Stránka 1 z 2

Vyskakovani oken IE

Napsal: 24 led 2010 20:14
od welbern
Stahnula se mi do PC asi nejaka havet, protoze najednou mi zacali obcas vyskakovat okna z IE (reklamy) a pritom pouzivam jen Firefox a na IE sem od formatovani pc nesahnul. Diky jestli na to nekdo mrknete

Logfile of random's system information tool 1.06 (written by random/random)
Run by uživatel at 2010-01-24 20:11:28
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 15 GB (10%) free of 153 GB
Total RAM: 2047 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:11:45, on 24.1.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\pdfforge Toolbar\SearchSettings.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Programy\RSIT.exe
C:\Program Files\trend micro\uživatel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Cm112Sound] RunDll32 cm112.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "E:\Programy\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Phase One Media Reader] E:\Programy\CAPTUR~1\DCIMImp.exe /noscan /CheckAutoStart
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSection nLite.inf,C (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: app_dll.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8030 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At10.job
C:\WINDOWS\tasks\At11.job
C:\WINDOWS\tasks\At12.job
C:\WINDOWS\tasks\At121.job
C:\WINDOWS\tasks\At122.job
C:\WINDOWS\tasks\At123.job
C:\WINDOWS\tasks\At124.job
C:\WINDOWS\tasks\At125.job
C:\WINDOWS\tasks\At126.job
C:\WINDOWS\tasks\At127.job
C:\WINDOWS\tasks\At128.job
C:\WINDOWS\tasks\At129.job
C:\WINDOWS\tasks\At13.job
C:\WINDOWS\tasks\At130.job
C:\WINDOWS\tasks\At131.job
C:\WINDOWS\tasks\At132.job
C:\WINDOWS\tasks\At133.job
C:\WINDOWS\tasks\At134.job
C:\WINDOWS\tasks\At135.job
C:\WINDOWS\tasks\At136.job
C:\WINDOWS\tasks\At137.job
C:\WINDOWS\tasks\At138.job
C:\WINDOWS\tasks\At139.job
C:\WINDOWS\tasks\At14.job
C:\WINDOWS\tasks\At140.job
C:\WINDOWS\tasks\At141.job
C:\WINDOWS\tasks\At142.job
C:\WINDOWS\tasks\At143.job
C:\WINDOWS\tasks\At144.job
C:\WINDOWS\tasks\At15.job
C:\WINDOWS\tasks\At16.job
C:\WINDOWS\tasks\At17.job
C:\WINDOWS\tasks\At18.job
C:\WINDOWS\tasks\At19.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\At20.job
C:\WINDOWS\tasks\At21.job
C:\WINDOWS\tasks\At22.job
C:\WINDOWS\tasks\At23.job
C:\WINDOWS\tasks\At24.job
C:\WINDOWS\tasks\At3.job
C:\WINDOWS\tasks\At4.job
C:\WINDOWS\tasks\At5.job
C:\WINDOWS\tasks\At6.job
C:\WINDOWS\tasks\At7.job
C:\WINDOWS\tasks\At8.job
C:\WINDOWS\tasks\At9.job
C:\WINDOWS\tasks\HP Usg Daily.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-12-12 1111320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll [2010-01-08 700416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-08 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2010-01-08 1109504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-08 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll [2010-01-08 700416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-10-30 16269312]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-01-24 39440]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2010-01-24 39440]
"Cm112Sound"=RunDll32 cm112.cpl,CMICtrlWnd []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-01-24 39440]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-01-24 39440]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2010-01-24 39440]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2010-01-24 39440]
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe [2010-01-24 39440]
"HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2010-01-24 39440]
"HP Software Update"=E:\Programy\HP\HP Software Update\HPWuSchd2.exe [2010-01-24 39440]
"HPHmon05"=C:\WINDOWS\system32\hphmon05.exe [2010-01-24 39440]
"Phase One Media Reader"=E:\Programy\CAPTUR~1\DCIMImp.exe [2010-01-24 39440]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2010-01-24 39440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2010-01-24 39440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="app_dll.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-09-30 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-12-01 11952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableRegistryTools"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"E:\Games\Wotlk\Repair.exe"="E:\Games\Wotlk\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Disabled:Crawler Spyware Terminator"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-01-24 18:56:50 ----D---- C:\Program Files\trend micro
2010-01-24 18:56:49 ----D---- C:\rsit
2010-01-24 17:33:22 ----A---- C:\WINDOWS\system32\app_dll.dll
2010-01-24 09:59:08 ----D---- C:\Documents and Settings\uživatel\Data aplikací\Search Settings
2010-01-24 09:59:06 ----D---- C:\Documents and Settings\uživatel\Data aplikací\pdfforge
2010-01-24 09:51:55 ----D---- C:\Program Files\Application Updater
2010-01-24 09:51:52 ----D---- C:\WINDOWS\SxsCaPendDel
2010-01-24 09:51:18 ----SHD---- C:\Config.Msi
2010-01-09 13:16:26 ----D---- C:\Program Files\Microsoft Silverlight
2010-01-04 13:56:13 ----A---- C:\WINDOWS\system32\ptpusb.dll
2010-01-04 13:56:12 ----A---- C:\WINDOWS\system32\ptpusd.dll
2010-01-02 18:33:32 ----D---- C:\Documents and Settings\uživatel\Data aplikací\Uniblue
2010-01-02 18:33:27 ----D---- C:\Program Files\Uniblue
2009-12-28 02:21:24 ----RA---- C:\WINDOWS\system32\fdco1.dll
2009-12-28 02:21:20 ----A---- C:\WINDOWS\system32\nvunrm.exe
2009-12-28 02:21:19 ----RA---- C:\WINDOWS\system32\nvconrm.dll
2009-12-28 02:21:19 ----RA---- C:\WINDOWS\system32\bdco1.dll
2009-12-28 02:09:19 ----D---- C:\SWSetup
2009-12-26 21:51:19 ----HD---- C:\$AVG8.VAULT$
2009-12-26 17:37:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard Entertainment
2009-12-25 09:23:29 ----A---- C:\WINDOWS\system32\dxva_sig.txt

======List of files/folders modified in the last 1 months======

2010-01-24 20:11:36 ----RD---- C:\Program Files
2010-01-24 19:54:15 ----D---- C:\WINDOWS\Temp
2010-01-24 19:46:21 ----SD---- C:\WINDOWS\Tasks
2010-01-24 18:45:09 ----D---- C:\WINDOWS\system32
2010-01-24 18:41:25 ----D---- C:\WINDOWS\system32\drivers
2010-01-24 18:41:09 ----SD---- C:\Documents and Settings\uživatel\Data aplikací\Microsoft
2010-01-24 17:34:42 ----D---- C:\Program Files\Mozilla Firefox
2010-01-24 17:33:41 ----D---- C:\Program Files\Adobe
2010-01-24 17:33:34 ----D---- C:\WINDOWS\Prefetch
2010-01-24 17:33:08 ----A---- C:\WINDOWS\system32\hphmon05.exe
2010-01-24 17:32:33 ----D---- C:\Documents and Settings\uživatel\Data aplikací\Skype
2010-01-24 17:32:22 ----D---- C:\Documents and Settings\uživatel\Data aplikací\skypePM
2010-01-24 17:31:51 ----D---- C:\WINDOWS
2010-01-24 17:29:58 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-24 17:25:36 ----D---- C:\Program Files\pdfforge Toolbar
2010-01-24 17:25:36 ----D---- C:\Program Files\Internet Explorer
2010-01-24 17:25:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-24 17:25:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-24 12:31:01 ----D---- C:\FOTO
2010-01-24 09:52:03 ----SHD---- C:\WINDOWS\Installer
2010-01-19 20:27:53 ----RD---- C:\DOKUMENTY
2010-01-17 17:45:12 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-02 15:47:20 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-02 02:32:21 ----D---- C:\WINDOWS\system32\config
2009-12-28 02:21:23 ----HD---- C:\WINDOWS\inf
2009-12-28 02:19:03 ----A---- C:\WINDOWS\Ascd_tmp.ini
2009-12-26 19:34:37 ----D---- C:\Program Files\Common Files

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2009-12-15 43672]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 43008]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-12-01 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-12-01 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-12-01 108552]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-09-30 3565056]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-03-18 51088]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-03-18 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-03-18 21744]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-03 4394496]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-03-06 58752]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-03-06 19968]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-02-16 12032]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 a4wymq3g;a4wymq3g; C:\WINDOWS\system32\drivers\a4wymq3g.sys []
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-09-28 7168]
S3 USBADVAU;USB Advance Audio Interface; C:\WINDOWS\system32\drivers\cm112.sys [2007-07-20 1312768]
S3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-09-30 602112]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-12-01 297752]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-08 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-09-06 71096]
R2 P1C1394;Phase One 1394 Camera Driver; C:\WINDOWS\System32\Drivers\p1c1394.sys [2005-11-21 23168]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-09-29 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-11 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Vyskakovani oken IE

Napsal: 24 led 2010 21:27
od Rudy
Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware

Re: Vyskakovani oken IE

Napsal: 24 led 2010 22:11
od welbern
ComboFix 10-01-24.01 - uživatel 24.01.2010 22:00:54.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1600 [GMT 1:00]
Spuštěný z: c:\documents and settings\uživatel\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Dokumenty\desktop.ini
c:\documents and settings\All Users\Dokumenty\Filmy
c:\documents and settings\All Users\Dokumenty\Filmy\Desktop.ini
c:\documents and settings\All Users\Dokumenty\Hudba
c:\documents and settings\All Users\Dokumenty\Hudba\Desktop.ini
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst1.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst10.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst11.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst12.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst13.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst14.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst15.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst2.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst3.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst4.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst5.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst6.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst7.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst8.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Sample Playlists\000E7F7C\Plylst9.wpl
c:\documents and settings\All Users\Dokumenty\Hudba\Ukázky hudby\Beethovenova symfonie č. 9 (Scherzo).wma
c:\documents and settings\All Users\Dokumenty\Hudba\Ukázky hudby\desktop.ini
c:\documents and settings\All Users\Dokumenty\Hudba\Ukázky hudby\Nové příběhy (Highway Blues).wma
c:\documents and settings\All Users\DRM
c:\documents and settings\All Users\DRM\drmv2.lic
c:\documents and settings\All Users\DRM\drmv2.sst
c:\documents and settings\All Users\Plocha\Adobe Reader 9.lnk
c:\documents and settings\All Users\Plocha\AVG Free 8.5.lnk
c:\documents and settings\All Users\Plocha\Capture One PRO 3.7.3.lnk
c:\documents and settings\All Users\Plocha\CDBurnerXP.lnk
c:\documents and settings\All Users\Plocha\DAEMON Tools Lite.lnk
c:\documents and settings\All Users\Plocha\RegistryBooster.lnk
c:\documents and settings\All Users\Plocha\Spyware Terminator.lnk
c:\documents and settings\All Users\Plocha\Zoner Photo Studio 10.lnk
c:\documents and settings\Default User\Local Settings\desktop.ini
c:\documents and settings\Default User\Okolní síť
c:\documents and settings\Default User\Okolní tiskárny
c:\documents and settings\LocalService\Local Settings\desktop.ini
c:\documents and settings\LocalService\ntuser.ini
c:\documents and settings\NetworkService\Local Settings\desktop.ini
c:\documents and settings\NetworkService\ntuser.ini
c:\program files\Internet Explorer\wmpscfgs.exe
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\config\systemprofile\Dokumenty
c:\windows\system32\config\systemprofile\Local Settings\desktop.ini
c:\windows\system32\config\systemprofile\Šablony
c:\windows\system32\config\systemprofile\Šablony\amipro.sam
c:\windows\system32\config\systemprofile\Šablony\excel.xls
c:\windows\system32\config\systemprofile\Šablony\excel4.xls
c:\windows\system32\config\systemprofile\Šablony\lotus.wk4
c:\windows\system32\config\systemprofile\Šablony\powerpnt.ppt
c:\windows\system32\config\systemprofile\Šablony\presenta.shw
c:\windows\system32\config\systemprofile\Šablony\quattro.wb2
c:\windows\system32\config\systemprofile\Šablony\sndrec.wav
c:\windows\system32\config\systemprofile\Šablony\winword.doc
c:\windows\system32\config\systemprofile\Šablony\winword2.doc
c:\windows\system32\config\systemprofile\Šablony\wordpfct.wpd
c:\windows\system32\config\systemprofile\Šablony\wordpfct.wpg
c:\windows\system32\config\systemprofile\Okolní síť
c:\windows\system32\config\systemprofile\Okolní tiskárny
c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe
c:\windows\system32\ieuinit.inf
c:\windows\system32\kr_done1
c:\windows\system32\twain_32.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-24 do 2010-01-24 )))))))))))))))))))))))))))))))
.

2010-01-24 20:01 . 2010-01-24 20:02 -------- d-----w- c:\program files\Crawler
2010-01-24 20:01 . 2010-01-24 20:01 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-24 20:01 . 2010-01-24 20:13 -------- d-----w- c:\program files\Spyware Terminator
2010-01-24 17:56 . 2010-01-24 19:11 -------- d-----w- c:\program files\trend micro
2010-01-24 17:56 . 2010-01-24 19:11 -------- d-----w- C:\rsit
2010-01-24 17:09 . 2010-01-24 17:09 -------- d-----r- c:\documents and settings\NetworkService\Oblíbené položky
2010-01-24 16:33 . 2010-01-24 16:33 59904 ----a-w- c:\windows\system32\app_dll.dll
2010-01-24 08:51 . 2010-01-24 08:51 -------- d-----w- c:\program files\Application Updater
2010-01-24 08:51 . 2010-01-24 15:41 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-09 12:16 . 2010-01-09 12:16 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-04 12:56 . 2001-10-24 11:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-01-04 12:56 . 2008-04-14 07:51 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-01-04 12:56 . 2008-04-13 23:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-04 12:56 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-02 17:33 . 2010-01-02 17:33 -------- d-----w- c:\program files\Uniblue
2009-12-28 01:21 . 2007-03-06 04:25 196096 ----a-r- c:\windows\system32\fdco1.dll
2009-12-28 01:21 . 2007-03-06 04:27 58752 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2009-12-28 01:21 . 2007-02-01 09:44 356352 ----a-w- c:\windows\system32\nvunrm.exe
2009-12-28 01:21 . 2007-03-06 04:27 110592 ----a-r- c:\windows\system32\drivers\nvtcp.sys
2009-12-28 01:21 . 2007-03-06 04:25 9216 ----a-r- c:\windows\system32\bdco1.dll
2009-12-28 01:21 . 2007-02-01 09:44 36352 ----a-r- c:\windows\system32\nvconrm.dll
2009-12-28 01:21 . 2007-03-06 04:26 261632 ----a-r- c:\windows\system32\drivers\nvsnpu.sys
2009-12-28 01:21 . 2007-03-06 04:27 921984 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2009-12-28 01:21 . 2007-03-06 04:27 19968 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2009-12-28 01:09 . 2009-12-28 01:09 -------- d-----w- C:\SWSetup
2009-12-26 20:51 . 2010-01-24 19:04 -------- d-----w- C:\$AVG8.VAULT$

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 20:14 . 2009-12-15 16:26 -------- d-----w- c:\program files\pdfforge Toolbar
2010-01-24 20:14 . 2004-05-05 05:15 39440 ----a-w- c:\windows\system32\hphmon05.exe
2010-01-17 16:45 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-01-17 16:45 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2009-12-15 18:16 . 2009-12-15 18:10 19907 ----a-w- c:\windows\HPHins02.dat
2009-12-15 18:15 . 2009-12-15 18:14 -------- d-----w- c:\program files\HP
2009-12-15 18:15 . 2009-12-15 18:15 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-12-15 18:11 . 2009-12-15 18:11 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-13 14:26 . 2009-12-13 14:26 -------- d-----w- c:\program files\Phase One
2009-12-13 12:22 . 2009-12-13 12:22 -------- d-----w- c:\program files\Microsoft Works
2009-12-13 12:21 . 2009-12-12 14:57 -------- d-----w- c:\program files\MSBuild
2009-12-13 12:21 . 2009-12-13 12:21 -------- d-----w- c:\program files\Microsoft.NET
2009-12-13 12:19 . 2009-12-13 12:19 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-12-12 14:57 . 2009-12-12 14:57 -------- d-----w- c:\program files\Reference Assemblies
2009-12-12 08:41 . 2009-12-12 08:41 -------- d-----w- c:\program files\Common Files\Nikon
2009-12-11 23:00 . 2009-12-11 23:00 -------- d-----w- c:\program files\Bonjour
2009-12-11 23:00 . 2009-12-01 13:05 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 22:22 . 2009-12-11 22:22 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-08 14:07 . 2009-12-08 14:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 14:07 . 2009-12-08 14:07 -------- d-----w- c:\program files\Java
2009-12-05 16:12 . 2009-12-05 16:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-05 10:50 . 2009-12-05 10:50 -------- d-----w- c:\program files\Zoner
2009-12-05 10:05 . 2009-12-05 10:05 -------- d-----w- c:\program files\HS-04U
2009-12-05 09:46 . 2009-12-05 09:46 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-05 09:44 . 2009-12-05 09:43 -------- d-----r- c:\program files\Skype
2009-12-05 09:43 . 2009-12-05 09:43 -------- d-----w- c:\program files\Common Files\Skype
2009-12-01 16:29 . 2009-12-01 16:05 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-01 16:06 . 2009-12-01 16:06 -------- d-----w- c:\program files\microsoft frontpage
2009-12-01 16:02 . 2009-12-01 16:02 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-01 13:06 . 2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-01 13:06 . 2009-12-01 13:06 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-01 13:06 . 2009-12-01 13:06 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 -------- d-----w- c:\program files\AVG
2009-12-01 13:03 . 2009-12-01 13:03 -------- d-----w- c:\program files\CDBurnerXP
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-01 12:53 . 2009-12-01 12:53 0 ----a-w- c:\windows\nsreg.dat
2009-12-01 12:53 . 2009-12-01 12:52 -------- d-----w- c:\program files\The KMPlayer
2009-12-01 12:52 . 2009-12-01 12:52 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-01 12:40 . 2009-12-01 12:40 0 ----a-w- c:\windows\ativpsrm.bin
2009-12-01 12:37 . 2009-12-01 12:36 -------- d-----w- c:\program files\ATI Technologies
2009-12-01 12:37 . 2009-12-01 11:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-01 12:36 . 2009-12-01 11:12 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-01 11:26 . 2009-12-01 16:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-01 11:26 . 2009-12-01 16:05 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-01 11:18 . 2009-12-01 11:18 -------- d-----w- c:\program files\DIFX
2009-12-01 11:14 . 2009-12-01 11:14 -------- d-----w- c:\program files\Realtek
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\acrotray .exe
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\AVG\AVG8\avgtray .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Adobe\Updater5\adobeupdater .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Microsoft Office\Office12\groovemonitor .exe
c:\program files\pdfforge Toolbar\searchsettings .exe
c:\program files\Spyware Terminator\spywareterminatorupdate .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2010-01-24 39440]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-01-24 39440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 16269312]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-24 39440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-01-24 39440]
"Cm112Sound"="cm112.cpl" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-01-24 39440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-01-24 39440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-24 39440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2010-01-24 39440]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2010-01-24 39440]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2010-01-24 39440]
"HP Software Update"="e:\programy\HP\HP Software Update\HPWuSchd2.exe" [2010-01-24 39440]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2010-01-24 39440]
"Phase One Media Reader"="e:\programy\CAPTUR~1\DCIMImp.exe" [2010-01-24 39440]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2010-01-24 39440]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide3"="rundll32 advpack.dll" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Games\\Wotlk\\Repair.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1.12.2009 14:06 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1.12.2009 14:06 108552]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [24.1.2010 21:01 142592]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [8.1.2010 0:51 380928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1.12.2009 14:06 297752]
R2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\drivers\p1c1394.sys [18.12.2009 17:56 23168]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.12.2009 13:52 721904]
S3 USBADVAU;USB Advance Audio Interface;c:\windows\system32\drivers\cm112.sys [5.12.2009 11:05 1312768]
.
Obsah adresáře 'Naplánované úlohy'

2010-01-24 c:\windows\Tasks\At49.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At50.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At51.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At52.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At53.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At54.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At55.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At56.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At57.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At58.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At59.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At60.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At61.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At62.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At63.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At64.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At65.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At66.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At67.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At68.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At69.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At70.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At71.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]

2010-01-24 c:\windows\Tasks\At72.job
- c:\program files\adobe\acrotray .exe [2010-01-24 16:33]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\uživatel\Data aplikací\Mozilla\Firefox\Profiles\d63ma1qq.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll
FF - component: c:\program files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - c:\program files\pdfforge Toolbar\SearchSettings.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 22:03
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-01-24 22:04:44
ComboFix-quarantined-files.txt 2010-01-24 21:04

Před spuštěním: Volných bajtů: 15 323 234 304
Po spuštění: Volných bajtů: 15 373 983 744

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 087C5D9A08C1CB1C124BF9ED0B77AC39

Re: Vyskakovani oken IE

Napsal: 24 led 2010 22:56
od Rudy
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Folder::
c:\program files\pdfforge Toolbar

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SearchSettings"=-

AtJob::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek

Re: Vyskakovani oken IE

Napsal: 26 led 2010 03:21
od welbern
ComboFix 10-01-25.02 - uživatel 26.01.2010 3:10.4.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1462 [GMT 1:00]
Spuštěný z: c:\documents and settings\uživatel\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-26 do 2010-01-26 )))))))))))))))))))))))))))))))
.

2010-01-25 13:29 . 2010-01-25 13:29 4 ----a-w- c:\program files\10052421.dat
2010-01-24 22:03 . 2010-01-24 22:03 -------- d-----w- C:\Nová složka
2010-01-24 20:01 . 2010-01-24 20:02 -------- d-----w- c:\program files\Crawler
2010-01-24 20:01 . 2010-01-24 20:01 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-24 20:01 . 2010-01-25 13:19 -------- d-----w- c:\program files\Spyware Terminator
2010-01-24 17:56 . 2010-01-24 21:16 -------- d-----w- c:\program files\trend micro
2010-01-24 17:56 . 2010-01-24 19:11 -------- d-----w- C:\rsit
2010-01-24 17:09 . 2010-01-24 17:09 -------- d-----r- c:\documents and settings\NetworkService\Oblíbené položky
2010-01-24 08:51 . 2010-01-24 08:51 -------- d-----w- c:\program files\Application Updater
2010-01-24 08:51 . 2010-01-24 15:41 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-09 12:16 . 2010-01-09 12:16 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-04 12:56 . 2001-10-24 11:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-01-04 12:56 . 2008-04-14 07:51 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-01-04 12:56 . 2008-04-13 23:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-04 12:56 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-02 17:33 . 2010-01-02 17:33 -------- d-----w- c:\program files\Uniblue
2009-12-28 01:21 . 2007-03-06 04:25 196096 ----a-r- c:\windows\system32\fdco1.dll
2009-12-28 01:21 . 2007-03-06 04:27 58752 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2009-12-28 01:21 . 2007-02-01 09:44 356352 ----a-w- c:\windows\system32\nvunrm.exe
2009-12-28 01:21 . 2007-03-06 04:27 110592 ----a-r- c:\windows\system32\drivers\nvtcp.sys
2009-12-28 01:21 . 2007-03-06 04:25 9216 ----a-r- c:\windows\system32\bdco1.dll
2009-12-28 01:21 . 2007-02-01 09:44 36352 ----a-r- c:\windows\system32\nvconrm.dll
2009-12-28 01:21 . 2007-03-06 04:26 261632 ----a-r- c:\windows\system32\drivers\nvsnpu.sys
2009-12-28 01:21 . 2007-03-06 04:27 921984 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2009-12-28 01:21 . 2007-03-06 04:27 19968 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2009-12-28 01:09 . 2009-12-28 01:09 -------- d-----w- C:\SWSetup

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 22:59 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 22:59 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2010-01-25 13:44 . 2004-05-05 05:15 39440 ----a-w- c:\windows\system32\hphmon05.exe
2010-01-24 20:14 . 2009-12-15 16:26 -------- d-----w- c:\program files\pdfforge Toolbar
2009-12-15 18:16 . 2009-12-15 18:10 19907 ----a-w- c:\windows\HPHins02.dat
2009-12-15 18:15 . 2009-12-15 18:14 -------- d-----w- c:\program files\HP
2009-12-15 18:15 . 2009-12-15 18:15 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-12-15 18:11 . 2009-12-15 18:11 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-13 14:26 . 2009-12-13 14:26 -------- d-----w- c:\program files\Phase One
2009-12-13 12:22 . 2009-12-13 12:22 -------- d-----w- c:\program files\Microsoft Works
2009-12-13 12:21 . 2009-12-12 14:57 -------- d-----w- c:\program files\MSBuild
2009-12-13 12:21 . 2009-12-13 12:21 -------- d-----w- c:\program files\Microsoft.NET
2009-12-13 12:19 . 2009-12-13 12:19 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-12-12 14:57 . 2009-12-12 14:57 -------- d-----w- c:\program files\Reference Assemblies
2009-12-12 08:41 . 2009-12-12 08:41 -------- d-----w- c:\program files\Common Files\Nikon
2009-12-11 23:00 . 2009-12-11 23:00 -------- d-----w- c:\program files\Bonjour
2009-12-11 23:00 . 2009-12-01 13:05 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 22:22 . 2009-12-11 22:22 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-08 14:07 . 2009-12-08 14:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 14:07 . 2009-12-08 14:07 -------- d-----w- c:\program files\Java
2009-12-05 16:12 . 2009-12-05 16:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-05 10:50 . 2009-12-05 10:50 -------- d-----w- c:\program files\Zoner
2009-12-05 10:05 . 2009-12-05 10:05 -------- d-----w- c:\program files\HS-04U
2009-12-05 09:46 . 2009-12-05 09:46 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-05 09:44 . 2009-12-05 09:43 -------- d-----r- c:\program files\Skype
2009-12-05 09:43 . 2009-12-05 09:43 -------- d-----w- c:\program files\Common Files\Skype
2009-12-01 16:29 . 2009-12-01 16:05 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-01 16:06 . 2009-12-01 16:06 -------- d-----w- c:\program files\microsoft frontpage
2009-12-01 16:02 . 2009-12-01 16:02 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-01 13:06 . 2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-01 13:06 . 2009-12-01 13:06 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-01 13:06 . 2009-12-01 13:06 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 -------- d-----w- c:\program files\AVG
2009-12-01 13:03 . 2009-12-01 13:03 -------- d-----w- c:\program files\CDBurnerXP
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-01 12:53 . 2009-12-01 12:53 0 ----a-w- c:\windows\nsreg.dat
2009-12-01 12:53 . 2009-12-01 12:52 -------- d-----w- c:\program files\The KMPlayer
2009-12-01 12:52 . 2009-12-01 12:52 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-01 12:40 . 2009-12-01 12:40 0 ----a-w- c:\windows\ativpsrm.bin
2009-12-01 12:37 . 2009-12-01 12:36 -------- d-----w- c:\program files\ATI Technologies
2009-12-01 12:37 . 2009-12-01 11:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-01 12:36 . 2009-12-01 11:12 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-01 11:26 . 2009-12-01 16:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-01 11:26 . 2009-12-01 16:05 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-01 11:18 . 2009-12-01 11:18 -------- d-----w- c:\program files\DIFX
2009-12-01 11:14 . 2009-12-01 11:14 -------- d-----w- c:\program files\Realtek
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\acrotray .exe
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\AVG\AVG8\avgtray .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Adobe\Updater5\adobeupdater .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Microsoft Office\Office12\groovemonitor .exe
c:\program files\pdfforge Toolbar\searchsettings .exe
c:\program files\Spyware Terminator\spywareterminatorupdate .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-01-24_21.03.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-26 02:07 . 2010-01-26 02:07 16384 c:\windows\Temp\Perflib_Perfdata_5b4.dat
+ 2009-12-15 18:13 . 2010-01-25 13:44 39440 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
- 2009-12-15 18:13 . 2010-01-24 16:33 39440 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
+ 2001-10-25 14:00 . 2010-01-25 22:59 67448 c:\windows\system32\perfc009.dat
- 2001-10-25 14:00 . 2010-01-17 16:45 67448 c:\windows\system32\perfc009.dat
+ 2009-12-01 16:02 . 2008-04-14 07:52 93184 c:\windows\system32\dllcache\iexplore.exe
+ 2009-12-01 16:02 . 2008-04-14 07:52 18432 c:\windows\system32\dllcache\iedw.exe
+ 2009-12-01 16:02 . 2008-04-14 07:51 38912 c:\windows\system32\dllcache\hmmapi.dll
+ 2010-01-25 12:30 . 2010-01-25 13:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010012520100126\index.dat
+ 2010-01-25 12:30 . 2010-01-25 12:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010011820100125\index.dat
- 2009-12-01 16:14 . 2010-01-24 20:47 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-12-01 16:14 . 2010-01-26 02:00 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-01-25 12:47 . 2010-01-25 12:47 16384 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Internet Explorer\MSIMGSIZ.DAT
+ 2010-01-25 23:05 . 2010-01-26 02:00 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2001-10-25 14:00 . 2010-01-25 22:59 432492 c:\windows\system32\perfh009.dat
- 2001-10-25 14:00 . 2010-01-17 16:45 432492 c:\windows\system32\perfh009.dat
+ 2009-12-01 16:14 . 2010-01-26 02:00 425984 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2010-01-26 39440]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2010-01-26 39440]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-01-25 3037696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 16269312]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-26 39440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-01-25 39440]
"Cm112Sound"="cm112.cpl" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-01-26 39440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [N/A]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-25 39440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2010-01-25 39440]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2010-01-25 39440]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2010-01-25 39440]
"HP Software Update"="e:\programy\HP\HP Software Update\HPWuSchd2.exe" [2010-01-25 39440]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2010-01-25 39440]
"Phase One Media Reader"="e:\programy\CAPTUR~1\DCIMImp.exe" [2010-01-25 39440]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide3"="rundll32 advpack.dll" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Games\\Wotlk\\Repair.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1.12.2009 14:06 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1.12.2009 14:06 108552]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [24.1.2010 21:01 142592]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [8.1.2010 0:51 380928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1.12.2009 14:06 297752]
R2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\drivers\p1c1394.sys [18.12.2009 17:56 23168]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.12.2009 13:52 721904]
S3 USBADVAU;USB Advance Audio Interface;c:\windows\system32\drivers\cm112.sys [5.12.2009 11:05 1312768]
.
Obsah adresáře 'Naplánované úlohy'

2010-01-26 c:\windows\Tasks\At121.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At122.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At123.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At124.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At125.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At126.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At127.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At128.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At129.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At130.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At131.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At132.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At133.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At134.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At135.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At136.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At137.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At138.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At139.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At140.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At141.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At142.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At143.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]

2010-01-26 c:\windows\Tasks\At144.job
- c:\program files\adobe\acrotray .exe [2010-01-24 22:51]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\uživatel\Data aplikací\Mozilla\Firefox\Profiles\d63ma1qq.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll
FF - component: c:\program files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-26 03:13
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(760)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-01-26 03:15:11
ComboFix-quarantined-files.txt 2010-01-26 02:15
ComboFix2.txt 2010-01-25 13:39
ComboFix3.txt 2010-01-24 22:08
ComboFix4.txt 2010-01-24 21:04

Před spuštěním: Volných bajtů: 15 227 785 216
Po spuštění: Volných bajtů: 15 203 995 648

- - End Of File - - 6792374476948EC04566BC436BED6E73

Re: Vyskakovani oken IE

Napsal: 26 led 2010 03:23
od welbern
je to cim dal tim horsi... dneska porad na pozadi behal Iexplorer a pak se mi i objevila hlaška, že cizi uživatel nainstaloval na Váš počítač Crawler toolbar... co s tim? Spustil sem hned combofix a ten crawler sem odinstaloval.

Re: Vyskakovani oken IE

Napsal: 26 led 2010 17:17
od welbern
tak sem nainstaloval sunbelt personal firewall..... nastavil sem to podle navodu tady a porad vyskakuje ze se Internet explorer snazi nekam dostat... vse sem zakazal a tak mi to jen pise ze zahazuje. Prosim mrknete na to nekdo

Antivirus uz mi po nekolikate nasel C:\Windows\system32\app_dll.dll nalezen trojsky kun SHeur2.CHWV

vzdy to odstranim a po nejake dobe je to zpatky

Re: Vyskakovani oken IE

Napsal: 26 led 2010 19:30
od Rudy
Nespustil jste CF pomocí skriptu. Bylo by to uvedeno v hlavičce logu.

Re: Vyskakovani oken IE

Napsal: 26 led 2010 19:59
od welbern
Aha omlouvam se nevim jak sem to spoustel byl sem asi moc hrr a udelal to spatne... tady je oprava

ComboFix 10-01-26.01 - uživatel 26.01.2010 19:42:09.5.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1420 [GMT 1:00]
Spuštěný z: c:\documents and settings\uživatel\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\uživatel\Plocha\CFScript.txt.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Internet Explorer\wmpscfgs.exe
c:\program files\pdfforge Toolbar
c:\program files\pdfforge Toolbar\FF\components\config.ini
c:\program files\pdfforge Toolbar\FF\components\IFBHOHelperWidgiToolbar.xpt
c:\program files\pdfforge Toolbar\FF\components\IFBHOWidgiToolbar.xpt
c:\program files\pdfforge Toolbar\FF\components\pdfforgeToolbarFF.dll
c:\program files\pdfforge Toolbar\FF\chrome.manifest
c:\program files\pdfforge Toolbar\FF\chrome\content\chevron.js
c:\program files\pdfforge Toolbar\FF\chrome\content\chevron.xul
c:\program files\pdfforge Toolbar\FF\chrome\content\login.js
c:\program files\pdfforge Toolbar\FF\chrome\content\login.xul
c:\program files\pdfforge Toolbar\FF\chrome\content\parser.js
c:\program files\pdfforge Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files\pdfforge Toolbar\FF\chrome\content\searchbox.js
c:\program files\pdfforge Toolbar\FF\chrome\content\searchbox.xul
c:\program files\pdfforge Toolbar\FF\chrome\content\widgicomm.js
c:\program files\pdfforge Toolbar\FF\chrome\content\widgihandling.js
c:\program files\pdfforge Toolbar\FF\chrome\content\widgichevron.js
c:\program files\pdfforge Toolbar\FF\chrome\content\widgilisteners.js
c:\program files\pdfforge Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files\pdfforge Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\pdfforge Toolbar\FF\chrome\content\widgiui.js
c:\program files\pdfforge Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\pdfforge Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\pdfforge Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files\pdfforge Toolbar\FF\chrome\locale\EN-US\yahoo-search.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\amazon.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\ebay.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\chevron.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\pdfc_branding.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\pdfc_branding_hover.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\pdfc_icon.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\pdfc_portal_logo.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search-button.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\searchbox.css
c:\program files\pdfforge Toolbar\FF\chrome\skin\separator.gif
c:\program files\pdfforge Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\pdfforge Toolbar\FF\install.rdf
c:\program files\pdfforge Toolbar\IE\1.1.2\config.ini
c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll.ren
c:\program files\pdfforge Toolbar\Res\amazon.gif
c:\program files\pdfforge Toolbar\Res\ebay.gif
c:\program files\pdfforge Toolbar\Res\icon_settings.gif
c:\program files\pdfforge Toolbar\Res\pdfc_branding.gif
c:\program files\pdfforge Toolbar\Res\pdfc_branding_hover.gif
c:\program files\pdfforge Toolbar\Res\pdfc_icon.gif
c:\program files\pdfforge Toolbar\Res\pdfc_portal_logo.gif
c:\program files\pdfforge Toolbar\Res\search-button-hover.gif
c:\program files\pdfforge Toolbar\Res\search-button.gif
c:\program files\pdfforge Toolbar\Res\search-chevron-hover.gif
c:\program files\pdfforge Toolbar\Res\search-chevron.gif
c:\program files\pdfforge Toolbar\Res\search_amazon.gif
c:\program files\pdfforge Toolbar\Res\search_ebay.gif
c:\program files\pdfforge Toolbar\Res\search_yahoo.gif
c:\program files\pdfforge Toolbar\Res\widgets.xml
c:\program files\pdfforge Toolbar\searchsettings .exe
c:\program files\pdfforge Toolbar\SearchSettings.dll.ren
c:\program files\pdfforge Toolbar\searchsettings.exe
c:\program files\pdfforge Toolbar\SearchSettingsRes409.dll
c:\program files\pdfforge Toolbar\sscfg.ini
c:\program files\pdfforge Toolbar\SSFF\components\IFBHOSearch.xpt
c:\program files\pdfforge Toolbar\SSFF\components\IFBHOSearchHelperEngine.xpt
c:\program files\pdfforge Toolbar\SSFF\components\IFHelperPreferences.xpt
c:\program files\pdfforge Toolbar\SSFF\components\SearchSettingsFF.dll
c:\program files\pdfforge Toolbar\SSFF\components\sscfg.ini
c:\program files\pdfforge Toolbar\SSFF\chrome.manifest
c:\program files\pdfforge Toolbar\SSFF\chrome\content\plugin.js
c:\program files\pdfforge Toolbar\SSFF\chrome\content\plugin.xul
c:\program files\pdfforge Toolbar\SSFF\chrome\content\protection.js
c:\program files\pdfforge Toolbar\SSFF\chrome\content\utils.js
c:\program files\pdfforge Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\pdfforge Toolbar\SSFF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\pdfforge Toolbar\SSFF\chrome\skin\yahoo.xml
c:\program files\pdfforge Toolbar\SSFF\install.rdf
c:\program files\pdfforge Toolbar\WidgiHelper.exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\hphmon05 .exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At121.job
c:\windows\Tasks\At122.job
c:\windows\Tasks\At123.job
c:\windows\Tasks\At124.job
c:\windows\Tasks\At125.job
c:\windows\Tasks\At126.job
c:\windows\Tasks\At127.job
c:\windows\Tasks\At128.job
c:\windows\Tasks\At129.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At130.job
c:\windows\Tasks\At131.job
c:\windows\Tasks\At132.job
c:\windows\Tasks\At133.job
c:\windows\Tasks\At134.job
c:\windows\Tasks\At135.job
c:\windows\Tasks\At136.job
c:\windows\Tasks\At137.job
c:\windows\Tasks\At138.job
c:\windows\Tasks\At139.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At140.job
c:\windows\Tasks\At141.job
c:\windows\Tasks\At142.job
c:\windows\Tasks\At143.job
c:\windows\Tasks\At144.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-26 do 2010-01-26 )))))))))))))))))))))))))))))))
.

2010-01-26 02:47 . 2008-10-31 06:09 270888 ----a-r- c:\windows\system32\drivers\SbFw.sys
2010-01-26 02:47 . 2008-06-21 03:54 65576 ----a-w- c:\windows\system32\drivers\SbFwIm.sys
2010-01-26 02:47 . 2010-01-26 02:47 -------- d-----w- c:\program files\Sunbelt Software
2010-01-25 13:29 . 2010-01-25 13:29 4 ----a-w- c:\program files\10052421.dat
2010-01-24 22:03 . 2010-01-24 22:03 -------- d-----w- C:\Nová složka
2010-01-24 20:01 . 2010-01-24 20:01 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-24 20:01 . 2010-01-25 13:19 -------- d-----w- c:\program files\Spyware Terminator
2010-01-24 17:56 . 2010-01-24 21:16 -------- d-----w- c:\program files\trend micro
2010-01-24 17:56 . 2010-01-24 19:11 -------- d-----w- C:\rsit
2010-01-24 17:09 . 2010-01-24 17:09 -------- d-----r- c:\documents and settings\NetworkService\Oblíbené položky
2010-01-24 08:51 . 2010-01-24 08:51 -------- d-----w- c:\program files\Application Updater
2010-01-24 08:51 . 2010-01-24 15:41 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-09 12:16 . 2010-01-09 12:16 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-04 12:56 . 2001-10-24 11:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-01-04 12:56 . 2008-04-14 07:51 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-01-04 12:56 . 2008-04-13 23:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-04 12:56 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-02 17:33 . 2010-01-02 17:33 -------- d-----w- c:\program files\Uniblue
2009-12-28 01:21 . 2007-03-06 04:25 196096 ----a-r- c:\windows\system32\fdco1.dll
2009-12-28 01:21 . 2007-03-06 04:27 58752 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2009-12-28 01:21 . 2007-02-01 09:44 356352 ----a-w- c:\windows\system32\nvunrm.exe
2009-12-28 01:21 . 2007-03-06 04:27 110592 ----a-r- c:\windows\system32\drivers\nvtcp.sys
2009-12-28 01:21 . 2007-03-06 04:25 9216 ----a-r- c:\windows\system32\bdco1.dll
2009-12-28 01:21 . 2007-02-01 09:44 36352 ----a-r- c:\windows\system32\nvconrm.dll
2009-12-28 01:21 . 2007-03-06 04:26 261632 ----a-r- c:\windows\system32\drivers\nvsnpu.sys
2009-12-28 01:21 . 2007-03-06 04:27 921984 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2009-12-28 01:21 . 2007-03-06 04:27 19968 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2009-12-28 01:09 . 2009-12-28 01:09 -------- d-----w- C:\SWSetup

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-26 18:40 . 2004-05-05 05:15 39440 ----a-w- c:\windows\system32\hphmon05.exe
2010-01-25 22:59 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 22:59 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2009-12-15 18:16 . 2009-12-15 18:10 19907 ----a-w- c:\windows\HPHins02.dat
2009-12-15 18:15 . 2009-12-15 18:14 -------- d-----w- c:\program files\HP
2009-12-15 18:15 . 2009-12-15 18:15 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-12-15 18:11 . 2009-12-15 18:11 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-13 14:26 . 2009-12-13 14:26 -------- d-----w- c:\program files\Phase One
2009-12-13 12:22 . 2009-12-13 12:22 -------- d-----w- c:\program files\Microsoft Works
2009-12-13 12:21 . 2009-12-12 14:57 -------- d-----w- c:\program files\MSBuild
2009-12-13 12:21 . 2009-12-13 12:21 -------- d-----w- c:\program files\Microsoft.NET
2009-12-13 12:19 . 2009-12-13 12:19 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-12-12 14:57 . 2009-12-12 14:57 -------- d-----w- c:\program files\Reference Assemblies
2009-12-12 08:41 . 2009-12-12 08:41 -------- d-----w- c:\program files\Common Files\Nikon
2009-12-11 23:00 . 2009-12-11 23:00 -------- d-----w- c:\program files\Bonjour
2009-12-11 23:00 . 2009-12-01 13:05 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 22:22 . 2009-12-11 22:22 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-08 14:07 . 2009-12-08 14:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 14:07 . 2009-12-08 14:07 -------- d-----w- c:\program files\Java
2009-12-05 16:12 . 2009-12-05 16:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-05 10:50 . 2009-12-05 10:50 -------- d-----w- c:\program files\Zoner
2009-12-05 10:05 . 2009-12-05 10:05 -------- d-----w- c:\program files\HS-04U
2009-12-05 09:46 . 2009-12-05 09:46 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-05 09:44 . 2009-12-05 09:43 -------- d-----r- c:\program files\Skype
2009-12-05 09:43 . 2009-12-05 09:43 -------- d-----w- c:\program files\Common Files\Skype
2009-12-01 16:29 . 2009-12-01 16:05 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-01 16:06 . 2009-12-01 16:06 -------- d-----w- c:\program files\microsoft frontpage
2009-12-01 16:02 . 2009-12-01 16:02 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-01 13:06 . 2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-01 13:06 . 2009-12-01 13:06 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-01 13:06 . 2009-12-01 13:06 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 -------- d-----w- c:\program files\AVG
2009-12-01 13:03 . 2009-12-01 13:03 -------- d-----w- c:\program files\CDBurnerXP
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-01 12:53 . 2009-12-01 12:53 0 ----a-w- c:\windows\nsreg.dat
2009-12-01 12:53 . 2009-12-01 12:52 -------- d-----w- c:\program files\The KMPlayer
2009-12-01 12:52 . 2009-12-01 12:52 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-01 12:40 . 2009-12-01 12:40 0 ----a-w- c:\windows\ativpsrm.bin
2009-12-01 12:37 . 2009-12-01 12:36 -------- d-----w- c:\program files\ATI Technologies
2009-12-01 12:37 . 2009-12-01 11:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-01 12:36 . 2009-12-01 11:12 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-01 11:26 . 2009-12-01 16:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-01 11:26 . 2009-12-01 16:05 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-01 11:18 . 2009-12-01 11:18 -------- d-----w- c:\program files\DIFX
2009-12-01 11:14 . 2009-12-01 11:14 -------- d-----w- c:\program files\Realtek
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\acrotray .exe
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\AVG\AVG8\avgtray .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Adobe\Updater5\adobeupdater .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Microsoft Office\Office12\groovemonitor .exe
c:\program files\Skype\Phone\skype .exe
c:\program files\Spyware Terminator\spywareterminatorupdate .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-01-24_21.03.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-26 18:38 . 2010-01-26 18:38 16384 c:\windows\Temp\Perflib_Perfdata_360.dat
+ 2009-12-15 18:13 . 2010-01-26 18:40 39440 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
- 2009-12-15 18:13 . 2010-01-24 16:33 39440 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
+ 2001-10-25 14:00 . 2010-01-25 22:59 67448 c:\windows\system32\perfc009.dat
- 2001-10-25 14:00 . 2010-01-17 16:45 67448 c:\windows\system32\perfc009.dat
+ 2008-06-21 03:54 . 2008-06-21 03:54 66600 c:\windows\system32\drivers\sbhips.sys
+ 2009-12-01 16:02 . 2008-04-14 07:52 93184 c:\windows\system32\dllcache\iexplore.exe
+ 2009-12-01 16:02 . 2008-04-14 07:52 18432 c:\windows\system32\dllcache\iedw.exe
+ 2009-12-01 16:02 . 2008-04-14 07:51 38912 c:\windows\system32\dllcache\hmmapi.dll
+ 2010-01-25 12:30 . 2010-01-25 13:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010012520100126\index.dat
+ 2010-01-25 12:30 . 2010-01-25 12:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010011820100125\index.dat
- 2009-12-01 16:14 . 2010-01-24 20:47 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-12-01 16:14 . 2010-01-26 17:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-01-25 12:47 . 2010-01-25 12:47 16384 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Internet Explorer\MSIMGSIZ.DAT
+ 2010-01-26 17:16 . 2010-01-26 17:52 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-01-26 02:47 . 2010-01-26 02:47 57344 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut4_C665E66BE8EF49DBB30B81BB5E60462C.exe
+ 2010-01-26 02:47 . 2010-01-26 02:47 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe
+ 2010-01-26 02:47 . 2010-01-26 02:47 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\ARPPRODUCTICON.exe
- 2001-10-25 14:00 . 2010-01-17 16:45 432492 c:\windows\system32\perfh009.dat
+ 2001-10-25 14:00 . 2010-01-25 22:59 432492 c:\windows\system32\perfh009.dat
+ 2010-01-26 02:47 . 2010-01-26 02:47 481280 c:\windows\Installer\249c24.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2010-01-26 39440]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-01-26 39440]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2010-01-26 39440]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-01-25 3037696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 16269312]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-26 39440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-01-26 39440]
"Cm112Sound"="cm112.cpl" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-01-26 39440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-01-26 39440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-26 39440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2010-01-26 39440]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2010-01-26 39440]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2010-01-26 39440]
"HP Software Update"="e:\programy\HP\HP Software Update\HPWuSchd2.exe" [2010-01-26 39440]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2010-01-26 39440]
"Phase One Media Reader"="e:\programy\CAPTUR~1\DCIMImp.exe" [2010-01-26 39440]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide3"="rundll32 advpack.dll" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Games\\Wotlk\\Repair.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\program files\\skype\\phone\\skype .exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1.12.2009 14:06 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1.12.2009 14:06 108552]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [26.1.2010 3:47 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [24.1.2010 21:01 142592]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [8.1.2010 0:51 380928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1.12.2009 14:06 297752]
R2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\drivers\p1c1394.sys [18.12.2009 17:56 23168]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31.10.2008 7:24 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31.10.2008 7:24 1365288]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [26.1.2010 3:47 65576]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.12.2009 13:52 721904]
S3 USBADVAU;USB Advance Audio Interface;c:\windows\system32\drivers\cm112.sys [5.12.2009 11:05 1312768]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\documents and settings\uživatel\Data aplikací\Mozilla\Firefox\Profiles\d63ma1qq.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-26 19:51
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1064)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-01-26 19:54:52
ComboFix-quarantined-files.txt 2010-01-26 18:54
ComboFix2.txt 2010-01-26 02:15
ComboFix3.txt 2010-01-25 13:39
ComboFix4.txt 2010-01-24 22:08
ComboFix5.txt 2010-01-26 18:40

Před spuštěním: Volných bajtů: 15 148 056 576
Po spuštění: Volných bajtů: 15 119 732 736

- - End Of File - - A1954F238C34FD3FCA851C77BDACDC61

Re: Vyskakovani oken IE

Napsal: 26 led 2010 20:03
od Rudy
Spusťte ještě jednou tímto skriptem:
Collect::
c:\program files\10052421.dat

Re: Vyskakovani oken IE

Napsal: 26 led 2010 20:26
od welbern
ComboFix 10-01-26.01 - uživatel 26.01.2010 20:14:07.6.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1368 [GMT 1:00]
Spuštěný z: c:\documents and settings\uživatel\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\uživatel\Plocha\CFScript.txt.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}

file zipped: c:\program files\10052421.dat
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\10052421.dat

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-26 do 2010-01-26 )))))))))))))))))))))))))))))))
.

2010-01-26 02:47 . 2008-10-31 06:09 270888 ----a-r- c:\windows\system32\drivers\SbFw.sys
2010-01-26 02:47 . 2008-06-21 03:54 65576 ----a-w- c:\windows\system32\drivers\SbFwIm.sys
2010-01-26 02:47 . 2010-01-26 02:47 -------- d-----w- c:\program files\Sunbelt Software
2010-01-24 22:03 . 2010-01-24 22:03 -------- d-----w- C:\Nová složka
2010-01-24 20:01 . 2010-01-24 20:01 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-01-24 20:01 . 2010-01-25 13:19 -------- d-----w- c:\program files\Spyware Terminator
2010-01-24 17:56 . 2010-01-24 21:16 -------- d-----w- c:\program files\trend micro
2010-01-24 17:56 . 2010-01-24 19:11 -------- d-----w- C:\rsit
2010-01-24 17:09 . 2010-01-24 17:09 -------- d-----r- c:\documents and settings\NetworkService\Oblíbené položky
2010-01-24 08:51 . 2010-01-24 08:51 -------- d-----w- c:\program files\Application Updater
2010-01-24 08:51 . 2010-01-24 15:41 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-09 12:16 . 2010-01-09 12:16 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-04 12:56 . 2001-10-24 11:25 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-01-04 12:56 . 2008-04-14 07:51 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-01-04 12:56 . 2008-04-13 23:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-01-04 12:56 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-02 17:33 . 2010-01-02 17:33 -------- d-----w- c:\program files\Uniblue
2009-12-28 01:21 . 2007-03-06 04:25 196096 ----a-r- c:\windows\system32\fdco1.dll
2009-12-28 01:21 . 2007-03-06 04:27 58752 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2009-12-28 01:21 . 2007-02-01 09:44 356352 ----a-w- c:\windows\system32\nvunrm.exe
2009-12-28 01:21 . 2007-03-06 04:27 110592 ----a-r- c:\windows\system32\drivers\nvtcp.sys
2009-12-28 01:21 . 2007-03-06 04:25 9216 ----a-r- c:\windows\system32\bdco1.dll
2009-12-28 01:21 . 2007-02-01 09:44 36352 ----a-r- c:\windows\system32\nvconrm.dll
2009-12-28 01:21 . 2007-03-06 04:26 261632 ----a-r- c:\windows\system32\drivers\nvsnpu.sys
2009-12-28 01:21 . 2007-03-06 04:27 921984 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2009-12-28 01:21 . 2007-03-06 04:27 19968 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2009-12-28 01:09 . 2009-12-28 01:09 -------- d-----w- C:\SWSetup

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-26 18:40 . 2004-05-05 05:15 39440 ----a-w- c:\windows\system32\hphmon05.exe
2010-01-25 22:59 . 2001-10-25 14:00 78052 ----a-w- c:\windows\system32\perfc005.dat
2010-01-25 22:59 . 2001-10-25 14:00 429024 ----a-w- c:\windows\system32\perfh005.dat
2009-12-15 18:16 . 2009-12-15 18:10 19907 ----a-w- c:\windows\HPHins02.dat
2009-12-15 18:15 . 2009-12-15 18:14 -------- d-----w- c:\program files\HP
2009-12-15 18:15 . 2009-12-15 18:15 43672 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2009-12-15 18:11 . 2009-12-15 18:11 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-13 14:26 . 2009-12-13 14:26 -------- d-----w- c:\program files\Phase One
2009-12-13 12:22 . 2009-12-13 12:22 -------- d-----w- c:\program files\Microsoft Works
2009-12-13 12:21 . 2009-12-12 14:57 -------- d-----w- c:\program files\MSBuild
2009-12-13 12:21 . 2009-12-13 12:21 -------- d-----w- c:\program files\Microsoft.NET
2009-12-13 12:19 . 2009-12-13 12:19 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-12-12 14:57 . 2009-12-12 14:57 -------- d-----w- c:\program files\Reference Assemblies
2009-12-12 08:41 . 2009-12-12 08:41 -------- d-----w- c:\program files\Common Files\Nikon
2009-12-11 23:00 . 2009-12-11 23:00 -------- d-----w- c:\program files\Bonjour
2009-12-11 23:00 . 2009-12-01 13:05 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-11 22:22 . 2009-12-11 22:22 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-08 14:07 . 2009-12-08 14:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-08 14:07 . 2009-12-08 14:07 -------- d-----w- c:\program files\Java
2009-12-05 16:12 . 2009-12-05 16:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-05 10:50 . 2009-12-05 10:50 -------- d-----w- c:\program files\Zoner
2009-12-05 10:05 . 2009-12-05 10:05 -------- d-----w- c:\program files\HS-04U
2009-12-05 09:46 . 2009-12-05 09:46 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-05 09:44 . 2009-12-05 09:43 -------- d-----r- c:\program files\Skype
2009-12-05 09:43 . 2009-12-05 09:43 -------- d-----w- c:\program files\Common Files\Skype
2009-12-01 16:29 . 2009-12-01 16:05 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-01 16:06 . 2009-12-01 16:06 -------- d-----w- c:\program files\microsoft frontpage
2009-12-01 16:02 . 2009-12-01 16:02 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-01 13:06 . 2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-01 13:06 . 2009-12-01 13:06 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-01 13:06 . 2009-12-01 13:06 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-01 13:06 . 2009-12-01 13:06 -------- d-----w- c:\program files\AVG
2009-12-01 13:03 . 2009-12-01 13:03 -------- d-----w- c:\program files\CDBurnerXP
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-12-01 12:56 . 2009-12-01 12:56 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-12-01 12:53 . 2009-12-01 12:53 0 ----a-w- c:\windows\nsreg.dat
2009-12-01 12:53 . 2009-12-01 12:52 -------- d-----w- c:\program files\The KMPlayer
2009-12-01 12:52 . 2009-12-01 12:52 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-01 12:40 . 2009-12-01 12:40 0 ----a-w- c:\windows\ativpsrm.bin
2009-12-01 12:37 . 2009-12-01 12:36 -------- d-----w- c:\program files\ATI Technologies
2009-12-01 12:37 . 2009-12-01 11:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-01 12:36 . 2009-12-01 11:12 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-01 11:26 . 2009-12-01 16:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-01 11:26 . 2009-12-01 16:05 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-01 11:18 . 2009-12-01 11:18 -------- d-----w- c:\program files\DIFX
2009-12-01 11:14 . 2009-12-01 11:14 -------- d-----w- c:\program files\Realtek
.

Kód: Vybrat vše

<pre>
c:\program files\Adobe\acrotray .exe
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\clistart .exe
c:\program files\AVG\AVG8\avgtray .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Adobe\Updater5\adobeupdater .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\Microsoft Office\Office12\groovemonitor .exe
c:\program files\Skype\Phone\skype .exe
c:\program files\Spyware Terminator\spywareterminatorupdate .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
((((((((((((((((((((((((((((( SnapShot@2010-01-24_21.03.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-26 18:38 . 2010-01-26 18:38 16384 c:\windows\Temp\Perflib_Perfdata_360.dat
+ 2009-12-15 18:13 . 2010-01-26 18:40 39440 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
- 2009-12-15 18:13 . 2010-01-24 16:33 39440 c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
+ 2001-10-25 14:00 . 2010-01-25 22:59 67448 c:\windows\system32\perfc009.dat
- 2001-10-25 14:00 . 2010-01-17 16:45 67448 c:\windows\system32\perfc009.dat
+ 2008-06-21 03:54 . 2008-06-21 03:54 66600 c:\windows\system32\drivers\sbhips.sys
+ 2009-12-01 16:02 . 2008-04-14 07:52 93184 c:\windows\system32\dllcache\iexplore.exe
+ 2009-12-01 16:02 . 2008-04-14 07:52 18432 c:\windows\system32\dllcache\iedw.exe
+ 2009-12-01 16:02 . 2008-04-14 07:51 38912 c:\windows\system32\dllcache\hmmapi.dll
+ 2010-01-25 12:30 . 2010-01-25 13:05 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010012520100126\index.dat
+ 2010-01-25 12:30 . 2010-01-25 12:30 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012010011820100125\index.dat
- 2009-12-01 16:14 . 2010-01-24 20:47 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-12-01 16:14 . 2010-01-26 17:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-01-25 12:47 . 2010-01-25 12:47 16384 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Internet Explorer\MSIMGSIZ.DAT
+ 2010-01-26 02:47 . 2010-01-26 02:47 57344 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut4_C665E66BE8EF49DBB30B81BB5E60462C.exe
+ 2010-01-26 02:47 . 2010-01-26 02:47 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe
+ 2010-01-26 02:47 . 2010-01-26 02:47 18718 c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\ARPPRODUCTICON.exe
- 2001-10-25 14:00 . 2010-01-17 16:45 432492 c:\windows\system32\perfh009.dat
+ 2001-10-25 14:00 . 2010-01-25 22:59 432492 c:\windows\system32\perfh009.dat
+ 2010-01-26 02:47 . 2010-01-26 02:47 481280 c:\windows\Installer\249c24.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2010-01-26 39440]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-01-26 39440]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2010-01-26 39440]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-01-25 3037696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 16269312]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-26 39440]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-01-26 39440]
"Cm112Sound"="cm112.cpl" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-01-26 39440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-01-26 39440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-26 39440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2010-01-26 39440]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2010-01-26 39440]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2010-01-26 39440]
"HP Software Update"="e:\programy\HP\HP Software Update\HPWuSchd2.exe" [2010-01-26 39440]
"HPHmon05"="c:\windows\system32\hphmon05.exe" [2010-01-26 39440]
"Phase One Media Reader"="e:\programy\CAPTUR~1\DCIMImp.exe" [2010-01-26 39440]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide3"="rundll32 advpack.dll" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-01 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Games\\Wotlk\\Repair.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\program files\\skype\\phone\\skype .exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1.12.2009 14:06 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1.12.2009 14:06 108552]
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [26.1.2010 3:47 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [24.1.2010 21:01 142592]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [8.1.2010 0:51 380928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1.12.2009 14:06 297752]
R2 P1C1394;Phase One 1394 Camera Driver;c:\windows\system32\drivers\p1c1394.sys [18.12.2009 17:56 23168]
R2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31.10.2008 7:24 95528]
R2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31.10.2008 7:24 1365288]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [26.1.2010 3:47 65576]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.12.2009 13:52 721904]
S3 USBADVAU;USB Advance Audio Interface;c:\windows\system32\drivers\cm112.sys [5.12.2009 11:05 1312768]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: mojebanka.cz\*
Trusted Zone: mojebanka.cz\*
FF - ProfilePath - c:\documents and settings\uživatel\Data aplikací\Mozilla\Firefox\Profiles\d63ma1qq.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-26 20:20
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1064)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-01-26 20:23:18
ComboFix-quarantined-files.txt 2010-01-26 19:23
ComboFix2.txt 2010-01-26 18:54
ComboFix3.txt 2010-01-26 02:15
ComboFix4.txt 2010-01-25 13:39
ComboFix5.txt 2010-01-26 19:12

Před spuštěním: Volných bajtů: 15 130 050 560
Po spuštění: Volných bajtů: 15 118 262 272

- - End Of File - - C8A4C220CBFFB2F1FF7C23237785D06A
Nahr nˇ probŘhlo ŁspŘçnŘ

Re: Vyskakovani oken IE

Napsal: 26 led 2010 21:04
od Rudy
Log již vypadá čistý. Nastala nějaká změna?

Re: Vyskakovani oken IE

Napsal: 26 led 2010 21:22
od welbern
No vypadalo to dobře, ale teď jsem dal restart počítače a už na mě zase volá firewall ze Internet Explorer se snaží někam dostat.

Re: Vyskakovani oken IE

Napsal: 26 led 2010 21:25
od Rudy
Smažte cache IE.

Re: Vyskakovani oken IE

Napsal: 26 led 2010 21:27
od welbern
Rudy píše:Smažte cache IE.
Omlouvám se ale nejsem v tom moc znalý. Kde je najdu?