tak tady to je..
ComboFix 07-12-31.4 - Uživatel 2008-01-04 11:17:32.3 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.1.1029.18.588 [GMT 1:00]
Running from: C:\Documents and Settings\Uživatel\Plocha\ComboFix.exe
Command switches used :: C:\Documents and Settings\Uživatel\Plocha\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\agjduugy.ini
C:\WINDOWS\system32\crjlakvo.ini
C:\WINDOWS\system32\fywoitgx.ini
C:\WINDOWS\system32\gbeygxrl.ini
C:\WINDOWS\system32\hlykygqe.ini
C:\WINDOWS\system32\kbhbmsii.ini
C:\WINDOWS\system32\ocgregyv.ini
C:\WINDOWS\system32\rdqtqdvg.ini
C:\WINDOWS\system32\routing.exe
C:\WINDOWS\system32\tjxsjnwv.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\agjduugy.ini
C:\WINDOWS\system32\crjlakvo.ini
C:\WINDOWS\system32\fywoitgx.ini
C:\WINDOWS\system32\gbeygxrl.ini
C:\WINDOWS\system32\hlykygqe.ini
C:\WINDOWS\system32\kbhbmsii.ini
C:\WINDOWS\system32\ocgregyv.ini
C:\WINDOWS\system32\rdqtqdvg.ini
C:\WINDOWS\system32\routing.exe
C:\WINDOWS\system32\tjxsjnwv.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ROUTING
-------\Routing
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.
2008-01-03 23:10 . 2008-01-03 23:10 45,056 --a------ C:\WINDOWS\system32\Indt2.sys
2008-01-03 23:09 . 2008-01-03 23:10 253,440 --a------ C:\WINDOWS\system32\ndt2.sys
2008-01-03 10:46 . 2008-01-03 14:52 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-03 10:46 . 2008-01-03 10:46 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 14:05 . 2008-01-02 14:06 <DIR> d-------- C:\Program Files\DAEMON Tools SearchBar
2008-01-02 13:57 . 2008-01-02 13:57 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-01-01 17:25 . 2008-01-01 17:34 <DIR> d-------- C:\Program Files\Kerio
2008-01-01 17:02 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 16:49 . 2008-01-01 16:49 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:01 . 2008-01-03 20:59 <DIR> d-------- C:\Program Files\DrWeb
2008-01-01 16:01 . 2008-01-01 16:01 77,824 --a----t- C:\WINDOWS\system32\DRWEBSP.DLL
2008-01-01 14:17 . 2008-01-01 14:17 <DIR> d--h----- C:\WINDOWS\PIF
2007-12-30 14:55 . 2008-01-01 14:17 <DIR> d-------- C:\Program Files\Crawler
2007-12-29 18:25 . 2007-12-30 09:47 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-12-29 13:45 . 2007-12-29 13:45 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-29 13:42 . 2007-12-29 13:42 <DIR> d-------- C:\Program Files\InCode Solutions
2007-12-29 11:29 . 2007-12-29 11:29 <DIR> d-------- C:\Program Files\Realtek
2007-12-28 20:09 . 1998-06-17 21:00 89,360 -ra------ C:\WINDOWS\system32\VB5DB.DLL
2007-12-28 20:09 . 2000-03-17 05:21 69,632 -ra------ C:\WINDOWS\system32\xmltok.dll
2007-12-28 20:09 . 2000-03-17 05:21 36,864 -ra------ C:\WINDOWS\system32\xmlparse.dll
2007-12-28 20:09 . 2002-04-24 09:43 35,840 -ra------ C:\WINDOWS\system32\comdlg32.oca
2007-12-28 20:09 . 2002-04-09 14:23 29,184 -ra------ C:\WINDOWS\system32\MSINET.oca
2007-12-28 20:09 . 2002-10-17 07:35 26,096 -ra------ C:\WINDOWS\system32\xmlinst.exe
2007-12-27 21:09 . 2007-12-31 11:16 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-27 21:09 . 2007-12-27 21:09 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-27 10:33 . 2007-12-27 18:17 56 --a------ C:\WINDOWS\system32\S-1-5-21-0094400A
2007-12-26 17:06 . 2007-12-26 18:15 <DIR> d-------- C:\audiograbber
2007-12-26 16:49 . 2007-12-26 18:15 34 --a------ C:\WINDOWS\cdplayer.ini
2007-12-26 16:27 . 2001-03-23 16:29 880,912 --a------ C:\WINDOWS\WM8EUTIL.exe
2007-12-25 21:18 . 2007-12-25 21:18 24 ---hs---- C:\WINDOWS\SCEC2B874.tmp
2007-12-25 10:21 . 2007-12-25 10:22 <DIR> d-------- C:\Program Files\Labtec
2007-12-25 10:21 . 2007-12-25 10:22 6,205 --a------ C:\WINDOWS\system\Kbdvx32a.vxd
2007-12-23 23:35 . 2007-12-23 23:35 5,154,304 --a------ C:\WindowsDefender.msi
2007-12-23 19:40 . 2007-10-11 00:50 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-23 19:40 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-23 19:40 . 2007-07-01 04:36 1,024,000 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-23 19:40 . 2007-10-11 00:50 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-23 19:40 . 2007-10-11 00:50 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-23 19:40 . 2007-10-11 00:50 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-23 19:40 . 2007-10-11 00:50 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-23 19:40 . 2007-10-11 00:50 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-23 19:40 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-23 18:21 . 2007-12-23 18:22 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-12-23 18:21 . 2007-12-23 18:22 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-12-18 05:00 . 2007-12-18 05:00 <DIR> d-------- C:\Program Files\Alwil Software
2007-12-18 05:00 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2007-12-18 05:00 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-18 05:00 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-18 05:00 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-12-18 05:00 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-18 05:00 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-18 05:00 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-18 05:00 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-18 05:00 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-16 16:17 . 2007-12-16 16:17 <DIR> d-------- C:\Program Files\DSPlayer_v0.889_lite
2007-12-15 18:36 . 2007-12-15 18:36 <DIR> d-------- C:\Program Files\ffdshow
2007-12-15 18:36 . 2007-12-15 18:36 36,734 --a------ C:\WINDOWS\system32\OggDSuninst.exe
2007-12-15 18:36 . 2007-12-15 18:36 33,533 --a------ C:\WINDOWS\system32\CoreVorbis-uninstall.exe
2007-12-15 18:35 . 2007-12-15 18:35 <DIR> d-------- C:\Program Files\XviD
2007-12-15 18:35 . 2007-12-15 18:35 <DIR> d-------- C:\Program Files\Morgan
2007-12-15 18:35 . 2007-12-15 18:35 <DIR> d-------- C:\Program Files\AC3Filter
2007-12-15 18:34 . 2007-12-15 18:34 848 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-15 18:26 . 2007-12-15 18:26 56 -r-hs---- C:\WINDOWS\system32\9E765C5CCF.sys
2007-12-09 21:29 . 2007-12-09 21:29 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-12-08 14:58 . 2007-12-08 14:58 <DIR> d-------- C:\Program Files\MP3Dancer
2007-12-08 14:58 . 2007-12-08 14:58 <DIR> d-------- C:\Program Files\Common Files\Totem Shared
2007-12-07 22:59 . 2007-12-09 21:31 <DIR> d-------- C:\Program Files\uTorrent
2007-12-07 20:05 . 2004-08-17 14:49 23,552 --a------ C:\WINDOWS\system32\OLD73.tmp
2007-12-07 20:05 . 2004-08-17 15:49 4,096 --a------ C:\WINDOWS\system32\OLD3D.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 19:57 --------- d-----w C:\Program Files\DivX
2008-01-02 18:01 --------- d-----w C:\Program Files\ICQToolbar
2008-01-02 12:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-30 08:47 --------- d-----w C:\Program Files\Bonjour
2007-12-24 21:56 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-18 05:55 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-15 17:24 --------- d-----w C:\Program Files\Codec Pack - All In 1
2007-12-15 17:23 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-12 11:20 --------- d-----w C:\Program Files\Seznam DVD
2007-12-01 21:51 --------- d-----w C:\Program Files\Winamp
2007-11-19 16:30 --------- d-----w C:\Program Files\Common Files\DirectX
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 18:50 --------- d-----w C:\Program Files\Common Files\Micropro
2007-11-07 18:34 --------- d-----w C:\Program Files\Micropro
2007-11-06 16:06 --------- d-----w C:\Program Files\CyberLink
2007-11-06 15:32 10,368 ----a-w C:\WINDOWS\system32\drivers\pfc.sys
2007-11-06 15:32 --------- d-----w C:\Program Files\Common Files\ACD Systems
2007-11-06 15:32 --------- d-----w C:\Program Files\ACD Systems
2007-10-22 16:15 491,520 ----a-w C:\WINDOWS\WebIE.dll
2007-10-22 16:15 45,056 ----a-w C:\WINDOWS\TRNOEH.DLL
2007-10-22 16:15 356,352 ----a-w C:\WINDOWS\TrnOutl.dll
2007-10-22 16:15 294,912 ----a-w C:\WINDOWS\TrnWord.dll
2007-10-22 16:15 26,624 ----a-w C:\WINDOWS\OETRN.EXE
2007-10-22 16:15 200,704 ----a-w C:\WINDOWS\TRNOET.DLL
2007-10-22 16:14 516,096 ----a-w C:\WINDOWS\UN32.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-01-01_17.09.57.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-03 09:46:33 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2008-01-03 09:46:33 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-01-03 09:46:33 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2005-09-26 10:05:06 286,720 ----a-w C:\WINDOWS\system32\drivers\fwdrv.sys
+ 2005-09-26 10:05:06 81,920 ----a-w C:\WINDOWS\system32\drivers\khips.sys
- 2007-12-31 16:58:12 82,476 ----a-w C:\WINDOWS\system32\perfc005.dat
+ 2008-01-01 17:26:32 82,476 ----a-w C:\WINDOWS\system32\perfc005.dat
- 2007-12-31 16:58:12 71,046 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-01 17:26:32 71,046 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-12-31 16:58:12 435,922 ----a-w C:\WINDOWS\system32\perfh005.dat
+ 2008-01-01 17:26:32 435,922 ----a-w C:\WINDOWS\system32\perfh005.dat
- 2007-12-31 16:58:12 438,960 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-01 17:26:32 438,960 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-04 10:23:00 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_664.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 16:49 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-12-07 15:08 21686568]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" [2005-02-26 01:28 212992]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-10 08:44 94208]
"WEBTRAN"="" []
"OEXPRESS"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35 90112]
"AGRSMMSG"="AGRSMMSG.exe" [2002-09-25 11:44 87751 C:\WINDOWS\AGRSMMSG.exe]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"SNPSTD2"="C:\WINDOWS\vsnpstd2.exe" [2004-06-10 11:54 286720]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 22:57 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 11:09 49152]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"FLMOFFICE4DMOUSE"="C:\Program Files\Labtec\Desktop\V5.1\moffice.exe" [2007-12-25 10:21 958464]
"OFFICEKB"="C:\Program Files\Labtec\Keyboard\V5.1\kbdap32a.exe" [2007-12-25 10:22 387584]
"NWEReboot"="" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-17 16:49 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe blrun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrA"=2 (0x2)
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2005-09-26 11:05]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2005-09-26 11:05]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-04 00:04]
R3 snpstd2;VideoCAM Look;C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-07-28 11:49]
S1 wfcxacap;WinFast TV PCI Audio Capture Driver;C:\WINDOWS\system32\DRIVERS\wfcxacap.sys [2006-10-23 09:05]
S2 wfcxatun;WinFast TV Analog Tuner Driver;C:\WINDOWS\system32\drivers\wfcxatun.sys [2006-10-23 09:09]
S2 WFCXVCAP;WinFast TV Video Capture Driver;C:\WINDOWS\system32\drivers\wfcxvcap.sys [2006-10-23 09:09]
S3 wfcxdtun;WinFast DTV BDA Tuner/Demod Driver;C:\WINDOWS\system32\drivers\wfcxdtun.sys [2006-10-23 09:08]
S3 wfcxtcap;WinFast DTV BDA Transport Stream Capture Driver;C:\WINDOWS\system32\drivers\wfcxtcap.sys [2006-10-23 09:07]
S3 wfcxxbar;WinFast TV Crossbar Driver;C:\WINDOWS\system32\drivers\wfcxxbar.sys [2006-10-23 09:08]
S3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS []
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-04 11:24:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-04 11:27:09 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-04 10:27:02
C:\qoobox\ComboFix2.txt 2008-01-03 10:20:53
C:\qoobox\ComboFix3.txt 2008-01-01 16:10:12
.
2007-12-31 00:05:39 --- E O F ---
---------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:12, on 4.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Labtec\Desktop\V5.1\moffice.exe
C:\Program Files\Labtec\Keyboard\V5.1\kbdap32a.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Labtec\Keyboard\V5.1\MOUSE32A.EXE
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Documents and Settings\Uživatel\Plocha\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Desktop\V5.1\moffice.exe
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Labtec\Keyboard\V5.1\kbdap32a.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://www.msi.com.tw
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resour ... se4009.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) -
http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/pub/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5D08A94-8330-4AE2-BEB5-0E4D477B28FC}: NameServer = 81.19.33.2,81.19.34.2
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 11353 bytes