ComboFix 12-03-21.02 - Fujitsu 21.03.2012 22:26:23.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6001.1.1250.420.1029.18.1013.166 [GMT 1:00]
Spuštěný z: c:\users\Fujitsu\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Fujitsu\Desktop\CFScript.txt..txt
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-02-21 do 2012-03-21 )))))))))))))))))))))))))))))))
.
.
2012-03-21 21:34 . 2012-03-21 21:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-21 19:10 . 2001-10-31 09:14 1552384 ----a-w- c:\windows\system32\mplvm6.dll
2012-03-21 19:10 . 2001-10-31 09:14 1122304 ----a-w- c:\windows\system32\mplvpx.dll
2012-03-21 19:10 . 2001-10-31 09:14 77824 ----a-w- c:\windows\system32\mplaa6.dll
2012-03-21 19:10 . 2001-10-31 09:14 65536 ----a-w- c:\windows\system32\mplapx.dll
2012-03-21 19:10 . 2001-10-31 09:14 65536 ----a-w- c:\windows\system32\mplam6.dll
2012-03-21 19:10 . 2001-10-31 09:14 1650688 ----a-w- c:\windows\system32\mplva6.dll
2012-03-21 19:10 . 2001-10-31 09:14 1581056 ----a-w- c:\windows\system32\mplvw7.dll
2012-03-21 19:10 . 2001-09-17 11:20 19968 ----a-w- c:\windows\system32\cpuinf32.dll
2012-03-21 19:10 . 2001-10-31 09:14 77824 ----a-w- c:\windows\system32\mplaw7.dll
2012-03-21 19:10 . 2004-10-30 14:39 761856 ----a-w- c:\windows\system32\xvidcore.dll
2012-03-21 19:10 . 2004-05-25 15:06 417792 ----a-w- c:\windows\system32\ac3filter.cpl
2012-03-21 19:10 . 2012-03-21 19:11 -------- d-----w- c:\program files\ACE Mega CoDecS Pack
2012-03-21 18:35 . 2012-03-21 19:48 -------- d-----w- c:\windows\system32\RTCOM
2012-03-21 17:26 . 2012-03-21 17:26 -------- d-----w- c:\users\Fujitsu\AppData\Local\Innovative Solutions
2012-03-21 17:26 . 2012-03-21 17:26 -------- d-----w- c:\program files\Innovative Solutions
2012-03-20 20:47 . 2012-03-20 20:47 24576 ----a-w- c:\windows\SetupAfterRebootService.exe
2012-03-20 20:38 . 2012-03-21 18:34 319456 ----a-w- c:\windows\DIFxAPI.dll
2012-03-20 20:38 . 2012-03-20 20:38 -------- d-----w- c:\program files\Realtek
2012-03-20 20:38 . 2012-03-21 18:48 -------- d--h--w- c:\program files\Temp
2012-03-20 20:38 . 2011-12-13 10:01 1698408 ----a-w- c:\windows\RtlExUpd.dll
2012-03-20 20:38 . 2006-02-07 14:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2012-03-20 20:38 . 2006-02-07 14:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2012-03-20 20:38 . 2006-02-07 14:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2012-03-20 20:38 . 2005-11-13 22:19 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2012-03-20 20:38 . 2006-02-07 14:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2012-03-20 20:37 . 2012-03-20 20:37 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2012-03-20 20:37 . 2012-03-20 20:37 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2012-03-20 18:51 . 2012-03-20 18:51 -------- d-----w- C:\_OTM
2012-03-20 18:02 . 2012-03-20 18:03 -------- d-----w- c:\program files\trend micro
2012-03-20 18:02 . 2012-03-20 18:03 -------- d-----w- C:\rsit
2012-03-20 10:53 . 2012-02-08 06:03 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E7DE018F-5274-42F8-975E-FB6420A6EE31}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-23 08:18 . 2011-08-06 00:15 237072 ------w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 2153472]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe" [2010-08-20 33120]
"Badoo Desktop"="c:\programdata\Badoo\Badoo Desktop\1.6.48.1082\Badoo.Desktop.exe" [2011-10-05 1051760]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2011-08-14 273544]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"Free PDF Print Dispatcher"="c:\program files\pdfconverter.com\FreePDF Creator\itFPCPrnDisp.exe" [2010-01-15 25600]
"PDF Converter Elite Print Dispatcher"="c:\program files\pdfconverter.com\PDF Converter Elite\2009\pcSONPrnDisp.exe" [2009-11-13 53248]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-09-03 9726568]
.
c:\users\Fujitsu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2276910232-3662711445-3577571815-1000]
"EnableNotificationsRef"=dword:00000001
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Obsah adresáře 'Naplánované úlohy'
.
2012-03-21 c:\windows\Tasks\User_Feed_Synchronization-{6988E79D-E164-41EB-80F1-77A08E806A88}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:25]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=CZ&install_date=20120202&user_guid=25911049D01F4690ABE015EB48F28A6E&machine_id=7ea38354d014767be90e508d77aab06f&browser=IE&os=win&os_version=6.0-x86-SP1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-03-21 22:35
Windows 6.0.6001 Service Pack 1 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
Celkový čas: 2012-03-21 22:37:41
ComboFix-quarantined-files.txt 2012-03-21 21:37
ComboFix2.txt 2012-03-21 20:26
.
Před spuštěním: Volných bajtů: 39 012 884 480
Po spuštění: Volných bajtů: 38 977 245 184
.
- - End Of File - - 916E2ACFD73AB66F2D772A40443F5B19