Tak, hotovo:
ComboFix 10-05-03.05 - Jan Krištof 05.05.2010 17:22:48.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.503.287 [GMT 2:00]
Spuštěný z: c:\documents and settings\Jan Krištof\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-05 do 2010-05-05 )))))))))))))))))))))))))))))))
.
2010-05-04 09:12 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-04 09:12 . 2010-05-04 09:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-04 09:12 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-04 07:47 . 2010-05-04 07:47 -------- d-----w- C:\~ErdUserProfile.$$$
2010-05-04 06:36 . 2010-05-04 06:36 -------- d-----w- c:\program files\Nero
2010-04-16 19:42 . 2010-04-16 19:42 -------- d-----w- c:\program files\FreeTime
2010-04-12 16:52 . 2010-04-14 18:03 -------- d-----w- C:\Need4Video files
2010-04-12 16:50 . 2010-04-12 16:50 -------- d-----w- c:\program files\Need4 Software Launcher
2010-04-12 16:50 . 2010-04-12 16:50 -------- d-----w- c:\program files\Need4 YouTube Download 6
2010-04-12 16:18 . 2010-04-12 16:18 -------- d-----w- c:\documents and settings\All Users\CydMini
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-05 15:16 . 1979-12-31 23:00 47050 ----a-w- c:\windows\system32\perfc005.dat
2010-05-05 15:16 . 1979-12-31 23:00 311274 ----a-w- c:\windows\system32\perfh005.dat
2010-05-04 06:36 . 2010-02-13 11:04 -------- d-----w- c:\program files\Common Files\Nero
2010-03-20 11:50 . 2010-03-20 11:50 -------- d-----w- c:\program files\CCleaner
2010-03-20 08:36 . 2010-03-20 08:35 -------- d-----w- c:\program files\Alwil Software
2010-03-10 06:17 . 1979-12-31 23:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:18 . 2001-12-03 14:40 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 1979-12-31 23:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 12:09 . 1979-12-31 23:00 2192128 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:09 . 2001-10-24 10:46 2068992 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-03-17 16:14 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:35 . 1979-12-31 23:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 1979-12-31 23:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-05-04_12.57.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 1979-12-31 23:00 . 2010-05-05 15:16 40862 c:\windows\system32\perfc009.dat
+ 1979-12-31 23:00 . 2010-05-05 15:16 313144 c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-10-09 151552]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-10-09 98304]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2001-08-01 94208]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2001-08-01 352256]
"LaunchAp"="c:\program files\Acer\Launch Manager\LaunchAp.exe" [2001-06-26 20480]
"PowerKey"="c:\program files\Acer\Launch Manager\PowerKey.exe" [2000-11-06 98304]
"HotkeyApp"="c:\program files\Acer\Launch Manager\HotkeyApp.exe" [2001-10-31 86016]
"KeyHook"="c:\program files\Acer\Launch Manager\KeyHook.exe" [2001-06-26 20480]
"CtrlVol"="c:\program files\Acer\Launch Manager\CtrlVol.exe" [2001-06-26 163840]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-16 188416]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"LTSMMSG"=LTSMMSG.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 dmiproxy;dmiproxy;c:\windows\system32\drivers\Dmiproxy.sys [16.1.2002 16:01 36680]
R1 NbmKmd;NbmKmd;c:\windows\system32\drivers\NBMKMD.SYS [16.1.2002 16:01 4160]
R3 {A7E39B01-B403-11d4-BD18-00D0B7A1821E};AIM 3.0 Part 01 Codec Driver VCH-A;c:\windows\system32\drivers\vch.sys [16.1.2002 15:48 18487]
R3 LucentSoftModem;Lucent Technologies Soft Modem;c:\windows\system32\drivers\LTSM.sys [1.1.1980 1:00 806342]
S3 POWERKEY;POWERKEY;\??\c:\program files\Acer\Launch Manager\POWERKEY.sys --> c:\program files\Acer\Launch Manager\POWERKEY.sys [?]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = local
IE: Download ALL with IDA
IE: Download remotely with IDA
IE: Download with IDA
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{09E90109-A9AA-4980-BCEF-76F8D924E902}
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-05 17:27
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(3800)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-05-05 17:30:25
ComboFix-quarantined-files.txt 2010-05-05 15:30
ComboFix2.txt 2010-05-05 15:17
Před spuštěním: Volných bajtů: 14 607 800 320
Po spuštění: Volných bajtů: 14 603 337 216
- - End Of File - - 6B6F6717F19737A4E292E5745C276268