ComboFix 11-01-14.01 - Kocourek_Mourek 15.01.2011 13:36:46.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.3327.2341 [GMT 1:00]
Spuštěný z: c:\users\Kocourek_Mourek\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\KOCOUR~1\AppData\Local\Temp\salexte2.dll
c:\users\Kocourek_Mourek\AppData\Local\temp\salexte2.dll
c:\users\Kocourek_Mourek\AppData\Roaming\Local
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\0.ddi
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\1.ddi
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\mondlhvjdwqr.avi.ddr
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\settings.ddi
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\mondlhvjdwqr.avi
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\Temporary Downloaded Files\wqyuyuqjjuob.avi
c:\users\Kocourek_Mourek\AppData\Roaming\Local\Temp\DDM\Settings\wqyuyuqjjuob.avi.ddr
c:\users\Kocourek_Mourek\AppData\Roaming\Mozilla\Firefox\Profiles\cx4de126.default\searchplugins\webalta-search.xml
F:\install.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-12-15 do 2011-01-15 )))))))))))))))))))))))))))))))
.
2011-01-15 12:55 . 2011-01-15 12:55 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Local\temp
2011-01-15 12:55 . 2011-01-15 12:55 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-01-15 12:55 . 2011-01-15 12:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-15 11:09 . 2010-01-22 08:56 149456 ----a-w- c:\windows\SGDetectionTool.dll
2011-01-15 11:09 . 2010-01-22 08:55 767952 ----a-w- c:\windows\BDTSupport.dll
2011-01-15 11:09 . 2010-01-22 08:56 165840 ----a-w- c:\windows\PCTBDRes.dll
2011-01-15 11:09 . 2010-01-22 08:56 1652688 ----a-w- c:\windows\PCTBDCore.dll
2011-01-15 11:08 . 2010-02-05 08:18 100136 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2011-01-15 11:08 . 2010-02-05 08:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-01-15 11:08 . 2010-03-10 10:36 217032 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-01-15 11:08 . 2009-11-23 12:54 88040 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-01-15 11:08 . 2010-02-05 08:25 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2011-01-15 11:08 . 2011-01-15 12:00 -------- d-----w- c:\program files\Spyware Doctor
2011-01-15 11:08 . 2011-01-15 11:09 -------- d-----w- c:\program files\Common Files\PC Tools
2011-01-15 11:08 . 2011-01-15 11:08 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Roaming\PC Tools
2011-01-15 11:08 . 2011-01-15 11:08 -------- d-----w- c:\programdata\PC Tools
2011-01-15 09:11 . 2011-01-15 09:11 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Roaming\Malwarebytes
2011-01-15 09:11 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-15 09:11 . 2011-01-15 09:11 -------- d-----w- c:\programdata\Malwarebytes
2011-01-15 09:11 . 2011-01-15 09:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-15 09:11 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-15 09:03 . 2011-01-15 09:03 -------- d-----w- c:\program files\Armor2net
2011-01-13 21:25 . 2011-01-13 21:25 -------- d-----w- c:\program files\Enigma Software Group
2011-01-13 21:25 . 2011-01-15 09:09 -------- d-----w- c:\windows\41EBC322660F4D16A0DF53147210CBDB.TMP
2011-01-13 18:31 . 2011-01-13 18:31 122880 --sha-r- c:\windows\system32\iscsidscv.dll
2011-01-13 18:11 . 2011-01-13 18:11 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Local\bluesoleil
2011-01-12 17:15 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EC775067-B5FD-45FB-9700-0F59A48E9EE4}\mpengine.dll
2011-01-10 17:43 . 2011-01-10 17:43 -------- d-----w- c:\program files\Promixis
2011-01-09 08:34 . 2011-01-09 08:34 -------- d-----w- c:\program files\GNU
2011-01-08 09:53 . 2011-01-08 09:54 -------- d-----w- c:\users\všicni
2011-01-07 19:19 . 2011-01-07 19:19 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Roaming\PlatinumHideIP
2011-01-07 19:19 . 2011-01-07 19:19 -------- d-----w- c:\programdata\PlatinumHideIP
2011-01-07 19:18 . 2011-01-07 19:19 -------- d-----w- c:\program files\PlatinumHideIP
2011-01-07 18:58 . 2011-01-07 18:58 -------- d-----w- C:\pchd
2011-01-06 17:39 . 2011-01-06 17:39 -------- d-----w- c:\programdata\AltrixSoft
2011-01-06 17:39 . 2011-01-06 17:39 -------- d-----w- c:\program files\Hard Drive Inspector
2011-01-06 17:38 . 2011-01-06 17:38 -------- d-----w- c:\program files\Common Files\AltrixSoft
2011-01-02 21:06 . 2011-01-02 21:06 -------- d-----w- c:\users\Guest
2011-01-02 20:50 . 2011-01-02 20:50 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Roaming\AltrixSoft
2011-01-02 15:31 . 2011-01-02 15:31 -------- d-----w- c:\program files\SEC
2010-12-25 14:40 . 2010-12-25 14:40 -------- d-----w- c:\program files\Common Files\Skype
2010-12-24 19:13 . 2010-12-24 20:12 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Roaming\DivX
2010-12-24 19:13 . 2011-01-02 14:53 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-12-24 19:10 . 2011-01-02 14:53 -------- d-----w- c:\program files\DivX
2010-12-24 19:09 . 2011-01-02 14:53 -------- d-----w- c:\programdata\DivX
2010-12-22 12:52 . 2010-12-22 12:53 -------- d-----w- c:\program files\MonitorDriver
2010-12-19 13:20 . 2009-11-02 16:47 11520 ----a-w- c:\windows\system32\drivers\gMouUsb.sys
2010-12-19 13:20 . 2009-11-02 16:43 20480 ----a-w- c:\windows\system32\drivers\gHidPnp.sys
2010-12-19 13:19 . 2010-12-19 13:19 -------- d-----w- C:\Genius
2010-12-18 17:49 . 2010-12-18 17:49 -------- d-----w- c:\users\Kocourek_Mourek\AppData\Roaming\AltrixSoft-BackupByHDInspectorPortable
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-15 11:11 . 2010-08-07 15:00 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-01-15 11:11 . 2010-08-07 15:00 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-12-02 03:35 . 2010-12-02 03:35 4280320 ----a-w- c:\windows\system32\GPhotos.scr
2010-11-04 05:52 . 2010-12-15 17:09 978944 ----a-w- c:\windows\system32\wininet.dll
2010-11-04 05:48 . 2010-12-15 17:09 44544 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-04 04:41 . 2010-12-15 17:09 386048 ----a-w- c:\windows\system32\html.iec
2010-11-04 04:08 . 2010-12-15 17:09 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-11-02 04:41 . 2010-12-15 17:09 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-02 04:40 . 2010-12-15 17:09 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-11-02 04:40 . 2010-12-15 17:09 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-11-02 04:39 . 2010-12-15 17:09 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-11-02 04:34 . 2010-12-15 17:09 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-11-02 04:34 . 2010-12-15 17:09 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-11-01 18:22 . 2010-11-01 18:22 9216 ----a-r- c:\users\Kocourek_Mourek\AppData\Roaming\Microsoft\Installer\{7426428E-71D4-452C-BA13-B14E5EB52859}\Icon7426428E16.exe
2010-10-27 04:32 . 2010-12-15 17:09 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-25 12:44 . 2010-10-25 12:44 286376 ----a-w- c:\windows\system32\EroScr.scr
2010-10-20 16:41 . 2010-10-20 16:41 67904 ----a-w- c:\windows\system32\NLSSRV32.EXE
2010-10-20 16:38 . 2010-11-14 08:22 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
2010-10-20 16:38 . 2010-11-14 08:22 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
2010-10-20 04:54 . 2010-12-15 17:09 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-20 03:00 . 2010-12-15 17:09 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-10-20 02:58 . 2010-12-15 17:09 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-10-19 09:41 . 2010-04-20 18:03 222080 ------w- c:\windows\system32\MpSigStub.exe
.
------- Sigcheck -------
[-] 2010-04-20 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2010-08-02 323392]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"Platinum Hide IP"="c:\program files\PlatinumHideIP\PlatinumHideIP.exe" [2011-01-07 3802352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-02-22 2140880]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-03-13 8546848]
"ASUSGamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2009-07-30 380928]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2009-09-03 61440]
"HDInspector.exe"="c:\program files\Hard Drive Inspector\HDInspector.exe" [2010-12-23 943864]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2010-08-31 319574]
"ARMORWALL"="c:\program files\Armor2net\ArmorWall Personal Firewall\ArmorWall.exe" [2003-10-22 790528]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2011-1-2 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\persistentroutes]
"195.137.182.212,255.255.255.255,95.129.100.194,1"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 21:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 02:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-07-22 21:10 402432 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-07-14 01:14 1173504 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SolidWorks_CheckForUpdates]
2008-09-15 23:33 7218472 ----a-r- c:\program files\Common Files\Manažer instalací SolidWorks\Scheduler\sldIMScheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-12-20 18:32 1242448 -c--a-w- h:\hry\GTR Evolution\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"snpstd"=c:\windows\vsnpstd.exe
"SPIRunE"=Rundll32 SPIRunE.dll,RunDLLEntry
R0 APFTrans;ArmorWall Filter;c:\windows\System32\APFTrans.sys [x]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 GeniusMouseService;GeniusMouseService;c:\genius\ioCentre\GMouseService.exe [2010-03-11 12288]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 135664]
R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-04-24 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-04-24 79360]
R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-21 1343400]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-10-03 691696]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 BtHidBus;Bluetooth HID Bus Service;c:\windows\System32\Drivers\BtHidBus.sys [2010-04-06 20104]
S0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys [2009-05-11 154664]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-03-10 217032]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-02-22 114984]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
S2 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [2010-08-31 147563]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-02-22 133512]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2010-02-22 810120]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2010-02-22 96896]
S2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [2010-10-20 196928]
S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-10-20 67904]
S2 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\Installer\MSI5049.tmp [2010-11-13 189760]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-16 369256]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-05-21 173352]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-10-30 1021256]
S3 BTCOM;Bluetooth Serial port driver;c:\windows\system32\DRIVERS\btcomport.sys [2010-08-26 25992]
S3 BTCOMBUS;Bluetooth Serial Port Bus Service;c:\windows\system32\Drivers\btcombus.sys [2010-08-26 22024]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\Drivers\btnetBus.sys [2010-04-06 25864]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\Drivers\gHidPnp.Sys [2009-11-02 20480]
S3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\DRIVERS\gMouUsb.sys [2009-11-02 11520]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [2010-04-06 23048]
S3 t3;Sound Blaster X-Fi Xtreme Audio;c:\windows\system32\drivers\t3.sys [2009-06-04 413208]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2011-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 19:10]
2011-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-24 19:10]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.com/
uDefault_Search_URL = hxxp://webalta.ru/poisk
mStart Page = hxxp://
www.google.com/
mSearch Bar = hxxp://webalta.ru/poisk
uInternet Settings,ProxyServer = http=;ftp=;https=;
uSearchAssistant = hxxp://webalta.ru/poisk
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
LSP: c:\program files\Armor2net\ArmorWall Personal Firewall\NETDOG.DLL
TCP: {4BB97CB0-DA71-4363-9CE6-750702AB91EA} = 81.19.5.10,81.19.5.11
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
FF - ProfilePath - c:\users\Kocourek_Mourek\AppData\Roaming\Mozilla\Firefox\Profiles\cx4de126.default\
FF - prefs.js: browser.search.selectedEngine - Webalta Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://webalta.ru/poisk?q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: WebTran: {003D3EDC-99B9-4a34-9C20-60CB94F7E829} - %profile%\extensions\{003D3EDC-99B9-4a34-9C20-60CB94F7E829}
FF - Ext: DAEMON Tools Toolbar:
DTToolbar@toolbarnet.com - %profile%\extensions\
DTToolbar@toolbarnet.com
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: FlashGot: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} - %profile%\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 6.1.7600
CreateFile("\\.\PHYSICALDRIVE3"): Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPDFReadSpool]
"ImagePath"="c:\windows\Installer\MSI5049.tmp"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1092956291-3097705103-2560731289-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
[HKEY_USERS\S-1-5-21-1092956291-3097705103-2560731289-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(560)
c:\program files\Armor2net\ArmorWall Personal Firewall\NETDOG.DLL
- - - - - - - > 'Explorer.exe'(2184)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\windows\system32\BsMobileSDK.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
.
Celkový čas: 2011-01-15 13:57:14
ComboFix-quarantined-files.txt 2011-01-15 12:57
ComboFix2.txt 2010-09-28 05:49
ComboFix3.txt 2009-09-12 05:24
ComboFix4.txt 2009-09-12 04:31
Před spuštěním: Volných bajtů: 83 881 828 352
Po spuštění: Volných bajtů: 83 831 369 728
- - End Of File - - DB10AC33E8BED9C7D6CC539D73218AF2