Re: Preventivka - zpomaleny pocitac
Napsal: 24 pro 2012 11:35
K restartu nedoslo
ComboFix 12-12-23.01 - Helena Polášková 24.12.2012 11:25:10.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.450 [GMT 1:00]
Spuštěný z: c:\documents and settings\Helena PolßÜkovß\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2013 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\8657bf86d1550058.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\b0faab6cd511c65a.fb
c:\windows\system32\Cache\b6686a3e36a77030.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\cf90e697fd10f290.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-24 do 2012-12-24 )))))))))))))))))))))))))))))))
.
.
2012-12-24 10:08 . 2012-12-24 10:08 -------- d-----w- c:\program files\CrystalDiskInfo
2012-12-24 09:43 . 2012-12-24 09:43 -------- d-----w- C:\_OTL
2012-12-24 08:53 . 2012-12-24 08:53 512 ----a-w- C:\PhysicalMBR.bin
2012-12-23 23:57 . 2012-12-23 23:57 -------- d-----w- c:\program files\Defraggler
2012-12-23 23:28 . 2012-12-23 23:28 -------- d-----w- c:\documents and settings\Administrator
2012-12-23 19:44 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-23 19:44 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-23 19:44 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-23 19:44 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-12-23 19:44 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-23 19:44 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-12-23 19:44 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-12-23 19:44 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-12-23 19:43 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-23 19:43 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-23 19:42 . 2012-12-23 19:42 -------- d-----w- c:\program files\AVAST Software
2012-12-23 19:42 . 2012-12-23 19:42 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-12-23 18:40 . 2012-12-23 22:39 -------- d-----w- c:\program files\trend micro
2012-12-23 14:45 . 2012-12-23 14:45 -------- d-----w- c:\program files\WinDirStat
2012-12-23 14:32 . 2012-12-23 14:32 -------- d-----w- c:\program files\CCleaner
2012-12-13 13:30 . 2012-12-13 13:30 5955856 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-12-06 09:42 . 2012-12-06 09:42 -------- d-----w- c:\program files\Common Files\Skype
2012-12-04 19:37 . 2012-12-04 19:37 -------- d-sh--w- c:\documents and settings\LogMeInRemoteUser\IETldCache
2012-12-01 18:50 . 2012-12-01 18:50 -------- d-----w- c:\documents and settings\Helena Polášková\Data aplikací\TuneUp Software
2012-12-01 18:44 . 2012-12-01 18:44 -------- d-----w- c:\documents and settings\Helena Polášková\Local Settings\Data aplikací\MFAData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-17 20:11 . 2012-12-17 20:11 15895 ----a-w- C:\MzIB1210,Zuzana_Vindišová_-_SV_klimatizace.zip
2012-12-17 19:59 . 2012-12-17 19:59 16315 ----a-w- C:\MzIB1210,Zetocha_Roman.zip
2012-12-17 19:53 . 2012-12-17 19:53 17239 ----a-w- C:\MzIB1210,Aure_services_s,r,o,.zip
2012-12-16 12:23 . 2008-04-14 12:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-18 19:00 . 2012-11-18 19:00 16378 ----a-w- C:\MzIB1209,Zetocha_Roman.zip
2012-11-18 18:43 . 2012-11-18 18:43 15952 ----a-w- C:\MzIB1209,Zuzana_Vindišová_-_SV_klimatizace.zip
2012-11-18 17:52 . 2012-09-10 21:07 17340 ----a-w- C:\MzIB1207,Aure_services_s,r,o,.zip
2012-11-13 11:55 . 2008-04-14 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-11 19:37 . 2008-10-31 13:42 83912 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-11-11 19:37 . 2008-10-31 13:42 92072 ----a-w- c:\windows\system32\LMIinit.dll
2012-11-04 19:46 . 2012-11-04 19:46 17184 ----a-w- C:\MzIB1209,Aure_services_s,r,o,.zip
2012-11-02 02:03 . 2008-04-14 12:00 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:12 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:12 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-11-01 12:12 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-10-25 10:57 . 2012-10-25 10:57 15874 ----a-w- C:\MzIB1208,Zuzana_Vindišová_-_SV_klimatizace.zip
2012-10-25 10:54 . 2012-10-25 10:54 16303 ----a-w- C:\MzIB1208,Zetocha_Roman.zip
2012-10-22 19:23 . 2012-10-22 19:23 17198 ----a-w- C:\MzIB1208,Aure_services_s,r,o,.zip
2012-10-02 18:04 . 2008-04-14 12:00 58368 ----a-w- c:\windows\system32\synceng.dll
2012-10-01 17:49 . 2012-10-01 17:49 15116 ----a-w- C:\MzIB1203,Tomáš_Nykl.zip
2012-10-01 17:46 . 2012-10-01 17:46 16485 ----a-w- C:\MzIB1202,Tomáš_Nykl.zip
2012-11-12 13:20 . 2012-11-12 13:20 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"nwiz"="nwiz.exe" [2008-09-17 1657376]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-19 16858112]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2005-10-04 997042]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2005-10-04 118784]
"Print2PDF Print Monitor"="c:\program files\Software602\Print2PDF\Print2PDF.exe" [2011-10-04 220992]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-11-11 19:37 92072 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^Helena Polášková^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Helena Polášková\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA PagePro 1300WStatusDisplay]
2004-04-13 13:26 151552 ----a-w- c:\windows\system32\MSTMON_N.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\soft602\\langserv.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [23.12.2012 20:44 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [23.12.2012 20:44 361032]
R2 602XML Updater;602Updater;c:\program files\Common Files\soft602\602updsvc\602updsvc.exe [10.10.2011 12:55 85344]
R2 Aladdin SQL Server;Aladdin SQL Server;c:\program files\Aladdin\Aladdin SQL Server\AladdinSQL.exe [9.10.2009 22:09 140736]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.12.2012 20:44 21256]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [18.7.2003 10:55 18848]
R2 MSSQL$MSOFT;SQL Server (MSOFT);c:\mssql2005express\MSSQL.1\MSSQL\Binn\sqlservr.exe -sMSOFT --> c:\mssql2005express\MSSQL.1\MSSQL\Binn\sqlservr.exe -sMSOFT [?]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [29.10.2010 20:34 374704]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys --> c:\program files\LogMeIn\x86\RaInfo.sys [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-24 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-12-23 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Helena Polášková\Data aplikací\Mozilla\Firefox\Profiles\ljs0f6qj.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2012-12-23 20:44; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: !HIDDEN! 2009-08-07 22:56; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2009-12-02 09:23; {800b5000-a755-47e1-992b-48a1c1357f07}; c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-12-24 11:32
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\relog_ap.dll
.
Celkový čas: 2012-12-24 11:34:05
ComboFix-quarantined-files.txt 2012-12-24 10:34
.
Před spuštěním: Volných bajtů: 113 671 520 256
Po spuštění: Volných bajtů: 113 740 009 472
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 604971A9A02E793ACC332128547A2A48
ComboFix 12-12-23.01 - Helena Polášková 24.12.2012 11:25:10.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.895.450 [GMT 1:00]
Spuštěný z: c:\documents and settings\Helena PolßÜkovß\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security 2013 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2013 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\8657bf86d1550058.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\b0faab6cd511c65a.fb
c:\windows\system32\Cache\b6686a3e36a77030.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\cf90e697fd10f290.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\TZLog.log
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-11-24 do 2012-12-24 )))))))))))))))))))))))))))))))
.
.
2012-12-24 10:08 . 2012-12-24 10:08 -------- d-----w- c:\program files\CrystalDiskInfo
2012-12-24 09:43 . 2012-12-24 09:43 -------- d-----w- C:\_OTL
2012-12-24 08:53 . 2012-12-24 08:53 512 ----a-w- C:\PhysicalMBR.bin
2012-12-23 23:57 . 2012-12-23 23:57 -------- d-----w- c:\program files\Defraggler
2012-12-23 23:28 . 2012-12-23 23:28 -------- d-----w- c:\documents and settings\Administrator
2012-12-23 19:44 . 2012-10-30 22:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-12-23 19:44 . 2012-10-30 22:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-12-23 19:44 . 2012-10-30 22:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-12-23 19:44 . 2012-10-30 22:51 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-12-23 19:44 . 2012-10-30 22:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-12-23 19:44 . 2012-10-30 22:51 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-12-23 19:44 . 2012-10-30 22:51 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-12-23 19:44 . 2012-10-30 22:51 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-12-23 19:43 . 2012-10-30 22:51 41224 ----a-w- c:\windows\avastSS.scr
2012-12-23 19:43 . 2012-10-30 22:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-12-23 19:42 . 2012-12-23 19:42 -------- d-----w- c:\program files\AVAST Software
2012-12-23 19:42 . 2012-12-23 19:42 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-12-23 18:40 . 2012-12-23 22:39 -------- d-----w- c:\program files\trend micro
2012-12-23 14:45 . 2012-12-23 14:45 -------- d-----w- c:\program files\WinDirStat
2012-12-23 14:32 . 2012-12-23 14:32 -------- d-----w- c:\program files\CCleaner
2012-12-13 13:30 . 2012-12-13 13:30 5955856 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2012-12-06 09:42 . 2012-12-06 09:42 -------- d-----w- c:\program files\Common Files\Skype
2012-12-04 19:37 . 2012-12-04 19:37 -------- d-sh--w- c:\documents and settings\LogMeInRemoteUser\IETldCache
2012-12-01 18:50 . 2012-12-01 18:50 -------- d-----w- c:\documents and settings\Helena Polášková\Data aplikací\TuneUp Software
2012-12-01 18:44 . 2012-12-01 18:44 -------- d-----w- c:\documents and settings\Helena Polášková\Local Settings\Data aplikací\MFAData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-17 20:11 . 2012-12-17 20:11 15895 ----a-w- C:\MzIB1210,Zuzana_Vindišová_-_SV_klimatizace.zip
2012-12-17 19:59 . 2012-12-17 19:59 16315 ----a-w- C:\MzIB1210,Zetocha_Roman.zip
2012-12-17 19:53 . 2012-12-17 19:53 17239 ----a-w- C:\MzIB1210,Aure_services_s,r,o,.zip
2012-12-16 12:23 . 2008-04-14 12:00 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-11-18 19:00 . 2012-11-18 19:00 16378 ----a-w- C:\MzIB1209,Zetocha_Roman.zip
2012-11-18 18:43 . 2012-11-18 18:43 15952 ----a-w- C:\MzIB1209,Zuzana_Vindišová_-_SV_klimatizace.zip
2012-11-18 17:52 . 2012-09-10 21:07 17340 ----a-w- C:\MzIB1207,Aure_services_s,r,o,.zip
2012-11-13 11:55 . 2008-04-14 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-11-11 19:37 . 2008-10-31 13:42 83912 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-11-11 19:37 . 2008-10-31 13:42 92072 ----a-w- c:\windows\system32\LMIinit.dll
2012-11-04 19:46 . 2012-11-04 19:46 17184 ----a-w- C:\MzIB1209,Aure_services_s,r,o,.zip
2012-11-02 02:03 . 2008-04-14 12:00 375296 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 12:12 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-11-01 12:12 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-11-01 12:12 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-11-01 00:35 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-10-25 10:57 . 2012-10-25 10:57 15874 ----a-w- C:\MzIB1208,Zuzana_Vindišová_-_SV_klimatizace.zip
2012-10-25 10:54 . 2012-10-25 10:54 16303 ----a-w- C:\MzIB1208,Zetocha_Roman.zip
2012-10-22 19:23 . 2012-10-22 19:23 17198 ----a-w- C:\MzIB1208,Aure_services_s,r,o,.zip
2012-10-02 18:04 . 2008-04-14 12:00 58368 ----a-w- c:\windows\system32\synceng.dll
2012-10-01 17:49 . 2012-10-01 17:49 15116 ----a-w- C:\MzIB1203,Tomáš_Nykl.zip
2012-10-01 17:46 . 2012-10-01 17:46 16485 ----a-w- C:\MzIB1202,Tomáš_Nykl.zip
2012-11-12 13:20 . 2012-11-12 13:20 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"nwiz"="nwiz.exe" [2008-09-17 1657376]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-19 16858112]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2005-10-04 997042]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2005-10-04 118784]
"Print2PDF Print Monitor"="c:\program files\Software602\Print2PDF\Print2PDF.exe" [2011-10-04 220992]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-11-11 19:37 92072 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^Helena Polášková^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Helena Polášková\Nabídka Start\Programy\Po spuštění\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KONICA MINOLTA PagePro 1300WStatusDisplay]
2004-04-13 13:26 151552 ----a-w- c:\windows\system32\MSTMON_N.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\soft602\\langserv.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [23.12.2012 20:44 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [23.12.2012 20:44 361032]
R2 602XML Updater;602Updater;c:\program files\Common Files\soft602\602updsvc\602updsvc.exe [10.10.2011 12:55 85344]
R2 Aladdin SQL Server;Aladdin SQL Server;c:\program files\Aladdin\Aladdin SQL Server\AladdinSQL.exe [9.10.2009 22:09 140736]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [23.12.2012 20:44 21256]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [18.7.2003 10:55 18848]
R2 MSSQL$MSOFT;SQL Server (MSOFT);c:\mssql2005express\MSSQL.1\MSSQL\Binn\sqlservr.exe -sMSOFT --> c:\mssql2005express\MSSQL.1\MSSQL\Binn\sqlservr.exe -sMSOFT [?]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [29.10.2010 20:34 374704]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys --> c:\program files\LogMeIn\x86\RaInfo.sys [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Obsah adresáře 'Naplánované úlohy'
.
2012-12-24 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-12-23 22:50]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Helena Polášková\Data aplikací\Mozilla\Firefox\Profiles\ljs0f6qj.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - ExtSQL: 2012-12-23 20:44; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF
FF - ExtSQL: !HIDDEN! 2009-08-07 22:56; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - ExtSQL: !HIDDEN! 2009-12-02 09:23; {800b5000-a755-47e1-992b-48a1c1357f07}; c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-12-24 11:32
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(832)
c:\windows\system32\relog_ap.dll
.
Celkový čas: 2012-12-24 11:34:05
ComboFix-quarantined-files.txt 2012-12-24 10:34
.
Před spuštěním: Volných bajtů: 113 671 520 256
Po spuštění: Volných bajtů: 113 740 009 472
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 604971A9A02E793ACC332128547A2A48