Prosím o kontrolu po opravě Combofixem II.
Napsal: 03 pro 2010 22:15
Dobrý večer, mám tu log z jiného počítače, který byl zpomalený a po několika minutách přestával reagovat, vyhledával jsem na fóru obdobné problémy a použil jsem Mbam a Combofix. Situace je o mnoho lepší, ale poprosil bych o kotrolu logu z Combofixu, děkuji:
ComboFix 10-12-02.06 - U�ivatel 03.12.2010 21:56:46.1.1 - x86
Syst�m Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1014.602 [GMT 1:00]
Spu�t�n� z: c:\documents and settings\U�ivatel\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Vytvo�en nov� Bod Obnoven�
.
((((((((((((((((((((((((((((((((((((((( Ostatn� v�mazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\UIVATE~1\LOCALS~1\Temp\lsass.exe
c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\looboopilu.exe
c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\nygeboojoo.exe
c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\wozykoufi.exe
c:\windows\nvsvc32.exe
c:\windows\system32\Drivers\zldimfny.sys
c:\windows\system32\drivers\cdrom.sys chyb�l.
Obnovena kopie z - c:\windows\$hf_mig$\KB932716-v2\SP3QFE\cdrom.sys
.
((((((((((((((((((((((((((((((((((((((( Ovlada�e/Slu�by )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_y1evdea99j
-------\Legacy_zldimfny
-------\Service_y1evdea99j
-------\Service_zldimfny
((((((((((((((((((((((((( Soubory vytvo�en� od 2010-11-03 do 2010-12-03 )))))))))))))))))))))))))))))))
.
2010-12-03 20:59 . 2008-05-02 10:49 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-11-22 21:37 . 2010-11-22 21:37 -------- d-----w- c:\documents and settings\U�ivatel\Data aplikac�\Malwarebytes
2010-11-22 19:50 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-22 19:50 . 2010-11-22 19:50 -------- d-----w- c:\documents and settings\All Users\Data aplikac�\Malwarebytes
2010-11-22 19:50 . 2010-11-22 19:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-22 19:50 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-22 19:49 . 2010-11-22 19:49 -------- d-----w- c:\documents and settings\Administrator
2010-11-16 18:59 . 2010-11-16 18:59 82944 ----a-w- c:\windows\system32\drivers\sbwhxbdp.sys
2010-11-16 10:57 . 2010-11-16 10:57 82944 ----a-w- c:\windows\system32\drivers\rqzdkncj.sys
2010-11-14 22:45 . 2010-11-14 22:45 91136 ----a-w- C:\winnt7.exe
2010-11-13 07:29 . 2010-11-13 07:29 19456 ---ha-w- c:\documents and settings\U�ivatel\rxgeel.exe
2010-11-13 06:29 . 2010-11-14 22:37 90 ----a-w- C:\t6.exe
2010-11-12 22:31 . 2010-11-12 22:31 91136 ----a-w- C:\ws7.exe
2010-11-12 13:52 . 2010-11-12 13:52 91136 --sh--r- c:\documents and settings\U�ivatel\Data aplikac�\juzjf.exe
2010-11-12 13:52 . 2010-11-12 14:11 41 ----a-w- C:\QuickTime1.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M v�pis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((((((( Spou�t�c� body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Pozn�mka* pr�zdn� z�znamy a legitimn� v�choz� �daje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2005-01-19 128000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-29 16132608]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-12 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-21 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-21 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-21 138008]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-01-13 111928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-06-17 185632]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
c:\documents and settings\All Users\Nab�dka Start\Programy\Po spu�t�n�\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Software Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2010-1-27 323584]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"d:\\Dokumenty\\Sta�en� soubory\\P1876832.JPG-www.facebook(2).exe"= c:\\WINDOWS\\nvsvc32.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [22.12.2007 17:08 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [22.12.2007 17:08 5248]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 9:03 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 9:06 95896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.8.2010 13:16 810144]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [5.8.2009 12:31 222968]
S2 gupdate;Slu�ba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29.8.2010 16:05 136176]
S2 rqzdkncj;rqzdkncj;c:\windows\system32\drivers\rqzdkncj.sys [16.11.2010 11:57 82944]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
.
Obsah adres��e 'Napl�novan� �lohy'
2010-11-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-12-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 15:04]
2010-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 15:04]
2010-12-03 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-09 20:18]
.
.
------- Dopl�kov� sken -------
.
uStart Page = hxxp://googleure.com
mStart Page = hxxp://home.sweetim.com
uInternet Connection Wizard,ShellNext = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\U�ivatel\Data aplikac�\Mozilla\Firefox\Profiles\sxic4otn.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\U�ivatel\Data aplikac�\Mozilla\Firefox\Profiles\sxic4otn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATN� POLO�KY ODSTRAN�N� Z REGISTRU - - - -
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKCU-Run-befakur - c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\nygeboojoo.exe
HKLM-Run-BroadcomWireless - c:\program files\Broadcom\Wireless\Utility\WlanUtil.exe
HKLM-Run-befakur - c:\windows\system32\nygeboojoo.exe
SafeBoot-rqzdkncj
SafeBoot-zldimfny.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-03 22:01
Windows 5.1.2600 Service Pack 2 NTFS
skenov�n� skryt�ch proces� ...
skenov�n� skryt�ch polo�ek 'Po spu�t�n�' ...
skenov�n� skryt�ch soubor� ...
sken byl �spe�n� dokon�en
skryt� soubory: 0
**************************************************************************
.
--------------------- Knihovny nav�zan� na b���c� procesy ---------------------
- - - - - - - > 'explorer.exe'(3608)
c:\program files\CursorXP\CurXP0.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Jin� spu�ten� procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\docume~1\UIVATE~1\LOCALS~1\Temp\RtkBtMnt.exe
.
**************************************************************************
.
Celkov� �as: 2010-12-03 22:05:24 - po��ta� byl restartov�n
ComboFix-quarantined-files.txt 2010-12-03 21:05
P�ed spu�t�n�m: 683�114�496
Po spu�t�n�: 1�565�110�272
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - E487B400426B0C108F9F92592B7EEF69
ComboFix 10-12-02.06 - U�ivatel 03.12.2010 21:56:46.1.1 - x86
Syst�m Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1014.602 [GMT 1:00]
Spu�t�n� z: c:\documents and settings\U�ivatel\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Vytvo�en nov� Bod Obnoven�
.
((((((((((((((((((((((((((((((((((((((( Ostatn� v�mazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\UIVATE~1\LOCALS~1\Temp\lsass.exe
c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\looboopilu.exe
c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\nygeboojoo.exe
c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\wozykoufi.exe
c:\windows\nvsvc32.exe
c:\windows\system32\Drivers\zldimfny.sys
c:\windows\system32\drivers\cdrom.sys chyb�l.
Obnovena kopie z - c:\windows\$hf_mig$\KB932716-v2\SP3QFE\cdrom.sys
.
((((((((((((((((((((((((((((((((((((((( Ovlada�e/Slu�by )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_y1evdea99j
-------\Legacy_zldimfny
-------\Service_y1evdea99j
-------\Service_zldimfny
((((((((((((((((((((((((( Soubory vytvo�en� od 2010-11-03 do 2010-12-03 )))))))))))))))))))))))))))))))
.
2010-12-03 20:59 . 2008-05-02 10:49 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-11-22 21:37 . 2010-11-22 21:37 -------- d-----w- c:\documents and settings\U�ivatel\Data aplikac�\Malwarebytes
2010-11-22 19:50 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-22 19:50 . 2010-11-22 19:50 -------- d-----w- c:\documents and settings\All Users\Data aplikac�\Malwarebytes
2010-11-22 19:50 . 2010-11-22 19:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-22 19:50 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-22 19:49 . 2010-11-22 19:49 -------- d-----w- c:\documents and settings\Administrator
2010-11-16 18:59 . 2010-11-16 18:59 82944 ----a-w- c:\windows\system32\drivers\sbwhxbdp.sys
2010-11-16 10:57 . 2010-11-16 10:57 82944 ----a-w- c:\windows\system32\drivers\rqzdkncj.sys
2010-11-14 22:45 . 2010-11-14 22:45 91136 ----a-w- C:\winnt7.exe
2010-11-13 07:29 . 2010-11-13 07:29 19456 ---ha-w- c:\documents and settings\U�ivatel\rxgeel.exe
2010-11-13 06:29 . 2010-11-14 22:37 90 ----a-w- C:\t6.exe
2010-11-12 22:31 . 2010-11-12 22:31 91136 ----a-w- C:\ws7.exe
2010-11-12 13:52 . 2010-11-12 13:52 91136 --sh--r- c:\documents and settings\U�ivatel\Data aplikac�\juzjf.exe
2010-11-12 13:52 . 2010-11-12 14:11 41 ----a-w- C:\QuickTime1.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M v�pis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
(((((((((((((((((((((((((((((((((( Spou�t�c� body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Pozn�mka* pr�zdn� z�znamy a legitimn� v�choz� �daje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2005-01-19 128000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-29 16132608]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-12 53248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-21 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-21 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-21 138008]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-01-13 111928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-06-17 185632]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-08-12 2215064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
c:\documents and settings\All Users\Nab�dka Start\Programy\Po spu�t�n�\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Software Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2010-1-27 323584]
c:\documents and settings\U�ivatel\Nab�dka Start\Programy\Po spu�t�n�\
0c865u6.exe [2010-11-13 60416]
0jff2lb.exe [2010-11-12 60416]
10003d7.exe [2010-11-16 60416]
1pl4hsi.exe [2010-11-16 60416]
1xdi3e1.exe [2010-11-12 60416]
26iddup.exe [2010-11-15 60416]
31jpvbh.exe [2010-11-15 60416]
3l60c86.exe [2010-11-13 60416]
4hii3zf.exe [2010-11-16 60416]
5nyzua5.exe [2010-11-16 60416]
5yyoupf.exe [2010-11-12 60416]
6juppgq.exe [2010-11-12 60416]
8703nio.exe [2010-11-14 60416]
9r6ii3z.exe [2010-11-16 60416]
a81mxi3uu3g.exe [2010-11-14 60416]
a870nioo3.exe [2010-11-14 60416]
agmhhyttkf.exe [2010-11-15 60416]
alcxxojjuv.exe [2010-11-15 60416]
aqwmm3yj.exe [2010-11-15 60416]
bbsnnezz.exe [2010-11-15 60416]
cidtupv66m.exe [2010-11-12 60416]
cxdjavbbmni.exe [2010-11-16 60416]
ddoz3v0r.exe [2010-11-16 60416]
e1u3w1rii.exe [2010-11-22 43008]
fvwcx6yeuk.exe [2010-11-16 60416]
i3k1aq1rii.exe [2010-11-22 43008]
it26l0h71j.exe [2010-11-13 60416]
kbrmsdtu.exe [2010-11-15 60416]
kq4hsizp8bw.exe [2010-11-16 60416]
lcxxojju.exe [2010-11-15 60416]
ll87nyoe5.exe [2010-11-12 60416]
ooafwrriddu.exe [2010-11-16 60416]
ozzpqlr66.exe [2010-11-12 60416]
qqlw3iyze0.exe [2010-11-13 60416]
qwc603f7br.exe [2010-11-16 60416]
rhhyy9kf.exe [2010-11-15 60416]
s6yj26l0h.exe [2010-11-13 60416]
sn03e1ab.exe [2010-11-12 60416]
teju3w1rii5.exe [2010-11-22 43008]
to11lbhito.exe [2010-11-13 60416]
ua8cnd7jpv.exe [2010-11-16 60416]
xtjjff2lbcx.exe [2010-11-16 60416]
y9kqqhhi6o6.exe [2010-11-13 60416]
yja1qg1xdi.exe [2010-11-12 60416]
yjkpa4cio.exe [2010-11-13 60416]
z3wrx1yjfql.exe [2010-11-16 60416]
ze3a1wxc87.exe [2010-11-12 60416]
zvl4hsizp8.exe [2010-11-16 60416]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"d:\\Dokumenty\\Sta�en� soubory\\P1876832.JPG-www.facebook(2).exe"= c:\\WINDOWS\\nvsvc32.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [22.12.2007 17:08 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [22.12.2007 17:08 5248]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 9:03 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 9:06 95896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12.8.2010 13:16 810144]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [5.8.2009 12:31 222968]
S2 gupdate;Slu�ba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29.8.2010 16:05 136176]
S2 rqzdkncj;rqzdkncj;c:\windows\system32\drivers\rqzdkncj.sys [16.11.2010 11:57 82944]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 13:49 227232]
.
Obsah adres��e 'Napl�novan� �lohy'
2010-11-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-12-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 15:04]
2010-11-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-29 15:04]
2010-12-03 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-09 20:18]
.
.
------- Dopl�kov� sken -------
.
uStart Page = hxxp://googleure.com
mStart Page = hxxp://home.sweetim.com
uInternet Connection Wizard,ShellNext = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\documents and settings\U�ivatel\Data aplikac�\Mozilla\Firefox\Profiles\sxic4otn.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Extension: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - c:\program files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\U�ivatel\Data aplikac�\Mozilla\Firefox\Profiles\sxic4otn.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - NEPLATN� POLO�KY ODSTRAN�N� Z REGISTRU - - - -
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
HKCU-Run-AdobeUpdater - c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
HKCU-Run-befakur - c:\documents and settings\U�ivatel\Data aplikac�\Microsoft\nygeboojoo.exe
HKLM-Run-BroadcomWireless - c:\program files\Broadcom\Wireless\Utility\WlanUtil.exe
HKLM-Run-befakur - c:\windows\system32\nygeboojoo.exe
SafeBoot-rqzdkncj
SafeBoot-zldimfny.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-03 22:01
Windows 5.1.2600 Service Pack 2 NTFS
skenov�n� skryt�ch proces� ...
skenov�n� skryt�ch polo�ek 'Po spu�t�n�' ...
skenov�n� skryt�ch soubor� ...
sken byl �spe�n� dokon�en
skryt� soubory: 0
**************************************************************************
.
--------------------- Knihovny nav�zan� na b���c� procesy ---------------------
- - - - - - - > 'explorer.exe'(3608)
c:\program files\CursorXP\CurXP0.dll
c:\windows\system32\btmmhook.dll
.
------------------------ Jin� spu�ten� procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\docume~1\UIVATE~1\LOCALS~1\Temp\RtkBtMnt.exe
.
**************************************************************************
.
Celkov� �as: 2010-12-03 22:05:24 - po��ta� byl restartov�n
ComboFix-quarantined-files.txt 2010-12-03 21:05
P�ed spu�t�n�m: 683�114�496
Po spu�t�n�: 1�565�110�272
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - E487B400426B0C108F9F92592B7EEF69