ComboFix 11-11-02.03 - Administrator 02.11.2011 20:32:45.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.767.443 [GMT 1:00]
Spuštěný z: g:\k avg\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\windows\$NtUninstallKB37558$
c:\windows\$NtUninstallKB37558$\2218846473\@
c:\windows\$NtUninstallKB37558$\2218846473\click.tlb
c:\windows\$NtUninstallKB37558$\2218846473\L\ospiwtoo
c:\windows\$NtUninstallKB37558$\2218846473\loader.tlb
c:\windows\$NtUninstallKB37558$\2218846473\U\@00000001
c:\windows\$NtUninstallKB37558$\2218846473\U\@000000c0
c:\windows\$NtUninstallKB37558$\2218846473\U\@000000cb
c:\windows\$NtUninstallKB37558$\2218846473\U\@000000cf
c:\windows\$NtUninstallKB37558$\2218846473\U\@80000000
c:\windows\$NtUninstallKB37558$\2218846473\U\@800000c0
c:\windows\$NtUninstallKB37558$\2218846473\U\@800000cb
c:\windows\$NtUninstallKB37558$\2218846473\U\@800000cf
c:\windows\$NtUninstallKB37558$\3244903967
c:\windows\IsUn0405.exe
c:\windows\msmqinst.log
c:\windows\system32\
c:\windows\XSxS
D:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_8440e909
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-02 do 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 18:02 . 2011-11-02 18:02 -------- d-----w- c:\program files\trend micro
2011-11-02 18:00 . 2011-11-02 18:02 -------- d-----w- C:\rsit
2011-11-02 15:08 . 2011-11-02 15:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Comodo
2011-11-02 15:08 . 2011-11-02 18:17 -------- d-----w- c:\program files\COMODO
2011-11-02 15:08 . 2011-11-02 15:08 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-11-02 15:07 . 2011-11-02 15:08 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Comodo Downloader
2011-11-01 20:46 . 2011-11-01 20:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2011-11-01 20:46 . 2011-11-01 20:47 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-10-31 18:34 . 2001-10-24 11:02 17280 -c--a-w- c:\windows\system32\dllcache\scr111.sys
2011-10-31 18:34 . 2001-10-24 11:02 16640 -c--a-w- c:\windows\system32\dllcache\scmstcs.sys
2011-10-31 18:34 . 2001-08-17 20:51 23936 -c--a-w- c:\windows\system32\dllcache\sccmusbm.sys
2011-10-31 18:34 . 2001-10-24 11:01 23936 -c--a-w- c:\windows\system32\dllcache\sccmn50m.sys
2011-10-31 18:34 . 2008-04-13 19:40 43904 -c--a-w- c:\windows\system32\dllcache\sbp2port.sys
2011-10-31 18:32 . 2004-08-03 21:31 20992 -c--a-w- c:\windows\system32\dllcache\rtl8139.sys
2011-10-31 18:32 . 2001-08-17 19:12 19017 -c--a-w- c:\windows\system32\dllcache\rtl8029.sys
2011-10-31 18:32 . 2001-08-17 19:19 30720 -c--a-w- c:\windows\system32\dllcache\rthwcls.sys
2011-10-31 18:32 . 2001-10-24 11:25 9728 -c--a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2011-10-31 18:32 . 2001-08-17 19:19 3840 -c--a-w- c:\windows\system32\dllcache\rpfun.sys
2011-10-31 18:32 . 2008-04-14 03:17 79104 -c--a-w- c:\windows\system32\dllcache\rocket.sys
2011-10-31 18:32 . 2001-08-17 19:12 37563 -c--a-w- c:\windows\system32\dllcache\rlnet5.sys
2011-10-31 18:32 . 2001-10-24 11:24 86097 -c--a-w- c:\windows\system32\dllcache\reslog32.dll
2011-10-31 18:32 . 2001-08-17 20:51 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2011-10-31 18:32 . 2001-10-24 10:58 714762 -c--a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2011-10-31 18:32 . 2001-10-24 10:58 899146 -c--a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2011-10-31 18:32 . 2001-10-24 11:25 41472 -c--a-w- c:\windows\system32\dllcache\qvusd.dll
2011-10-31 18:30 . 2001-08-17 20:53 17792 -c--a-w- c:\windows\system32\dllcache\ppa.sys
2011-10-31 18:29 . 2001-10-24 11:25 86016 -c--a-w- c:\windows\system32\dllcache\pctspk.exe
2011-10-31 18:28 . 2001-08-17 21:05 31872 -c--a-w- c:\windows\system32\dllcache\ovce.sys
2011-10-31 18:28 . 2001-08-17 21:05 28032 -c--a-w- c:\windows\system32\dllcache\ovcd.sys
2011-10-31 18:28 . 2001-08-17 21:05 48000 -c--a-w- c:\windows\system32\dllcache\ovcam2.sys
2011-10-31 18:28 . 2001-08-17 21:05 25088 -c--a-w- c:\windows\system32\dllcache\ovca.sys
2011-10-31 18:28 . 2001-10-24 10:50 54186 -c--a-w- c:\windows\system32\dllcache\otcsercb.sys
2011-10-31 18:28 . 2001-10-24 10:50 43689 -c--a-w- c:\windows\system32\dllcache\otceth5.sys
2011-10-31 18:28 . 2001-08-17 19:12 27209 -c--a-w- c:\windows\system32\dllcache\otc06x5.sys
2011-10-31 18:28 . 2001-08-17 19:20 54528 -c--a-w- c:\windows\system32\dllcache\opl3sax.sys
2011-10-31 18:28 . 2008-04-13 19:46 61696 -c--a-w- c:\windows\system32\dllcache\ohci1394.sys
2011-10-31 18:28 . 2001-08-17 19:50 198144 -c--a-w- c:\windows\system32\dllcache\nv3.sys
2011-10-31 18:28 . 2001-10-24 11:24 123776 -c--a-w- c:\windows\system32\dllcache\nv3.dll
2011-10-31 18:28 . 2001-08-17 19:49 51552 -c--a-w- c:\windows\system32\dllcache\ntgrip.sys
2011-10-31 18:26 . 2001-10-24 11:24 59104 -c--a-w- c:\windows\system32\dllcache\n9i128v2.dll
2011-10-31 18:25 . 2001-08-17 21:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys
2011-10-31 18:25 . 2008-04-13 19:54 22016 -c--a-w- c:\windows\system32\dllcache\msircomm.sys
2011-10-31 18:25 . 2001-08-17 21:02 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2011-10-31 18:25 . 2001-08-17 20:48 6016 -c--a-w- c:\windows\system32\dllcache\msfsio.sys
2011-10-31 18:25 . 2008-04-13 19:46 51200 -c--a-w- c:\windows\system32\dllcache\msdv.sys
2011-10-31 18:25 . 2001-08-17 20:52 17280 -c--a-w- c:\windows\system32\dllcache\mraid35x.sys
2011-10-31 18:25 . 2008-04-13 19:46 15232 -c--a-w- c:\windows\system32\dllcache\mpe.sys
2011-10-31 18:24 . 2001-10-24 10:54 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2011-10-31 18:24 . 2001-08-17 20:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys
2011-10-31 18:24 . 2001-08-17 20:52 6528 -c--a-w- c:\windows\system32\dllcache\miniqic.sys
2011-10-31 18:24 . 2001-10-24 10:52 320384 -c--a-w- c:\windows\system32\dllcache\mgaum.sys
2011-10-31 18:24 . 2001-10-24 11:24 235648 -c--a-w- c:\windows\system32\dllcache\mgaud.dll
2011-10-31 18:24 . 2008-04-13 19:41 26112 -c--a-w- c:\windows\system32\dllcache\memstpci.sys
2011-10-31 18:24 . 2001-10-24 11:23 47616 -c--a-w- c:\windows\system32\dllcache\memgrp.dll
2011-10-31 18:24 . 2001-08-17 20:58 8320 -c--a-w- c:\windows\system32\dllcache\memcard.sys
2011-10-31 18:24 . 2001-10-24 10:50 164586 -c--a-w- c:\windows\system32\dllcache\mdgndis5.sys
2011-10-31 18:24 . 2001-08-17 20:52 7424 -c--a-w- c:\windows\system32\dllcache\mammoth.sys
2011-10-31 18:24 . 2001-08-17 19:19 48768 -c--a-w- c:\windows\system32\dllcache\maestro.sys
2011-10-31 18:22 . 2001-10-24 11:24 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2011-10-31 18:22 . 2008-04-14 04:21 48640 -c--a-w- c:\windows\system32\dllcache\kdsui.dll
2011-10-31 18:22 . 2008-04-14 04:21 254464 -c--a-w- c:\windows\system32\dllcache\kdsusd.dll
2011-10-31 18:22 . 2001-08-17 20:49 26624 -c--a-w- c:\windows\system32\dllcache\irstusb.sys
2011-10-31 18:22 . 2001-08-17 20:51 18688 -c--a-w- c:\windows\system32\dllcache\irsir.sys
2011-10-31 18:22 . 2008-04-14 04:21 27648 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2011-10-31 18:22 . 2001-08-17 20:49 23552 -c--a-w- c:\windows\system32\dllcache\irmk7.sys
2011-10-31 18:22 . 2008-04-14 04:22 152064 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2011-10-31 18:22 . 2008-04-13 19:54 88192 -c--a-w- c:\windows\system32\dllcache\irda.sys
2011-10-31 18:22 . 2001-08-17 19:12 45632 -c--a-w- c:\windows\system32\dllcache\ip5515.sys
2011-10-31 18:21 . 2001-10-24 11:24 90200 -c--a-w- c:\windows\system32\dllcache\io8ports.dll
2011-10-31 18:21 . 2001-08-17 20:50 38784 -c--a-w- c:\windows\system32\dllcache\io8.sys
2011-10-31 18:21 . 2001-10-24 10:42 13056 -c--a-w- c:\windows\system32\dllcache\inport.sys
2011-10-31 18:21 . 2001-08-17 20:52 16000 -c--a-w- c:\windows\system32\dllcache\ini910u.sys
2011-10-31 18:21 . 2001-10-24 11:24 372824 -c--a-w- c:\windows\system32\dllcache\iconf32.dll
2011-10-31 18:21 . 2001-08-17 21:06 100992 -c--a-w- c:\windows\system32\dllcache\icam5usb.sys
2011-10-31 18:21 . 2001-10-24 11:24 20480 -c--a-w- c:\windows\system32\dllcache\icam5ext.dll
2011-10-31 18:21 . 2001-10-24 11:24 45056 -c--a-w- c:\windows\system32\dllcache\icam5com.dll
2011-10-31 18:21 . 2001-08-17 21:06 154496 -c--a-w- c:\windows\system32\dllcache\icam4usb.sys
2011-10-31 18:21 . 2001-10-24 11:24 62464 -c--a-w- c:\windows\system32\dllcache\icam4ext.dll
2011-10-31 18:21 . 2001-10-24 11:24 91136 -c--a-w- c:\windows\system32\dllcache\icam4com.dll
2011-10-31 18:21 . 2001-10-24 11:24 26624 -c--a-w- c:\windows\system32\dllcache\icam3ext.dll
2011-10-31 18:19 . 2001-10-24 11:24 9759 -c--a-w- c:\windows\system32\dllcache\hsf_inst.dll
2011-10-31 18:18 . 2001-10-24 11:24 119296 -c--a-w- c:\windows\system32\dllcache\hpdigwia.dll
2011-10-31 18:17 . 2001-08-17 19:15 455680 -c--a-w- c:\windows\system32\dllcache\fus2base.sys
2011-10-31 18:16 . 2001-08-17 19:19 63360 -c--a-w- c:\windows\system32\dllcache\ess.sys
2011-10-31 18:15 . 2001-08-17 19:10 69692 -c--a-w- c:\windows\system32\dllcache\el575nd5.sys
2011-10-31 18:14 . 2001-10-24 11:24 110621 -c--a-w- c:\windows\system32\dllcache\digirlpt.dll
2011-10-31 18:13 . 2001-08-17 19:19 72832 -c--a-w- c:\windows\system32\dllcache\cwbwdm.sys
2011-10-31 18:12 . 2001-10-24 11:24 32256 -c--a-w- c:\windows\system32\dllcache\diapi2NT.dll
2011-10-31 18:11 . 2001-08-17 19:11 66557 -c--a-w- c:\windows\system32\dllcache\bcm42u.sys
2011-10-31 18:10 . 2004-08-03 21:32 10880 -c--a-w- c:\windows\system32\dllcache\admjoy.sys
2011-10-30 18:33 . 2011-10-30 19:48 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\AVG
2011-10-30 17:01 . 2011-10-30 17:01 -------- d-----w- c:\program files\Windows Resource Kits
2011-10-29 19:40 . 2011-10-29 19:56 -------- d-----w- c:\windows\system32\NtmsData
2011-10-29 17:29 . 2011-10-29 17:29 -------- d--h--w- c:\windows\PIF
2011-10-26 18:12 . 2011-10-26 18:12 -------- d-----w- C:\ERDNT
2011-10-23 20:52 . 2011-10-27 15:48 -------- d-----w- c:\program files\NORTON UTILITIES 14
2011-10-23 19:34 . 2008-04-13 22:49 75264 ----a-w- c:\windows\system32\ipsec.sys
2011-10-19 15:54 . 2011-10-19 15:54 -------- d-----w- C:\AVGTemp
2011-10-18 17:00 . 2011-10-31 19:46 -------- d-----w- c:\windows\system32\drivers\AVG
2011-10-18 17:00 . 2011-10-26 15:43 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG2012
2011-10-18 16:23 . 2011-10-18 16:23 -------- d-----w- c:\program files\ESET
2011-10-17 18:46 . 2011-10-30 18:32 -------- d-----w- c:\program files\AVG
2011-10-16 19:33 . 2011-10-16 19:33 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Canneverbe Limited
2011-10-16 19:32 . 2011-11-02 15:31 -------- d-----w- c:\program files\CDBurnerXP
2011-10-16 19:32 . 2011-10-16 19:32 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Canneverbe Limited
2011-10-16 18:22 . 2011-10-16 18:22 -------- d-----w- c:\windows\system32\wbem\Repository
2011-10-16 18:05 . 2011-10-17 16:51 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-10-16 17:42 . 2011-10-31 19:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2011-10-08 15:46 . 2011-10-08 15:49 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\NP2
2011-10-07 21:04 . 2011-10-07 21:24 -------- d-----w- c:\program files\Neuro-Programmer 2 Professional
2011-10-07 19:48 . 2011-10-07 19:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Babylon
2011-10-07 19:48 . 2011-10-07 19:48 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Babylon
2011-10-07 19:48 . 2011-10-07 19:48 -------- d-----w- c:\documents and settings\Administrator\Data aplikací\Babylon
2011-10-07 18:36 . 2011-11-01 20:48 -------- d-----w- c:\program files\IDoser v4
2011-10-07 17:48 . 2011-10-07 17:48 97760 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-10-07 17:48 . 2011-10-07 17:48 492768 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:48 . 2011-10-07 17:48 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:48 . 2011-10-07 17:48 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47 . 2011-10-07 17:47 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-07 17:47 . 2011-10-07 17:47 300200 ----a-w- c:\windows\system32\guard32.dll
2011-10-06 18:54 . 2011-10-06 18:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\Xenocode
2011-10-06 16:46 . 2011-10-06 16:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Data aplikací\MediaGet2
2011-10-05 20:48 . 2011-10-17 00:21 -------- d-sh--w- c:\documents and settings\Administrator\Local Settings\Data aplikací\8440e909
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 09:41 . 2010-03-18 09:09 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-18 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-18 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-19 16:58 . 2011-06-27 11:59 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-13 04:30 . 2011-09-13 04:30 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-09-09 09:12 . 2004-08-18 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 14:10 . 2004-08-18 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-31 21:07 . 2010-05-02 16:18 249856 ----a-w- c:\windows\Setup1.exe
2011-08-31 21:07 . 2010-05-02 16:18 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-08-18 07:35 . 2011-08-18 07:35 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-08-17 13:49 . 2004-08-18 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-08 04:08 . 2011-08-08 04:08 40016 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64c54209-175c-454d-9291-ac46d4d952cf}]
2011-03-23 17:33 86696 ----a-w- c:\program files\completebartb\completebarDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
2011-05-09 09:49 176936 ----a-w- c:\program files\uTorrentBar\prxtbuTo0.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-07-10 15:28 1174920 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fe618700-e0ee-441e-8b1d-18ce226bb193}]
2011-03-23 17:33 262312 ----a-w- c:\program files\completebartb\auxi\completebarAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{64c54209-175c-454d-9291-ac46d4d952cf}"= "c:\program files\completebartb\completebarDx.dll" [2011-03-23 86696]
"{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
.
[HKEY_CLASSES_ROOT\clsid\{64c54209-175c-454d-9291-ac46d4d952cf}]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}"= "c:\program files\uTorrentBar\prxtbuTo0.dll" [2011-05-09 176936]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-07-10 1174920]
.
[HKEY_CLASSES_ROOT\clsid\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-01-13 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"EPSON Stylus C43 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-12-10 75776]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
"Anti-phishing Domain Advisor"="c:\documents and settings\All Users\Data aplikací\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2011-03-15 232104]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-09-23 2404704]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-01-13 155648]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-10-20 2497352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start
http://www.avg.com/ww.special-uninstall ... er=9.0.914" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-4-9 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [11.7.2011 0:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [13.9.2011 5:30 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [11.7.2011 0:13 229840]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [7.10.2011 18:48 492768]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.10.2011 18:48 31704]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [19.10.2011 16:58 192776]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [23.1.2004 16:33 13952]
R3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [23.1.2004 16:32 28800]
R3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [17.4.2010 8:41 15576]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11.7.2011 0:14 295248]
S2 A4SII300;A4SII300;c:\windows\system32\drivers\a4sii300.sys [16.1.2011 20:02 25824]
S2 Ca1528av;SPCA1528 Video Camera Service;c:\windows\system32\Drivers\Ca1528av.sys --> c:\windows\system32\Drivers\Ca1528av.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [12.9.2011 5:23 5265248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [11.7.2011 0:14 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [11.7.2011 0:14 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [11.7.2011 0:14 16720]
S3 Bulk1528;SPCA1528 Still Camera Service;c:\windows\system32\Drivers\Bulk1528.sys --> c:\windows\system32\Drivers\Bulk1528.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25.1.2007 18:31 42000]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
Obsah adresáře 'Naplánované úlohy'
.
2011-11-02 c:\windows\Tasks\AVG PC Tuneup 2011 Integrator Start On Administrator Logon.job
- c:\program files\AVG\AVG PC Tuneup 2011\BoostSpeed.exe [2011-10-30 14:58]
.
2011-11-02 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-07-10 15:29]
.
2011-11-02 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2011-11-01 14:31]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: DhcpNameServer = 10.0.0.138
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{D27FC31C-6E3D-4305-8D53-ACDAEFA5F862} - (no file)
AddRemove-Adobe Photoshop 6.0.1 CE - c:\windows\ISUN0405.EXE
AddRemove-HijackThis - G:\HijackThis.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-02 20:52
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2625337770-2973904658-525432662-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17C83A77-4F46-40C9-B9A2-3970E88BA0A8}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iagmhlnjfepmnpgegf"=hex:6a,61,6b,66,67,66,70,6b,6a,6c,61,6f,6f,63,64,70,6d,67,
6f,64,00,40
"haahfolbffncfglm"=hex:6a,61,6b,66,70,65,6d,6d,61,65,66,6d,67,69,66,6d,65,68,
63,6a,00,40
"hakjcepkncbbmppc"=hex:61,61,00,00
"hakjcepkhehbaljh"=hex:61,61,00,00
.
[HKEY_USERS\S-1-5-21-2625337770-2973904658-525432662-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7A495AE5-EAFF-3DC3-264B-07DBFFD7D5EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hajcolgejehjhgdc"=hex:61,61,00,00
"hajcolgepgfgmkaj"=hex:61,61,00,00
"ianddafcholdnfnbam"=hex:6a,61,67,6f,63,6b,6f,6b,65,6b,64,61,65,65,65,63,64,64,
63,67,00,40
"hadenfbadiddjfmi"=hex:6a,61,67,6f,6d,6a,69,6b,64,6a,67,62,66,6d,61,64,69,66,
6f,62,00,40
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{17C83A77-4F46-40C9-B9A2-3970E88BA0A8}\InProcServer32*]
"jamggonocfldbellifmo"=hex:6a,61,6b,66,67,66,70,6b,6a,6c,61,6f,6f,63,64,70,6d,
67,6f,64,00,40
"iamgioidolbnadbibo"=hex:6a,61,6b,66,70,65,6d,6d,61,65,66,6d,67,69,66,6d,65,68,
63,6a,00,40
"iamgclpecgefgbhmhf"=hex:61,61,00,00
"iamgclpecgceaalijn"=hex:61,61,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7A495AE5-EAFF-3DC3-264B-07DBFFD7D5EC}\InProcServer32*]
"iahfkbhmicfcnlealj"=hex:61,61,00,00
"iahfkbhmichbpkaged"=hex:61,61,00,00
"jahfgcdbpnohimokhjdk"=hex:6a,61,67,6f,63,6b,6f,6b,65,6b,64,61,65,65,65,63,64,
64,63,67,00,40
"iahficfejjgmcpiogm"=hex:6a,61,67,6f,6d,6a,69,6b,64,6a,67,62,66,6d,61,64,69,66,
6f,62,00,40
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'lsass.exe'(728)
c:\windows\system32\MPR.dll
c:\windows\system32\guard32.dll
.
- - - - - - - > 'explorer.exe'(2116)
c:\windows\system32\guard32.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'csrss.exe'(640)
c:\windows\system32\cmdcsr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-11-02 20:56:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-02 19:56
.
Před spuštěním: 1 608 708 096
Po spuštění: 1 717 862 400
.
- - End Of File - - BBC1A306F89D2C2EB38744CBECE848EE