Re: Adobe Reader
Napsal: 27 led 2012 16:40
Omlouvám se že tak po dlouhé době ale přece jen 
ComboFix 12-01-21.02 - jakub 27.01.2012 16:06:54.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3000.1798 [GMT 1:00]
Spuštěný z: c:\users\jakub\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\jakub\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\InnoGames_International\prxtbInn0.dll"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-1.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-2.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-3.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-4.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-5.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-6.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-7.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-8.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-9.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.gif"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.src"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.xml"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\1006102202\config.xml
c:\program files\ICQ6Toolbar\1006102202\Icons.bmp
c:\program files\ICQ6Toolbar\1006102202\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\1006102202\ICQToolBar.dll
c:\program files\ICQ6Toolbar\1006102202\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\1006102202\logo_small.gif
c:\program files\ICQ6Toolbar\1006102202\short.wav
c:\program files\ICQ6Toolbar\1006102202\Version.txt
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\ICQ6Toolbar\voucher.bmp
c:\program files\ICQ6Toolbar\voucher2.bmp
c:\program files\InnoGames_International\prxtbInn0.dll
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-1.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-2.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-3.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-4.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-5.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-6.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-7.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-8.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-9.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.gif
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.src
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.xml
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gusvc
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-27 do 2012-01-27 )))))))))))))))))))))))))))))))
.
.
2012-01-27 15:14 . 2012-01-27 15:22 -------- d-----w- c:\users\jakub\AppData\Local\temp
2012-01-27 15:14 . 2012-01-27 15:14 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-01-27 15:14 . 2012-01-27 15:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-27 14:57 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{097A72C3-8EAB-412B-B092-ABA780B544BF}\mpengine.dll
2012-01-22 16:06 . 2012-01-22 16:29 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2012-01-22 09:11 . 2012-01-22 09:20 -------- d-----w- c:\program files\trend micro
2012-01-22 09:11 . 2012-01-22 09:20 -------- d-----w- C:\rsit
2012-01-15 16:12 . 2011-11-17 06:48 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-15 16:12 . 2011-11-16 16:23 278528 ----a-w- c:\windows\system32\schannel.dll
2012-01-15 16:12 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-01-15 16:12 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
2012-01-15 16:12 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-15 16:12 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
2012-01-14 11:26 . 2011-12-01 15:21 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-14 11:26 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-01-14 11:26 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-01-14 11:26 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-01-14 11:26 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-01-14 11:26 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-01-14 11:26 . 2011-10-25 15:58 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-01-14 11:26 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2012-01-01 12:22 . 2012-01-01 12:22 -------- d-----w- c:\programdata\Nikon
2012-01-01 11:39 . 2012-01-01 12:44 -------- d-----w- c:\users\jakub\AppData\Local\Nikon
2012-01-01 11:24 . 2012-01-01 11:24 -------- d-----w- c:\users\jakub\AppData\Local\ArcSoft
2012-01-01 11:24 . 2012-01-01 11:55 -------- d--h--w- c:\programdata\ArcSoft
2012-01-01 11:24 . 2012-01-01 12:48 -------- d-----w- c:\program files\Common Files\ArcSoft
2012-01-01 11:23 . 2012-01-01 11:26 -------- d-----w- c:\users\jakub\AppData\Roaming\ArcSoft
2012-01-01 11:23 . 2001-09-05 03:18 77824 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2012-01-01 11:23 . 2001-09-05 03:18 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
2012-01-01 11:23 . 2001-09-05 03:14 176128 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2012-01-01 11:23 . 2001-09-05 03:13 32768 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2012-01-01 11:21 . 2012-01-01 11:21 57344 ----a-r- c:\users\jakub\AppData\Roaming\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2012-01-01 11:19 . 2012-01-01 11:19 -------- d-----w- c:\programdata\Ultima_T15
2012-01-01 11:19 . 2012-01-01 11:19 -------- d-----w- c:\programdata\EnterNHelp
2012-01-01 11:19 . 2012-01-01 11:22 -------- d-----w- c:\users\jakub\AppData\Local\Downloaded Installations
2012-01-01 11:18 . 2012-01-01 12:45 -------- d-----w- c:\program files\Nikon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-20 18:05 . 2011-06-07 15:04 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-01 11:19 . 2009-09-20 19:39 106496 ----a-w- c:\windows\system32\ATL71.DLL
2011-12-28 13:54 . 2011-12-24 19:01 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-12-28 13:54 . 2011-12-24 19:00 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-12-25 21:53 . 2011-12-24 19:00 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-24 19:01 . 2011-12-24 19:01 22328 ----a-w- c:\users\jakub\AppData\Roaming\PnkBstrK.sys
2011-12-14 14:33 . 2011-12-14 14:33 515856 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-12-11 19:31 . 2009-05-20 14:04 952 --sha-w- c:\programdata\KGyGaAvL.sys
2011-12-07 09:08 . 2009-10-03 07:02 236576 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2011-04-23 06:43 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-04-23 06:43 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-04-23 06:43 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-04-23 06:43 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-04-23 06:43 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-04-23 06:43 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-04-23 06:43 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2011-04-23 06:43 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-23 13:37 . 2011-12-14 14:31 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-11-16 16:23 . 2012-01-15 16:12 278528 ----a-w- c:\windows\system32\schannel.dll
2011-11-08 14:42 . 2011-12-14 14:31 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-29 08:57 . 2011-12-26 07:42 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2009-05-14 23:13 157168 ----a-w- c:\programdata\Partner\partner.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2005-01-19 128000]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Seznam Postak"="c:\program files\Seznam.cz\bin\postak.exe" [2012-01-10 491040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-05 1033512]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-25 145944]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-09-01 858632]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-06-11 409600]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"4StoryPrePatch"="d:\program files\Gameforge4D\4Story\PrePatch.exe" [2011-12-02 327680]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-27 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files\EPSON\EPAPDL\E_SAPDL2.EXE [2009-05-26 09:43]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} - hxxp://pl.recruit.netmonitor.cz/WebInstaller.dll
FF - ProfilePath - c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-27 16:19
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\windows\TEMP\3020.tmp 85095695 bytes
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(5868)
c:\windows\system32\btmmhook.dll
c:\windows\System32\SysHook.dll
c:\windows\system32\ieframe.dll
c:\program files\CursorXP\CurXP0.dll
c:\program files\K-Lite Codec Pack\ffdshow\ffdshow.ax
c:\windows\system32\VSFilter.dll
c:\windows\system32\btncopy.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Launch Manager\QtZgAcer.EXE
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Epson Software\Event Manager\EEventManager.exe
c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\users\jakub\AppData\Local\Temp\RtkBtMnt.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Celkový čas: 2012-01-27 16:28:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-27 15:28
ComboFix2.txt 2012-01-22 18:28
.
Před spuštěním: Volných bajtů: 50 205 261 824
Po spuštění: Volných bajtů: 49 376 071 680
.
- - End Of File - - 2BC9BECA13D8960D044A7BD136A0A0EC

ComboFix 12-01-21.02 - jakub 27.01.2012 16:06:54.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3000.1798 [GMT 1:00]
Spuštěný z: c:\users\jakub\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\jakub\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\program files\InnoGames_International\prxtbInn0.dll"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-1.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-2.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-3.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-4.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-5.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-6.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-7.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-8.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-9.xml"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.gif"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.src"
"c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.xml"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Ask.com
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\1006102202\config.xml
c:\program files\ICQ6Toolbar\1006102202\Icons.bmp
c:\program files\ICQ6Toolbar\1006102202\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\1006102202\ICQToolBar.dll
c:\program files\ICQ6Toolbar\1006102202\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\1006102202\logo_small.gif
c:\program files\ICQ6Toolbar\1006102202\short.wav
c:\program files\ICQ6Toolbar\1006102202\Version.txt
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\ICQ6Toolbar\voucher.bmp
c:\program files\ICQ6Toolbar\voucher2.bmp
c:\program files\InnoGames_International\prxtbInn0.dll
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-1.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-2.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-3.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-4.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-5.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-6.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-7.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-8.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin-9.xml
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.gif
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.src
c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\searchplugins\icqplugin.xml
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_gusvc
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-12-27 do 2012-01-27 )))))))))))))))))))))))))))))))
.
.
2012-01-27 15:14 . 2012-01-27 15:22 -------- d-----w- c:\users\jakub\AppData\Local\temp
2012-01-27 15:14 . 2012-01-27 15:14 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-01-27 15:14 . 2012-01-27 15:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-27 14:57 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{097A72C3-8EAB-412B-B092-ABA780B544BF}\mpengine.dll
2012-01-22 16:06 . 2012-01-22 16:29 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2012-01-22 09:11 . 2012-01-22 09:20 -------- d-----w- c:\program files\trend micro
2012-01-22 09:11 . 2012-01-22 09:20 -------- d-----w- C:\rsit
2012-01-15 16:12 . 2011-11-17 06:48 440192 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-15 16:12 . 2011-11-16 16:23 278528 ----a-w- c:\windows\system32\schannel.dll
2012-01-15 16:12 . 2011-11-16 16:23 377344 ----a-w- c:\windows\system32\winhttp.dll
2012-01-15 16:12 . 2011-11-16 16:23 72704 ----a-w- c:\windows\system32\secur32.dll
2012-01-15 16:12 . 2011-11-16 16:21 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-15 16:12 . 2011-11-16 14:12 9728 ----a-w- c:\windows\system32\lsass.exe
2012-01-14 11:26 . 2011-12-01 15:21 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-14 11:26 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-01-14 11:26 . 2011-10-14 16:03 189952 ----a-w- c:\windows\system32\winmm.dll
2012-01-14 11:26 . 2011-10-14 16:00 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-01-14 11:26 . 2011-11-25 15:59 376320 ----a-w- c:\windows\system32\winsrv.dll
2012-01-14 11:26 . 2011-11-18 17:47 66560 ----a-w- c:\windows\system32\packager.dll
2012-01-14 11:26 . 2011-10-25 15:58 1314816 ----a-w- c:\windows\system32\quartz.dll
2012-01-14 11:26 . 2011-10-25 15:58 497152 ----a-w- c:\windows\system32\qdvd.dll
2012-01-01 12:22 . 2012-01-01 12:22 -------- d-----w- c:\programdata\Nikon
2012-01-01 11:39 . 2012-01-01 12:44 -------- d-----w- c:\users\jakub\AppData\Local\Nikon
2012-01-01 11:24 . 2012-01-01 11:24 -------- d-----w- c:\users\jakub\AppData\Local\ArcSoft
2012-01-01 11:24 . 2012-01-01 11:55 -------- d--h--w- c:\programdata\ArcSoft
2012-01-01 11:24 . 2012-01-01 12:48 -------- d-----w- c:\program files\Common Files\ArcSoft
2012-01-01 11:23 . 2012-01-01 11:26 -------- d-----w- c:\users\jakub\AppData\Roaming\ArcSoft
2012-01-01 11:23 . 2001-09-05 03:18 77824 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2012-01-01 11:23 . 2001-09-05 03:18 225280 ----a-w- c:\program files\Common Files\InstallShield\IScript\iscript.dll
2012-01-01 11:23 . 2001-09-05 03:14 176128 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2012-01-01 11:23 . 2001-09-05 03:13 32768 ----a-w- c:\program files\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2012-01-01 11:21 . 2012-01-01 11:21 57344 ----a-r- c:\users\jakub\AppData\Roaming\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2012-01-01 11:19 . 2012-01-01 11:19 -------- d-----w- c:\programdata\Ultima_T15
2012-01-01 11:19 . 2012-01-01 11:19 -------- d-----w- c:\programdata\EnterNHelp
2012-01-01 11:19 . 2012-01-01 11:22 -------- d-----w- c:\users\jakub\AppData\Local\Downloaded Installations
2012-01-01 11:18 . 2012-01-01 12:45 -------- d-----w- c:\program files\Nikon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-20 18:05 . 2011-06-07 15:04 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-01 11:19 . 2009-09-20 19:39 106496 ----a-w- c:\windows\system32\ATL71.DLL
2011-12-28 13:54 . 2011-12-24 19:01 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-12-28 13:54 . 2011-12-24 19:00 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-12-25 21:53 . 2011-12-24 19:00 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-12-24 19:01 . 2011-12-24 19:01 22328 ----a-w- c:\users\jakub\AppData\Roaming\PnkBstrK.sys
2011-12-14 14:33 . 2011-12-14 14:33 515856 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-12-11 19:31 . 2009-05-20 14:04 952 --sha-w- c:\programdata\KGyGaAvL.sys
2011-12-07 09:08 . 2009-10-03 07:02 236576 ------w- c:\windows\system32\MpSigStub.exe
2011-11-28 18:01 . 2011-04-23 06:43 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-04-23 06:43 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-04-23 06:43 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-04-23 06:43 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-04-23 06:43 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-04-23 06:43 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-04-23 06:43 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-11-28 17:51 . 2011-04-23 06:43 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-23 13:37 . 2011-12-14 14:31 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-11-16 16:23 . 2012-01-15 16:12 278528 ----a-w- c:\windows\system32\schannel.dll
2011-11-08 14:42 . 2011-12-14 14:31 2048 ----a-w- c:\windows\system32\tzres.dll
2011-12-29 08:57 . 2011-12-26 07:42 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2009-05-14 23:13 157168 ----a-w- c:\programdata\Partner\partner.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2005-01-19 128000]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Seznam Postak"="c:\program files\Seznam.cz\bin\postak.exe" [2012-01-10 491040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-28 6111232]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-05 1033512]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-25 145944]
"ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-09-23 6144]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-09-01 858632]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-06-11 409600]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-04-07 673616]
"4StoryPrePatch"="d:\program files\Gameforge4D\4Story\PrePatch.exe" [2011-12-02 327680]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Obsah adresáře 'Naplánované úlohy'
.
2012-01-27 c:\windows\Tasks\Epson Printer Software Downloader.job
- c:\program files\EPSON\EPAPDL\E_SAPDL2.EXE [2009-05-26 09:43]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uSearchAssistant = hxxp://www.google.com/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{7644E42D-B096-457F-8B5B-901238FC81AE} - c:\program files\ICQ7.6\ICQ.exe
TCP: DhcpNameServer = 10.0.0.138
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/3.0.1.0/GarminAxControl.CAB
DPF: {65D72393-E210-4A2A-B8E0-10AC45986770} - hxxp://pl.recruit.netmonitor.cz/WebInstaller.dll
FF - ProfilePath - c:\users\jakub\AppData\Roaming\Mozilla\Firefox\Profiles\45euejyp.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-27 16:19
Windows 6.0.6002 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\windows\TEMP\3020.tmp 85095695 bytes
.
sken byl úspešně dokončen
skryté soubory: 1
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(5868)
c:\windows\system32\btmmhook.dll
c:\windows\System32\SysHook.dll
c:\windows\system32\ieframe.dll
c:\program files\CursorXP\CurXP0.dll
c:\program files\K-Lite Codec Pack\ffdshow\ffdshow.ax
c:\windows\system32\VSFilter.dll
c:\windows\system32\btncopy.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Google\Update\GoogleUpdate.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
c:\program files\Acer\Empowering Technology\Service\ETService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Launch Manager\QtZgAcer.EXE
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Epson Software\Event Manager\EEventManager.exe
c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\users\jakub\AppData\Local\Temp\RtkBtMnt.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Celkový čas: 2012-01-27 16:28:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-01-27 15:28
ComboFix2.txt 2012-01-22 18:28
.
Před spuštěním: Volných bajtů: 50 205 261 824
Po spuštění: Volných bajtů: 49 376 071 680
.
- - End Of File - - 2BC9BECA13D8960D044A7BD136A0A0EC