fast browser search
Napsal: 11 kvě 2010 12:06
Potřeboval bych pomoc při odstranění Fast browser search. Ve firefoxu po kliknutí na nové okno dojde k otevření stránky fast browser search místo prázdné stránky jak to bylo dříve. Dále byl ve windows v položce přidat odebrat programy program Fast browser search, který nereagoval na pokusy odinstalování. Pomocí Combofixu se ho nějakým zázrakem podařilo odinstalovat ale ve firefoxu zůstalo vše při starém.
LOG:
ComboFix 10-05-10.03 - Kristýna 11.05.2010 12:47:12.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.958.504 [GMT 2:00]
Spuštěný z: c:\documents and settings\Kristýna\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100511-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\NavExcel Search Toolbar
c:\program files\NavExcel Search Toolbar\NavExcelBar.dll
c:\program files\NavExcel Search Toolbar\settings.dat
c:\program files\SGPSA
c:\windows\system32\1T76d2EtKoVT.dat
c:\windows\system32\3r3pvjPnRS875D7a.dat
c:\windows\system32\411Ccqg2nQ1.dat
c:\windows\system32\5j3BL.dat
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-11 do 2010-05-11 )))))))))))))))))))))))))))))))
.
2010-05-04 14:03 . 2010-05-04 14:04 -------- d-----w- c:\program files\OpenTTD
2010-04-26 11:45 . 2010-04-26 11:45 -------- d-----w- c:\program files\Axis Communications
2010-04-26 11:45 . 2010-04-26 11:45 -------- d-----w- c:\program files\Makov kodek
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-17 14:56 . 2007-05-08 17:40 -------- d-----w- c:\program files\DAEMON Tools
2010-04-17 12:58 . 2009-06-04 10:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-12 20:25 . 2009-01-03 23:00 -------- d-----w- c:\program files\ICQ6Toolbar
2010-04-12 20:25 . 2008-02-13 10:33 -------- d-----w- c:\program files\ICQToolbar
2010-04-12 20:25 . 2009-12-04 12:19 -------- d-----w- c:\program files\GameSpy Arcade
2010-04-06 17:16 . 2010-04-06 17:16 -------- d-----w- c:\program files\RADVideo
2010-04-06 14:06 . 2009-11-19 08:43 -------- d-----w- c:\program files\QuickTime
2010-04-01 09:46 . 2010-01-29 13:30 -------- d-----w- c:\program files\ICQ7.0
2010-03-29 22:46 . 2009-06-04 10:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 22:45 . 2009-06-04 10:35 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-28 05:23 . 2001-10-25 12:00 74516 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 05:23 . 2001-10-25 12:00 401230 ----a-w- c:\windows\system32\perfh005.dat
2010-03-26 12:36 . 2010-03-26 12:36 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-03-26 12:36 . 2010-03-26 12:36 -------- d-----w- c:\program files\DVDVideoSoft
2010-03-15 17:53 . 2009-06-22 18:41 -------- d-----w- c:\program files\Common Files\Real
2010-03-15 17:53 . 2010-03-15 17:52 -------- d-----w- c:\program files\real
2010-03-15 17:53 . 2010-03-15 17:53 -------- d-----w- c:\program files\Common Files\xing shared
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-04-24 273200]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" [2010-03-28 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" [2006-04-11 176128]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2003-12-13 33792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-12 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-15 202256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-17 13:49 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\WINDOWS\\system32\\VTTimer.exe"=
"c:\\WINDOWS\\system32\\VTTrayp.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\Winamp\\winampa.exe"=
"c:\\Program Files\\DAEMON Tools\\daemon.exe"=
"c:\\Program Files\\Sony\\SonicStage\\SSAAD.exe"=
"c:\\WINDOWS\\system32\\KB905474\\wgasetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Moravian Instruments\\Control Web 5 CZE\\cw5.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Documents and Settings\\Kristýna\\Dokumenty\\ICQ\\194969369\\ReceivedFiles\\324823895 Dobrmi\\Microsoft Games\\Age of Empires II\\Empires2.exe"=
"c:\\Documents and Settings\\Kristýna\\Dokumenty\\ICQ\\194969369\\ReceivedFiles\\324823895 Dobrmi\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21.5.2009 17:56 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21.5.2009 17:56 20560]
R2 CwIPCSvc;Control Web IPC;c:\program files\Moravian Instruments\Shared\cwsvc.exe [11.2.2008 6:00 69632]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [4.1.2009 1:00 246520]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.3.2007 22:57 642560]
S3 cdrmkaun;cdrmkaun;\??\c:\docume~1\KRISTN~1\LOCALS~1\Temp\cdrmkaun.sys --> c:\docume~1\KRISTN~1\LOCALS~1\Temp\cdrmkaun.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [29.12.2009 16:24 13224]
.
Obsah adresáře 'Naplánované úlohy'
2010-05-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-05-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-861567501-1303643608-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-05-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-861567501-1303643608-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-05-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://mondozoo.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {E8ED87DA-0F7E-44DA-902B-2525870DCFAB} = 213.211.45.3,212.96.160.1
FF - ProfilePath - c:\documents and settings\Kristýna\Data aplikací\Mozilla\Firefox\Profiles\r8gs6zhj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/resul ... EF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/resul ... 1A03A6}&q=
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Notify-WgaLogon - (no file)
AddRemove-Worms Armageddon Demo - c:\team17\Worms Armageddon Demo\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-11 12:51
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-861567501-1303643608-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Celkový čas: 2010-05-11 12:53:06
ComboFix-quarantined-files.txt 2010-05-11 10:53
Před spuštěním: 1 907 232 768
Po spuštění: 2 003 763 200
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 8D2FC95962121193EB988F10D848BE05
LOG:
ComboFix 10-05-10.03 - Kristýna 11.05.2010 12:47:12.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.958.504 [GMT 2:00]
Spuštěný z: c:\documents and settings\Kristýna\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100511-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\NavExcel Search Toolbar
c:\program files\NavExcel Search Toolbar\NavExcelBar.dll
c:\program files\NavExcel Search Toolbar\settings.dat
c:\program files\SGPSA
c:\windows\system32\1T76d2EtKoVT.dat
c:\windows\system32\3r3pvjPnRS875D7a.dat
c:\windows\system32\411Ccqg2nQ1.dat
c:\windows\system32\5j3BL.dat
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-11 do 2010-05-11 )))))))))))))))))))))))))))))))
.
2010-05-04 14:03 . 2010-05-04 14:04 -------- d-----w- c:\program files\OpenTTD
2010-04-26 11:45 . 2010-04-26 11:45 -------- d-----w- c:\program files\Axis Communications
2010-04-26 11:45 . 2010-04-26 11:45 -------- d-----w- c:\program files\Makov kodek
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-17 14:56 . 2007-05-08 17:40 -------- d-----w- c:\program files\DAEMON Tools
2010-04-17 12:58 . 2009-06-04 10:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-12 20:25 . 2009-01-03 23:00 -------- d-----w- c:\program files\ICQ6Toolbar
2010-04-12 20:25 . 2008-02-13 10:33 -------- d-----w- c:\program files\ICQToolbar
2010-04-12 20:25 . 2009-12-04 12:19 -------- d-----w- c:\program files\GameSpy Arcade
2010-04-06 17:16 . 2010-04-06 17:16 -------- d-----w- c:\program files\RADVideo
2010-04-06 14:06 . 2009-11-19 08:43 -------- d-----w- c:\program files\QuickTime
2010-04-01 09:46 . 2010-01-29 13:30 -------- d-----w- c:\program files\ICQ7.0
2010-03-29 22:46 . 2009-06-04 10:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 22:45 . 2009-06-04 10:35 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-28 05:23 . 2001-10-25 12:00 74516 ----a-w- c:\windows\system32\perfc005.dat
2010-03-28 05:23 . 2001-10-25 12:00 401230 ----a-w- c:\windows\system32\perfh005.dat
2010-03-26 12:36 . 2010-03-26 12:36 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2010-03-26 12:36 . 2010-03-26 12:36 -------- d-----w- c:\program files\DVDVideoSoft
2010-03-15 17:53 . 2009-06-22 18:41 -------- d-----w- c:\program files\Common Files\Real
2010-03-15 17:53 . 2010-03-15 17:52 -------- d-----w- c:\program files\real
2010-03-15 17:53 . 2010-03-15 17:53 -------- d-----w- c:\program files\Common Files\xing shared
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-04-24 273200]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" [2010-03-28 133368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-07 53248]
"VTTrayp"="VTtrayp.exe" [2006-04-11 176128]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2003-12-13 33792]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-12 149280]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-15 202256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-17 13:49 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\WINDOWS\\system32\\VTTimer.exe"=
"c:\\WINDOWS\\system32\\VTTrayp.exe"=
"c:\\WINDOWS\\SOUNDMAN.EXE"=
"c:\\Program Files\\Winamp\\winampa.exe"=
"c:\\Program Files\\DAEMON Tools\\daemon.exe"=
"c:\\Program Files\\Sony\\SonicStage\\SSAAD.exe"=
"c:\\WINDOWS\\system32\\KB905474\\wgasetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Moravian Instruments\\Control Web 5 CZE\\cw5.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Documents and Settings\\Kristýna\\Dokumenty\\ICQ\\194969369\\ReceivedFiles\\324823895 Dobrmi\\Microsoft Games\\Age of Empires II\\Empires2.exe"=
"c:\\Documents and Settings\\Kristýna\\Dokumenty\\ICQ\\194969369\\ReceivedFiles\\324823895 Dobrmi\\Microsoft Games\\Age of Empires II\\age2_x1.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21.5.2009 17:56 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21.5.2009 17:56 20560]
R2 CwIPCSvc;Control Web IPC;c:\program files\Moravian Instruments\Shared\cwsvc.exe [11.2.2008 6:00 69632]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [4.1.2009 1:00 246520]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9.3.2007 22:57 642560]
S3 cdrmkaun;cdrmkaun;\??\c:\docume~1\KRISTN~1\LOCALS~1\Temp\cdrmkaun.sys --> c:\docume~1\KRISTN~1\LOCALS~1\Temp\cdrmkaun.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [29.12.2009 16:24 13224]
.
Obsah adresáře 'Naplánované úlohy'
2010-05-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-05-11 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-861567501-1303643608-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-05-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-861567501-1303643608-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-05-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://mondozoo.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {E8ED87DA-0F7E-44DA-902B-2525870DCFAB} = 213.211.45.3,212.96.160.1
FF - ProfilePath - c:\documents and settings\Kristýna\Data aplikací\Mozilla\Firefox\Profiles\r8gs6zhj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/resul ... EF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/resul ... 1A03A6}&q=
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
Notify-WgaLogon - (no file)
AddRemove-Worms Armageddon Demo - c:\team17\Worms Armageddon Demo\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-11 12:51
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-861567501-1303643608-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Celkový čas: 2010-05-11 12:53:06
ComboFix-quarantined-files.txt 2010-05-11 10:53
Před spuštěním: 1 907 232 768
Po spuštění: 2 003 763 200
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 8D2FC95962121193EB988F10D848BE05