Zde log z
Combofixu :
----------------------------------------------------
ComboFix 11-08-04.01 - Jakub 04.08.2011 19:11:01.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3037.2454 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jakub\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Java\jre6\core.zip
c:\program files\Java\jre6\patchjre.exe
c:\program files\Java\jre6\zipper.exe
c:\windows\$NtUninstallKB11960$
c:\windows\$NtUninstallKB11960$\1004989089\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB11960$\1004989089\click.tlb
c:\windows\$NtUninstallKB11960$\1004989089\L\kxwnlbnf
c:\windows\$NtUninstallKB11960$\1004989089\loader.tlb
c:\windows\$NtUninstallKB11960$\1004989089\U\@00000001
c:\windows\$NtUninstallKB11960$\1004989089\U\@000000c0
c:\windows\$NtUninstallKB11960$\1004989089\U\@000000cb
c:\windows\$NtUninstallKB11960$\1004989089\U\@000000cf
c:\windows\$NtUninstallKB11960$\1004989089\U\@80000000
c:\windows\$NtUninstallKB11960$\1004989089\U\@800000c0
c:\windows\$NtUninstallKB11960$\1004989089\U\@800000cb
c:\windows\$NtUninstallKB11960$\1004989089\U\@800000cf
c:\windows\$NtUninstallKB11960$\3715359679
c:\windows\assembly\GAC_MSIL\desktop.ini
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
.
Nakažená kopie c:\windows\system32\wuauclt.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\wuauclt.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-04 do 2011-08-04 )))))))))))))))))))))))))))))))
.
.
2011-07-23 19:21 . 2011-07-23 19:21 -------- d-----w- c:\program files\AVAST Software
2011-07-22 13:04 . 2011-07-22 13:04 443448 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-07-22 09:00 . 2009-10-08 09:31 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-07-22 09:00 . 2009-10-08 09:31 165840 ----a-w- c:\windows\PCTBDRes.dll
2011-07-22 09:00 . 2009-10-08 09:31 1636304 ----a-w- c:\windows\PCTBDCore.dll
2011-07-22 09:00 . 2009-10-08 09:31 767952 ----a-w- c:\windows\BDTSupport.dll
2011-07-22 09:00 . 2009-09-24 06:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-07-22 09:00 . 2009-10-06 14:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-07-22 09:00 . 2009-09-23 14:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-07-22 09:00 . 2009-09-03 07:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-07-22 09:00 . 2011-07-22 09:07 -------- d-----w- c:\program files\Spyware Doctor
2011-07-22 09:00 . 2011-07-22 09:00 -------- d-----w- c:\program files\Common Files\PC Tools
2011-07-22 09:00 . 2011-07-22 09:00 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\PC Tools
2011-07-21 11:27 . 2011-07-21 11:27 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Malwarebytes
2011-07-21 09:37 . 2011-07-21 09:48 -------- d-----w- C:\potvůrka.com
2011-07-20 15:22 . 2011-07-20 15:22 -------- d-----w- C:\rsit
2011-07-20 15:22 . 2011-07-20 15:22 -------- d-----w- c:\program files\trend micro
2011-07-20 13:41 . 2011-07-20 13:41 512 ----a-w- C:\PhysicalMBR.bin
2011-07-20 08:15 . 2011-07-20 08:15 -------- d--h--w- c:\windows\PIF
2011-07-19 09:31 . 2011-07-19 09:31 -------- d-----w- c:\program files\Common Files\Pegasus Imaging
2011-07-19 09:31 . 2011-07-19 09:31 -------- d-----w- c:\program files\Common Files\Yahoo!
2011-07-19 09:29 . 2011-07-19 15:47 -------- d-----w- c:\windows\SxsCaPendDel
2011-07-18 19:15 . 2011-07-18 19:15 -------- d-----w- c:\windows\system32\LogFiles
2011-07-18 17:16 . 2008-04-14 11:00 9728 -c----w- c:\windows\system32\dllcache\rwnh.dll
2011-07-18 17:15 . 2008-04-14 11:00 8192 -c----w- c:\windows\system32\dllcache\staxmem.dll
2011-07-18 17:12 . 2008-04-14 11:00 16384 -c----w- c:\windows\system32\dllcache\isignup.exe
2011-07-18 17:12 . 2008-04-14 11:00 16384 ----a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2011-07-18 17:02 . 2011-01-25 08:18 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-07-18 17:02 . 2011-01-25 08:18 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-07-18 17:02 . 2011-01-25 08:16 117760 ------w- c:\windows\system32\COMACF.tmp
2011-07-18 17:02 . 2011-01-25 08:16 594432 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-07-18 17:02 . 2011-01-25 08:15 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-07-18 17:02 . 2011-01-25 08:18 1676288 ------w- c:\windows\system32\COMACB.tmp
2011-07-18 17:02 . 2011-01-25 08:18 575488 ------w- c:\windows\system32\COMACD.tmp
2011-07-18 17:02 . 2011-01-25 08:15 89088 ------w- c:\windows\system32\Spool\prtprocs\w32x86\COMAA5.tmp
2011-07-18 17:02 . 2011-01-25 08:16 594432 ------w- c:\windows\system32\Spool\prtprocs\w32x86\COMAA3.tmp
2011-07-18 17:01 . 2011-01-25 08:17 934792 -c----w- c:\windows\system32\dllcache\WgaTray.exe
2011-07-18 17:01 . 2011-01-25 08:17 239496 -c----w- c:\windows\system32\dllcache\wgaLogon.dll
2011-07-18 17:01 . 2011-01-25 08:15 922112 -c----w- c:\windows\system32\dllcache\imapi2fs.dll
2011-07-18 17:01 . 2011-01-25 08:15 426496 -c----w- c:\windows\system32\dllcache\imapi2.dll
2011-07-18 17:00 . 2011-01-25 08:13 293376 -c----w- c:\windows\system32\dllcache\browserchoice.exe
2011-07-18 16:50 . 2008-04-14 11:00 13312 -c----w- c:\windows\system32\dllcache\irclass.dll
2011-07-18 16:50 . 2008-04-14 11:00 13312 ------w- c:\windows\system32\irclass.dll
2011-07-18 16:50 . 2008-04-14 11:00 24661 -c----w- c:\windows\system32\dllcache\spxcoins.dll
2011-07-18 16:50 . 2008-04-14 11:00 24661 ------w- c:\windows\system32\spxcoins.dll
2011-07-18 10:08 . 2011-07-18 10:08 -------- d-----w- c:\windows\ufa
2011-07-18 10:08 . 2011-07-18 10:10 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 10:08 . 2011-07-18 10:08 180224 ----a-w- c:\program files\Windows NT\dwm.exe
2011-07-18 10:08 . 2011-07-18 10:08 180224 ----a-w- c:\program files\Windows NT\Windows NT\dwm.exe
2011-07-18 10:06 . 2011-07-18 10:06 -------- d-----w- c:\windows\Options
2011-07-18 10:06 . 2009-06-22 10:59 1574112 ------w- c:\windows\system32\drivers\athw.sys
2011-07-18 10:06 . 2009-06-22 10:59 1574112 ------w- c:\windows\system32\athw.sys
2011-07-18 10:06 . 2011-07-18 10:06 -------- d-----w- C:\temp
2011-07-18 08:45 . 2011-07-18 08:45 -------- d-----w- c:\windows\av_ico
2011-07-18 08:44 . 2011-07-18 08:44 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-07-18 08:34 . 2011-07-18 08:34 404640 ------w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-18 08:34 . 2011-07-18 08:34 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-07-18 08:33 . 2011-07-18 08:33 -------- d-----w- c:\documents and settings\LocalService\Nabídka Start
2011-07-17 15:44 . 2011-07-17 15:45 -------- d-----w- c:\program files\Kodek CZ
2011-07-16 19:48 . 2011-07-16 19:48 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Media Get LLC
2011-07-16 19:47 . 2011-07-18 09:20 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\MediaGet2
2011-07-16 19:45 . 2005-09-23 20:18 171520 ------w- c:\windows\system32\drivers\MarvinBus.sys
2011-07-16 19:45 . 2011-07-16 19:45 -------- d-----w- c:\program files\Common Files\Pinnacle
2011-07-16 19:45 . 2011-07-16 19:45 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Downloaded Installations
2011-07-16 19:45 . 2011-07-16 19:45 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Pinnacle
2011-07-16 19:44 . 2011-07-19 20:34 -------- d-----w- c:\documents and settings\All Users\Data aplikac
2011-07-16 19:41 . 2011-07-19 09:31 -------- d-----w- c:\program files\Pinnacle
2011-07-16 19:32 . 2011-07-16 19:32 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Adobe
2011-07-16 19:32 . 2011-07-16 19:32 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-16 18:40 . 2011-07-16 19:32 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Temp
2011-07-16 18:40 . 2011-07-16 18:40 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2011-07-16 18:40 . 2011-07-16 18:45 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Google
2011-07-16 18:40 . 2011-07-16 18:40 -------- d-----w- c:\program files\Google
2011-07-16 18:40 . 2011-07-18 10:09 -------- d-----w- c:\program files\DivX
2011-07-16 18:36 . 2011-08-04 07:13 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\skypePM
2011-07-16 18:36 . 2011-08-04 14:34 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Skype
2011-07-16 18:36 . 2011-07-16 18:36 -------- d-----w- c:\program files\Common Files\Skype
2011-07-16 18:35 . 2011-07-16 18:36 -------- d-----r- c:\program files\Skype
2011-07-16 18:12 . 2011-08-04 16:25 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Mirillis
2011-07-16 18:12 . 2011-07-16 18:12 -------- d-----w- c:\documents and settings\Jakub\Data aplikací\Mirillis
2011-07-16 18:10 . 2011-07-16 18:10 -------- d-----w- c:\program files\Mirillis
2011-07-16 17:58 . 2011-07-16 17:58 -------- d-----w- c:\program files\DsNET Corp
2011-07-16 17:37 . 2011-07-16 17:37 -------- d-----w- c:\documents and settings\Jakub\Local Settings\Data aplikací\Mozilla
2011-07-16 17:32 . 2011-07-19 09:22 -------- d-----w- c:\documents and settings\All Users\Studio14Trial
2011-07-16 16:03 . 2011-07-16 16:03 -------- d-sh--w- c:\documents and settings\Jakub\IECompatCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-04 10:49 . 2011-07-04 10:50 73728 ------w- c:\windows\system32\javacpl.cpl
2011-07-04 10:49 . 2011-07-04 10:50 472808 ------w- c:\windows\system32\deployJava1.dll
2011-06-02 17:53 . 2011-06-02 17:53 94208 ------w- c:\windows\system32\dpl100.dll
2011-07-08 07:29 . 2011-07-16 17:37 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-01-25 . 8F41FD1CC693054347C6FB7B0E618B07 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-07-20_16.16.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2007-11-07 00:19 . 2007-11-07 00:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
- 2007-11-06 23:19 . 2007-11-06 23:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 04:07 . 2008-07-29 04:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-04-14 11:00 . 2011-08-04 07:05 87344 c:\windows\system32\perfc009.dat
- 2008-04-14 11:00 . 2011-07-20 07:21 87344 c:\windows\system32\perfc009.dat
- 2011-01-25 08:09 . 2011-01-25 08:09 62976 c:\windows\system32\drivers\cdrom.sys
+ 2011-01-25 08:09 . 2008-04-13 18:40 62976 c:\windows\system32\drivers\cdrom.sys
+ 2011-08-03 11:51 . 2011-08-03 11:51 22016 c:\windows\Installer\1022b94.msi
+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 01:54 . 2008-07-29 01:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2011-07-04 10:32 . 2011-01-25 08:17 186880 c:\windows\system32\searchprotocolhost.exe
+ 2011-07-04 10:32 . 2011-01-25 08:17 441856 c:\windows\system32\searchindexer.exe
- 2008-04-14 11:00 . 2011-07-20 07:21 501716 c:\windows\system32\perfh009.dat
+ 2008-04-14 11:00 . 2011-08-04 07:05 501716 c:\windows\system32\perfh009.dat
+ 2008-04-14 11:00 . 2011-08-04 07:05 517560 c:\windows\system32\perfh005.dat
- 2008-04-14 11:00 . 2011-07-20 07:21 517560 c:\windows\system32\perfh005.dat
- 2008-04-14 11:00 . 2011-07-20 07:21 110088 c:\windows\system32\perfc005.dat
+ 2008-04-14 11:00 . 2011-08-04 07:05 110088 c:\windows\system32\perfc005.dat
+ 2011-08-04 07:07 . 2011-08-04 07:07 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2011-07-21 20:25 . 2011-07-21 20:25 228352 c:\windows\Installer\d9032.msi
+ 2011-07-23 19:22 . 2011-07-23 19:22 219648 c:\windows\Installer\89597.msi
+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 06:05 . 2008-07-29 06:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DWPersistentQueuedReporting"="c:\program files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE" [2006-10-26 434528]
"PLFSetI"="c:\windows\PLFSetI.exe" [2008-07-29 200704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-11 13594624]
"nwiz"="nwiz.exe" [2009-03-11 1657376]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-11 86016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"KB976002-v5"="advpack.dll" [2011-01-25 128512]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-6-20 607584]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2011-7-4 123904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2011-01-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"d:\\HRY\\Battlefield 2\\BF2.exe"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [22.7.2011 11:00 207280]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [28.4.2010 8:17 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2.7.2010 12:43 94360]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [22.7.2011 11:00 112592]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [4.7.2011 13:45 39424]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [25.1.2011 10:15 9472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4.7.2011 12:35 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [16.7.2011 20:40 135664]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [16.7.2011 20:40 135664]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [22.7.2011 11:00 358600]
S3 WinRM;Vzdálená správa systému Windows (WS-Management);c:\windows\System32\svchost.exe -k WinRM [25.1.2011 10:12 14848]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPFFontCache_v0400.exe --> c:\windows\Microsoft.NET\Framework\v4.0.30319\WPFFontCache_v0400.exe [?]
S4 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-16 18:40]
.
2011-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-16 18:40]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 213.46.172.36 213.46.172.37
FF - ProfilePath - c:\documents and settings\Jakub\Data aplikací\Mozilla\Firefox\Profiles\gc73v2we.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.cz/
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 55333
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-04 19:22
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
.
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
.
- - - - - - - > 'explorer.exe'(676)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\RUNDLL32.EXE
c:\windows\System32\NOTEPAD.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-08-04 19:23:39 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-04 17:23
ComboFix2.txt 2011-07-21 09:48
ComboFix3.txt 2011-07-20 16:18
.
Před spuštěním: Volných bajtů: 142 567 960 576
Po spuštění: Volných bajtů: 142 576 504 832
.
- - End Of File - - BD78FD317706B5167EC6B7124596AE56