DDS (Ver_09-12-01.01) - NTFSx86
Run by user at 13:45:32,26 on ne 27.12.2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.305 [GMT 1:00]
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: AVG *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\user\Plocha\dds.pif
============== Pseudo HJT Report ===============
uDefault_Search_URL = hxxp://
www.google.com
uStart Page = hxxp://
www.seznam.cz/
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
mURLSearchHooks: H - No File
TB: {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SDFix] c:\sdfix\RunThis.bat /second
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
TCP: {7E1B775D-FB9F-4945-8B6B-60D8BA4F52C7} = 10.1.1.1
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-27 64160]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-4-21 132808]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-2-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 55024]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-4-21 723632]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2008-4-14 69120]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 7408]
=============== Created Last 30 ================
2009-12-27 09:26:08 158 ----a-w- c:\windows\TSDataEx.ini
2009-12-24 07:16:01 0 d-----w- c:\documents and settings\user\DoctorWeb
2009-12-22 13:33:07 0 d-----w- c:\windows\ERUNT
2009-12-22 07:24:14 0 d-----w- c:\program files\ESET
2009-12-13 07:59:08 0 d-----w- c:\program files\Ares
2009-12-12 13:56:12 0 d-----w- C:\GTR2
2009-12-12 08:34:27 0 d-sh--w- c:\documents and settings\all users\DRM
2009-12-11 19:09:53 5466642 ----a-w- c:\windows\REGBK06.ZIP
2009-12-11 19:08:26 0 d---a-w- c:\windows\VDLL.DLL
2009-12-11 19:08:26 0 d-----w- c:\windows\RUNDL132.EXE
2009-12-06 17:26:07 0 d-----w- c:\docume~1\user\dataap~1\Thinstall
2009-11-28 17:37:51 0 d-----w- c:\program files\City Interactive
==================== Find3M ====================
2009-12-03 15:14:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13:56 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-18 09:41:21 171552 ----a-w- c:\windows\system32\guard32.dll
2009-11-18 09:41:20 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-11-18 09:41:20 132808 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-11-14 09:39:50 91866 ----a-w- c:\windows\system32\perfc005.dat
2009-11-14 09:39:50 469558 ----a-w- c:\windows\system32\perfh005.dat
2009-11-13 08:51:34 29512 ----a-w- c:\windows\system32\TURegOpt.exe
2009-10-25 05:11:34 77312 ----a-w- c:\windows\MBR.exe
2009-10-22 10:29:52 3773087 ----a-w- c:\windows\REGBK05.ZIP
2009-10-11 03:17:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-10 04:54:42 5073806 ----a-w- c:\windows\REGBK04.ZIP
2009-10-02 20:41:13 5067769 ----a-w- c:\windows\REGBK03.ZIP
============= FINISH: 13:46:27,89 ===============