omboFix 10-05-13.03 - Honza Kryl 14.05.2010 18:20:47.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.509.216 [GMT 2:00]
Spuštěný z: c:\documents and settings\Honza Kryl\Plocha\ComboFix.exe
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - netcfgx.dll: deleted 100 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\program files\internet optimizer
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search2
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\recycled\Recycled
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\system32\VB40032.DLL
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-14 do 2010-05-14 )))))))))))))))))))))))))))))))
.
V tomto časovém úseku nebyly vytvořeny žádné nové soubory.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-14 14:40 . 2010-05-14 14:40 -------- d-----w- c:\program files\trend micro
2010-05-14 14:01 . 2002-02-19 15:43 62156 ----a-w- c:\windows\system32\perfc005.dat
2010-05-14 14:01 . 2002-02-19 15:43 379532 ----a-w- c:\windows\system32\perfh005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen 2.6"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2003-07-16 913408]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-08 1953792]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-03-13 19543592]
"Ashampoo PopUpBlocker"="c:\progra~1\Ashampoo\ASHAMP~1\PopUpKiller.exe" [2004-02-03 1216000]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-11-30 1306624]
"T-Mobile Communication Centre"="c:\program files\T-Mobile Communication Centre\Centre.exe" [2006-07-29 687163]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ICQ Lite"="c:\program files\ICQLite\ICQLite.exe" [2006-07-11 3144800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"nwiz"="nwiz.exe" [2005-02-24 1495040]
"SoundMan"="SOUNDMAN.EXE" [2003-02-27 47104]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2004-12-20 33792]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Media Access"="c:\program files\Media Access\MediaAccK.exe" [2005-05-07 20992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-10-21 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 36975]
"ICQ Lite"="c:\program files\ICQLite\ICQLite.exe" [2006-07-11 3144800]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"PrintPack dispatcher"="c:\program files\Software602\Print2PDF\PrnPack.exe" [2007-05-03 2759872]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-01 106496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\Honza Kryl\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ctfmon.exe [2006-6-27 20480]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2005-11-1 151552]
Picture Package VCD Maker.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2005-11-1 106496]
Software Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-6-14 180224]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ICQLite\\ICQLite.exe"=
"c:\\Documents and Settings\\Honza Kryl\\Dokumenty\\ICQ Lite\\263499798\\Jerrrrri_264668594\\INIC.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Documents and Settings\\Honza Kryl\\Plocha\\Usca2004.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\EA SPORTS\\NHL07\\nhl2007.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [27.12.2005 23:27 164992]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [27.12.2005 23:27 12544]
S1 vdrv8000;vdrv8000;c:\windows\system32\DRIVERS\vdrv8000.sys --> c:\windows\system32\DRIVERS\vdrv8000.sys [?]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe [1.3.2007 14:50 151552]
S3 GT43XX;GT Combo 802.11g Wireless LAN Adapter Driver GT43XX;c:\windows\system32\drivers\gtwl5.SYS [29.7.2006 11:18 266496]
S3 gtcdcmdm;GTRAN USB CDC Driver (PID 3196);c:\windows\system32\drivers\gtusbmdm_gpc6400.sys [25.3.2007 19:03 62035]
S3 GTEDGWModem;Option NV GTEDGWModem;c:\windows\system32\drivers\GTEDG.sys [29.7.2006 11:18 107904]
S3 GTEDGWWNIC;Option NV GTEDGWWNIC;c:\windows\system32\drivers\GTEDGNet.sys [29.7.2006 11:19 52864]
S3 OptionWWSC;GT Combo EDGE SIM Card Reader;c:\windows\system32\drivers\GTEDGSC.sys [29.7.2006 11:19 21888]
S3 TridDev;Trident Device;c:\windows\system32\drivers\Triddev.sys [2.1.2007 23:40 3584]
S3 tridhid;tridhid - USB 2.0 HID Driver;c:\windows\system32\drivers\tridhid.sys [2.1.2007 23:40 15488]
S3 TridVid;Trident USB TV;c:\windows\system32\drivers\TridVid.sys [2.1.2007 23:40 166912]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.11.2005 16:27 664064]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uInternet Connection Wizard,ShellNext = iexplore
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-pdfSaver3 - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-14 18:31
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-790525478-1343024091-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-790525478-1343024091-839522115-1003\Software\Zepter Software\RegLib*04448c82\CloneDVD/2]
"1"=dword:4450e051
"2"=dword:45ed4b31
[HKEY_USERS\S-1-5-21-790525478-1343024091-839522115-1003\Software\Zepter Software\RegLib*04448c82\CloneDVD2/2]
"1"=dword:4450e051
"2"=dword:45ed4b31
.
Celkový čas: 2010-05-14 18:39:19
ComboFix-quarantined-files.txt 2010-05-14 16:39
Před spuštěním: 8 793 952 256
Po spuštění: Volných bajtů: 12 764 684 288
- - End Of File - - 82503293CB840DDD31093E8B6E8514A9