prosím o kontrolu logu - nestandartní chování PC
Napsal: 19 říj 2010 18:11
Dobrý den,
již jsem sem psal ale moje založené téma zmizelo, nevím proč... Zakládam tedy nové..
Pokračuju ve fázi kdy po logu z HijackThis mi bylo doporuceno projet PC Combofixem a na to do textaku zkopirovat nejaky text, ktery jsem pak hodil na ikonu Combofixu, nasledne probehla "rehabilitace"...
posilam zatim posledni log: (z 18.10.)
ComboFix 10-10-16.03 - Philliboy 18.10.2010 21:22:17.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3071.2603 [GMT 2:00]
Spuštěný z: c:\documents and settings\Philliboy\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Philliboy\Plocha\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira Firewall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FILE ::
"c:\windows\nod32restoretemdono.reg"
"c:\windows\system32\Default\winlogon.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\nod32restoretemdono.reg
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EKRN
-------\Service_ekrn
-------\Service_EhttpSrv
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-18 do 2010-10-18 )))))))))))))))))))))))))))))))
.
2010-10-16 20:55 . 2010-10-16 20:55 -------- d-----w- c:\program files\Common Files\Java
2010-10-16 20:23 . 2010-10-16 20:23 40344 ----a-w- c:\documents and settings\Philliboy\Data aplikací\FbxU.exe
2010-10-16 01:55 . 2010-09-14 23:01 718296 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-10-16 01:55 . 2010-09-14 23:01 14808 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-10-13 13:09 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 13:09 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 13:09 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-09-27 17:36 . 2009-07-14 15:14 150768 ----a-w- c:\documents and settings\Philliboy\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((( SnapShot@2010-10-17_09.58.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-18 19:28 . 2010-10-18 19:28 16384 c:\windows\temp\Perflib_Perfdata_42c.dat
+ 2010-01-24 08:58 . 2010-10-17 17:11 530436 c:\windows\system32\Restore\rstrlog.dat
+ 2010-10-17 16:54 . 2010-10-17 16:54 3376640 c:\windows\Installer\58538.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-10-18 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-10-18 19:07 2735200 ----a-w- c:\program files\Vuze_Remote\tbVuz1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-10-18 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-10-18 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PrtScr by FireStarter"="c:\program files\PrtScr\PrtScr.exe" [2008-03-19 1375744]
"Centrum.cz Notifikátor"="c:\program files\NetCentrum\Notifikator\Notifikator.exe" [2010-05-18 606720]
"Google Update"="c:\documents and settings\Philliboy\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-11-02 133104]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-28 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-25 14477312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"nwiz"="nwiz.exe" [2009-01-15 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"mouseElf"="c:\progra~1\GAMING~1\MouseElf.EXE" [2005-07-15 208896]
"HD Tune"="c:\progra~1\HDTUNE~1\HDTune.exe" [2005-09-12 405504]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-01-27 185896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-10 2500552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Philliboy^Nabídka Start^Programy^Po spuštění^TimeLeft.lnk]
path=c:\documents and settings\Philliboy\Nabídka Start\Programy\Po spuštění\TimeLeft.lnk
backup=c:\windows\pss\TimeLeft.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Centrum.cz Notifikátor]
2010-05-18 11:49 606720 ----a-w- c:\program files\NetCentrum\Notifikator\Notifikator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 01:08 2512392 ----a-w- c:\windows\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\supertintin_skype]
2009-12-06 20:46 1043456 ----a-w- c:\program files\Supertintin for Skype\supertintin_skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-01-27 14:59 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Drive Manager]
2009-06-26 14:56 450560 ----a-w- c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\~ el Philloydo ~\\Programs\\DC++\\DCPlusPlus.exe"=
"d:\\~ el Philloydo ~\\Programs\\DC++ strong\\StrongDC.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [10.9.2010 23:40 239240]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [10.9.2010 23:40 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [26.6.2009 16:56 102400]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys --> c:\windows\system32\DRIVERS\avfwim.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [18.4.2010 10:56 7808]
S3 gHidUsbF;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidUsbF.sys [18.4.2010 10:56 12800]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.3.2010 21:56 691696]
.
Obsah adresáře 'Naplánované úlohy'
2010-10-18 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2010-03-08 15:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\Philliboy\Data aplikací\Mozilla\Firefox\Profiles\qm1l15m6.profil\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\DivXplayer\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\DivXplayer\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="AFF91DBDD2393E54F331286DA8031DA89FAEB0C66DC396C96D49B05E597FA1BA88C760E16347A00F829E82A9993CDA0208B50BD1431FC1996F49896FD6F48B5D974D6C4B3DBA1C2312EC1230E7A3BC5BA193284936F0A10104065A942350C8090F8F58DBD4CF9D6FA23BA0FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA9C6AECB7A5D1407C038D530D6EB3452D2B699138BC585C758410BD59E2C5D4C0855DA5C4D56B8B45777553F6E6D19F4F01459E33A7BB008B706CFA6D85999C1D469ACD472E79CF0D04200F0D720134CC9EC1A4FB66C49372BE4407D665881CF025CE77B388AF6CFD41A923F5E91FD3A19B228936702A9E3AD8E6F3F3FE189B9E9B78CF8C6E3F468BD0615B77E76E1CB5B0CB2C2B69DD12C7D64D6A05D234BD12FBC7A4B4B0F67652DC2713CB2F4E89E54D1CD42941364C51F7DD22D40BD8383B45FF6407599C50589C17480FE28626688126FCC712B2CF6D7A223C36EC5134BA3C4AC7BFA05A9197A27538DE720C06AC38D736FC4A0131F35D4ED166C4600BA66CA28F414475087EECAA240765E9B8692B9998B0AA32AAB0446B82D47B97077AE7FDA797DCB1CCB16B95DC939DBAEA8494086D7BF582422D85BF2E18E9233396F281A27F66F93F366B4E12EC201D6557B7FBE5DE7575A1B8BB06AE3D6B43A4EE13A9FF3C685DEA098307246A6AE18A38408B07A892C47C23515553636FA971881628825B5D1CC8AAAD43540003898BE839F295F30D70B5936884AAE48B0860C0F0056588E104F7A5BFEB49AEBE225E5D840DD94674C69B1324448782E9762B30FA66EFC236EFCCE33BEDFAB0C6BA9ECAB16E471C5734CB68E322E128A642EAAC79D1AD6C70D8EF9F8D8889A06803C39E685B925DFA9BCE2F86F3FCE05C00DA3C760087D55846382BA46E5E604C391C737A0BA31D03CEC465ECF26D5C9CA48E3DC9F475C28DDFA82C833115FB3CD85288E33AD6BB6F130857259EDA10810CB441D3D4E33A195FDA8B8008A29C529177C243AB8FCB4827C5A2D47878073982AB2DED2F796A62035B5E4C1B13D705568FC7267E6E3F018708E49874715C35C183040A87FED1EE20D81E8C0CF68EDC440F3B62028F117D4CA04C53C655635496DD0A0C0877475361AF526F88CCB7B5E8AC0737D51CDD44BEF2FE4BBFE8F073E283FA34E95BB9EE99091421C79DAD9FCD5D76E4C96705D846597309213DFFB9369B831B892250CBECA66A58D075FCFF0D4BFB29015A767FB5A59EFFC86385D8E740E779BCAE939EC46997F668B7626FB5E930EFD4C942DA19E2636EE22E175EE33A3E3C57195201BA567BD724210ABD4ED8212FDA02FEC5923C0548E93F494E433752D3C9B08426B2E9D1833C7F1B1A8A151152FD6BE6B"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(504)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'lsass.exe'(564)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(3580)
c:\windows\system32\guard32.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\MPR.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Panda USB Vaccine\USBVaccine.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\documents and settings\Philliboy\Local Settings\Data aplikací\Google\Update\1.2.183.39\GoogleCrashHandler.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-10-18 21:32:49 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-18 19:32
Před spuštěním: 3 203 059 712
Po spuštění: 3 152 785 408
- - End Of File - - 4EC479D1ECC5BC33BE2EA01E153B1133
již jsem sem psal ale moje založené téma zmizelo, nevím proč... Zakládam tedy nové..
Pokračuju ve fázi kdy po logu z HijackThis mi bylo doporuceno projet PC Combofixem a na to do textaku zkopirovat nejaky text, ktery jsem pak hodil na ikonu Combofixu, nasledne probehla "rehabilitace"...
posilam zatim posledni log: (z 18.10.)
ComboFix 10-10-16.03 - Philliboy 18.10.2010 21:22:17.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3071.2603 [GMT 2:00]
Spuštěný z: c:\documents and settings\Philliboy\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Philliboy\Plocha\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: Avira Firewall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FILE ::
"c:\windows\nod32restoretemdono.reg"
"c:\windows\system32\Default\winlogon.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\nod32restoretemdono.reg
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EKRN
-------\Service_ekrn
-------\Service_EhttpSrv
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-18 do 2010-10-18 )))))))))))))))))))))))))))))))
.
2010-10-16 20:55 . 2010-10-16 20:55 -------- d-----w- c:\program files\Common Files\Java
2010-10-16 20:23 . 2010-10-16 20:23 40344 ----a-w- c:\documents and settings\Philliboy\Data aplikací\FbxU.exe
2010-10-16 01:55 . 2010-09-14 23:01 718296 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-10-16 01:55 . 2010-09-14 23:01 14808 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-10-13 13:09 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-13 13:09 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-13 13:09 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-09-27 17:36 . 2009-07-14 15:14 150768 ----a-w- c:\documents and settings\Philliboy\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((( SnapShot@2010-10-17_09.58.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-18 19:28 . 2010-10-18 19:28 16384 c:\windows\temp\Perflib_Perfdata_42c.dat
+ 2010-01-24 08:58 . 2010-10-17 17:11 530436 c:\windows\system32\Restore\rstrlog.dat
+ 2010-10-17 16:54 . 2010-10-17 16:54 3376640 c:\windows\Installer\58538.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-10-18 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2010-10-18 19:07 2735200 ----a-w- c:\program files\Vuze_Remote\tbVuz1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-10-18 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\tbVuz1.dll" [2010-10-18 2735200]
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PrtScr by FireStarter"="c:\program files\PrtScr\PrtScr.exe" [2008-03-19 1375744]
"Centrum.cz Notifikátor"="c:\program files\NetCentrum\Notifikator\Notifikator.exe" [2010-05-18 606720]
"Google Update"="c:\documents and settings\Philliboy\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-11-02 133104]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-28 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-25 14477312]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"nwiz"="nwiz.exe" [2009-01-15 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"mouseElf"="c:\progra~1\GAMING~1\MouseElf.EXE" [2005-07-15 208896]
"HD Tune"="c:\progra~1\HDTUNE~1\HDTune.exe" [2005-09-12 405504]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-01-27 185896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-10 2500552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
c:\documents and settings\Philliboy\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATnotes.lnk - c:\program files\ATnotes\ATnotes.exe [2003-11-10 1069056]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Philliboy^Nabídka Start^Programy^Po spuštění^TimeLeft.lnk]
path=c:\documents and settings\Philliboy\Nabídka Start\Programy\Po spuštění\TimeLeft.lnk
backup=c:\windows\pss\TimeLeft.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Centrum.cz Notifikátor]
2010-05-18 11:49 606720 ----a-w- c:\program files\NetCentrum\Notifikator\Notifikator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
2007-05-11 01:08 2512392 ----a-w- c:\windows\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 00:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\supertintin_skype]
2009-12-06 20:46 1043456 ----a-w- c:\program files\Supertintin for Skype\supertintin_skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-01-27 14:59 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Drive Manager]
2009-06-26 14:56 450560 ----a-w- c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\~ el Philloydo ~\\Programs\\DC++\\DCPlusPlus.exe"=
"d:\\~ el Philloydo ~\\Programs\\DC++ strong\\StrongDC.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [10.9.2010 23:40 239240]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [10.9.2010 23:40 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [26.6.2009 16:56 102400]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys --> c:\windows\system32\DRIVERS\avfwim.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [18.4.2010 10:56 7808]
S3 gHidUsbF;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidUsbF.sys [18.4.2010 10:56 12800]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.3.2010 21:56 691696]
.
Obsah adresáře 'Naplánované úlohy'
2010-10-18 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2010-03-08 15:45]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
FF - ProfilePath - c:\documents and settings\Philliboy\Data aplikací\Mozilla\Firefox\Profiles\qm1l15m6.profil\
FF - prefs.js: browser.startup.homepage - www.centrum.cz
FF - plugin: c:\program files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: c:\program files\DivXplayer\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\DivXplayer\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="AFF91DBDD2393E54F331286DA8031DA89FAEB0C66DC396C96D49B05E597FA1BA88C760E16347A00F829E82A9993CDA0208B50BD1431FC1996F49896FD6F48B5D974D6C4B3DBA1C2312EC1230E7A3BC5BA193284936F0A10104065A942350C8090F8F58DBD4CF9D6FA23BA0FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6171C11EC38DE3DA9C6AECB7A5D1407C038D530D6EB3452D2B699138BC585C758410BD59E2C5D4C0855DA5C4D56B8B45777553F6E6D19F4F01459E33A7BB008B706CFA6D85999C1D469ACD472E79CF0D04200F0D720134CC9EC1A4FB66C49372BE4407D665881CF025CE77B388AF6CFD41A923F5E91FD3A19B228936702A9E3AD8E6F3F3FE189B9E9B78CF8C6E3F468BD0615B77E76E1CB5B0CB2C2B69DD12C7D64D6A05D234BD12FBC7A4B4B0F67652DC2713CB2F4E89E54D1CD42941364C51F7DD22D40BD8383B45FF6407599C50589C17480FE28626688126FCC712B2CF6D7A223C36EC5134BA3C4AC7BFA05A9197A27538DE720C06AC38D736FC4A0131F35D4ED166C4600BA66CA28F414475087EECAA240765E9B8692B9998B0AA32AAB0446B82D47B97077AE7FDA797DCB1CCB16B95DC939DBAEA8494086D7BF582422D85BF2E18E9233396F281A27F66F93F366B4E12EC201D6557B7FBE5DE7575A1B8BB06AE3D6B43A4EE13A9FF3C685DEA098307246A6AE18A38408B07A892C47C23515553636FA971881628825B5D1CC8AAAD43540003898BE839F295F30D70B5936884AAE48B0860C0F0056588E104F7A5BFEB49AEBE225E5D840DD94674C69B1324448782E9762B30FA66EFC236EFCCE33BEDFAB0C6BA9ECAB16E471C5734CB68E322E128A642EAAC79D1AD6C70D8EF9F8D8889A06803C39E685B925DFA9BCE2F86F3FCE05C00DA3C760087D55846382BA46E5E604C391C737A0BA31D03CEC465ECF26D5C9CA48E3DC9F475C28DDFA82C833115FB3CD85288E33AD6BB6F130857259EDA10810CB441D3D4E33A195FDA8B8008A29C529177C243AB8FCB4827C5A2D47878073982AB2DED2F796A62035B5E4C1B13D705568FC7267E6E3F018708E49874715C35C183040A87FED1EE20D81E8C0CF68EDC440F3B62028F117D4CA04C53C655635496DD0A0C0877475361AF526F88CCB7B5E8AC0737D51CDD44BEF2FE4BBFE8F073E283FA34E95BB9EE99091421C79DAD9FCD5D76E4C96705D846597309213DFFB9369B831B892250CBECA66A58D075FCFF0D4BFB29015A767FB5A59EFFC86385D8E740E779BCAE939EC46997F668B7626FB5E930EFD4C942DA19E2636EE22E175EE33A3E3C57195201BA567BD724210ABD4ED8212FDA02FEC5923C0548E93F494E433752D3C9B08426B2E9D1833C7F1B1A8A151152FD6BE6B"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(504)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'lsass.exe'(564)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(3580)
c:\windows\system32\guard32.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\MPR.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Panda USB Vaccine\USBVaccine.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\documents and settings\Philliboy\Local Settings\Data aplikací\Google\Update\1.2.183.39\GoogleCrashHandler.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\oodag.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-10-18 21:32:49 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-18 19:32
Před spuštěním: 3 203 059 712
Po spuštění: 3 152 785 408
- - End Of File - - 4EC479D1ECC5BC33BE2EA01E153B1133