V pohodě.
Při nabíhání Win se mě zobrazuje hláška:
Vyberte operační systém, který chcete spustit a je tam na výběr:
Microsoft windows Recovery Console
do not select this (ladící program byl aktivován)
Microsoft Windows XP Professional
hned se to ale spustí do Windows.
ComboFix 11-02-07.02 - Michal 10.02.2011 12:28:07.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.2046.1649 [GMT 1:00]
Spuštěný z: c:\documents and settings\Michal\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Michal\Plocha\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: ZoneAlarm Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Rezidentní štít AV je zapnutý
FILE ::
"c:\docume~1\MIC~1\LOCALS~1\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\2b1dc_xp.exe"
"c:\docume~1\MIC~1\LOCALS~1\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\cbacab.exe"
"c:\docume~1\MIC~1\LOCALS~1\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\setup.dll"
"c:\documents and settings\Michal\Local Settings\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\2b1dc_xp.exe"
"c:\documents and settings\Michal\Local Settings\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\cbacab.exe"
"c:\documents and settings\Michal\Local Settings\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\setup.dll,"
"c:\windows\iun6002.exe"
"c:\windows\Setup1.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\Crawler\Toolbar\ctbr.dll
c:\program files\Crawler
c:\program files\Crawler\firefox\components\xcomm.dll
c:\program files\Crawler\firefox\components\xplugin.xpt
c:\program files\Crawler\firefox\components\xshared.dll
c:\program files\Crawler\firefox\components\xshared.xpt
c:\program files\Crawler\firefox\components\xsupport.dll
c:\program files\Crawler\firefox\components\xsupport.xpt
c:\program files\Crawler\firefox\chrome.manifest
c:\program files\Crawler\firefox\chrome\common.jar
c:\program files\Crawler\firefox\install.ini
c:\program files\Crawler\firefox\install.rdf
c:\program files\Crawler\Toolbar\adrkeys.dat
c:\program files\Crawler\Toolbar\common_ff.dat
c:\program files\Crawler\Toolbar\confirm.dat
c:\program files\Crawler\Toolbar\ctbcomm.dll
c:\program files\Crawler\Toolbar\ctbr.dll
c:\program files\Crawler\Toolbar\CTConf.dat
c:\program files\Crawler\Toolbar\CTipsDef.dll
c:\program files\Crawler\Toolbar\CToolbar.exe
c:\program files\Crawler\Toolbar\CUpdate.exe
c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
c:\program files\Crawler\Toolbar\firefox\components\xplugin.xpt
c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
c:\program files\Crawler\Toolbar\firefox\components\xshared.xpt
c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
c:\program files\Crawler\Toolbar\firefox\components\xsupport.xpt
c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
c:\program files\Crawler\Toolbar\firefox\chrome.manifest
c:\program files\Crawler\Toolbar\firefox\chrome\common.jar
c:\program files\Crawler\Toolbar\firefox\chrome\stwsg.jar
c:\program files\Crawler\Toolbar\firefox\install.ini
c:\program files\Crawler\Toolbar\firefox\install.rdf
c:\program files\Crawler\Toolbar\firefox\stwsg_ff.ini
c:\program files\Crawler\Toolbar\Languages\STWSG_CS.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_DA.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_DE.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_EN.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_ES.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_FF.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_FR.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_IT.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_NL.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_PT-BR.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_PT.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_RU.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_SR.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_CS.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_DA.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_DE.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_EN.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_ES.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_FR.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_IT.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_NL.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_PL.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_PT-BR.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_PT.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_RU.cab
c:\program files\Crawler\Toolbar\lookfor.dat
c:\program files\Crawler\Toolbar\majorse.dat
c:\program files\Crawler\Toolbar\rootmenu.dat
c:\program files\Crawler\Toolbar\services.dat
c:\program files\Crawler\Toolbar\STWSG_FF.dat
c:\program files\Crawler\Toolbar\STWSGLanguageAct\info.ini
c:\program files\Crawler\Toolbar\STWSGLanguageAct\language.ini
c:\program files\Crawler\Toolbar\TBR5LanguageAct\info.ini
c:\program files\Crawler\Toolbar\TBR5LanguageAct\language.ini
c:\program files\Crawler\Toolbar\Update\domains.cab
c:\program files\Crawler\Toolbar\WebSecurityGuard.dll
c:\program files\Crawler\Toolbar\WSGData\ap_S-1-5-21-57989841-776561741-725345543-1003.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_000.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_000_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_001.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_001_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_002.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_002_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_003.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_003_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_004.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_004_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_005.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_005_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_006.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_006_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_007.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_007_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_008.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_008_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_009.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_009_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_010.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_010_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_011.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_011_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_012.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_012_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_013.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_013_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_014.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_014_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_015.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_015_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_016.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_016_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_017.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_017_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_018.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_018_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_019.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_019_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_020.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_020_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_021.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_021_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_022.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_022_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_023.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_023_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_024.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_024_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_025.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_025_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_026.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_026_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_027.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_027_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_028.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_028_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_029.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_029_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_030.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_030_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_031.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_031_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_032.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_032_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_033.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_033_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_034.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_034_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_035.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_035_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_036.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_036_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_037.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_037_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_038.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_038_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_039.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_039_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_040.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_040_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\index.dat
c:\program files\Crawler\Toolbar\WSGData\domains\TopList.dat
c:\program files\Crawler\Toolbar\WSGData\ud_S-1-5-21-57989841-776561741-725345543-1003.dat
c:\program files\Crawler\Toolbar\WSGData\uv_S-1-5-21-57989841-776561741-725345543-1003.dat
c:\program files\Crawler\Toolbar\WSGData\wfilter.dat
c:\windows\iun6002.exe
c:\windows\Setup1.exe
c:\docume~1\MIC~1\LOCALS~1\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\2b1dc_xp.exe . . . . nemohl být smazán
c:\docume~1\MIC~1\LOCALS~1\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\cbacab.exe . . . . nemohl být smazán
c:\docume~1\MIC~1\LOCALS~1\Temp\9E91A7D6-843E0470-19FF4A1E-E8A29C8F\setup.dll . . . . nemohl být smazán
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-10 do 2011-02-10 )))))))))))))))))))))))))))))))
.
2011-02-07 20:05 . 2011-02-07 20:05 -------- d-----w- c:\documents and settings\Michal\Local Settings\Data aplikací\ESET
2011-02-07 20:05 . 2011-02-07 20:05 -------- d-----w- c:\documents and settings\Michal\Data aplikací\ESET
2011-02-07 20:05 . 2011-02-07 20:05 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\ESET
2011-02-07 20:04 . 2011-02-07 20:04 -------- d-----w- c:\program files\ESET
2011-02-07 20:04 . 2011-02-07 20:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2011-02-05 11:51 . 2011-02-05 11:51 -------- d-----w- c:\documents and settings\Michal\Data aplikací\Malwarebytes
2011-02-05 11:51 . 2011-02-05 11:51 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-05 11:51 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-05 11:51 . 2011-02-05 11:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-05 11:51 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-05 11:39 . 2011-02-05 11:39 -------- d-----w- c:\documents and settings\Michal\DoctorWeb
2011-02-05 11:31 . 2011-02-05 11:32 135032 ----a-w- c:\windows\system32\drivers\dwprot.sys
2011-02-04 23:07 . 2010-11-16 16:45 69120 ----a-w- c:\windows\system32\zlcomm.dll
2011-02-04 23:07 . 2010-11-16 16:45 104448 ----a-w- c:\windows\system32\zlcommdb.dll
2011-02-04 23:07 . 2011-02-04 23:07 -------- d-----w- c:\windows\system32\ZoneLabs
2011-02-04 23:07 . 2010-11-16 16:45 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2011-02-04 23:03 . 2011-02-04 23:03 -------- d-----w- c:\program files\Zone Labs
2011-02-04 23:03 . 2011-02-10 11:35 -------- d-----w- c:\windows\Internet Logs
2011-02-03 17:01 . 2011-02-03 17:01 -------- d-----w- c:\windows\system32\wbem\Repository
2011-01-31 16:29 . 2011-01-31 16:29 -------- d-----w- c:\windows\Sun
2011-01-31 15:50 . 2011-01-31 15:50 -------- d-----w- c:\program files\Epocware
2011-01-31 13:20 . 2004-08-03 22:08 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2011-01-31 13:20 . 2004-08-03 22:08 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2011-01-31 13:20 . 2008-11-07 17:55 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2011-01-31 13:18 . 2011-01-31 13:21 -------- d-----w- c:\documents and settings\Michal\Data aplikací\PC Suite
2011-01-31 13:18 . 2011-01-31 13:21 -------- d-----w- c:\documents and settings\Michal\Data aplikací\Nokia
2011-01-31 13:18 . 2011-01-31 13:18 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PC Suite
2011-01-31 13:18 . 2011-01-31 13:18 -------- d-----w- c:\program files\Common Files\PCSuite
2011-01-31 13:15 . 2011-01-31 13:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Installations
2011-01-31 12:21 . 2011-01-31 12:38 -------- d-----w- c:\program files\EA GAMES
2011-01-31 12:21 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-31 12:00 . 2011-02-09 12:52 -------- d-----w- c:\program files\WinClamAVShield
2011-01-31 11:52 . 2011-01-31 11:52 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2011-01-31 11:52 . 2011-02-10 11:29 -------- d-----w- c:\documents and settings\Michal\Data aplikací\Spyware Terminator
2011-01-31 11:52 . 2011-02-09 12:52 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Spyware Terminator
2011-01-31 11:52 . 2011-02-03 16:10 -------- d-----w- c:\program files\Spyware Terminator
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 14:04 . 2010-12-21 14:04 141264 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-12-21 14:04 . 2010-12-21 14:04 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-12-21 12:47 . 2010-12-21 12:47 33120 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2010-12-21 12:47 . 2010-12-21 12:47 134000 ----a-w- c:\windows\system32\drivers\epfw.sys
2010-12-15 16:35 . 2010-12-15 16:35 73216 ----a-w- c:\windows\ST6UNST.EXE
2010-12-15 16:07 . 2010-12-15 16:07 82380 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-06-02 385024]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2011-01-31 2183680]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-11-16 1043968]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2219184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-9-8 5185536]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 22:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-06-28 23:43 1626112 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-05-27 02:47 16208384 ------r- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
R0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys [5.2.2011 12:31 135032]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [21.12.2010 15:04 115008]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [31.1.2011 12:52 142592]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [12.1.2011 16:41 810144]
R2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [8.9.2010 10:41 237056]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [8.9.2010 10:45 1034752]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [8.9.2010 10:44 484352]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [27.12.2010 20:39 11520]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-11-22 13:18 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
TCP: {7D51E5DC-CA5E-4D67-9869-E87415687C3B} = 62.84.128.6,62.84.132.6
FF - ProfilePath - c:\documents and settings\Michal\Data aplikací\Mozilla\Firefox\Profiles\mfjf0wej.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.centrum.czFF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: PC Sync 2 Synchronisation Extension:
bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
AddRemove-CToolbar_UNINSTALL - c:\progra~1\Crawler\Toolbar\CToolbar.exe
AddRemove-Easy CD-DA Extractor 7.0 - c:\windows\iun6002.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-10 12:34
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Photodex\ProShowProducer\ScsiAccess.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-02-10 12:37:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-10 11:37
ComboFix2.txt 2011-02-08 13:41
Před spuštěním: Volných bajtů: 222 743 265 280
Po spuštění: Volných bajtů: 222 704 422 912
- - End Of File - - 3760C3A7E6F6C89058206077A7A2A7B8