
ComboFix 10-03-15.04 - Notebook 16.03.2010 1:27.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.420.1029.18.2813.2090 [GMT 1:00]
Spuštěný z: c:\users\Notebook\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Notebook\AppData\Roaming\logs.dat
c:\windows\system32\oem7.inf
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-16 do 2010-03-16 )))))))))))))))))))))))))))))))
.
2010-03-16 00:36 . 2010-03-16 00:36 -------- d-----w- c:\users\Notebook\AppData\Local\temp
2010-03-16 00:36 . 2010-03-16 00:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-16 00:11 . 2010-03-16 00:11 -------- d-----w- c:\program files\trend micro
2010-03-16 00:11 . 2010-03-16 00:11 -------- d-----w- C:\rsit
2010-03-15 23:39 . 2010-03-15 23:39 -------- d-----w- c:\users\Notebook\AppData\Roaming\Ahead
2010-03-15 23:38 . 2010-03-15 23:38 -------- d-----w- c:\programdata\Ahead
2010-03-15 10:23 . 2010-03-15 10:23 -------- d-----w- c:\program files\uTorrent
2010-03-15 10:22 . 2010-03-15 23:40 -------- d-----w- c:\users\Notebook\AppData\Roaming\uTorrent
2010-03-13 16:35 . 2010-03-13 16:35 -------- d-----w- c:\users\Notebook\AppData\Roaming\DAEMON Tools Pro
2010-03-13 16:35 . 2010-03-13 16:35 -------- d-----w- c:\users\Notebook\AppData\Roaming\DAEMON Tools
2010-03-13 16:34 . 2010-03-13 16:34 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-03-13 16:33 . 2010-03-13 16:33 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-03-13 16:33 . 2010-03-13 16:33 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-03-13 16:32 . 2010-03-13 16:32 -------- d-----w- c:\users\Notebook\AppData\Roaming\DAEMON Tools Lite
2010-03-07 09:35 . 2010-02-12 10:32 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-03-03 13:44 . 2010-03-03 13:44 -------- d-----w- c:\programdata\Blizzard
2010-03-01 19:12 . 2010-03-01 19:13 -------- d-----w- c:\users\Notebook\AppData\Roaming\Media Player Classic
2010-03-01 14:28 . 2010-03-01 14:28 -------- d-----w- c:\program files\Xilisoft
2010-02-26 06:48 . 2010-03-09 19:51 -------- d-----w- C:\Fraps
2010-02-25 13:35 . 2010-02-25 13:35 -------- d-----w- c:\program files\Windows Portable Devices
2010-02-25 07:43 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2010-02-25 07:43 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2010-02-25 07:43 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2010-02-25 07:40 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-02-25 07:40 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2010-02-25 07:40 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2010-02-25 07:40 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2010-02-25 07:40 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2010-02-25 07:40 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2010-02-25 07:40 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2010-02-25 07:40 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2010-02-25 07:40 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2010-02-25 07:40 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2010-02-25 07:40 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2010-02-25 07:40 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2010-02-25 07:38 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-02-25 07:38 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-02-25 07:38 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-02-24 09:57 . 2010-03-15 23:44 -------- d-----w- c:\users\Notebook\AppData\Local\Ahead
2010-02-24 09:45 . 2010-02-24 09:46 -------- d-----w- c:\windows\system32\ca-ES
2010-02-24 09:45 . 2010-02-24 09:46 -------- d-----w- c:\windows\system32\eu-ES
2010-02-24 09:45 . 2010-02-24 09:46 -------- d-----w- c:\windows\system32\vi-VN
2010-02-24 09:36 . 2009-12-12 14:15 178176 ----a-w- c:\windows\system32\unrar.dll
2010-02-24 09:36 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-02-24 09:36 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-02-24 09:36 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-02-24 09:36 . 2010-02-02 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-02-24 09:36 . 2010-02-24 09:37 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-24 09:26 . 2010-02-24 09:26 -------- d-----w- c:\windows\system32\EventProviders
2010-02-24 09:23 . 2010-03-15 23:36 -------- d-----w- c:\program files\Common Files\Ahead
2010-02-21 06:21 . 2010-02-21 06:21 -------- d-----w- c:\program files\MSXML 4.0
2010-02-20 19:16 . 2010-02-20 19:16 -------- d-----w- c:\programdata\WindowsSearch
2010-02-20 00:32 . 2010-02-20 00:32 -------- d-----w- c:\users\Notebook\AppData\Local\Nero
2010-02-20 00:32 . 2010-02-20 00:48 -------- d-----w- c:\users\Notebook\AppData\Roaming\Nero
2010-02-19 19:18 . 2007-03-26 06:25 38784 ----a-w- c:\windows\system32\drivers\Axtmvprt.sys
2010-02-19 19:18 . 2007-03-26 06:25 40064 ----a-w- c:\windows\system32\drivers\Axtmvmdm.sys
2010-02-19 19:18 . 2007-03-22 08:36 3456 ----a-w- c:\windows\system32\drivers\Axtmvflt.sys
2010-02-19 19:18 . 2010-02-19 19:18 -------- d-----w- c:\program files\Axesstel
2010-02-19 07:45 . 2010-03-15 23:33 -------- d-----w- c:\program files\Nero
2010-02-19 07:44 . 2010-03-15 23:33 -------- d-----w- c:\programdata\Nero
2010-02-19 07:44 . 2010-02-24 09:02 -------- d-----w- c:\program files\Common Files\Nero
2010-02-18 18:51 . 2010-02-18 18:51 -------- d-----w- c:\users\Notebook\AppData\Roaming\TS3Client
2010-02-15 06:21 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-02-15 06:21 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-02-15 06:21 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-15 06:21 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-14 06:23 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-02-14 06:23 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-16 00:32 . 2008-01-21 06:13 598832 ----a-w- c:\windows\system32\perfh005.dat
2010-03-16 00:32 . 2008-01-21 06:13 114992 ----a-w- c:\windows\system32\perfc005.dat
2010-03-16 00:22 . 2010-02-07 07:56 12 ----a-w- c:\windows\bthservsdp.dat
2010-03-14 21:45 . 2010-02-06 15:08 -------- d-----w- c:\users\Notebook\AppData\Roaming\ICQ
2010-03-12 15:15 . 2010-02-11 14:06 -------- d-----w- c:\program files\World of Warcraft
2010-03-12 10:35 . 2010-02-06 15:08 -------- d-----w- c:\program files\ICQ7.0
2010-03-11 23:22 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-03-08 17:58 . 2010-02-06 15:07 -------- d-----w- c:\users\Notebook\AppData\Roaming\Skype
2010-03-08 15:08 . 2010-02-07 09:41 -------- d-----w- c:\users\Notebook\AppData\Roaming\skypePM
2010-03-01 19:06 . 2010-02-06 09:21 -------- d-----w- c:\users\Notebook\AppData\Roaming\BSplayer PRO
2010-02-25 23:02 . 2010-02-05 10:15 54312 ----a-w- c:\users\Notebook\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-25 13:35 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-02-25 13:34 . 2010-02-25 13:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-02-24 09:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2010-02-24 09:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2010-02-24 09:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2010-02-24 09:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2010-02-24 09:46 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2010-02-24 08:16 . 2010-02-05 13:07 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-22 10:15 . 2010-02-06 12:59 -------- d-----w- c:\users\Notebook\AppData\Roaming\LangSoft
2010-02-12 18:40 . 2010-02-12 18:39 -------- d-----w- c:\users\Notebook\AppData\Roaming\Ventrilo
2010-02-12 18:38 . 2010-02-12 18:38 -------- d-----w- c:\program files\Ventrilo
2010-02-12 18:38 . 2010-02-12 18:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-07 14:48 . 2010-02-07 14:49 737280 ----a-w- c:\windows\iun6002.exe
2010-02-07 14:17 . 2010-02-07 14:17 -------- d-----w- c:\program files\Katalog DVD
2010-02-07 13:35 . 2010-02-05 11:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-07 13:29 . 2010-02-05 11:46 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-07 13:27 . 2010-02-07 13:27 -------- d-----w- c:\programdata\UDL
2010-02-07 13:26 . 2010-02-07 13:02 -------- d-----w- c:\program files\epson
2010-02-07 13:23 . 2010-02-07 13:23 -------- d-----w- c:\program files\ABBYY FineReader 6.0 Sprint
2010-02-07 13:09 . 2010-02-07 12:59 -------- d-----w- c:\programdata\EPSON
2010-02-07 12:58 . 2010-02-07 12:58 -------- d-----w- c:\program files\TeamSpeak 3 Client
2010-02-07 09:50 . 2010-02-07 09:48 -------- d-----w- c:\program files\CesarFTP
2010-02-07 09:41 . 2010-02-07 09:41 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-02-07 07:59 . 2010-02-07 07:59 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-02-07 06:23 . 2010-02-07 06:23 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2010-02-06 17:31 . 2010-02-06 17:28 -------- d-----w- c:\program files\Counter-Strike 1.6
2010-02-06 15:07 . 2010-02-06 15:06 -------- d-----r- c:\program files\Skype
2010-02-06 15:07 . 2010-02-06 15:07 -------- d-----w- c:\program files\Common Files\Skype
2010-02-06 15:06 . 2010-02-06 15:06 -------- d-----w- c:\programdata\Skype
2010-02-06 13:01 . 2010-02-06 13:01 798771 ----a-w- c:\programdata\LangSoft\WebIE.dll
2010-02-06 13:01 . 2010-02-06 13:01 299008 ----a-w- c:\programdata\LangSoft\TrnWord.dll
2010-02-06 13:01 . 2010-02-06 13:00 -------- d-----w- c:\programdata\LangSoft
2010-02-06 13:01 . 2010-02-06 13:01 356352 ----a-w- c:\programdata\LangSoft\TrnOutl.dll
2010-02-06 09:35 . 2010-02-06 09:35 -------- d-----w- c:\program files\Alcohol Soft
2010-02-06 09:33 . 2010-02-06 09:33 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-06 09:23 . 2010-02-06 09:23 -------- d-----w- c:\users\Notebook\AppData\Roaming\IObit
2010-02-06 09:23 . 2010-02-06 09:23 -------- d-----w- c:\program files\IObit
2010-02-06 09:21 . 2010-02-06 09:21 -------- d-----w- c:\program files\Webteh
2010-02-06 09:17 . 2010-02-06 09:17 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-06 09:07 . 2010-02-06 09:07 -------- d-----w- c:\program files\RocketDock
2010-02-06 09:06 . 2010-02-06 09:06 -------- d-----w- c:\program files\Alwil Software
2010-02-05 11:53 . 2010-02-05 11:53 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2010-02-05 11:53 . 2010-02-05 11:53 -------- d-----w- c:\program files\Synaptics
2010-02-05 11:50 . 2010-02-05 11:46 -------- d-----w- c:\program files\Realtek
2010-02-05 11:50 . 2010-02-05 11:50 -------- d-----w- c:\users\Notebook\AppData\Roaming\InstallShield
2010-02-05 11:46 . 2010-02-05 11:46 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-02-05 11:46 . 2010-02-05 11:46 315392 ----a-w- c:\windows\HideWin.exe
2010-02-05 11:43 . 2010-02-05 11:43 -------- d-----w- c:\users\Notebook\AppData\Roaming\ATI
2010-02-05 11:43 . 2010-02-05 11:43 -------- d-----w- c:\programdata\ATI
2010-02-05 11:42 . 2010-02-05 11:42 0 ----a-w- c:\windows\ativpsrm.bin
2010-02-05 11:40 . 2010-02-05 11:38 -------- d-----w- c:\program files\ATI Technologies
2010-02-05 11:38 . 2010-02-05 11:38 10134 ----a-r- c:\users\Notebook\AppData\Roaming\Microsoft\Installer\{58FF8C7E-F431-7069-DA9A-A61411208DF3}\ARPPRODUCTICON.exe
2010-02-05 11:38 . 2010-02-05 11:38 -------- d-----w- c:\program files\ATI
2010-02-05 11:36 . 2010-02-05 11:36 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-02-05 10:21 . 2010-02-05 10:15 680 ----a-w- c:\users\Notebook\AppData\Local\d3d9caps.dat
2010-02-05 10:12 . 2010-02-05 10:12 -------- d-sh--we c:\programdata\Plocha
2010-02-05 10:12 . 2010-02-05 10:12 -------- d-sh--we c:\programdata\Oblíbené položky
2010-02-05 10:12 . 2010-02-05 10:12 -------- d-sh--we c:\programdata\Šablony
2010-02-05 10:12 . 2010-02-05 10:12 -------- d-sh--we c:\programdata\Nabídka Start
2010-02-05 10:12 . 2010-02-05 10:12 -------- d-sh--we c:\programdata\Dokumenty
2010-02-05 10:12 . 2010-02-05 10:12 -------- d-sh--we c:\programdata\Data aplikací
2010-01-25 12:00 . 2010-02-24 21:31 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 21:31 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 21:31 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 21:31 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 21:31 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 21:31 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 21:31 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 21:31 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-25 08:21 . 2010-02-24 21:31 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-23 09:26 . 2010-02-24 21:31 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-06 15:39 . 2010-02-24 21:31 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-01-06 15:38 . 2010-02-24 21:31 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-01-06 15:38 . 2010-02-24 21:31 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-24 21:31 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 15:38 . 2010-02-24 21:31 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-24 21:31 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 13:30 . 2010-02-24 21:31 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-01-02 06:38 . 2010-02-05 13:35 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-02-05 13:35 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-02-05 13:35 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-02-05 13:35 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-20 09:53 . 2009-12-20 09:53 234016 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2009-11-15 33120]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"FileUploader"="c:\users\Notebook\Downloads\SRDownloader.exe" [2010-03-13 475136]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880]
"Skytel"="Skytel.exe" [2008-06-25 1826816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1037608]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b1,c1,97,31,37,b5,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-06 691696]
R3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\DRIVERS\Axtmvflt.sys [2007-03-22 3456]
R3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\DRIVERS\Axtmvmdm.sys [2007-03-26 40064]
R3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\Drivers\Axtmvprt.sys [2007-03-26 38784]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
2010-03-16 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-02-06 14:35]
2010-03-16 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-02-06 13:45]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\program files\ICQ7.0\ICQ.exe
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
FF - ProfilePath - c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\e8v7k9dd.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\e8v7k9dd.default\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}\components\nsWebFF15.dll
FF - component: c:\users\Notebook\AppData\Roaming\Mozilla\Firefox\Profiles\e8v7k9dd.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-16 01:36
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\users\Notebook\AppData\Local\Temp\catchme.dll 53248 bytes executable
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-03-16 01:40:49
ComboFix-quarantined-files.txt 2010-03-16 00:40
Před spuštěním: Volných bajtů: 37 221 314 560
Po spuštění: Volných bajtů: 38 845 100 032
- - End Of File - - B345689C8418ABC717DABF5059BD3926