:20 --------- d-----w c:\documents and settings\Dzimb0\Application Data\skypePM
2009-03-01 20:20 --------- d-----w c:\documents and settings\Dzimb0\Application Data\Skype
2009-03-01 14:27 --------- d-----w c:\documents and settings\Dzimb0\Application Data\LimeWire
2009-02-25 20:43 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-25 20:30 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-22 20:38 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-22 18:55 --------- d-----w c:\documents and settings\Dzimb0\Application Data\dvdcss
2009-02-21 07:02 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2009-01-31 22:34 --------- d-----w c:\program files\Google
2009-01-31 16:16 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-31 16:16 --------- d-----w c:\program files\AGEIA Technologies
2009-01-18 16:56 --------- d-----w c:\documents and settings\Dzimb0\Application Data\gtk-2.0
2009-01-13 21:29 --------- d-----w c:\documents and settings\Dzimb0\Application Data\Mp3tag
2009-01-10 18:45 --------- d-----w c:\program files\Yahoo!
2009-01-09 17:25 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-01-05 16:25 --------- d-----w c:\documents and settings\Dzimb0\Application Data\Mount&Blade
2009-01-05 14:10 --------- d-----w c:\documents and settings\Dzimb0\Application Data\BitSpirit
2009-01-01 21:39 --------- d-----w c:\documents and settings\Dzimb0\Application Data\Sony
2009-01-01 21:39 --------- d-----w c:\documents and settings\Dzimb0\Application Data\Publish Providers
2009-01-01 21:35 --------- d-----w c:\program files\Vstplugins
2008-12-26 14:16 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-12-24 13:28 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-19 23:30 81,920 ----a-w c:\windows\system32\frapsvid.dll
2008-12-17 09:57 129,552 ----a-w c:\windows\system32\VBoxNetFltNotify.dll
2008-12-11 14:00 147,192 ----a-w c:\windows\system32\guard32.dll
2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll
2008-12-10 21:57 306,432 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-12-10 19:55 558,142 ----a-w c:\windows\java\Packages\IA179J1B.ZIP
2008-12-10 19:55 155,995 ----a-w c:\windows\java\Packages\F5JLJN1B.ZIP
2008-12-09 02:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-12-01 20:52 425,984 ----a-w c:\windows\system32\ATIDEMGX.dll
2008-12-01 20:51 318,464 ----a-w c:\windows\system32\ati2dvag.dll
2008-12-01 20:46 11,304,960 ----a-w c:\windows\system32\atioglxx.dll
2008-12-01 20:41 188,416 ----a-w c:\windows\system32\atipdlxx.dll
2008-12-01 20:40 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2008-12-01 20:40 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2008-12-01 20:40 147,456 ----a-w c:\windows\system32\Oemdspif.dll
2008-12-01 20:40 143,360 ----a-w c:\windows\system32\ati2evxx.dll
2008-12-01 20:38 598,016 ----a-w c:\windows\system32\ati2evxx.exe
2008-12-01 20:37 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2008-12-01 20:27 4,120,384 ----a-w c:\windows\system32\ati3duag.dll
2008-12-01 20:19 307,200 ----a-w c:\windows\system32\atiiiexx.dll
2008-12-01 20:11 2,495,360 ----a-w c:\windows\system32\ativvaxx.dll
2008-12-01 19:57 48,640 ----a-w c:\windows\system32\amdpcom32.dll
2008-12-01 19:53 45,056 ----a-w c:\windows\system32\amdcalrt.dll
2008-12-01 19:53 45,056 ----a-w c:\windows\system32\amdcalcl.dll
2008-12-01 19:53 401,408 ----a-w c:\windows\system32\atikvmag.dll
2008-12-01 19:52 86,016 ----a-w c:\windows\system32\atiadlxx.dll
2008-12-01 19:52 17,408 ----a-w c:\windows\system32\atitvo32.dll
2008-12-01 19:50 3,252,224 ----a-w c:\windows\system32\Amdcaldd.dll
2008-12-01 19:50 286,720 ----a-w c:\windows\system32\atiok3x2.dll
2008-12-01 19:45 577,536 ----a-w c:\windows\system32\ati2cqag.dll
2008-12-01 13:35 593,920 ------w c:\windows\system32\ati2sgag.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"DAEMON Tools Lite"="d:\programy\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"uTorrent"="d:\programy\uTorrent\uTorrent.exe" [2009-02-19 270128]
"Google Update"="c:\documents and settings\Dzimb0\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-11 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="d:\programy\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"COMODO Firewall Pro"="d:\programy\Comodo\Firewall\cfp.exe" [2008-12-11 1797880]
"COMODO Internet Security"="d:\programy\Comodo\Firewall\cfp.exe" [2008-12-11 1797880]
"Flashget"="d:\programy\FlashGet\FlashGet.exe" [2007-06-29 1990704]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 c:\windows\sttray.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Dzimb0\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - d:\programy\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 23:34 24576 d:\programy\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 d:\programy\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
--a------ 2007-08-27 13:42 517120 d:\programy\ATI Tray Tools\atitray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 20:21 57344 d:\programy\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-12-11 15:15 133104 c:\documents and settings\Dzimb0\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 d:\programy\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-12-24 14:28 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programy\\uTorrent\\uTorrent.exe"=
"d:\\Programy\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Programy\\Cerberus\\Cerberus.exe"=
"d:\\Programy\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Programy\\BitSpirit\\BitSpirit.exe"=
"d:\\Programy\\FlashGet\\flashget.exe"=
"d:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"d:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"d:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 ps6ajtsb;Stalker (Pro) Synchronization Driver (ps6ajtsb);c:\windows\system32\drivers\ps6ajtsb.sys [2007-03-05 52104]
R1 atitray;atitray;d:\programy\ATI Tray Tools\atitray.sys [2007-05-22 18088]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2008-12-10 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-12-10 31504]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-01-10 100368]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-01-10 41680]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;d:\programy\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-12-10 68865]
R2 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-07-05 63352]
R3 PSched;QoS Packet Scheduler;c:\windows\system32\drivers\psched.sys [2002-08-29 69120]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-01-10 81360]
S0 pe3ajtsb;Stalker (Pro) Environment Driver (pe3ajtsb);c:\windows\system32\drivers\pe3ajtsb.sys [2007-03-05 65408]
S2 PDSched;PDScheduler;d:\programy\Raxco\PerfectDisk\PDSched.exe [2005-01-04 237635]
S2 pr2ajtsb;Stalker (Pro) Drivers Auto Removal (pr2ajtsb);c:\windows\system32\pr2ajtsb.exe svc --> c:\windows\system32\pr2ajtsb.exe svc [?]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [2008-12-18 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [2008-12-18 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [2008-12-18 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [2008-12-18 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [2008-12-18 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [2008-12-18 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [2008-12-18 110120]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-02-27 c:\windows\Tasks\1-Click Maintenance.job
- d:\programy\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:17]
2009-03-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-963894560-839522115-1003.job
- c:\documents and settings\Dzimb0\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-11 15:15]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-RGSC - d:\hry\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
.
------- Supplementary Scan -------
.
IE: &Stáhnout &vše FlashGetem - d:\programy\FlashGet\jc_all.htm
IE: &Stáhnout FlashGetem - d:\programy\FlashGet\jc_link.htm
IE: Download Using &BitSpirit - d:\programy\BitSpirit\bsurl.htm
IE: E&xportovať do programu Microsoft Excel - d:\programy\MICROS~1\Office12\EXCEL.EXE/3000
IE: ÓñČĚŘľ«ÁéĎÂÔŘ(&B)
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Dzimb0\Application Data\Mozilla\Firefox\Profiles\dj7lucw8.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.pcforum.sk/index.php
FF - plugin: c:\documents and settings\Dzimb0\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: d:\programy\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: d:\programy\Mozilla Firefox 3\plugins\npyaxmpb.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: d:\programy\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: d:\programz\DivX\DivX Web Player\npdivx32.dll
---- FIREFOX POLICIES ----
d:\programy\Mozilla Firefox 3\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-01 21:20:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\windows\system32\Ati2evxx.dll
d:\programy\AlienGUIse\fastload.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
d:\programy\Avira\AntiVir PersonalEdition Classic\avguard.exe
d:\programy\Comodo\Firewall\cmdagent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-03-01 21:21:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-01 20:21:52
Pre-Run: 5 575 647 232 bytes free
Post-Run: 5,658,685,440 voľných bajtov
225