Re: Prosím o kontrolu - nelze vyvolat správce úloh
Napsal: 18 dub 2012 23:42
Po restartu mi vyběhla aktualizace Avastu, ačkoliv je vypnutý, tak doufám, že to scan nijak neovlivnilo... 
ComboFix 12-04-18.02 - Radka 19.04.2012 0:29.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3036.2340 [GMT 2:00]
Spuštěný z: c:\documents and settings\Radka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Radka\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: PC Cleaner Pro *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\taskmgr.exe.exe"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\AdobeAAMUpdater-1.0-RADKA-PC-Radka.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-515967899-1801674531-1003Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-515967899-1801674531-1003UA.job"
"c:\windows\tasks\videopadShakeIcon.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\taskmgr.exe.exe
c:\windows\tasks\Adobe Flash Player Updater.job
c:\windows\tasks\AdobeAAMUpdater-1.0-RADKA-PC-Radka.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\videopadShakeIcon.job
.
c:\windows\system32\netsetup.exe . . . je infikován!!
.
c:\windows\system32\odbcconf.exe . . . je infikován!!
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Legacy_NMINDEXINGSERVICE
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_NMIndexingService
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-18 do 2012-04-18 )))))))))))))))))))))))))))))))
.
.
2012-04-18 19:35 . 2012-04-18 19:39 -------- d-----w- c:\program files\trend micro
2012-04-18 19:35 . 2012-04-18 19:36 -------- d-----w- C:\rsit
2012-04-17 19:30 . 2012-04-17 19:39 -------- d-----w- c:\documents and settings\Radka\Data aplikací\PCPro
2012-04-17 19:30 . 2012-04-17 19:30 -------- d-----w- c:\documents and settings\Radka\Data aplikací\PC Cleaners
2012-04-17 17:14 . 2005-09-23 20:18 171520 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2012-04-17 17:14 . 2012-04-17 17:14 -------- d-----w- c:\program files\Common Files\Pinnacle
2012-04-17 17:14 . 2012-04-17 17:14 -------- d-----w- c:\documents and settings\Radka\Local Settings\Data aplikací\Downloaded Installations
2012-04-17 17:13 . 2012-04-17 17:13 -------- d-----w- c:\documents and settings\Radka\Local Settings\Data aplikací\Pinnacle
2012-04-17 17:13 . 2012-04-17 17:18 -------- d-----w- c:\documents and settings\All Users\Data aplikac
2012-04-17 17:07 . 2012-04-17 17:07 -------- d-----w- c:\program files\Common Files\Pegasus Imaging
2012-04-17 17:07 . 2012-04-17 17:07 -------- d-----w- c:\program files\Common Files\Yahoo!
2012-04-17 17:01 . 2012-04-17 17:07 -------- d-----w- c:\program files\Pinnacle
2012-04-16 18:02 . 2012-04-16 18:02 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2012-04-14 05:43 . 2012-04-14 05:43 -------- d-----w- c:\program files\Sega
2012-04-13 14:47 . 2012-04-13 14:47 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-04-09 06:02 . 2012-04-14 06:38 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files\Internet Explorer\plugins\nppdf32.dll
2012-04-01 18:13 . 2012-04-18 20:01 -------- d-----w- c:\program files\Spybot - Search & Destroy
2012-04-01 17:25 . 2012-04-01 17:25 -------- d-----w- c:\program files\Loaris
2012-03-30 15:17 . 2012-03-30 15:17 -------- d-----w- c:\program files\NCH Software
2012-03-30 15:16 . 2012-03-30 15:16 -------- d-----w- c:\documents and settings\Radka\Data aplikací\NCH Software
2012-03-28 20:15 . 2012-03-28 20:15 -------- d-----w- C:\SSM
2012-03-28 19:57 . 2012-03-28 19:57 582144 ----a-w- c:\program files\Common Files\Microsoft Shared\DAO\DAO350.DLL
2012-03-28 19:57 . 2012-03-28 19:57 368912 ----a-w- c:\windows\system32\VBAR332.DLL
2012-03-28 19:57 . 2012-03-28 19:57 252176 ----a-w- c:\windows\system32\MSRD2X35.DLL
2012-03-28 19:57 . 2012-03-28 19:57 24848 ----a-w- c:\windows\system32\MSJTER35.DLL
2012-03-28 19:57 . 2012-03-28 19:57 123664 ----a-w- c:\windows\system32\MSJINT35.DLL
2012-03-28 19:57 . 2012-03-28 19:57 1045776 ----a-w- c:\windows\system32\MSJET35.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 06:38 . 2011-11-06 20:02 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-14 21:49 . 2012-03-14 04:46 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2012-03-14 04:50 . 2012-03-14 04:50 348256 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSTAHost\CorelPHOTOPAINT\9.0\1033\ResourceCache.dll
2012-03-14 04:48 . 2012-03-14 04:48 348256 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSTAHost\CorelDRAW\9.0\1033\ResourceCache.dll
2012-03-11 19:07 . 2012-03-11 19:08 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-11 19:07 . 2010-04-24 13:12 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-07 00:15 . 2011-03-16 15:33 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2009-12-03 22:19 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-03-16 15:33 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2009-12-03 22:19 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2009-12-03 22:19 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2009-12-03 22:19 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2009-12-03 22:19 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2009-12-03 22:19 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2009-12-03 22:19 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2009-12-03 22:19 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-03-01 10:59 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 10:59 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 10:59 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-14 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-02-23 08:18 . 2009-12-05 14:06 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-12 09:02 . 2012-02-08 11:22 188128 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2012-02-11 20:25 . 2011-09-09 19:32 473656 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-02-07 09:02 . 2012-02-07 09:02 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-06 10:21 . 2012-02-06 10:21 796672 ----a-w- c:\windows\GPInstall.exe
2012-02-03 09:57 . 2008-04-14 12:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 21:15 . 2012-03-14 21:15 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-18_21.19.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-18 22:35 . 2012-04-18 22:35 16384 c:\windows\temp\Perflib_Perfdata_ca0.dat
+ 2012-04-18 22:35 . 2012-04-18 22:35 16384 c:\windows\temp\Perflib_Perfdata_918.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"AccelerometerSysTrayApplet"="c:\windows\System32\accelerometerST.exe" [2009-01-22 82488]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-29 1545512]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-07-20 1044480]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Radka^Nabídka Start^Programy^Po spuštění^KvetinkaProzeny.lnk]
path=c:\documents and settings\Radka\Nabídka Start\Programy\Po spuštění\KvetinkaProzeny.lnk
backup=c:\windows\pss\KvetinkaProzeny.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Radka^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\Radka\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ActivControl]
2010-06-10 12:54 1092896 ----a-w- c:\program files\Activ Software\ActivDriver\ActivControl2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 17:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Input Device Main Program]
2008-10-16 23:22 356352 -c--a-w- c:\program files\HP\HP Wireless Comfort Mouse\TSR\xDaemon.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\QIP Infium JadrisPack\\qip.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DsNET Corp\\aTube Catcher 2.0\\yct.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Cisco Packet Tracer 5.3.3\\bin\\PacketTracer5.exe"=
"c:\\Documents and Settings\\Radka\\Plocha\\Prográmky\\uTorrent.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\umi.exe"=
.
R0 phmcd;phmcd;c:\windows\system32\drivers\phmcd.sys [14.6.2010 5:22 47056]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28.3.2008 12:14 24064]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16.3.2011 17:33 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4.12.2009 0:19 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [13.4.2012 16:47 242240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4.12.2009 0:19 20696]
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [6.2.2010 16:10 164992]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [19.9.2010 8:54 20328]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [6.2.2010 16:10 12544]
R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [14.4.2008 14:00 14336]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\drivers\activhidsermini.sys [26.5.2010 15:20 74752]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [1.12.2009 12:00 228408]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\drivers\activmouse.sys [26.5.2010 15:21 6144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 14:16 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [9.4.2012 8:02 253088]
S3 HpStm001;USB Style Packet Filter Driver;c:\windows\system32\drivers\HpStm001.sys [24.12.2009 22:07 11264]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25.6.2010 19:07 35088]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 13:37 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 14:16 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [23.7.2009 5:08 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30.3.2009 4:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30.3.2009 4:23 366936]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
yksvcs REG_MULTI_SZ yksvc
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
TCP: DhcpNameServer = 62.204.224.2 62.240.163.170 62.204.224.3
FF - ProfilePath - c:\documents and settings\Radka\Data aplikací\Mozilla\Firefox\Profiles\lkcion54.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-19 00:36
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1136)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3316)
c:\windows\system32\msi.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\System32\snmp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2012-04-19 00:40:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-18 22:40
ComboFix2.txt 2012-04-18 21:23
.
Před spuštěním: Volných bajtů: 37 111 758 848
Po spuštění: Volných bajtů: 36 877 545 472
.
- - End Of File - - 981C659BC542448CEE87CA938788D1A4

ComboFix 12-04-18.02 - Radka 19.04.2012 0:29.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3036.2340 [GMT 2:00]
Spuštěný z: c:\documents and settings\Radka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Radka\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: PC Cleaner Pro *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\windows\taskmgr.exe.exe"
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\AdobeAAMUpdater-1.0-RADKA-PC-Radka.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-515967899-1801674531-1003Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-515967899-1801674531-1003UA.job"
"c:\windows\tasks\videopadShakeIcon.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\taskmgr.exe.exe
c:\windows\tasks\Adobe Flash Player Updater.job
c:\windows\tasks\AdobeAAMUpdater-1.0-RADKA-PC-Radka.job
c:\windows\tasks\GoogleUpdateTaskMachineCore.job
c:\windows\tasks\GoogleUpdateTaskMachineUA.job
c:\windows\tasks\videopadShakeIcon.job
.
c:\windows\system32\netsetup.exe . . . je infikován!!
.
c:\windows\system32\odbcconf.exe . . . je infikován!!
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Legacy_NMINDEXINGSERVICE
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_NMIndexingService
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-18 do 2012-04-18 )))))))))))))))))))))))))))))))
.
.
2012-04-18 19:35 . 2012-04-18 19:39 -------- d-----w- c:\program files\trend micro
2012-04-18 19:35 . 2012-04-18 19:36 -------- d-----w- C:\rsit
2012-04-17 19:30 . 2012-04-17 19:39 -------- d-----w- c:\documents and settings\Radka\Data aplikací\PCPro
2012-04-17 19:30 . 2012-04-17 19:30 -------- d-----w- c:\documents and settings\Radka\Data aplikací\PC Cleaners
2012-04-17 17:14 . 2005-09-23 20:18 171520 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2012-04-17 17:14 . 2012-04-17 17:14 -------- d-----w- c:\program files\Common Files\Pinnacle
2012-04-17 17:14 . 2012-04-17 17:14 -------- d-----w- c:\documents and settings\Radka\Local Settings\Data aplikací\Downloaded Installations
2012-04-17 17:13 . 2012-04-17 17:13 -------- d-----w- c:\documents and settings\Radka\Local Settings\Data aplikací\Pinnacle
2012-04-17 17:13 . 2012-04-17 17:18 -------- d-----w- c:\documents and settings\All Users\Data aplikac
2012-04-17 17:07 . 2012-04-17 17:07 -------- d-----w- c:\program files\Common Files\Pegasus Imaging
2012-04-17 17:07 . 2012-04-17 17:07 -------- d-----w- c:\program files\Common Files\Yahoo!
2012-04-17 17:01 . 2012-04-17 17:07 -------- d-----w- c:\program files\Pinnacle
2012-04-16 18:02 . 2012-04-16 18:02 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2012-04-14 05:43 . 2012-04-14 05:43 -------- d-----w- c:\program files\Sega
2012-04-13 14:47 . 2012-04-13 14:47 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-04-09 06:02 . 2012-04-14 06:38 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2012-04-04 05:53 . 2012-04-04 05:53 182160 ----a-w- c:\program files\Internet Explorer\plugins\nppdf32.dll
2012-04-01 18:13 . 2012-04-18 20:01 -------- d-----w- c:\program files\Spybot - Search & Destroy
2012-04-01 17:25 . 2012-04-01 17:25 -------- d-----w- c:\program files\Loaris
2012-03-30 15:17 . 2012-03-30 15:17 -------- d-----w- c:\program files\NCH Software
2012-03-30 15:16 . 2012-03-30 15:16 -------- d-----w- c:\documents and settings\Radka\Data aplikací\NCH Software
2012-03-28 20:15 . 2012-03-28 20:15 -------- d-----w- C:\SSM
2012-03-28 19:57 . 2012-03-28 19:57 582144 ----a-w- c:\program files\Common Files\Microsoft Shared\DAO\DAO350.DLL
2012-03-28 19:57 . 2012-03-28 19:57 368912 ----a-w- c:\windows\system32\VBAR332.DLL
2012-03-28 19:57 . 2012-03-28 19:57 252176 ----a-w- c:\windows\system32\MSRD2X35.DLL
2012-03-28 19:57 . 2012-03-28 19:57 24848 ----a-w- c:\windows\system32\MSJTER35.DLL
2012-03-28 19:57 . 2012-03-28 19:57 123664 ----a-w- c:\windows\system32\MSJINT35.DLL
2012-03-28 19:57 . 2012-03-28 19:57 1045776 ----a-w- c:\windows\system32\MSJET35.DLL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 06:38 . 2011-11-06 20:02 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-14 21:49 . 2012-03-14 04:46 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2012-03-14 04:50 . 2012-03-14 04:50 348256 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSTAHost\CorelPHOTOPAINT\9.0\1033\ResourceCache.dll
2012-03-14 04:48 . 2012-03-14 04:48 348256 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSTAHost\CorelDRAW\9.0\1033\ResourceCache.dll
2012-03-11 19:07 . 2012-03-11 19:08 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-11 19:07 . 2010-04-24 13:12 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-07 00:15 . 2011-03-16 15:33 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2009-12-03 22:19 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-03-16 15:33 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2009-12-03 22:19 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2009-12-03 22:19 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2009-12-03 22:19 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2009-12-03 22:19 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2009-12-03 22:19 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2009-12-03 22:19 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2009-12-03 22:19 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-03-01 10:59 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 10:59 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-01 10:59 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-14 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-02-23 08:18 . 2009-12-05 14:06 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-12 09:02 . 2012-02-08 11:22 188128 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VCSExpress\10.0\1033\ResourceCache.dll
2012-02-11 20:25 . 2011-09-09 19:32 473656 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-02-07 09:02 . 2012-02-07 09:02 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-06 10:21 . 2012-02-06 10:21 796672 ----a-w- c:\windows\GPInstall.exe
2012-02-03 09:57 . 2008-04-14 12:00 1860096 ----a-w- c:\windows\system32\win32k.sys
2012-03-14 21:15 . 2012-03-14 21:15 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-18_21.19.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-18 22:35 . 2012-04-18 22:35 16384 c:\windows\temp\Perflib_Perfdata_ca0.dat
+ 2012-04-18 22:35 . 2012-04-18 22:35 16384 c:\windows\temp\Perflib_Perfdata_918.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"AccelerometerSysTrayApplet"="c:\windows\System32\accelerometerST.exe" [2009-01-22 82488]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-29 1545512]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-07-20 1044480]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-12-11 604776]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Radka^Nabídka Start^Programy^Po spuštění^KvetinkaProzeny.lnk]
path=c:\documents and settings\Radka\Nabídka Start\Programy\Po spuštění\KvetinkaProzeny.lnk
backup=c:\windows\pss\KvetinkaProzeny.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Radka^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\Radka\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ActivControl]
2010-06-10 12:54 1092896 ----a-w- c:\program files\Activ Software\ActivDriver\ActivControl2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2009-02-26 17:36 30040 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Input Device Main Program]
2008-10-16 23:22 356352 -c--a-w- c:\program files\HP\HP Wireless Comfort Mouse\TSR\xDaemon.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TrackMania Sunrise\\TmSunrise.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\QIP Infium JadrisPack\\qip.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DsNET Corp\\aTube Catcher 2.0\\yct.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Cisco Packet Tracer 5.3.3\\bin\\PacketTracer5.exe"=
"c:\\Documents and Settings\\Radka\\Plocha\\Prográmky\\uTorrent.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 15\\Programs\\umi.exe"=
.
R0 phmcd;phmcd;c:\windows\system32\drivers\phmcd.sys [14.6.2010 5:22 47056]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28.3.2008 12:14 24064]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R0 sptd;sptd;\SystemRoot\\SystemRoot\System32\Drivers\sptd.sys --> \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [?]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16.3.2011 17:33 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4.12.2009 0:19 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [13.4.2012 16:47 242240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4.12.2009 0:19 20696]
R2 athsgt;athsgt;c:\windows\system32\drivers\athsgt.sys [6.2.2010 16:10 164992]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [19.9.2010 8:54 20328]
R2 limsgt;limsgt;c:\windows\system32\drivers\limsgt.sys [6.2.2010 16:10 12544]
R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [14.4.2008 14:00 14336]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\drivers\activhidsermini.sys [26.5.2010 15:20 74752]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [1.12.2009 12:00 228408]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\drivers\activmouse.sys [26.5.2010 15:21 6144]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 14:16 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [9.4.2012 8:02 253088]
S3 HpStm001;USB Style Packet Filter Driver;c:\windows\system32\drivers\HpStm001.sys [24.12.2009 22:07 11264]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25.6.2010 19:07 35088]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19.2.2010 13:37 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 14:16 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [23.7.2009 5:08 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [30.3.2009 4:09 239336]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [30.3.2009 4:23 366936]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
yksvcs REG_MULTI_SZ yksvc
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} -
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
TCP: DhcpNameServer = 62.204.224.2 62.240.163.170 62.204.224.3
FF - ProfilePath - c:\documents and settings\Radka\Data aplikací\Mozilla\Firefox\Profiles\lkcion54.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-19 00:36
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1136)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3316)
c:\windows\system32\msi.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\System32\snmp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2012-04-19 00:40:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-04-18 22:40
ComboFix2.txt 2012-04-18 21:23
.
Před spuštěním: Volných bajtů: 37 111 758 848
Po spuštění: Volných bajtů: 36 877 545 472
.
- - End Of File - - 981C659BC542448CEE87CA938788D1A4