ComboFix 11-11-28.02 - OEM 28.11.2011 16:56:36.11.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1014.484 [GMT 1:00]
Spuštěný z: c:\documents and settings\OEM\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-28 do 2011-11-28 )))))))))))))))))))))))))))))))
.
.
2011-11-28 13:49 . 2011-11-28 15:55 -------- d-----w- c:\windows\system32\CatRoot2
2011-11-27 16:33 . 2011-11-27 16:33 -------- d-----w- c:\documents and settings\OEM\Data aplikací\Process Hacker 2
2011-11-27 11:45 . 2011-11-27 11:45 -------- d-----w- c:\program files\Process Hacker 2
2011-11-26 17:46 . 2011-11-26 17:46 -------- d-----w- c:\documents and settings\OEM\Data aplikací\PCDr
2011-11-26 17:12 . 2008-05-07 06:38 90624 ----a-w- c:\windows\system32\nmwcdcls.dll
2011-11-26 17:12 . 2011-11-26 17:12 -------- d-----w- c:\program files\Nokia
2011-11-26 17:11 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2011-11-26 17:11 . 2011-11-26 17:11 -------- d-----w- c:\program files\PC Connectivity Solution
2011-11-26 17:11 . 2011-11-26 17:11 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Installations
2011-11-26 15:22 . 2008-02-08 08:46 57408 ------w- c:\windows\system32\drivers\wsimd.sys
2011-11-26 15:22 . 2009-05-19 10:41 254022 ----a-w- c:\windows\system32\wsfwDS.dll
2011-11-26 15:22 . 2009-05-19 10:41 249924 ----a-w- c:\windows\system32\wsimd.dll
2011-11-26 15:22 . 2009-05-19 10:23 82017 ----a-r- c:\windows\system32\dsaNac.dll
2011-11-26 15:22 . 2009-05-19 10:23 1269854 ----a-r- c:\windows\system32\dsa.dll
2011-11-26 15:22 . 2009-04-03 10:18 1347168 ----a-w- c:\windows\system32\athw.sys
2011-11-26 15:22 . 2008-02-08 08:46 57408 ----a-w- c:\windows\system32\wsimd.sys
2011-11-26 15:22 . 2006-08-07 13:17 118784 ----a-w- c:\windows\system32\ATHCFG10.DLL
2011-11-26 14:23 . 2011-11-26 14:23 -------- d-----w- c:\program files\Common Files\Intel
2011-11-26 14:23 . 2011-11-26 14:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Intel
2011-11-25 23:25 . 2011-11-26 14:13 376832 ----a-w- c:\windows\system32\AegisI5Installer.exe
2011-11-25 11:16 . 2011-11-25 11:16 -------- d-----w- c:\documents and settings\NetworkService\Data aplikací\Intel
2011-11-25 11:16 . 2011-11-25 11:16 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Intel
2011-11-25 11:15 . 2011-11-25 11:15 -------- d-----w- c:\documents and settings\OEM\Data aplikací\Intel
2011-11-24 22:45 . 2011-11-24 22:45 -------- d-----w- C:\rsit
2011-11-24 22:13 . 2007-02-27 10:09 36400 ----a-w- c:\windows\system32\ibmpmsvc.exe
2011-11-24 22:13 . 2007-01-24 09:27 67960 ----a-w- c:\windows\system32\drivers\btwusb.sys
2011-11-24 12:19 . 2007-01-30 03:05 108080 ----a-w- c:\windows\system32\IPSSVC.EXE
2011-11-24 07:57 . 2008-04-14 07:51 155136 ------w- c:\windows\system32\mssha.dll
2011-11-24 07:53 . 2011-11-24 07:58 -------- d-----w- c:\windows\ServicePackFiles
2011-11-24 07:45 . 2006-12-28 23:31 19569 ----a-w- c:\windows\002734_.tmp
2011-11-23 21:58 . 2011-11-23 21:58 -------- d-----w- c:\documents and settings\OEM\Data aplikací\Malwarebytes
2011-11-23 21:58 . 2011-11-23 21:58 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-11-20 23:49 . 2008-04-14 07:52 78848 ----a-w- c:\windows\system32\msiexec.exe
2011-11-20 23:49 . 2008-06-20 11:40 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-20 10:31 . 2011-11-20 10:31 35712 ----a-w- c:\windows\system32\drivers\BlackBox.sys
2011-11-19 13:37 . 2011-11-19 13:37 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-11-18 11:22 . 2011-11-17 22:57 133208 ----a-w- c:\windows\system32\drivers\10418741.sys
2011-11-17 20:38 . 2011-11-17 22:57 133208 ----a-w- c:\windows\system32\drivers\44042542.sys
2011-11-17 16:38 . 2011-11-27 08:38 -------- d-----w- c:\program files\trend micro
2011-11-17 14:59 . 2011-11-18 08:19 -------- d-----w- c:\documents and settings\OEM\Data aplikací\AVI ReComp
2011-11-17 14:58 . 2011-11-17 14:58 -------- d-----w- c:\program files\Gabest
2011-11-17 14:58 . 2011-11-17 14:58 -------- d-----w- c:\program files\Xvid
2011-11-17 14:57 . 2011-11-17 14:57 -------- d-----w- c:\program files\AviSynth 2.5
2011-11-17 14:54 . 2011-11-17 14:58 -------- d-----w- c:\program files\AVI ReComp
2011-11-17 14:45 . 2011-11-17 14:45 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\ESET
2011-11-17 11:55 . 2011-11-17 11:55 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-11-17 11:48 . 2011-11-17 11:48 -------- d-----w- c:\program files\ESET
2011-11-17 09:09 . 2011-11-17 11:38 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2011-11-16 18:37 . 2011-11-17 12:35 -------- d-sh--w- c:\documents and settings\OEM\Local Settings\Data aplikací\632ff156
2011-11-08 08:54 . 2011-11-08 09:58 -------- d-----w- c:\program files\WAS
2011-10-30 18:14 . 2011-10-30 18:14 -------- d-----w- c:\documents and settings\OEM\Data aplikací\Search Settings
2011-10-30 18:13 . 2011-11-17 12:47 -------- d-----w- c:\program files\Application Updater
2011-10-30 18:13 . 2011-10-30 18:13 -------- d-----w- c:\program files\IObit Toolbar
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-26 14:31 . 2007-11-20 21:23 33536 ----a-w- c:\windows\system32\drivers\tvtfilter.sys
2011-11-26 14:29 . 2007-11-20 21:23 129784 ------w- c:\windows\system32\pxafs.dll
2011-11-26 14:29 . 2007-11-20 21:23 118520 ------w- c:\windows\system32\pxinsi64.exe
2011-11-26 14:29 . 2007-11-20 21:23 116472 ------w- c:\windows\system32\pxcpyi64.exe
2011-11-26 14:29 . 2006-09-27 21:53 43528 ------w- c:\windows\system32\drivers\pxhelp20.sys
2011-10-24 18:31 . 2011-10-24 18:31 89680 ----a-w- c:\documents and settings\OEM\MSSSerif120.fon
2011-10-24 18:31 . 2011-10-24 18:31 64544 ----a-w- c:\documents and settings\OEM\MSSSerif96.fon
2011-11-11 22:07 . 2011-04-30 04:16 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-24_22.07.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-06-22 17:29 . 2011-06-22 17:29 16896 c:\windows\system32\S24NCfg.dll
+ 2007-11-20 21:23 . 2011-11-26 14:29 64760 c:\windows\system32\pxinsa64.exe
- 2007-11-20 21:23 . 2007-11-20 21:23 64760 c:\windows\system32\pxinsa64.exe
+ 2007-11-20 21:21 . 2011-11-26 14:29 72440 c:\windows\system32\pxhpinst.exe
- 2007-11-20 21:21 . 2007-11-20 21:23 72440 c:\windows\system32\pxhpinst.exe
+ 2007-11-20 21:23 . 2011-11-26 14:29 64760 c:\windows\system32\pxcpya64.exe
+ 2011-11-26 17:11 . 2008-08-26 09:26 18816 c:\windows\system32\DRVSTORE\pccsmcfd_A3B3916E5D8138F59EE218321B27B044D3B18294\pccsmcfd.sys
+ 2011-11-26 17:12 . 2008-05-07 06:38 20864 c:\windows\system32\DRVSTORE\ccdcmbo_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\ccdcmbo.sys
+ 2011-11-26 17:12 . 2008-05-07 06:38 90624 c:\windows\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\nmwcdcls.dll
+ 2011-11-26 17:12 . 2008-05-07 06:38 17536 c:\windows\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\ccdcmb.sys
+ 2010-05-19 21:15 . 2010-05-19 21:15 13952 c:\windows\system32\drivers\s24trans.sys
+ 2010-09-22 13:18 . 2010-09-22 13:18 29984 c:\windows\system32\BtXpShell.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 99616 c:\windows\system32\btrezxp.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 83232 c:\windows\system32\btprn2k.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 54560 c:\windows\system32\BTNCopy.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 99688 c:\windows\system32\BtMmHook.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 54624 c:\windows\system32\btdev.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 91504 c:\windows\system32\BtAudioHelper.dll
+ 2011-11-26 15:23 . 2006-07-17 15:26 77824 c:\windows\system32\athcfg11res.dll
- 2007-11-20 21:23 . 2007-11-20 21:23 53248 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\RRShortcut.21662843_F2BE_4BBB_AE57_E9FF3AE4F2C2.exe
+ 2007-11-20 21:23 . 2011-11-26 14:38 53248 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\RRShortcut.21662843_F2BE_4BBB_AE57_E9FF3AE4F2C2.exe
- 2007-11-20 21:23 . 2007-11-20 21:23 45056 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\rrmediashortcut.17CFF8A8_DF81_4628_B574_CEDE1139BCC2.exe
+ 2007-11-20 21:23 . 2011-11-26 14:38 45056 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\rrmediashortcut.17CFF8A8_DF81_4628_B574_CEDE1139BCC2.exe
- 2007-11-20 21:23 . 2007-11-20 21:23 49152 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\NewShortcut3.17CFF8A8_DF81_4628_B574_CEDE1139BCC2.exe
+ 2007-11-20 21:23 . 2011-11-26 14:38 49152 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\NewShortcut3.17CFF8A8_DF81_4628_B574_CEDE1139BCC2.exe
+ 2007-11-20 21:23 . 2011-11-26 14:38 49152 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\NewShortcut1.21662843_F2BE_4BBB_AE57_E9FF3AE4F2C2.exe
- 2007-11-20 21:23 . 2007-11-20 21:23 49152 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\NewShortcut1.21662843_F2BE_4BBB_AE57_E9FF3AE4F2C2.exe
- 2007-11-20 21:12 . 2007-11-20 21:12 49152 c:\windows\Installer\{8675339C-128C-44DD-83BF-0A5D6ABD8297}\tvsu.exe3_8675339C128C44DD83BF0A5D6ABD8297.exe
+ 2007-11-20 21:12 . 2011-11-26 14:48 49152 c:\windows\Installer\{8675339C-128C-44DD-83BF-0A5D6ABD8297}\tvsu.exe3_8675339C128C44DD83BF0A5D6ABD8297.exe
+ 2011-11-26 14:48 . 2011-11-26 14:48 53248 c:\windows\Installer\{8675339C-128C-44DD-83BF-0A5D6ABD8297}\tvsu.exe2_8675339C128C44DD83BF0A5D6ABD8297.exe
- 2007-11-20 21:12 . 2007-11-20 21:12 53248 c:\windows\Installer\{8675339C-128C-44DD-83BF-0A5D6ABD8297}\tvsu.exe2_8675339C128C44DD83BF0A5D6ABD8297.exe
+ 2011-11-26 14:48 . 2011-11-26 14:48 53248 c:\windows\Installer\{8675339C-128C-44DD-83BF-0A5D6ABD8297}\ARPPRODUCTICON.exe
- 2007-11-20 21:12 . 2007-11-20 21:12 53248 c:\windows\Installer\{8675339C-128C-44DD-83BF-0A5D6ABD8297}\ARPPRODUCTICON.exe
+ 2011-11-26 14:02 . 2011-11-26 14:02 33982 c:\windows\Installer\{84814E6B-2581-46EC-926A-823BD1C670F6}\ARPPRODUCTICON.exe
+ 2011-11-26 17:18 . 2011-11-26 17:18 10134 c:\windows\Installer\{83258E90-1F76-4E13-9F60-A0F8ED41E76F}\ARPPRODUCTICON.exe
+ 2011-11-26 14:25 . 2011-11-26 14:25 49152 c:\windows\Installer\{3FE3D6A5-2F5E-4870-A3AC-D1D88E0B2797}\NewShortcut1_EC2A9EA7A46E48B9A0FD04BC5EF9F6A5.exe
+ 2010-09-22 13:18 . 2010-09-22 13:18 30040 c:\windows\BtwIEProxy.exe
+ 2011-11-26 17:12 . 2008-06-06 08:24 8064 c:\windows\system32\DRVSTORE\ccdcmbm_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\usbser_lowerflt.sys
+ 2011-11-26 17:12 . 2008-05-07 06:38 8064 c:\windows\system32\DRVSTORE\ccdcmbcj_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\usbser_lowerfltj.sys
+ 2007-11-20 21:23 . 2011-11-26 14:38 9158 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\ARPPRODUCTICONLENOVO.exe
- 2007-11-20 21:23 . 2007-11-20 21:23 9158 c:\windows\Installer\{F151F2B3-0C32-44D3-90E2-E639B8024622}\ARPPRODUCTICONLENOVO.exe
+ 2011-11-26 17:12 . 2011-11-26 17:12 3262 c:\windows\Installer\{C3F19A5F-35A8-4FDB-A6ED-0F4CE398DA48}\ARPPRODUCTICON.exe
+ 2011-11-26 14:25 . 2011-11-26 14:25 9110 c:\windows\Installer\{3FE3D6A5-2F5E-4870-A3AC-D1D88E0B2797}\ARPPRODUCTICON.exe
+ 2010-09-22 13:18 . 2010-09-22 13:18 582944 c:\windows\system32\WidcommSdk.dll
+ 2011-11-26 15:23 . 2009-09-24 14:00 401498 c:\windows\system32\wgapi.dll
+ 2011-11-26 15:23 . 2009-09-24 14:00 352347 c:\windows\system32\wcapiU.dll
+ 2011-11-26 15:23 . 2009-09-24 13:56 426052 c:\windows\system32\wcapi.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 521568 c:\windows\system32\wbtapi.dll
+ 2011-11-26 15:23 . 2006-08-07 13:17 147456 c:\windows\system32\ssleay32.dll
+ 2006-05-12 13:26 . 2011-11-26 14:29 379640 c:\windows\system32\PxWave.dll
- 2006-05-12 13:26 . 2007-11-20 21:23 379640 c:\windows\system32\PxWave.dll
+ 2006-05-12 13:26 . 2011-11-26 14:29 187128 c:\windows\system32\PxMas.dll
+ 2006-11-01 00:02 . 2011-11-26 14:29 510712 c:\windows\system32\pxdrv.dll
+ 2006-05-12 13:25 . 2011-11-26 14:29 547576 c:\windows\system32\Px.dll
+ 2011-11-26 15:23 . 2006-08-07 13:17 651264 c:\windows\system32\libeay32.dll
+ 2011-11-26 15:23 . 2009-05-19 10:25 262216 c:\windows\system32\IPTests.dll
+ 2011-11-25 22:46 . 2007-02-12 11:40 557056 c:\windows\system32\DRVSTORE\w29n51_02092897E25039DF89C96EBB4841ACF0590117AE\Netw2c32.dll
+ 2011-11-26 17:11 . 2008-05-20 09:32 831048 c:\windows\system32\DRVSTORE\pccswpddri_66268C3E0C6968D7F539EAEAD801C68E0DB54FE9\WudfUpdate_01005.dll
+ 2011-11-26 17:11 . 2008-05-20 09:37 525824 c:\windows\system32\DRVSTORE\pccswpddri_66268C3E0C6968D7F539EAEAD801C68E0DB54FE9\PCCSWpdDriver.dll
+ 2011-11-25 11:15 . 2010-05-19 22:14 684032 c:\windows\system32\DRVSTORE\netwnx32_996D2EADED773B28D811AD2C67AE7435A86102EE\NETwNc32.dll
+ 2011-11-25 09:59 . 2010-05-18 21:29 684032 c:\windows\system32\DRVSTORE\netwnx32_5FF92BC28A46A6879973B2E4D95DED1E9DEC95BE\NETwNc32.dll
+ 2011-11-26 14:24 . 2010-02-24 16:39 675840 c:\windows\system32\DRVSTORE\netwlx32_2BE482C52CE0CF8A56BFD3ACF4CED8D99910A62A\NETwLc32.dll
+ 2011-11-25 21:39 . 2007-02-15 04:31 730112 c:\windows\system32\DRVSTORE\netw4x64_785EBDADC1651DEA5A2129C8454ECFADF7C81710\NETw4c64.dll
+ 2011-11-25 22:46 . 2007-06-01 09:33 684032 c:\windows\system32\DRVSTORE\netw4x32_E0FE06D1ECA9E65F55CA9E5396616665E1612479\NETw4c32.dll
+ 2011-11-25 22:46 . 2007-06-01 09:33 684032 c:\windows\system32\DRVSTORE\netw4k32_EB4BD78BC68C739D52433B4AE5118A1E9BA411EE\NETw4c32.dll
+ 2011-11-26 17:12 . 2008-05-07 06:38 659968 c:\windows\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\nmwcdcocls.dll
+ 2007-11-20 21:44 . 2008-04-14 04:50 361344 c:\windows\system32\drivers\tcpip.sys
+ 2010-09-22 13:18 . 2010-09-22 13:18 111904 c:\windows\system32\BTXPPanel.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 165200 c:\windows\system32\btwpimif.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 181616 c:\windows\system32\BtWiaExt.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 238880 c:\windows\system32\btwhidcs.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 165208 c:\windows\system32\btsendto_wab.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 279896 c:\windows\system32\btsendto_office.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 144728 c:\windows\system32\btsendto_notes.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 173400 c:\windows\system32\btsendto_ie.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 333136 c:\windows\system32\btsendto.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 218464 c:\windows\system32\btsec.dll
+ 2010-09-22 13:18 . 2010-09-22 12:55 995328 c:\windows\system32\btrez.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 152864 c:\windows\system32\btosif_olx.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 329040 c:\windows\system32\btosif_ol.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 320856 c:\windows\system32\btosif_notes.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 218448 c:\windows\system32\btosif.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 996720 c:\windows\system32\BTNeighborhood.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 554336 c:\windows\system32\btins.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 726352 c:\windows\system32\BTChooser.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 128288 c:\windows\system32\bthcrpui.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 111904 c:\windows\system32\bthcrp.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 435552 c:\windows\system32\btcss.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 288080 c:\windows\system32\btbip.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 128288 c:\windows\system32\btbigbmp.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 128360 c:\windows\system32\bt2k_ins.dll
+ 2011-11-26 15:23 . 2009-09-24 14:03 307294 c:\windows\system32\athcfg20U.dll
+ 2011-11-26 15:23 . 2009-09-24 14:03 127079 c:\windows\system32\athcfg20resU.dll
+ 2011-11-26 15:23 . 2009-09-24 13:55 127053 c:\windows\system32\athcfg20res.dll
+ 2011-11-26 15:23 . 2009-09-24 13:55 299079 c:\windows\system32\athcfg20.dll
+ 2011-11-26 15:23 . 2006-07-17 15:26 372736 c:\windows\system32\athcfg11.dll
+ 2011-11-26 15:23 . 2009-09-24 14:03 475220 c:\windows\system32\acs.exe
- 2007-11-20 21:03 . 2007-02-21 03:19 151552 c:\windows\Installer\iProInst.dll
+ 2007-11-20 21:03 . 2007-11-19 10:30 151552 c:\windows\Installer\iProInst.dll
+ 2011-11-26 17:12 . 2011-11-26 17:12 335360 c:\windows\Installer\430d9.msi
+ 2011-11-26 17:11 . 2011-11-26 17:11 464896 c:\windows\Installer\430d4.msi
+ 2006-05-12 13:26 . 2011-11-26 14:29 1628920 c:\windows\system32\PxSFS.DLL
+ 2001-11-14 12:56 . 2001-11-14 12:56 1802240 c:\windows\system32\lcppn21.dll
+ 2011-11-25 22:46 . 2007-04-04 12:46 2210048 c:\windows\system32\DRVSTORE\w29n51_02092897E25039DF89C96EBB4841ACF0590117AE\w29n51.sys
+ 2011-11-25 22:46 . 2007-04-04 12:48 2206464 c:\windows\system32\DRVSTORE\w29n51_02092897E25039DF89C96EBB4841ACF0590117AE\w29n50.sys
+ 2011-11-25 22:46 . 2007-02-12 11:41 2732032 c:\windows\system32\DRVSTORE\w29n51_02092897E25039DF89C96EBB4841ACF0590117AE\Netw2r32.dll
+ 2011-11-25 11:15 . 2010-10-18 01:14 6913920 c:\windows\system32\DRVSTORE\netwnx32_996D2EADED773B28D811AD2C67AE7435A86102EE\NETwNx32.sys
+ 2011-11-25 11:15 . 2010-05-19 21:12 2760704 c:\windows\system32\DRVSTORE\netwnx32_996D2EADED773B28D811AD2C67AE7435A86102EE\NETwNr32.dll
+ 2011-11-25 09:59 . 2011-08-03 16:15 7473152 c:\windows\system32\DRVSTORE\netwnx32_5FF92BC28A46A6879973B2E4D95DED1E9DEC95BE\NETwNx32.sys
+ 2011-11-25 09:59 . 2010-05-18 21:31 2760704 c:\windows\system32\DRVSTORE\netwnx32_5FF92BC28A46A6879973B2E4D95DED1E9DEC95BE\NETwNr32.dll
+ 2011-11-26 14:24 . 2010-10-07 04:11 6609920 c:\windows\system32\DRVSTORE\netwlx32_2BE482C52CE0CF8A56BFD3ACF4CED8D99910A62A\NETwLx32.sys
+ 2011-11-26 14:24 . 2010-02-24 16:37 2756608 c:\windows\system32\DRVSTORE\netwlx32_2BE482C52CE0CF8A56BFD3ACF4CED8D99910A62A\NETwLr32.dll
+ 2011-11-25 21:39 . 2007-03-27 20:27 3091456 c:\windows\system32\DRVSTORE\netw4x64_785EBDADC1651DEA5A2129C8454ECFADF7C81710\NETw4x64.sys
+ 2011-11-25 21:39 . 2007-02-15 04:31 2655744 c:\windows\system32\DRVSTORE\netw4x64_785EBDADC1651DEA5A2129C8454ECFADF7C81710\NETw4r64.dll
+ 2011-11-25 22:46 . 2007-06-21 03:43 2208512 c:\windows\system32\DRVSTORE\netw4x32_E0FE06D1ECA9E65F55CA9E5396616665E1612479\NETw4x32.sys
+ 2011-11-25 22:46 . 2007-06-01 09:33 2772992 c:\windows\system32\DRVSTORE\netw4x32_E0FE06D1ECA9E65F55CA9E5396616665E1612479\NETw4r32.dll
+ 2011-11-25 22:46 . 2007-06-01 09:33 2772992 c:\windows\system32\DRVSTORE\netw4k32_EB4BD78BC68C739D52433B4AE5118A1E9BA411EE\NETw4r32.dll
+ 2011-11-25 22:46 . 2007-06-21 03:41 2203520 c:\windows\system32\DRVSTORE\netw4k32_EB4BD78BC68C739D52433B4AE5118A1E9BA411EE\NETw4k32.sys
+ 2011-11-26 17:12 . 2008-05-07 06:39 1419232 c:\windows\system32\DRVSTORE\ccdcmb_8BBEC91EFF51E4A1A9EC754A696F267BFDD220D5\wdfcoinstaller01005.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 1795432 c:\windows\system32\BtWizard.dll
+ 2010-09-22 13:18 . 2010-09-22 13:18 2860384 c:\windows\system32\btwicons.dll
+ 2011-11-26 14:25 . 2011-11-26 14:25 7163392 c:\windows\Installer\68ac1.msi
+ 2011-11-26 14:02 . 2011-11-26 14:02 2694656 c:\windows\Installer\67b32.msi
+ 2011-11-26 14:48 . 2011-11-26 14:48 8033280 c:\windows\Installer\5d1e9.msi
+ 2011-11-26 14:37 . 2011-11-26 14:37 28469248 c:\windows\Installer\68b7c.msi
+ 2011-11-26 14:11 . 2011-08-13 05:02 40685056 c:\windows\Installer\_{3FE3D6A5-2F5E-4870-A3AC-D1D88E0B2797}\Intel PROSet Wireless.msi
+ 2011-11-26 14:29 . 2011-11-26 14:28 102683648 c:\windows\Downloaded Installations\{042525AF-47D2-4998-A80C-6DB95248344F}\Rescue and Recovery.msi
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840]
.
[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
.
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
.
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-08-09 417112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2007-04-12 196608]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2007-04-12 208896]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 58416]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2007-03-09 66176]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-03-05 172032]
"TpShocks"="TpShocks.exe" [2007-03-29 181808]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-03-28 243248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-02-26 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-02-26 155648]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-02-26 131072]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2010-12-09 1093632]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"ISUSPM Startup"="c:\program files\Common Files\Installshield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2007-03-22 120368]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-08 3076144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start
http://www.avg.com/ww.special-uninstall ... er=9.0.894" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\OEM\Nabídka Start\Programy\Po spuštění\
AccuWeather.lnk - c:\documents and settings\OEM\Dokumenty\AccuWeather.com Stratus\AccuWeather.com Stratus.exe [2011-8-18 142848]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-9-22 607584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-03-14 21:17 89600 ------w- c:\windows\system32\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 07:37 34344 ------w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 02:06 28672 ------w- c:\program files\Lenovo\HOTKEY\tphklock.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
2009-01-14 13:49 113680 ----a-w- c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
2011-04-28 07:59 220552 ----a-w- c:\program files\PDF24\pdf24.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [7.1.2009 23:39 20744]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2.3.2007 17:47 19760]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4.8.2011 9:20 118104]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [8.9.2011 7:34 974944]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [14.3.2007 22:10 11152]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [10.12.2010 0:27 1118208]
R3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [7.12.2008 12:44 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2.7.2008 14:58 26248]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [13.9.2006 12:42 35264]
R4 KProcessHacker2;KProcessHacker2;c:\program files\Process Hacker 2\kprocesshacker.sys [27.11.2011 12:45 33352]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [4.8.2011 9:20 103112]
S2 Application Updater;Application Updater;"c:\program files\Application Updater\ApplicationUpdater.exe" --> c:\program files\Application Updater\ApplicationUpdater.exe [?]
S2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe --> c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPService REG_MULTI_SZ HPSLPSVC
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-11-28 c:\windows\Tasks\ASC4_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-08-10 14:40]
.
2011-11-28 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2007-11-20 16:15]
.
2007-11-20 c:\windows\Tasks\Připomenutí registrace 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-11-20 07:52]
.
2007-11-20 c:\windows\Tasks\Připomenutí registrace 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-11-20 07:52]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.com
mStart Page = hxxp://search.myheritage.com
uInternet Settings,ProxyOverride = *.local
IE: Add to AMV Converter... - c:\program files\MP3 Player Utilities 4.09\AMVConverter\grab.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 4.09\MediaManager\grab.html
IE: Odeslat do zařízení &Bluetooth... - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
TCP: DhcpNameServer = 212.80.66.7
FF - ProfilePath - c:\documents and settings\OEM\Data aplikací\Mozilla\Firefox\Profiles\6jts2rqn.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage -
www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://
www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-BtTray - c:\program files\IVT Corporation\BlueSoleil\BtTray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-28 17:03
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(592)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\program files\ThinkVantage Fingerprint Software\pscssint.dll
.
- - - - - - - > 'lsass.exe'(648)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
.
- - - - - - - > 'explorer.exe'(1296)
c:\windows\system32\btmmhook.dll
.
Celkový čas: 2011-11-28 17:06:19
ComboFix-quarantined-files.txt 2011-11-28 16:06
ComboFix2.txt 2011-11-25 22:28
ComboFix3.txt 2011-11-24 22:28
ComboFix4.txt 2011-11-24 22:09
.
Před spuštěním: Volných bajtů: 16 386 908 160
Po spuštění: Volných bajtů: 19 623 153 664
.
- - End Of File - - EF4A0B653A882AB2071DF39EAD8477CD