ComboFix 10-04-26.02 - HANUŠ 26.04.2010 20:31:57.4.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.256.120 [GMT 2:00]
Spuštěný z: c:\documents and settings\HANUŠ\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\HANUŠ\Plocha\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Dealio
c:\program files\Dealio\DealioAU.exe
c:\program files\Dealio\kb127\Dealio Deskbar.exe
c:\program files\Dealio\kb127\Dealio.dll
c:\program files\Dealio\kb127\DealioRes409.dll
c:\program files\Dealio\kb127\res\alerts.gif
c:\program files\Dealio\kb127\res\alerts_over.gif
c:\program files\Dealio\kb127\res\alerts_rec.gif
c:\program files\Dealio\kb127\res\alerts_rec_over.gif
c:\program files\Dealio\kb127\res\deal_report.jpg
c:\program files\Dealio\kb127\res\DealioSearch.html
c:\program files\Dealio\kb127\res\deals-leftcap.gif
c:\program files\Dealio\kb127\res\ebay_login.jpg
c:\program files\Dealio\kb127\res\err_mainwindow.html
c:\program files\Dealio\kb127\res\err_toolbar.html
c:\program files\Dealio\kb127\res\global_scripts.js
c:\program files\Dealio\kb127\res\headerbgthin.jpg
c:\program files\Dealio\kb127\res\highlight-bg.png
c:\program files\Dealio\kb127\res\chevron-small.gif
c:\program files\Dealio\kb127\res\logo.gif
c:\program files\Dealio\kb127\res\logo_over.gif
c:\program files\Dealio\kb127\res\man_toolbar.css
c:\program files\Dealio\kb127\res\man_toolbar.html
c:\program files\Dealio\kb127\res\man_toolbar.js
c:\program files\Dealio\kb127\res\man_toolbarl.js
c:\program files\Dealio\kb127\res\post-this-deal.gif
c:\program files\Dealio\kb127\res\post-this-deal_over.gif
c:\program files\Dealio\kb127\res\scripts.js
c:\program files\Dealio\kb127\res\scroller.js
c:\program files\Dealio\kb127\res\search-chevron.gif
c:\program files\Dealio\kb127\res\search-chevron_over.gif
c:\program files\Dealio\kb127\res\search_bg_blink.gif
c:\program files\Dealio\kb127\res\separator.gif
c:\program files\Dealio\kb127\res\settings.gif
c:\program files\Dealio\kb127\res\settings_over.gif
c:\program files\Dealio\kb127\res\yahoo-search.png
c:\program files\Dealio\kb127\resDN\bottom.gif
c:\program files\Dealio\kb127\resDN\close.gif
c:\program files\Dealio\kb127\resDN\deskbar.css
c:\program files\Dealio\kb127\resDN\deskbar.js
c:\program files\Dealio\kb127\resDN\dispatch_helper.js
c:\program files\Dealio\kb127\resDN\ebay_compatible.jpg
c:\program files\Dealio\kb127\resDN\chevron_down.gif
c:\program files\Dealio\kb127\resDN\chevron_up.gif
c:\program files\Dealio\kb127\resDN\logo.gif
c:\program files\Dealio\kb127\resDN\logo_chevron_bkg.gif
c:\program files\Dealio\kb127\resDN\losing.gif
c:\program files\Dealio\kb127\resDN\lost.gif
c:\program files\Dealio\kb127\resDN\man_deskbar.html
c:\program files\Dealio\kb127\resDN\menu_arrow.gif
c:\program files\Dealio\kb127\resDN\menu_check.gif
c:\program files\Dealio\kb127\resDN\no_image.gif
c:\program files\Dealio\kb127\resDN\prod_img.gif
c:\program files\Dealio\kb127\resDN\search_chevron.gif
c:\program files\Dealio\kb127\resDN\spacer.gif
c:\program files\Dealio\kb127\resDN\textfield_bkg.gif
c:\program files\Dealio\kb127\resDN\top.gif
c:\program files\Dealio\kb127\resDN\unknown.gif
c:\program files\Dealio\kb127\resDN\winning.gif
c:\program files\Dealio\kb127\resDN\won.gif
c:\program files\Dealio\kb127\rules\index.76.35
c:\program files\Dealio\kb127\rules\rules.1.10.76
c:\program files\Dealio\kb127\rules\rules.1.109.43
c:\program files\Dealio\kb127\rules\rules.1.110.43
c:\program files\Dealio\kb127\rules\rules.1.12.52
c:\program files\Dealio\kb127\rules\rules.1.13.58
c:\program files\Dealio\kb127\rules\rules.1.130.58
c:\program files\Dealio\kb127\rules\rules.1.135.50
c:\program files\Dealio\kb127\rules\rules.1.153.44
c:\program files\Dealio\kb127\rules\rules.1.155.43
c:\program files\Dealio\kb127\rules\rules.1.156.49
c:\program files\Dealio\kb127\rules\rules.1.16.60
c:\program files\Dealio\kb127\rules\rules.1.161.52
c:\program files\Dealio\kb127\rules\rules.1.178.66
c:\program files\Dealio\kb127\rules\rules.1.184.55
c:\program files\Dealio\kb127\rules\rules.1.188.52
c:\program files\Dealio\kb127\rules\rules.1.189.45
c:\program files\Dealio\kb127\rules\rules.1.196.43
c:\program files\Dealio\kb127\rules\rules.1.198.56
c:\program files\Dealio\kb127\rules\rules.1.199.43
c:\program files\Dealio\kb127\rules\rules.1.200.53
c:\program files\Dealio\kb127\rules\rules.1.201.43
c:\program files\Dealio\kb127\rules\rules.1.202.43
c:\program files\Dealio\kb127\rules\rules.1.203.71
c:\program files\Dealio\kb127\rules\rules.1.205.62
c:\program files\Dealio\kb127\rules\rules.1.213.71
c:\program files\Dealio\kb127\rules\rules.1.214.49
c:\program files\Dealio\kb127\rules\rules.1.215.43
c:\program files\Dealio\kb127\rules\rules.1.216.67
c:\program files\Dealio\kb127\rules\rules.1.217.67
c:\program files\Dealio\kb127\rules\rules.1.218.52
c:\program files\Dealio\kb127\rules\rules.1.219.43
c:\program files\Dealio\kb127\rules\rules.1.220.43
c:\program files\Dealio\kb127\rules\rules.1.221.57
c:\program files\Dealio\kb127\rules\rules.1.222.43
c:\program files\Dealio\kb127\rules\rules.1.223.68
c:\program files\Dealio\kb127\rules\rules.1.226.68
c:\program files\Dealio\kb127\rules\rules.1.227.43
c:\program files\Dealio\kb127\rules\rules.1.228.62
c:\program files\Dealio\kb127\rules\rules.1.229.76
c:\program files\Dealio\kb127\rules\rules.1.23.63
c:\program files\Dealio\kb127\rules\rules.1.239.43
c:\program files\Dealio\kb127\rules\rules.1.24.43
c:\program files\Dealio\kb127\rules\rules.1.240.43
c:\program files\Dealio\kb127\rules\rules.1.241.43
c:\program files\Dealio\kb127\rules\rules.1.242.43
c:\program files\Dealio\kb127\rules\rules.1.243.43
c:\program files\Dealio\kb127\rules\rules.1.244.63
c:\program files\Dealio\kb127\rules\rules.1.245.43
c:\program files\Dealio\kb127\rules\rules.1.247.43
c:\program files\Dealio\kb127\rules\rules.1.248.43
c:\program files\Dealio\kb127\rules\rules.1.249.43
c:\program files\Dealio\kb127\rules\rules.1.250.43
c:\program files\Dealio\kb127\rules\rules.1.251.43
c:\program files\Dealio\kb127\rules\rules.1.252.43
c:\program files\Dealio\kb127\rules\rules.1.253.43
c:\program files\Dealio\kb127\rules\rules.1.254.43
c:\program files\Dealio\kb127\rules\rules.1.255.43
c:\program files\Dealio\kb127\rules\rules.1.256.43
c:\program files\Dealio\kb127\rules\rules.1.257.43
c:\program files\Dealio\kb127\rules\rules.1.279.43
c:\program files\Dealio\kb127\rules\rules.1.28.58
c:\program files\Dealio\kb127\rules\rules.1.282.75
c:\program files\Dealio\kb127\rules\rules.1.283.43
c:\program files\Dealio\kb127\rules\rules.1.284.43
c:\program files\Dealio\kb127\rules\rules.1.289.67
c:\program files\Dealio\kb127\rules\rules.1.290.62
c:\program files\Dealio\kb127\rules\rules.1.291.61
c:\program files\Dealio\kb127\rules\rules.1.296.43
c:\program files\Dealio\kb127\rules\rules.1.297.43
c:\program files\Dealio\kb127\rules\rules.1.304.43
c:\program files\Dealio\kb127\rules\rules.1.307.43
c:\program files\Dealio\kb127\rules\rules.1.308.75
c:\program files\Dealio\kb127\rules\rules.1.31.47
c:\program files\Dealio\kb127\rules\rules.1.310.46
c:\program files\Dealio\kb127\rules\rules.1.311.43
c:\program files\Dealio\kb127\rules\rules.1.315.43
c:\program files\Dealio\kb127\rules\rules.1.316.43
c:\program files\Dealio\kb127\rules\rules.1.317.43
c:\program files\Dealio\kb127\rules\rules.1.318.43
c:\program files\Dealio\kb127\rules\rules.1.319.49
c:\program files\Dealio\kb127\rules\rules.1.32.48
c:\program files\Dealio\kb127\rules\rules.1.334.44
c:\program files\Dealio\kb127\rules\rules.1.335.60
c:\program files\Dealio\kb127\rules\rules.1.336.44
c:\program files\Dealio\kb127\rules\rules.1.337.44
c:\program files\Dealio\kb127\rules\rules.1.338.75
c:\program files\Dealio\kb127\rules\rules.1.339.47
c:\program files\Dealio\kb127\rules\rules.1.34.43
c:\program files\Dealio\kb127\rules\rules.1.340.47
c:\program files\Dealio\kb127\rules\rules.1.341.47
c:\program files\Dealio\kb127\rules\rules.1.349.50
c:\program files\Dealio\kb127\rules\rules.1.35.48
c:\program files\Dealio\kb127\rules\rules.1.350.50
c:\program files\Dealio\kb127\rules\rules.1.351.51
c:\program files\Dealio\kb127\rules\rules.1.352.54
c:\program files\Dealio\kb127\rules\rules.1.353.51
c:\program files\Dealio\kb127\rules\rules.1.354.51
c:\program files\Dealio\kb127\rules\rules.1.357.62
c:\program files\Dealio\kb127\rules\rules.1.358.52
c:\program files\Dealio\kb127\rules\rules.1.359.52
c:\program files\Dealio\kb127\rules\rules.1.360.53
c:\program files\Dealio\kb127\rules\rules.1.361.54
c:\program files\Dealio\kb127\rules\rules.1.362.68
c:\program files\Dealio\kb127\rules\rules.1.363.58
c:\program files\Dealio\kb127\rules\rules.1.364.54
c:\program files\Dealio\kb127\rules\rules.1.365.53
c:\program files\Dealio\kb127\rules\rules.1.367.56
c:\program files\Dealio\kb127\rules\rules.1.368.58
c:\program files\Dealio\kb127\rules\rules.1.369.55
c:\program files\Dealio\kb127\rules\rules.1.370.56
c:\program files\Dealio\kb127\rules\rules.1.371.56
c:\program files\Dealio\kb127\rules\rules.1.372.57
c:\program files\Dealio\kb127\rules\rules.1.373.55
c:\program files\Dealio\kb127\rules\rules.1.375.56
c:\program files\Dealio\kb127\rules\rules.1.376.57
c:\program files\Dealio\kb127\rules\rules.1.377.55
c:\program files\Dealio\kb127\rules\rules.1.378.65
c:\program files\Dealio\kb127\rules\rules.1.384.58
c:\program files\Dealio\kb127\rules\rules.1.386.71
c:\program files\Dealio\kb127\rules\rules.1.387.59
c:\program files\Dealio\kb127\rules\rules.1.388.59
c:\program files\Dealio\kb127\rules\rules.1.389.59
c:\program files\Dealio\kb127\rules\rules.1.390.60
c:\program files\Dealio\kb127\rules\rules.1.391.60
c:\program files\Dealio\kb127\rules\rules.1.392.60
c:\program files\Dealio\kb127\rules\rules.1.393.60
c:\program files\Dealio\kb127\rules\rules.1.394.60
c:\program files\Dealio\kb127\rules\rules.1.396.61
c:\program files\Dealio\kb127\rules\rules.1.397.61
c:\program files\Dealio\kb127\rules\rules.1.398.60
c:\program files\Dealio\kb127\rules\rules.1.399.60
c:\program files\Dealio\kb127\rules\rules.1.403.61
c:\program files\Dealio\kb127\rules\rules.1.404.63
c:\program files\Dealio\kb127\rules\rules.1.405.61
c:\program files\Dealio\kb127\rules\rules.1.406.61
c:\program files\Dealio\kb127\rules\rules.1.407.76
c:\program files\Dealio\kb127\rules\rules.1.408.63
c:\program files\Dealio\kb127\rules\rules.1.409.61
c:\program files\Dealio\kb127\rules\rules.1.412.62
c:\program files\Dealio\kb127\rules\rules.1.413.62
c:\program files\Dealio\kb127\rules\rules.1.414.62
c:\program files\Dealio\kb127\rules\rules.1.415.62
c:\program files\Dealio\kb127\rules\rules.1.416.62
c:\program files\Dealio\kb127\rules\rules.1.417.62
c:\program files\Dealio\kb127\rules\rules.1.418.62
c:\program files\Dealio\kb127\rules\rules.1.419.62
c:\program files\Dealio\kb127\rules\rules.1.420.62
c:\program files\Dealio\kb127\rules\rules.1.421.62
c:\program files\Dealio\kb127\rules\rules.1.423.63
c:\program files\Dealio\kb127\rules\rules.1.424.63
c:\program files\Dealio\kb127\rules\rules.1.425.63
c:\program files\Dealio\kb127\rules\rules.1.426.63
c:\program files\Dealio\kb127\rules\rules.1.427.63
c:\program files\Dealio\kb127\rules\rules.1.428.65
c:\program files\Dealio\kb127\rules\rules.1.429.63
c:\program files\Dealio\kb127\rules\rules.1.430.63
c:\program files\Dealio\kb127\rules\rules.1.432.65
c:\program files\Dealio\kb127\rules\rules.1.433.64
c:\program files\Dealio\kb127\rules\rules.1.434.65
c:\program files\Dealio\kb127\rules\rules.1.435.64
c:\program files\Dealio\kb127\rules\rules.1.436.76
c:\program files\Dealio\kb127\rules\rules.1.437.64
c:\program files\Dealio\kb127\rules\rules.1.438.71
c:\program files\Dealio\kb127\rules\rules.1.439.71
c:\program files\Dealio\kb127\rules\rules.1.440.75
c:\program files\Dealio\kb127\rules\rules.1.442.73
c:\program files\Dealio\kb127\rules\rules.1.443.73
c:\program files\Dealio\kb127\rules\rules.1.444.73
c:\program files\Dealio\kb127\rules\rules.1.445.68
c:\program files\Dealio\kb127\rules\rules.1.446.69
c:\program files\Dealio\kb127\rules\rules.1.450.67
c:\program files\Dealio\kb127\rules\rules.1.451.67
c:\program files\Dealio\kb127\rules\rules.1.452.68
c:\program files\Dealio\kb127\rules\rules.1.453.68
c:\program files\Dealio\kb127\rules\rules.1.454.69
c:\program files\Dealio\kb127\rules\rules.1.456.69
c:\program files\Dealio\kb127\rules\rules.1.457.75
c:\program files\Dealio\kb127\rules\rules.1.458.70
c:\program files\Dealio\kb127\rules\rules.1.459.70
c:\program files\Dealio\kb127\rules\rules.1.460.69
c:\program files\Dealio\kb127\rules\rules.1.462.74
c:\program files\Dealio\kb127\rules\rules.1.463.69
c:\program files\Dealio\kb127\rules\rules.1.464.70
c:\program files\Dealio\kb127\rules\rules.1.465.68
c:\program files\Dealio\kb127\rules\rules.1.468.70
c:\program files\Dealio\kb127\rules\rules.1.469.70
c:\program files\Dealio\kb127\rules\rules.1.470.70
c:\program files\Dealio\kb127\rules\rules.1.471.73
c:\program files\Dealio\kb127\rules\rules.1.472.70
c:\program files\Dealio\kb127\rules\rules.1.478.74
c:\program files\Dealio\kb127\rules\rules.1.479.73
c:\program files\Dealio\kb127\rules\rules.1.480.68
c:\program files\Dealio\kb127\rules\rules.1.481.71
c:\program files\Dealio\kb127\rules\rules.1.482.74
c:\program files\Dealio\kb127\rules\rules.1.49.67
c:\program files\Dealio\kb127\rules\rules.1.50.43
c:\program files\Dealio\kb127\rules\rules.1.500.71
c:\program files\Dealio\kb127\rules\rules.1.501.74
c:\program files\Dealio\kb127\rules\rules.1.502.71
c:\program files\Dealio\kb127\rules\rules.1.51.69
c:\program files\Dealio\kb127\rules\rules.1.52.72
c:\program files\Dealio\kb127\rules\rules.1.520.76
c:\program files\Dealio\kb127\rules\rules.1.521.76
c:\program files\Dealio\kb127\rules\rules.1.522.76
c:\program files\Dealio\kb127\rules\rules.1.53.51
c:\program files\Dealio\kb127\rules\rules.1.531.76
c:\program files\Dealio\kb127\rules\rules.1.532.75
c:\program files\Dealio\kb127\rules\rules.1.534.75
c:\program files\Dealio\kb127\rules\rules.1.54.47
c:\program files\Dealio\kb127\rules\rules.1.55.45
c:\program files\Dealio\kb127\rules\rules.1.56.69
c:\program files\Dealio\kb127\rules\rules.1.57.43
c:\program files\Dealio\kb127\rules\rules.1.58.47
c:\program files\Dealio\kb127\rules\rules.1.593.76
c:\program files\Dealio\kb127\rules\rules.1.595.76
c:\program files\Dealio\kb127\rules\rules.1.63.57
c:\program files\Dealio\kb127\rules\rules.1.66.47
c:\program files\Dealio\kb127\rules\rules.1.70.75
c:\program files\Dealio\kb127\rules\rules.1.71.43
c:\program files\Dealio\SearchSettingsKit.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-03-26 do 2010-04-26 )))))))))))))))))))))))))))))))
.
2010-04-26 06:40 . 2010-04-25 10:43 390144 ----a-w- c:\windows\system32\CF24040.exe
2010-04-25 20:41 . 2010-04-25 20:41 -------- d-----w- c:\program files\trend micro
2010-04-25 20:40 . 2010-04-25 20:40 -------- d-----w- C:\rsit
2010-04-23 11:46 . 2010-04-23 11:46 -------- d-----w- C:\FOUND.005
2010-04-23 09:38 . 2010-01-22 07:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-04-23 09:38 . 2010-01-22 07:55 767952 ----a-w- c:\windows\BDTSupport.dll
2010-04-23 09:38 . 2009-10-27 23:36 1152444 ----a-w- c:\windows\UDB.zip
2010-04-23 09:38 . 2008-11-26 10:08 131 ----a-w- c:\windows\IDB.zip
2010-04-23 09:38 . 2010-01-22 07:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-04-23 09:38 . 2010-01-22 07:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2010-04-23 09:31 . 2010-02-05 07:25 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-04-23 09:30 . 2010-04-23 09:30 -------- d-----w- c:\program files\Spyware Doctor
2010-04-18 06:55 . 2010-04-18 06:55 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-04-18 06:55 . 2010-03-10 09:36 217032 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-04-18 06:55 . 2010-04-18 06:55 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-04-17 08:40 . 2010-04-17 08:40 -------- d-----w- c:\program files\Common Files\PC Tools
2010-04-10 17:36 . 2010-04-10 17:36 -------- d-----w- C:\FOUND.004
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-26 00:04 . 2005-04-13 20:55 602112 ----a-w- c:\windows\uninstal.exe
2010-04-18 06:55 . 2010-04-18 06:55 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2009-10-07 18:43 . 2009-10-07 18:43 32768 ------w- c:\program files\temp
2009-02-05 13:36 . 2009-02-05 13:19 120328171 ----a-w- c:\program files\mysql-noinstall-5.1.31-win32.zip
2006-11-27 16:39 . 2006-11-27 16:39 1077258 ----a-w- c:\program files\miranda-im-v0[1].5.1-unicode.exe
2004-12-07 16:33 . 2004-12-07 16:33 96256 ----a-w- c:\program files\TurboTray.exe
2004-12-07 16:33 . 2004-12-07 16:33 266240 ----a-w- c:\program files\Turbo.dll
1991-07-16 15:05 . 2003-09-03 19:42 97442 ----a-w- c:\program files\ARJ.EXE
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ISUSPM"="c:\documents and settings\All Users\Data aplikací\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-07-12 226904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-04-02 4616192]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 98304]
"FinePrint Dispatcher v4"="c:\windows\System32\spool\DRIVERS\W32X86\3\fpdisp4.exe" [2002-10-30 364544]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis1.exe" [2002-10-30 364544]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-06-03 77824]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-03-09 1286608]
"CARPService"="carpserv.exe" [2001-12-23 4608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-04-02 49152]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\ICQ\\Icq.exe"=
"c:\\WINCMD\\WINCMD32.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\MATLAB701\\bin\\win32\\MATLAB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [18.4.2010 8:55 217032]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14.5.2009 15:47 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14.5.2009 15:49 96408]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [23.4.2010 11:38 112592]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [23.4.2010 11:30 366840]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys --> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys --> c:\windows\system32\Drivers\avgtdix.sys [?]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S3 PhTVTune;Video Wonder Pro III WDM TV Tuner;c:\windows\system32\DRIVERS\PhTVTune.sys --> c:\windows\system32\DRIVERS\PhTVTune.sys [?]
S4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [18.4.2010 8:55 233136]
S4 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [23.4.2010 11:31 70408]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - PCTSDInjDriver32
.
Obsah adresáře 'Naplánované úlohy'
2007-08-09 c:\windows\Tasks\XoftSpy.job
- c:\program files\XoftSpy\XoftSpy.exe [2007-04-26 12:39]
2009-12-17 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.2.0.5\DriverRobot.exe [2009-12-17 15:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
mStart Page = hxxp://
www.seznam.cz/
uInternet Settings,ProxyServer = proxy.felk.cvut.cz:80
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*
http://www.yahoo.com
IE: Compare Prices with &Dealio - c:\documents and settings\HANUŠ\Data aplikací\Dealio\kb127\res\DealioSearch.html
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
LSP: imon.dll
Trusted Zone: microsoft.com \*.windowsupdate
Trusted Zone: windowsupdate.com
Trusted Zone: yahoo.com\launch
TCP: {8EBF79BF-B9ED-4F88-B498-9C8F32409C34} = 195.146.100.100,195.146.100.5
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {3190CE28-0B6E-4133-A7D3-87D29CB92120} - hxxp://
www.listicka.cz/toolbar.cab
FF - ProfilePath - c:\documents and settings\HANUŠ\Data aplikací\Mozilla\Firefox\Profiles\98mp6ngb.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.centrum.cz
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Google\Google Updater\1.3.612.22906\npCIDetect6.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_19\bin\NPJava11.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_19\bin\NPJava12.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_19\bin\NPJava131_19.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_19\bin\NPJava32.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_19\bin\NPOJI600.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
FF - plugin: e:\instalation\program\plugins\npdivx32.dll
FF - plugin: e:\instalation\program\plugins\npdsplay.dll
FF - plugin: e:\instalation\program\plugins\NPSWF32.dll
FF - plugin: e:\instalation\program\plugins\npwmsdrm.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-26 20:54
Windows 5.1.2600 Service Pack 3 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(592)
c:\windows\system32\imon.dll
.
Celkový čas: 2010-04-26 21:06:44
ComboFix-quarantined-files.txt 2010-04-26 19:06
ComboFix2.txt 2010-04-25 21:32
ComboFix3.txt 2010-04-25 12:06
ComboFix4.txt 2008-10-20 18:21
Před spuštěním: 3 866 427 392
Po spuštění: 3 822 059 520
- - End Of File - - 1F1FF644B3FAFC20B9342DA36524A9A4