Takže tohle :
ComboFix 12-02-16.02 - Petr . 02. 2012 20:49:35.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1029.18.2046.1297 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\tmp9F.tmp
c:\windows\system32\tmpA0.tmp
K:\install.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-16 do 2012-02-16 )))))))))))))))))))))))))))))))
.
.
2012-02-16 19:23 . 2012-02-16 19:27 -------- d-----w- C:\rsit
2012-02-16 19:23 . 2012-02-16 19:27 -------- d-----w- c:\program files\trend micro
2012-02-16 18:54 . 2012-02-16 19:07 -------- d-----w- C:\UsbFix
2012-02-16 14:39 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-02-16 14:39 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-12 16:57 . 2012-02-12 17:14 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Synthesia
2012-02-12 15:10 . 2012-02-12 15:10 2677 ------w- C:\STFDF.tmp
2012-02-12 12:10 . 2012-02-12 12:10 2677 ------w- C:\STF19.tmp
2012-02-12 12:04 . 2012-02-12 12:04 2677 ------w- C:\STF11.tmp
2012-02-11 19:25 . 2012-02-11 19:25 2677 ------w- C:\STF1C8.tmp
2012-02-11 19:24 . 2012-02-11 19:24 2677 ------w- C:\STF1C6.tmp
2012-02-11 19:20 . 2012-02-11 19:20 2677 ------w- C:\STF1B8.tmp
2012-02-11 15:27 . 2012-02-11 15:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Ubisoft
2012-02-10 13:35 . 2012-02-10 13:35 2677 ------w- C:\STF8D.tmp
2012-02-09 15:06 . 2012-02-09 15:06 -------- d-----w- c:\program files\Yontoo
2012-02-09 15:06 . 2012-02-09 15:06 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Tarma Installer
2012-02-09 15:06 . 2012-02-09 15:06 237 ------w- C:\user.js
2012-02-09 15:06 . 2012-02-09 15:06 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\Babylon
2012-02-09 15:06 . 2012-02-09 15:06 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Babylon
2012-02-09 15:06 . 2012-02-09 15:06 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Babylon
2012-02-09 13:50 . 2012-02-09 13:50 2629 ------w- C:\STF171.tmp
2012-02-09 13:32 . 2012-02-09 13:32 -------- d-----w- c:\program files\CROTEAM
2012-02-07 14:06 . 2012-02-07 14:06 -------- d--h--w- c:\program files\Webstart Studios
2012-02-05 11:20 . 2012-02-05 11:20 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Adobe Systems
2012-02-05 11:02 . 2002-12-11 23:14 46592 ----a-w- c:\windows\system32\dxdllreg.exe
2012-02-04 17:03 . 2012-02-04 17:10 -------- d-----w- c:\program files\Army Rage
2012-02-04 16:36 . 2012-02-04 16:46 -------- d-----w- C:\Download
2012-02-03 18:53 . 2000-05-21 22:00 140488 ----a-w- c:\windows\system32\COMDLG32.OCX
2012-02-03 18:53 . 2000-12-05 22:00 109248 ----a-w- c:\windows\system32\MSWINSCK.OCX
2012-02-01 15:13 . 2012-02-01 15:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\EA Core
2012-02-01 14:54 . 2012-02-13 06:41 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Origin
2012-02-01 14:54 . 2012-02-13 06:53 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Origin
2012-02-01 14:49 . 2012-02-01 14:49 -------- d-----w- C:\ProgramData
2012-02-01 14:14 . 2008-09-04 18:17 447752 ----a-r- c:\windows\system32\vp6vfw.dll
2012-02-01 14:14 . 2012-02-01 14:14 -------- d-----w- c:\program files\Microsoft WSE
2012-01-28 21:40 . 2012-01-28 22:01 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\Skyrim
2012-01-28 15:52 . 2012-02-16 19:18 -------- d-----w- C:\Counter-Strike 1.6
2012-01-23 14:11 . 2012-01-23 14:11 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\Identities
2012-01-21 08:46 . 2012-01-21 08:46 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\FlatOut Ultimate Carnage
2012-01-21 08:42 . 2012-01-21 08:42 -------- d-----w- c:\windows\system32\xlive
2012-01-21 08:33 . 2012-01-21 08:33 -------- d-----w- c:\program files\Empire Interactive
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-16 19:07 . 2012-02-16 19:06 121946649 ----a-w- C:\UsbFix_Upload_Me_PC.zip
2012-02-02 15:40 . 2011-10-30 16:54 138264 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-02-02 15:39 . 2011-11-01 19:14 234768 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-02-02 15:39 . 2011-10-30 16:54 234768 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-01-12 17:20 . 2006-03-02 12:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2006-03-02 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2006-03-02 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:42 . 2006-03-02 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:23 . 2006-03-02 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-28 18:01 . 2011-10-27 19:33 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 18:01 . 2011-10-27 19:33 199816 ----a-w- c:\windows\system32\aswBoot.exe
2011-11-28 17:53 . 2011-10-27 19:33 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 17:53 . 2011-10-27 19:33 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-11-28 17:52 . 2011-10-27 19:33 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-11-28 17:52 . 2011-10-27 19:33 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-11-28 17:52 . 2011-10-27 19:33 111320 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-11-28 17:51 . 2011-10-27 19:33 105176 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-11-28 17:51 . 2011-10-27 19:33 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-11-28 17:48 . 2011-10-27 19:33 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-11-25 21:57 . 2006-03-02 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-11-20 06:12 . 2006-03-02 12:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-19 10:38 . 2011-11-19 10:38 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-02-13 06:36 . 2011-10-31 14:35 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2011-08-24 130864]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C93F72A2-2162-4BBA-A07A-F13663C297A6}]
2011-10-13 14:51 2697528 ----a-w- c:\program files\Yandex\YandexBarIE\fastdial.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2011-08-24 17:21 1299248 ----a-r- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-12-09 01:11 194848 ----a-w- c:\program files\Yontoo\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{91397D20-1446-11D4-8AF4-0040CA1127B6}"= "c:\program files\Yandex\YandexBarIE\yndbar.dll" [2011-10-20 12336440]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2011-08-24 1299248]
.
[HKEY_CLASSES_ROOT\clsid\{91397d20-1446-11d4-8af4-0040ca1127b6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{91397D20-1446-11D4-8AF4-0040CA1127B6}"= "c:\program files\Yandex\YandexBarIE\yndbar.dll" [2011-10-20 12336440]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2011-08-24 1299248]
.
[HKEY_CLASSES_ROOT\clsid\{91397d20-1446-11d4-8af4-0040ca1127b6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}]
[HKEY_CLASSES_ROOT\Yandex.Toolbar]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2012-01-30 1242448]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-02-09 738168]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Clownfish"="c:\program files\Clownfish\Clownfish.exe" [2011-11-28 986624]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"RTHDCPL"="RTHDCPL.EXE" [2011-08-09 20055144]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 172032]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2011-08-01 114992]
"LogMeIn Hamachi Ui"="j:\hamachi\hamachi-2-ui.exe" [2012-02-07 1987976]
.
c:\documents and settings\Petr\Nabídka Start\Programy\Po spuštění\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\stanley1254\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\demetricz\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\EA Games\\Battlefield Play4Free\\BFP4f.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"j:\\Hry\\Vietcong\\vietcong.exe"=
"j:\\Hry\\UT2004\\System\\UT2004.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"j:\\Dead Island\\DeadIslandGame.exe"=
"c:\\Program Files\\Tunngle\\TnglCtrl.exe"=
"c:\\Program Files\\Tunngle\\Tunngle.exe"=
"c:\\Program Files\\Steam\\steamapps\\stanley1254\\team fortress 2 beta\\hl2.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\champions online\\Champions Online\\Live\\GameClient.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\champions online\\Champions Online.exe"=
"c:\\Documents and Settings\\Petr\\Plocha\\JIRKOVY Kraviny\\Terraria 1.1\\TerrariaServer.exe"=
"c:\\Program Files\\Steam\\steamapps\\arrow46\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\demetriczko\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\metro 2033\\metro2033.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\portal 2\\portal2.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\nation red\\NationRed.exe"=
"c:\\Counter-Strike 1.6\\csko.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Empire Interactive\\FlatOut Ultimate Carnage\\Fouc.exe"=
"c:\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\magicka\\Magicka.exe"=
"c:\\Program Files\\Steam\\steamapps\\stanley1254\\garrysmod\\hl2.exe"=
"j:\\MT2\\Sanford\\M2.bin"=
"j:\\MT2\\Sanford\\M2.exe"=
"j:\\Orcs Must Die Repack\\VV\\Build\\release\\OrcsMustDie.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57031:TCP"= 57031:TCP:Pando Media Booster
"57031:UDP"= 57031:UDP:Pando Media Booster
"56547:TCP"= 56547:TCP:Pando Media Booster
"56547:UDP"= 56547:UDP:Pando Media Booster
.
R0 pe3agmlb;Armed Assault Environment Driver (pe3agmlb);c:\windows\system32\drivers\pe3agmlb.sys [4. 6. 2007 20:01 65408]
R0 ps6agmlb;Armed Assault Synchronization Driver (ps6agmlb);c:\windows\system32\drivers\ps6agmlb.sys [4. 6. 2007 20:01 55688]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [27. 10. 2011 20:33 435032]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [27. 10. 2011 20:33 314456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27. 10. 2011 20:33 20568]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [27. 10. 2011 19:11 2253120]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [24. 10. 2011 21:07 119656]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [17. 11. 2011 18:36 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18. 3. 2010 13:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27. 10. 2011 20:34 136176]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;j:\hamachi\hamachi-2.exe -s --> j:\hamachi\hamachi-2.exe -s [?]
S2 pr2agmlb;Armed Assault Drivers Auto Removal (pr2agmlb);c:\windows\system32\pr2agmlb.exe svc --> c:\windows\system32\pr2agmlb.exe svc [?]
S2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [17. 11. 2011 18:36 745832]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [27. 10. 2011 19:53 1691480]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27. 10. 2011 20:34 136176]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [3. 10. 2011 16:49 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18. 3. 2010 13:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-27 19:33]
.
2012-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-27 19:33]
.
2012-02-16 c:\windows\Tasks\HP Usg Daily.job
- c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped05.exe [2004-06-07 05:35]
.
.
------- Doplňkový sken -------
.
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
TCP: DhcpNameServer = 10.0.0.138
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\c406tk2b.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.cz/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
FF - prefs.js: network.proxy.type - 0
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=109217
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - bced444700000000000000ff819ef10e
FF - user.js: extensions.BabylonToolbar_i.hardId - bced444700000000000000ff819ef10e
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15379
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1716:06
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
FF - user.js: extentions.y2layers.installId - 15cb28ed-0f09-49ef-bedd-d5c72bc563b6
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,BuzzdockTease,DropDownDeals,BestVideoDownloader,TopRelatedTopics,BestVideoDownloader,
FF - user.js: extensions.autoDisableScopes - 14
FF - user.js: security.csp.enable - false
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-RunOnce-<NO NAME> - (no file)
AddRemove-CadStd - j:\afjh\CadStd\uninst.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-02-16 21:02
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2052111302-1757981266-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:2a,e9,68,36,be,2f,c3,2a,22,5c,2e,65,bd,c9,d4,1e,43,35,8d,5c,94,
3b,44,8e,17,27,39,6b,96,0a,73,4e,7b,f1,a2,f3,07,81,2c,2a,28,dd,ee,e1,7b,50,\
"rkeysecu"=hex:db,7d,54,0a,ea,2f,e2,b4,2c,e8,77,f3,b6,bc,ea,11
.
Celkový čas: 2012-02-16 21:07:06
ComboFix-quarantined-files.txt 2012-02-16 20:07
.
Před spuštěním: Volných bajtů: 74 825 379 840
Po spuštění: Volných bajtů: 79 279 710 208
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - F7262D0D395EF040390BD51DE17D78A6