ComboFix 10-01-24.05 - miro 25.01.2010 16:15:37.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.511.199 [GMT 1:00]
Spuštěný z: c:\documents and settings\miro\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100125-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Eset NOD32 Antivirus 2.51 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Plocha\Continue Titan Poker setup.lnk
c:\program files\ICQ6.5\ICQLRun.exe
c:\windows\system32\Data
c:\windows\system32\Data\CT0060W.DAT
c:\windows\system32\Data\CTP0060W.DAT
c:\windows\system32\Data\CTP0061W.DAT
c:\windows\system32\Data\CTP0100W.DAT
c:\windows\system32\Data\CTP0101W.DAT
c:\windows\system32\Data\CTP0102W.DAT
c:\windows\system32\Data\CTP0103W.DAT
c:\windows\system32\Data\CTP0105W.DAT
c:\windows\system32\Data\CTP0170W.DAT
c:\windows\system32\Data\CTP017AW.DAT
c:\windows\system32\Data\CTP017BW.DAT
c:\windows\system32\Data\CTP017CW.DAT
c:\windows\system32\Data\CTP017DW.DAT
c:\windows\system32\Data\CTP017EW.DAT
c:\windows\system32\Data\CTP017FW.DAT
c:\windows\system32\Data\CTP017GW.DAT
c:\windows\system32\Data\CTP017HW.DAT
c:\windows\system32\Data\CTP0221W.DAT
c:\windows\system32\Data\CTP0222W.DAT
c:\windows\system32\Data\CTP0226W.DAT
c:\windows\system32\Data\CTP0228W.DAT
c:\windows\system32\Data\CTP1140W.DAT
c:\windows\system32\Data\CTP4620W.DAT
c:\windows\system32\Data\CTP4670W.DAT
c:\windows\system32\Data\CTP4760W.DAT
c:\windows\system32\Data\CTP4780W.DAT
c:\windows\system32\Data\CTP4790W.DAT
c:\windows\system32\Data\CTP4830W.DAT
c:\windows\system32\Data\CTP4831W.DAT
c:\windows\system32\Data\CTP4832W.DAT
c:\windows\system32\Data\CTP4840W.DAT
c:\windows\system32\Data\CTP4850W.DAT
c:\windows\system32\Data\CTP4870W.DAT
c:\windows\system32\Data\CTP4871W.DAT
c:\windows\system32\Data\CTP4872W.DAT
c:\windows\system32\Data\CTP4875W.DAT
c:\windows\system32\Data\CTP4890W.DAT
c:\windows\system32\Data\CTP4891W.DAT
c:\windows\system32\Data\CTP4893W.DAT
c:\windows\system32\Data\CTPDXW.DAT
c:\windows\system32\Data\CTPM002W.DAT
c:\windows\system32\Data\CTSBASW.DAT
c:\windows\unins000.dat
c:\windows\unins000.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-25 do 2010-01-25 )))))))))))))))))))))))))))))))
.
2010-01-25 15:04 . 2010-01-25 15:03 390144 ----a-w- c:\windows\system32\CF6616.exe
2010-01-13 16:12 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-11 07:57 . 2010-01-11 07:57 -------- d-----w- c:\windows\Hewlett-Packard
2010-01-04 15:24 . 2010-01-04 19:31 -------- d-----w- c:\documents and settings\All Users\Data aplikac
2010-01-04 15:18 . 2005-12-12 05:57 204881 ----a-w- c:\windows\system32\DiskIO.dll
2010-01-04 15:18 . 2005-12-12 05:57 155721 ----a-w- c:\windows\system32\RALMain.dll
2010-01-04 15:18 . 2005-07-12 12:25 401408 ----a-w- c:\windows\system32\pvmjpg30.dll
2010-01-04 15:18 . 2002-09-24 09:12 466624 ----a-w- c:\windows\system32\LTRPR13n.DLL
2010-01-04 15:18 . 2002-09-24 09:12 304816 ----a-w- c:\windows\system32\LTRIO13N.DLL
2010-01-04 15:18 . 2002-09-24 09:12 194248 ----a-w- c:\windows\system32\LTRFD13n.DLL
2010-01-04 15:18 . 2002-09-24 09:12 934576 ----a-w- c:\windows\system32\ltr13n.dll
2010-01-04 15:14 . 2010-01-04 15:14 -------- d-----w- c:\program files\SmartSound Software
2010-01-04 15:13 . 2003-11-25 04:02 138752 ----a-w- c:\windows\system32\mase32.dll
2010-01-04 15:13 . 2003-11-25 04:02 57856 ----a-w- c:\windows\system32\masd32.dll
2010-01-04 15:13 . 2003-11-25 04:02 27648 ----a-w- c:\windows\system32\ma32.dll
2010-01-04 15:13 . 2003-11-25 04:02 196096 ----a-w- c:\windows\system32\macd32.dll
2010-01-04 15:13 . 2003-11-25 04:02 136192 ----a-w- c:\windows\system32\mamc32.dll
2010-01-04 15:12 . 2003-03-26 05:58 487424 ----a-w- c:\windows\system32\MSVCP70.DLL
2010-01-04 15:12 . 2004-01-23 15:44 49152 ----a-w- c:\windows\system32\PCLEGetGuid.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 15:27 . 2009-10-19 13:10 -------- d-----w- c:\program files\ICQ6.5
2010-01-25 15:12 . 2003-12-06 14:04 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000005-00001102-00000002-80671102}.dat
2010-01-25 15:12 . 2003-12-06 14:04 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000005-00001102-00000002-80671102}.dat
2010-01-19 07:27 . 2004-12-25 16:22 -------- d-----w- c:\program files\Avast4
2010-01-11 07:57 . 2003-12-24 18:33 -------- d-----w- c:\program files\Hewlett-Packard
2010-01-11 07:57 . 2007-12-30 15:18 -------- d-----w- c:\program files\HP
2010-01-05 18:51 . 2009-12-25 09:32 -------- d-----w- c:\program files\StepMania
2010-01-04 15:15 . 2008-01-06 11:54 -------- d-----w- c:\program files\Pinnacle
2010-01-04 15:15 . 2003-12-06 13:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-27 12:52 . 2006-10-20 10:18 -------- d-----w- c:\program files\Warcraft III
2009-12-26 22:08 . 2005-06-11 19:37 -------- d-----w- c:\program files\Steam
2009-12-21 19:08 . 2004-08-23 18:35 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-10 14:58 . 2003-04-16 12:00 82484 ----a-w- c:\windows\system32\perfc005.dat
2009-12-10 14:58 . 2003-04-16 12:00 437886 ----a-w- c:\windows\system32\perfh005.dat
2009-11-24 23:54 . 2004-12-25 16:22 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2004-12-25 16:22 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2004-12-25 16:22 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2008-05-10 09:02 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-05-10 09:02 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2004-12-25 16:22 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2005-03-06 12:10 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2004-12-25 16:22 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2004-12-25 16:22 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2009-11-21 16:03 . 2003-04-16 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2007-08-21 08:01 . 2007-08-21 08:01 3006511 ----a-w- c:\program files\ie6.rar
2006-07-09 13:31 . 2006-07-09 13:31 398537 ----a-w- c:\program files\army.zip
2006-06-30 10:06 . 2006-06-30 10:07 2643424 ----a-w- c:\program files\Age2upA.exe
2006-06-11 07:34 . 2006-06-11 07:52 1494483 ----a-w- c:\program files\War3.exe
2006-05-17 19:35 . 2006-05-17 19:34 10673375 ----a-w- c:\program files\nentczst.exe
2005-11-19 15:21 . 2005-11-19 15:21 210879 ----a-w- c:\program files\Anti-Blaxx.rar
2007-06-01 13:33 . 2006-01-18 14:46 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-06-01 13:33 . 2006-01-18 14:46 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-06-01 13:33 . 2006-01-18 14:46 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2004-12-24 11:41 . 2004-12-24 11:41 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-24 09:53 . 2009-06-15 12:48 172023840 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-11 6729728]
"nwiz"="nwiz.exe" [2005-05-11 1519616]
"CTHelper"="CTHELPER.EXE" [2003-06-09 28672]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"avast!"="c:\progra~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-05-11 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-05-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-09-14 180269]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Corel MEDIA FOLDERS INDEXER 8.LNK]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Corel MEDIA FOLDERS INDEXER 8.LNK
backup=c:\windows\pss\Corel MEDIA FOLDERS INDEXER 8.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^DSLMON.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\DSLMON.lnk
backup=c:\windows\pss\DSLMON.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Last.fm Helper.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Last.fm Helper.lnk
backup=c:\windows\pss\Last.fm Helper.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Motorola Desktop Suite mRouter Config.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Motorola Desktop Suite mRouter Config.lnk
backup=c:\windows\pss\Motorola Desktop Suite mRouter Config.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Motorola Desktop Suite.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Motorola Desktop Suite.lnk
backup=c:\windows\pss\Motorola Desktop Suite.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^msmsgs.exe]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\msmsgs.exe
backup=c:\windows\pss\msmsgs.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^miro^Nabídka Start^Programy^Po spuštění^PowerReg Scheduler V3.exe]
path=c:\documents and settings\miro\Nabídka Start\Programy\Po spuštění\PowerReg Scheduler V3.exe
backup=c:\windows\pss\PowerReg Scheduler V3.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^miro^Nabídka Start^Programy^Po spuštění^Product Registration.lnk]
path=c:\documents and settings\miro\Nabídka Start\Programy\Po spuštění\Product Registration.lnk
backup=c:\windows\pss\Product Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^miro^Nabídka Start^Programy^Po spuštění^Sid Registration.lnk]
path=c:\documents and settings\miro\Nabídka Start\Programy\Po spuštění\Sid Registration.lnk
backup=c:\windows\pss\Sid Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^miro^Nabídka Start^Programy^Po spuštění^Xfire.lnk]
path=c:\documents and settings\miro\Nabídka Start\Programy\Po spuštění\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
2005-05-18 14:08 208896 ----a-w- c:\program files\Anti-Blaxx\Anti-Blaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 03:22 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2005-11-08 22:00 128920 ----a-w- c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2004-06-04 10:38 286720 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 08:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia Tray Application]
2002-10-22 07:52 598016 ----a-w- c:\program files\Common Files\Nokia\NCLTools\NclTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2005-05-05 16:13 98304 ----a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ServiceLayer]
2002-10-16 07:43 69632 ----a-w- c:\program files\Common Files\Nokia\Services\ServiceLayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2004-09-28 19:26 32881 ----a-w- c:\program files\Java\j2re1.4.2_06\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\Steam\\SteamApps\\maekoboss\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Steam\\SteamApps\\maekoboss\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\miro\\Dokumenty\\ICQ Lite\\245327306\\Hrdlo_285390787\\WoW-1.4.0-enUS-downloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\maekoboss\\condition zero\\hl.exe"=
"c:\\Program Files\\DC\\DCPlusPlus.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_06\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\apache\\mysql\\bin\\mysqld-nt.exe"=
"c:\\Program Files\\Steam\\SteamApps\\maekoboss\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Steam\\SteamApps\\maekoboss\\dedicated server\\hlds.exe"=
"c:\\Program Files\\Steam\\SteamApps\\maekoboss\\source dedicated server\\srcds.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Warcraft III\\war3.exe"=
"c:\\Program Files\\GOTCHA!\\Gotcha.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\gumboy demo\\GumboyCrazyAdventuresDemo2.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [2.12.2004 21:42 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [10.5.2008 10:02 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [10.5.2008 10:02 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [6.8.2008 8:10 222456]
R3 Tetris;Tetris driver;c:\windows\system32\drivers\Tetris.sys [17.3.2006 14:18 48928]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.11.2005 14:53 664064]
S0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [2.12.2004 21:42 140800]
S2 PHPGeekUtil;PHPGeekUtil;c:\apache\Apache.exe [25.1.2002 5:30 20480]
S3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\drivers\BTCamDrv.sys [3.2.2006 13:24 219136]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [8.12.2007 17:37 13352]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\drivers\k510bus.sys [6.5.2007 11:57 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\drivers\k510mdfl.sys [6.5.2007 11:57 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\drivers\k510mdm.sys [6.5.2007 11:57 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\k510mgmt.sys [6.5.2007 11:57 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\drivers\k510obex.sys [6.5.2007 11:57 83344]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2.8.2005 22:10 32512]
S3 w550obex;Sony Ericsson W550 USB WMC OBEX Interface Drivers;c:\windows\system32\DRIVERS\w550obex.sys --> c:\windows\system32\DRIVERS\w550obex.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.google.cz/
uSearchURL,(Default) = hxxp://
www.google.com/keyword/%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: &Přelož do češtiny - c:\program files\Seznam Bezpecny Internet\SBI.dll/5034
IE: &Search
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Hledej v &Seznamu - c:\program files\Seznam Bezpecny Internet\SBI.dll/5033
IE: Hledej v Seznam &Fulltextu - c:\program files\Seznam Bezpecny Internet\SBI.dll/5035
IE: Zobrazit originál
IE: {{572BF76C-9EFF-4e1e-93DE-72EF1E91B3DF} - {DB7FBFE3-82CB-49E0-9C41-39C2A80B4966} - c:\progra~1\EUROTR~1\e2003i.dll
DPF: BSC Applet Security - hxxps://ra.internetbanka.cz/ra31/bin/aplsec-99.99.99.99.cab
DPF: BSC Applet Utilities - hxxps://ra.internetbanka.cz/ra31/bin/aplutil-99.99.99.99.cab
DPF: BSC Business Objects - hxxps://ra.internetbanka.cz/ra31/bin/business-99.99.99.99.cab
DPF: BSC Java Components Library - hxxps://ra.internetbanka.cz/ra31/bin/jcl-99.99.99.99.cab
DPF: BSC Text Utilities - hxxps://ra.internetbanka.cz/ra31/bin/text-99.99.99.99.cab
DPF: BSC Utilities - hxxps://ra.internetbanka.cz/ra31/bin/util-99.99.99.99.cab
DPF: GEMINI IBS 32 GEMB Applet Security - hxxps://ib.internetbanka.cz/ibs31/bin/IBS32-GEMB-aplsec-3.3.0.0.cab
DPF: GEMINI IBS 32 GEMB Applet Utilities - hxxps://ib.internetbanka.cz/ibs31/bin/IBS32-GEMB-aplutil-99.99.99.99.cab
DPF: IAIK Java Cryptography Extension - hxxps://ra.internetbanka.cz/ra31/bin/IAIK-99.99.99.99.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\miro\Data aplikací\Mozilla\Firefox\Profiles\0tp5jlzw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Czech Soccer Manager 2002 Final Edition - c:\program files\Czech Soccer Manager 2002 Final Edition\DeIsL1.isu
AddRemove-Heroes of Might and Magic II - c:\program files\Heroes2\DeIsL1.isu
AddRemove-Invision 2.0 Build 3515 - e:\mirc__~1\KOPIE-~1\MIRC__~1\UNWISE.EXE
AddRemove-KnightShift - c:\progra~1\KNIGHT~1\UNWISE.EXE
AddRemove-Revenant - c:\program files\Revenant\Uninst.isu
AddRemove-Trefík - podpora databází - c:\program files\DeIsL1.isu
AddRemove-Vampire - c:\program files\Vampire The Masquerade - Redemption\Vampire.isu
AddRemove-{FBC2DD8F-A7DE-4CA3-B793-E50A7BA25AF0}_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-25 16:28
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-2025429265-616249376-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Celkový čas: 2010-01-25 16:38:24
ComboFix-quarantined-files.txt 2010-01-25 15:38
ComboFix2.txt 2009-06-14 19:25
ComboFix3.txt 2009-06-14 11:38
Před spuštěním: 7 074 516 992
Po spuštění: 7 658 254 336
Current=2 Default=2 Failed=3 LastKnownGood=1 Sets=1,2,3,4
- - End Of File - - 4E14D4E8936C161E7B2F47B2AF694EF7
RootRepeal
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/01/26 21:22
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name:
Image Path:
Address: 0xF8511000 Size: 98304 File Visible: No Signed: -
Status: -
Name:
Image Path:
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: 00000051
Image Path: \Driver\00000051
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF616A000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8BCC000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB9674000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b26b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b2574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b2a52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b214c
#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf85c7c22
#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf85c7f9a
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b264e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b208c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b20f0
#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf85c8064
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b276e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b272e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf61b28ae
Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x83395bf8 Size: 15
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CLOSE]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_READ]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_WRITE]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_QUERY_EA]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SET_EA]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CLEANUP]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_POWER]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: dtscsi, IRP_MJ_PNP]
Process: System Address: 0x830c20d8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_EA]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_EA]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLEANUP]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_SECURITY]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_SET_QUOTA]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x830b05f8 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CLOSE]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_READ]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_WRITE]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_EA]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_EA]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SHUTDOWN]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CLEANUP]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_SECURITY]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_POWER]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_SET_QUOTA]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: atapi, IRP_MJ_PNP]
Process: System Address: 0x831d4f00 Size: 99
Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_READ]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_POWER]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Disk, IRP_MJ_PNP]
Process: System Address: 0x83395e30 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x833de530 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8312fdb8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8312fdb8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8312fdb8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8312fdb8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8312fdb8 Size: 15
Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8312fdb8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_CREATE]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_CLOSE]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_POWER]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: xmasscsi, IRP_MJ_PNP]
Process: System Address: 0x833950e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ]
Process: System Address: 0x831e8a64 Size: 11
Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA]
Process: System Address: 0x82ff20e8 Size: 15
Object: Hidden Code [Driver: Srv, IRP_MJ_READ]
Process: System Address: 0x8280b82c Size: 11
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x8299f674 Size: 11
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x83044298 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_CREATE]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_CLOSE]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_READ]
Process: System Address: 0x830a30b4 Size: 11
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_WRITE]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_CLEANUP]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Npfsȅఄ扏济comdlg32.dll, IRP_MJ_SET_SECURITY]
Process: System Address: 0x830ab6a0 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_CREATE]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_CLOSE]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_READ]
Process: System Address: 0x82fea25c Size: 11
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_WRITE]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_CLEANUP]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Msfsȅ敓Ѐ, IRP_MJ_SET_SECURITY]
Process: System Address: 0x82fea0e8 Size: 15
Object: Hidden Code [Driver: Fs_Rec, IRP_MJ_READ]
Process: System Address: 0x82fca094 Size: 11
Object: Hidden Code [Driver: Mup, IRP_MJ_CREATE]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_CLOSE]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_READ]
Process: System Address: 0x83020254 Size: 11
Object: Hidden Code [Driver: Mup, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_SHUTDOWN]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_CLEANUP]
Process: System Address: 0x830f4708 Size: 15
Object: Hidden Code [Driver: Mup, IRP_MJ_PNP]
Process: System Address: 0x830f4708 Size: 15
==EOF==
VirusTotal píše že soubor nelze nalézt