ComboFix 11-03-26.01 - Notebook 26.03.2011 23:19:06.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2046.1576 [GMT 1:00]
Spuštěný z: c:\documents and settings\Notebook\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Notebook\Data aplikací\Dealio
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\IE\4.3\config.ini
c:\program files\Dealio Toolbar\IE\4.3\deALiotoolbarie.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\program files\pdfforge Toolbar\IE\4.3\pdFForgetoolbarie.dll
c:\program files\YouTube Downloader Toolbar\IE\4.3\yoUTubedownloadertoolbarie.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-26 do 2011-03-26 )))))))))))))))))))))))))))))))
.
.
2011-03-26 22:29 . 2011-03-26 22:29 4096 ----a-w- c:\windows\system32\05.tmp
2011-03-25 22:10 . 2011-03-25 22:10 -------- d-----w- C:\rsit
2011-03-25 22:10 . 2011-03-25 22:10 -------- d-----w- c:\program files\trend micro
2011-03-25 16:57 . 2011-03-25 16:57 4096 ----a-w- c:\windows\system32\04.tmp
2011-03-25 12:57 . 2011-03-25 12:57 -------- d-----r- c:\documents and settings\LocalService\Dokumenty
2011-03-25 08:46 . 2011-03-25 08:46 -------- d-----w- c:\program files\CCleaner
2011-03-24 00:14 . 2011-03-24 00:14 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\dvdcss
2011-03-22 16:43 . 2011-03-22 16:43 -------- d-----w- c:\documents and settings\Notebook\.thumbnails
2011-03-22 16:24 . 2011-03-25 12:53 -------- d-----w- c:\documents and settings\Notebook\.gimp-2.6
2011-03-22 16:24 . 2011-03-22 16:24 -------- d-----w- c:\program files\GIMP-2.0
2011-03-22 11:30 . 2011-03-22 11:30 -------- d-----w- c:\documents and settings\Notebook\Local Settings\Data aplikací\Mozilla
2011-03-21 15:30 . 2011-03-21 15:36 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\PSpad
2011-03-21 15:30 . 2011-03-21 15:30 -------- d-----w- c:\program files\PSPad editor
2011-03-21 14:40 . 2011-03-21 14:40 -------- d-----w- c:\program files\FlashFXP 4
2011-03-21 14:40 . 2011-03-21 14:40 -------- d-----w- c:\documents and settings\All Users\Data aplikací\FlashFXP
2011-03-21 14:33 . 2011-03-21 14:33 -------- d-----w- c:\documents and settings\Notebook\Local Settings\Data aplikací\GlobalSCAPE
2011-03-21 14:33 . 2011-03-21 14:33 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\GlobalSCAPE
2011-03-21 14:33 . 2011-03-21 14:33 -------- d-----w- c:\documents and settings\All Users\Data aplikací\GlobalSCAPE
2011-03-21 11:38 . 2011-03-21 11:38 -------- d-----w- c:\program files\Ask.com
2011-03-21 11:38 . 2011-03-21 11:38 -------- d-----w- c:\program files\GlobalSCAPE
2011-03-21 11:37 . 2011-03-23 21:34 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\FileZilla
2011-03-21 11:37 . 2011-03-21 11:37 -------- d-----w- c:\program files\FileZilla FTP Client
2011-03-20 11:55 . 2011-03-20 11:55 -------- d-----w- c:\program files\Microsoft Games
2011-03-20 00:38 . 2011-03-20 00:38 -------- d-----w- c:\program files\Common Files\DirectX
2011-03-20 00:37 . 2011-03-20 00:37 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\WarlockStudio
2011-03-18 23:41 . 2011-03-18 23:44 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\vlc
2011-03-12 23:27 . 2011-03-22 22:36 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\gtk-2.0
2011-03-11 16:01 . 2011-03-11 16:01 -------- d-----w- c:\program files\pdfforge Toolbar
2011-03-11 16:00 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2011-03-11 16:00 . 1998-06-23 23:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2011-03-11 16:00 . 2011-03-11 16:01 -------- d-----w- c:\program files\PDFCreator
2011-03-11 16:00 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2011-03-11 15:04 . 2001-10-24 11:25 87040 ----a-w- c:\windows\system32\wiafbdrv.dll
2011-03-11 15:04 . 2001-10-24 11:25 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2011-03-11 15:04 . 2001-10-24 11:24 32768 ----a-w- c:\windows\system32\hpgtmcro.dll
2011-03-11 15:04 . 2001-10-24 11:24 32768 ----a-w- c:\windows\system32\dllcache\hpgtmcro.dll
2011-03-11 15:04 . 2001-10-24 11:24 126976 ----a-w- c:\windows\system32\hpgt34tk.dll
2011-03-11 15:04 . 2001-10-24 11:24 126976 ----a-w- c:\windows\system32\dllcache\hpgt34tk.dll
2011-03-11 15:04 . 2001-10-24 11:24 101376 ----a-w- c:\windows\system32\hpgt34.dll
2011-03-11 15:04 . 2001-10-24 11:24 101376 ----a-w- c:\windows\system32\dllcache\hpgt34.dll
2011-03-11 15:04 . 2004-08-03 21:58 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-03-11 15:04 . 2004-08-03 21:58 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2011-03-11 09:17 . 2011-03-11 09:17 -------- d-----w- c:\documents and settings\Notebook\Local Settings\Data aplikací\ArmA Demo
2011-03-11 09:12 . 2011-03-11 09:12 -------- d-----w- c:\program files\OpenAL
2011-03-11 09:09 . 2011-03-11 09:09 -------- d-----w- c:\program files\Atari
2011-03-10 19:29 . 2011-03-10 19:29 -------- d-----w- C:\DUKE3D
2011-03-10 19:19 . 2004-08-17 14:49 21504 ----a-w- c:\windows\system32\hidserv.dll
2011-03-10 19:19 . 2004-08-17 14:49 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2011-03-10 19:19 . 2004-08-17 14:45 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2011-03-10 19:19 . 2004-08-17 14:45 14848 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2011-03-10 19:19 . 2004-08-03 22:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-03-10 19:19 . 2004-08-03 22:08 31616 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-03-08 17:25 . 2009-04-12 08:52 81920 ----a-w- c:\windows\system32\Juchinsetmenu.exe
2011-03-08 17:25 . 2009-04-07 14:12 9984 ----a-w- c:\windows\system32\drivers\Juchin.sys
2011-03-07 11:22 . 2011-03-07 11:22 -------- d-----w- c:\program files\Codemasters
2011-03-07 07:24 . 2011-03-07 07:38 61440 ----a-r- c:\documents and settings\Notebook\Data aplikací\Microsoft\Installer\{A57D86AF-DE8E-4B26-972E-A1A28FFF7742}\flatout.exe1_853599CE1B5C4FEFB643B8F48F508EDC.exe
2011-03-07 07:24 . 2011-03-07 07:38 61440 ----a-r- c:\documents and settings\Notebook\Data aplikací\Microsoft\Installer\{A57D86AF-DE8E-4B26-972E-A1A28FFF7742}\flatout.exe_853599CE1B5C4FEFB643B8F48F508EDC.exe
2011-03-07 07:24 . 2011-03-07 07:38 61440 ----a-r- c:\documents and settings\Notebook\Data aplikací\Microsoft\Installer\{A57D86AF-DE8E-4B26-972E-A1A28FFF7742}\ARPPRODUCTICON.exe
2011-03-07 07:03 . 2011-03-07 07:20 -------- d-----w- c:\program files\Empire Interactive
2011-03-06 23:02 . 2011-03-06 23:05 -------- d-----w- c:\program files\JFDuke3D
2011-03-06 22:25 . 2011-03-06 22:25 -------- d-----w- c:\documents and settings\Notebook\Local Settings\Data aplikací\Help
2011-03-06 22:23 . 2011-03-06 22:23 -------- d-----w- C:\C_DILLA
2011-03-06 22:22 . 2011-03-06 22:24 -------- d-----w- c:\program files\AcadLT 2000 Trial
2011-03-06 22:22 . 1999-04-26 10:41 299520 ----a-w- c:\windows\uninst.exe
2011-03-06 22:22 . 2011-03-06 22:22 -------- d-----w- c:\documents and settings\Notebook\WINDOWS
2011-03-03 16:46 . 2007-12-10 07:00 61440 ----a-w- c:\windows\system32\ZIMF.DLL
2011-03-03 16:46 . 2007-12-10 07:00 57344 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\ZIMFPRNT.DLL
2011-03-03 16:46 . 2007-12-10 07:00 53248 ----a-w- c:\windows\system32\ZTAG.DLL
2011-03-03 16:46 . 2007-12-10 07:00 430080 ----a-w- c:\windows\system32\ZSHP1020.EXE
2011-03-03 16:46 . 2007-12-10 07:00 106496 ----a-w- c:\windows\system32\ZSPOOL.DLL
2011-03-03 16:46 . 2007-12-10 07:00 102400 ----a-w- c:\windows\system32\ZLhp1020.DLL
2011-03-03 16:46 . 2011-03-03 16:46 -------- d-----w- c:\program files\Hewlett-Packard
2011-03-03 16:27 . 2004-08-03 22:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-03-03 16:27 . 2004-08-03 22:01 25856 ----a-w- c:\windows\system32\dllcache\usbprint.sys
2011-03-03 07:56 . 2011-03-03 07:56 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2011-03-03 07:51 . 2011-03-03 07:51 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2011-03-03 07:21 . 2011-03-03 07:21 -------- d-----w- c:\program files\EAGLE-5.11.0
2011-03-03 07:21 . 2011-03-03 07:21 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\CadSoft
2011-03-02 23:06 . 2011-03-02 23:06 127469 ----a-w- c:\windows\MeterBasic Uninstaller.exe
2011-03-02 23:04 . 2011-03-02 23:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Hagel Technologies
2011-03-02 23:03 . 2011-03-02 23:03 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Hagel Technologies
2011-03-02 22:56 . 2011-03-02 22:56 97560 ----a-w- c:\windows\Meter Uninstaller.exe
2011-03-02 22:56 . 2011-03-02 22:56 -------- d-----w- c:\program files\Meter
2011-02-28 07:51 . 2011-02-28 07:51 -------- d-----w- c:\documents and settings\All Users\Data aplikací\id Software
2011-02-26 14:34 . 2011-02-27 18:58 -------- d-----w- c:\documents and settings\Notebook\Data aplikací\.minecraft
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-11 09:17 . 2007-06-16 00:30 108144 ----a-w- c:\windows\system32\CmdLineExt.dll
2011-03-11 09:12 . 2003-11-07 12:28 409600 ----a-w- c:\windows\system32\wrap_oal.dll
2011-03-11 09:12 . 2003-11-07 12:28 114688 ----a-w- c:\windows\system32\OpenAL32.dll
2011-01-31 21:03 . 2011-01-31 20:53 53248 ----a-w- c:\windows\unrar.dll
2011-01-31 12:30 . 2011-01-31 12:30 12800 ----a-w- c:\windows\system32\drivers\ekauio.sys
2011-01-18 16:43 . 2011-02-07 06:34 42960 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-01-18 16:43 . 2011-01-18 16:43 109328 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2011-01-18 16:43 . 2011-02-07 06:34 158736 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-01-18 16:43 . 2011-01-18 16:43 133648 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2011-01-18 16:43 . 2011-01-18 16:43 120208 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2011-01-13 08:47 . 2011-02-01 13:26 38848 ----a-w- c:\windows\avastSS.scr
2011-01-13 08:47 . 2011-02-01 13:26 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-01-13 08:41 . 2011-02-01 13:26 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-13 08:40 . 2011-02-01 13:26 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-13 08:40 . 2011-02-01 13:26 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-01-13 08:39 . 2011-02-01 13:26 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-01-13 08:37 . 2011-02-01 13:26 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-13 08:37 . 2011-02-01 13:26 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-01-13 08:37 . 2011-02-01 13:26 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 10:51 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 16:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Notebook\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2007-06-14 136176]
"ModemOnHold"="c:\program files\NetWaiting\NetWaiting.exe" [2003-09-10 20480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"Document Manager"="c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe" [2006-09-08 102400]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
"NVHotkey"="nvHotkey.dll" [2008-02-22 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-22 86016]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-12-06 1910152]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-01-28 526336]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-02-23 30192]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-18 15360]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
2x-Office.lnk - c:\program files\Juchin\Office Mouse\Juchin Mouse.exe [N/A]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-7-5 24576]
EMBASSY Trust Suite Secure Update.lnk - c:\program files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe [2006-8-25 192512]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Notebook\\Data aplikací\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Vietcong\\Vietcong.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Atari\\ArmA Demo\\ArmADemo.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2497:TCP"= 2497:TCP:jpqzg
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1.2.2011 14:26 294608]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [14.6.2007 23:16 218688]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [7.2.2011 7:34 158736]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [7.2.2011 7:34 42960]
R2 Ç-DillaSrv;Ç-DillaSrv;c:\windows\system32\drivers\CDANTSRV.EXE [16.3.1999 20:49 19456]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [28.1.2011 17:10 387072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1.2.2011 14:26 17744]
R2 Ekauio;Ekahau NDIS Usermode I/O Protocol;c:\windows\system32\drivers\ekauio.sys [31.1.2011 13:30 12800]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [6.12.2010 8:31 1238408]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [18.1.2011 17:43 109328]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [18.1.2011 17:43 120208]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3.3.2011 8:51 136176]
S2 hfwdnynvu;dztxchipl;c:\windows\system32\svchost.exe -k netsvcs [13.9.2004 16:20 14336]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [23.2.2011 21:25 30192]
S3 WAPSJ;WAPSJ;c:\docume~1\Notebook\LOCALS~1\Temp\WAPSJ.exe --> c:\docume~1\Notebook\LOCALS~1\Temp\WAPSJ.exe [?]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
hfwdnynvu
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-03 07:50]
.
2011-03-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-03 07:50]
.
2011-03-26 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-10 16:29]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2786678
uDefault_Search_URL = hxxp://
www.google.com/ie
mStart Page = hxxp://www1.euro.dell.com/content/default.aspx?c=cz&l=cs&s=bsd
uInternet Connection Wizard,ShellNext = hxxp://www1.euro.dell.com/content/default.aspx?c=cz&l=cs&s=bsd
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\uTorrentBar\tbuTor.dll
BHO-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\uTorrentBar\tbuTor.dll
Toolbar-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\uTorrentBar\tbuTor.dll
HKCU-Run-DU Meter - c:\program files\DU Meter\DUMeter.exe
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
AddRemove-Achtung, die Kurve! - c:\program files\Achtung
AddRemove-BenchMarX - c:\program files\BenchMarX\uninstall.exe
AddRemove-Flashpoint - c:\program files\Codemasters\UnInstall.exe
AddRemove-FlightForFight - c:\program files\WarlockStudio\FlightForFight\UnInstall.exe
AddRemove-Mozilla Firefox 4.0 (x86 cs) - c:\program files\Mozilla Firefox\uninstall\helper.exe
AddRemove-uTorrentBar Toolbar - c:\progra~1\UTORRE~1\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-26 23:31
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hfwdnynvu]
"ServiceDll"="c:\windows\system32\vnkja.dll"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2792)
c:\windows\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\stsystra.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Wave Systems Corp\Common\DataServer.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2011-03-26 23:35:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-03-26 22:35
.
Před spuštěním: Volných bajtů: 14 635 704 320
Po spuštění: Volných bajtů: 14 587 596 800
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 8CAC0DB1B0FE97F67228D64D11BCC42C