pripájam combofix.
ComboFix 11-02-24.05 - Administrativa 25.02.2011 14:52:03.1.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.2.1250.421.1033.18.191.95 [GMT 1:00]
Running from: c:\documents and settings\Administrativa\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrativa\My Documents\cc_20110225_123938.reg
.
((((((((((((((((((((((((( Files Created from 2011-01-25 to 2011-02-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-20 12:06 . 2011-01-20 12:06 1409 ----a-w- c:\windows\QTFont.for
2007-05-24 10:56 . 2007-05-24 10:56 17282392 ----a-w- c:\program files\602xml_filler_sk.exe
2007-05-04 05:52 . 2007-05-04 05:51 27074096 ----a-w- c:\program files\PowerPointViewer.exe
2007-01-24 10:35 . 2007-01-24 10:35 2855080 ----a-w- c:\program files\aawsepersonal.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pdfSaver3"="c:\program files\PDF\pdfSaver\pdfSaver3.exe" [2004-05-19 385024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"S3Trayp"="S3trayp.exe" [2005-04-05 159744]
"RTHDCPL"="RTHDCPL.EXE" [2006-01-12 15961088]
"CHotkey"="zHotkey.exe" [2003-07-29 515584]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-05 282624]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-10-07 1461080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
c:\documents and settings\Administrativa\Start Menu\Programs\Startup\
¬istiź.lnk - c:\program files\¬istiź\¬istiź.exe [2003-9-6 122880]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Cyberlink\\PowerDirector\\PDR.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [10.6.2008 17:56 35168]
R3 S3G700;S3G700;c:\windows\system32\drivers\S3G700m.sys [19.11.2006 0:10 792576]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [19.11.2006 0:04 5824]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ALERTER
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.cas.sk/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrativa\Application Data\Mozilla\Firefox\Profiles\kfyis2yb.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-pdfSaver3 - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-02-25 15:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1275210071-492894223-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2011-02-25 15:07:56
ComboFix-quarantined-files.txt 2011-02-25 14:07
Pre-Run: 42 410 532 864 bytes free
Post-Run: 13 adresárov, 43 235 278 848 voľných bajtov
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 0A3EB636F045ACDFFD1B67A4A7F4C2F9