Re: prosím o kontrolu logu při najetí se restartuje......
Napsal: 11 úno 2011 09:54
ComboFix 11-02-08.03 - Peťa 11.02.2011 9:36.3.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.330 [GMT 1:00]
Spuštěný z: c:\documents and settings\Peťa\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Peťa\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\SMILEY~2
c:\progra~1\SMILEY~2\bar\1.bin\1vbar.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vbarsvc.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vdatact.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vdyn.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vfeedmg.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vhighin.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vhtml.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vhtmlmu.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vhttpct.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vidle.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vimpipe.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vmedint.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vmlbtn.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vmsg.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vPlugin.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vradio.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vregfft.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vscript.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vskin.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vskplay.exe
c:\progra~1\SMILEY~2\bar\1.bin\CHROME.MANIFEST
c:\progra~1\SMILEY~2\bar\1.bin\chrome\1vffxtbr.jar
c:\progra~1\SMILEY~2\bar\1.bin\INSTALL.RDF
c:\progra~1\SMILEY~2\bar\1.bin\LOGO.BMP
c:\progra~1\SMILEY~2\bar\1.bin\NP1vStub.dll
c:\progra~1\SMILEY~2\bar\Cache\0003E4A4
c:\progra~1\SMILEY~2\bar\Cache\00065873.bmp
c:\progra~1\SMILEY~2\bar\Cache\00065EEB.bmp
c:\progra~1\SMILEY~2\bar\Cache\00066266.bmp
c:\progra~1\SMILEY~2\bar\Cache\0006641B.bmp
c:\progra~1\SMILEY~2\bar\Cache\00067717.bmp
c:\progra~1\SMILEY~2\bar\Cache\00067B6C.bmp
c:\progra~1\SMILEY~2\bar\Cache\00067E4A.bin
c:\progra~1\SMILEY~2\bar\Cache\files.ini
c:\progra~1\SMILEY~2\bar\History\search3
c:\progra~1\SMILEY~2\bar\Message\COMMON.T8S
c:\progra~1\SMILEY~2\bar\Settings\prevcfg2.htm
c:\progra~1\SMILEY~2\bar\Settings\s_pid.dat
c:\windows\system32\drivers\cbufr.sys
Nakažená kopie c:\windows\system32\drivers\aec.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\aec.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SMILEYCENTRAL_1VSERVICE
-------\Service_SmileyCentral_1vService
-------\Service_doxtn
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-11 do 2011-02-11 )))))))))))))))))))))))))))))))
.
2011-02-11 07:32 . 2011-02-11 07:32 739328 ----a-w- c:\windows\system32\drivers\dthetjg.sys
2011-02-10 06:59 . 2011-02-10 06:59 739328 ----a-w- c:\windows\system32\drivers\qbrddsnx.sys
2011-02-10 06:58 . 2011-02-10 06:58 739328 ----a-w- c:\windows\system32\drivers\sjxwo.sys
2011-02-09 21:23 . 2011-02-09 21:23 739328 ----a-w- c:\windows\system32\drivers\rfipy.sys
2011-02-09 21:00 . 2011-02-09 21:00 -------- d-----w- C:\_OTL
2011-02-09 11:34 . 2011-02-09 11:34 739328 ----a-w- c:\windows\system32\drivers\vjttyjapf.sys
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- c:\program files\trend micro
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- C:\rsit
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2011-02-09 21:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 11:07 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-08 11:06 . 2011-02-10 07:11 -------- d-----w- c:\program files\Yahoo!
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\CCleaner
2011-01-29 21:13 . 2011-01-31 13:32 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\skypePM
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----w- c:\program files\Common Files\Skype
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----r- c:\program files\Skype
2011-01-29 21:07 . 2011-01-31 20:38 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Skype
2011-01-29 21:06 . 2011-01-29 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-01-25 17:22 . 2011-01-25 17:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-01-25 17:18 . 2011-01-25 17:18 -------- d-----w- c:\program files\Microsoft WSE
2011-01-25 16:48 . 2011-01-25 16:48 -------- d-----w- c:\program files\Electronic Arts
2011-01-18 12:40 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-16 20:27 . 2011-01-16 20:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-26 21:34 . 2007-08-02 12:00 29392 ----a-w- c:\windows\system32\drivers\secdrv.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-08-02 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=""
[HKLM\~\startupfolder\C:^Documents and Settings^Peťa^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Peťa\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2009-02-06 12:23 2021400 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 13:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-03 14:44 15028104 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-09-27 16:16 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Documents and Settings\\Peťa\\Plocha\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.8.2010 13:35 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 13:23 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 13:24 93336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 13:23 727720]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.8.2010 11:18 246520]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.9.2010 17:13 136176]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-02-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-30 20:18]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FDCB521-35A7-4342-A0C7-1194C9EBB954} = 192.168.150.237,194.228.2.1
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb002YYCZ_ZNzfb014&ptb=7C552DF5-D873-46DD-BDA3-3CC277730C7F&psa=&ind=2010111304&ptnrS=ZNzfb002YYCZ_ZNzfb014&si=&st=kwd&n=77cfdd48&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-11 09:46
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1936)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Celkový čas: 2011-02-11 09:51:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-11 08:51
ComboFix2.txt 2011-02-09 11:28
ComboFix3.txt 2011-02-09 08:31
Před spuštěním: 1 949 245 440
Po spuštění: 1 934 323 712
- - End Of File - - C0269DFE4419D93C44C9191826E41D87
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.330 [GMT 1:00]
Spuštěný z: c:\documents and settings\Peťa\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Peťa\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\SMILEY~2
c:\progra~1\SMILEY~2\bar\1.bin\1vbar.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vbarsvc.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vdatact.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vdyn.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vfeedmg.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vhighin.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vhtml.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vhtmlmu.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vhttpct.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vidle.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vimpipe.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vmedint.exe
c:\progra~1\SMILEY~2\bar\1.bin\1vmlbtn.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vmsg.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vPlugin.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vradio.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vregfft.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vscript.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vskin.dll
c:\progra~1\SMILEY~2\bar\1.bin\1vskplay.exe
c:\progra~1\SMILEY~2\bar\1.bin\CHROME.MANIFEST
c:\progra~1\SMILEY~2\bar\1.bin\chrome\1vffxtbr.jar
c:\progra~1\SMILEY~2\bar\1.bin\INSTALL.RDF
c:\progra~1\SMILEY~2\bar\1.bin\LOGO.BMP
c:\progra~1\SMILEY~2\bar\1.bin\NP1vStub.dll
c:\progra~1\SMILEY~2\bar\Cache\0003E4A4
c:\progra~1\SMILEY~2\bar\Cache\00065873.bmp
c:\progra~1\SMILEY~2\bar\Cache\00065EEB.bmp
c:\progra~1\SMILEY~2\bar\Cache\00066266.bmp
c:\progra~1\SMILEY~2\bar\Cache\0006641B.bmp
c:\progra~1\SMILEY~2\bar\Cache\00067717.bmp
c:\progra~1\SMILEY~2\bar\Cache\00067B6C.bmp
c:\progra~1\SMILEY~2\bar\Cache\00067E4A.bin
c:\progra~1\SMILEY~2\bar\Cache\files.ini
c:\progra~1\SMILEY~2\bar\History\search3
c:\progra~1\SMILEY~2\bar\Message\COMMON.T8S
c:\progra~1\SMILEY~2\bar\Settings\prevcfg2.htm
c:\progra~1\SMILEY~2\bar\Settings\s_pid.dat
c:\windows\system32\drivers\cbufr.sys
Nakažená kopie c:\windows\system32\drivers\aec.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\aec.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SMILEYCENTRAL_1VSERVICE
-------\Service_SmileyCentral_1vService
-------\Service_doxtn
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-11 do 2011-02-11 )))))))))))))))))))))))))))))))
.
2011-02-11 07:32 . 2011-02-11 07:32 739328 ----a-w- c:\windows\system32\drivers\dthetjg.sys
2011-02-10 06:59 . 2011-02-10 06:59 739328 ----a-w- c:\windows\system32\drivers\qbrddsnx.sys
2011-02-10 06:58 . 2011-02-10 06:58 739328 ----a-w- c:\windows\system32\drivers\sjxwo.sys
2011-02-09 21:23 . 2011-02-09 21:23 739328 ----a-w- c:\windows\system32\drivers\rfipy.sys
2011-02-09 21:00 . 2011-02-09 21:00 -------- d-----w- C:\_OTL
2011-02-09 11:34 . 2011-02-09 11:34 739328 ----a-w- c:\windows\system32\drivers\vjttyjapf.sys
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- c:\program files\trend micro
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- C:\rsit
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2011-02-09 21:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 11:07 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-08 11:06 . 2011-02-10 07:11 -------- d-----w- c:\program files\Yahoo!
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\CCleaner
2011-01-29 21:13 . 2011-01-31 13:32 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\skypePM
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----w- c:\program files\Common Files\Skype
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----r- c:\program files\Skype
2011-01-29 21:07 . 2011-01-31 20:38 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Skype
2011-01-29 21:06 . 2011-01-29 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-01-25 17:22 . 2011-01-25 17:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-01-25 17:18 . 2011-01-25 17:18 -------- d-----w- c:\program files\Microsoft WSE
2011-01-25 16:48 . 2011-01-25 16:48 -------- d-----w- c:\program files\Electronic Arts
2011-01-18 12:40 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-16 20:27 . 2011-01-16 20:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-26 21:34 . 2007-08-02 12:00 29392 ----a-w- c:\windows\system32\drivers\secdrv.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-08-02 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=""
[HKLM\~\startupfolder\C:^Documents and Settings^Peťa^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Peťa\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2009-02-06 12:23 2021400 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 13:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-03 14:44 15028104 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-09-27 16:16 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Documents and Settings\\Peťa\\Plocha\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.8.2010 13:35 691696]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 13:23 106208]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 13:24 93336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 13:23 727720]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.8.2010 11:18 246520]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.9.2010 17:13 136176]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-02-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-11 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-30 20:18]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FDCB521-35A7-4342-A0C7-1194C9EBB954} = 192.168.150.237,194.228.2.1
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb002YYCZ_ZNzfb014&ptb=7C552DF5-D873-46DD-BDA3-3CC277730C7F&psa=&ind=2010111304&ptnrS=ZNzfb002YYCZ_ZNzfb014&si=&st=kwd&n=77cfdd48&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-11 09:46
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1936)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\DllHost.exe
.
**************************************************************************
.
Celkový čas: 2011-02-11 09:51:27 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-11 08:51
ComboFix2.txt 2011-02-09 11:28
ComboFix3.txt 2011-02-09 08:31
Před spuštěním: 1 949 245 440
Po spuštění: 1 934 323 712
- - End Of File - - C0269DFE4419D93C44C9191826E41D87