Modrá smrt
Napsal: 11 bře 2011 15:23
Dobrý den,
už po několik dní nám naskakuje modrá smrt. A ne jednou za den. (Buď když toho na počítači děláme hodně, nebo naopak nic.) Už dřív jsme s tím měli problém, hrozně zasviněný PC. Přikládám log z Combofix. Dík za jakýkoli nápady...
ComboFix 11-03-10.03 - Lenííísek 11.03.2011 15:06:49.10.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.508 [GMT 1:00]
Spuštěný z: d:\programy\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-11 do 2011-03-11 )))))))))))))))))))))))))))))))
.
.
2011-03-10 12:49 . 2004-07-15 23:20 733184 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2011-03-10 12:49 . 2004-07-15 23:20 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2011-03-10 12:49 . 2004-07-15 23:19 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2011-03-10 12:49 . 2004-07-15 23:18 172032 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2011-03-10 12:49 . 2004-07-15 23:18 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2011-03-10 12:49 . 2011-03-10 12:49 180356 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2011-03-10 12:49 . 2011-03-10 12:49 303236 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2011-03-05 15:39 . 2011-03-05 15:39 -------- d-----w- c:\documents and settings\Tomáš\Local Settings\Data aplikací\Cyberlink
2011-03-05 11:42 . 2011-03-05 11:42 -------- d-----w- c:\documents and settings\Lenííísek\Local Settings\Data aplikací\Cyberlink
2011-02-27 17:32 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-02-27 17:32 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-02-27 17:32 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-02-27 17:32 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-02-27 17:32 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-02-27 17:32 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-02-27 17:32 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-02-27 17:32 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-02-27 16:24 . 2011-02-27 16:24 -------- d-----w- c:\documents and settings\Lenííísek\Data aplikací\progeSOFT
2011-02-27 16:22 . 2011-02-27 16:22 -------- d-----w- c:\documents and settings\All Users\progeSOFT
2011-02-27 16:21 . 2010-03-16 11:15 540672 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\apc64.dll
2011-02-27 16:21 . 2010-03-16 11:15 462901 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\link.exe
2011-02-27 16:21 . 2010-03-16 11:15 252416 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\vba6mtrt.dll
2011-02-27 16:21 . 2010-03-16 11:15 180276 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\mspdb60.dll
2011-02-27 16:21 . 2010-03-16 11:15 14096 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\vb6debug.dll
2011-02-27 16:21 . 2010-03-16 11:15 57344 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\1033\apc60itl.dll
2011-02-27 16:21 . 2010-03-16 11:15 159744 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL
2011-02-27 16:20 . 2010-03-16 11:13 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2011-02-27 16:19 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2011-02-27 16:19 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2011-02-27 16:19 . 2010-03-16 11:16 61440 ----a-w- c:\windows\system32\wintab32.dll
2011-02-27 16:19 . 2010-03-16 11:14 73728 ----a-w- c:\windows\system32\skeydrv.dll
2011-02-27 16:19 . 2010-03-16 11:14 129632 ----a-w- c:\windows\system32\skeyinst.dll
2011-02-27 16:19 . 2010-03-16 11:14 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2011-02-27 16:19 . 2011-02-27 16:19 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2011-02-27 16:19 . 2010-03-16 11:12 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2011-02-27 16:19 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2011-02-27 16:19 . 2001-03-13 14:51 1066176 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2011-02-27 07:49 . 2011-02-27 07:49 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2011-02-27 07:37 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-02-27 07:37 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2011-02-27 07:37 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-02-15 14:08 . 2011-02-15 14:08 -------- d-----w- c:\program files\Common Files\Skype
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-05 11:33 . 2009-08-17 16:20 29480 ----a-w- c:\windows\system32\msxml3a.dll
2011-02-27 11:31 . 2009-09-25 12:33 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-02-27 11:31 . 2010-08-28 11:48 215128 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-02-27 11:31 . 2009-09-25 12:32 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-02-27 07:49 . 2009-09-25 12:32 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-02-24 19:57 . 2008-10-06 19:21 196608 ----a-w- c:\windows\system32\drivers\nStandard.bin
2011-01-04 17:56 . 2009-09-25 12:32 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2010-12-20 18:09 . 2010-12-20 18:09 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-12-19 11:38 . 2010-12-13 13:52 53248 ----a-w- c:\windows\system32\apache.dll
2009-10-20 12:10 . 2009-10-20 12:10 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-03-09_20.26.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-11 14:01 . 2011-03-11 14:01 16384 c:\windows\Temp\Perflib_Perfdata_35c.dat
+ 2010-09-23 02:47 . 2010-09-23 02:47 35760 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\reader_sl.exe
+ 2010-09-23 01:03 . 2010-09-23 01:03 99776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\eula.exe
+ 2010-09-23 00:52 . 2010-09-23 00:52 27048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\acrotextextractor.exe
+ 2010-09-22 16:12 . 2010-09-22 16:12 15800 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroRd32Info.exe
+ 2010-09-10 16:17 . 2010-09-10 16:17 684032 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\JP2KLib.dll
+ 2010-09-22 18:41 . 2010-09-22 18:41 542168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AdobeCollabSync.exe
+ 2010-09-23 02:47 . 2010-09-23 02:47 349616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroRd32.exe
+ 2010-09-22 16:04 . 2010-09-22 16:04 660912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroPDF.dll
+ 2010-09-22 17:39 . 2010-09-22 17:39 280024 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\acrobroker.exe
+ 2010-09-22 16:50 . 2010-09-22 16:50 251296 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\a3dutility.exe
+ 2010-09-22 16:05 . 2010-09-22 16:05 2405784 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\rt3d.dll
+ 2010-06-19 15:51 . 2010-06-19 15:51 5713920 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AGM.dll
+ 2011-01-31 10:45 . 2011-01-31 10:45 11135488 c:\windows\Installer\106b1.msp
+ 2010-09-23 01:03 . 2010-09-23 01:03 20460984 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroRd32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2010-12-27 18:44 3911776 ----a-w- c:\program files\BitTorrentBar\tbBit0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\free-downloads.net\tbfre2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre2.dll" [2010-10-18 3908192]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBit0.dll" [2010-12-27 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre2.dll" [2010-10-18 3908192]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\tbBit0.dll" [2010-12-27 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-19 68856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"Google Update"="c:\documents and settings\Lenííísek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-02-27 135664]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"ASUSGamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2007-07-12 380928]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-30 149280]
"QuickTime Task"="d:\programy\QuickTime\qttask.exe" [2007-06-29 286720]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-20 30192]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"RemoteControl10"="d:\programy\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-11-17 75048]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\Tom ç\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
.
c:\documents and settings\Lenˇˇˇsek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "d:\programy\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^E-mail monitor 1.1.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\E-mail monitor 1.1.lnk
backup=c:\windows\pss\E-mail monitor 1.1.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^VirtuaWin.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\VirtuaWin.lnk
backup=c:\windows\pss\VirtuaWin.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Hamachi.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Hamachi.lnk
backup=c:\windows\pss\Hamachi.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Stardock ObjectDock.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Yahoo! Widgets.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Yahoo! Widgets.lnk
backup=c:\windows\pss\Yahoo! Widgets.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2010-12-01 17:58 397176 ----a-w- d:\programy\BitTorrent\BitTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-01-05 08:18 133432 ----a-w- d:\programy\ICQ7.2\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-02-24 19:17 385928 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RadioSure]
2010-02-02 18:17 913920 ----a-w- d:\programy\RadioSure-2.0.886-portable\RadioSure.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-10-19 18:28 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Czech\\setup.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"d:\\Programy\\ICQ7.2\\ICQ.exe"=
"d:\\Programy\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Programy\\aTube Catcher 1.0\\yct.exe"=
"d:\\Programy\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\Programy\\Skype\\Phone\\Skype.exe"=
"d:\\hry\\ANNO 1404\\Anno4.exe"=
"d:\\hry\\ANNO 1404\\tools\\Anno4Web.exe"=
"d:\\hry\\ANNO 1404\\tools\\Benchmark.exe"=
"d:\\hry\\ANNO 1404\\Addon.exe"=
"d:\\hry\\ANNO 1404\\tools\\AddonWeb.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Tunngle\\TnglCtrl.exe"=
"c:\\Program Files\\Tunngle\\Tunngle.exe"=
"d:\\hry\\World of Warcraft Wrath of The Lich King\\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"=
"d:\\Programy\\VLC\\vlc.exe"=
"d:\\hry\\Call of Duty - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Tommi\\uTorrent\\uTorrent.exe"=
"d:\\hry\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"d:\\Programy\\PowerDVD10\\PowerDVD Cinema\\PowerDVDCinema10.exe"=
"d:\\Programy\\PowerDVD10\\PowerDVD10.exe"=
"d:\\hry\\Farming Simulator 2011\\FarmingSimulator2011.exe"=
"d:\\hry\\Farming Simulator 2011\\game.exe"=
"d:\\hry\\Tom Clancy's Splinter Cell Chaos Theory\\System\\splintercell3.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23776:TCP"= 23776:TCP:BitComet 23776 TCP
"23776:UDP"= 23776:UDP:BitComet 23776 UDP
"22147:TCP"= 22147:TCP:BitComet 22147 TCP
"22147:UDP"= 22147:UDP:BitComet 22147 UDP
"3724:TCP"= 3724:TCP:1
"6112:TCP"= 6112:TCP:2
"6113:TCP"= 6113:TCP:3
"6114:TCP"= 6114:TCP:4
"4000:TCP"= 4000:TCP:5
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.5.2010 21:06 165584]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/03/05 12:36];d:\programy\PowerDVD10\NavFilter\000.fcl [17.11.2010 21:29 87536]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.5.2010 21:06 17744]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [12.10.2008 10:22 246520]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [16.11.2009 17:33 50704]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [31.10.2010 11:15 583640]
R2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [26.12.2010 19:04 718072]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [12.12.2010 16:41 27136]
S2 gupdate1c99eacbb9579ce;Služba Google Update (gupdate1c99eacbb9579ce);c:\program files\Google\Update\GoogleUpdate.exe [6.3.2009 23:41 133104]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;"c:\program files\LogMeIn Hamachi\hamachi-2.exe" -s --> c:\program files\LogMeIn Hamachi\hamachi-2.exe [?]
S3 AMDMSRIO;AMDMSRIO;\??\c:\docume~1\LENSEK~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys --> c:\docume~1\LENSEK~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [20.10.2009 13:10 30192]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.10.2008 11:53 717296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 12:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-06 22:41]
.
2011-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-06 22:41]
.
2011-03-10 c:\windows\Tasks\RMSchedule.job
- c:\program files\Registry Mechanic\RegMech.exe [2010-10-31 07:46]
.
2011-02-19 c:\windows\Tasks\Wise Disk Cleaner Schedule Task.job
- d:\tommi\Wise Disk Cleaner\WiseDiskCleaner.exe [2011-01-03 19:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{E5E5909F-B771-4E28-9BF5-54DD753E32A6} - d:\programy\FreshDownload\fd.exe
TCP: {5A3E5E72-BE8F-47B5-B78C-CC3A73FC9A14} = 195.146.99.31,62.204.224.2,62.204.224.1
TCP: {C8AC6BBA-4F3A-4BF9-ACF9-87A87BDE9EAD} = 62.77.67.2,62.84.132.6
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-11 15:10
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\d:\programy\PowerDVD10\NavFilter\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2852)
d:\programy\SugarSync\SugarSyncShellExt.dll
d:\programy\MediaMonkey\DeskPlayer.dll
d:\programy\CyberLink\PowerDVD\deskband32.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\msi.dll
d:\programy\Fences\FencesMenu.dll
d:\programy\fences\DesktopDock.dll
.
Celkový čas: 2011-03-11 15:13:08
ComboFix-quarantined-files.txt 2011-03-11 14:13
ComboFix2.txt 2011-03-10 20:36
ComboFix3.txt 2011-03-09 20:28
ComboFix4.txt 2010-09-25 15:41
ComboFix5.txt 2011-03-11 14:05
.
Před spuštěním: 2 008 326 144
Po spuštění: 2 045 222 912
.
- - End Of File - - 4904935C68ABA8C3DB2A664CE68EAD41
už po několik dní nám naskakuje modrá smrt. A ne jednou za den. (Buď když toho na počítači děláme hodně, nebo naopak nic.) Už dřív jsme s tím měli problém, hrozně zasviněný PC. Přikládám log z Combofix. Dík za jakýkoli nápady...
ComboFix 11-03-10.03 - Lenííísek 11.03.2011 15:06:49.10.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.508 [GMT 1:00]
Spuštěný z: d:\programy\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-11 do 2011-03-11 )))))))))))))))))))))))))))))))
.
.
2011-03-10 12:49 . 2004-07-15 23:20 733184 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iKernel.dll
2011-03-10 12:49 . 2004-07-15 23:20 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\ctor.dll
2011-03-10 12:49 . 2004-07-15 23:19 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iscript.dll
2011-03-10 12:49 . 2004-07-15 23:18 172032 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iuser.dll
2011-03-10 12:49 . 2004-07-15 23:18 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe
2011-03-10 12:49 . 2011-03-10 12:49 180356 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\iGdi.dll
2011-03-10 12:49 . 2011-03-10 12:49 303236 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\setup.dll
2011-03-05 15:39 . 2011-03-05 15:39 -------- d-----w- c:\documents and settings\Tomáš\Local Settings\Data aplikací\Cyberlink
2011-03-05 11:42 . 2011-03-05 11:42 -------- d-----w- c:\documents and settings\Lenííísek\Local Settings\Data aplikací\Cyberlink
2011-02-27 17:32 . 2010-06-02 03:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-02-27 17:32 . 2010-06-02 03:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-02-27 17:32 . 2010-06-02 03:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-02-27 17:32 . 2010-05-26 10:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-02-27 17:32 . 2010-05-26 10:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-02-27 17:32 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-02-27 17:32 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-02-27 17:32 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-02-27 17:32 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-02-27 16:24 . 2011-02-27 16:24 -------- d-----w- c:\documents and settings\Lenííísek\Data aplikací\progeSOFT
2011-02-27 16:22 . 2011-02-27 16:22 -------- d-----w- c:\documents and settings\All Users\progeSOFT
2011-02-27 16:21 . 2010-03-16 11:15 540672 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\apc64.dll
2011-02-27 16:21 . 2010-03-16 11:15 462901 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\link.exe
2011-02-27 16:21 . 2010-03-16 11:15 252416 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\vba6mtrt.dll
2011-02-27 16:21 . 2010-03-16 11:15 180276 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\mspdb60.dll
2011-02-27 16:21 . 2010-03-16 11:15 14096 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\vb6debug.dll
2011-02-27 16:21 . 2010-03-16 11:15 57344 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\1033\apc60itl.dll
2011-02-27 16:21 . 2010-03-16 11:15 159744 ----a-w- c:\program files\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL
2011-02-27 16:20 . 2010-03-16 11:13 2134016 ----a-w- c:\windows\system32\cdintf251.dll
2011-02-27 16:19 . 1999-11-08 12:45 339968 ----a-w- c:\windows\system32\Slide.ocx
2011-02-27 16:19 . 1999-07-21 16:25 274432 ----a-w- c:\windows\system32\DwgThumbnail.ocx
2011-02-27 16:19 . 2010-03-16 11:16 61440 ----a-w- c:\windows\system32\wintab32.dll
2011-02-27 16:19 . 2010-03-16 11:14 73728 ----a-w- c:\windows\system32\skeydrv.dll
2011-02-27 16:19 . 2010-03-16 11:14 129632 ----a-w- c:\windows\system32\skeyinst.dll
2011-02-27 16:19 . 2010-03-16 11:14 43968 ----a-w- c:\windows\system32\drivers\eusk3usb.sys
2011-02-27 16:19 . 2011-02-27 16:19 1115704 ----a-w- c:\windows\system32\O2CPlayer.OCX
2011-02-27 16:19 . 2010-03-16 11:12 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2011-02-27 16:19 . 1998-04-24 23:00 368912 ----a-w- c:\windows\system32\vbar332.dll
2011-02-27 16:19 . 2001-03-13 14:51 1066176 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2011-02-27 07:49 . 2011-02-27 07:49 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2011-02-27 07:37 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-02-27 07:37 . 2009-09-04 16:44 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2011-02-27 07:37 . 2009-09-04 16:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2011-02-27 07:37 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-02-15 14:08 . 2011-02-15 14:08 -------- d-----w- c:\program files\Common Files\Skype
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-05 11:33 . 2009-08-17 16:20 29480 ----a-w- c:\windows\system32\msxml3a.dll
2011-02-27 11:31 . 2009-09-25 12:33 139128 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-02-27 11:31 . 2010-08-28 11:48 215128 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-02-27 11:31 . 2009-09-25 12:32 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-02-27 07:49 . 2009-09-25 12:32 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-02-24 19:57 . 2008-10-06 19:21 196608 ----a-w- c:\windows\system32\drivers\nStandard.bin
2011-01-04 17:56 . 2009-09-25 12:32 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2010-12-20 18:09 . 2010-12-20 18:09 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-12-19 11:38 . 2010-12-13 13:52 53248 ----a-w- c:\windows\system32\apache.dll
2009-10-20 12:10 . 2009-10-20 12:10 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-03-09_20.26.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-03-11 14:01 . 2011-03-11 14:01 16384 c:\windows\Temp\Perflib_Perfdata_35c.dat
+ 2010-09-23 02:47 . 2010-09-23 02:47 35760 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\reader_sl.exe
+ 2010-09-23 01:03 . 2010-09-23 01:03 99776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\eula.exe
+ 2010-09-23 00:52 . 2010-09-23 00:52 27048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\acrotextextractor.exe
+ 2010-09-22 16:12 . 2010-09-22 16:12 15800 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroRd32Info.exe
+ 2010-09-10 16:17 . 2010-09-10 16:17 684032 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\JP2KLib.dll
+ 2010-09-22 18:41 . 2010-09-22 18:41 542168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AdobeCollabSync.exe
+ 2010-09-23 02:47 . 2010-09-23 02:47 349616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroRd32.exe
+ 2010-09-22 16:04 . 2010-09-22 16:04 660912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroPDF.dll
+ 2010-09-22 17:39 . 2010-09-22 17:39 280024 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\acrobroker.exe
+ 2010-09-22 16:50 . 2010-09-22 16:50 251296 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\a3dutility.exe
+ 2010-09-22 16:05 . 2010-09-22 16:05 2405784 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\rt3d.dll
+ 2010-06-19 15:51 . 2010-06-19 15:51 5713920 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AGM.dll
+ 2011-01-31 10:45 . 2011-01-31 10:45 11135488 c:\windows\Installer\106b1.msp
+ 2010-09-23 01:03 . 2010-09-23 01:03 20460984 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA79201B7449A0400000010\9.4.0\AcroRd32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2010-12-27 18:44 3911776 ----a-w- c:\program files\BitTorrentBar\tbBit0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\free-downloads.net\tbfre2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre2.dll" [2010-10-18 3908192]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBit0.dll" [2010-12-27 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre2.dll" [2010-10-18 3908192]
"{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\tbBit0.dll" [2010-12-27 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2010-01-23 03:13 143360 ----a-w- d:\programy\SugarSync\SugarSyncShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-19 68856]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]
"Google Update"="c:\documents and settings\Lenííísek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-02-27 135664]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"ASUSGamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2007-07-12 380928]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-30 149280]
"QuickTime Task"="d:\programy\QuickTime\qttask.exe" [2007-06-29 286720]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-20 30192]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"RemoteControl10"="d:\programy\PowerDVD10\PDVD10Serv.exe" [2010-02-02 87336]
"BDRegion"="c:\program files\Cyberlink\Shared files\brs.exe" [2010-11-17 75048]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
c:\documents and settings\Tom ç\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
.
c:\documents and settings\Lenˇˇˇsek\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "d:\programy\Fences\FencesMenu.dll" [2010-06-22 202088]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^E-mail monitor 1.1.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\E-mail monitor 1.1.lnk
backup=c:\windows\pss\E-mail monitor 1.1.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^VirtuaWin.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\VirtuaWin.lnk
backup=c:\windows\pss\VirtuaWin.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Hamachi.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Hamachi.lnk
backup=c:\windows\pss\Hamachi.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Stardock ObjectDock.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tomáš^Nabídka Start^Programy^Po spuštění^Yahoo! Widgets.lnk]
path=c:\documents and settings\Tomáš\Nabídka Start\Programy\Po spuštění\Yahoo! Widgets.lnk
backup=c:\windows\pss\Yahoo! Widgets.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2010-12-01 17:58 397176 ----a-w- d:\programy\BitTorrent\BitTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
2011-01-05 08:18 133432 ----a-w- d:\programy\ICQ7.2\ICQ.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2010-02-24 19:17 385928 ----a-w- c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RadioSure]
2010-02-02 18:17 913920 ----a-w- d:\programy\RadioSure-2.0.886-portable\RadioSure.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-10-19 18:28 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Czech\\setup.exe"=
"c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"d:\\Programy\\ICQ7.2\\ICQ.exe"=
"d:\\Programy\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Programy\\aTube Catcher 1.0\\yct.exe"=
"d:\\Programy\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"d:\\Programy\\Skype\\Phone\\Skype.exe"=
"d:\\hry\\ANNO 1404\\Anno4.exe"=
"d:\\hry\\ANNO 1404\\tools\\Anno4Web.exe"=
"d:\\hry\\ANNO 1404\\tools\\Benchmark.exe"=
"d:\\hry\\ANNO 1404\\Addon.exe"=
"d:\\hry\\ANNO 1404\\tools\\AddonWeb.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Tunngle\\TnglCtrl.exe"=
"c:\\Program Files\\Tunngle\\Tunngle.exe"=
"d:\\hry\\World of Warcraft Wrath of The Lich King\\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"=
"d:\\Programy\\VLC\\vlc.exe"=
"d:\\hry\\Call of Duty - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Tommi\\uTorrent\\uTorrent.exe"=
"d:\\hry\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"d:\\Programy\\PowerDVD10\\PowerDVD Cinema\\PowerDVDCinema10.exe"=
"d:\\Programy\\PowerDVD10\\PowerDVD10.exe"=
"d:\\hry\\Farming Simulator 2011\\FarmingSimulator2011.exe"=
"d:\\hry\\Farming Simulator 2011\\game.exe"=
"d:\\hry\\Tom Clancy's Splinter Cell Chaos Theory\\System\\splintercell3.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23776:TCP"= 23776:TCP:BitComet 23776 TCP
"23776:UDP"= 23776:UDP:BitComet 23776 UDP
"22147:TCP"= 22147:TCP:BitComet 22147 TCP
"22147:UDP"= 22147:UDP:BitComet 22147 UDP
"3724:TCP"= 3724:TCP:1
"6112:TCP"= 6112:TCP:2
"6113:TCP"= 6113:TCP:3
"6114:TCP"= 6114:TCP:4
"4000:TCP"= 4000:TCP:5
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.5.2010 21:06 165584]
R2 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC};Power Control [2011/03/05 12:36];d:\programy\PowerDVD10\NavFilter\000.fcl [17.11.2010 21:29 87536]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.5.2010 21:06 17744]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [12.10.2008 10:22 246520]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [16.11.2009 17:33 50704]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [31.10.2010 11:15 583640]
R2 TunngleService;TunngleService;c:\program files\Tunngle\TnglCtrl.exe [26.12.2010 19:04 718072]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\drivers\tap0901t.sys [12.12.2010 16:41 27136]
S2 gupdate1c99eacbb9579ce;Služba Google Update (gupdate1c99eacbb9579ce);c:\program files\Google\Update\GoogleUpdate.exe [6.3.2009 23:41 133104]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;"c:\program files\LogMeIn Hamachi\hamachi-2.exe" -s --> c:\program files\LogMeIn Hamachi\hamachi-2.exe [?]
S3 AMDMSRIO;AMDMSRIO;\??\c:\docume~1\LENSEK~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys --> c:\docume~1\LENSEK~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys [?]
S3 EagleXNt;EagleXNt;\??\c:\windows\system32\drivers\EagleXNt.sys --> c:\windows\system32\drivers\EagleXNt.sys [?]
S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [20.10.2009 13:10 30192]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28.10.2008 11:53 717296]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 12:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-06 22:41]
.
2011-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-06 22:41]
.
2011-03-10 c:\windows\Tasks\RMSchedule.job
- c:\program files\Registry Mechanic\RegMech.exe [2010-10-31 07:46]
.
2011-02-19 c:\windows\Tasks\Wise Disk Cleaner Schedule Task.job
- d:\tommi\Wise Disk Cleaner\WiseDiskCleaner.exe [2011-01-03 19:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{E5E5909F-B771-4E28-9BF5-54DD753E32A6} - d:\programy\FreshDownload\fd.exe
TCP: {5A3E5E72-BE8F-47B5-B78C-CC3A73FC9A14} = 195.146.99.31,62.204.224.2,62.204.224.1
TCP: {C8AC6BBA-4F3A-4BF9-ACF9-87A87BDE9EAD} = 62.77.67.2,62.84.132.6
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-11 15:10
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC}]
"ImagePath"="\??\d:\programy\PowerDVD10\NavFilter\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2852)
d:\programy\SugarSync\SugarSyncShellExt.dll
d:\programy\MediaMonkey\DeskPlayer.dll
d:\programy\CyberLink\PowerDVD\deskband32.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\msi.dll
d:\programy\Fences\FencesMenu.dll
d:\programy\fences\DesktopDock.dll
.
Celkový čas: 2011-03-11 15:13:08
ComboFix-quarantined-files.txt 2011-03-11 14:13
ComboFix2.txt 2011-03-10 20:36
ComboFix3.txt 2011-03-09 20:28
ComboFix4.txt 2010-09-25 15:41
ComboFix5.txt 2011-03-11 14:05
.
Před spuštěním: 2 008 326 144
Po spuštění: 2 045 222 912
.
- - End Of File - - 4904935C68ABA8C3DB2A664CE68EAD41