ComboFix 10-08-07.02 - Kátai 010.08.08. 17:09:38.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.36.1038.18.631.192 [GMT 2:00]
Running from: c:\documents and settings\Kátai\Asztal\ComboFix.exe
AV: avast! Internet Security *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\Temp
c:\program files\Common Files\Temp\Love's Power Mahjong SETUP.exe
c:\program files\Common Files\Temp\unins000.dat
c:\program files\Common Files\Temp\unins000.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-08 to 2010-08-08 )))))))))))))))))))))))))))))))
.
2010-08-08 12:37 . 2010-06-28 20:39 312912 -c--a-w- c:\windows\system32\drivers\aswSnx.sys
2010-08-08 12:37 . 2010-06-28 20:39 99280 -c--a-w- c:\windows\system32\drivers\aswFW.sys
2010-08-08 12:36 . 2010-06-28 20:38 188168 -c--a-w- c:\windows\system32\drivers\aswNdis2.sys
2010-08-08 12:36 . 2010-06-28 20:33 23376 -c--a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-08 12:36 . 2010-06-28 20:32 100176 -c--a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-08 12:36 . 2010-06-28 20:32 94544 -c--a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-08 12:36 . 2010-06-28 20:32 28880 -c--a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-08 12:35 . 2010-06-28 20:10 12112 -c--a-w- c:\windows\system32\drivers\aswNdis.sys
2010-08-08 12:35 . 2010-06-28 20:57 38848 -c--a-w- c:\windows\avastSS.scr
2010-08-08 12:35 . 2010-06-28 20:57 165032 -c--a-w- c:\windows\system32\aswBoot.exe
2010-08-08 12:35 . 2010-08-08 12:35 -------- dc----w- c:\program files\Alwil Software
2010-08-08 11:11 . 2010-06-28 20:37 165456 -c----w- c:\windows\system32\drivers\aswSP.sys
2010-08-08 11:11 . 2010-06-28 20:32 17744 -c----w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-08 11:11 . 2010-06-28 20:37 46672 -c--a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-08 09:10 . 2010-04-29 13:39 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-08 09:10 . 2010-08-08 09:10 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-08 09:10 . 2010-04-29 13:39 20952 -c--a-w- c:\windows\system32\drivers\mbam.sys
2010-08-05 18:37 . 2010-08-05 18:38 -------- dc----w- c:\program files\Common Files\ComObject
2010-08-05 18:05 . 2010-08-05 18:05 -------- dc----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-08-03 17:34 . 2010-08-03 19:32 -------- dc----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-27 06:29 . 2010-07-27 06:29 8484352 -c----w- c:\windows\system32\dllcache\shell32.dll
2010-07-15 11:22 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-05 19:49 . 2009-07-15 17:04 -------- dc--a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-23 18:37 . 2009-07-15 15:44 -------- dc-h--w- c:\program files\InstallShield Installation Information
2010-06-23 17:50 . 2010-06-23 17:50 -------- dc----w- c:\program files\GameHouse
2010-06-23 17:08 . 2010-06-23 17:08 -------- dc----w- c:\program files\Digital Memory v2.50
2010-06-23 16:41 . 2010-06-23 16:41 1574912 -c--a-w- C:\siw.exe
2010-06-14 14:31 . 2009-07-15 14:03 744448 -c--a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-19 16:17 . 2010-05-19 16:17 9 -c--a-w- C:\MRACE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\snxPluginsShell]
@="{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}"
[HKEY_CLASSES_ROOT\CLSID\{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE}]
2010-06-28 20:59 153184 -c--a-w- c:\program files\Alwil Software\Avast5\snxPlugins.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskMngr"="wscript.exe" [2009-01-30 155648]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [2010.08.08. 14:35 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [2010.08.08. 14:36 188168]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [2010.08.08. 14:37 99280]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2010.08.08. 14:37 312912]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010.08.08. 13:11 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010.08.08. 13:11 17744]
R3 trid3d;trid3d;c:\windows\system32\drivers\trid3dm.sys [2009.07.15. 17:40 142748]
S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [2010.08.08. 14:35 119200]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASWFW
*NewlyCreated* - ASWSNX
*NewlyCreated* - AVAST!_ANTIVIRUS
*NewlyCreated* - AVAST!_FIREWALL
*NewlyCreated* - AVAST!_MAIL_SCANNER
*NewlyCreated* - AVAST!_WEB_SCANNER
.
Contents of the 'Scheduled Tasks' folder
2010-07-28 c:\windows\Tasks\Auslogics Console Defragmentation.job
- c:\program files\Auslogics\Auslogics Disk Defrag\cdefrag.exe [2010-03-17 10:07]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://home.myplaycity.com/IE: E&xportálás Microsoft Excel formátumba - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: {E9E7F3B9-8322-4841-8F23-EDBA3719AA5C} = 212.24.187.210
FF - ProfilePath - c:\documents and settings\Kátai\Application Data\Mozilla\Firefox\Profiles\y4t0jzqb.default\
FF - prefs.js: browser.startup.homepage -
hxxp://home.myplaycity.com/---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Love's Power Mahjong_is1 - c:\program files\Common Files\Temp\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-08 17:30
Windows 5.1.2600 Szervizcsomag 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-08-08 17:34:19
ComboFix-quarantined-files.txt 2010-08-08 15:34
Pre-Run: 5 049 724 928 bájt szabad
Post-Run: 5 319 249 920 bájt szabad
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional - magyar" /noexecute=optin /fastdetect
- - End Of File - - C00CA6CFB9976A8D1F40DBFE82F3840C
Ez a sok avastos cucc, annak a következménye, hogy először egy sima avastot akartam feltenni, de sehogy sem tudtam levenni csak csökkentett módban?