ComboFix 10-03-04.05 - Věra 05.03.2010 18:36:49.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1022.640 [GMT 1:00]
Spuštěný z: c:\documents and settings\Věra\Plocha\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\1679560647.dat
c:\windows\system32\driVERs\wlufgkj.sys
c:\windows\wiaservim.log
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_wlufgkj
-------\Service_wlufgkj
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-05 do 2010-03-05 )))))))))))))))))))))))))))))))
.
2010-02-26 14:34 . 2010-02-26 14:35 -------- d-----w- c:\program files\trend micro
2010-02-26 14:34 . 2010-02-26 14:35 -------- d-----w- C:\rsit
2010-02-25 16:03 . 2010-02-25 16:11 -------- d-----w- c:\program files\D-Day
2010-02-13 17:16 . 2010-02-13 17:16 -------- d-----w- c:\program files\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 10:23 . 2010-01-23 16:36 304160 ----a-w- C:\PA207.DAT
2010-02-18 14:13 . 2010-01-23 16:03 -------- d-----w- c:\program files\ICQ7.0
2010-02-02 16:31 . 2010-02-02 16:31 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-25 16:41 . 2010-01-25 16:41 -------- d-----w- c:\program files\GoldWave
2010-01-24 07:46 . 2009-01-01 13:22 -------- d-----w- c:\program files\ICQ6Toolbar
2010-01-23 16:04 . 2007-08-29 06:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-17 17:04 . 2010-01-17 17:03 -------- d-----w- c:\program files\totalcmd
2010-01-11 10:11 . 2009-06-02 18:16 -------- d-----w- c:\program files\Mořské dobrodružství
2007-09-14 18:21 . 2007-09-14 18:20 297276 ----a-w- c:\program files\Uninst.isu
1999-07-15 22:10 . 2007-09-14 18:21 905216 ----a-w- c:\program files\revolt.exe
1999-07-15 21:10 . 2007-09-14 18:21 142680 ----a-w- c:\program files\readme.doc
1998-10-16 08:41 . 2007-09-14 18:21 322560 ------w- c:\program files\Mss32.dll
1998-10-06 11:36 . 2007-09-14 18:21 4640 ------w- c:\program files\mssb16.tsk
1998-10-06 11:36 . 2007-09-14 18:21 272384 ------w- c:\program files\mss16.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-01_17.52.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-23 16:32 . 2008-04-14 04:22 54272 c:\windows\system32\vfwwdm32.dll
- 1980-01-01 00:00 . 2009-05-29 12:33 53608 c:\windows\system32\perfc009.dat
+ 1980-01-01 00:00 . 2009-10-25 07:17 53608 c:\windows\system32\perfc009.dat
+ 1980-01-01 00:00 . 2009-10-25 07:17 63148 c:\windows\system32\perfc005.dat
- 1980-01-01 00:00 . 2009-05-29 12:33 63148 c:\windows\system32\perfc005.dat
+ 2007-09-12 14:52 . 2009-08-27 10:42 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2010-01-23 16:33 . 2008-04-13 19:46 19200 c:\windows\system32\drivers\WSTCODEC.SYS
+ 2010-01-23 16:34 . 2008-04-13 19:46 15232 c:\windows\system32\drivers\StreamIP.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 11136 c:\windows\system32\drivers\SLIP.sys
+ 2004-09-03 17:19 . 2004-09-03 17:19 54368 c:\windows\system32\drivers\prodrv06.sys
+ 2010-01-23 16:34 . 2008-04-13 19:46 10880 c:\windows\system32\drivers\NdisIP.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 85248 c:\windows\system32\drivers\NABTSFEC.sys
+ 2007-11-14 13:06 . 2007-11-14 13:06 53768 c:\windows\system32\drivers\epfwtdi.sys
+ 2007-11-14 13:06 . 2007-11-14 13:06 30728 c:\windows\system32\drivers\epfwndis.sys
+ 2007-11-14 13:06 . 2007-11-14 13:06 50696 c:\windows\system32\drivers\epfw.sys
+ 2007-11-14 13:04 . 2007-11-14 13:04 27656 c:\windows\system32\drivers\easdrv.sys
+ 2007-11-14 13:03 . 2007-11-14 13:03 33800 c:\windows\system32\drivers\eamon.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 17024 c:\windows\system32\drivers\CCDECODE.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 19200 c:\windows\system32\dllcache\wstcodec.sys
+ 2010-01-23 16:32 . 2008-04-14 04:22 54272 c:\windows\system32\dllcache\vfwwdm32.dll
+ 2010-01-23 16:34 . 2008-04-13 19:46 15232 c:\windows\system32\dllcache\streamip.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 11136 c:\windows\system32\dllcache\slip.sys
+ 2010-01-23 16:34 . 2008-04-13 19:46 10880 c:\windows\system32\dllcache\ndisip.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 85248 c:\windows\system32\dllcache\nabtsfec.sys
+ 2010-01-23 16:33 . 2008-04-13 19:46 17024 c:\windows\system32\dllcache\ccdecode.sys
+ 2009-07-01 17:54 . 2008-10-16 13:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-07-01 17:54 . 2008-04-14 03:22 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-07-01 17:54 . 2008-04-14 03:22 26112 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-07-01 17:54 . 2008-04-14 03:22 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-07-01 17:54 . 2008-04-14 03:22 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-07-01 17:54 . 2008-04-14 03:21 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-07-01 17:54 . 2008-04-14 03:22 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-07-01 17:54 . 2008-04-14 02:29 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-07-01 17:54 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-07-01 17:54 . 2008-04-14 03:22 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 1980-01-01 00:00 . 2008-04-13 18:57 14336 c:\windows\system32\dllcache\asyncmac.sys
- 2007-08-29 07:01 . 2008-09-28 18:54 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-08-29 07:01 . 2010-02-18 18:49 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-08-29 07:01 . 2010-02-18 18:49 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-08-29 07:01 . 2008-09-28 18:54 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-08-29 07:01 . 2008-09-28 18:54 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2007-08-29 07:01 . 2010-02-18 18:49 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-02-25 20:00 . 2010-02-25 20:00 22528 c:\windows\Installer\cf8ef6.msi
+ 2009-01-10 16:28 . 2009-01-10 16:28 51712 c:\windows\Installer\1df336e.msi
+ 2010-02-13 17:16 . 2010-02-13 17:16 10134 c:\windows\Installer\{DF6F459C-8B89-4F88-B63F-A2E136BB6B79}\ARPPRODUCTICON.exe
+ 2009-08-09 12:10 . 2009-08-09 12:10 10134 c:\windows\Installer\{B7E0C767-2F7F-4A9C-82F9-DBA8FE435692}\ARPPRODUCTICON.exe
- 2009-05-07 14:10 . 2009-05-07 14:10 10134 c:\windows\Installer\{B7E0C767-2F7F-4A9C-82F9-DBA8FE435692}\ARPPRODUCTICON.exe
- 2009-05-07 14:10 . 2009-05-07 14:10 40960 c:\windows\Installer\{B7E0C767-2F7F-4A9C-82F9-DBA8FE435692}\AMCap.exe_B7E0C7672F7F4A9C82F9DBA8FE435692.exe
+ 2009-08-09 12:10 . 2009-08-09 12:10 40960 c:\windows\Installer\{B7E0C767-2F7F-4A9C-82F9-DBA8FE435692}\AMCap.exe_B7E0C7672F7F4A9C82F9DBA8FE435692.exe
+ 2009-07-01 17:59 . 2009-07-01 17:59 10134 c:\windows\Installer\{6842BFA3-05A9-4C61-A73B-5493B761CACC}\callmsi.exe
+ 2010-02-13 17:16 . 2010-02-13 17:16 10134 c:\windows\Installer\{31CF6C0E-51F0-41D2-B088-A6A143C4303C}\ARPPRODUCTICON.exe
+ 2003-12-01 15:20 . 2003-12-01 15:20 4832 c:\windows\system32\drivers\sfhlp01.sys
+ 2004-07-19 14:49 . 2004-07-19 14:49 7040 c:\windows\system32\drivers\prosync1.sys
+ 2010-01-23 16:34 . 2008-04-13 19:39 5504 c:\windows\system32\drivers\MSTEE.sys
+ 2010-01-23 16:34 . 2008-04-13 19:39 5504 c:\windows\system32\dllcache\mstee.sys
+ 2006-11-20 07:04 . 2006-11-20 07:04 6656 c:\windows\system32\CoInst.dll
+ 2007-11-07 00:19 . 2007-11-07 00:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
+ 2007-11-07 00:19 . 2007-11-07 00:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-06 19:23 . 2007-11-06 19:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2009-08-09 12:05 . 2005-04-27 14:36 245408 c:\windows\system32\unicows.dll
+ 1980-01-01 00:00 . 2009-10-25 07:17 383254 c:\windows\system32\perfh009.dat
- 1980-01-01 00:00 . 2009-05-29 12:33 383254 c:\windows\system32\perfh009.dat
- 1980-01-01 00:00 . 2009-05-29 12:33 382548 c:\windows\system32\perfh005.dat
+ 1980-01-01 00:00 . 2009-10-25 07:17 382548 c:\windows\system32\perfh005.dat
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2004-09-03 17:23 . 2004-09-03 17:23 115680 c:\windows\system32\drivers\prohlp02.sys
+ 2006-11-20 06:48 . 2006-11-20 06:48 506112 c:\windows\system32\drivers\PFC027.SYS
+ 2009-07-01 17:54 . 2008-04-14 03:22 507904 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-07-01 17:54 . 2009-03-03 00:14 826368 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-07-01 17:54 . 2008-04-14 03:22 578560 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-07-01 17:54 . 2008-04-14 03:22 295936 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-07-01 17:54 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-07-01 17:54 . 2009-02-09 11:25 111104 c:\windows\system32\dllcache\cache\services.exe
+ 2009-07-01 17:54 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-07-01 17:54 . 2009-03-21 14:09 988160 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-07-01 17:54 . 2008-04-14 03:21 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2007-08-29 06:51 . 2008-04-13 16:39 142592 c:\windows\system32\dllcache\aec.sys
+ 2006-10-12 16:09 . 2006-10-12 16:09 413696 c:\windows\PixArt\Pac207\PASnap.exe
+ 2006-11-03 09:01 . 2006-11-03 09:01 319488 c:\windows\PixArt\Pac207\Monitor.exe
+ 2006-11-20 07:01 . 2006-11-20 07:01 163840 c:\windows\PixArt\Pac207\AmCap.exe
+ 2009-08-10 07:48 . 2009-08-10 07:48 792576 c:\windows\Installer\d3e7.msi
+ 2008-03-08 15:29 . 2008-03-08 15:29 892416 c:\windows\Installer\a5c99.msi
+ 2007-09-12 17:17 . 2007-09-12 17:17 431104 c:\windows\Installer\864deb.msi
+ 2009-01-11 18:05 . 2009-01-11 18:05 470528 c:\windows\Installer\421479.msi
+ 2007-09-12 15:37 . 2007-09-12 15:37 344064 c:\windows\Installer\421445.msp
+ 2007-09-19 16:34 . 2007-09-19 16:34 377344 c:\windows\Installer\41905.msi
+ 2008-11-13 16:35 . 2008-11-13 16:35 432640 c:\windows\Installer\3a1e8f.msi
+ 2009-07-01 17:59 . 2009-07-01 17:59 830464 c:\windows\Installer\1b68c.msi
+ 2008-01-23 15:51 . 2008-01-23 15:51 816640 c:\windows\Installer\189712.msp
+ 2008-07-28 14:04 . 2008-07-28 14:04 162304 c:\windows\Installer\1896fe.msp
+ 2008-11-22 11:54 . 2008-11-22 11:54 886272 c:\windows\Installer\181e92.msi
+ 2007-08-29 07:03 . 2007-08-29 07:03 265216 c:\windows\Installer\10619.msi
+ 2009-08-09 12:59 . 2009-08-09 12:59 371272 c:\windows\Installer\{D103C4BA-F905-437A-8049-DB24763BBE36}\SkypeIcon.exe
+ 2009-07-01 17:59 . 2009-07-01 17:59 140544 c:\windows\Installer\{6842BFA3-05A9-4C61-A73B-5493B761CACC}\egui.exe
+ 1980-01-01 00:00 . 2006-03-02 14:00 1356800 c:\windows\system32\webfldrs.msi
+ 2009-07-01 17:54 . 2008-04-14 03:21 1571840 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-07-01 17:54 . 2009-02-09 11:26 2191232 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-07-01 17:54 . 2009-02-10 17:09 2068224 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-07-01 17:54 . 2008-04-14 03:22 1034240 c:\windows\system32\dllcache\cache\explorer.exe
+ 2008-09-28 17:38 . 2006-03-02 14:00 1356800 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2007-05-25 10:08 . 2007-05-25 10:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2007-08-29 09:28 . 2007-08-29 09:28 6379520 c:\windows\Installer\fd80c.msi
+ 2009-04-06 15:00 . 2009-04-06 15:00 5518336 c:\windows\Installer\f98dff.msp
+ 2007-08-29 06:55 . 2007-08-29 06:55 3446272 c:\windows\Installer\f5251.msi
+ 2009-05-01 13:49 . 2009-05-01 13:49 4328960 c:\windows\Installer\c10b25.msp
+ 2008-11-12 18:09 . 2008-11-12 18:09 5788160 c:\windows\Installer\bc265b.msi
+ 2009-06-09 14:59 . 2009-06-09 14:59 1263616 c:\windows\Installer\91f189.msi
+ 2009-03-05 13:40 . 2009-03-05 13:40 6819840 c:\windows\Installer\6eba72.msp
+ 2009-08-09 12:10 . 2009-08-09 12:10 5857792 c:\windows\Installer\637b8.msi
+ 2009-01-14 14:43 . 2009-01-14 14:43 5520384 c:\windows\Installer\5d686d.msp
+ 2007-10-05 17:13 . 2007-10-05 17:13 9803264 c:\windows\Installer\5ce30.msi
+ 2010-02-13 17:16 . 2010-02-13 17:16 1189376 c:\windows\Installer\4fccbe.msi
+ 2010-02-13 17:16 . 2010-02-13 17:16 4392448 c:\windows\Installer\4fccb9.msi
+ 2008-04-24 09:22 . 2008-04-24 09:22 4275712 c:\windows\Installer\4214b7.msp
+ 2005-10-26 13:59 . 2005-10-26 13:59 2883072 c:\windows\Installer\4214ae.msp
+ 2008-11-05 13:25 . 2008-11-05 13:25 5518336 c:\windows\Installer\421439.msp
+ 2008-12-12 10:09 . 2008-12-12 10:09 5517824 c:\windows\Installer\36a16d.msp
+ 2009-08-09 12:59 . 2009-08-09 12:59 1565696 c:\windows\Installer\2f1991.msi
+ 2007-09-01 09:09 . 2007-09-01 09:09 7476736 c:\windows\Installer\2f098.msi
+ 2007-09-01 09:01 . 2007-09-01 09:01 7569920 c:\windows\Installer\2f08e.msi
+ 2008-10-05 03:12 . 2008-10-05 03:12 4784128 c:\windows\Installer\1df3374.msp
+ 2008-06-11 14:05 . 2008-06-11 14:05 9994240 c:\windows\Installer\1897f6.msp
+ 2008-11-19 08:01 . 2008-11-19 08:01 3732480 c:\windows\Installer\1897d7.msp
+ 2008-10-22 21:43 . 2008-10-22 21:43 6820352 c:\windows\Installer\1897ce.msp
+ 2008-10-22 21:48 . 2008-10-22 21:48 7672832 c:\windows\Installer\1897b9.msp
+ 2008-04-01 13:33 . 2008-04-01 13:33 5479936 c:\windows\Installer\1897a4.msp
+ 2008-01-31 09:30 . 2008-01-31 09:30 9947648 c:\windows\Installer\18978c.msp
+ 2008-01-14 15:53 . 2008-01-14 15:53 5213696 c:\windows\Installer\189770.msp
+ 2008-10-25 08:15 . 2008-10-25 08:15 6227456 c:\windows\Installer\189750.msp
+ 2008-07-08 10:27 . 2008-07-08 10:27 8436736 c:\windows\Installer\189727.msp
+ 2009-02-11 14:02 . 2009-02-11 14:02 5519872 c:\windows\Installer\14c797.msp
+ 2009-01-15 02:35 . 2009-01-15 02:35 4830720 c:\windows\Installer\1370a4.msp
+ 2007-09-02 06:49 . 2007-09-02 06:49 1256448 c:\windows\Installer\11b3b.msi
+ 2007-08-29 07:00 . 2007-08-29 07:00 3122176 c:\windows\Installer\10348a.msi
+ 2007-08-29 06:56 . 2007-08-29 06:56 5864960 c:\windows\Installer\103480.msp
+ 2007-09-12 17:18 . 2007-09-12 17:18 15256576 c:\windows\Installer\864e02.msp
+ 2008-07-30 07:50 . 2008-07-30 07:50 12506112 c:\windows\Installer\421481.msp
+ 2008-06-04 12:29 . 2008-06-04 12:29 16905728 c:\windows\Installer\42145b.msp
+ 2007-09-12 15:37 . 2007-09-12 15:37 12836864 c:\windows\Installer\421452.msp
+ 2007-09-12 15:40 . 2007-09-12 15:40 12896768 c:\windows\Installer\421446.msp
+ 2007-12-06 18:37 . 2007-12-06 18:37 19175936 c:\windows\Installer\2bd2c.msi
+ 2008-01-14 14:24 . 2008-01-14 14:24 10721280 c:\windows\Installer\18973b.msp
+ 2007-08-29 06:56 . 2007-08-29 06:56 19210240 c:\windows\Installer\103479.msp
+ 2008-02-16 14:46 . 2009-08-09 12:08 10101760 c:\windows\Downloaded Installations\{05EC26A0-5B74-47F2-9D79-5D50503CA570}\PC CIF Camer@.msi
+ 2007-07-27 07:43 . 2007-07-27 07:43 109673984 c:\windows\Installer\421423.msp
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-10-19 187192]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-10-19 15:15 1345336 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-19 1345336]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-07-12 29696]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-09-29 49152]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
"egui"="c:\program files\Smart Security\egui.exe" [2007-11-14 1410304]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-05 282624]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\c:^documents and settings^věra^nabídka start^programy^po spuštění^rncsys32.exe]
path=c:\documents and settings\Věra\Nabídka Start\Programy\Po spuštění\rncsys32.exe
backup=c:\windows\pss\rncsys32.exeStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Věra^Nabídka Start^Programy^Po spuštění^siszyd32.exe]
path=c:\documents and settings\Věra\Nabídka Start\Programy\Po spuštění\siszyd32.exe
backup=c:\windows\pss\siszyd32.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-10-27 13:21 61952 ------w- c:\windows\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2006-10-11 10:45 75304 ----a-w- c:\program files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-10-05 17:13 282624 ----a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2007-08-31 14:46 1460560 ----a-w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-09-28 11:16 185896 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\Hasbro Interactive\\RollerCoaster Tycoon\\rct.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.0\\ICQ.exe"=
"c:\\Program Files\\ICQ7.0\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 ekrn;Eset Service;c:\program files\Smart Security\ekrn.exe [14.11.2007 14:05 455936]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [1.1.2009 14:22 246520]
S0 pwjdaim;pwjdaim; [x]
S1 9ec11c71;9ec11c71;c:\windows\system32\drivers\9ec11c71.sys [26.5.2009 14:17 0]
S2 gupdate1ca18eed470808a;Služba Google Update (gupdate1ca18eed470808a);c:\program files\Google\Update\GoogleUpdate.exe [9.8.2009 13:39 133104]
S3 PAC207;PC Camer@;c:\windows\system32\drivers\PFC027.SYS [20.11.2006 7:48 506112]
.
Obsah adresáře 'Naplánované úlohy'
2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 12:38]
2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 12:38]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://
www.seznam.cz/
mStart Page = hxxp://home.sweetim.com
uInternet Connection Wizard,ShellNext = iexplore
IE: {{88EB38EF-4D2C-436D-ABD3-56B232674062} - c:\program files\ICQ7.0\ICQ.exe
TCP: {93E3A136-3973-4909-90FB-98180DA96C9C} = 208.67.220.220,208.67.222.222
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game12.zylom.com/activex/zylomgamesplayer.cab
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-ICQ - ~c:\program files\ICQ7.0\ICQ.exe
MSConfigStartUp-Toolbar_eula_launcher - c:\install\google\eula\EULALauncher.exe
AddRemove-atoll - c:\atoll\Uninstall-Atoll.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-05 18:47
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2516)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
.
**************************************************************************
.
Celkový čas: 2010-03-05 18:55:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-05 17:55
ComboFix2.txt 2009-07-01 17:55
Před spuštěním: Volných bajtů: 171 983 813 120
Po spuštění: Volných bajtů: 172 828 486 656
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - D13DB26352B6927B240B6BCB51FE35BE