Takže tak:
LOG z
Combofixu:
ComboFix 10-06-24.03 - Olina Tlapáková 25.06.2010 11:08.4.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2037.1411 [GMT 2:00]
Spuštěný z: C:\ComboFix.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-25 do 2010-06-25 )))))))))))))))))))))))))))))))
.
2010-06-25 07:47 . 2010-06-25 07:47 3719978 ----a-r- C:\ComboFix.exe
2010-06-25 06:28 . 2010-06-25 06:29 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-06-25 06:11 . 2010-06-25 06:11 -------- d-----w- C:\rsit
2010-06-25 06:11 . 2010-06-25 06:11 -------- d-----w- c:\program files\trend micro
2010-06-24 14:25 . 2010-06-24 14:25 -------- d-----w- C:\!KillBox
2010-06-24 14:04 . 2010-06-24 14:12 -------- d-----w- c:\windows\LastGood
2010-06-24 13:26 . 2010-06-24 13:26 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-06-24 11:33 . 2008-04-13 22:15 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2010-06-24 11:32 . 2008-11-07 16:55 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-06-24 11:27 . 2010-06-24 11:27 -------- d-----w- c:\program files\DIFX
2010-06-24 11:26 . 2010-02-26 12:32 92672 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-06-24 11:24 . 2010-06-24 13:42 -------- d-----w- c:\program files\Nokia
2010-06-17 10:02 . 2010-06-17 10:02 0 ----a-w- c:\windows\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-25 07:24 . 2008-02-04 13:22 -------- d-----w- c:\program files\FARAO
2010-06-24 13:41 . 2001-10-25 12:00 46196 ----a-w- c:\windows\system32\perfc005.dat
2010-06-24 13:41 . 2001-10-25 12:00 309990 ----a-w- c:\windows\system32\perfh005.dat
2010-06-24 11:32 . 2010-06-24 11:32 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-06-24 11:32 . 2010-06-24 11:32 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-05 11:54 . 2010-05-05 11:53 -------- d-----w- c:\program files\UTAX TA
.
((((((((((((((((((((((((((((( SnapShot@2010-06-24_13.35.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-25 07:22 . 2010-06-25 07:22 16384 c:\windows\temp\Perflib_Perfdata_78c.dat
+ 2001-10-25 12:00 . 2010-06-24 13:41 40128 c:\windows\system32\perfc009.dat
+ 2010-06-24 14:12 . 2001-10-25 12:00 31360 c:\windows\LastGood\system32\dllcache\weitekp9.sys
+ 2010-06-24 14:12 . 2001-10-25 12:00 41600 c:\windows\LastGood\system32\dllcache\weitekp9.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 73728 c:\windows\LastGood\system32\dllcache\w3ext.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 48256 c:\windows\LastGood\system32\dllcache\w32.dll
+ 2010-06-24 14:12 . 2008-04-14 06:50 86073 c:\windows\LastGood\system32\dllcache\voicesub.dll
+ 2010-06-24 14:12 . 2008-04-14 06:50 76288 c:\windows\LastGood\system32\dllcache\uniime.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 14336 c:\windows\LastGood\system32\dllcache\tsprof.exe
+ 2010-06-24 14:12 . 2008-04-14 06:50 10240 c:\windows\LastGood\system32\dllcache\tmigrate.dll
+ 2010-06-24 14:12 . 2004-08-03 21:32 44032 c:\windows\LastGood\system32\dllcache\tintlphr.exe
+ 2010-06-24 14:12 . 2001-10-25 12:00 19464 c:\windows\LastGood\system32\dllcache\tdspx.sys
+ 2010-06-24 14:12 . 2001-10-25 12:00 21896 c:\windows\LastGood\system32\dllcache\tdipx.sys
+ 2010-06-24 14:12 . 2001-10-25 12:00 13192 c:\windows\LastGood\system32\dllcache\tdasync.sys
+ 2010-06-24 14:12 . 2001-10-25 12:00 16896 c:\windows\LastGood\system32\dllcache\status.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 10240 c:\windows\LastGood\system32\dllcache\snmpstup.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 15872 c:\windows\LastGood\system32\dllcache\smierrsm.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 31744 c:\windows\LastGood\system32\dllcache\smb6w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 31744 c:\windows\LastGood\system32\dllcache\sma3w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 38912 c:\windows\LastGood\system32\dllcache\sm9aw.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 26624 c:\windows\LastGood\system32\dllcache\sm93w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 26624 c:\windows\LastGood\system32\dllcache\sm92w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 26112 c:\windows\LastGood\system32\dllcache\sm90w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 26112 c:\windows\LastGood\system32\dllcache\sm8dw.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 29184 c:\windows\LastGood\system32\dllcache\sm8cw.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 26112 c:\windows\LastGood\system32\dllcache\sm8aw.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 26112 c:\windows\LastGood\system32\dllcache\sm89w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 30208 c:\windows\LastGood\system32\dllcache\sm87w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 30208 c:\windows\LastGood\system32\dllcache\sm81w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 25088 c:\windows\LastGood\system32\dllcache\sm59w.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 18944 c:\windows\LastGood\system32\dllcache\simptcp.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 79872 c:\windows\LastGood\system32\dllcache\rwia330.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 79872 c:\windows\LastGood\system32\dllcache\rwia001.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 14848 c:\windows\LastGood\system32\dllcache\register.exe
+ 2010-06-24 14:10 . 2001-10-25 12:00 16896 c:\windows\LastGood\system32\dllcache\quser.exe
+ 2010-06-24 14:10 . 2001-10-25 12:00 11264 c:\windows\LastGood\system32\dllcache\pmxmcro.dll
+ 2010-06-24 14:10 . 2008-04-14 06:49 67584 c:\windows\LastGood\system32\dllcache\pmigrate.dll
+ 2010-06-24 14:10 . 2008-04-13 20:13 70144 c:\windows\LastGood\system32\dllcache\pintlphr.exe
+ 2010-06-24 14:10 . 2008-04-14 06:49 53760 c:\windows\LastGood\system32\dllcache\pintlcsd.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 20992 c:\windows\LastGood\system32\dllcache\permchk.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 31744 c:\windows\LastGood\system32\dllcache\pagecnt.dll
+ 2010-06-24 14:10 . 2008-04-14 06:49 15360 c:\windows\LastGood\system32\dllcache\padrs804.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 14336 c:\windows\LastGood\system32\dllcache\padrs412.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 36927 c:\windows\LastGood\system32\dllcache\padrs411.dll
+ 2010-06-24 14:10 . 2008-04-14 06:49 15872 c:\windows\LastGood\system32\dllcache\padrs404.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 53248 c:\windows\LastGood\system32\dllcache\nextlink.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 98304 c:\windows\LastGood\system32\dllcache\msir3jp.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 34816 c:\windows\LastGood\system32\dllcache\migisol.exe
+ 2010-06-24 14:09 . 2001-10-25 12:00 92416 c:\windows\LastGood\system32\dllcache\mga.sys
+ 2010-06-24 14:09 . 2001-10-25 12:00 92032 c:\windows\LastGood\system32\dllcache\mga.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 26624 c:\windows\LastGood\system32\dllcache\mdsync.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 22016 c:\windows\LastGood\system32\dllcache\logscrpt.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 70656 c:\windows\LastGood\system32\dllcache\korwbrkr.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 18432 c:\windows\LastGood\system32\dllcache\jupiw.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 19968 c:\windows\LastGood\system32\dllcache\inetsloc.dll
+ 2010-06-24 14:08 . 2004-08-03 21:31 59392 c:\windows\LastGood\system32\dllcache\imscinst.exe
+ 2010-06-24 14:08 . 2001-10-25 12:00 59904 c:\windows\LastGood\system32\dllcache\imkrinst.exe
+ 2010-06-24 14:08 . 2001-10-25 12:00 45109 c:\windows\LastGood\system32\dllcache\imjpuex.exe
+ 2010-06-24 14:08 . 2008-04-14 06:47 81976 c:\windows\LastGood\system32\dllcache\imjpdct.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 57398 c:\windows\LastGood\system32\dllcache\imjpdadm.exe
+ 2010-06-24 14:08 . 2001-10-25 12:00 44032 c:\windows\LastGood\system32\dllcache\imekrmig.exe
+ 2010-06-24 14:08 . 2008-04-14 06:47 86016 c:\windows\LastGood\system32\dllcache\imekrmbx.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 14848 c:\windows\LastGood\system32\dllcache\iisreset.exe
+ 2010-06-24 14:08 . 2001-10-25 12:00 19456 c:\windows\LastGood\system32\dllcache\iiscrmap.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 60928 c:\windows\LastGood\system32\dllcache\iisclex4.dll
+ 2010-06-24 14:06 . 2008-04-14 06:38 56320 c:\windows\LastGood\system32\dllcache\chtskdic.dll
+ 2010-06-24 14:06 . 2008-04-14 06:38 97792 c:\windows\LastGood\system32\dllcache\chtmbx.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 14848 c:\windows\LastGood\system32\dllcache\chgusr.exe
+ 2010-06-24 14:06 . 2001-10-25 12:00 15872 c:\windows\LastGood\system32\dllcache\chgport.exe
+ 2010-06-24 14:06 . 2001-10-25 12:00 13312 c:\windows\LastGood\system32\dllcache\chglogon.exe
+ 2010-06-24 14:07 . 2001-10-25 12:00 36864 c:\windows\LastGood\system32\dllcache\hanjadic.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 11776 c:\windows\LastGood\system32\dllcache\fxssend.exe
+ 2010-06-24 14:07 . 2001-10-25 12:00 31744 c:\windows\LastGood\system32\dllcache\fxsroute.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 14848 c:\windows\LastGood\system32\dllcache\flattemp.exe
+ 2010-06-24 14:07 . 2001-08-17 18:10 22090 c:\windows\LastGood\system32\dllcache\fem556n5.sys
+ 2010-06-24 14:11 . 2001-10-24 11:25 12288 c:\windows\LastGood\system32\dllcache\EXCH_smtpctrs.dll
+ 2010-06-24 14:11 . 2001-10-24 11:25 26112 c:\windows\LastGood\system32\dllcache\EXCH_seos.dll
+ 2010-06-24 14:11 . 2001-10-24 11:25 57856 c:\windows\LastGood\system32\dllcache\EXCH_scripto.dll
+ 2010-06-24 14:11 . 2001-10-24 11:25 23040 c:\windows\LastGood\system32\dllcache\EXCH_regtrace.exe
+ 2010-06-24 14:10 . 2001-10-24 11:24 38912 c:\windows\LastGood\system32\dllcache\EXCH_ntfsdrv.dll
+ 2010-06-24 14:09 . 2001-10-24 11:24 65536 c:\windows\LastGood\system32\dllcache\EXCH_mailmsg.dll
+ 2010-06-24 14:07 . 2001-10-24 11:24 43520 c:\windows\LastGood\system32\dllcache\EXCH_fcachdll.dll
+ 2010-06-24 14:05 . 2001-10-24 11:24 45056 c:\windows\LastGood\system32\dllcache\EXCH_aqadmin.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 25856 c:\windows\LastGood\system32\dllcache\et4000.sys
+ 2010-06-24 14:07 . 2001-10-25 12:00 45056 c:\windows\LastGood\system32\dllcache\esunid.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 57856 c:\windows\LastGood\system32\dllcache\esuimgd.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 31744 c:\windows\LastGood\system32\dllcache\esucmd.dll
+ 2010-06-24 14:07 . 2001-08-17 18:10 19996 c:\windows\LastGood\system32\dllcache\em556n4.sys
+ 2010-06-24 14:06 . 2001-10-25 12:00 18944 c:\windows\LastGood\system32\dllcache\cprofile.exe
+ 2010-06-24 14:06 . 2004-08-03 21:31 57399 c:\windows\LastGood\system32\dllcache\cplexe.exe
+ 2010-06-24 14:06 . 2001-10-25 12:00 20480 c:\windows\LastGood\system32\dllcache\counters.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 57344 c:\windows\LastGood\system32\dllcache\convlog.exe
+ 2010-06-24 14:06 . 2001-10-25 12:00 33792 c:\windows\LastGood\system32\dllcache\controt.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 54528 c:\windows\LastGood\system32\dllcache\cap7146.sys
+ 2010-06-24 14:06 . 2001-10-25 12:00 10752 c:\windows\LastGood\system32\dllcache\c_iscii.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 45568 c:\windows\LastGood\system32\dllcache\browscap.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 29184 c:\windows\LastGood\system32\dllcache\asptxn.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 10240 c:\windows\LastGood\system32\dllcache\aspperf.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 50176 c:\windows\LastGood\system32\dllcache\adrot.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 7168 c:\windows\LastGood\system32\dllcache\wamregps.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 9216 c:\windows\LastGood\system32\dllcache\wamps51.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\w3svapi.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 4608 c:\windows\LastGood\system32\dllcache\w3ctrs51.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\smimsgif.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\smierrsy.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 9728 c:\windows\LastGood\system32\dllcache\query.exe
+ 2010-06-24 14:10 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\pmxgl.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdvntc.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdusa.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdurdu.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdth3.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdth2.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdth1.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdth0.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdsyr2.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdsyr1.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 7680 c:\windows\LastGood\system32\dllcache\kbdnecnt.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 9216 c:\windows\LastGood\system32\dllcache\kbdnecat.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 7168 c:\windows\LastGood\system32\dllcache\kbdnec95.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdintel.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdintam.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\kbdinpun.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinmar.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinkan.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinhin.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdinguj.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdindev.dll
+ 2010-06-24 14:09 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdheb.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5120 c:\windows\LastGood\system32\dllcache\kbdgeo.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbdfa.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbddiv2.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbddiv1.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5120 c:\windows\LastGood\system32\dllcache\kbdarmw.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5120 c:\windows\LastGood\system32\dllcache\kbdarme.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbda3.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbda2.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\kbda1.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\kbd101a.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 9216 c:\windows\LastGood\system32\dllcache\iwrps.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 7168 c:\windows\LastGood\system32\dllcache\isapips.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 8704 c:\windows\LastGood\system32\dllcache\infoctrs.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 7680 c:\windows\LastGood\system32\dllcache\inetmgr.exe
+ 2010-06-24 14:08 . 2001-10-25 12:00 6656 c:\windows\LastGood\system32\dllcache\iissync.exe
+ 2010-06-24 14:05 . 2001-10-25 12:00 5632 c:\windows\LastGood\system32\dllcache\iisrstap.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 3584 c:\windows\LastGood\system32\dllcache\iismui.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 9728 c:\windows\LastGood\system32\dllcache\change.exe
+ 2010-06-24 14:04 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\ftpsapi2.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 7680 c:\windows\LastGood\system32\dllcache\ftpctrs2.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\ftlx041e.dll
+ 2010-06-24 14:11 . 2001-10-24 11:25 7168 c:\windows\LastGood\system32\dllcache\EXCH_snprfdll.dll
+ 2010-06-24 14:05 . 2001-10-24 11:24 5632 c:\windows\LastGood\system32\dllcache\EXCH_adsiisex.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 6656 c:\windows\LastGood\system32\dllcache\c_is2022.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 9216 c:\windows\LastGood\system32\dllcache\authfilt.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 6144 c:\windows\LastGood\system32\dllcache\admxprox.dll
+ 2001-10-25 12:00 . 2010-06-24 13:41 311740 c:\windows\system32\perfh009.dat
+ 2010-06-24 14:12 . 2008-04-14 06:50 426041 c:\windows\LastGood\system32\dllcache\voicepad.dll
+ 2010-06-24 14:12 . 2004-08-03 21:32 455168 c:\windows\LastGood\system32\dllcache\tintsetp.exe
+ 2010-06-24 14:12 . 2001-10-25 12:00 185344 c:\windows\LastGood\system32\dllcache\thawbrkr.dll
+ 2010-06-24 14:12 . 2001-10-25 12:00 101376 c:\windows\LastGood\system32\dllcache\srusbusd.dll
+ 2010-06-24 14:11 . 2001-10-25 12:00 143422 c:\windows\LastGood\system32\dllcache\softkey.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 131584 c:\windows\LastGood\system32\dllcache\pmxviceo.dll
+ 2010-06-24 14:10 . 2008-04-14 06:49 175104 c:\windows\LastGood\system32\dllcache\pintlcsa.dll
+ 2010-06-24 14:10 . 2001-10-25 12:00 229439 c:\windows\LastGood\system32\dllcache\multibox.dll
+ 2010-06-24 14:08 . 2008-04-14 06:47 315455 c:\windows\LastGood\system32\dllcache\imskf.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 471102 c:\windows\LastGood\system32\dllcache\imskdic.dll
+ 2010-06-24 14:08 . 2008-04-14 06:47 102456 c:\windows\LastGood\system32\dllcache\imlang.dll
+ 2010-06-24 14:08 . 2008-04-14 06:47 274489 c:\windows\LastGood\system32\dllcache\imjputyc.dll
+ 2010-06-24 14:08 . 2004-08-03 21:32 262200 c:\windows\LastGood\system32\dllcache\imjputy.exe
+ 2010-06-24 14:08 . 2004-08-03 21:32 233527 c:\windows\LastGood\system32\dllcache\imjprw.exe
+ 2010-06-24 14:08 . 2004-08-03 21:32 208952 c:\windows\LastGood\system32\dllcache\imjpmig.exe
+ 2010-06-24 14:08 . 2004-08-03 21:31 196665 c:\windows\LastGood\system32\dllcache\imjpinst.exe
+ 2010-06-24 14:08 . 2004-08-03 21:31 155705 c:\windows\LastGood\system32\dllcache\imjpdsvr.exe
+ 2010-06-24 14:08 . 2004-08-03 21:31 307257 c:\windows\LastGood\system32\dllcache\imjpdct.exe
+ 2010-06-24 14:08 . 2008-04-14 06:47 716856 c:\windows\LastGood\system32\dllcache\imjpcus.dll
+ 2010-06-24 14:08 . 2008-04-14 06:47 368696 c:\windows\LastGood\system32\dllcache\imjpcic.dll
+ 2010-06-24 14:08 . 2008-04-14 06:47 811064 c:\windows\LastGood\system32\dllcache\imjp81k.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 311359 c:\windows\LastGood\system32\dllcache\imepadsv.exe
+ 2010-06-24 14:08 . 2001-10-25 12:00 102463 c:\windows\LastGood\system32\dllcache\imepadsm.dll
+ 2010-06-24 14:08 . 2008-04-14 06:47 106496 c:\windows\LastGood\system32\dllcache\imekrcic.dll
+ 2010-06-24 14:05 . 2001-10-25 12:00 171008 c:\windows\LastGood\system32\dllcache\iisui.dll
+ 2010-06-24 14:06 . 2008-04-14 06:38 173568 c:\windows\LastGood\system32\dllcache\chtskf.dll
+ 2010-06-24 14:06 . 2001-10-25 12:00 838144 c:\windows\LastGood\system32\dllcache\chtbrkr.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 137216 c:\windows\LastGood\system32\dllcache\fxsclntr.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 112128 c:\windows\LastGood\system32\dllcache\fxscfgwz.dll
+ 2010-06-24 14:07 . 2001-10-25 12:00 514587 c:\windows\LastGood\system32\dllcache\edb500.dll
+ 2010-06-24 14:06 . 2004-08-03 21:31 480256 c:\windows\LastGood\system32\dllcache\cintsetp.exe
+ 2010-06-24 14:06 . 2008-04-14 06:38 198656 c:\windows\LastGood\system32\dllcache\cintime.dll
+ 2010-06-24 14:05 . 2009-02-09 11:26 2191232 c:\windows\LastGood\system32\dllcache\ntoskrnl.exe
+ 2010-06-24 14:10 . 2009-02-10 17:09 2068224 c:\windows\LastGood\system32\dllcache\ntkrnlpa.exe
+ 2010-06-24 14:06 . 2001-10-25 12:00 1677824 c:\windows\LastGood\system32\dllcache\chsbrkr.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 10129408 c:\windows\LastGood\system32\dllcache\hwxkor.dll
+ 2010-06-24 14:08 . 2008-04-14 06:46 13463552 c:\windows\LastGood\system32\dllcache\hwxjpn.dll
+ 2010-06-24 14:08 . 2001-10-25 12:00 10096640 c:\windows\LastGood\system32\dllcache\hwxcht.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-06-07 2403568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-07 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-07 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-07 137752]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Olina Tlap kov \Nabˇdka Start\Programy\Po spuçtŘnˇ\
Z stupce - FarUpd.lnk - y:\install\FarUpd.exe [2009-5-28 331776]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: Public
Trusted Zone: Public (Y:)
Trusted Zone: server
Trusted Zone: taco
FF - ProfilePath - c:\documents and settings\Olina Tlapáková\Data aplikací\Mozilla\Firefox\Profiles\wimhyrn9.default\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-25 11:10
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(728)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'explorer.exe'(516)
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-06-25 11:11:12
ComboFix-quarantined-files.txt 2010-06-25 07:51
ComboFix2.txt 2010-06-24 13:36
ComboFix3.txt 2009-02-16 15:12
ComboFix4.txt 2009-01-12 12:02
Před spuštěním: Volných bajtů: 123 265 183 744
Po spuštění: Volných bajtů: 123 311 050 752
- - End Of File - - EA08ED4D65EFA22F66905F021409A3F4
LOG z
UsbFixu (ten odkaz nefunguje):
############################## | UsbFix 7.014 | [Research]
User: Olina Tlapáková (Administrator) # OLINA [ ]
Updated 24/06/10 by El Desaparecido / C_XX
Started at 11:12:13 | 25/06/2010
Website:
http://pagesperso-orange.fr/NosTools/index.html
Contact:
FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
CPU 2: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: AVG Anti-Virus Network Edition 9.0 [(!) Disabled | Updated]
RAM -> 2037 Mb
C:\ (%systemdrive%) -> Fixed drive # 128 Gb (114 Mb free - 89%) [] # NTFS
H:\ -> CD-ROM
I:\ -> Fixed drive # 105 Gb (99 Mb free - 95%) [Nový svazek] # NTFS
J:\ -> Removable drive # 2 Gb (2 Mb free - 95%) [CORSAIR] # FAT32
################## | Files # Infected Folders |
Found ! J:\log.txt
################## | Registry |
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F |
Co se týče přepsaných hodnot v registrech (fystemRoot), tak ty nejsou - jsou tam správné, ale nemůžu vyloučit, že tam někdy v minulosti byla ta potvora, co se šíří přes flashky (ten počítač je přístupný mnoha lidem, někdo z nich samozřejmě mohl mít infikovanou flashku).
Nicméně je pravda, že se dneska rozběhly aktualizace, takže asi zase tak docela záplatovaný nebyl.
Uff, napište mi, že už je to všecko, jo?
