Kód: Vybrat vše
ComboFix 10-05-20.A0 - Kamil 21.05.2010 11:07:24.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1918.1523 [GMT 2:00]
Spuštěný z: c:\documents and settings\Kamil\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-21 do 2010-05-21 )))))))))))))))))))))))))))))))
.
2010-05-21 09:06 . 2010-05-21 09:06 -------- d-sh--w- c:\documents and settings\Kamil\IECompatCache
2010-05-21 09:05 . 2010-05-21 09:05 -------- d-sh--w- c:\documents and settings\Kamil\PrivacIE
2010-05-10 11:47 . 2010-05-10 11:48 -------- d-----r- c:\documents and settings\Kamil\Oblíbené položky
2010-05-10 11:47 . 2010-05-10 11:48 -------- d-----r- c:\documents and settings\Kamil\Dokumenty
2010-05-10 11:47 . 2008-07-25 07:01 -------- d--h--w- c:\documents and settings\Kamil\Okolní tiskárny
2010-05-10 11:47 . 2008-07-25 07:01 -------- d--h--w- c:\documents and settings\Kamil\Okolní síť
2010-05-10 11:47 . 2008-07-25 07:01 -------- d-----r- c:\documents and settings\Kamil\Nabídka Start
2010-05-10 11:47 . 2008-07-25 05:08 -------- d--h--w- c:\documents and settings\Kamil\Šablony
2010-05-10 11:47 . 2010-05-21 09:06 -------- d-----w- c:\documents and settings\Kamil
2010-05-10 11:39 . 2010-05-11 10:31 -------- d-----w- c:\documents and settings\Kleskeň
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 15:07 . 2010-01-25 06:06 802304 ----a-w- c:\windows\system32\drivers\trifd.sys
2010-04-16 09:47 . 2009-02-20 09:59 -------- d-----w- c:\program files\Google
2010-04-07 09:17 . 2010-04-07 09:17 -------- d-----w- c:\program files\Common Files\xing shared
2010-04-07 09:17 . 2009-10-01 05:04 -------- d-----w- c:\program files\Common Files\Real
2010-04-07 09:17 . 2010-04-07 09:17 -------- d-----w- c:\program files\Real
2010-03-29 03:50 . 2001-10-25 14:00 83832 ----a-w- c:\windows\system32\perfc005.dat
2010-03-29 03:50 . 2001-10-25 14:00 440590 ----a-w- c:\windows\system32\perfh005.dat
2010-03-10 06:17 . 2004-08-17 16:49 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-03 12:12 . 2010-03-03 12:12 9762 ---ha-w- C:\aaw7boot.cmd
2010-03-03 11:57 . 2010-03-03 11:57 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-25 06:18 . 2004-08-17 16:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-04 00:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-10 16342528]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Max Communicator.lnk - c:\program files\Max Communicator\MaxComm.exe [2006-5-19 819712]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Max Communicator\\MaxComm.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?]
R2 Vivotek_ST3402;Vivotek ST3402 Launcher;c:\program files\Vivotek\ST3402\Launcher_VV.exe [23.5.2007 15:47 331776]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s --> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?]
R3 GemCCID;GemCCID;c:\windows\system32\drivers\GemCCID.sys [4.4.2008 9:02 87424]
R3 NmPar;PCI Parallel Port;c:\windows\system32\drivers\NmPar.sys [9.4.2008 10:28 80512]
R3 nmserial;PCI Serial Port;c:\windows\system32\drivers\NmSerial.sys [4.4.2008 8:30 70016]
S2 gupdate1c99341e40e2c82;Google Update Service (gupdate1c99341e40e2c82);c:\program files\Google\Update\GoogleUpdate.exe [20.2.2009 11:59 133104]
.
Obsah adresáře 'Naplánované úlohy'
2010-05-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-30 04:07]
2010-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-20 09:59]
2010-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-20 09:59]
2010-05-21 c:\windows\Tasks\User_Feed_Synchronization-{2BFA24F5-820C-403E-9D83-8741F74150BB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Doplňkový sken -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-HijackThis - c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Y3GZBJ25\HijackThis.exe
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-21 11:09
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
- - - - - - - > 'explorer.exe'(3152)
c:\windows\system32\vorbis.dll
c:\windows\system32\ogg.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-05-21 11:10:52
ComboFix-quarantined-files.txt 2010-05-21 09:10
Před spuštěním: Volných bajtů: 68 018 077 696
Po spuštění: Volných bajtů: 67 983 642 624
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - F3BE2D90BFD5C91E844884560699FCAD