Re: qooqlle - nechtěná domovská stránka
Napsal: 12 lis 2010 17:57
OK, AVG jsem odinstaloval, provedl log a dal zpět
)).
ComboFix 10-11-11.02 - Karel 12.11.2010 17:39:49.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2700 [GMT 1:00]
Spuštěný z: c:\documents and settings\Karel\Plocha\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\pthreadVC.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-10-12 do 2010-11-12 )))))))))))))))))))))))))))))))
.
2010-11-10 21:21 . 2010-11-10 21:21 -------- d-----w- c:\documents and settings\Karel\Local Settings\Data aplikací\Unity
2010-11-08 17:12 . 2010-11-08 17:12 -------- d-----w- C:\rsit
2010-11-08 11:55 . 2010-11-08 11:55 388096 ----a-r- c:\documents and settings\Karel\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-08 11:55 . 2010-11-10 14:02 -------- d-----w- c:\program files\Trend Micro
2010-11-08 06:47 . 2010-11-08 06:47 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-11-08 06:43 . 2010-11-08 11:39 350769 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-11-08 06:39 . 2010-11-08 11:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Comodo
2010-11-07 22:07 . 2010-11-08 11:40 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-11-07 22:07 . 2010-11-08 11:35 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-11-07 19:40 . 2010-11-07 19:40 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-11-06 07:49 . 2010-11-06 07:50 -------- d-----w- c:\documents and settings\Karel\Data aplikací\DivX
2010-11-06 07:49 . 2010-07-12 18:36 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-11-06 07:49 . 2010-07-12 18:36 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-11-06 07:47 . 2010-11-07 22:14 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DivX
2010-11-06 07:47 . 2010-11-06 07:47 6782976 ----a-w- c:\documents and settings\Karel\Data aplikací\igfxtray.exe
2010-10-29 13:56 . 2010-10-29 13:56 -------- d-----w- c:\documents and settings\Karel\Local Settings\Data aplikací\AVG Security Toolbar
2010-10-26 11:56 . 2010-10-26 11:56 -------- d-----w- c:\documents and settings\LocalService\Nabídka Start
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2007-04-03 06:44 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 06:51 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 06:51 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 06:53 . 2001-10-25 13:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-10 05:52 . 2008-12-18 09:52 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2008-12-18 09:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:52 . 2008-12-18 09:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:52 . 2008-04-14 06:37 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:57 . 2008-04-14 05:45 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:03 . 2008-04-14 06:52 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:54 . 2008-04-14 06:52 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 06:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-04-13 22:45 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 03:33 . 2010-02-05 18:48 5386752 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-08-26 02:12 . 2010-02-05 18:48 57344 ----a-w- c:\windows\system32\aticalrt.dll
2010-08-26 02:11 . 2010-02-05 18:48 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-08-26 02:10 . 2010-02-05 18:48 4390912 ----a-w- c:\windows\system32\aticaldd.dll
2010-08-26 02:03 . 2010-02-05 18:48 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-08-26 02:01 . 2010-02-05 18:48 15876096 ----a-w- c:\windows\system32\atioglxx.dll
2010-08-26 01:57 . 2010-02-05 18:48 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-08-26 01:56 . 2010-02-05 18:48 300544 ----a-w- c:\windows\system32\ati2dvag.dll
2010-08-26 01:52 . 2010-02-05 18:48 3927936 ----a-w- c:\windows\system32\ati3duag.dll
2010-08-26 01:39 . 2010-02-05 18:48 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-08-26 01:39 . 2010-02-05 18:48 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-08-26 01:38 . 2010-02-05 18:48 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-08-26 01:38 . 2010-02-05 18:48 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-08-26 01:38 . 2010-02-05 18:48 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-08-26 01:37 . 2010-02-05 18:48 2603520 ----a-w- c:\windows\system32\ativvaxx.dll
2010-08-26 01:37 . 2010-02-05 18:48 606208 ----a-w- c:\windows\system32\ati2evxx.exe
2010-08-26 01:35 . 2010-02-05 18:48 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-08-26 01:34 . 2010-10-06 19:14 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-08-26 01:30 . 2010-02-05 18:48 626688 ----a-w- c:\windows\system32\atikvmag.dll
2010-08-26 01:30 . 2010-02-05 18:48 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-08-26 01:29 . 2010-02-05 18:48 188416 ----a-w- c:\windows\system32\atiadlxx.dll
2010-08-26 01:28 . 2010-02-05 18:48 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-08-26 01:23 . 2010-02-05 18:48 688128 ----a-w- c:\windows\system32\ati2cqag.dll
2010-08-26 01:22 . 2010-02-05 18:48 64512 ----a-w- c:\windows\system32\atimpc32.dll
2010-08-26 01:22 . 2010-02-05 18:48 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2010-08-26 01:21 . 2010-02-05 18:48 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-08-23 16:12 . 2008-04-14 06:51 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-04-14 06:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2008-04-14 06:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
.
------- Sigcheck -------
[-] 2008-12-18 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-25 98304]
"IgfxTraySound"="c:\documents and settings\Karel\Data aplikací\igfxtray.exe" [2010-11-06 6782976]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-5 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0oodbs
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-10-06 19:27 1242448 ----a-w- c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
2005-07-28 07:32 94208 ------w- c:\program files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Calendar Checker]
2005-08-22 08:10 69632 ----a-w- c:\program files\Ulead Systems\Ulead Photo Express 6\CalCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"k:\\Programy\\Strong DC 2.40\\StrongDC.exe"=
"c:\\Totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\moon base alpha\\Binaries\\Win32\\MoonBaseAlphaGame.exe"=
"e:\\Hry\\StarCraft II\\StarCraft II.exe"=
"e:\\Hry\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5.2.2010 20:13 691696]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [7.10.2008 20:31 61424]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [5.2.2010 20:27 344064]
R2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [5.2.2010 20:27 405504]
R2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [5.2.2010 19:32 212232]
R3 AVerA706;AVerMedia A706 BDA Service;c:\windows\system32\drivers\AVerA706.sys [5.2.2010 20:27 1169920]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15.8.2008 5:46 284016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5.2.2010 19:32 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.qooqlle.com/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WEBIE.DLL
TCP: {82FB2278-B20F-4DF9-9D1C-A45CE1DFE6AA} = 192.168.1.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\documents and settings\Karel\Data aplikací\Mozilla\Firefox\Profiles\g4m4jwa5.default\
FF - prefs.js: browser.search.selectedEngine - qooqlle
FF - prefs.js: browser.startup.homepage - hxxp://www.qooqlle.com/
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 9666
FF - prefs.js: network.proxy.gopher - 127.0.0.1
FF - prefs.js: network.proxy.gopher_port - 9666
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 9666
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9666
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 9666
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\XStandard\Bin\NPXStandard.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-AdobeBridge - (no file)
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
AddRemove-UnityWebPlayer - c:\documents and settings\Karel\Local Settings\Data aplikací\Unity\WebPlayer\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-12 17:41
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="CC90383C0FC5E2944214E6CAA370970A07B045B11D82E2A998D264AD590E0F8FA9D06CCC1B84965EA56C0E9590A65812BCAA057BE93E692100752A2A00AA67FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA6A0AC4980AC7933A6171C11EC38DE3D3149C658C22FFAD0209D91A7B187D911A250C5BC18B26470A9E35EA16B09D75C0587DD941BD1BF210BB77618516088B87E67FC1796D0D84358C42D1830CC3D755303BDFBDCE1292ACE3A46D55F683FF97B59F348D1796DE9619D0CFB54755D9D2DA6419E811BAE2AD014D879362C016CF3B22090AA285574B33C2DD4618E36FE38A2F76CD4B7B9830C753BFB06B744C856472B11585B3216D435F71130A838662C6D25BA757827BB10532DBCD61D756F272DF0D3E2949DA65B5F067EEFD5C845D7BC4143D8A34A7C7BE723FC7E717263FD3D0541A8DBA223F2D4A55324AFBEAF9C0DF6234581691409AE45E3AC4E8ECA85962DAB5A3AC12ADE755BA7A2D0E95FEE9F27DB57DD3EF4806A727BDE5311717D1BE04480406F81F0645B7616D80AB0D8F76353FE0AF5B3BF9FB8B2EB9FB4C5B8F04FA4727F920F938911227DEBD4A3F5DD74D27FD9B38ABA175E5CFAD928599D815946DE0F87DFC08E9B6EACB072DE795ED40771A60DD876DD59AC0B2C8F65A87C1589C7089FA289E3CC0349D380AA28483501BECC8B1F0EC5D8406B440144E8D3CBB1820C9D2D12BCAA6DCE0410F3DA31F838A8ADAE822F643D15C0D287F3023CF965B9BA3976140F701D0CF526CA00EFB604C2AD674F1C11198C050DA197AAB1D131693D2019D9160D662260BAE497223B2375341B712BEA366E042F4476AD703A8364BC70D64552A2828900BB1BB62785B57BAEA5FA47D212E45FF3D47B6BFBCA30D0673F134906088D0D140B6A872348C2E48F5323EDEC5B7C8A9FAFB4D61AD26E287194556F384687CA5FFB73477DECB21548E6C2322277A9CEF5A156F6D4D15AB8106BC953B49D55B52B59FA47630CD2C45495D739A07EC2C9C0F03767FA7F73A2003540A40B01BF94415EEA6B45F8D47F2F0B84BDD93E816B4E51D0D61E439BDDFC56ACA88C95F102F23DCE2F57B3CCA458648F10023604F870EFC20A133C1C32CC25A63751B5FDEC921BD71E8FF5B6E75634E00E929A4D8A7CEA515676BA1EBEB26EEA3DB470D598788F5C5AADAAEE5231FE8732C8D3430DCB55E0A7A545B3F3FCF1593A5688D49B01A9D219AEF136BDF4403585A50031423CB6FEFC4214CD99776474C11873B4DF8AE9DA23D71D32DA3266C0256F6E443EAF89D86BB296C5C7F56DE47DA25E18A57843B3D63236EB2D00D022C32D248FE98B3DC018A1EDD5ECCEA8F7A95FA4827E342141240878510E74D879A8AC588A013934AF3F"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Celkový čas: 2010-11-12 17:42:54
ComboFix-quarantined-files.txt 2010-11-12 16:42
Před spuštěním: Volných bajtů: 185 776 160 768
Po spuštění: Volných bajtů: 185 808 961 536
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT /usepmtimer
- - End Of File - - 1BB3E58021213B36067DBC5722A27CAE

ComboFix 10-11-11.02 - Karel 12.11.2010 17:39:49.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3326.2700 [GMT 1:00]
Spuštěný z: c:\documents and settings\Karel\Plocha\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\pthreadVC.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-10-12 do 2010-11-12 )))))))))))))))))))))))))))))))
.
2010-11-10 21:21 . 2010-11-10 21:21 -------- d-----w- c:\documents and settings\Karel\Local Settings\Data aplikací\Unity
2010-11-08 17:12 . 2010-11-08 17:12 -------- d-----w- C:\rsit
2010-11-08 11:55 . 2010-11-08 11:55 388096 ----a-r- c:\documents and settings\Karel\Data aplikací\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-08 11:55 . 2010-11-10 14:02 -------- d-----w- c:\program files\Trend Micro
2010-11-08 06:47 . 2010-11-08 06:47 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-11-08 06:43 . 2010-11-08 11:39 350769 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-11-08 06:39 . 2010-11-08 11:34 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Comodo
2010-11-07 22:07 . 2010-11-08 11:40 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-11-07 22:07 . 2010-11-08 11:35 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-11-07 19:40 . 2010-11-07 19:40 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-11-06 07:49 . 2010-11-06 07:50 -------- d-----w- c:\documents and settings\Karel\Data aplikací\DivX
2010-11-06 07:49 . 2010-07-12 18:36 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-11-06 07:49 . 2010-07-12 18:36 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-11-06 07:47 . 2010-11-07 22:14 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DivX
2010-11-06 07:47 . 2010-11-06 07:47 6782976 ----a-w- c:\documents and settings\Karel\Data aplikací\igfxtray.exe
2010-10-29 13:56 . 2010-10-29 13:56 -------- d-----w- c:\documents and settings\Karel\Local Settings\Data aplikací\AVG Security Toolbar
2010-10-26 11:56 . 2010-10-26 11:56 -------- d-----w- c:\documents and settings\LocalService\Nabídka Start
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2007-04-03 06:44 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 06:51 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 06:51 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 06:53 . 2001-10-25 13:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-10 05:52 . 2008-12-18 09:52 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2008-12-18 09:52 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:52 . 2008-12-18 09:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:52 . 2008-04-14 06:37 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:57 . 2008-04-14 05:45 1852800 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:03 . 2008-04-14 06:52 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:54 . 2008-04-14 06:52 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 06:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-04-13 22:45 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 03:33 . 2010-02-05 18:48 5386752 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-08-26 02:12 . 2010-02-05 18:48 57344 ----a-w- c:\windows\system32\aticalrt.dll
2010-08-26 02:11 . 2010-02-05 18:48 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-08-26 02:10 . 2010-02-05 18:48 4390912 ----a-w- c:\windows\system32\aticaldd.dll
2010-08-26 02:03 . 2010-02-05 18:48 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-08-26 02:01 . 2010-02-05 18:48 15876096 ----a-w- c:\windows\system32\atioglxx.dll
2010-08-26 01:57 . 2010-02-05 18:48 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-08-26 01:56 . 2010-02-05 18:48 300544 ----a-w- c:\windows\system32\ati2dvag.dll
2010-08-26 01:52 . 2010-02-05 18:48 3927936 ----a-w- c:\windows\system32\ati3duag.dll
2010-08-26 01:39 . 2010-02-05 18:48 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-08-26 01:39 . 2010-02-05 18:48 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-08-26 01:38 . 2010-02-05 18:48 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-08-26 01:38 . 2010-02-05 18:48 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-08-26 01:38 . 2010-02-05 18:48 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-08-26 01:37 . 2010-02-05 18:48 2603520 ----a-w- c:\windows\system32\ativvaxx.dll
2010-08-26 01:37 . 2010-02-05 18:48 606208 ----a-w- c:\windows\system32\ati2evxx.exe
2010-08-26 01:35 . 2010-02-05 18:48 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-08-26 01:34 . 2010-10-06 19:14 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-08-26 01:30 . 2010-02-05 18:48 626688 ----a-w- c:\windows\system32\atikvmag.dll
2010-08-26 01:30 . 2010-02-05 18:48 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-08-26 01:29 . 2010-02-05 18:48 188416 ----a-w- c:\windows\system32\atiadlxx.dll
2010-08-26 01:28 . 2010-02-05 18:48 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-08-26 01:23 . 2010-02-05 18:48 688128 ----a-w- c:\windows\system32\ati2cqag.dll
2010-08-26 01:22 . 2010-02-05 18:48 64512 ----a-w- c:\windows\system32\atimpc32.dll
2010-08-26 01:22 . 2010-02-05 18:48 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2010-08-26 01:21 . 2010-02-05 18:48 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-08-23 16:12 . 2008-04-14 06:51 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-04-14 06:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2008-04-14 06:51 590848 ----a-w- c:\windows\system32\rpcrt4.dll
.
------- Sigcheck -------
[-] 2008-12-18 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-25 98304]
"IgfxTraySound"="c:\documents and settings\Karel\Data aplikací\igfxtray.exe" [2010-11-06 6782976]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-2-5 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0oodbs
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-10-06 19:27 1242448 ----a-w- c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
2005-07-28 07:32 94208 ------w- c:\program files\Common Files\Ulead Systems\AutoDetector\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Calendar Checker]
2005-08-22 08:10 69632 ----a-w- c:\program files\Ulead Systems\Ulead Photo Express 6\CalCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"k:\\Programy\\Strong DC 2.40\\StrongDC.exe"=
"c:\\Totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\moon base alpha\\Binaries\\Win32\\MoonBaseAlphaGame.exe"=
"e:\\Hry\\StarCraft II\\StarCraft II.exe"=
"e:\\Hry\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5.2.2010 20:13 691696]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [7.10.2008 20:31 61424]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [5.2.2010 20:27 344064]
R2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [5.2.2010 20:27 405504]
R2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [5.2.2010 19:32 212232]
R3 AVerA706;AVerMedia A706 BDA Service;c:\windows\system32\drivers\AVerA706.sys [5.2.2010 20:27 1169920]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15.8.2008 5:46 284016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5.2.2010 19:32 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.qooqlle.com/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\translat\WEBIE.DLL
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\translat\WEBIE.DLL
TCP: {82FB2278-B20F-4DF9-9D1C-A45CE1DFE6AA} = 192.168.1.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\documents and settings\Karel\Data aplikací\Mozilla\Firefox\Profiles\g4m4jwa5.default\
FF - prefs.js: browser.search.selectedEngine - qooqlle
FF - prefs.js: browser.startup.homepage - hxxp://www.qooqlle.com/
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 9666
FF - prefs.js: network.proxy.gopher - 127.0.0.1
FF - prefs.js: network.proxy.gopher_port - 9666
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 9666
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 9666
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 9666
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\XStandard\Bin\NPXStandard.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-AdobeBridge - (no file)
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
AddRemove-UnityWebPlayer - c:\documents and settings\Karel\Local Settings\Data aplikací\Unity\WebPlayer\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-12 17:41
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="CC90383C0FC5E2944214E6CAA370970A07B045B11D82E2A998D264AD590E0F8FA9D06CCC1B84965EA56C0E9590A65812BCAA057BE93E692100752A2A00AA67FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA6A0AC4980AC7933A6171C11EC38DE3D3149C658C22FFAD0209D91A7B187D911A250C5BC18B26470A9E35EA16B09D75C0587DD941BD1BF210BB77618516088B87E67FC1796D0D84358C42D1830CC3D755303BDFBDCE1292ACE3A46D55F683FF97B59F348D1796DE9619D0CFB54755D9D2DA6419E811BAE2AD014D879362C016CF3B22090AA285574B33C2DD4618E36FE38A2F76CD4B7B9830C753BFB06B744C856472B11585B3216D435F71130A838662C6D25BA757827BB10532DBCD61D756F272DF0D3E2949DA65B5F067EEFD5C845D7BC4143D8A34A7C7BE723FC7E717263FD3D0541A8DBA223F2D4A55324AFBEAF9C0DF6234581691409AE45E3AC4E8ECA85962DAB5A3AC12ADE755BA7A2D0E95FEE9F27DB57DD3EF4806A727BDE5311717D1BE04480406F81F0645B7616D80AB0D8F76353FE0AF5B3BF9FB8B2EB9FB4C5B8F04FA4727F920F938911227DEBD4A3F5DD74D27FD9B38ABA175E5CFAD928599D815946DE0F87DFC08E9B6EACB072DE795ED40771A60DD876DD59AC0B2C8F65A87C1589C7089FA289E3CC0349D380AA28483501BECC8B1F0EC5D8406B440144E8D3CBB1820C9D2D12BCAA6DCE0410F3DA31F838A8ADAE822F643D15C0D287F3023CF965B9BA3976140F701D0CF526CA00EFB604C2AD674F1C11198C050DA197AAB1D131693D2019D9160D662260BAE497223B2375341B712BEA366E042F4476AD703A8364BC70D64552A2828900BB1BB62785B57BAEA5FA47D212E45FF3D47B6BFBCA30D0673F134906088D0D140B6A872348C2E48F5323EDEC5B7C8A9FAFB4D61AD26E287194556F384687CA5FFB73477DECB21548E6C2322277A9CEF5A156F6D4D15AB8106BC953B49D55B52B59FA47630CD2C45495D739A07EC2C9C0F03767FA7F73A2003540A40B01BF94415EEA6B45F8D47F2F0B84BDD93E816B4E51D0D61E439BDDFC56ACA88C95F102F23DCE2F57B3CCA458648F10023604F870EFC20A133C1C32CC25A63751B5FDEC921BD71E8FF5B6E75634E00E929A4D8A7CEA515676BA1EBEB26EEA3DB470D598788F5C5AADAAEE5231FE8732C8D3430DCB55E0A7A545B3F3FCF1593A5688D49B01A9D219AEF136BDF4403585A50031423CB6FEFC4214CD99776474C11873B4DF8AE9DA23D71D32DA3266C0256F6E443EAF89D86BB296C5C7F56DE47DA25E18A57843B3D63236EB2D00D022C32D248FE98B3DC018A1EDD5ECCEA8F7A95FA4827E342141240878510E74D879A8AC588A013934AF3F"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Celkový čas: 2010-11-12 17:42:54
ComboFix-quarantined-files.txt 2010-11-12 16:42
Před spuštěním: Volných bajtů: 185 776 160 768
Po spuštění: Volných bajtů: 185 808 961 536
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /NOEXECUTE=OPTIN /FASTDETECT /usepmtimer
- - End Of File - - 1BB3E58021213B36067DBC5722A27CAE