ComboFix 09-10-28.08 - Prdka 30.10.2009 7:46.13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.608 [GMT 1:00]
Spuštěný z: c:\documents and settings\Danielka\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Danielka\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 091029-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Data aplikacˇ\tiryzu.vbs
c:\documents and settings\All Users\Data aplikacˇ\urunoxi.vbs
c:\documents and settings\Danielka\Data aplikacˇ\gyza.bat
c:\documents and settings\Danielka\Data aplikacˇ\imir.bat
c:\documents and settings\Danielka\Data aplikacˇ\ohuhatyxo.vbs
c:\documents and settings\Danielka\Data aplikacˇ\otagudov.inf
c:\documents and settings\Danielka\Data aplikacˇ\vafyfad.vbs
c:\documents and settings\Danielka\Local Settings\Data aplikacˇ\edenuzijov.bat
c:\documents and settings\Danielka\Local Settings\Data aplikacˇ\kydepavag.inf
c:\documents and settings\Danielka\Local Settings\Data aplikacˇ\ycidolejy.bat
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-09-28 do 2009-10-30 )))))))))))))))))))))))))))))))
.
2009-10-29 17:51 . 2009-10-29 21:29 944160 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-29 17:03 . 2009-10-29 17:03 -------- d-----w- c:\documents and settings\Danielka\DoctorWeb
2009-10-29 14:12 . 2009-10-29 14:12 -------- d-----w- c:\windows\Sun
2009-10-29 14:12 . 2009-10-29 14:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-29 14:12 . 2009-10-29 14:12 -------- d-----w- c:\program files\Java
2009-10-28 19:42 . 2009-10-28 19:42 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-28 16:51 . 2009-10-28 16:51 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-10-28 16:25 . 2009-10-28 16:25 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-10-28 16:24 . 2009-02-04 17:24 -------- d-----w- c:\documents and settings\Administrator\Bluetooth Software
2009-10-28 16:24 . 2009-02-08 21:26 -------- d-----r- c:\documents and settings\Administrator\Dokumenty
2009-10-28 16:24 . 2009-02-04 17:37 -------- d--h--r- c:\documents and settings\Administrator\Data aplikací
2009-10-28 16:23 . 2009-02-08 20:47 -------- d-----r- c:\documents and settings\Administrator\Oblíbené položky
2009-10-28 16:23 . 2009-02-04 17:29 -------- d-----w- c:\documents and settings\Administrator\Plocha
2009-10-28 16:23 . 2009-02-04 15:00 -------- d--h--w- c:\documents and settings\Administrator\Okolní tiskárny
2009-10-28 16:23 . 2009-02-04 15:00 -------- d--h--w- c:\documents and settings\Administrator\Okolní síť
2009-10-28 16:23 . 2009-02-04 15:00 -------- d-----r- c:\documents and settings\Administrator\Nabídka Start
2009-10-28 16:23 . 2009-02-04 14:06 -------- d--h--w- c:\documents and settings\Administrator\Šablony
2009-10-28 16:23 . 2009-10-28 16:51 -------- d-----w- c:\documents and settings\Administrator
2009-10-28 15:17 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-28 15:17 . 2009-10-28 15:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-28 15:17 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-28 15:09 . 2009-10-28 15:09 -------- d-----w- C:\_OTM
2009-10-28 15:04 . 2009-06-10 06:42 389632 ----a-w- C:\OTM.exe
2009-10-28 13:42 . 2009-10-28 13:42 -------- d-----w- c:\program files\Trend Micro
2009-10-28 13:21 . 2008-04-14 12:00 152576 -c--a-w- c:\windows\system32\dllcache\bnts.dll
2009-10-28 13:16 . 2009-10-28 13:16 -------- d-----w- c:\program files\NKProds
2009-10-28 13:08 . 2009-10-28 13:12 -------- d-----w- c:\program files\Cookie Killer
2009-10-28 10:47 . 2009-10-28 10:47 -------- d-----w- c:\program files\CCleaner
2009-10-28 10:35 . 2009-08-17 17:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-28 10:35 . 2009-08-17 17:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-28 10:34 . 2009-08-17 17:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-28 10:34 . 2009-08-17 17:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-28 10:34 . 2009-08-17 17:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-28 10:34 . 2009-08-17 17:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-28 10:34 . 2009-08-17 17:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-28 10:34 . 2009-08-17 17:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-28 10:34 . 2009-08-17 17:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-28 10:34 . 2009-10-28 10:34 -------- d-----w- c:\program files\Alwil Software
2009-10-27 20:48 . 2009-10-27 20:48 -------- d-----w- c:\program files\ESET
2009-10-27 16:28 . 2009-10-27 16:28 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-27 16:22 . 2009-10-27 19:54 -------- d-----w- c:\program files\Google
2009-10-23 12:47 . 2009-10-23 12:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-23 11:16 . 2009-10-28 10:16 -------- d-----w- c:\program files\Avast4
2009-10-10 18:19 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-10-10 18:19 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-10-10 18:19 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-10-10 18:19 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-10-10 18:19 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-10-10 18:19 . 2009-10-10 18:19 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-03 17:16 . 2009-10-03 17:16 -------- d-----w- c:\windows\Hewlett-Packard
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-30 06:41 . 2009-10-29 17:27 529496 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-10-30 06:41 . 2009-02-04 14:53 83098 ----a-w- c:\windows\system32\perfc005.dat
2009-10-30 06:41 . 2009-02-04 14:53 438402 ----a-w- c:\windows\system32\perfh005.dat
2009-10-29 21:29 . 2009-10-29 17:51 12140 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-28 19:49 . 2009-04-25 23:20 -------- d-----w- c:\program files\Lavasoft
2009-10-28 19:41 . 2009-04-25 23:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-03 17:16 . 2009-05-05 17:47 -------- d-----w- c:\program files\HP
2009-09-11 14:19 . 2009-02-04 14:53 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:05 . 2009-02-04 14:53 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:58 . 2009-02-04 14:53 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:02 . 2009-02-04 14:53 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 17:24 . 2009-02-04 14:07 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2009-02-04 14:07 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2009-02-04 14:07 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2008-10-16 12:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2009-02-04 14:07 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2009-02-04 14:53 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2009-02-04 14:07 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2009-02-04 14:07 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2009-02-04 14:53 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:29 . 2008-04-14 08:06 2147328 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:29 . 2008-04-14 08:06 2025984 ------w- c:\windows\system32\ntkrnlpa.exe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\All Users\Data aplikacˇ ----
---- Directory of c:\documents and settings\Danielka\Data aplikacˇ ----
---- Directory of c:\documents and settings\Danielka\Local Settings\Data aplikacˇ ----
((((((((((((((((((((((((((((( SnapShot@2009-10-28_17.11.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-30 06:37 . 2009-10-30 06:37 16384 c:\windows\temp\Perflib_Perfdata_574.dat
+ 2009-10-29 13:21 . 2009-10-29 13:21 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-10-28 19:42 . 2009-10-28 19:42 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2009-10-28 19:42 . 2009-10-28 19:42 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-10-28 19:42 . 2009-10-28 19:42 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
- 2009-02-04 14:53 . 2009-10-28 17:01 441772 c:\windows\system32\perfh009.dat
+ 2009-02-04 14:53 . 2009-10-29 09:00 441772 c:\windows\system32\perfh009.dat
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-10-29 14:12 . 2009-10-29 14:12 149280 c:\windows\system32\javaws.exe
+ 2009-10-29 14:12 . 2009-10-29 14:12 145184 c:\windows\system32\javaw.exe
+ 2009-10-29 14:12 . 2009-10-29 14:12 145184 c:\windows\system32\java.exe
+ 2009-10-19 16:27 . 2009-10-19 16:27 401008 c:\windows\Downloaded Program Files\fslauncher.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-10-28 19:42 . 2009-10-28 19:42 1583616 c:\windows\Installer\5ed144.msi
+ 2009-10-29 14:12 . 2009-10-29 14:12 1757696 c:\windows\Installer\121672b.msi
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-12 21898024]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-12 2000112]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-12-04 114688]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-12-17 622592]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-29 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-09-18 16855040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-2-4 376832]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [28.10.2009 11:34 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12.10.2009 21:24 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.10.2009 21:24 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28.10.2009 11:34 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [4.2.2009 18:54 55136]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [17.4.2007 20:09 11032]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [4.2.2009 18:22 10752]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [4.2.2009 10:41 38400]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12.10.2009 21:24 7408]
S2 gupdate1ca5721be0c60e0;Google Update Service (gupdate1ca5721be0c60e0);c:\program files\Google\Update\GoogleUpdate.exe [27.10.2009 17:22 133104]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\axtmvflt.sys [27.4.2009 18:41 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\axtmvmdm.sys [27.4.2009 18:41 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\axtmvprt.sys [27.4.2009 18:41 38784]
S3 fsssvc;Windows Live Zabezpečení rodiny;c:\program files\Windows Live\Family Safety\fsssvc.exe [8.12.2008 17:01 533344]
S3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [13.1.2009 12:31 25216]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2009-07-17 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 12:49]
2009-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 16:22]
2009-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-27 16:22]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.czIE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos-be ... canner.cab.
**************************************************************************
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Celkový čas: 2009-10-30 7:59
ComboFix-quarantined-files.txt 2009-10-30 06:58
ComboFix2.txt 2009-10-29 17:39
ComboFix3.txt 2009-10-29 15:04
ComboFix4.txt 2009-10-29 09:32
ComboFix5.txt 2009-10-30 06:44
Před spuštěním: Volných bajtů: 72 059 154 432
Po spuštění: Volných bajtů: 72 023 228 416
- - End Of File - - 0D11DA8DA00F7F9B63D7394BDC1ED9C2