Po skriptu to restartovalo a pri vypisu LOGu sem mozna omylem zavrel nejaky notepad text ktery se mi automaticky vzdycky pri startu spousti (vytaci me to ale doufam ze to neovlivnilo ten vypis natolik ze se to pak seklo), je v nich uvedeny nejaky klic z registru... delalo to uz pred tim, resp . po nejakym comboscanu.
Horsi je ze to vypsalo log, zavrelo se okno Comba a pocitac dale nereagoval byl zasekly. Takze sem zkusil znova tvrdy restart ze to napodruhe nabootuje, nepovedlo se. Prejel sem na druhy "WINDOWS.O" abych mohl poslat alespon tento LOG. Na dalsi scany MWAV a HJT bych musel jit do nouzoveho rezimu coz by nemelo vadit? A pokud se podari poslu dalsi vyžádané logy MWAV a HJT.
c:\windows\system32\jcsb.new 10920 bytes
c:\windows\system32\jcsball.dat 30671 bytes
c:\windows\system32\jerror.dat 2186 bytes
Koukam do logu ze ty soubory tam porad sou...

mel sem za to ze je combo smazne...
Soubor wininet.dll přijatý 2009.02.26 18:20:15 (CET)
Současný stav: Čekejte ... Ve frontě Čekání Testování Dokončeno NENALEZENO ZASTAVENO
Výsledek: 0/39 (0%)
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.0.0.101 2009.02.26 -
AhnLab-V3 5.0.0.2 2009.02.26 -
AntiVir 7.9.0.93 2009.02.26 -
Authentium 5.1.0.4 2009.02.26 -
Avast 4.8.1335.0 2009.02.25 -
AVG 8.0.0.237 2009.02.26 -
BitDefender 7.2 2009.02.26 -
CAT-QuickHeal 10.00 2009.02.26 -
ClamAV 0.94.1 2009.02.26 -
Comodo 986 2009.02.20 -
DrWeb 4.44.0.09170 2009.02.26 -
eSafe 7.0.17.0 2009.02.26 -
eTrust-Vet 31.6.6375 2009.02.26 -
F-Prot 4.4.4.56 2009.02.26 -
F-Secure 8.0.14470.0 2009.02.26 -
Fortinet 3.117.0.0 2009.02.26 -
GData 19 2009.02.26 -
Ikarus T3.1.1.45.0 2009.02.26 -
K7AntiVirus 7.10.648 2009.02.26 -
Kaspersky 7.0.0.125 2009.02.26 -
McAfee 5536 2009.02.25 -
McAfee+Artemis 5536 2009.02.25 -
Microsoft 1.4306 2009.02.26 -
NOD32 3893 2009.02.26 -
Norman 6.00.06 2009.02.26 -
nProtect 2009.1.8.0 2009.02.26 -
Panda 10.0.0.10 2009.02.26 -
PCTools 4.4.2.0 2009.02.26 -
Prevx1 V2 2009.02.26 -
Rising 21.18.32.00 2009.02.26 -
SecureWeb-Gateway 6.0.0 2009.02.26 -
Sophos 4.39.0 2009.02.26 -
Sunbelt 3.2.1858.2 2009.02.25 -
Symantec 10 2009.02.26 -
TheHacker 6.3.2.5.265 2009.02.25 -
TrendMicro 8.700.0.1004 2009.02.26 -
VBA32 3.12.10.0 2009.02.26 -
ViRobot 2009.2.26.1625 2009.02.26 -
VirusBuster 4.5.11.0 2009.02.26 -
Rozšiřující informace
File size: 826368 bytes
ComboFix 09-02-24.02 - Petr 2009-02-26 17:38:20.8 - NTFSx86Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.2046.1274 [GMT 1:00]
Spuštěný z: c:\documents and settings\Petr\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Petr\Plocha\CFScript.txt
* Vytvořen nový Bod Obnovení
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
FILE ::
c:\program files\Apple Software Update\SoftwareUpdate.exe
c:\windows\system32\dllcache\OLD10.tmp
c:\windows\system32\dllcache\OLD11.tmp
c:\windows\system32\dllcache\OLD13.tmp
c:\windows\system32\dllcache\OLD14.tmp
c:\windows\system32\dllcache\OLD15.tmp
c:\windows\system32\dllcache\OLD16.tmp
c:\windows\system32\dllcache\OLD17.tmp
c:\windows\system32\dllcache\OLD18.tmp
c:\windows\system32\dllcache\OLD19.tmp
c:\windows\system32\dllcache\OLD1A.tmp
c:\windows\system32\dllcache\OLD1B.tmp
c:\windows\system32\dllcache\OLD1C.tmp
c:\windows\system32\dllcache\OLD1D.tmp
c:\windows\system32\dllcache\OLD1E.tmp
c:\windows\system32\dllcache\OLD1F.tmp
c:\windows\system32\dllcache\OLD2.tmp
c:\windows\system32\dllcache\OLD20.tmp
c:\windows\system32\dllcache\OLD21.tmp
c:\windows\system32\dllcache\OLD22.tmp
c:\windows\system32\dllcache\OLD23.tmp
c:\windows\system32\dllcache\OLD24.tmp
c:\windows\system32\dllcache\OLD25.tmp
c:\windows\system32\dllcache\OLD26.tmp
c:\windows\system32\dllcache\OLD27.tmp
c:\windows\system32\dllcache\OLD28.tmp
c:\windows\system32\dllcache\OLD29.tmp
c:\windows\system32\dllcache\OLD2A.tmp
c:\windows\system32\dllcache\OLD2B.tmp
c:\windows\system32\dllcache\OLD2C.tmp
c:\windows\system32\dllcache\OLD2D.tmp
c:\windows\system32\dllcache\OLD2F.tmp
c:\windows\system32\dllcache\OLD30.tmp
c:\windows\system32\dllcache\OLD32.tmp
c:\windows\system32\dllcache\OLD33.tmp
c:\windows\system32\dllcache\OLD35.tmp
c:\windows\system32\dllcache\OLD36.tmp
c:\windows\system32\dllcache\OLD38.tmp
c:\windows\system32\dllcache\OLD39.tmp
c:\windows\system32\dllcache\OLD3B.tmp
c:\windows\system32\dllcache\OLD4E2.tmp
c:\windows\system32\dllcache\OLD4E6.tmp
c:\windows\system32\dllcache\OLD4EA.tmp
c:\windows\system32\dllcache\OLD4EE.tmp
c:\windows\system32\dllcache\OLD4F2.tmp
c:\windows\system32\dllcache\OLD89A.tmp
c:\windows\system32\dllcache\OLD89E.tmp
c:\windows\system32\dllcache\OLD8A2.tmp
c:\windows\system32\dllcache\OLD8A6.tmp
c:\windows\system32\dllcache\OLDB.tmp
c:\windows\system32\dllcache\OLDE.tmp
c:\windows\system32\drivers\aswFsBlk.sys
c:\windows\system32\drivers\aswSP.sys
c:\windows\system32\flvDX.dll
c:\windows\system32\jcsb.new
c:\windows\system32\jcsball.dat
c:\windows\system32\jerror.dat
c:\windows\system32\msfDX.dll
c:\windows\system32\Smab0.dll
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\TMP17.tmp
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Data aplikací\Kaspersky Lab
c:\documents and settings\All Users\Data aplikací\Kaspersky Lab\AVP.7.125_10.08_20.08_670.SRV.exception.log
c:\documents and settings\All Users\Data aplikací\Kaspersky Lab\AVP.7.125_10.08_20.43_384.ALL.exception.log
c:\program files\Apple Software Update\SoftwareUpdate.exe
c:\windows\OPTIONS\CABS\_desktop.ini
c:\windows\system32\dllcache\OLD10.tmp
c:\windows\system32\dllcache\OLD11.tmp
c:\windows\system32\dllcache\OLD13.tmp
c:\windows\system32\dllcache\OLD14.tmp
c:\windows\system32\dllcache\OLD15.tmp
c:\windows\system32\dllcache\OLD16.tmp
c:\windows\system32\dllcache\OLD17.tmp
c:\windows\system32\dllcache\OLD18.tmp
c:\windows\system32\dllcache\OLD19.tmp
c:\windows\system32\dllcache\OLD1A.tmp
c:\windows\system32\dllcache\OLD1B.tmp
c:\windows\system32\dllcache\OLD1C.tmp
c:\windows\system32\dllcache\OLD1D.tmp
c:\windows\system32\dllcache\OLD1E.tmp
c:\windows\system32\dllcache\OLD1F.tmp
c:\windows\system32\dllcache\OLD2.tmp
c:\windows\system32\dllcache\OLD20.tmp
c:\windows\system32\dllcache\OLD21.tmp
c:\windows\system32\dllcache\OLD22.tmp
c:\windows\system32\dllcache\OLD23.tmp
c:\windows\system32\dllcache\OLD24.tmp
c:\windows\system32\dllcache\OLD25.tmp
c:\windows\system32\dllcache\OLD26.tmp
c:\windows\system32\dllcache\OLD27.tmp
c:\windows\system32\dllcache\OLD28.tmp
c:\windows\system32\dllcache\OLD29.tmp
c:\windows\system32\dllcache\OLD2A.tmp
c:\windows\system32\dllcache\OLD2B.tmp
c:\windows\system32\dllcache\OLD2C.tmp
c:\windows\system32\dllcache\OLD2D.tmp
c:\windows\system32\dllcache\OLD2F.tmp
c:\windows\system32\dllcache\OLD30.tmp
c:\windows\system32\dllcache\OLD32.tmp
c:\windows\system32\dllcache\OLD33.tmp
c:\windows\system32\dllcache\OLD35.tmp
c:\windows\system32\dllcache\OLD36.tmp
c:\windows\system32\dllcache\OLD38.tmp
c:\windows\system32\dllcache\OLD39.tmp
c:\windows\system32\dllcache\OLD3B.tmp
c:\windows\system32\dllcache\OLD4E2.tmp
c:\windows\system32\dllcache\OLD4E6.tmp
c:\windows\system32\dllcache\OLD4EA.tmp
c:\windows\system32\dllcache\OLD4EE.tmp
c:\windows\system32\dllcache\OLD4F2.tmp
c:\windows\system32\dllcache\OLD89A.tmp
c:\windows\system32\dllcache\OLD89E.tmp
c:\windows\system32\dllcache\OLD8A2.tmp
c:\windows\system32\dllcache\OLD8A6.tmp
c:\windows\system32\dllcache\OLDB.tmp
c:\windows\system32\dllcache\OLDE.tmp
c:\windows\system32\flvDX.dll
c:\windows\system32\jcsb.new
c:\windows\system32\jcsball.dat
c:\windows\system32\jerror.dat
c:\windows\system32\msfDX.dll
c:\windows\system32\Smab0.dll
c:\windows\Tasks\AppleSoftwareUpdate.job
c:\windows\TMP17.tmp
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASWFSBLK
-------\Legacy_ASWSP
((((((((((((((((((((((((( Soubory vytvořené od 2009-01-26 do 2009-02-26 )))))))))))))))))))))))))))))))
.
2009-02-25 20:44 . 2008-04-14 07:51 290,816 --a--c--- c:\windows\system32\dllcache\OLD37.tmp
2009-02-25 20:44 . 2008-04-14 07:51 43,520 --a--c--- c:\windows\system32\dllcache\OLD34.tmp
2009-02-25 20:44 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLD3A.tmp
2009-02-25 20:44 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLD2E.tmp
2009-02-25 20:44 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLD3D.tmp
2009-02-25 20:44 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLD31.tmp
2009-02-25 20:01 . 2006-05-04 19:02 380,928 --a------ c:\windows\system32\drivers\rt61.sys
2009-02-25 20:01 . 2005-12-15 10:38 315,392 --a------ c:\windows\system32\AegisI5.exe
2009-02-25 20:01 . 2006-05-15 16:25 295,028 --a------ c:\windows\system32\Install6x.dll
2009-02-25 20:01 . 2009-02-25 20:01 21,275 --a------ c:\windows\system32\drivers\AegisP.sys
2009-02-25 20:01 . 2006-04-06 13:15 8,192 --a------ c:\windows\system32\drivers\RT2661.bin
2009-02-25 20:01 . 2006-04-06 13:15 8,192 --a------ c:\windows\system32\drivers\RT2561s.bin
2009-02-25 20:01 . 2006-04-06 13:15 8,192 --a------ c:\windows\system32\drivers\RT2561.bin
2009-02-25 20:01 . 2006-03-10 15:33 78 --a------ c:\windows\filespec6x
2009-02-25 15:54 . 2009-02-25 15:54 <DIR> d-------- c:\program files\Trend Micro
2009-02-23 21:19 . 2009-02-23 21:19 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\MicroWorld
2009-02-23 21:19 . 2009-02-23 21:19 626,688 --a------ c:\windows\system32\msvcr80.dll
2009-02-23 21:19 . 2009-02-23 21:19 548,864 --a------ c:\windows\system32\msvcp80.dll
2009-02-23 21:19 . 2009-02-23 21:19 28,672 --a------ c:\windows\system32\eEmpty.exe
2009-02-23 21:19 . 2005-09-22 23:22 522 --a------ c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-02-22 20:19 . 2008-04-14 07:51 290,816 --a--c--- c:\windows\system32\dllcache\adsiis51.dll
2009-02-22 20:19 . 2008-04-14 07:51 43,520 --a--c--- c:\windows\system32\dllcache\admwprox.dll
2009-02-22 20:19 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\author.dll
2009-02-22 20:19 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\admin.dll
2009-02-22 20:19 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\author.exe
2009-02-22 20:19 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\admin.exe
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d-------- c:\documents and settings\Default User.WINDOWS.0\Plocha
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d--h----- c:\documents and settings\Default User.WINDOWS.0\Okolní tiskárny
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d--h----- c:\documents and settings\Default User.WINDOWS.0\Okolní síť
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d-------- c:\documents and settings\Default User.WINDOWS.0\Oblíbené položky
2009-02-22 19:50 . 2009-02-22 18:56 <DIR> d--h----- c:\documents and settings\Default User.WINDOWS.0\Šablony
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> dr------- c:\documents and settings\Default User.WINDOWS.0\Nabídka Start
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d-------- c:\documents and settings\Default User.WINDOWS.0\Dokumenty
2009-02-22 19:50 . 2009-02-22 19:21 <DIR> d-------- c:\documents and settings\All Users.WINDOWS.0\Plocha
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d-------- c:\documents and settings\All Users.WINDOWS.0\Oblíbené položky
2009-02-22 19:50 . 2009-02-22 19:50 <DIR> d--h----- c:\documents and settings\All Users.WINDOWS.0\Šablony
2009-02-22 19:50 . 2009-02-22 19:01 <DIR> dr------- c:\documents and settings\All Users.WINDOWS.0\Nabídka Start
2009-02-22 19:50 . 2009-02-22 18:57 <DIR> dr------- c:\documents and settings\All Users.WINDOWS.0\Dokumenty
2009-02-22 19:49 . 2009-02-22 19:50 <DIR> dr-h----- c:\documents and settings\Default User.WINDOWS.0\Data aplikací
2009-02-22 19:49 . 2009-02-23 17:32 <DIR> d--h----- c:\documents and settings\Default User.WINDOWS.0
2009-02-22 19:49 . 2009-02-22 19:50 <DIR> dr-h----- c:\documents and settings\All Users.WINDOWS.0\Data aplikací
2009-02-22 19:49 . 2009-02-22 18:58 <DIR> d-------- c:\documents and settings\All Users.WINDOWS.0
2009-02-22 19:43 . 2009-02-23 16:55 <DIR> d-------- C:\WINDOWS.0
2009-02-22 19:05 . 2009-02-22 19:50 <DIR> d-------- c:\documents and settings\Petr.MAŠINA\Plocha
2009-02-22 19:05 . 2009-02-22 19:50 <DIR> d--h----- c:\documents and settings\Petr.MAŠINA\Okolní tiskárny
2009-02-22 19:05 . 2009-02-22 19:50 <DIR> d--h----- c:\documents and settings\Petr.MAŠINA\Okolní síť
2009-02-22 19:05 . 2009-02-22 19:05 <DIR> dr------- c:\documents and settings\Petr.MAŠINA\Oblíbené položky
2009-02-22 19:05 . 2009-02-22 18:56 <DIR> d--h----- c:\documents and settings\Petr.MAŠINA\Šablony
2009-02-22 19:05 . 2009-02-22 19:50 <DIR> dr------- c:\documents and settings\Petr.MAŠINA\Nabídka Start
2009-02-22 19:05 . 2009-02-22 19:05 <DIR> dr------- c:\documents and settings\Petr.MAŠINA\Dokumenty
2009-02-22 19:05 . 2009-02-22 19:05 <DIR> dr-h----- c:\documents and settings\Petr.MAŠINA\Data aplikací
2009-02-22 19:05 . 2009-02-23 15:41 <DIR> d-------- c:\documents and settings\Petr.MAŠINA
2009-02-22 19:03 . 2009-02-22 19:03 <DIR> d-------- c:\documents and settings\NetworkService.NT AUTHORITY\Data aplikací
2009-02-22 19:03 . 2009-02-22 19:03 <DIR> d-------- c:\documents and settings\LocalService.NT AUTHORITY\Data aplikací
2009-02-22 19:03 . 2009-02-22 19:03 <DIR> d--hs---- c:\documents and settings\LocalService.NT AUTHORITY
2009-02-22 19:02 . 2009-02-22 19:03 <DIR> d--hs---- c:\documents and settings\NetworkService.NT AUTHORITY
2009-02-22 18:58 . 2009-02-22 18:58 <DIR> d--hs---- c:\documents and settings\All Users.WINDOWS.0\DRM
2009-02-22 16:20 . 2001-08-17 21:28 794,654 --a------ c:\windows\system32\dllcache\usr1801.sys
2009-02-22 16:19 . 2001-10-24 11:58 899,146 --a------ c:\windows\system32\dllcache\r2mdkxga.sys
2009-02-22 16:18 . 2008-08-14 14:26 2,068,224 --a------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-22 16:17 . 2001-10-25 15:00 1,875,968 --a------ c:\windows\system32\dllcache\msir3jp.lex
2009-02-22 16:16 . 2001-10-25 15:00 1,158,818 --a------ c:\windows\system32\dllcache\korwbrkr.lex
2009-02-22 16:11 . 2008-08-14 14:26 2,191,360 --a--c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-22 16:11 . 2008-04-14 07:51 189,440 --a--c--- c:\windows\system32\dllcache\smtpadm.dll
2009-02-22 16:11 . 2008-04-14 07:48 77,824 --a--c--- c:\windows\system32\dllcache\logui.ocx
2009-02-22 16:11 . 2001-10-24 12:24 66,048 --a--c--- c:\windows\system32\dllcache\s3legacy.dll
2009-02-22 16:11 . 2008-04-14 07:52 32,827 --a--c--- c:\windows\system32\dllcache\tcptest.exe
2009-02-22 16:11 . 2008-04-14 07:51 20,536 --a--c--- c:\windows\system32\dllcache\shtml.dll
2009-02-22 16:11 . 2008-04-14 07:52 16,437 --a--c--- c:\windows\system32\dllcache\shtml.exe
2009-02-22 16:11 . 2008-04-04 01:28 16,384 --a--c--- c:\windows\system32\dllcache\tcptsat.dll
2009-02-22 16:11 . 2008-04-14 07:52 8,192 --a--c--- c:\windows\system32\dllcache\staxmem.dll
2009-02-22 16:11 . 2001-10-25 15:00 7,168 --a--c--- c:\windows\system32\dllcache\wamregps.dll
2009-02-22 15:21 . 2001-10-24 11:46 75,136 --a--c--- c:\windows\system32\dllcache\atimpae.sys
2009-02-22 12:23 . 2009-02-22 12:23 <DIR> d-------- c:\program files\Driver-Soft
2009-02-22 12:23 . 2004-06-14 14:56 427,864 --a------ c:\windows\system32\XceedZip.dll
2009-02-22 10:11 . 2009-02-22 19:56 <DIR> d-------- c:\program files\nLite
2009-02-22 09:10 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLD5.tmp
2009-02-22 09:10 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLD8.tmp
2009-02-22 08:22 . 2009-02-22 08:46 <DIR> d-------- c:\windows\SxsCaPendDel
2009-02-22 08:19 . 2009-02-22 08:19 <DIR> d-------- c:\program files\Microsoft
2009-02-22 07:54 . 2009-02-22 08:05 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Autodesk
2009-02-22 07:52 . 2009-02-22 07:55 <DIR> d-------- c:\program files\Common Files\Autodesk Shared
2009-02-22 07:52 . 2009-02-22 07:54 <DIR> d-------- c:\program files\Autodesk
2009-02-22 06:43 . 2009-02-22 06:43 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\OptiTex
2009-02-22 06:42 . 2009-02-22 06:42 <DIR> d-------- c:\program files\DAZ
2009-02-22 06:42 . 2009-02-22 06:42 <DIR> d-------- c:\program files\Common Files\DAZ
2009-02-22 06:42 . 2008-08-21 19:12 10,113,024 --a------ c:\windows\system32\dzcore.dll
2009-02-22 06:42 . 2008-08-21 18:42 6,131,712 --a------ c:\windows\system32\daz-qt-mt.dll
2009-02-22 06:42 . 2008-08-21 18:34 2,076,672 --a------ c:\windows\system32\dz3delight.dll
2009-02-22 06:42 . 2008-08-21 18:42 1,785,856 --a------ c:\windows\system32\daz-qsa.dll
2009-02-22 06:42 . 2008-08-21 19:15 49,152 --a------ c:\windows\system32\dzcarrara.dll
2009-02-22 06:42 . 2008-08-21 19:14 33,280 --a------ c:\windows\system32\dzbryce6.dll
2009-02-22 06:42 . 2008-08-21 19:14 26,624 --a------ c:\windows\system32\dzwrapper.dll
2009-02-21 22:03 . 2008-04-14 07:51 290,816 --a--c--- c:\windows\system32\dllcache\OLDD.tmp
2009-02-21 22:03 . 2008-04-14 07:51 43,520 --a--c--- c:\windows\system32\dllcache\OLDA.tmp
2009-02-21 22:03 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLD4.tmp
2009-02-21 22:03 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLD7.tmp
2009-02-21 21:17 . 2008-04-14 07:51 290,816 --a--c--- c:\windows\system32\dllcache\OLDC.tmp
2009-02-21 21:17 . 2008-04-14 07:51 43,520 --a--c--- c:\windows\system32\dllcache\OLD9.tmp
2009-02-21 21:17 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLDF.tmp
2009-02-21 21:17 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLD3.tmp
2009-02-21 21:17 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLD6.tmp
2009-02-21 21:17 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLD12.tmp
2009-02-21 21:00 . 2001-10-24 12:24 137,216 --a------ c:\windows\system32\dllcache\atidrae(2).dll
2009-02-21 20:10 . 2009-02-23 16:02 <DIR> d-------- c:\documents and settings\Petr\Data aplikací\Orbit
2009-02-21 14:32 . 2008-04-14 07:46 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2009-02-21 14:31 . 2001-08-17 20:14 952,007 --a--c--- c:\windows\system32\dllcache\diwan.sys
2009-02-21 14:30 . 2008-04-14 07:51 218,112 --a--c--- c:\windows\system32\dllcache\c_g18030.dll
2009-02-21 14:29 . 2001-10-24 12:24 382,592 --a--c--- c:\windows\system32\dllcache\atidrab.dll
2009-02-21 14:28 . 2008-04-14 07:51 876,653 --a--c--- c:\windows\system32\dllcache\fp4awel.dll
2009-02-21 14:27 . 2008-04-14 07:51 184,435 --a--c--- c:\windows\system32\dllcache\fp4amsft.dll
2009-02-21 14:27 . 2008-04-14 07:51 147,513 --a--c--- c:\windows\system32\dllcache\fp4apws.dll
2009-02-21 14:27 . 2008-04-14 07:51 102,509 --a--c--- c:\windows\system32\dllcache\fp4atxt.dll
2009-02-21 14:27 . 2008-04-14 07:51 82,035 --a--c--- c:\windows\system32\dllcache\fp4anscp.dll
2009-02-21 14:27 . 2008-04-14 07:51 49,210 --a--c--- c:\windows\system32\dllcache\fp4areg.dll
2009-02-21 14:27 . 2008-04-14 07:51 41,020 --a--c--- c:\windows\system32\dllcache\fp4avnb.dll
2009-02-21 14:21 . 2009-02-21 14:21 <DIR> d-------- c:\windows\SQL9_KB960089_ENU
2009-02-21 12:47 . 2009-02-21 12:48 <DIR> d-------- c:\program files\OpenFX
2009-02-21 11:07 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLDEA.tmp
2009-02-21 11:07 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLDEE.tmp
2009-02-21 10:45 . 2008-04-14 07:51 290,816 --a--c--- c:\windows\system32\dllcache\OLDDE.tmp
2009-02-21 10:45 . 2008-04-14 07:51 43,520 --a--c--- c:\windows\system32\dllcache\OLDDA.tmp
2009-02-21 10:45 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLDE2.tmp
2009-02-21 10:45 . 2008-04-14 07:51 20,540 --a--c--- c:\windows\system32\dllcache\OLD8A.tmp
2009-02-21 10:45 . 2008-04-14 07:52 16,439 --a--c--- c:\windows\system32\dllcache\OLDE6.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-26 16:45 --------- d-----w c:\documents and settings\Petr\Data aplikací\uTorrent
2009-02-26 16:44 14,656 ----a-w c:\windows\gdrv.sys
2009-02-26 16:43 --------- d---a-w c:\documents and settings\All Users\Data aplikací\TEMP
2009-02-26 16:38 --------- d-----w c:\program files\Apple Software Update
2009-02-26 16:10 --------- d-----w c:\documents and settings\Petr\Data aplikací\Metacafe
2009-02-26 16:10 --------- d-----w c:\documents and settings\All Users\Data aplikací\Metacafe
2009-02-26 16:09 --------- d-----w c:\program files\Mozilla Firefox 3 Beta 5
2009-02-26 15:58 --------- d-----w c:\program files\Metacafe
2009-02-26 13:51 --------- d-----w c:\documents and settings\All Users\Data aplikací\Microsoft Help
2009-02-25 19:21 --------- d-----w c:\program files\iolo
2009-02-25 19:01 --------- d-----w c:\program files\RALINK
2009-02-25 18:37 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-25 18:37 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-25 18:37 --------- d-----w c:\documents and settings\Petr\Data aplikací\SUPERAntiSpyware.com
2009-02-25 18:29 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-25 18:29 --------- d-----w c:\program files\iLiberty
2009-02-25 18:27 --------- d-----w c:\documents and settings\All Users\Data aplikací\Codemasters
2009-02-25 18:26 --------- d-----w c:\documents and settings\Petr\Data aplikací\Microsoft Games
2009-02-25 18:24 --------- d-----w c:\program files\Ubisoft
2009-02-25 18:19 --------- d-----w c:\program files\Ovislink
2009-02-25 18:19 --------- d-----w c:\program files\Common Files\Acronis
2009-02-23 20:17 --------- d-----w c:\program files\CCleaner
2009-02-23 19:43 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-23 19:43 --------- d-----w c:\documents and settings\All Users\Data aplikací\Spybot - Search & Destroy
2009-02-22 18:56 --------- d-----w c:\program files\Orbitdownloader
2009-02-21 13:33 --------- d-----w c:\program files\ESET
2009-02-21 13:21 --------- d-----w c:\program files\Microsoft SQL Server
2009-02-21 10:37 --------- d-----w c:\program files\Bonjour
2009-02-21 10:35 --------- d-----w c:\documents and settings\Petr\Data aplikací\DiskAid
2009-02-21 10:30 --------- d-----w c:\program files\totalcmd
2009-02-21 10:30 --------- d-----w c:\program files\Recuva
2009-02-21 10:30 --------- d-----w c:\program files\MPlayer for Windows
2009-02-21 10:30 --------- d-----w c:\program files\MozyHome
2009-02-21 10:30 --------- d-----w c:\program files\MediaInfo
2009-02-21 10:30 --------- d-----w c:\program files\MediaCoder
2009-02-21 10:30 --------- d-----w c:\program files\iTunes
2009-02-21 10:30 --------- d-----w c:\program files\DAEMON Tools Lite
2009-02-21 10:30 --------- d-----w c:\program files\Common Files\LightScribe
2009-02-21 10:30 --------- d-----w c:\program files\Common Files\BinarySense
2009-02-21 10:30 --------- d-----w c:\program files\Common Files\Akamai
2009-02-21 10:30 --------- d-----w c:\program files\ATITool
2009-02-15 19:32 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-12 15:49 --------- d-----w c:\program files\MediaCoder iPhone Edition
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-07 13:55 --------- d-----w c:\program files\Gigabyte
2009-02-07 11:22 77,168 ----a-w c:\documents and settings\Petr\Data aplikací\GDIPFONTCACHEV1.DAT
2009-02-03 15:59 --------- d-----w c:\program files\USDownloader135
2009-02-01 20:48 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-01 20:48 22,328 ----a-w c:\documents and settings\Petr\Data aplikací\PnkBstrK.sys
2009-02-01 19:59 --------- d-----w c:\program files\Codemasters
2009-02-01 18:22 --------- d-----w c:\documents and settings\Petr\Data aplikací\Skype
2009-02-01 18:00 --------- d-----w c:\documents and settings\Petr\Data aplikací\skypePM
2009-01-29 14:39 --------- d-----w c:\program files\Skype
2009-01-25 07:37 --------- d-----w c:\program files\Personal Voice Changer Driver
2009-01-24 18:40 --------- d-----w c:\program files\Windows Desktop Search
2009-01-24 10:55 --------- d-----w c:\documents and settings\All Users\Data aplikací\DVD Shrink
2009-01-23 18:54 --------- d-----w c:\documents and settings\Petr\Data aplikací\Windows Search
2009-01-21 19:33 23,600 ----a-w c:\windows\system32\drivers\TVICHW32.SYS
2009-01-21 19:33 23,600 ----a-w c:\windows\system32\drivers\TVICHW32(2).SYS
2009-01-19 16:07 --------- d-----w c:\documents and settings\All Users\Data aplikací\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-19 16:06 --------- d-----w c:\program files\iPod
2009-01-18 20:48 --------- d-----w c:\documents and settings\All Users\Data aplikací\Malwarebytes
2009-01-18 20:40 --------- d-----w c:\documents and settings\Petr\Data aplikací\Malwarebytes
2009-01-12 20:06 --------- d-----w c:\program files\Common Files\Apple
2009-01-12 20:04 --------- d-----w c:\program files\QuickTime Alternative
2009-01-11 19:57 --------- d-----w c:\program files\WinSCP
2009-01-09 14:23 319,488 ----a-w c:\windows\HideWin.exe
2009-01-08 20:54 --------- d-----w c:\program files\HD Tune
2008-02-07 13:53 32 ----a-w c:\documents and settings\All Users\Data aplikací\ezsid.dat
2007-10-24 06:47 47,360 ----a-w c:\documents and settings\Petr\Data aplikací\pcouffin.sys
2007-10-11 08:23 8,255 -c--a-w c:\program files\atitool.rar
2007-09-06 12:28 1,097,728 ----a-w c:\documents and settings\Petr\iTunesMobileDevice.dll
2005-01-28 14:15 192,512 ----a-w c:\windows\inf\unregmp2(2).exe
2008-01-08 18:47 61 --sh--w c:\windows\cnerolf.bin
2008-02-04 19:26 151,040 --sha-w c:\windows\system32\VistaUltm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-02-25_20.39.32.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-17 19:04:42 8,465,920 ----a-w c:\windows\$hf_mig$\KB967715\SP3QFE\shell32.dll
+ 2008-07-09 07:36:00 18,296 ----a-w c:\windows\$hf_mig$\KB967715\spmsg.dll
+ 2008-07-09 07:36:01 233,848 ----a-w c:\windows\$hf_mig$\KB967715\spuninst.exe
+ 2008-07-09 07:36:00 26,488 ----a-w c:\windows\$hf_mig$\KB967715\update\spcustom.dll
+ 2008-07-09 07:36:04 759,160 ----a-w c:\windows\$hf_mig$\KB967715\update\update.exe
+ 2008-07-09 07:36:11 391,032 ----a-w c:\windows\$hf_mig$\KB967715\update\updspapi.dll
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-04-14 06:51:56 8,465,408 -c--a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-06-17 19:02:56 8,465,408 -c--a-w c:\windows\system32\dllcache\shell32.dll
- 2008-06-29 15:46:40 128,840 ----a-w c:\windows\system32\Metacafe.scr
+ 2009-02-17 20:39:11 128,840 ----a-w c:\windows\system32\Metacafe.scr
- 2008-04-14 06:51:56 8,465,408 ----a-w c:\windows\system32\shell32.dll
+ 2008-06-17 19:02:56 8,465,408 ----a-w c:\windows\system32\shell32.dll
- 2007-11-30 12:39:09 18,296 ------w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:36:00 18,296 ------w c:\windows\system32\spmsg.dll
+ 2009-02-26 16:44:00 16,384 ----atw c:\windows\temp\Perflib_Perfdata_364.dat
+ 2009-02-26 16:44:00 16,384 ----atw c:\windows\temp\Perflib_Perfdata_68c.dat
+ 2009-02-26 16:44:01 16,384 ----atw c:\windows\temp\Perflib_Perfdata_784.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-24 15:52 3044664 --a------ c:\program files\MozyHome\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-24 15:52 3044664 --a------ c:\program files\MozyHome\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"uTorrent"="c:\program files\uTorrent\utorrent.exe" [2009-02-15 270128]
"OEXPRESS"="c:\windows\OETRN.EXE" [2007-10-17 26624]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tray3"="c:\windows\system32\RecvMessage.exe" [2007-01-10 196608]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-07-16 61440]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 1828136]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 86960]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-05-16 213936]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-09-10 1188152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 c:\windows\SoundMan.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 c:\windows\RTHDCPL.exe]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 c:\windows\alcwzrd.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
desktop(2).ini [2008-10-31 169]
Metacafe.lnk - c:\program files\Metacafe\MetacafeAgent.exe [2009-02-17 145736]
MozyHome Status.lnk - c:\program files\MozyHome\mozystat.exe [2008-10-24 2954552]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2009-02-25 614400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"SENTINEL"= snti386.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TryAndDecideService"=2 (0x2)
"PnkBstrA"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"36X Raid Configurer"=c:\windows\system32\JMRaidSetup.exe boot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
"QuickTime Task"="c:\program files\QuickTime Alternative\QTTask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"=
"c:\\Program Files\\strongDCrc10\\StrongDC.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII\\RpcSandraSrv.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Mozilla Firefox 3 Beta 5\\firefox.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\MirandaPortable\\App\\miranda\\miranda32.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"f:\\Games\\[ PC Games ] - Age of Empires II(FULL)\\empires2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Gigabyte\\@BIOS\\gwflash.exe"=
"c:\\Program Files\\Gigabyte\\@BIOS\\update.exe"=
"c:\\WINDOWS\\system32\\RecvMessage.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 RRamdisk;Ramdisk Driver;c:\windows\system32\drivers\rramdisk.sys [2009-01-08 12288]
R0 secdir;Folder Security Personal;c:\windows\system32\secdir.sys [2008-08-16 70656]
R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-06-05 53752]
R2 COM Service;COM Service;c:\program files\Gigabyte\C.O.M\GCSVR.exe [2009-02-07 16384]
R2 HDDlife HDD Access service;HDDlife HDD Access service;c:\program files\Common Files\BinarySense\hldasvc.exe [2007-08-09 816376]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [2008-10-20 596840]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [2008-10-20 596840]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [2009-02-04 9472]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-08-03 69120]
R3 tenCapture;tenCapture;c:\windows\system32\drivers\tenCapture.sys [2007-04-21 9344]
S1 amdtools;AMD Special Tools Driver; [x]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 Akamai;Akamai;c:\windows\System32\svchost.exe -k Akamai [2004-08-17 14336]
S2 HDD Temperature;HDD Temperature Service; [x]
S2 MSSQL$CSSQL05;SQL Server (CSSQL05);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-12-18 29181272]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [2007-10-09 20856]
S3 FlyPCI;FlyPCI;c:\windows\system32\drivers\FlyPCI.sys [2008-07-28 4134]
S3 mirrorv3;mirrorv3;c:\windows\system32\drivers\rminiv3.sys [2006-11-01 3328]
S3 NRKCTL32;NRKCTL32; [x]
S3 PhTVTune;TCL2002 TV Tuner;c:\windows\system32\drivers\phtvtune.sys [2008-07-27 19904]
S3 SetupNTGLM7X;SetupNTGLM7X; [x]
S3 TVICHW32;TVICHW32;c:\windows\system32\drivers\TVICHW32.SYS [2009-01-21 23600]
--- Ostatní služby/ovladače v paměti ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{07f9586d-7ab8-11dc-8682-001a4d4ebf13}]
\Shell\AutoRun\command - D:\autorun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ECABE060-DAD2-D904-EED9-EF6419549337}]
c:\windows\system32\svchost.exe
.
Obsah adresáře 'Naplánované úlohy'
2009-02-20 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe []
2009-02-25 c:\windows\Tasks\20090107_211900_Hlavní Záloha.job
- c:\program files\Nero\Nero8\Nero BackItUp\BackItUp.exe [2007-08-08 09:24]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext =
hxxp://esd.element5.com/product.html?pr ... =200030350uInternet Settings,ProxyOverride = *.local
IE: Crawler Search - tbr:iemenu
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Stáhnout pomocí Net Transportu - c:\program files\Xi\NetTransport 2\NTAddLink.html
IE: Stáhnout vše pomocí &Net Transportu - c:\program files\Xi\NetTransport 2\NTAddList.html
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\windows\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\windows\WebIE.dll
Handler: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - c:\program files\BinarySense\HDDlife 3\hlAPP.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} -
hxxp://193.165.78.6/VatDec.cabDPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
FF - ProfilePath - c:\documents and settings\Petr\Data aplikací\Mozilla\Firefox\Profiles\4o3l9ne1.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 5\plugins\np-mswmp.dll
FF - plugin: c:\program files\Photosynth\npPhotosynthMozilla.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin5.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox 3 Beta 5\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-26 17:44:15
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
c:\windows\system32\$FSPINI$.DAT 1024 bytes
c:\windows\system32\FLOCKER.ACL 0 bytes
c:\windows\system32\Flocker.USR 444 bytes
c:\windows\system32\jcsb.new 10920 bytes
c:\windows\system32\jcsball.dat 30671 bytes
c:\windows\system32\jerror.dat 2186 bytes
sken byl úspešně dokončen
skryté soubory: 6
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet108\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1220945662-606747145-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{474415E1-AF1A-A200-48AF-54150B2D4BA0}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"panifpacfhnpkeclcmgimcbofgaejjee"=hex:61,62,69,67,63,6f,6d,64,67,6f,70,6c,62,
70,70,67,6b,6c,62,6e,67,6e,66,64,6d,6e,6e,61,61,66,70,63,6c,69,00,47
"padhieabcecjoebgaoofijogllcpfkai"=hex:61,62,69,67,63,6f,6d,64,67,6f,70,6c,62,
70,70,67,6b,6c,62,6e,67,6e,66,64,6f,6e,6c,66,70,66,67,62,6c,63,00,00
[HKEY_USERS\S-1-5-21-1220945662-606747145-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B5E0D790-0328-6E83-BA75-CE581B58000B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"pabbgidbgmnfcialmmojcepgpbpgbbjn"=hex:61,62,6b,6e,6b,6a,6c,6a,64,65,65,6d,68,
64,6b,6f,6f,63,61,63,65,66,6e,6b,64,6e,69,65,63,65,68,63,64,62,00,47
[HKEY_USERS\S-1-5-21-1220945662-606747145-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:41,d4,3a,33,d3,89,92,d0,4d,ca,e0,c0,34,33,2c,9a,e2,a4,04,0d,d8,42,d6,
25,64,5e,0d,23,f4,92,d9,b6,16,8d,1c,12,4d,ab,4d,08,53,fa,3f,3b,c4,05,08,3a,\
"??"=hex:02,79,70,68,17,b4,8f,d8,a0,cb,70,02,f9,7f,5f,53
[HKEY_USERS\S-1-5-21-1220945662-606747145-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:98,df,b9,c4,97,53,a6,37,e5,b9,75,ca,a1,e1,ed,7d,15,1a,f1,7d,82,
2d,19,55,b7,85,26,45,37,7c,d6,f0,ef,b7,15,a4,56,87,59,44,93,32,27,4a,c9,01,\
"rkeysecu"=hex:7b,72,96,fc,88,1e,5a,a0,13,5b,4e,03,6d,02,78,63
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,b0,46,df,66,96,
d8,12,f2,c8,28,51,af,b0,29,a3,98,81,44,76,ac,2b,fd,57,1b,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,c7,19,ca,a0,33,
66,67,75,71,3b,04,66,8b,46,0d,96,9d,69,59,06,95,af,c3,b2,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,24,64,06,cf,27,
51,23,29,25,da,ec,7e,55,20,c9,26,92,87,b0,92,31,16,17,90,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,da,cb,98,c5,35,
70,56,26,3e,1e,9e,e0,57,5a,93,61,93,7b,db,ec,91,42,93,ee,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,16,fb,66,e8,9f,
f4,6a,e6,cd,44,cd,b9,a6,33,6c,cd,71,28,a9,72,58,d9,5e,fe,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,e3,3b,1d,e3,ea,
8d,71,67,b0,18,ed,a7,3f,8d,37,a4,55,62,3e,9a,b5,d2,e8,e6,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,fa,8c,48,14,5a,
ca,97,b9,31,77,e1,ba,b1,f8,68,02,4a,2d,f1,b3,5f,d1,61,5b,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:aa,52,c6,00,84,3c,26,64,d9,88,5a,62,9a,
43,cf,27,83,6c,56,8b,a0,85,96,ab,45,0b,81,f4,c6,b2,de,f0,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,aa,f1,64,2b,c6,
4f,a2,73,51,fa,6e,91,28,9e,14,cc,e8,43,70,67,8c,62,db,5d,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,33,43,be,b6,59,
15,79,0f,b1,cd,45,5a,a8,c4,f8,b9,88,df,a0,f4,43,7f,51,96,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,2e,29,59,36,9d,
a5,af,b8,e3,0e,66,d5,eb,bc,2f,6b,e9,98,75,5c,f1,de,8d,af,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:05,73,21,dd,54,d8,4a,c5,f5,89,2c,49,ad,
da,a4,67,fa,ea,66,7f,d4,3b,6b,70,66,f3,d3,3e,0c,de,60,76,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Nls\net\AllowedPaths*]
@=hex:f1,ef,1c,47,00,00,00,00
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1212)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
c:\program files\MozyHome\mozybackup.exe
c:\program files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\snmp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\notepad.exe
c:\program files\ATITool\ATITool.exe
c:\program files\ATITool\ATITool.exe
c:\windows\system32\notepad.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\PdaNet for iPhone\PdaNetPC.exe
c:\program files\PdaNet for iPhone\PdaNetPC.exe
c:\program files\totalcmd\TOTALCMD.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\totalcmd\TOTALCMD.EXE
.
**************************************************************************
.
Celkový čas: 2009-02-26 17:48:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-02-26 16:48:22
ComboFix2.txt 2009-02-25 19:40:59
Před spuštěním: Volných bajtů: 168,601,382,912
Po spuštění: Volných bajtů: 168,441,073,664
Current=108 Default=108 Failed=107 LastKnownGood=109 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109
682 --- E O F --- 2009-02-26 13:51:20