ComboFix 13-10-21.01 - Standa 22.10.2013 8:05.6.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3292.2799 [GMT 2:00]
Spuštěný z: c:\documents and settings\Standa\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Standa\Plocha\CFScript.txt.txt
AV: ESET NOD32 Antivirus 6.0 *Disabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý
.
.
FILE ::
"c:\documents and settings\Standa\Local Settings\Data aplikací\djolert.dll"
"c:\windows\tasks\tmtxnbi.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\msmqinst.log
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-09-22 do 2013-10-22 )))))))))))))))))))))))))))))))
.
.
2013-10-21 17:10 . 2013-10-21 17:10 -------- d-----w- C:\30e5266ce5920a3c32
2013-10-21 13:19 . 2013-07-03 02:12 25088 -c----w- c:\windows\system32\dllcache\hidparse.sys
2013-10-21 13:18 . 2013-07-17 00:58 123008 -c----w- c:\windows\system32\dllcache\usbvideo.sys
2013-10-21 13:18 . 2013-07-17 00:58 46848 -c----w- c:\windows\system32\dllcache\irbus.sys
2013-10-21 13:18 . 2013-07-17 00:58 60160 -c----w- c:\windows\system32\dllcache\usbaudio.sys
2013-10-21 13:18 . 2013-08-09 00:55 144128 -c----w- c:\windows\system32\dllcache\usbport.sys
2013-10-21 13:18 . 2013-08-09 00:55 32384 -c----w- c:\windows\system32\dllcache\usbccgp.sys
2013-10-21 13:18 . 2013-08-09 00:55 5376 -c----w- c:\windows\system32\dllcache\usbd.sys
2013-10-21 13:18 . 2009-03-18 11:02 30336 -c----w- c:\windows\system32\dllcache\usbehci.sys
2013-10-21 09:37 . 2013-10-21 09:37 -------- d-----w- C:\rsit
2013-10-21 07:01 . 2013-10-21 07:01 -------- d-----w- C:\FRST
2013-10-21 06:43 . 2013-10-21 10:30 -------- d-----w- C:\AdwCleaner
2013-10-21 05:46 . 2013-10-21 05:46 -------- d-----w- c:\documents and settings\Standa\Local Settings\Data aplikací\iolo
2013-10-21 05:46 . 2013-10-21 05:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\iolo
2013-10-16 10:32 . 2013-10-16 10:32 -------- d-----w- c:\program files\Professional Lambda Remover
2013-10-16 10:32 . 2013-10-16 10:32 -------- d-----w- c:\program files\Professional DPF Remover
2013-10-16 10:32 . 2013-10-16 10:32 -------- d-----w- c:\program files\Professional EGR Remover
2013-10-09 07:24 . 2013-10-09 08:24 17813896 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-10-09 05:23 . 2013-10-09 05:23 -------- d-----w- C:\Dell
2013-10-08 05:46 . 2013-10-08 05:46 -------- d-----w- c:\documents and settings\Standa\Data aplikací\SUPERAntiSpyware.com
2013-10-08 05:45 . 2013-10-17 07:48 -------- d-----w- c:\program files\SUPERAntiSpyware
2013-10-08 05:45 . 2013-10-08 05:45 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2013-10-07 14:08 . 2013-10-07 14:09 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ngXrVU33
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-10-09 08:24 . 2012-06-26 05:03 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-10-09 08:24 . 2011-05-18 05:26 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-23 18:25 . 2004-08-17 13:49 920064 ----a-w- c:\windows\system32\wininet.dll
2013-09-23 18:25 . 2004-08-17 13:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-09-23 18:25 . 2004-08-17 13:49 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-09-23 18:25 . 2004-08-17 13:49 18944 ----a-w- c:\windows\system32\corpol.dll
2013-09-23 18:06 . 2004-08-17 13:44 385024 ----a-w- c:\windows\system32\html.iec
2013-09-04 14:46 . 2013-09-04 14:46 24576 ----a-w- c:\documents and settings\Standa\Local Settings\Data aplikací\djolert.dll
2013-08-29 07:01 . 2004-08-17 13:44 1878656 ----a-w- c:\windows\system32\win32k.sys
2013-08-29 00:56 . 2011-12-13 06:19 26240 ----a-w- c:\windows\system32\drivers\usbser.sys
2013-08-13 09:31 . 2011-01-24 12:44 178863 ----a-w- c:\windows\Multi Protocol Programming System Uninstaller.exe
2013-08-09 01:56 . 2004-08-17 13:49 386560 ----a-w- c:\windows\system32\themeui.dll
2013-08-09 00:55 . 2004-08-03 21:08 144128 ----a-w- c:\windows\system32\drivers\usbport.sys
2013-08-09 00:55 . 2011-01-24 07:27 32384 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2013-08-09 00:55 . 2001-10-25 12:00 5376 ----a-w- c:\windows\system32\drivers\usbd.sys
2013-08-05 13:30 . 2004-08-17 13:49 1289216 ----a-w- c:\windows\system32\ole32.dll
2013-08-02 23:48 . 2006-10-18 20:47 1543680 ------w- c:\windows\system32\wmvdecod.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-07-25 20684656]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-10-17 5706480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-02-25 18791456]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-23 174104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-23 144920]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-11-26 5074384]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Standa\Nabídka Start\Programy\Po spuštění\
DOSPRN.lnk - c:\program files\DOSPRN\DOSprn.exe [2011-1-24 815104]
RT-Updater.lnk - c:\auto-diagnostika\vagcom.exe Update [2013-1-21 1164288]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
ADnews.lnk - c:\auto-diagnostika\Auto-diagnostika.exe [2013-1-31 1368632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableVirtualization"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2013-05-07 115440]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^ADnews.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\ADnews.lnk
backup=c:\windows\pss\ADnews.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Service Manager.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Service Manager.lnk
backup=c:\windows\pss\Service Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Standa^Nabídka Start^Programy^Po spuštění^RT-Updater.lnk]
path=c:\documents and settings\Standa\Nabídka Start\Programy\Po spuštění\RT-Updater.lnk
backup=c:\windows\pss\RT-Updater.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Služba Acronis Scheduler2"="c:\program files\Common Files\Acronis\Plán2\schedhlp.exe"
"TrueImageMonitor.exe"=c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe"
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" /s
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"PsaStart"=c:\applic\ddc\bin\psastart.exe c:\applic\ddc\bin\psaagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\APP\\PPS\\mozilla.exe"=
"c:\\APPLIC\\Portail\\mozilla.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Keys Server\\sntlkeyssrvr.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\pemicro\\prog08sz\\prog08sz.exe"=
"c:\\Program Files\\Air Live IP Wizard II\\IPWizardII.exe"=
"c:\\Program Files\\VideoViewer\\VideoViewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);c:\windows\system32\drivers\tdrpm258.sys [19.7.2011 7:42 911680]
R1 AppleCharger;AppleCharger;c:\windows\system32\drivers\AppleCharger.sys [23.1.2011 22:53 19496]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [11.10.2011 7:42 232512]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [8.10.2012 9:21 121216]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [8.10.2012 9:21 104736]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [23.5.2013 22:11 119056]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [19.7.2011 7:42 2480048]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [26.11.2012 14:34 1329304]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\app\FIREBIRD\bin\fbguard.exe -s --> c:\app\FIREBIRD\bin\fbguard.exe -s [?]
R2 LcSvrAdm;ELSA Administration Service;c:\elsawin\bin\LcSvrAdm.exe [8.4.2013 8:37 147456]
R2 LcSvrDba;ELSA DBA Server;c:\elsawin\bin\LcSvrDba.exe [8.4.2013 8:37 241664]
R2 LcSvrHis;ELSA Historie Server;c:\elsawin\bin\LcSvrHis.exe [8.4.2013 8:37 217088]
R2 LcSvrPAS;ELSA PASS Server;c:\elsawin\bin\LcSvrPas.exe [8.4.2013 8:37 368640]
R2 LcSvrSaz;ELSA APOSpro Server;c:\elsawin\bin\LcSvrSaz.exe [8.4.2013 8:37 258048]
R2 Motorola Device Manager;Motorola Device Manager Service;c:\program files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [24.10.2012 0:58 120728]
R2 MSSQL$SFN;MSSQL$SFN;c:\program files\Microsoft SQL Server\MSSQL$SFN\Binn\sqlservr.exe -sSFN --> c:\program files\Microsoft SQL Server\MSSQL$SFN\Binn\sqlservr.exe -sSFN [?]
R2 pardrv;pardrv;c:\windows\system32\drivers\pardrv.sys [24.1.2011 8:11 9728]
R2 PEDRV;P&E Microcomputer System PCI Driver.;c:\windows\system32\drivers\pedrv.sys [16.10.2009 16:28 28080]
R2 SentinelKeysServer;Sentinel Keys Server;c:\program files\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [11.7.2008 2:02 328992]
R2 STM Parallel Driver;STM Parallel Driver;c:\windows\system32\drivers\parstm.sys [3.7.2012 15:19 35040]
R2 VSGate;ELSA Vaudis Service;c:\elsawin\bin\VSGate.exe [8.4.2013 8:37 81920]
R3 adatadrv;Autodata Protection Service;c:\windows\system32\drivers\adatadrv.sys [15.2.2011 15:09 762112]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [19.7.2011 7:42 160288]
R3 BrUsbScn;Ovladač skeneru Brother MFC USB;c:\windows\system32\drivers\BrUsbScn.sys [24.1.2011 9:27 10368]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\app\FIREBIRD\bin\fbserver.exe -s --> c:\app\FIREBIRD\bin\fbserver.exe -s [?]
R3 LcSvrAuf;ELSA Auftragsverwaltungs Service;c:\elsawin\bin\LcSvrAuf.exe [8.4.2013 8:37 1306624]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5.3.2012 12:06 22856]
R3 PciPPorts;PCI ECP Parallel Port;c:\windows\system32\drivers\PciPPorts.sys [23.1.2011 23:00 82944]
R3 PciSPorts;High-Speed PCI Serial Port;c:\windows\system32\drivers\PciSPorts.sys [23.1.2011 23:00 115200]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5.3.2012 12:06 701512]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [25.7.2013 8:52 162672]
S2 WorkshopDBService;WorkshopDBService;c:\progra~1\VIVIDW~1\WORKSH~1.EXE -zglaxservice WorkshopDBService --> c:\progra~1\VIVIDW~1\WORKSH~1.EXE -zglaxservice WorkshopDBService [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [23.1.2011 22:41 1691480]
S3 AMTCAR;Amt-Cartech System Driver (AmtCar.Sys);c:\windows\system32\drivers\AmtCar.sys [22.4.2009 13:27 31712]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe --> system32\AppleChargerSrv.exe [?]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [29.11.2012 10:02 6016]
S3 CTU2K;CTU2K.SYS CTU2K device driver;c:\windows\system32\drivers\CTU2K.sys [24.1.2011 12:20 24197]
S3 CYUSB3;UPA-USB3.0 Driver;c:\windows\system32\drivers\UPAUSB.sys [13.9.2013 17:50 49320]
S3 ezusb;ezusb;c:\windows\system32\DRIVERS\ezusb.sys --> c:\windows\system32\DRIVERS\ezusb.sys [?]
S3 FTD2XX;VAGUSB.sys VAG-Com USB driver;c:\windows\system32\drivers\VAGUSB.sys [24.1.2011 12:19 25596]
S3 HS4l;Handyscope HS4 driver (before renumeration);c:\windows\system32\drivers\HS4l.sys [12.5.2011 13:37 18944]
S3 HS4r;Handyscope HS4 driver;c:\windows\system32\drivers\HS4r.sys [12.5.2011 13:37 19840]
S3 jlink;J-Link driver;c:\windows\system32\drivers\jlink.sys [7.10.2011 8:15 14208]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [29.11.2012 10:02 20864]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [29.11.2012 10:02 8448]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [29.11.2012 10:02 23808]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [29.11.2012 10:02 11008]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [13.12.2011 8:16 137472]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [13.12.2011 8:16 8576]
S3 RT-USB;Ross-Tech USB driver;c:\windows\system32\drivers\RT-USB.SYS [28.3.2012 13:45 59464]
S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [20.1.2012 12:10 14592]
S3 SmokXX;SmokXX.SYS FT8U2XX device driver;c:\windows\system32\drivers\SmokXX.sys [3.9.2012 9:26 29292]
S3 SQLAgent$SFN;SQLAgent$SFN;c:\program files\Microsoft SQL Server\MSSQL$SFN\Binn\sqlagent.EXE -i SFN --> c:\program files\Microsoft SQL Server\MSSQL$SFN\Binn\sqlagent.EXE -i SFN [?]
S3 VCommUSB;Service for ACTIA USB Devices;c:\windows\system32\drivers\VCommUSB.sys [24.1.2011 13:57 40576]
S3 zlportio;zlportio;\??\z:\car\Dashboard\Utility\Calculators\Licznik 8 novy !!!!\Licznik 8\licznic686\licznik8\zlportio.sys --> z:\car\Dashboard\Utility\Calculators\Licznik 8 novy !!!!\Licznik 8\licznic686\licznik8\zlportio.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-18 10:16 1185744 ----a-w- c:\program files\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-26 08:24]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-08 05:47]
.
2013-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-04-08 05:47]
.
2013-10-08 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 843019b9-847c-4d4e-9095-a43973afff18.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21]
.
2013-10-22 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task a851042c-bbdd-46de-97da-d5c6594b053a.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
DPF: {336C9D79-263A-4D75-AA7C-60DAF945AE67} - hxxp://178.72.207.174/classes/OvisLinkCamV_H264.cab
DPF: {971FC730-55F1-461F-83FD-B3BF5E1F039E} - hxxp://192.168.1.109/AVC_AX_742.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-10-22 08:13
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2768)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Acronis\Plán2\schedul2.exe
c:\windows\system32\crypserv.exe
c:\app\FIREBIRD\bin\fbguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\program files\Microsoft SQL Server\MSSQL$SFN\Binn\sqlservr.exe
c:\program files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\system32\BRMFRSMG.EXE
c:\app\FIREBIRD\bin\fbserver.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Celkový čas: 2013-10-22 08:16:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-10-22 06:16
ComboFix2.txt 2013-10-21 14:25
ComboFix3.txt 2013-10-21 13:17
ComboFix4.txt 2013-10-21 11:07
.
Před spuštěním: Volných bajtů: 421 514 539 008
Po spuštění: Volných bajtů: 421 585 997 824
.
- - End Of File - - 29434D28CBABD32E0DB095F8073A3F98
413FC2A0C716421B3158746D63736515