ComboFix 10-04-27.04 - Steew 29.04.2010 15:18:14.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3326.2566 [GMT 2:00]
Spuštěný z: c:\users\Steew\Desktop\ComboFix.exe
AV: Eset NOD32 Antivirus 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-28 do 2010-04-29 )))))))))))))))))))))))))))))))
.
2010-04-29 13:26 . 2010-04-29 13:27 -------- d-----w- c:\users\Steew\AppData\Local\temp
2010-04-29 13:26 . 2010-04-29 13:26 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-04-29 13:26 . 2010-04-29 13:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-27 16:16 . 2010-04-27 16:16 -------- d-----w- c:\windows\AsDmiHtm
2010-04-27 16:15 . 2008-05-02 05:59 122368 ----a-w- c:\windows\system32\drivers\Rtlh86.sys
2010-04-27 16:15 . 2010-04-27 16:15 -------- d-----w- c:\users\Steew\AppData\Roaming\InstallShield
2010-04-21 13:20 . 2010-04-24 12:06 0 ----a-w- c:\windows\system32\Access.dat
2010-04-20 21:35 . 2010-04-20 21:35 -------- d-----w- c:\users\Steew\AppData\Roaming\Malwarebytes
2010-04-20 21:35 . 2010-03-29 22:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-20 21:35 . 2010-04-20 21:35 -------- d-----w- c:\programdata\Malwarebytes
2010-04-20 21:35 . 2010-03-29 22:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 21:35 . 2010-04-20 21:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 19:04 . 2010-04-19 19:04 -------- d-----w- c:\programdata\Media Center Programs
2010-04-19 16:26 . 2010-04-19 16:26 -------- d-----w- c:\program files\THQ
2010-04-18 14:35 . 2010-04-18 14:58 -------- d-----w- c:\users\Steew\AppData\Roaming\Tropico 3
2010-04-18 14:31 . 2010-04-18 15:00 -------- d-----w- c:\program files\Kalypso
2010-04-17 19:21 . 2010-04-17 19:21 -------- d-----w- c:\users\Steew\AppData\Local\GHISLER
2010-04-17 18:21 . 2010-04-17 18:21 -------- d-----w- C:\totalcmd
2010-04-17 18:21 . 2010-04-17 18:21 -------- d-----w- c:\users\Steew\AppData\Roaming\GHISLER
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\UC.PIF
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\RAR.PIF
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\PKZIP.PIF
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\LHA.PIF
2010-04-17 18:21 . 2009-09-24 05:50 545 ----a-w- c:\windows\ARJ.PIF
2010-04-17 11:57 . 2010-04-29 13:12 -------- d-----w- c:\users\Steew\AppData\Roaming\Tunngle
2010-04-17 11:57 . 2010-04-29 13:12 -------- d-----w- c:\programdata\Tunngle
2010-04-17 11:57 . 2009-09-16 05:02 27136 ----a-w- c:\windows\system32\drivers\tap0901t.sys
2010-04-17 11:56 . 2010-04-17 11:58 -------- d-----w- c:\program files\Tunngle
2010-04-17 11:46 . 2010-04-29 06:23 -------- d-----w- c:\users\Steew\AppData\Local\LogMeIn Hamachi
2010-04-17 11:44 . 2010-04-17 11:44 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-04-17 01:18 . 2010-04-17 01:18 -------- d-----w- c:\program files\Windows Portable Devices
2010-04-17 01:01 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-04-17 01:01 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-04-17 01:01 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-04-16 23:49 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-04-16 23:49 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-04-16 23:49 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-04-16 15:24 . 2010-04-16 15:26 -------- d-----w- c:\windows\system32\ca-ES
2010-04-16 15:24 . 2010-04-16 15:26 -------- d-----w- c:\windows\system32\eu-ES
2010-04-16 15:24 . 2010-04-16 15:26 -------- d-----w- c:\windows\system32\vi-VN
2010-04-16 15:20 . 2010-04-16 15:20 -------- d-----w- c:\windows\system32\SPReview
2010-04-16 15:09 . 2009-04-10 21:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2010-04-16 15:09 . 2009-04-10 21:27 57856 ----a-w- c:\windows\system32\compcln.exe
2010-04-16 15:02 . 2009-04-10 21:32 438744 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2010-04-16 14:38 . 2010-04-16 14:38 -------- d-----w- C:\3761acbd78d0957dbfbd5708fb09042d
2010-04-16 14:08 . 2010-04-16 14:08 -------- d-----w- c:\windows\system32\EventProviders
2010-04-14 10:56 . 2010-02-23 11:10 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 10:56 . 2010-02-23 11:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 10:56 . 2010-02-23 11:10 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 10:56 . 2010-02-18 14:07 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 10:56 . 2010-02-18 14:07 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 10:56 . 2010-03-04 17:33 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 10:55 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 10:55 . 2010-02-18 14:07 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 10:55 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 10:54 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 10:54 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-09 08:11 . 2010-04-10 16:24 -------- d-----w- c:\users\Steew\AppData\Roaming\ICQ
2010-04-09 08:10 . 2010-04-09 08:13 -------- d-----w- c:\program files\ICQ6.5
2010-04-04 14:40 . 2010-04-16 15:51 -------- d-----w- c:\program files\TeamSpeak 3 Client
2010-04-03 16:57 . 2010-04-03 16:57 -------- d-----w- c:\users\Steew\AppData\Local\Logitech
2010-04-03 16:57 . 2010-04-03 16:57 -------- d-----w- c:\programdata\Logitech
2010-04-03 16:57 . 2010-04-03 16:57 -------- d-----w- c:\program files\Logitech
2010-04-03 13:15 . 2010-04-03 13:27 -------- d-----w- c:\program files\UP 2.0n Full
2010-04-03 11:08 . 2010-04-03 14:06 -------- d-----w- c:\program files\Ubisoft
2010-04-03 09:53 . 2010-04-03 09:53 -------- d-----w- c:\users\Steew\AppData\Roaming\KWorld Multimedia
2010-04-03 09:52 . 2010-04-03 09:53 -------- d-----w- c:\program files\Genius TVGo DVB-T03
2010-04-03 09:52 . 2010-04-03 09:53 -------- d-----w- c:\temp\Uninstall
2010-04-03 09:52 . 2010-04-03 09:52 -------- d-----w- c:\program files\KWorld Multimedia
2010-04-03 09:51 . 2007-12-27 03:57 299008 ----a-w- c:\windows\afaunist.exe
2010-04-03 09:51 . 2007-10-26 17:26 224 ----a-w- c:\windows\system32\AF15IRTBL.bin
2010-04-03 09:51 . 2007-06-22 01:13 28672 ----a-w- c:\windows\system32\AF15BDAEX.dll
2010-04-03 09:51 . 2008-04-30 00:34 449408 ----a-w- c:\windows\system32\drivers\AF15BDA.sys
2010-04-03 09:51 . 2010-04-03 09:52 -------- d-----w- C:\Temp
2010-04-03 09:51 . 2010-04-03 09:51 -------- d-----w- c:\temp\Driver
2010-04-02 21:28 . 2010-04-02 22:44 -------- d-----w- c:\users\Steew\AppData\Roaming\TeamViewer
2010-04-02 21:27 . 2010-04-02 21:27 -------- d-----w- c:\program files\TeamViewer
2010-04-01 15:02 . 2010-04-01 15:02 -------- d-----w- c:\users\Steew\AppData\Local\PunkBuster
2010-04-01 14:52 . 2010-04-01 14:52 138056 ----a-w- c:\users\Steew\AppData\Roaming\PnkBstrK.sys
2010-04-01 14:47 . 2010-04-28 21:30 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-31 22:05 . 2010-04-28 21:29 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-03-31 13:02 . 2010-03-31 13:02 -------- d-----w- c:\users\Steew\AppData\Local\Ironclad Games
2010-03-31 11:48 . 2010-03-31 11:48 -------- d-----w- c:\programdata\Ironclad Games
2010-03-31 11:42 . 2010-03-31 11:42 -------- d-----w- c:\program files\Stardock
2010-03-31 10:35 . 2010-04-03 17:41 -------- d-----w- C:\Fraps
2010-03-30 22:21 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-03-30 22:20 . 2010-03-09 15:42 834048 ----a-w- c:\windows\system32\wininet.dll
2010-03-30 22:20 . 2010-03-09 16:25 78336 ----a-w- c:\windows\system32\ieencode.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-29 13:23 . 2008-01-21 06:46 598594 ----a-w- c:\windows\system32\perfh005.dat
2010-04-29 13:23 . 2008-01-21 06:46 114786 ----a-w- c:\windows\system32\perfc005.dat
2010-04-29 01:20 . 2010-03-26 17:09 -------- d-----w- c:\program files\Steam
2010-04-29 01:20 . 2010-03-26 17:09 -------- d-----w- c:\program files\Common Files\Steam
2010-04-28 22:02 . 2010-03-26 01:30 -------- d-----w- c:\users\Steew\AppData\Roaming\skypePM
2010-04-28 22:02 . 2010-03-26 01:30 -------- d-----w- c:\users\Steew\AppData\Roaming\Skype
2010-04-27 16:15 . 2010-03-26 14:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-21 13:42 . 2010-03-28 20:03 -------- d-----w- c:\users\Steew\AppData\Roaming\uTorrent
2010-04-20 21:59 . 2010-03-26 14:06 -------- d-----w- c:\program files\ASUS
2010-04-20 20:12 . 2010-03-26 21:20 -------- d-----w- c:\users\Steew\AppData\Roaming\FileZilla
2010-04-20 19:05 . 2010-03-26 00:02 -------- d-----w- c:\program files\ESET
2010-04-19 04:23 . 2010-03-26 13:40 55080 ----a-w- c:\users\Steew\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-17 01:18 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-04-17 01:18 . 2010-04-17 01:18 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-04-16 15:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-04-16 15:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-16 15:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-04-16 15:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-04-16 15:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-04-16 15:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-04-16 15:26 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-04-07 11:35 . 2010-04-07 11:35 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-04-04 16:12 . 2010-03-26 01:23 -------- d-----w- c:\users\Steew\AppData\Roaming\TS3Client
2010-04-02 11:10 . 2010-03-26 01:12 -------- d-----w- c:\program files\Miranda IM
2010-04-01 14:47 . 2010-03-27 10:30 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-04-01 14:44 . 2010-03-27 10:30 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-03-30 09:09 . 2010-03-30 09:09 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-30 09:09 . 2010-03-30 09:09 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-30 09:09 . 2010-03-30 09:09 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-30 09:09 . 2010-03-30 09:09 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-30 09:09 . 2010-03-30 09:09 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-30 09:09 . 2010-03-30 09:09 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-30 09:09 . 2010-03-30 09:09 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-30 09:09 . 2010-03-30 09:09 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-30 09:09 . 2010-03-30 09:09 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-03-30 09:09 . 2010-03-30 09:08 -------- d-----w- c:\program files\Common Files\Real
2010-03-30 09:08 . 2010-03-30 09:08 -------- d-----w- c:\program files\Real
2010-03-30 09:08 . 2010-03-30 09:08 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-30 09:08 . 2010-03-30 09:08 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-03-30 09:08 . 2010-03-30 09:08 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-03-30 01:17 . 2010-03-25 23:40 -------- d-----w- c:\programdata\NVIDIA
2010-03-28 21:41 . 2010-03-28 21:41 -------- d-----w- c:\program files\PowerISO
2010-03-28 21:09 . 2010-03-28 20:59 -------- d-----w- c:\users\Steew\AppData\Roaming\DAEMON Tools Lite
2010-03-28 21:05 . 2010-03-28 21:05 -------- d-----w- c:\users\Steew\AppData\Roaming\DAEMON Tools Pro
2010-03-28 21:05 . 2010-03-28 21:05 -------- d-----w- c:\users\Steew\AppData\Roaming\DAEMON Tools
2010-03-28 21:04 . 2010-03-28 21:04 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-03-28 21:04 . 2010-03-28 21:04 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-03-28 20:59 . 2010-03-28 20:59 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-28 20:52 . 2010-03-28 20:52 -------- d-----w- c:\users\Steew\AppData\Roaming\GameRanger
2010-03-28 20:08 . 2010-03-28 20:08 -------- d-----w- c:\program files\uTorrent
2010-03-28 10:54 . 2010-03-28 10:54 -------- d-----w- c:\program files\Microsoft.NET
2010-03-28 00:34 . 2010-03-28 00:34 -------- d-----w- c:\program files\Play+Smile
2010-03-27 22:57 . 2010-03-27 22:57 -------- d-----w- c:\program files\YomaTools
2010-03-27 18:38 . 2010-03-27 18:38 -------- d-----w- c:\program files\Bohemia Interactive
2010-03-27 10:23 . 2010-03-27 10:23 -------- d--h--r- c:\users\Steew\AppData\Roaming\SecuROM
2010-03-27 09:45 . 2010-03-27 09:45 -------- d-----w- c:\program files\Electronic Arts
2010-03-27 09:38 . 2010-03-27 01:08 -------- d-----w- c:\users\Steew\AppData\Roaming\BSplayer
2010-03-27 01:08 . 2010-03-27 01:08 -------- d-----w- c:\users\Steew\AppData\Roaming\BSplayer Pro
2010-03-27 01:07 . 2010-03-27 01:07 -------- d-----w- c:\program files\Webteh
2010-03-26 21:20 . 2010-03-26 21:20 -------- d-----w- c:\program files\FileZilla FTP Client
2010-03-26 20:08 . 2010-03-26 20:08 -------- d-----w- c:\users\Steew\AppData\Roaming\ArcSoft
2010-03-26 20:07 . 2010-03-26 20:07 -------- d-----w- c:\program files\Common Files\ArcSoft
2010-03-26 20:07 . 2010-03-26 20:07 -------- d-----w- c:\program files\ArcSoft
2010-03-26 20:05 . 2010-03-26 20:05 -------- d-----w- c:\program files\Common Files\PAC207
2010-03-26 20:05 . 2010-03-26 20:05 -------- d-----w- c:\program files\Trust
2010-03-26 19:08 . 2010-03-26 19:08 -------- d-----w- c:\program files\A4Tech
2010-03-26 14:02 . 2010-03-26 14:00 -------- d-----w- c:\program files\Realtek
2010-03-26 14:00 . 2010-03-26 14:00 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-03-26 14:00 . 2010-03-26 14:00 315392 ----a-w- c:\windows\HideWin.exe
2010-03-26 13:51 . 2010-03-26 13:51 -------- d-----w- c:\program files\Intel
2010-03-26 13:37 . 2010-03-26 13:37 -------- d-sh--we c:\programdata\Šablony
2010-03-26 13:37 . 2010-03-26 13:37 -------- d-sh--we c:\programdata\Plocha
2010-03-26 13:37 . 2010-03-26 13:37 -------- d-sh--we c:\programdata\Oblíbené položky
2010-03-26 13:37 . 2010-03-26 13:37 -------- d-sh--we c:\programdata\Nabídka Start
2010-03-26 13:37 . 2010-03-26 13:37 -------- d-sh--we c:\programdata\Dokumenty
2010-03-26 13:37 . 2010-03-26 13:37 -------- d-sh--we c:\programdata\Data aplikací
2010-03-26 01:30 . 2010-03-26 01:30 56 ---ha-w- c:\programdata\ezsidmv.dat
2010-03-26 01:29 . 2010-03-26 01:29 -------- d-----r- c:\program files\Skype
2010-03-26 01:29 . 2010-03-26 01:29 -------- d-----w- c:\program files\Common Files\Skype
2010-03-26 01:29 . 2010-03-26 01:29 -------- d-----w- c:\programdata\Skype
2010-03-26 01:20 . 2010-03-26 01:20 -------- d-----w- c:\programdata\boost_interprocess
2010-03-26 00:02 . 2010-03-26 00:04 512096 ----a-w- c:\windows\system32\drivers\amon.sys
2010-03-26 00:02 . 2010-03-26 00:04 298104 ----a-w- c:\windows\system32\imon.dll
2010-03-26 00:02 . 2010-03-26 00:04 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
2010-03-25 23:40 . 2010-03-25 23:35 -------- d-----w- c:\programdata\Comodo
2010-03-25 23:35 . 2010-03-25 23:35 74328 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-03-25 23:35 . 2010-03-25 23:35 29520 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-03-25 23:35 . 2010-03-25 23:35 171552 ----a-w- c:\windows\system32\guard32.dll
2010-03-25 23:35 . 2010-03-25 23:35 130960 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-03-25 23:35 . 2010-03-25 23:35 -------- d-----w- c:\program files\COMODO
2010-03-25 23:30 . 2010-03-25 23:30 -------- d-----w- c:\program files\My Company Name
2010-03-25 23:17 . 2010-03-26 13:59 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-25 23:11 . 2010-03-26 13:39 680 ----a-w- c:\users\Steew\AppData\Local\d3d9caps.dat
2010-03-22 13:52 . 2010-03-27 01:09 697690 ----a-w- c:\users\Steew\AppData\Roaming\BSplayer\AC3 Filter\unins000.exe
2010-02-24 08:16 . 2010-03-26 00:55 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 16:01 . 2010-03-27 01:09 1185871 ----a-w- c:\users\Steew\AppData\Roaming\BSplayer\FFDShow\unins000.exe
2010-02-23 15:00 . 2010-03-27 01:09 42288 ----a-w- c:\users\Steew\AppData\Roaming\BSplayer\Haali media splitter\uninstall.exe
2010-02-20 23:06 . 2010-03-26 18:56 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-26 18:56 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-26 18:56 411648 ----a-w- c:\windows\system32\drivers\http.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-10 2153472]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-04-06 26102056]
"Steam"="c:\program files\Steam\Steam.exe" [2010-04-26 1238352]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"Center Agent"="c:\program files\Genius TVGo DVB-T03\HyperMediaCenter\DTVR\Scheduled.exe" [2008-04-14 1519616]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 6144000]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-03-25 1800464]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2010-03-26 949376]
"WheelMouse"="c:\program files\A4Tech\Mouse\Amoumain.exe" [2007-05-15 204800]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-11 13527584]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-11 92704]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-30 202256]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
c:\users\Steew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Remote Control.lnk - c:\program files\Genius TVGo DVB-T03\Genius TVGo DVB-T03 Utilities\AFRCtl.exe [2010-4-3 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):41,15,14,61,7a,dd,ca,01
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-03-28 717296]
R3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-03-25 130960]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-03-25 29520]
S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2010-03-26 15424]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-02-11 172328]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [2010-03-23 704760]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\users\Steew\AppData\Roaming\Mozilla\Firefox\Profiles\9o57y87o.default\
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-29 15:27
Windows 6.0.6002 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-62988530-4219308771-1675412009-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:a2,02,85,26,5c,b4,96,38,16,05,72,6f,87,49,18,d8,ae,98,25,4b,60,c1,2e,
74,d3,3a,f0,64,01,5d,5a,0a,b7,c9,e8,37,dc,cb,dc,9d,13,6a,0a,96,c7,33,d5,fc,\
"??"=hex:d5,1a,22,f0,84,c1,52,33,85,a1,43,ea,fd,a0,56,c6
[HKEY_USERS\S-1-5-21-62988530-4219308771-1675412009-1000\Software\SecuROM\License information*]
"datasecu"=hex:87,1f,d6,84,17,c5,ff,83,15,01,d9,66,17,c6,f6,07,07,20,0e,2a,e1,
fe,2c,8a,ae,cb,75,87,eb,60,f9,3f,25,80,e2,12,fa,eb,70,5d,c9,2f,79,62,27,fd,\
"rkeysecu"=hex:08,28,4f,72,b3,a0,ba,fc,f5,79,91,8d,3b,fb,50,c5
.
Celkový čas: 2010-04-29 15:29:57
ComboFix-quarantined-files.txt 2010-04-29 13:29
ComboFix2.txt 2010-04-20 19:19
Před spuštěním: Volných bajtů: 104 731 684 864
Po spuštění: Volných bajtů: 104 755 425 280
- - End Of File - - 41C48451187C79EF3B5F649F7FDB273D