takze tady je pozadovany log
ComboFix 08-11-20.02 - Krejčík 2008-11-21 14:54:09.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.826 [GMT 1:00]
Spuštěný z: e:\documents and settings\Krejčík\Plocha\ComboFix.exe
* Vytvořen nový Bod Obnovení
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\Krejčík\Local Settings\Temporary Internet Files\REG.EXE
e:\documents and settings\Krejčík\Local Settings\Temporary Internet Files\UN32.EXE
e:\documents and settings\Krejčík\Local Settings\Temporary Internet Files\UN32.INI
.
((((((((((((((((((((((((( Soubory vytvořené od 2008-10-21 do 2008-11-21 )))))))))))))))))))))))))))))))
.
2008-11-21 14:11 . 2008-11-21 14:11 578,560 --a--c--- e:\windows\system32\dllcache\user32.dll
2008-11-21 14:10 . 2008-11-21 14:10 <DIR> d-------- e:\windows\ERUNT
2008-11-21 14:05 . 2008-11-21 14:28 <DIR> d-------- E:\SDFix
2008-11-20 20:29 . 2008-11-20 20:29 <DIR> d-------- e:\documents and settings\Krejčík\DoctorWeb
2008-11-20 20:29 . 2008-11-20 20:29 <DIR> d-------- e:\documents and settings\Krejčík\DoctorWeb
2008-11-14 15:41 . 2008-11-14 16:00 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DiskAid
2008-11-14 15:41 . 2008-11-14 16:00 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DiskAid
2008-11-14 15:41 . 2008-11-14 16:00 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DiskAid
2008-11-12 11:39 . 2008-09-04 18:17 1,106,944 -----c--- e:\windows\system32\dllcache\msxml3.dll
2008-11-12 11:39 . 2008-10-24 12:21 455,296 -----c--- e:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 19:19 . 2008-11-11 19:19 <DIR> d-------- e:\program files\iTunes
2008-11-11 19:19 . 2008-11-11 19:19 <DIR> d-------- e:\program files\iPod
2008-11-11 19:19 . 2008-11-11 19:19 <DIR> d-------- e:\documents and settings\All Users\Data aplikací\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-11 19:19 . 2008-04-17 13:12 107,368 --a------ e:\windows\system32\GEARAspi.dll
2008-11-11 19:19 . 2008-04-17 13:12 15,464 --a------ e:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-11 13:48 . 2008-11-11 13:48 <DIR> d-------- e:\program files\Bonjour
2008-11-11 13:47 . 2008-11-11 13:48 <DIR> d-------- e:\program files\QuickTime
2008-11-11 13:45 . 2008-11-11 13:45 <DIR> d-------- e:\program files\Apple Software Update
2008-11-08 20:13 . 2008-11-08 20:13 <DIR> d-------- e:\program files\DVDVideoSoft
2008-11-08 20:11 . 2008-11-08 20:13 7,974,075 --a------ e:\temp\FreeVideoToiPodConverter.exe
2008-11-08 20:10 . 2008-11-08 20:11 <DIR> d-------- E:\Temp
2008-11-08 19:10 . 2008-11-08 20:40 <DIR> d-------- e:\program files\ChrisTV PVR
2008-11-08 19:10 . 2007-02-07 11:01 22 --a------ e:\windows\system32\wnpa32.sys
2008-11-08 18:59 . 2008-11-08 19:01 <DIR> d-------- e:\program files\ChrisTV Online
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\UC.PIF
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\RAR.PIF
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\PKZIP.PIF
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\PKUNZIP.PIF
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\NOCLOSE.PIF
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\LHA.PIF
2008-11-08 12:27 . 2008-08-08 07:04 545 --a------ e:\windows\ARJ.PIF
2008-11-08 12:27 . 2008-11-08 12:28 542 --a------ e:\windows\wincmd.ini
2008-11-07 13:09 . 2008-11-07 13:09 <DIR> d-------- e:\program files\Cenega Czech
2008-11-05 20:05 . 2008-11-05 21:14 <DIR> d-------- e:\program files\Autodesk
2008-11-05 20:05 . 2008-11-05 20:05 <DIR> d-------- e:\documents and settings\All Users\Data aplikací\Autodesk, Inc
2008-11-05 19:56 . 2008-11-18 18:28 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\Autodesk
2008-11-05 19:56 . 2008-11-18 18:28 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\Autodesk
2008-11-05 19:56 . 2008-11-18 18:28 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\Autodesk
2008-11-05 19:55 . 2008-11-05 19:57 <DIR> d-------- e:\program files\DWG TrueView 2009
2008-11-05 19:55 . 2008-11-05 21:14 <DIR> d-------- e:\documents and settings\All Users\Data aplikací\Autodesk
2008-11-02 00:18 . 2008-11-02 09:11 664 --a------ e:\windows\system32\d3d9caps.dat
2008-11-01 23:34 . 2008-11-05 20:54 <DIR> d-------- e:\program files\Common Files\Autodesk Shared
2008-11-01 23:34 . 2008-11-05 19:59 <DIR> d-------- e:\program files\AOEMView 2009
2008-11-01 19:24 . 2008-11-01 19:24 <DIR> d-------- e:\program files\Google
2008-11-01 11:59 . 2008-11-09 13:02 <DIR> d-------- e:\program files\SopCast
2008-10-31 19:16 . 2008-10-31 19:25 <DIR> d-------- e:\program files\Orb Networks
2008-10-29 18:33 . 2008-10-29 18:38 <DIR> d-------- e:\windows\NV26322572.TMP
2008-10-29 13:44 . 2008-10-29 13:44 <DIR> d-------- e:\program files\Trend Micro
2008-10-28 11:02 . 2008-10-28 11:02 <DIR> d-------- e:\windows\system32\LogFiles
2008-10-24 21:13 . 2008-11-20 14:15 69 --a------ e:\windows\NeroDigital.ini
2008-10-24 14:03 . 2008-10-24 14:03 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\SolidWorksNewsReader
2008-10-24 14:03 . 2008-10-24 14:03 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\SolidWorksNewsReader
2008-10-24 14:03 . 2008-10-24 14:03 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\SolidWorksNewsReader
2008-10-24 14:02 . 2008-11-18 19:36 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\SolidWorks
2008-10-24 14:02 . 2008-11-18 19:36 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\SolidWorks
2008-10-24 14:02 . 2008-11-18 19:36 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\SolidWorks
2008-10-24 14:00 . 2008-10-24 14:00 0 --a------ e:\windows\eDrawingOfficeAutomator.INI
2008-10-24 13:59 . 2008-10-24 13:59 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DWGeditor
2008-10-24 13:59 . 2008-10-24 13:59 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DWGeditor
2008-10-24 13:59 . 2008-10-24 13:59 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DWGeditor
2008-10-24 13:57 . 2008-10-24 13:58 <DIR> d-------- e:\program files\SolidWorks Installation Manager
2008-10-24 13:57 . 2004-11-05 10:08 670,208 --a------ e:\windows\system32\drivers\hardlock.sys
2008-10-24 13:56 . 2008-10-24 13:56 23 --ah----- e:\windows\yacht.xws
2008-10-24 13:55 . 2008-10-24 13:59 <DIR> d-------- e:\program files\Common Files\eDrawings2007
2008-10-24 13:52 . 2008-10-24 13:52 <DIR> d-------- e:\windows\system32\GroupPolicy
2008-10-24 13:50 . 2008-10-24 14:00 <DIR> d-------- e:\program files\Common Files\SolidWorks Shared
2008-10-24 13:49 . 2008-10-24 14:02 <DIR> d-------- e:\program files\SolidWorks
2008-10-24 13:49 . 2008-10-24 13:49 <DIR> d-------- e:\program files\Common Files\Solidworks Data
2008-10-24 13:44 . 2008-10-24 13:44 42 --a------ e:\windows\trailer.xws
2008-10-24 11:56 . 2008-10-15 17:38 337,408 -----c--- e:\windows\system32\dllcache\netapi32.dll
2008-10-23 16:12 . 2008-10-23 16:12 107,888 --a------ e:\windows\system32\CmdLineExt.dll
2008-10-23 16:11 . 2008-10-23 16:11 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\Leadertech
2008-10-23 16:11 . 2008-10-23 16:11 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\Leadertech
2008-10-23 16:11 . 2008-10-23 16:11 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\Leadertech
2008-10-23 15:54 . 2008-10-23 16:13 <DIR> d-------- e:\program files\EA Sports
2008-10-23 15:54 . 2008-03-05 14:56 3,786,760 --a------ e:\windows\system32\D3DX9_37.dll
2008-10-23 15:54 . 2007-05-16 15:45 3,497,832 --a------ e:\windows\system32\d3dx9_34.dll
2008-10-23 15:54 . 2007-03-12 15:42 3,495,784 --a------ e:\windows\system32\d3dx9_33.dll
2008-10-23 15:54 . 2006-11-29 12:06 3,426,072 --a------ e:\windows\system32\d3dx9_32.dll
2008-10-23 15:54 . 2006-09-28 15:05 2,414,360 --a------ e:\windows\system32\d3dx9_31.dll
2008-10-23 15:54 . 2007-04-04 17:53 81,768 --a------ e:\windows\system32\xinput1_3.dll
2008-10-23 15:51 . 2008-10-23 15:51 <DIR> d-------- e:\program files\DAEMON Tools Toolbar
2008-10-23 15:49 . 2008-10-23 15:51 <DIR> d-------- e:\program files\DAEMON Tools Lite
2008-10-23 15:47 . 2008-10-23 15:47 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DAEMON Tools
2008-10-23 15:47 . 2008-10-23 15:47 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DAEMON Tools
2008-10-23 15:47 . 2008-10-23 15:47 <DIR> d-------- e:\documents and settings\Krejčík\Data aplikací\DAEMON Tools
2008-10-23 15:47 . 2008-10-23 15:47 717,296 --a------ e:\windows\system32\drivers\sptd.sys
2008-10-23 15:30 . 2008-10-04 11:22 4,713,709,568 --a------ E:\FIFA09CZ.iso
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 13:54 --------- d-----w e:\program files\ESET
2008-11-21 13:50 --------- d-----w e:\program files\lg_fwupdate
2008-11-11 12:47 --------- d-----w e:\program files\Common Files\Apple
2008-11-08 19:40 --------- d-----w e:\program files\ChrisTV PVR
2008-11-08 19:14 --------- d-----w e:\program files\Common Files\DVDVideoSoft
2008-10-24 11:21 455,296 ----a-w e:\windows\system32\drivers\mrxsmb.sys
2008-10-19 18:15 --------- d-----w e:\program files\MediaCoder iPhone Edition
2008-10-18 09:41 --------- d-----w e:\program files\MSXML 4.0
2008-10-18 08:32 --------- d-----w e:\program files\Microsoft SQL Server
2008-10-18 08:29 --------- d-----w e:\program files\Microsoft.NET
2008-10-18 08:27 --------- d-----w e:\program files\MSXML 6.0
2008-10-18 07:26 --------- d-----w e:\program files\Microsoft WSE
2008-10-18 07:03 --------- d-----w e:\program files\MSBuild
2008-10-18 06:58 --------- d-----w e:\program files\Reference Assemblies
2008-10-17 15:35 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\IrfanView
2008-10-17 15:35 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\IrfanView
2008-10-17 15:35 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\IrfanView
2008-10-16 13:28 --------- d-----w e:\program files\Any Video Converter
2008-10-16 13:28 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Any Video Converter
2008-10-16 13:28 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Any Video Converter
2008-10-16 13:28 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Any Video Converter
2008-10-16 13:13 202,776 ----a-w e:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w e:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w e:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w e:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w e:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w e:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w e:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w e:\windows\system32\wups.dll
2008-10-16 12:57 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\gtk-2.0
2008-10-16 12:57 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\gtk-2.0
2008-10-16 12:57 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\gtk-2.0
2008-10-16 12:51 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\avidemux
2008-10-16 12:51 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\avidemux
2008-10-16 12:51 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\avidemux
2008-10-16 09:38 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Ahead
2008-10-16 09:38 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Ahead
2008-10-16 09:38 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Ahead
2008-10-16 09:32 --------- d-----w e:\program files\Common Files\Ahead
2008-10-16 09:30 --------- d-----w e:\program files\Nero
2008-10-16 09:30 --------- d-----w e:\documents and settings\All Users\Data aplikací\Nero
2008-10-16 09:01 --------- d--h--w e:\program files\InstallShield Installation Information
2008-10-15 18:17 --------- d-----w e:\program files\Xvid CZ
2008-10-15 18:16 729,088 ----a-w e:\windows\iun6002.exe
2008-10-15 18:16 --------- d-----w e:\program files\Codec Pack - VobSub
2008-10-14 19:59 264,097 ----a-w e:\windows\PDFCreator_Toolbar_Uninstaller_9822.exe
2008-10-14 19:59 --------- d-----w e:\program files\PDFCreator Toolbar
2008-10-14 19:59 --------- d-----w e:\program files\PDFCreator
2008-10-13 18:49 --------- d-----w e:\program files\Plato Video Converter
2008-10-13 16:59 --------- d-----w e:\documents and settings\All Users\Data aplikací\NVIDIA
2008-10-12 19:03 512,096 ----a-w e:\windows\system32\drivers\amon.sys
2008-10-12 19:03 298,104 ----a-w e:\windows\system32\imon.dll
2008-10-12 19:03 15,424 ----a-w e:\windows\system32\drivers\nod32drv.sys
2008-10-12 11:31 --------- d-----w e:\program files\Miranda IM
2008-10-11 18:24 --------- d-----w e:\program files\Common Files\Ulead Systems
2008-10-11 18:23 --------- d-----w e:\program files\WinFast
2008-10-11 18:23 --------- d-----w e:\documents and settings\All Users\Data aplikací\Ulead Systems
2008-10-11 13:43 --------- d-----w e:\program files\OneClick iPhone Video Converter
2008-10-11 13:09 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\vlc
2008-10-11 13:09 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\vlc
2008-10-11 13:09 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\vlc
2008-10-11 13:08 --------- d-----w e:\program files\VideoLAN
2008-10-11 13:05 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\BSplayer PRO
2008-10-11 13:05 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\BSplayer PRO
2008-10-11 13:05 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\BSplayer PRO
2008-10-11 13:04 --------- d-----w e:\program files\Webteh
2008-10-11 13:00 --------- d-----w e:\program files\DVD X Studios
2008-10-11 13:00 --------- d-----w e:\documents and settings\All Users\Data aplikací\DVD X Studios
2008-10-11 09:41 --------- d-----w e:\program files\AllerCalc
2008-10-11 07:49 --------- d-----w e:\program files\Lavasoft
2008-10-11 07:49 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Lavasoft
2008-10-11 07:49 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Lavasoft
2008-10-11 07:49 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Lavasoft
2008-10-10 21:32 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Apple Computer
2008-10-10 21:32 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Apple Computer
2008-10-10 21:32 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Apple Computer
2008-10-10 21:21 --------- d-----w e:\documents and settings\All Users\Data aplikací\Apple Computer
2008-10-10 21:19 --------- d-----w e:\documents and settings\All Users\Data aplikací\Apple
2008-10-10 20:57 --------- d-----w e:\program files\Common Files\Adobe
2008-10-10 20:53 --------- d-----w e:\program files\Verlag Dashöfer s.r.o
2008-10-10 20:41 --------- d-----w e:\program files\Common Files\Borland Shared
2008-10-10 20:35 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\DIMAGE
2008-10-10 20:35 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\DIMAGE
2008-10-10 20:35 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\DIMAGE
2008-10-10 20:34 --------- d-----w e:\program files\DiMAGE Viewer
2008-10-10 20:34 --------- d-----w e:\program files\Common Files\InstallShield
2008-10-10 19:46 --------- d-----w e:\program files\microsoft frontpage
2008-10-10 19:33 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Microsoft Web Folders
2008-10-10 19:33 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Microsoft Web Folders
2008-10-10 19:33 --------- d-----w e:\documents and settings\Krejčík\Data aplikací\Microsoft Web Folders
2008-10-10 19:22 --------- d-----w e:\program files\VIA Technologies, INC
2008-10-10 19:12 --------- d-----w e:\documents and settings\All Users\Data aplikací\ESET
2008-10-10 19:07 --------- d-----w e:\program files\IrfanView
2008-10-10 18:44 --------- d-----w e:\program files\My Company Name
2008-09-30 15:43 1,286,152 ----a-w e:\windows\system32\msxml4.dll
2008-09-15 15:27 1,846,400 ----a-w e:\windows\system32\win32k.sys
2008-09-10 01:16 1,307,648 ------w e:\windows\system32\msxml6.dll
2008-09-04 17:17 1,106,944 ----a-w e:\windows\system32\msxml3.dll
2008-08-29 09:18 87,336 ----a-w e:\windows\system32\dns-sd.exe
2008-08-29 08:53 61,440 ----a-w e:\windows\system32\dnssd.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"AllerCalc"="e:\program files\AllerCalc\AllerCalc.exe" [2000-08-22 560408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="e:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
"DAEMON Tools Lite"="e:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"WinFast Schedule"="e:\program files\WinFast\WFTVFM\WFWIZ.exe" [2004-08-02 176128]
"nod32kui"="e:\program files\Eset\nod32kui.exe" [2008-10-12 949376]
"LGODDFU"="e:\program files\lg_fwupdate\fwupdate.exe" [2005-04-12 229376]
"NeroFilterCheck"="e:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"AppleSyncNotifier"="e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"nwiz"="nwiz.exe" [2008-09-17 e:\windows\system32\nwiz.exe]
"emMON"="emMON.exe" [2006-05-30 e:\windows\emMON.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
e:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - e:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-18 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\Miranda IM\\miranda32.exe"=
"e:\\Program Files\\SopCast\\SopCast.exe"=
"e:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"e:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
R2 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT);"e:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sAUTODESKVAULT [2008-01-22 29178224]
R3 PSched;Plánovač paketů technologie QoS;e:\windows\system32\DRIVERS\psched.sys [2004-08-04 69120]
R3 WFIOCTL;WFIOCTL;\??\e:\program files\WinFast\WFTVFM\WFIOCTL.SYS [2008-10-11 9510]
S3 USB28xxBGA;USB 2820 Device;e:\windows\system32\DRIVERS\emBDA.sys [2006-09-12 292864]
S3 USB28xxOEM;USB 28xx OEM Filter;e:\windows\system32\DRIVERS\emOEM.sys [2006-08-21 7168]
*Newly Created Service* - PROCEXP90
.
.
------- Doplňkový sken -------
.
FireFox -: Profile - e:\documents and settings\Krejčík\Data aplikací\Mozilla\Firefox\Profiles\qllv7dg0.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://
www.seznam.cz/
FF -: plugin - e:\program files\iTunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-21 14:55:45
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
e:\docume~1\KREJK~1\LOCALS~1\Temp\RGI596.tmp
sken byl úspešně dokončen
skryté soubory: 1
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
PROCES: e:\windows\system32\lsass.exe
-> e:\program files\Eset\pr_imon.dll
.
Celkový čas: 2008-11-21 14:57:01
ComboFix-quarantined-files.txt 2008-11-21 13:56:33
Před spuštěním: Volných bajtů: 101 993 218 048
Po spuštění: Volných bajtů: 101,983,457,280
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
e:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
284 --- E O F --- 2008-11-12 21:01:55