hotovo :
ComboFix 10-12-21.01 - Honza 22.12.2010 9:45.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2047.1571 [GMT 1:00]
Spuštěný z: c:\documents and settings\Honza\Dokumenty\Stažené soubory\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Honza\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-11-22 do 2010-12-22 )))))))))))))))))))))))))))))))
.
2010-12-21 14:52 . 2010-12-21 14:52 -------- d-----w- c:\program files\IrfanView
2010-12-21 14:47 . 2001-10-24 11:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-12-21 14:47 . 2004-08-17 14:49 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-12-21 14:47 . 2004-08-03 21:58 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-12-21 14:47 . 2004-08-03 21:58 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-12-21 12:06 . 2010-12-22 08:33 -------- d-----w- c:\documents and settings\dočasný_2
2010-12-20 09:23 . 2010-12-20 09:23 -------- d-----w- c:\windows\system32\XPSViewer
2010-12-20 09:23 . 2010-12-20 09:23 -------- d-----w- c:\program files\MSBuild
2010-12-20 09:23 . 2010-12-20 09:23 -------- d-----w- c:\program files\Reference Assemblies
2010-12-20 09:22 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-12-20 09:22 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-12-20 09:22 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-12-20 09:22 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-12-20 09:22 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-12-20 09:22 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-12-20 09:22 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-12-20 09:22 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-12-20 09:22 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-12-20 09:22 . 2010-12-20 09:22 -------- d-----w- C:\c9893840080db0d91dff
2010-12-20 09:20 . 2010-12-20 09:20 -------- d-----w- c:\program files\MSXML 6.0
2010-12-19 15:32 . 2010-12-19 15:32 -------- d-----w- c:\documents and settings\Honza\Data aplikací\Stranger
2010-12-19 15:32 . 2010-12-19 15:32 278728 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-12-19 15:32 . 2010-12-19 15:32 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2010-12-19 15:31 . 2010-12-19 15:31 -------- d-----w- c:\program files\Stranger
2010-12-19 15:19 . 2010-12-19 15:20 -------- d-----w- C:\rsit
2010-12-19 15:19 . 2010-12-19 15:20 -------- d-----w- c:\program files\trend micro
2010-12-18 17:39 . 2010-12-18 17:39 -------- d-----w- c:\windows\ServicePackFiles
2010-12-18 16:25 . 2010-12-20 20:07 -------- d-----w- c:\program files\Metin2
2010-12-16 19:14 . 2010-12-21 19:30 -------- d-----w- c:\program files\Mijagi-MT2
2010-12-16 14:47 . 2010-12-16 14:47 -------- d--h--w- c:\windows\PIF
2010-12-16 13:21 . 2010-12-22 08:12 -------- d-----w- c:\documents and settings\Honza\Data aplikací\skypePM
2010-12-16 13:10 . 2010-12-16 13:10 -------- d-----w- c:\program files\Common Files\Skype
2010-12-16 13:10 . 2010-12-16 13:10 -------- d-----r- c:\program files\Skype
2010-12-16 13:10 . 2010-12-22 08:41 -------- d-----w- c:\documents and settings\Honza\Data aplikací\Skype
2010-12-16 13:10 . 2010-12-16 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2010-12-14 19:52 . 2010-12-15 08:29 -------- d-----w- c:\documents and settings\Honza\Data aplikací\DivX
2010-12-14 19:52 . 2010-07-12 18:36 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-12-14 19:52 . 2010-07-12 18:36 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-12-14 19:51 . 2010-12-14 19:51 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-12-14 19:50 . 2010-12-14 19:53 -------- d-----w- c:\program files\DivX
2010-12-14 19:49 . 2010-12-14 19:53 -------- d-----w- c:\documents and settings\All Users\Data aplikací\DivX
2010-12-14 15:50 . 2010-12-14 15:50 -------- d-----w- c:\windows\system32\xlive
2010-12-14 15:49 . 2010-12-14 15:50 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-12-10 13:43 . 2010-12-10 13:43 -------- d-----w- c:\program files\Gameforge4D
2010-12-10 09:33 . 2010-12-10 09:51 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-12-10 09:26 . 2010-02-24 12:31 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-12-10 09:25 . 2008-06-14 18:00 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-12-10 09:25 . 2008-06-14 18:00 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-12-10 09:22 . 2010-02-16 19:34 2060544 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-12-10 09:22 . 2010-02-16 19:34 2018816 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-12-10 09:22 . 2010-02-16 19:34 2183552 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-12-10 09:22 . 2010-02-16 19:34 2139136 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-12-10 09:20 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-12-10 09:14 . 2010-12-21 13:49 -------- d--h--w- c:\windows\$hf_mig$
2010-12-09 14:24 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-12-09 14:24 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-12-09 14:24 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-12-09 14:24 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-12-09 14:24 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-12-09 14:24 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-12-09 14:24 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-12-09 14:20 . 2010-12-09 14:20 -------- d-----w- C:\found.000
2010-12-09 14:15 . 2010-12-09 14:15 -------- d-----w- C:\625c07dd13026f9dd87eab
2010-12-09 14:15 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-12-09 14:15 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-12-09 14:15 . 2010-12-09 14:15 -------- d-----w- c:\program files\Alwil Software
2010-12-09 14:15 . 2010-12-09 14:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2010-12-07 14:35 . 2010-12-07 14:35 -------- d-----w- c:\windows\system32\E
2010-12-07 14:32 . 2010-12-10 16:13 -------- d-----w- c:\program files\Sindicate
2010-12-07 10:14 . 2010-12-10 13:55 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\Conduit
2010-12-07 10:14 . 2010-12-07 10:14 -------- d-----w- c:\program files\Conduit
2010-12-07 10:14 . 2010-12-10 13:55 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\BitTorrentBar
2010-12-07 10:13 . 2010-12-16 18:25 -------- d-----w- c:\documents and settings\Honza\Data aplikací\BitTorrent
2010-12-07 10:13 . 2010-12-07 11:28 -------- d-----w- c:\program files\BitTorrent
2010-12-06 18:32 . 2010-12-06 18:32 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\assembly
2010-12-06 18:32 . 2010-12-16 16:36 -------- d-----w- c:\program files\NCSoft
2010-12-06 15:52 . 2010-12-06 16:15 -------- d-----w- c:\program files\Cheat Engine
2010-12-06 15:52 . 2006-09-04 18:16 679936 ----a-w- c:\windows\system32\D3DX81ab.dll
2010-12-06 15:52 . 2006-09-04 18:16 1970176 ----a-w- c:\windows\system32\d3dx9.dll
2010-12-06 15:44 . 2010-12-06 15:44 -------- d-----w- c:\program files\BrotherSoft_Extreme
2010-12-06 15:43 . 2010-12-16 15:46 -------- d-----w- c:\documents and settings\Honza\Data aplikací\GetRightToGo
2010-12-04 22:24 . 2010-12-04 22:24 -------- d-----w- c:\program files\Common Files\DirectX
2010-12-04 22:23 . 2010-12-04 22:23 -------- d-----w- c:\windows\DD1865F0AD7340FBB23E1822E02396FF.TMP
2010-12-04 22:23 . 2010-12-04 22:23 -------- d-----w- c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
2010-12-04 22:23 . 2010-12-04 22:23 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-12-04 12:51 . 2010-12-04 12:51 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\2K Games
2010-12-03 11:42 . 2010-12-03 11:42 -------- d-----w- c:\program files\NVIDIA Corporation
2010-12-03 08:01 . 2010-12-03 08:01 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\Identities
2010-12-02 18:22 . 2010-12-02 18:22 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\AliensVsPredator
2010-12-02 18:18 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2010-12-02 18:18 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2010-12-02 18:18 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-12-02 18:18 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2010-12-02 18:14 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-12-02 18:14 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2010-12-02 18:14 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-12-02 17:36 . 2010-12-22 08:36 -------- d-----w- c:\program files\Steam
2010-12-01 17:44 . 2010-12-01 17:44 418480 ----a-w- c:\windows\system32\wrap_oal.dll
2010-12-01 17:44 . 2010-12-01 17:44 115432 ----a-w- c:\windows\system32\OpenAL32.dll
2010-12-01 17:44 . 2010-12-01 17:44 -------- d-----w- c:\program files\OpenAL
2010-12-01 17:36 . 2010-12-01 17:36 -------- d-----w- c:\program files\Evolved Games
2010-12-01 14:55 . 2010-12-01 15:10 -------- d-----w- c:\program files\Counter-Strike Source
2010-11-29 21:07 . 2010-11-29 21:07 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\Winamp Toolbar
2010-11-29 19:50 . 2010-11-29 19:50 -------- d-----w- c:\program files\Winamp Detect
2010-11-29 19:49 . 2010-11-29 19:49 -------- d-----w- c:\program files\Winamp Toolbar
2010-11-29 19:49 . 2010-11-29 19:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Winamp Toolbar
2010-11-29 19:49 . 2005-01-28 12:44 819200 ----a-w- c:\program files\Windows Media Player\wmsetsdk.exe
2010-11-29 19:49 . 2005-01-28 12:44 47616 ----a-w- c:\program files\Windows Media Player\msoobci.dll
2010-11-29 19:07 . 2010-11-29 19:07 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\WMTools Downloaded Files
2010-11-29 15:29 . 2010-11-29 15:29 -------- d-----w- c:\documents and settings\Honza\Data aplikací\Activision
2010-11-29 15:29 . 2010-11-29 15:29 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Activision
2010-11-29 15:12 . 2008-10-27 09:04 514384 ----a-w- c:\windows\system32\XAudio2_3.dll
2010-11-29 15:12 . 2008-10-27 09:04 70992 ----a-w- c:\windows\system32\XAPOFX1_2.dll
2010-11-29 15:12 . 2008-10-15 05:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2010-11-29 15:12 . 2008-10-15 05:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2010-11-29 15:12 . 2008-10-15 05:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2010-11-29 15:12 . 2008-10-27 09:04 235856 ----a-w- c:\windows\system32\xactengine3_3.dll
2010-11-29 15:12 . 2008-10-27 09:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2010-11-29 15:01 . 2010-11-29 15:01 -------- d-----w- c:\program files\Activision
2010-11-29 14:56 . 2010-11-29 14:56 -------- d-sh--w- c:\windows\ftpcache
2010-11-26 14:56 . 2010-11-26 14:56 -------- d-----w- c:\program files\VIA
2010-11-26 14:56 . 2007-04-11 14:35 331184 ------w- c:\windows\system32\difxapi.dll
2010-11-26 13:35 . 2010-12-15 12:40 -------- d-----w- c:\documents and settings\Honza\Local Settings\Data aplikací\Temp
2010-11-25 07:48 . 2010-11-25 07:48 -------- d-----w- c:\documents and settings\Honza\Data aplikací\Gearbox Software
2010-11-24 17:48 . 2010-11-24 17:48 -------- d-----w- c:\program files\Ubisoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-11-08 22:57 . 2010-11-08 22:57 353592 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
.
((((((((((((((((((((((((((((( SnapShot_2010-12-21_17.59.47 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-10-25 10:00 . 2010-12-21 16:26 67312 c:\windows\system32\perfc009.dat
+ 2001-10-25 10:00 . 2010-12-22 08:25 67312 c:\windows\system32\perfc009.dat
- 2001-10-25 10:00 . 2010-12-21 16:26 77872 c:\windows\system32\perfc005.dat
+ 2001-10-25 10:00 . 2010-12-22 08:25 77872 c:\windows\system32\perfc005.dat
+ 2001-10-25 10:00 . 2010-12-22 08:25 432356 c:\windows\system32\perfh009.dat
- 2001-10-25 10:00 . 2010-12-21 16:26 432356 c:\windows\system32\perfh009.dat
+ 2001-10-25 10:00 . 2010-12-22 08:25 428750 c:\windows\system32\perfh005.dat
- 2001-10-25 10:00 . 2010-12-21 16:26 428750 c:\windows\system32\perfh005.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2010-07-28 1267024]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-11-13 3913000]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-13 20:58 3913000 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2010-11-13 20:58 3913000 ----a-w- c:\program files\BitTorrentBar\tbBitT.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-11-13 3913000]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-11-13 3913000]
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-11-13 3913000]
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-11-23 3037696]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2010-11-23 323392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-11-23 39408]
"Steam"="c:\program files\Steam\steam.exe" [2010-12-02 1242448]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-11-23 2183680]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2010-07-12 74752]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"4StoryPrePatch"="c:\program files\Gameforge4D\4Story\PrePatch.exe" [2010-10-20 319488]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-12-08 1226608]
"DivX Download Manager"="c:\program files\DivX\DivX Plus Web Player\DDmService.exe" [2010-12-08 63360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\game.dat"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Spark Unlimited\\Legendary\\Binaries\\Legendary.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\Honza\\Dokumenty\\Stažené soubory\\PTR-Installer-4.0.0.12824-enGB-downloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Gearbox Software\\BrothersInArmsEiB\\System\\EiB.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Blizzard Downloader.exe"=
"c:\\Program Files\\Activision\\Transformers - Revenge of the Fallen\\Transformers2.exe"=
"c:\\Program Files\\Counter-Strike Source\\hl2.exe"=
"c:\\Program Files\\Evolved Games\\Terminator Salvation\\TerminatorSalvation.exe"=
"c:\\Documents and Settings\\Honza\\Plocha\\War3\\Warcraft III.exe"=
"c:\\Documents and Settings\\Honza\\Plocha\\War3\\War3.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Sindicate\\client.bin"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Documents and Settings\\Honza\\Plocha\\United\\Metin2client.bin"=
"c:\\Program Files\\Steam\\steamapps\\common\\overlord ii - demo\\Overlord2Demo.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\overlord ii - demo\\Config.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\mafia ii - public demo\\launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_Launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP_DX11.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\aliens vs predator\\AvP.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war ii - spd\\DOW2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Mijagi-MT2\\metin2client.bin"=
"c:\\Program Files\\Metin2\\metin2client.bin"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.12.2010 15:24 165584]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [23.11.2010 17:54 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.12.2010 15:24 17744]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.11.2010 17:30 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [23.11.2010 17:50 1684736]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Obsah adresáře 'Naplánované úlohy'
2010-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-23 16:30]
2010-12-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-23 16:30]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.crawler.com/homepage.aspx?tbid=60342
uSearch Page = hxxp://
www.google.com
uSearch Bar = hxxp://
www.google.com/ie
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Crawler Search - tbr:iemenu
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Honza\Data aplikací\Mozilla\Firefox\Profiles\9ix6yozr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2790392&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension: {AB2CE124-6272-4b12-94A9-7303C7397BD1} - c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - c:\program files\Crawler\Toolbar\firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: BrotherSoft Extreme Community Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - %profile%\extensions\{51a86bb3-6602-4c85-92a5-130ee4864f13}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\
engine@conduit.com
FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - %profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-22 09:48
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-789336058-484763869-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:3c,a2,a0,9c,b9,8c,02,06,3e,c5,6e,3b,8f,a1,05,d3,8d,06,a0,a3,61,
13,a6,25,10,de,c7,b0,e5,d3,21,68,ec,ff,0d,49,da,9e,2b,b8,d4,56,4c,d4,9e,fa,\
"rkeysecu"=hex:9a,32,12,2a,ac,f8,0a,a1,62,bf,3a,c9,08,b4,e5,62
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(924)
c:\windows\system32\msi.dll
.
Celkový čas: 2010-12-22 09:49:20
ComboFix-quarantined-files.txt 2010-12-22 08:49
ComboFix2.txt 2010-12-21 18:00
ComboFix3.txt 2010-12-19 18:35
ComboFix4.txt 2010-12-19 17:14
Před spuštěním: Volných bajtů: 98 735 431 680
Po spuštění: Volných bajtů: 98 723 127 296
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 760C013E25E54478C4EF8022BC999C06