dobry den
ComboFix 12-07-30.03 - Dalin 02.08.2012 10:26:38.5.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.1219 [GMT 2:00]
Spuštěný z: c:\documents and settings\Dalin\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Dalin\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
FILE ::
"c:\windows\Tasks\Adobe Flash Player Updater.job"
"c:\windows\Tasks\AdobeAAMUpdater-1.0-QUAD-Dalin.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\Adobe Flash Player Updater.job
c:\windows\Tasks\AdobeAAMUpdater-1.0-QUAD-Dalin.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_5641
-------\Legacy_GUARD.MAIL.RU
-------\Legacy_GUPDATE
-------\Service_5641
-------\Service_Guard.Mail.ru
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-07-02 do 2012-08-02 )))))))))))))))))))))))))))))))
.
.
2012-08-01 01:35 . 2012-08-01 01:35 -------- d-----w- c:\program files\LooksBuilder
2012-07-31 21:16 . 2012-07-31 21:16 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-31 08:02 . 2012-07-31 08:02 -------- d-----w- c:\documents and settings\Dalin\Local Settings\Data aplikací\PCHealth
2012-07-31 04:37 . 2012-06-02 13:18 214256 ----a-w- c:\windows\system32\muweb.dll
2012-07-31 04:37 . 2012-06-02 13:18 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-07-30 11:38 . 2012-07-30 20:46 -------- d-----w- C:\rsit
2012-07-30 11:24 . 2012-07-30 11:24 -------- d-----w- C:\RK_Quarantine
2012-07-27 14:37 . 2012-07-29 20:57 -------- d-----w- c:\documents and settings\Dalin\Data aplikací\vlc
2012-07-26 22:19 . 2012-07-31 06:35 -------- d-----w- c:\program files\Microsoft Works
2012-07-26 22:17 . 2012-07-26 22:17 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-07-26 22:17 . 2012-07-26 22:19 -------- d-----w- c:\windows\SHELLNEW
2012-07-26 22:16 . 2012-07-26 22:16 -------- d-----r- C:\MSOCache
2012-07-26 07:36 . 2011-03-17 10:08 -------- d-----w- C:\SigerTools
2012-07-25 09:03 . 2012-07-25 09:03 -------- d-----w- C:\Downloads
2012-07-25 09:02 . 2012-08-02 08:26 -------- d-----w- c:\documents and settings\Dalin\Data aplikací\BitComet
2012-07-25 09:02 . 2012-07-25 09:02 -------- d-----w- c:\program files\BitComet
2012-07-19 17:29 . 2012-07-19 17:29 -------- d-----w- c:\program files\CrystalDiskInfo
2012-07-17 23:56 . 2012-07-27 10:56 90112 ----a-w- c:\windows\DUMP4892.tmp
2012-07-16 11:17 . 2012-07-30 20:45 -------- d-----w- c:\program files\trend micro
2012-07-05 16:45 . 2012-07-05 16:45 5030088 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-02 08:03 . 2012-02-16 03:42 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2012-07-31 21:20 . 2008-04-14 12:00 188288 ----a-w- c:\windows\system32\drivers\acpi.sys
2012-07-27 09:53 . 2012-04-02 07:28 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-27 09:53 . 2012-02-16 11:21 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-25 14:04 . 2012-06-25 14:04 1394248 ----a-w- c:\windows\system32\msxml4.dll
2012-06-13 13:55 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:49 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:49 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2009-08-06 17:24 22552 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2012-02-16 01:24 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2012-02-16 01:24 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 13:19 . 2012-02-16 01:24 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2012-02-16 01:24 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2012-02-16 01:24 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 13:19 . 2009-08-06 17:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2009-08-06 17:24 18456 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2009-08-06 17:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2008-04-14 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2012-02-16 01:24 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2012-02-16 01:24 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:09 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-11 14:44 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:44 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-05-09 21:24 . 2012-05-09 21:24 45056 ----a-r- c:\documents and settings\Dalin\Data aplikací\Microsoft\Installer\{91057632-CA70-413C-B628-2D3CDBBB906B}\ARPPRODUCTICON.exe
2012-05-09 21:23 . 2012-05-09 21:23 45056 ----a-r- c:\documents and settings\Dalin\Data aplikací\Microsoft\Installer\{885A63EA-382B-4DD4-A755-14809B8557D6}\ARPPRODUCTICON.exe
2012-05-05 03:14 . 2008-04-14 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14 . 2008-04-14 08:06 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-02-16 22:47 . 2012-02-16 22:47 933888 ----a-w- c:\program files\HairVrPrims2011.dll
2012-02-16 22:47 . 2012-02-16 22:47 7961088 ----a-w- c:\program files\vray2011.dll
2012-02-16 22:47 . 2012-02-16 22:47 753664 ----a-w- c:\program files\dte_wrapper.dll
2012-02-16 22:47 . 2012-02-16 22:47 622080 ----a-w- c:\program files\glslang.dll
2012-02-16 22:47 . 2012-02-16 22:47 412160 ----a-w- c:\program files\cgauth.dll
2012-02-16 22:47 . 2012-02-16 22:47 3741184 ----a-w- c:\program files\vray.dll
2012-02-16 22:47 . 2012-02-16 22:47 3291320 ----a-w- c:\program files\libmmd.dll
2012-02-16 22:47 . 2012-02-16 22:47 138752 ----a-w- c:\program files\glvm.dll
2012-07-18 21:18 . 2012-02-16 03:06 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-07-31_22.48.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-02 08:38 . 2012-08-02 08:38 16384 c:\windows\temp\Perflib_Perfdata_1cc.dat
- 2012-07-26 22:20 . 2012-07-31 06:37 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2012-02-22 16:21 . 2012-02-22 16:21 53248 c:\windows\Installer\{7A76CAF3-D7D8-45C0-9CCB-8AC1DDF38516}\ARPPRODUCTICON.exe
+ 2012-08-01 01:35 . 2012-08-01 01:35 53248 c:\windows\Installer\{7A76CAF3-D7D8-45C0-9CCB-8AC1DDF38516}\ARPPRODUCTICON.exe
+ 2011-07-20 04:28 . 2011-07-20 04:28 54104 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SCANOST.EXE
+ 2011-07-20 04:28 . 2011-07-20 04:28 75624 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\RM.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 38248 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\RECALL.DLL
+ 2011-07-20 03:32 . 2011-07-20 03:32 47496 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PUBTRAP.DLL
+ 2011-05-26 18:18 . 2011-05-26 18:18 52088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLVBA.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 34208 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\DUMPSTER.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 87408 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\DLGSETP.DLL
- 2012-07-26 22:20 . 2012-07-31 06:37 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2011-09-15 18:41 . 2011-09-15 18:41 408936 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WINWORD.EXE
+ 2011-07-20 04:28 . 2011-07-20 04:28 282032 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SCNPST64.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 273832 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SCNPST32.DLL
+ 2011-07-27 02:55 . 2011-07-27 02:55 410992 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\RTFHTML.DLL
+ 2011-07-20 05:06 . 2011-07-20 05:06 770480 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\REGFORM.EXE
+ 2011-07-20 03:32 . 2011-07-20 03:32 593288 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PUBCONV.DLL
+ 2011-07-27 02:42 . 2011-07-27 02:42 625040 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PTXT9.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 421736 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PSTPRX32.DLL
+ 2011-07-20 03:32 . 2011-07-20 03:32 135056 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PRTF9.DLL
+ 2011-05-31 13:58 . 2011-05-31 13:58 521080 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\POWERPNT.EXE
+ 2011-05-31 14:15 . 2011-05-31 14:15 177040 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLPH.DLL
+ 2011-07-27 02:55 . 2011-07-27 02:55 596888 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLMIME.DLL
+ 2011-05-26 18:18 . 2011-05-26 18:18 136536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLCTL.DLL
+ 2011-07-27 04:03 . 2011-07-27 04:03 194448 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OMSXP32.DLL
+ 2011-07-27 04:03 . 2011-07-27 04:03 661888 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OMSMAIN.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 253824 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OLKFSTUB.DLL
+ 2011-07-27 02:42 . 2011-07-27 02:42 497056 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MORPH9.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 340320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MIMEDIR.DLL
+ 2012-07-31 06:35 . 2012-07-31 06:35 117160 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPOMINT.DLL
+ 2011-07-20 05:06 . 2011-07-20 05:06 176024 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPOLK.DLL
+ 2011-07-20 04:28 . 2011-07-20 04:28 138088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IMPMAIL.DLL
+ 2009-02-26 10:09 . 2009-02-26 10:09 154000 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ENVELOPE.DLL
+ 2011-05-26 18:18 . 2011-05-26 18:18 115584 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\EMABLT32.DLL
+ 2011-07-27 02:55 . 2011-07-27 02:55 128376 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\CONTAB32.DLL
+ 2012-08-01 01:04 . 2012-08-01 01:04 117160 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
- 2012-07-31 06:35 . 2012-07-31 06:35 117160 c:\windows\assembly\GAC_32\Microsoft.Office.InfoPath.Client.Internal.Host.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2010-12-07 11:50 . 2010-12-07 11:50 4061184 c:\windows\system32\PhotoLooksRenderer.dll
- 2010-12-07 12:50 . 2010-12-07 12:50 4061184 c:\windows\system32\PhotoLooksRenderer.dll
- 2012-02-16 01:49 . 2012-07-31 21:20 2618400 c:\windows\system32\FNTCACHE.DAT
+ 2012-02-16 01:49 . 2012-08-02 08:38 2618400 c:\windows\system32\FNTCACHE.DAT
+ 2012-08-01 01:35 . 2012-08-01 01:35 3578368 c:\windows\Installer\929f8b.msi
+ 2012-04-04 20:38 . 2012-04-04 20:38 2831360 c:\windows\Installer\743951.msp
+ 2012-04-28 19:44 . 2012-04-28 19:44 9101824 c:\windows\Installer\743930.msp
+ 2011-11-01 11:34 . 2011-11-01 11:34 4250112 c:\windows\Installer\743918.msp
+ 2012-05-30 05:18 . 2012-05-30 05:18 1748480 c:\windows\Installer\7438cf.msp
+ 2012-06-19 10:54 . 2012-06-19 10:54 2239488 c:\windows\Installer\7438c4.msp
+ 2012-03-23 12:59 . 2012-03-23 12:59 7899648 c:\windows\Installer\7438ac.msp
+ 2012-04-28 19:44 . 2012-04-28 19:44 9586176 c:\windows\Installer\743894.msp
+ 2012-04-04 20:38 . 2012-04-04 20:38 3620864 c:\windows\Installer\74387b.msp
+ 2011-11-01 11:34 . 2011-11-01 11:34 2247168 c:\windows\Installer\743863.msp
+ 2011-11-01 11:34 . 2011-11-01 11:34 1169920 c:\windows\Installer\74384b.msp
+ 2011-11-01 11:34 . 2011-11-01 11:34 4225536 c:\windows\Installer\743833.msp
+ 2012-03-15 00:24 . 2012-03-15 00:24 1795584 c:\windows\Installer\743816.msp
+ 2011-11-01 11:34 . 2011-11-01 11:34 2531840 c:\windows\Installer\7437fe.msp
+ 2012-04-04 20:37 . 2012-04-04 20:37 2540544 c:\windows\Installer\7437e6.msp
+ 2012-04-28 19:43 . 2012-04-28 19:43 8459264 c:\windows\Installer\7437ce.msp
+ 2012-02-17 06:45 . 2012-02-17 06:45 2299392 c:\windows\Installer\7437b6.msp
+ 2012-04-04 20:37 . 2012-04-04 20:37 3149824 c:\windows\Installer\74379f.msp
+ 2012-07-26 22:20 . 2012-08-01 01:15 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2012-07-26 22:20 . 2012-08-01 01:15 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2012-07-26 22:20 . 2012-07-31 06:37 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2011-08-17 07:49 . 2011-08-17 07:49 4683624 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WRD12CNV.DLL
+ 2009-10-09 21:10 . 2009-10-09 21:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBE6.DLL
+ 2011-05-31 15:24 . 2011-05-31 15:24 2014592 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PPTVIEW.EXE
+ 2011-07-27 02:44 . 2011-07-27 02:44 8494968 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\PPCORE.DLL
+ 2011-07-27 02:55 . 2011-07-27 02:55 3004800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OLMAPI32.DLL
+ 2011-07-07 00:58 . 2011-07-07 00:58 1616240 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGL.DLL
+ 2011-07-27 02:42 . 2011-07-27 02:42 9596784 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSPUB.EXE
+ 2011-07-27 03:09 . 2011-07-27 03:09 5310848 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPEDITOR.DLL
+ 2011-07-27 03:09 . 2011-07-27 03:09 5484416 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IPDESIGN.DLL
+ 2011-07-27 03:09 . 2011-07-27 03:09 1460088 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\INFOPATH.EXE
+ 2011-07-27 03:47 . 2011-07-27 03:47 2532736 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\GRAPH.EXE
+ 2012-05-30 05:18 . 2012-05-30 05:18 11885056 c:\windows\Installer\743900.msp
+ 2011-08-30 06:40 . 2011-08-30 06:40 15145832 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\XL12CNV.EXE
+ 2011-09-15 18:42 . 2011-09-15 18:42 18115432 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\WWLIB.DLL
+ 2011-08-03 16:18 . 2011-08-03 16:18 12997488 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLOOK.EXE
+ 2011-08-30 18:25 . 2011-08-30 18:25 18367336 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\EXCEL.EXE
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Dalin\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Dalin\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Dalin\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-02-14 22:58 94208 ----a-w- c:\documents and settings\Dalin\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Total CMA Pack"="c:\program files\Total CMA Pack\Total CMA Pack.exe" [2009-09-01 43255]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 3080264]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"3200 Scan2PC"="c:\windows\Twain_32\Samsung\SCX3200\Scan2pc.exe" [2010-05-18 1989120]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Dalin\Nabídka Start\Programy\Po spuštění\
Dropbox.lnk - c:\documents and settings\Dalin\Data aplikací\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
AutoScreenShot.lnk - c:\program files\AutoScreenShot\AutoScreenShot.exe [2004-9-15 224327]
Snagit 10.lnk - c:\program files\TechSmith\Snagit 10\Snagit32.exe [2011-3-21 7067464]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Total CMA Pack\\TOTALCMD.EXE"=
"c:\\Program Files\\Autodesk\\3ds Max 2010\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2010\\mentalray\\satellite\\raysat_3dsmax2010_32.exe"=
"c:\\Documents and Settings\\Dalin\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Adobe\\Adobe Photoshop CS4\\Photoshop.exe"=
"c:\\WINDOWS\\system32\\SUPDSvc2.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\ScanMgr.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\SCX3200\\Scan2Pc.exe"=
"c:\\WINDOWS\\twain_32\\Samsung\\SCX3200\\Sscan2io.exe"=
"c:\\Program Files\\Scan Assistant\\USDAgent.exe"=
"c:\\Rebus\\Rebus Manager\\RebusManager.exe"=
"c:\\Documents and Settings\\Dalin\\Local Settings\\Data aplikací\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2012\\mentalimages\\satellite\\raysat_3dsmax2012_32.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2012\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 2012\\mentalimages\\satellite\\raysat_3dsmax2012_32server.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Samsung\\Samsung Universal Scan Driver\\USDAgent.exe"=
"c:\\Program Files\\Samsung\\Samsung Universal Scan Driver\\ICCUpdater.exe"=
"c:\\Program Files\\YourFileDownloader\\Downloader.exe"=
"c:\\Program Files\\YourFileDownloader\\YourFile.exe"=
"c:\\Program Files\\ICQ7M\\ICQ.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"12557:TCP"= 12557:TCP:BitComet 12557 TCP
"12557:UDP"= 12557:UDP:BitComet 12557 UDP
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [16.2.2012 14:52 242240]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 10:20 118104]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [4.8.2011 10:20 103112]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [22.9.2011 13:03 974944]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;c:\program files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [12.3.2009 18:36 86016]
R2 mi-raysat_3dsmax2012_32;mental ray 3.9 Satellite for Autodesk 3ds Max 2012 32-bit - English 32-bit;c:\program files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe [23.2.2011 7:59 86016]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [16.2.2012 4:02 2253120]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [5.7.2012 18:41 3048136]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [9.4.2012 17:23 2789672]
R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [26.4.2012 19:13 2666880]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [23.12.2010 18:35 14336]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [23.12.2010 18:35 20736]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [23.12.2010 18:35 20096]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [23.12.2010 18:35 25088]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [29.9.2009 9:11 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [29.9.2009 9:11 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [29.9.2009 9:11 12928]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [9.4.2012 17:24 15656]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [3.7.2012 13:19 160944]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2.4.2012 9:28 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2.5.2012 14:17 113120]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [16.2.2012 14:46 27064]
S3 Samsung UPD Service2;Samsung UPD Service2;c:\windows\system32\SUPDSvc2.exe [23.2.2012 18:25 136784]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 14:37 517096]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-08-02 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2012-06-05 20:18]
.
.
------- Doplňkový sken -------
.
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: Stáhnout odkaz s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: {{781B39EC-2E18-41FC-9B00-B84E4FFCA85F} - c:\program files\ICQ7M\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\documents and settings\Dalin\Data aplikací\Mozilla\Firefox\Profiles\3i1grfts.default\
FF - prefs.js: browser.search.selectedEngine - Seznam
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.cz/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-02 10:39
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD1002FAEX-00Y9A0 rev.05.01D05 -> Harddisk2\DR2 -> \Device\Ide\IdeDeviceP4T0L0-12
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(632)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
.
- - - - - - - > 'lsass.exe'(688)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(2176)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\program files\NVIDIA Corporation\nview\nview.dll
c:\program files\NVIDIA Corporation\nview\NVWRSCS.DLL
c:\documents and settings\Dalin\Data aplikací\Dropbox\bin\DropboxExt.14.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\cs-cz\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\cs-cz\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\program files\Autodesk\3ds Max 2012\AcSignCore16.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\TeamViewer\Version7\TeamViewer.exe
c:\program files\TeamViewer\Version7\tv_w32.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RunDLL32.exe
c:\windows\system32\rundll32.exe
c:\program files\Total CMA Pack\TOTALCMD.EXE
c:\program files\TechSmith\Snagit 10\TSCHelp.exe
c:\windows\system32\SearchProtocolHost.exe
c:\program files\TechSmith\Snagit 10\SnagPriv.exe
c:\windows\system32\SearchFilterHost.exe
c:\program files\TechSmith\Snagit 10\snagiteditor.exe
.
**************************************************************************
.
Celkový čas: 2012-08-02 10:43:25 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-08-02 08:43
ComboFix2.txt 2012-07-31 22:50
.
Před spuštěním: Volných bajtů: 813 842 587 648
Po spuštění: Volných bajtů: 813 804 597 248
.
- - End Of File - - 1DB48A2B0D9AF624DAD6A80B8CCF9583