ComboFix 11-04-16.03 - Ondra 17.04.2011 22:37:43.5.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3582.2705 [GMT 2:00]
Spuštěný z: c:\documents and settings\Ondra\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Ondra\Plocha\CFscript.txt
* Vytvořen nový Bod Obnovení
.
FILE ::
"C:\found.001"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1275210071-1284227242-839522115-1003.job"
"c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1275210071-1284227242-839522115-1003.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1275210071-1284227242-839522115-1003.job
c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1275210071-1284227242-839522115-1003.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE1C9B099A30C58B0
-------\Service_gkariyw
-------\Service_gupdate1c9b099a30c58b0
-------\Service_xcpip
-------\Service_xpsec
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-17 do 2011-04-17 )))))))))))))))))))))))))))))))
.
.
2011-04-16 12:14 . 2011-04-17 18:58 -------- d-----w- c:\documents and settings\Ondra\.freemind
2011-04-16 12:14 . 2011-04-16 12:14 -------- d-----w- c:\program files\FreeMind
2011-04-04 22:30 . 2011-04-11 17:20 -------- d-----w- c:\program files\Defraggler
2011-04-04 10:39 . 2011-04-04 10:39 -------- d-----w- c:\documents and settings\Ondra\Data aplikací\Foxit Software
2011-04-04 09:14 . 2011-04-04 09:14 75208 ----a-w- c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
2011-04-04 08:35 . 2011-04-04 08:35 -------- d-----w- C:\_OTM
2011-04-02 22:44 . 2011-04-02 22:44 -------- d-----w- C:\found.001
2011-04-02 16:23 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-02 16:23 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-02 16:23 . 2011-04-02 16:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-02 10:04 . 2010-09-29 15:13 24064 ----a-w- c:\windows\system32\drivers\motmodem.sys
2011-04-02 10:04 . 2010-12-03 12:03 20352 ----a-w- c:\windows\system32\drivers\motccgp.sys
2011-04-02 10:04 . 2009-01-29 14:18 8320 ----a-w- c:\windows\system32\drivers\motccgpfl.sys
2011-04-02 10:04 . 2007-11-02 12:51 6400 ----a-w- c:\windows\system32\drivers\motswch.sys
2011-04-02 10:04 . 2009-12-21 11:42 15616 ----a-w- c:\windows\system32\mot_ci.dll
2011-04-02 10:04 . 2009-05-08 08:56 42752 ----a-w- c:\windows\system32\drivers\motodrv.sys
2011-04-02 10:04 . 2011-04-02 10:04 -------- d-----w- c:\program files\Common Files\Motorola Shared
2011-04-02 10:04 . 2011-04-02 10:15 -------- d-----w- c:\program files\Motorola
2011-04-01 07:29 . 2011-04-01 07:29 -------- d-----w- C:\spoolerlogs
2011-03-30 17:57 . 2011-04-01 21:29 -------- d-----w- c:\documents and settings\All Users\Data aplikací\lDi28604gNpNk28604
2011-03-25 14:44 . 2009-06-03 10:33 3482112 ----a-w- c:\windows\system32\drivers\snp2uvc.sys
2011-03-25 14:44 . 2009-02-11 12:45 27264 ----a-w- c:\windows\system32\drivers\sncduvc.sys
2011-03-25 14:44 . 2008-08-20 17:04 291328 ----a-w- c:\windows\system32\vsnp2uvc.dll
2011-03-25 14:44 . 2008-08-01 15:10 675840 ----a-w- c:\windows\vsnp2uvc.exe
2011-03-25 14:44 . 2007-07-04 16:28 176128 ----a-w- c:\windows\system32\csnp2uvc.dll
2011-03-25 14:44 . 2008-08-21 12:46 184320 ----a-w- c:\windows\system32\rsnp2uvc.dll
2011-03-25 14:44 . 2009-06-01 09:22 320512 ----a-w- c:\windows\tsnp2uvc.exe
2011-03-25 14:44 . 2011-03-25 14:44 -------- d-----w- c:\program files\Common Files\SNP2UVC
2011-03-25 14:44 . 2004-08-09 16:43 94208 ----a-w- c:\windows\amcap.exe
2011-03-25 14:31 . 2008-04-13 18:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2011-03-25 14:31 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-03-24 21:12 . 2011-03-24 21:12 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SafeNet Sentinel
2011-03-24 21:03 . 2011-03-24 21:05 -------- d-----w- c:\program files\Microsoft SQL Server
2011-03-24 21:01 . 2005-06-15 02:00 102400 ----a-w- c:\windows\system32\tsccvid.dll
2011-03-24 21:01 . 2011-03-24 21:01 -------- d-----w- c:\windows\system32\RNBOSENT
2011-03-24 21:01 . 2008-04-02 15:29 50176 ----a-w- c:\windows\system32\SNTI386.DLL
2011-03-24 21:01 . 2008-04-02 15:29 76288 ----a-w- c:\windows\system32\drivers\SENTINEL.SYS
2011-03-24 21:01 . 2008-04-02 15:29 18432 ----a-w- c:\windows\system32\RNBOVDD.DLL
2011-03-24 21:00 . 2011-03-24 21:00 304640 ----a-w- c:\windows\system32\hlvdd.dll
2011-03-24 21:00 . 2011-03-24 21:00 6656 ----a-w- c:\windows\system32\haspvdd.dll
2011-03-24 21:00 . 2011-03-24 21:00 47616 ----a-w- c:\windows\system32\drivers\Haspnt.sys
2011-03-24 21:00 . 2011-03-24 21:00 383 ----a-w- c:\windows\system32\haspdos.sys
2011-03-24 20:55 . 2011-03-24 20:58 -------- d-----w- c:\program files\Edgecam
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2008-12-09 20:51 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:36 . 2004-08-18 11:00 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:53 . 2004-08-18 11:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:08 . 2004-08-18 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:08 . 2004-08-18 11:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:08 . 2004-08-18 11:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-18 11:00 385024 ----a-w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2004-08-18 11:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-18 11:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:54 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-18 11:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2004-08-18 11:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-18 11:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2004-08-18 11:00 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2004-08-18 11:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2008-12-09 20:50 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2008-12-09 20:50 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-08-18 11:00 440320 ----a-w- c:\windows\system32\shimgvw.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\All Users\Data aplikacĂ\lDi28604gNpNk28604 ----
.
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotkeyP"="c:\program files\hotkeyp\HotkeyP.exe" [2008-07-15 65536]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-04-20 26192680]
"Alt+S Override"="c:\program files\Alt+S Override\Alt+S Override.exe" [2009-10-08 154112]
"EasyPHP"="c:\program files\EasyPHP-5.3.1\EasyPHP-5.3.1.exe" [2010-02-15 277504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-07 13529088]
"nwiz"="nwiz.exe" [2008-05-07 1630208]
"NVHotkey"="nvHotkey.dll" [2008-05-07 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-07 86016]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 823296]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 974848]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-10 36864]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-10-25 167936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
.
c:\documents and settings\Ondra\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Z stupce - miranda32.exe.lnk - c:\program files\Miranda IM\miranda32.exe [2011-1-21 817760]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
CLS2009.01.lnk - c:\program files\Edgecam\Cam\cls.exe [2011-3-24 782336]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Bluetooth.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ondra^Nabídka Start^Programy^Po spuštění^Adobe Gamma.lnk]
path=c:\documents and settings\Ondra\Nabídka Start\Programy\Po spuštění\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ondra^Nabídka Start^Programy^Po spuštění^Jádro Plánovače úloh SolidWorks.lnk]
path=c:\documents and settings\Ondra\Nabídka Start\Programy\Po spuštění\Jádro Plánovače úloh SolidWorks.lnk
backup=c:\windows\pss\Jádro Plánovače úloh SolidWorks.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ondra^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Ondra\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-09-13 10:12 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mumservice]
2011-02-02 14:45 1066304 ----a-w- c:\program files\Motorola\Software Update\mumservice.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 15:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-11-04 09:30 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartSync - ScheduleSync]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
2008-04-04 10:38 88584 ----a-w- c:\program files\Logitech\Gaming Software\LWEMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-03-06 13:37 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BBDemon"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"mnmsrvc"=3 (0x3)
"ERSvc"=2 (0x2)
"TapiSrv"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\LowRateVoip\\LowRateVoip.exe"=
"c:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Python25\\pythonw.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\rFactor\\rFactor.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=
"c:\\Program Files\\Motorola\\Software Update\\mumapp.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"7328:TCP"= 7328:TCP:Services
"7329:TCP"= 7329:TCP:Services
"9880:TCP"= 9880:TCP:Services
"9881:TCP"= 9881:TCP:Services
"5804:TCP"= 5804:TCP:Services
"5507:TCP"= 5507:TCP:Services
"9677:TCP"= 9677:TCP:Services
"8008:TCP"= 8008:TCP:Services
"4960:TCP"= 4960:TCP:Services
"5369:TCP"= 5369:TCP:Services
"2225:TCP"= 2225:TCP:Services
"6991:TCP"= 6991:TCP:Services
"4507:TCP"= 4507:TCP:Services
"7514:TCP"= 7514:TCP:Services
"1694:TCP"= 1694:TCP:Services
"7912:TCP"= 7912:TCP:Services
"2460:TCP"= 2460:TCP:Services
"9271:TCP"= 9271:TCP:Services
"2413:TCP"= 2413:TCP:Services
"9334:TCP"= 9334:TCP:Services
"4975:TCP"= 4975:TCP:Services
"8818:TCP"= 8818:TCP:Services
"3960:TCP"= 3960:TCP:Services
"7959:TCP"= 7959:TCP:Services
"2491:TCP"= 2491:TCP:Services
"9099:TCP"= 9099:TCP:Services
"1725:TCP"= 1725:TCP:Services
"9474:TCP"= 9474:TCP:Services
"9521:TCP"= 9521:TCP:Services
"9943:TCP"= 9943:TCP:Services
"1897:TCP"= 1897:TCP:Services
"3054:TCP"= 3054:TCP:Services
"4539:TCP"= 4539:TCP:Services
"2850:TCP"= 2850:TCP:Services
"2038:TCP"= 2038:TCP:Services
"7287:TCP"= 7287:TCP:Services
"5802:TCP"= 5802:TCP:Services
"1788:TCP"= 1788:TCP:Services
"7490:TCP"= 7490:TCP:Services
"3585:TCP"= 3585:TCP:Services
.
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [13.10.2006 22:53 14912]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [1.11.2010 18:08 143184]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [1.11.2010 18:08 41936]
R2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [3.12.2010 1:48 218432]
R2 Remote Solver for Flow Simulation 2010;Remote Solver for Flow Simulation 2010;c:\program files\SolidWorks Corp\SolidWorks Flow Simulation\binCFW\StandAloneSlv.exe [23.11.2009 20:48 71464]
R3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [22.5.2009 18:47 16384]
R3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\drivers\gMouPS2.sys [22.5.2009 18:47 17408]
R3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [22.5.2009 18:47 9856]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [8.10.2010 16:57 100560]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [8.10.2010 16:57 111568]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [20.1.2010 1:59 87336]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [21.11.2010 16:11 112640]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [21.11.2010 19:43 100480]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2.4.2011 12:04 20352]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2.4.2011 12:04 8320]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2.4.2011 12:04 42752]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [1.11.2010 18:08 31888]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [27.1.2010 12:22 11520]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 8:01 2799808]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.12.2008 19:02 721904]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - xcpip
*Deregistered* - xpsec
.
Obsah adresáře 'Naplánované úlohy'
.
2011-04-17 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2009-01-01 05:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.lide.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {D282F74B-6F08-4903-B5C4-F39D344FDC8A} = 77.78.80.211,213.46.172.36
FF - ProfilePath - c:\documents and settings\Ondra\Data aplikací\Mozilla\Firefox\Profiles\h74hq88m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.startup.homepage - hxxp://localhost/to-do-list.php
FF - prefs.js: keyword.URL - hxxp://
www.google.co.in/search?btnG=Google+Search&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: ÄŚeskĂ© slovnĂky pro kontrolu pravopisu:
cs@dictionaries.addons.mozilla.org - %profile%\extensions\
cs@dictionaries.addons.mozilla.org
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-04-17 22:51
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3060)
c:\windows\system32\webcheck.dll
c:\program files\Windows Desktop Search\dsWebAllow.dll
c:\program files\Windows Desktop Search\cs-cz\dsWebAllowRes.dll.mui
c:\program files\Windows Desktop Search\dsWebAllowRes.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\EASYPH~1.1\Apache\bin\apache.exe
c:\progra~1\EASYPH~1.1\MySql\bin\mysqld.exe
c:\progra~1\EASYPH~1.1\Apache\bin\apache.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Motorola\MotoHelper\MotoHelperAgent.exe
c:\program files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\Rundll32.exe
.
**************************************************************************
.
Celkový čas: 2011-04-17 22:55:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-04-17 20:55
ComboFix2.txt 2010-02-11 17:13
.
Před spuštěním: Volných bajtů: 57 237 352 448
Po spuštění: Volných bajtů: 57 300 873 216
.
- - End Of File - - 8830A302A076AD19C81D13AA24A47AFA