log z ComboFixu-poznámka-já sem z kombofixem kdysi dávno pracoval, ako rát teda sem v té době neměl SPF(dřív Kerio Firewall) no a nepočítal jsem s tím že se spustí, já ho totiž pravděpodobně nechal puštěnej, a on začal strkat rypák kam mu nic neni, cosi když CF začal se skenem mi vyhodil, nejakou chybu že cosi zablokoval, nejakou injekci kódu nebo co ale nešlo to povolit, prostě to bloknul, CF nic neřikal, ale myslim že to bylo od něho něco

nwm no
ComboFix:
ComboFix 10-02-24.03 - patah 25.02.2010 14:55:15.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.767.473 [GMT 1:00]
Spuštěný z: d:\documents and settings\patah\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\windows\system32\twain_32.dll
d:\windows\system32\vbzlib1.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-25 do 2010-02-25 )))))))))))))))))))))))))))))))
.
2010-02-24 15:40 . 2010-02-24 15:40 -------- d-sh--w- d:\documents and settings\patah\IECompatCache
2010-02-24 15:16 . 2009-04-06 08:08 4682 ----a-w- d:\windows\system32\npptNT2.sys
2010-02-24 15:05 . 2010-02-24 15:05 -------- d-----w- d:\program files\NCsoft
2010-02-24 14:36 . 2010-01-07 15:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-02-24 14:36 . 2010-01-07 15:07 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-02-24 14:36 . 2010-02-24 14:36 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-02-24 14:31 . 2010-02-24 14:31 -------- d-----w- D:\_OTM
2010-02-23 18:36 . 2010-02-23 18:36 -------- d-----w- d:\program files\CCleaner
2010-02-23 15:09 . 2010-02-23 15:09 0 ----a-w- d:\windows\nsreg.dat
2010-02-23 13:40 . 2010-02-23 19:24 -------- d-----w- d:\program files\trend micro
2010-02-23 13:40 . 2010-02-23 13:40 -------- d-----w- D:\rsit
2010-02-22 20:44 . 2010-02-22 20:44 -------- d-sh--w- d:\windows\system32\config\systemprofile\IETldCache
2010-02-22 20:44 . 2010-02-22 20:44 -------- d-sh--w- d:\windows\system32\config\systemprofile\IECompatCache
2010-02-22 20:44 . 2010-02-22 20:44 -------- d-sh--w- d:\windows\system32\config\systemprofile\PrivacIE
2010-02-22 20:40 . 2010-02-22 20:40 95024 ----a-w- d:\windows\system32\drivers\SBREDrv.sys
2010-02-22 18:04 . 2008-10-31 06:09 270888 ----a-r- d:\windows\system32\drivers\SbFw.sys
2010-02-22 18:04 . 2008-06-21 03:54 65576 ----a-w- d:\windows\system32\drivers\SbFwIm.sys
2010-02-22 18:04 . 2010-02-22 18:04 -------- d-----w- d:\program files\Sunbelt Software
2010-02-22 17:55 . 2010-02-22 17:55 -------- d-sh--w- d:\documents and settings\patah\PrivacIE
2010-02-22 17:40 . 2010-02-22 17:40 -------- d-----w- d:\program files\SystemRequirementsLab
2010-02-22 17:40 . 2010-02-22 17:40 -------- d-----w- d:\documents and settings\patah\SystemRequirementsLab
2010-02-22 17:40 . 2010-02-22 17:40 -------- d-----w- d:\windows\Sun
2010-02-22 13:50 . 2010-02-22 13:51 -------- d-----w- d:\program files\GTASAConsole
2010-02-22 13:34 . 2010-02-22 13:34 -------- d-----w- d:\program files\Rockstar Games
2010-02-21 19:56 . 2010-02-21 19:56 -------- d-sh--w- d:\documents and settings\mama\PrivacIE
2010-02-21 09:45 . 2010-02-21 09:45 -------- d-----w- d:\program files\Windows Media Connect 2
2010-02-21 09:43 . 2010-02-21 09:43 -------- d-----w- d:\program files\Microsoft Kalkulačka+
2010-02-21 09:21 . 2010-02-21 09:21 -------- d-----w- d:\windows\l2schemas
2010-02-21 09:21 . 2010-02-21 09:21 -------- d-----w- d:\windows\system32\cs
2010-02-21 09:21 . 2010-02-21 09:21 -------- d-----w- d:\windows\system32\bits
2010-02-21 08:55 . 2010-02-21 08:55 -------- d-sh--w- d:\documents and settings\NetworkService\IETldCache
2010-02-21 08:51 . 2010-02-21 08:51 -------- d-sh--w- d:\documents and settings\patah\IETldCache
2010-02-20 18:21 . 2009-12-11 08:38 69120 -c----w- d:\windows\system32\dllcache\iecompat.dll
2010-02-20 18:20 . 2010-02-24 17:42 -------- d-----w- d:\windows\ie8updates
2010-02-20 18:20 . 2009-12-21 19:08 12800 -c----w- d:\windows\system32\dllcache\xpshims.dll
2010-02-20 18:20 . 2009-12-21 19:08 594432 -c----w- d:\windows\system32\dllcache\msfeeds.dll
2010-02-20 18:20 . 2009-12-21 19:08 55296 -c----w- d:\windows\system32\dllcache\msfeedsbs.dll
2010-02-20 18:20 . 2009-12-21 19:08 1985536 -c----w- d:\windows\system32\dllcache\iertutil.dll
2010-02-20 18:20 . 2009-12-21 19:08 246272 -c----w- d:\windows\system32\dllcache\ieproxy.dll
2010-02-20 18:20 . 2009-12-21 19:08 11070464 -c----w- d:\windows\system32\dllcache\ieframe.dll
2010-02-20 18:17 . 2010-02-21 09:21 -------- d-----w- d:\windows\system32\cs-CZ
2010-02-20 18:17 . 2010-02-20 18:20 -------- dc-h--w- d:\windows\ie8
2010-02-20 17:40 . 2010-02-21 09:19 -------- d-----w- d:\windows\ServicePackFiles
2010-02-20 17:39 . 2010-02-20 17:39 -------- d-----w- d:\program files\MSXML 4.0
2010-02-20 15:26 . 2008-06-14 17:35 272128 -c----w- d:\windows\system32\dllcache\bthport.sys
2010-02-20 15:26 . 2008-06-14 17:35 272128 ------w- d:\windows\system32\drivers\bthport.sys
2010-02-20 15:25 . 2009-12-31 16:50 353792 -c----w- d:\windows\system32\dllcache\srv.sys
2010-02-20 15:20 . 2009-11-21 16:03 471552 -c----w- d:\windows\system32\dllcache\aclayers.dll
2010-02-20 15:00 . 2009-10-15 16:32 81920 -c----w- d:\windows\system32\dllcache\fontsub.dll
2010-02-20 15:00 . 2009-10-15 16:32 119808 -c----w- d:\windows\system32\dllcache\t2embed.dll
2010-02-20 14:56 . 2009-12-04 18:22 455424 -c----w- d:\windows\system32\dllcache\mrxsmb.sys
2010-02-20 14:29 . 2008-04-21 21:15 216576 -c----w- d:\windows\system32\dllcache\wordpad.exe
2010-02-20 14:18 . 2009-08-06 18:23 274288 ----a-w- d:\windows\system32\mucltui.dll
2010-02-20 09:35 . 2007-02-20 15:04 190696 ----a-w- d:\windows\system32\NPSWF32_FlashUtil.exe
2010-02-20 09:35 . 2007-02-20 15:04 2463976 ----a-w- d:\windows\system32\NPSWF32.dll
2010-02-20 09:17 . 2010-02-20 09:17 -------- d-----w- d:\program files\bellaundben
2010-02-20 09:16 . 2010-02-22 13:41 -------- d-----w- d:\program files\phenomedia
2010-02-20 08:39 . 2010-02-20 08:55 -------- d-----w- d:\program files\World of Warcraft
2010-02-20 08:30 . 2008-04-13 18:45 26112 ----a-w- d:\windows\system32\drivers\usbser.sys
2010-02-20 08:29 . 2008-03-21 12:57 14640 ------w- d:\windows\system32\spmsgXP_2k3.dll
2010-02-20 08:28 . 2010-02-20 08:28 -------- d-----w- d:\program files\Bonjour
2010-02-20 08:18 . 2010-02-20 08:18 -------- d-----w- d:\program files\Common Files\Macrovision Shared
2010-02-19 20:13 . 2010-02-19 20:13 -------- d-----w- d:\program files\Windows Sidebar
2010-02-19 20:05 . 2010-02-19 20:15 -------- d-----w- d:\program files\Nero
2010-02-19 20:05 . 2010-02-19 20:23 -------- d-----w- d:\program files\Common Files\Nero
2010-02-19 19:51 . 2008-04-13 18:47 25856 ----a-w- d:\windows\system32\drivers\usbprint.sys
2010-02-19 19:51 . 2008-04-13 18:45 15104 ----a-w- d:\windows\system32\drivers\usbscan.sys
2010-02-19 19:51 . 2008-04-13 18:39 5504 ----a-w- d:\windows\system32\drivers\mstee.sys
2010-02-19 19:51 . 2008-04-13 18:46 10880 ----a-w- d:\windows\system32\drivers\ndisip.sys
2010-02-19 19:51 . 2008-04-13 18:46 15232 ----a-w- d:\windows\system32\drivers\streamip.sys
2010-02-19 19:51 . 2008-04-13 18:46 11136 ----a-w- d:\windows\system32\drivers\slip.sys
2010-02-19 19:51 . 2008-04-13 18:46 19200 ----a-w- d:\windows\system32\drivers\wstcodec.sys
2010-02-19 19:51 . 2008-04-13 18:46 85248 ----a-w- d:\windows\system32\drivers\nabtsfec.sys
2010-02-19 19:51 . 2008-04-13 18:46 17024 ----a-w- d:\windows\system32\drivers\ccdecode.sys
2010-02-19 19:50 . 2008-04-14 03:22 54272 ----a-w- d:\windows\system32\vfwwdm32.dll
2010-02-19 19:50 . 2010-02-19 19:50 -------- d-----w- d:\program files\Common Files\CANON
2010-02-19 19:48 . 2007-05-21 20:00 69632 ----a-w- d:\windows\system32\Spool\prtprocs\w32x86\CNMPP94.DLL
2010-02-19 19:48 . 2007-05-21 20:00 27136 ----a-w- d:\windows\system32\Spool\prtprocs\w32x86\CNMPD94.DLL
2010-02-19 19:48 . 2007-05-21 20:00 215040 ----a-w- d:\windows\system32\CNMLM94.DLL
2010-02-19 19:48 . 2010-02-19 19:48 -------- d--h--w- d:\windows\system32\CanonIJ Uninstaller Information
2010-02-19 19:48 . 2007-03-23 07:30 1400832 ----a-w- d:\windows\system32\CNC520C.DLL
2010-02-19 19:48 . 2007-03-23 07:29 98304 ----a-w- d:\windows\system32\CNC520I.DLL
2010-02-19 19:48 . 2007-03-19 01:23 200704 ----a-w- d:\windows\system32\CNC520L.DLL
2010-02-19 19:48 . 2007-03-15 05:12 188416 ----a-w- d:\windows\system32\CNC520O.DLL
2010-02-19 19:48 . 2010-02-19 19:48 -------- d--h--w- d:\program files\CanonBJ
2010-02-19 19:47 . 2010-02-19 19:52 -------- d-----w- d:\program files\Canon
2010-02-19 19:46 . 2002-07-03 10:44 53248 ----a-w- d:\windows\amcap.exe
2010-02-19 19:45 . 2004-01-05 17:34 40960 ----a-w- d:\windows\vsnpstd2.exe
2010-02-19 19:45 . 2003-10-24 10:21 53248 ----a-w- d:\windows\system32\dsnpstd2.dll
2010-02-19 19:45 . 2003-04-21 13:09 245408 ----a-w- d:\windows\system32\unicows.dll
2010-02-19 19:45 . 2004-03-22 20:31 302720 ----a-w- d:\windows\system32\drivers\snpstd2.sys
2010-02-19 19:45 . 2004-02-24 19:56 40960 ----a-w- d:\windows\system32\rsnpstd2.dll
2010-02-19 19:45 . 2004-02-17 09:56 36864 ----a-w- d:\windows\system32\vsnpstd2.dll
2010-02-19 19:45 . 2004-02-16 12:59 61440 ----a-w- d:\windows\system32\csnpstd2.dll
2010-02-19 19:45 . 2010-02-19 19:45 -------- d-----w- d:\program files\Common Files\snpstd2
2010-02-19 19:45 . 2004-02-23 14:17 20480 ----a-w- d:\windows\usnpstd2.exe
2010-02-19 19:31 . 2010-02-19 19:31 -------- d-----w- d:\program files\Secunia
2010-02-19 19:30 . 2010-02-19 19:30 -------- d-----w- d:\program files\QuickTime
2010-02-19 19:30 . 2010-02-19 19:30 -------- d-----w- d:\program files\Common Files\Apple
2010-02-19 19:29 . 2010-02-19 19:29 -------- d-----w- d:\program files\Apple Software Update
2010-02-19 19:26 . 2010-02-20 09:24 -------- d-----w- d:\program files\Common Files\Adobe
2010-02-19 19:19 . 2008-04-14 03:22 221184 ----a-w- d:\windows\system32\wmpns.dll
2010-02-19 19:12 . 2010-02-19 19:13 -------- d-----w- d:\program files\Common Files\Nokia
2010-02-19 19:12 . 2010-02-19 19:12 -------- d-----w- d:\program files\DIFX
2010-02-19 19:12 . 2008-08-26 08:26 18816 ----a-w- d:\windows\system32\drivers\pccsmcfd.sys
2010-02-19 19:12 . 2010-02-19 19:12 -------- d-----w- d:\program files\PC Connectivity Solution
2010-02-19 19:12 . 2009-12-30 10:30 7936 ----a-w- d:\windows\system32\drivers\usbser_lowerfltj.sys
2010-02-19 19:12 . 2009-12-30 10:30 7936 ----a-w- d:\windows\system32\drivers\usbser_lowerflt.sys
2010-02-19 19:12 . 2009-12-30 10:30 22016 ----a-w- d:\windows\system32\drivers\ccdcmbo.sys
2010-02-19 19:12 . 2010-01-21 13:53 18048 ----a-w- d:\windows\system32\drivers\ccdcmb.sys
2010-02-19 19:12 . 2009-12-30 10:30 660480 ----a-w- d:\windows\system32\nmwcdcocls.dll
2010-02-19 19:12 . 2010-02-23 12:55 -------- dc----w- d:\windows\system32\DRVSTORE
2010-02-19 19:12 . 2009-10-06 10:55 1112288 ----a-w- d:\windows\system32\wdfcoinstaller01007.dll
2010-02-19 19:12 . 2009-12-30 10:30 91136 ----a-w- d:\windows\system32\nmwcdcls.dll
2010-02-19 19:09 . 2010-02-20 08:30 -------- d-----w- d:\windows\system32\drivers\UMDF
2010-02-19 19:09 . 2010-02-19 19:09 -------- d-----w- d:\windows\system32\LogFiles
2010-02-19 19:08 . 2010-02-19 19:24 -------- d-----w- d:\program files\Nokia
2010-02-19 19:05 . 2010-02-19 19:05 56 ---ha-w- d:\windows\system32\ezsidmv.dat
2010-02-19 19:01 . 2010-02-19 19:06 -------- d-----w- d:\documents and settings\patah\Tracing
2010-02-19 19:01 . 2010-02-21 08:51 -------- d-----w- d:\program files\Microsoft Silverlight
2010-02-19 19:00 . 2010-02-19 19:01 -------- d-----w- d:\program files\Microsoft
2010-02-19 19:00 . 2010-02-19 19:00 -------- d-----w- d:\program files\Windows Live SkyDrive
2010-02-19 19:00 . 2010-02-19 19:01 -------- d-----w- d:\program files\Windows Live
2010-02-19 18:55 . 2010-02-19 18:55 -------- d-----w- d:\program files\Common Files\Windows Live
2010-02-19 18:49 . 2010-02-19 18:51 -------- d-----w- d:\program files\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 15:05 . 2010-02-19 16:45 -------- d--h--w- d:\program files\InstallShield Installation Information
2010-02-23 14:47 . 2006-03-02 12:00 78030 ----a-w- d:\windows\system32\perfc005.dat
2010-02-23 14:47 . 2006-03-02 12:00 429018 ----a-w- d:\windows\system32\perfh005.dat
2010-02-21 09:28 . 2010-02-19 16:24 86327 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-21 09:28 . 2010-02-19 16:24 2740 ----a-w- d:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-02-21 09:22 . 2010-02-19 16:24 8972 ----a-w- d:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-02-20 08:29 . 2010-02-20 08:29 0 ---ha-w- d:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-02-20 08:29 . 2010-02-20 08:29 0 ---ha-w- d:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-02-19 19:45 . 2010-02-19 16:44 -------- d-----w- d:\program files\Common Files\InstallShield
2010-02-19 17:59 . 2010-02-19 17:59 -------- d-----w- d:\program files\DsNET Corp
2010-02-19 17:48 . 2010-02-19 17:47 -------- d-----w- d:\program files\DAEMON Tools Lite
2010-02-19 17:48 . 2010-02-19 17:48 691696 ----a-w- d:\windows\system32\drivers\sptd.sys
2010-02-19 17:46 . 2010-02-19 17:38 -------- d-----w- d:\program files\The KMPlayer
2010-02-19 17:36 . 2010-02-19 17:36 -------- d-----w- d:\program files\Codec Pack - All In 1
2010-02-19 17:35 . 2010-02-19 17:36 737280 ----a-w- d:\windows\iun6002.exe
2010-02-19 17:17 . 2010-02-19 17:16 -------- d-----w- d:\program files\ATI Technologies
2010-02-19 17:07 . 2010-02-19 17:07 -------- d-----w- d:\program files\MSBuild
2010-02-19 17:07 . 2010-02-19 17:07 -------- d-----w- d:\program files\Reference Assemblies
2010-02-19 16:59 . 2010-02-19 16:59 -------- d-----w- d:\program files\MSXML 6.0
2010-02-19 16:36 . 2010-02-19 16:36 12288 ----a-w- d:\windows\system32\drivers\sp_prot.sys
2010-02-19 16:36 . 2010-02-19 16:36 -------- d-----w- d:\program files\System Protect
2010-02-19 16:34 . 2010-02-19 16:34 -------- d-----w- d:\program files\Alwil Software
2010-02-19 16:25 . 2010-02-19 16:25 -------- d-----w- d:\program files\microsoft frontpage
2010-02-19 16:21 . 2010-02-19 16:21 21812 ----a-w- d:\windows\system32\emptyregdb.dat
2010-02-11 18:53 . 2010-02-19 16:35 38848 ----a-w- d:\windows\system32\avastSS.scr
2010-02-11 18:53 . 2010-02-19 16:35 153184 ----a-w- d:\windows\system32\aswBoot.exe
2010-02-11 18:42 . 2010-02-19 16:35 46672 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2010-02-11 18:42 . 2010-02-19 16:35 162512 ----a-w- d:\windows\system32\drivers\aswSP.sys
2010-02-11 18:39 . 2010-02-19 16:35 23376 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2010-02-11 18:38 . 2010-02-19 16:35 100432 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2010-02-11 18:38 . 2010-02-19 16:35 94800 ----a-w- d:\windows\system32\drivers\aswmon.sys
2010-02-11 18:38 . 2010-02-19 16:35 19024 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2010-02-11 18:38 . 2010-02-19 16:35 28880 ----a-w- d:\windows\system32\drivers\aavmker4.sys
2010-01-08 22:42 . 2010-01-08 22:42 3366912 ----a-w- d:\windows\system32\GPhotos.scr
2009-12-31 16:50 . 2006-03-02 12:00 353792 ----a-w- d:\windows\system32\drivers\srv.sys
2009-12-22 05:36 . 2009-12-22 05:36 81920 ------w- d:\windows\system32\ieencode.dll
2009-12-21 19:08 . 2006-03-02 12:00 916480 ----a-w- d:\windows\system32\wininet.dll
2009-12-17 07:42 . 2010-02-19 16:20 343552 ----a-w- d:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2006-03-02 12:00 33280 ----a-w- d:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2006-03-02 12:00 455424 ----a-w- d:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:14 . 2006-03-02 12:00 1294336 ----a-w- d:\windows\system32\quartz.dll
2009-11-27 17:14 . 2004-08-17 15:49 17920 ----a-w- d:\windows\system32\msyuv.dll
2009-11-27 16:09 . 2006-03-02 12:00 28672 ----a-w- d:\windows\system32\msvidc32.dll
2009-11-27 16:09 . 2001-10-24 12:25 8704 ----a-w- d:\windows\system32\tsbyuv.dll
2009-11-27 16:09 . 2006-03-02 12:00 84992 ----a-w- d:\windows\system32\avifil32.dll
2009-11-27 16:09 . 2006-03-02 12:00 11264 ----a-w- d:\windows\system32\msrle32.dll
2009-11-27 16:09 . 2004-08-17 15:49 48128 ----a-w- d:\windows\system32\iyuv_32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- d:\documents and settings\patah\Data aplikací\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- d:\documents and settings\patah\Data aplikací\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- d:\documents and settings\patah\Data aplikací\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="d:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"SystemProtect"="d:\program files\System Protect\SysProtect_Tray.exe" [2010-02-19 1223680]
"BtTray"="d:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2009-02-27 278016]
"CanonSolutionMenu"="d:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="d:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SNPSTD2"="d:\windows\vsnpstd2.exe" [2004-01-05 40960]
d:\documents and settings\patah\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Dropbox.lnk - d:\documents and settings\patah\Data aplikacˇ\Dropbox\bin\Dropbox.exe [2009-12-31 21968784]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Documents and Settings\\patah\\Data aplikací\\Dropbox\\bin\\Dropbox.exe"=
"d:\\Program Files\\ICQ7.0\\ICQ.exe"=
"d:\\Program Files\\ICQ7.0\\aolload.exe"=
"d:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"d:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"d:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;d:\windows\system32\drivers\BtHidBus.sys [7.1.2009 23:39 20744]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [19.2.2010 17:35 162512]
R1 SbFw;SbFw;d:\windows\system32\drivers\SbFw.sys [22.2.2010 19:04 270888]
R1 sbhips;Sunbelt HIPS Driver;d:\windows\system32\drivers\sbhips.sys [21.6.2008 4:54 66600]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [19.2.2010 17:35 19024]
R2 BsMobileCS;BsMobileCS;d:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe [27.2.2009 16:40 143467]
R2 SbPF.Launcher;SbPF.Launcher;d:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [31.10.2008 7:24 95528]
R2 SPF4;Sunbelt Personal Firewall 4;d:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [31.10.2008 7:24 1365288]
R3 btnetBUs;Bluetooth PAN Bus Service;d:\windows\system32\drivers\btnetBus.sys [7.12.2008 12:44 30088]
R3 IvtBtBUs;IVT Bluetooth Bus Service;d:\windows\system32\drivers\IvtBtBus.sys [2.7.2008 14:58 26248]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;d:\windows\system32\drivers\SbFwIm.sys [22.2.2010 19:04 65576]
R3 sp_prot;System Protect Filter Driver;d:\windows\system32\drivers\sp_prot.sys [19.2.2010 17:36 12288]
S0 sptd;sptd;d:\windows\system32\drivers\sptd.sys [19.2.2010 18:48 691696]
S2 gupdate;Google Update Service (gupdate);d:\program files\Google\Update\GoogleUpdate.exe [19.2.2010 19:49 135664]
S2 SP_Service;System Protect Deletion Prevention Service;d:\program files\System Protect\SysProtect_srv.exe [19.2.2010 17:36 598528]
S3 PSI;PSI;d:\windows\system32\drivers\psi_mf.sys [17.6.2009 13:20 12648]
.
Obsah adresáře 'Naplánované úlohy'
2010-02-25 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-02-19 18:49]
2010-02-24 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2010-02-19 18:49]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
uDefault_Search_URL = hxxp://
www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 10.14.11.1:3128
uSearchAssistant = hxxp://
www.google.com/ie
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - d:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send by Bluetooth - d:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Send via &Message... - d:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
IE: {{88EB38EF-4D2C-436D-ABD3-56B232674062} - d:\program files\ICQ7.0\ICQ.exe
TCP: {371C9FDF-DD27-4F3F-B7F8-8C482C85D04F} = 193.179.148.42,0.0.0.0
FF - ProfilePath - d:\documents and settings\patah\Data aplikací\Mozilla\Firefox\Profiles\3voz1ea1.default\
FF - component: d:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Microsoft\Office Live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - d:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
d:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-25 15:04
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,de,49,30,5c,2b,a8,d6,40,bc,26,d6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,de,49,30,5c,2b,a8,d6,40,bc,26,d6,\
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(848)
d:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-02-25 15:07:56
ComboFix-quarantined-files.txt 2010-02-25 14:07
Před spuštěním: Volných bajtů: 19 031 105 536
Po spuštění: Volných bajtů: 19 012 169 728
- - End Of File - - 21712CFA61D8BA74E5238F58C9FBD5D7