Re: Prosím o preventivku
Napsal: 06 říj 2011 18:18
Ja si jej sem vlozim, vynecham cast SnapShot
ComboFix 11-10-06.03 - hynek 06.10.2011 18:49:01.6.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.1022.588 [GMT 2:00]
Spuštěný z: c:\documents and settings\hynek\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\matej\WINDOWS
C:\DSC02524.JPG
C:\DSC02540.JPG
C:\DSCN2077.jpg
c:\windows\msmqinst.log
c:\windows\unin0405.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-06 do 2011-10-06 )))))))))))))))))))))))))))))))
.
.
2011-10-06 16:49 . 2011-10-06 16:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-10-06 16:39 . 2011-10-06 16:39 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\MpKsl294726ca.sys
2011-10-06 16:39 . 2011-10-06 16:39 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\offreg.dll
2011-10-05 20:16 . 2011-10-05 20:16 -------- d-----w- C:\_OTL
2011-10-05 15:55 . 2011-09-12 14:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\mpengine.dll
2011-10-04 19:32 . 2011-10-04 19:32 512 ----a-w- C:\PhysicalMBR.bin
2011-10-04 17:58 . 2011-10-04 17:58 -------- d-sh--w- c:\documents and settings\hynek\IECompatCache
2011-10-04 17:55 . 2011-10-04 17:55 -------- d-sh--w- c:\documents and settings\hynek\PrivacIE
2011-10-04 14:25 . 2011-09-12 14:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-04 14:18 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-10-04 14:15 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-10-04 14:11 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-10-04 14:08 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-10-04 14:08 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-10-04 13:33 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-10-04 13:33 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-10-02 20:37 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-10-02 20:26 . 2011-10-02 20:26 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-10-02 20:25 . 2011-10-02 20:26 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-02 20:19 . 2011-10-02 20:19 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\system32\scripting
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\l2schemas
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\system32\en
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\system32\bits
2011-10-02 18:41 . 2008-04-14 00:12 33792 ------w- c:\windows\system32\mmcperf.exe
2011-10-02 18:41 . 2008-04-14 00:11 397312 ------w- c:\windows\system32\mmcex.dll
2011-10-02 18:41 . 2008-04-14 00:11 184320 ------w- c:\windows\system32\microsoft.managementconsole.dll
2011-10-02 18:41 . 2008-04-14 00:11 106496 ------w- c:\windows\system32\mmcfxcommon.dll
2011-10-02 18:41 . 2008-04-14 00:11 86016 ------w- c:\windows\system32\mdmxsdk.dll
2011-10-02 18:41 . 2004-08-03 20:41 11868 ------w- c:\windows\system32\drivers\mdmxsdk.sys
2011-10-02 18:41 . 2008-04-14 00:11 37376 ------w- c:\windows\system32\l2gpstore.dll
2011-10-02 18:41 . 2008-04-14 00:11 61440 ------w- c:\windows\system32\kmsvc.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdpash.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdnepr.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdiultn.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdbhc.dll
2011-10-02 17:41 . 2011-10-02 17:41 -------- d-sh--w- c:\documents and settings\hynek\IETldCache
2011-10-02 17:33 . 2011-06-23 18:36 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-10-02 17:33 . 2011-06-23 18:36 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-10-02 17:33 . 2011-06-23 18:36 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-10-02 17:33 . 2011-06-23 18:36 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-10-02 17:33 . 2011-06-23 18:36 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-10-02 17:33 . 2011-06-23 18:36 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-10-02 17:33 . 2011-06-23 18:36 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-10-02 17:32 . 2011-10-02 17:32 -------- dc-h--w- c:\windows\ie8
2011-10-02 17:09 . 2011-10-02 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2011-10-02 16:53 . 2011-10-02 16:53 -------- d-----w- c:\windows\nview
2011-10-02 16:53 . 2008-05-16 12:01 446464 ----a-w- c:\windows\system32\nvudisp.exe
2011-10-02 16:52 . 2008-05-16 09:48 446464 ----a-w- c:\windows\system32\NVUNINST.EXE
2011-10-02 16:52 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-10-02 16:52 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-10-02 16:52 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-10-02 16:52 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-10-02 16:52 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-10-02 16:52 . 2011-10-02 16:52 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-10-02 16:52 . 2011-10-02 16:52 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-10-02 16:52 . 2011-10-02 16:52 -------- d-----w- C:\NVIDIA
2011-09-17 20:31 . 2011-09-17 20:31 -------- d-----w- c:\program files\Plus500
2011-09-09 09:12 . 2011-09-09 09:12 599040 -c----w- c:\windows\system32\dllcache\crypt32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2006-03-15 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-07-26 18:53 . 2011-07-26 18:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-26 18:53 . 2008-01-28 13:18 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-07-15 13:29 . 2006-03-15 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-10-05 18:07 . 2011-05-31 14:46 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2005-03-03 479232]
"SoundMan"="SOUNDMAN.EXE" [2006-08-02 577536]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2007-8-24 344064]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2007-3-15 819200]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\temp\\WAP54G-full package-0420\\Setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.3.2007 14:19 639224]
R1 MpKsl294726ca;MpKsl294726ca;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\MpKsl294726ca.sys [6.10.2011 18:39 28752]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);c:\windows\system32\drivers\SE31bus.sys [28.3.2007 22:47 61600]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;c:\windows\system32\drivers\SE31mdfl.sys [1.5.2006 13:57 9360]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;c:\windows\system32\drivers\SE31mdm.sys [1.5.2006 13:57 97184]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\SE31mgmt.sys [1.5.2006 13:58 88688]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);c:\windows\system32\drivers\se31nd5.sys [1.5.2006 13:56 18704]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;c:\windows\system32\drivers\SE31obex.sys [1.5.2006 13:59 86560]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);c:\windows\system32\drivers\se31unic.sys [1.5.2006 13:56 90800]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 13:37 517096]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL294726CA
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.100.1
DPF: {D67DB088-70B4-4006-B052-57F614FD3AA8} - hxxp://www.vguard.net/myasp/chtIEx.cab
FF - ProfilePath - c:\documents and settings\hynek\Application Data\Mozilla\Firefox\Profiles\yf39my4j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-DivX Codec - c:\program files\DivX\DivXCodecUninstall.exe
AddRemove-Image Mapper - c:\grafy\DeIsL1.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-06 18:58
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\DNSAPI.dll
.
- - - - - - - > 'lsass.exe'(812)
c:\program files\Bonjour\mdnsNSP.dll
.
Celkový čas: 2011-10-06 19:01:41
ComboFix-quarantined-files.txt 2011-10-06 17:01
ComboFix2.txt 2009-10-04 11:04
ComboFix3.txt 2009-10-03 16:50
ComboFix4.txt 2009-08-16 14:23
.
Před spuštěním: 50 430 373 888 bytes free
Po spuštění: Volných bajtů: 54 489 075 712
.
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - D0E90C990352502E8C6ED25B4ABEE5DF
ComboFix 11-10-06.03 - hynek 06.10.2011 18:49:01.6.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1033.18.1022.588 [GMT 2:00]
Spuštěný z: c:\documents and settings\hynek\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\matej\WINDOWS
C:\DSC02524.JPG
C:\DSC02540.JPG
C:\DSCN2077.jpg
c:\windows\msmqinst.log
c:\windows\unin0405.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-06 do 2011-10-06 )))))))))))))))))))))))))))))))
.
.
2011-10-06 16:49 . 2011-10-06 16:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-10-06 16:39 . 2011-10-06 16:39 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\MpKsl294726ca.sys
2011-10-06 16:39 . 2011-10-06 16:39 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\offreg.dll
2011-10-05 20:16 . 2011-10-05 20:16 -------- d-----w- C:\_OTL
2011-10-05 15:55 . 2011-09-12 14:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\mpengine.dll
2011-10-04 19:32 . 2011-10-04 19:32 512 ----a-w- C:\PhysicalMBR.bin
2011-10-04 17:58 . 2011-10-04 17:58 -------- d-sh--w- c:\documents and settings\hynek\IECompatCache
2011-10-04 17:55 . 2011-10-04 17:55 -------- d-sh--w- c:\documents and settings\hynek\PrivacIE
2011-10-04 14:25 . 2011-09-12 14:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-04 14:18 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-10-04 14:15 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-10-04 14:11 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-10-04 14:08 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-10-04 14:08 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-10-04 13:33 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-10-04 13:33 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-10-02 20:37 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-10-02 20:26 . 2011-10-02 20:26 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-10-02 20:25 . 2011-10-02 20:26 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-02 20:19 . 2011-10-02 20:19 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\system32\scripting
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\l2schemas
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\system32\en
2011-10-02 20:01 . 2011-10-02 20:01 -------- d-----w- c:\windows\system32\bits
2011-10-02 18:41 . 2008-04-14 00:12 33792 ------w- c:\windows\system32\mmcperf.exe
2011-10-02 18:41 . 2008-04-14 00:11 397312 ------w- c:\windows\system32\mmcex.dll
2011-10-02 18:41 . 2008-04-14 00:11 184320 ------w- c:\windows\system32\microsoft.managementconsole.dll
2011-10-02 18:41 . 2008-04-14 00:11 106496 ------w- c:\windows\system32\mmcfxcommon.dll
2011-10-02 18:41 . 2008-04-14 00:11 86016 ------w- c:\windows\system32\mdmxsdk.dll
2011-10-02 18:41 . 2004-08-03 20:41 11868 ------w- c:\windows\system32\drivers\mdmxsdk.sys
2011-10-02 18:41 . 2008-04-14 00:11 37376 ------w- c:\windows\system32\l2gpstore.dll
2011-10-02 18:41 . 2008-04-14 00:11 61440 ------w- c:\windows\system32\kmsvc.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdpash.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdnepr.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdiultn.dll
2011-10-02 18:41 . 2008-04-14 00:09 6144 ------w- c:\windows\system32\kbdbhc.dll
2011-10-02 17:41 . 2011-10-02 17:41 -------- d-sh--w- c:\documents and settings\hynek\IETldCache
2011-10-02 17:33 . 2011-06-23 18:36 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-10-02 17:33 . 2011-06-23 18:36 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-10-02 17:33 . 2011-06-23 18:36 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-10-02 17:33 . 2011-06-23 18:36 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-10-02 17:33 . 2011-06-23 18:36 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-10-02 17:33 . 2011-06-23 18:36 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-10-02 17:33 . 2011-06-23 18:36 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-10-02 17:32 . 2011-10-02 17:32 -------- dc-h--w- c:\windows\ie8
2011-10-02 17:09 . 2011-10-02 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2011-10-02 16:53 . 2011-10-02 16:53 -------- d-----w- c:\windows\nview
2011-10-02 16:53 . 2008-05-16 12:01 446464 ----a-w- c:\windows\system32\nvudisp.exe
2011-10-02 16:52 . 2008-05-16 09:48 446464 ----a-w- c:\windows\system32\NVUNINST.EXE
2011-10-02 16:52 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2011-10-02 16:52 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2011-10-02 16:52 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2011-10-02 16:52 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2011-10-02 16:52 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2011-10-02 16:52 . 2011-10-02 16:52 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2011-10-02 16:52 . 2011-10-02 16:52 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2011-10-02 16:52 . 2011-10-02 16:52 -------- d-----w- C:\NVIDIA
2011-09-17 20:31 . 2011-09-17 20:31 -------- d-----w- c:\program files\Plus500
2011-09-09 09:12 . 2011-09-09 09:12 599040 -c----w- c:\windows\system32\dllcache\crypt32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2006-03-15 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-07-26 18:53 . 2011-07-26 18:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-26 18:53 . 2008-01-28 13:18 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-07-15 13:29 . 2006-03-15 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-10-05 18:07 . 2011-05-31 14:46 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2005-03-03 479232]
"SoundMan"="SOUNDMAN.EXE" [2006-08-02 577536]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2007-8-24 344064]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2007-3-15 819200]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\temp\\WAP54G-full package-0420\\Setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.3.2007 14:19 639224]
R1 MpKsl294726ca;MpKsl294726ca;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{87064ADE-8B06-475E-BF33-AE15297D064E}\MpKsl294726ca.sys [6.10.2011 18:39 28752]
S3 SE31bus;Sony Ericsson Device 049 Driver driver (WDM);c:\windows\system32\drivers\SE31bus.sys [28.3.2007 22:47 61600]
S3 SE31mdfl;Sony Ericsson Device 049 USB WMC Modem Filter;c:\windows\system32\drivers\SE31mdfl.sys [1.5.2006 13:57 9360]
S3 SE31mdm;Sony Ericsson Device 049 USB WMC Modem Driver;c:\windows\system32\drivers\SE31mdm.sys [1.5.2006 13:57 97184]
S3 SE31mgmt;Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\SE31mgmt.sys [1.5.2006 13:58 88688]
S3 se31nd5;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS);c:\windows\system32\drivers\se31nd5.sys [1.5.2006 13:56 18704]
S3 SE31obex;Sony Ericsson Device 049 USB WMC OBEX Interface;c:\windows\system32\drivers\SE31obex.sys [1.5.2006 13:59 86560]
S3 se31unic;Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM);c:\windows\system32\drivers\se31unic.sys [1.5.2006 13:56 90800]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 13:37 517096]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL294726CA
.
Obsah adresáře 'Naplánované úlohy'
.
2011-10-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.100.1
DPF: {D67DB088-70B4-4006-B052-57F614FD3AA8} - hxxp://www.vguard.net/myasp/chtIEx.cab
FF - ProfilePath - c:\documents and settings\hynek\Application Data\Mozilla\Firefox\Profiles\yf39my4j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-DivX Codec - c:\program files\DivX\DivXCodecUninstall.exe
AddRemove-Image Mapper - c:\grafy\DeIsL1.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-06 18:58
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\DNSAPI.dll
.
- - - - - - - > 'lsass.exe'(812)
c:\program files\Bonjour\mdnsNSP.dll
.
Celkový čas: 2011-10-06 19:01:41
ComboFix-quarantined-files.txt 2011-10-06 17:01
ComboFix2.txt 2009-10-04 11:04
ComboFix3.txt 2009-10-03 16:50
ComboFix4.txt 2009-08-16 14:23
.
Před spuštěním: 50 430 373 888 bytes free
Po spuštění: Volných bajtů: 54 489 075 712
.
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - D0E90C990352502E8C6ED25B4ABEE5DF