Takže AVG jsem se nakonec zbavil. Znovu jsem zkusil spustit regedit a z ničehoc naběhl bez problému. Přesto ale radši přikládám ComboFix log
ComboFix 10-11-24.01 - Petr 25.11.2010 21:54:50.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1468 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-10-25 do 2010-11-25 )))))))))))))))))))))))))))))))
.
2010-11-25 19:49 . 2010-11-25 19:49 -------- d-----w- c:\program files\AVG
2010-11-25 19:40 . 2010-11-25 19:38 116373696 ----a-w- C:\avg_iswt_stf_all_90_730a1834.exe
2010-11-25 14:45 . 2010-11-25 14:45 -------- d---a-w- C:\.Trash-1000
2010-11-25 14:23 . 2010-11-25 14:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Martau
2010-11-25 14:23 . 2010-11-25 14:23 -------- d-----w- c:\program files\Total Uninstall 5
2010-11-25 14:03 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-11-25 14:03 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-11-24 16:47 . 2010-11-24 17:42 -------- d-----w- c:\program files\ERUNT
2010-11-24 15:09 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-11-24 14:13 . 2007-11-30 08:45 644400 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2010-11-24 12:44 . 2010-11-24 12:44 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\Bentley
2010-11-24 12:44 . 2010-11-24 12:44 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Bentley
2010-11-23 17:04 . 2010-11-23 17:04 -------- d-----w- c:\program files\Common Files\Bentley Shared
2010-11-23 17:04 . 2010-11-24 12:44 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Bentley
2010-11-23 17:04 . 2010-11-23 17:04 -------- d-----w- c:\program files\Bentley
2010-11-19 00:58 . 2010-11-19 00:58 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Blizzard
2010-11-18 23:48 . 2010-11-18 23:48 -------- d-----w- C:\Logs
2010-11-18 19:33 . 2010-11-19 00:55 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-11-08 12:07 . 2010-11-08 12:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2010-11-08 12:02 . 2010-11-08 12:02 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\Temp
2010-11-08 12:02 . 2010-11-08 12:02 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2010-11-08 12:02 . 2010-11-24 14:13 -------- d-----w- c:\program files\Google
2010-11-08 12:02 . 2010-11-10 12:07 -------- d-----w- c:\documents and settings\Petr\Local Settings\Data aplikací\Google
2010-11-06 10:37 . 2010-11-06 10:37 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-11-05 11:32 . 2010-11-05 11:32 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Spore
2010-11-04 19:35 . 2010-11-11 21:24 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Audacity
2010-11-04 19:35 . 2010-11-04 19:35 -------- d-----w- c:\program files\Audacity 1.3 Beta (Unicode)
2010-11-04 14:44 . 2010-11-04 14:55 -------- d-----w- c:\documents and settings\Petr\Data aplikací\Mp3tag
2010-11-04 14:43 . 2010-11-04 14:43 -------- d-----w- c:\program files\Mp3tag
2010-10-30 07:45 . 2010-10-30 07:45 45056 ----a-r- c:\documents and settings\Petr\Data aplikací\Microsoft\Installer\{1A4E47DC-6701-4A85-AA16-C1F99A44598C}\NewShortcut5_1A4E47DC67014A85AA16C1F99A44598C.exe
2010-10-30 07:45 . 2010-10-30 07:45 45056 ----a-r- c:\documents and settings\Petr\Data aplikací\Microsoft\Installer\{1A4E47DC-6701-4A85-AA16-C1F99A44598C}\NewShortcut1_1A4E47DC67014A85AA16C1F99A44598C.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 10:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-14 09:10 . 2010-06-30 20:49 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys
2010-09-11 02:19 . 2007-06-27 01:58 5417472 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-09-11 01:57 . 2010-01-16 20:16 57344 ----a-w- c:\windows\system32\aticalrt.dll
2010-09-11 01:57 . 2010-01-16 20:16 53248 ----a-w- c:\windows\system32\aticalcl.dll
2010-09-11 01:56 . 2010-01-16 20:16 4419584 ----a-w- c:\windows\system32\aticaldd.dll
2010-09-11 01:54 . 2010-01-16 20:16 16248832 ----a-w- c:\windows\system32\atioglxx.dll
2010-09-11 01:50 . 2010-01-16 17:31 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-09-11 01:43 . 2010-01-16 17:31 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-09-11 01:42 . 2007-06-27 01:58 300544 ----a-w- c:\windows\system32\ati2dvag.dll
2010-09-11 01:39 . 2007-06-27 01:41 3942880 ----a-w- c:\windows\system32\ati3duag.dll
2010-09-11 01:29 . 2007-06-27 01:14 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-09-11 01:26 . 2007-06-27 01:51 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-09-11 01:26 . 2007-06-27 01:51 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-09-11 01:26 . 2007-06-27 01:51 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-09-11 01:26 . 2007-06-27 01:50 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-09-11 01:26 . 2007-06-27 01:50 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-09-11 01:25 . 2007-06-27 01:31 2669312 ----a-w- c:\windows\system32\ativvaxx.dll
2010-09-11 01:25 . 2007-06-27 01:49 606208 ----a-w- c:\windows\system32\ati2evxx.exe
2010-09-11 01:24 . 2007-06-27 01:48 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-09-11 01:23 . 2010-06-10 15:32 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-09-11 01:19 . 2007-06-27 01:17 634880 ----a-w- c:\windows\system32\atikvmag.dll
2010-09-11 01:18 . 2010-01-16 20:16 192512 ----a-w- c:\windows\system32\atiadlxx.dll
2010-09-11 01:17 . 2007-06-27 01:16 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-09-11 01:13 . 2007-06-27 01:10 696320 ----a-w- c:\windows\system32\ati2cqag.dll
2010-09-11 01:11 . 2010-01-16 20:16 64512 ----a-w- c:\windows\system32\atimpc32.dll
2010-09-11 01:11 . 2010-01-16 20:16 64512 ----a-w- c:\windows\system32\amdpcom32.dll
2010-09-11 01:11 . 2007-06-27 01:15 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-09-10 05:52 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:52 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:52 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:52 . 2008-04-14 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:57 . 2008-04-14 12:00 1852800 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-11-25_15.14.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-25 20:45 . 2010-11-25 20:45 16384 c:\windows\Temp\Perflib_Perfdata_7c8.dat
+ 2007-03-22 18:17 . 2007-03-22 18:17 35440 c:\windows\system32\FM20ENU.DLL
- 2010-01-16 18:54 . 2010-01-16 18:54 23040 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 23040 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 61440 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 61440 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 27136 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 27136 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 11264 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 11264 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 86016 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 86016 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 12288 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 12288 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-01-16 18:54 . 2010-01-16 18:54 64088 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
+ 2003-07-15 06:00 . 2003-07-15 06:00 99904 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\TRANSMGR.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 11848 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
+ 2003-07-14 21:57 . 2003-07-14 21:57 58944 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 66616 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\SENDTO.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 74288 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\RM.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 40512 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-05-09 04:54 . 2003-05-09 04:54 77824 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-15 05:42 . 2003-07-15 05:42 37432 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\RECALL.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 93752 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 49208 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLWAB.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 64056 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLRPC.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 88128 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLMIME.DLL
+ 2003-07-15 05:41 . 2003-07-15 05:41 24640 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLACCT.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 27192 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 13888 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 56888 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 41528 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 16384 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 39488 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 55360 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-15 05:46 . 2003-07-15 05:46 42040 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 39488 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOSVFBR.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 35896 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOSV.DLL
+ 2003-07-14 21:52 . 2003-07-14 21:52 28224 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 55360 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
+ 2003-07-15 05:44 . 2003-07-15 05:44 25144 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOEURO.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 27704 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
+ 2003-07-15 05:52 . 2003-07-15 05:52 17464 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
+ 2003-07-15 05:51 . 2003-07-15 05:51 87104 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 35328 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 18944 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 17920 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
+ 2003-07-14 21:57 . 2003-07-14 21:57 87096 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
+ 2003-07-15 05:41 . 2003-07-15 05:41 13368 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\FINDER.EXE
+ 2003-07-15 05:57 . 2003-07-15 05:57 98360 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
+ 2003-07-15 05:56 . 2003-07-15 05:56 14904 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
+ 2003-07-26 01:57 . 2003-07-26 01:57 75832 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\DLGSETP.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 47160 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
+ 2003-07-15 05:53 . 2003-07-15 05:53 94768 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\AW.DLL
+ 2003-07-15 05:57 . 2003-07-15 05:57 38968 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 87616 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\ADDRPARS.DLL
+ 2010-11-25 19:23 . 2010-11-25 19:23 66936 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2010-01-16 18:54 . 2010-01-16 18:54 4096 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 4096 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2010-01-16 18:03 . 2010-11-25 19:41 254272 c:\windows\system32\FNTCACHE.DAT
- 2010-01-16 18:03 . 2010-10-13 18:51 254272 c:\windows\system32\FNTCACHE.DAT
- 2010-01-16 18:54 . 2010-01-16 18:54 409600 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 409600 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 286720 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 286720 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 249856 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 249856 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 794624 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 794624 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 135168 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 135168 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2010-01-16 18:54 . 2010-11-25 19:24 593920 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2010-01-16 18:54 . 2010-01-16 18:54 593920 c:\windows\Installer\{90110405-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2003-07-21 18:46 . 2003-07-21 18:46 390712 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\RTFHTML.DLL
+ 2003-07-15 10:18 . 2003-07-15 10:18 430136 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
+ 2003-07-15 05:43 . 2003-07-15 05:43 139320 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLPH.DLL
+ 2003-07-15 05:45 . 2003-07-15 05:45 196152 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLOOK.EXE
+ 2003-07-08 18:48 . 2003-07-08 18:48 115288 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
+ 2003-07-15 05:44 . 2003-07-15 05:44 102968 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLCTL.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 242240 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 828472 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
+ 2003-07-15 10:14 . 2003-07-15 10:14 283696 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OIS.EXE
+ 2010-01-16 18:54 . 2010-01-16 18:54 223800 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OFFICE.DLL
+ 2003-07-15 06:00 . 2003-07-15 06:00 145984 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
+ 2003-07-24 05:40 . 2003-07-24 05:40 482872 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
+ 2003-07-15 05:56 . 2003-07-15 05:56 124984 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
+ 2003-07-15 06:02 . 2003-07-15 06:02 627256 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
+ 2003-06-19 23:05 . 2003-06-19 23:05 364648 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
+ 2003-07-15 10:18 . 2003-07-15 10:18 376888 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSORUN.DLL
+ 2003-07-23 21:35 . 2003-07-23 21:35 127032 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
+ 2003-07-15 02:14 . 2003-07-15 02:14 106552 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
+ 2003-07-14 21:57 . 2003-07-14 21:57 120888 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
+ 2002-04-09 19:14 . 2002-04-09 19:14 187560 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSMDUN80.DLL
+ 2002-12-17 18:08 . 2002-12-17 18:08 359600 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSDMENG.DLL
+ 2003-07-14 21:58 . 2003-07-14 21:58 230968 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
+ 2003-07-15 05:46 . 2003-07-15 05:46 176696 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MIMEDIR.DLL
+ 2003-05-28 22:42 . 2003-05-28 22:42 342616 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\METCONV.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 443904 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 252928 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 758784 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
+ 2003-05-28 22:42 . 2003-05-28 22:42 514680 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\INTLNAME.DLL
+ 2003-07-24 05:32 . 2003-07-24 05:32 121400 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\IMPMAIL.DLL
+ 2003-07-15 05:53 . 2003-07-15 05:53 161336 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\IETAG.DLL
+ 2003-07-26 02:14 . 2003-07-26 02:14 799288 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
+ 2003-07-15 05:40 . 2003-07-15 05:40 179768 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\FPERSON.DLL
+ 2003-07-15 06:36 . 2003-07-15 06:36 186424 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
+ 2003-07-31 22:19 . 2003-07-31 22:19 131648 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\ENVELOPE.DLL
+ 2003-07-15 02:14 . 2003-07-15 02:14 350264 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
+ 2010-11-25 19:23 . 2010-11-25 19:23 226656 c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2007-06-06 09:53 . 2007-06-06 09:53 1195888 c:\windows\system32\FM20.DLL
+ 2005-10-26 13:59 . 2005-10-26 13:59 2883072 c:\windows\Installer\efa000.msp
+ 2010-10-22 12:25 . 2010-10-22 12:25 5521408 c:\windows\Installer\ef9efa.msp
+ 2003-08-03 17:52 . 2003-08-03 17:52 2808376 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
+ 2003-07-31 22:21 . 2003-07-31 22:21 1782840 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE
+ 2003-07-30 19:40 . 2003-07-30 19:40 6133312 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE
+ 2003-08-01 22:09 . 2003-08-01 22:09 8086072 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OWC11.DLL
+ 2003-08-10 06:06 . 2003-08-10 06:06 7522360 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLLIB.DLL
+ 2003-07-07 20:36 . 2003-07-07 20:36 2058343 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2003-07-15 06:05 . 2003-07-15 06:05 1054264 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
+ 2003-06-19 00:31 . 2003-06-19 00:31 1033216 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
+ 2003-07-11 09:15 . 2003-07-11 09:15 1292872 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSONSEXT.DLL
+ 2002-12-17 18:09 . 2002-12-17 18:09 2071752 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSOLAP80.DLL
+ 2002-12-17 18:08 . 2002-12-17 18:08 1383592 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\MSDMINE.DLL
+ 2003-07-15 06:11 . 2003-07-15 06:11 2139192 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE
+ 2003-07-26 02:00 . 2003-07-26 02:00 1157696 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL
+ 2003-07-24 06:01 . 2003-07-24 06:01 1949240 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\FPCUTL.DLL
+ 2003-08-06 20:24 . 2003-08-06 20:24 12037688 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE
+ 2003-08-13 09:34 . 2003-08-13 09:34 10073144 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE
+ 2007-07-27 07:43 . 2007-07-27 07:43 109673984 c:\windows\Installer\ef9fea.msp
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OscarEditor"="c:\program files\OSCAR Editor\OscarEditor.exe" [2009-06-16 3331584]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Petr\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-1-16 3444008]
update.lnk - c:\program files\ERUNT\update.bat [2010-11-24 108]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
CoreCenter.lnk - c:\program files\MSI\Core Center\CoreCenter.exe [2010-6-11 928256]
Samsung Multimedia Keyboard.lnk - c:\program files\SAMSUNG\Samsung Multimedia Keyboard\gpkbd.exe [2010-1-16 585728]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Hry\\DiRT2\\dirt2_game.exe"=
"e:\\Hry\\FEAR\\FEAR.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"e:\\Hry\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"e:\\Hry\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"e:\\Hry\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"57039:TCP"= 57039:TCP:Pando Media Booster
"57039:UDP"= 57039:UDP:Pando Media Booster
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.1.2010 10:41 685816]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [23.3.2010 17:38 270888]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [23.3.2010 17:38 65576]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 12:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.11.2010 13:02 136176]
S2 SbPF.Launcher;SbPF.Launcher;"c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe" --> c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [?]
S3 ldiskl;ldiskl;\??\c:\docume~1\Petr\LOCALS~1\Temp\ldiskl.sys --> c:\docume~1\Petr\LOCALS~1\Temp\ldiskl.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 12:16 753504]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - PCAlertDriver
.
Obsah adresáře 'Naplánované úlohy'
2010-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-08 12:02]
2010-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-08 12:02]
2010-11-25 c:\windows\Tasks\update.job
- c:\program files\ERUNT\update.bat [2010-11-24 17:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.aramayapalim.com
mStart Page = hxxp://
www.aramayapalim.com
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {165627AB-B9A7-4091-B08D-72CA6D91796B} = 192.168.0.50
TCP: {F60AA547-CBB3-4124-A3E7-65229977A4A9} = 10.0.0.138
.
.
------- Asociace souborů -------
.
.scr=AutoCADScriptFile
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-11-25 21:58
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-220523388-1078145449-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c0,ac,67,08,ce,56,32,5a,6e,7f,e0,1a,31,11,51,60,6e,b7,26,57,16,7c,91,
ad,1e,28,d8,b1,96,13,f1,6f,98,52,af,c3,bb,3e,40,71,67,6b,d9,96,97,9b,1b,75,\
"??"=hex:74,46,de,da,ce,a6,b0,cd,f7,64,0d,30,a0,3c,53,3a
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="3935213D7D2AAEBACF18C4171FC0BEA0970D5DE4F7D8F660F61D862F63606A19F191E8DDF92EC734855A933F714EEB90933DD95D911B9487665FC6AA422F973BBE95A2791A1DA838EC0C02C1897FBBE00539673F10536BB81DA47B530323F3691675484261893C2980E091B83FF4F2EA8752B328B9CC385F747B976B7B5656FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808FEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933F3730898A13606CAFD4F8747D5E8AD89508C973AB16DDF331BC1527C0174B7735A8D545D5F1E8E10470DC561D683E5A2B6EEAA42E0C827632D140A0428CB2C82D9B6E295A44E1F9250AEEA06014A25859BC2ADC2D9BC5BB49DFBE56FBC15A27C4220BA4407253E647CAABC018F2B3E5F98D9427199E73B0E5CCF857E21C2E5A1F6C19A507185623F4435B603119B7480D94C41E575EE7879E8283CD00FCBB5D46E55730520D5797E35C906A06712815EA277B69F94FA38A3DB6214EF13A7441C35D7EB922781E120ED2A8D524A0B1212467A60FE723915DE5F1FC9438F5538A2E80D5C0C69F5EFCA23D5E3F3C40648D7AE3A334860599DA131C4CB9B37D52DB7BD79D3E9A1A6EBC49D9754C635063811D9DE56A60011D306A3FB412A152F32CD7BE81105DE0B127AB8F65C6F4E936A42D85425A7CA97AD491C31800683EB4A7C7C698C1E821C91FBE546AE741639DD9550CA2F3B8BAA944D971698A8B397EBFE304BEED941D98E7CA996B2C3680802D57936B7B7E28BE698219FC7712CC483329AA614BD254522551B3F022E7412BCF5A14F375643FCF555DC8703A1C489EE9B52548FB60D67D780E55C6B673CEFE4092B125834754889CF004AF2E0290001DF82722712A948AE1F4C4DF186963ECAC90ABD7B53953B5AFA5629F4385B4402CBE9E4D18580F89C742234CB8AAD9AAD93C8D6339892A596EDBC2998973079ABCBDDD0BFA76C0A88E94EF86252022942680327474D315CE0DF261423504F45ADF5C31FD0729B93CD094E4556A1E41232EC6C38332088B74E3198770C1A37502BFE977F1CC70E303E83B28AF8227D021AE8C7DB27A0049569612F23810D37C7BAC2E864E9E91AFD1C2C9DF95060C5A78CCA6F2606C4E3D4B019172D6229F4DEE73FDA82B700EA20A07C4A8B174C8E358C2350EFE667BB5A959F926D44D168CAB017A4543795FB3C770F037B3DB9F8659326EC5317C3F38F7D657803EECBDFC4891490994E1A22FD402429C6E3E1FB710FADD831147D48E1447A334D5F417A8A581E7ED196E180940F1F30B2E2E0E21960B53E2E9298C640B69541F245C12DDD79C4E246DD229031EC8721444338CC22DB60DA337A7D5520169034DC073FC105BA3BC37EA4F7A20A540B184844C9AB51CB717F"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1528)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
- - - - - - - > 'explorer.exe'(2396)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\windows\system32\webcheck.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\program files\Common Files\Microsoft Shared\Web Components\11\1029\OWCI11.DLL
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ImgUtil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-11-25 22:00:24
ComboFix-quarantined-files.txt 2010-11-25 21:00
Před spuštěním: Volných bajtů: 23 455 211 520
Po spuštění: Volných bajtů: 23 458 340 864
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 0E0BB42D69E184EBFAF340D60BB07DD3