OT Movelt -výsledek========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
c:\temp\WER029d.dir00 moved successfully.
c:\temp\WER1b0f.dir00 moved successfully.
c:\temp\WER1b25.dir00 moved successfully.
c:\temp\WER1bb9.dir00 moved successfully.
c:\temp\WER1bd7.dir00 moved successfully.
c:\temp\WER1d21.dir00 moved successfully.
c:\temp\WER26c4.dir00 moved successfully.
c:\temp\WER2b18.dir00 moved successfully.
c:\temp\WER2d04.dir00 moved successfully.
c:\temp\WER2ec1.dir00 moved successfully.
c:\temp\WER2f2a.dir00 moved successfully.
c:\temp\WER3b94.dir00 moved successfully.
c:\temp\WER48f7.dir00 moved successfully.
c:\temp\WER4a97.dir00 moved successfully.
c:\temp\WER5190.dir00 moved successfully.
c:\temp\WER51a3.dir00 moved successfully.
c:\temp\WER5342.dir00 moved successfully.
c:\temp\WER5564.dir00 moved successfully.
c:\temp\WER5957.dir00 moved successfully.
c:\temp\WER5bc3.dir00 moved successfully.
c:\temp\WER5d1e.dir00 moved successfully.
c:\temp\WER5fe3.dir00 moved successfully.
c:\temp\WER5ffc.dir00 moved successfully.
c:\temp\WER606e.dir00 moved successfully.
c:\temp\WER6655.dir00 moved successfully.
c:\temp\WER6a78.dir00 moved successfully.
c:\temp\WER6b4b.dir00 moved successfully.
c:\temp\WER6d20.dir00 moved successfully.
c:\temp\WER7026.dir00 moved successfully.
c:\temp\WER75c8.dir00 moved successfully.
c:\temp\WER834e.dir00 moved successfully.
c:\temp\WER84ab.dir00 moved successfully.
c:\temp\WER8ac7.dir00 moved successfully.
c:\temp\WER8fe3.dir00 moved successfully.
c:\temp\WER9ab1.dir00 moved successfully.
c:\temp\WERa0bd.dir00 moved successfully.
c:\temp\WERb706.dir00 moved successfully.
c:\temp\WERc404.dir00 moved successfully.
c:\temp\WERc4f0.dir00 moved successfully.
c:\temp\WERc597.dir00 moved successfully.
c:\temp\WERd05a.dir00 moved successfully.
c:\temp\WERd10e.dir00 moved successfully.
c:\temp\WERd1a6.dir00 moved successfully.
c:\temp\WERd671.dir00 moved successfully.
c:\temp\WERe7d2.dir00 moved successfully.
c:\temp\WERe912.dir00 moved successfully.
c:\temp\WERea59.dir00 moved successfully.
c:\temp\WEReda6.dir00 moved successfully.
c:\temp\WERee0a.dir00 moved successfully.
c:\temp\WERfb82.dir00 moved successfully.
c:\temp\nsz20.tmp moved successfully.
c:\temp\nse21.tmp moved successfully.
c:\temp\is-KNOQM.tmp\_isetup moved successfully.
c:\temp\is-KNOQM.tmp moved successfully.
c:\temp\is-F96H3.tmp moved successfully.
c:\windows\Tasks\Norton Security Scan for Jirka.job moved successfully.
c:\program files\Norton Security Scan\Nss.exe moved successfully.
c:\program files\AskBarDis\bar\bin\askBar1.dll unregistered successfully.
c:\program files\AskBarDis\bar\bin\askBar1.dll moved successfully.
========== COMMANDS ==========
File delete failed. c:\Temp\~DFAEFC.tmp scheduled to be deleted on reboot.
File delete failed. c:\Temp\~DFE694.tmp scheduled to be deleted on reboot.
File delete failed. c:\Temp\~DFE6E8.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JETDCC3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_470.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_580.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_618.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_tDmoM4cdo0bMW6M scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03102009_074116
Files moved on Reboot...
c:\Temp\~DFAEFC.tmp moved successfully.
File c:\Temp\~DFE694.tmp not found!
File c:\Temp\~DFE6E8.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\JETDCC3.tmp moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_470.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_580.dat moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_618.dat moved successfully.
File C:\WINDOWS\temp\sqlite_tDmoM4cdo0bMW6M not found!
ComboFix========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
c:\temp\WER029d.dir00 moved successfully.
c:\temp\WER1b0f.dir00 moved successfully.
c:\temp\WER1b25.dir00 moved successfully.
c:\temp\WER1bb9.dir00 moved successfully.
c:\temp\WER1bd7.dir00 moved successfully.
c:\temp\WER1d21.dir00 moved successfully.
c:\temp\WER26c4.dir00 moved successfully.
c:\temp\WER2b18.dir00 moved successfully.
c:\temp\WER2d04.dir00 moved successfully.
c:\temp\WER2ec1.dir00 moved successfully.
c:\temp\WER2f2a.dir00 moved successfully.
c:\temp\WER3b94.dir00 moved successfully.
c:\temp\WER48f7.dir00 moved successfully.
c:\temp\WER4a97.dir00 moved successfully.
c:\temp\WER5190.dir00 moved successfully.
c:\temp\WER51a3.dir00 moved successfully.
c:\temp\WER5342.dir00 moved successfully.
c:\temp\WER5564.dir00 moved successfully.
c:\temp\WER5957.dir00 moved successfully.
c:\temp\WER5bc3.dir00 moved successfully.
c:\temp\WER5d1e.dir00 moved successfully.
c:\temp\WER5fe3.dir00 moved successfully.
c:\temp\WER5ffc.dir00 moved successfully.
c:\temp\WER606e.dir00 moved successfully.
c:\temp\WER6655.dir00 moved successfully.
c:\temp\WER6a78.dir00 moved successfully.
c:\temp\WER6b4b.dir00 moved successfully.
c:\temp\WER6d20.dir00 moved successfully.
c:\temp\WER7026.dir00 moved successfully.
c:\temp\WER75c8.dir00 moved successfully.
c:\temp\WER834e.dir00 moved successfully.
c:\temp\WER84ab.dir00 moved successfully.
c:\temp\WER8ac7.dir00 moved successfully.
c:\temp\WER8fe3.dir00 moved successfully.
c:\temp\WER9ab1.dir00 moved successfully.
c:\temp\WERa0bd.dir00 moved successfully.
c:\temp\WERb706.dir00 moved successfully.
c:\temp\WERc404.dir00 moved successfully.
c:\temp\WERc4f0.dir00 moved successfully.
c:\temp\WERc597.dir00 moved successfully.
c:\temp\WERd05a.dir00 moved successfully.
c:\temp\WERd10e.dir00 moved successfully.
c:\temp\WERd1a6.dir00 moved successfully.
c:\temp\WERd671.dir00 moved successfully.
c:\temp\WERe7d2.dir00 moved successfully.
c:\temp\WERe912.dir00 moved successfully.
c:\temp\WERea59.dir00 moved successfully.
c:\temp\WEReda6.dir00 moved successfully.
c:\temp\WERee0a.dir00 moved successfully.
c:\temp\WERfb82.dir00 moved successfully.
c:\temp\nsz20.tmp moved successfully.
c:\temp\nse21.tmp moved successfully.
c:\temp\is-KNOQM.tmp\_isetup moved successfully.
c:\temp\is-KNOQM.tmp moved successfully.
c:\temp\is-F96H3.tmp moved successfully.
c:\windows\Tasks\Norton Security Scan for Jirka.job moved successfully.
c:\program files\Norton Security Scan\Nss.exe moved successfully.
c:\program files\AskBarDis\bar\bin\askBar1.dll unregistered successfully.
c:\program files\AskBarDis\bar\bin\askBar1.dll moved successfully.
========== COMMANDS ==========
File delete failed. c:\Temp\~DFAEFC.tmp scheduled to be deleted on reboot.
File delete failed. c:\Temp\~DFE694.tmp scheduled to be deleted on reboot.
File delete failed. c:\Temp\~DFE6E8.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JETDCC3.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_470.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_580.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_618.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\sqlite_tDmoM4cdo0bMW6M scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03102009_074116
Files moved on Reboot...
c:\Temp\~DFAEFC.tmp moved successfully.
File c:\Temp\~DFE694.tmp not found!
File c:\Temp\~DFE6E8.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\JETDCC3.tmp moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_470.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_580.dat moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_618.dat moved successfully.
File C:\WINDOWS\temp\sqlite_tDmoM4cdo0bMW6M not found!
HiJackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:16:16, on 10.3.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer3\TeamViewer_Service.exe
C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://home.sweetim.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.app-zilla.com/search.htmR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\4601\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: Solid State Networks IE Browser Plugin - {BD08A9D5-0E5C-4f42-99A3-C0CB5E860557} - C:\WINDOWS\system32\SolidStateNetworks\SolidStateION\solidax.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Joint Operations Typhoon Rising Registration.lnk = C:\TEMP\{5AB2A97A-0378-47B1-9D6F-8185FB731FD2}\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\NOVG.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: Joint Operations Typhoon Rising Registration.lnk = C:\TEMP\{5AB2A97A-0378-47B1-9D6F-8185FB731FD2}\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\NOVG.EXE (User 'Default user')
O4 - Startup: Joint Operations Typhoon Rising Registration.lnk = C:\TEMP\{5AB2A97A-0378-47B1-9D6F-8185FB731FD2}\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\NOVG.EXE
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.74\AMVConverter\grab.html
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.04\AMVConverter\grab.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.74\MediaManager\grab.html
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.cz/s/v/35.06/uploader2.cabO16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) -
http://www.playwhat.com/solidPlugin/solidstateion.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{42764D17-109C-47FE-9498-8B4CE18A15F8}: NameServer = 192.168.11.1,80.78.144.6
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
--
End of file - 11023 bytes
VirustotalAntivirus Verze Poslední aktualizace Výsledek
a-squared 4.0.0.101 2009.03.10 -
AhnLab-V3 5.0.0.2 2009.02.27 -
AntiVir 7.9.0.107 2009.03.09 -
Authentium 5.1.0.4 2009.03.09 -
Avast 4.8.1335.0 2009.03.09 -
AVG 8.0.0.237 2009.03.09 -
BitDefender 7.2 2009.03.10 -
CAT-QuickHeal 10.00 2009.03.09 -
ClamAV 0.94.1 2009.03.10 -
Comodo 1039 2009.03.09 -
DrWeb 4.44.0.09170 2009.03.10 -
eSafe 7.0.17.0 2009.03.09 -
eTrust-Vet 31.6.6388 2009.03.09 -
F-Prot 4.4.4.56 2009.03.09 -
F-Secure 8.0.14470.0 2009.03.10 -
Fortinet 3.117.0.0 2009.03.10 -
GData 19 2009.03.10 -
Ikarus T3.1.1.45.0 2009.03.10 -
K7AntiVirus 7.10.665 2009.03.10 -
Kaspersky 7.0.0.125 2009.03.10 -
McAfee 5548 2009.03.09 -
McAfee+Artemis 5548 2009.03.09 -
Microsoft 1.4405 2009.03.10 -
NOD32 3922 2009.03.09 -
Norman 6.00.06 2009.03.09 -
nProtect 2009.1.8.0 2009.03.10 -
Panda 10.0.0.10 2009.03.09 -
PCTools 4.4.2.0 2009.03.09 -
Prevx1 V2 2009.03.10 -
Rising 21.20.10.00 2009.03.10 -
SecureWeb-Gateway 6.7.6 2009.03.09 -
Sophos 4.39.0 2009.03.10 -
Sunbelt 3.2.1858.2 2009.03.10 -
Symantec 1.4.4.12 2009.03.10 -
TheHacker 6.3.3.0.278 2009.03.10 -
TrendMicro 8.700.0.1004 2009.03.10 -
VBA32 3.12.10.1 2009.03.10 -
ViRobot 2009.3.10.1642 2009.03.10 -
VirusBuster 4.5.11.0 2009.03.09 -
Rozšiřující informace
File size: 50030 bytes
MD5...: cbcd6efb5dae90ed0ca2cd289ee54d20
SHA1..: 453dbcab138cd139f11040434b76be090f139933
SHA256: 6eda53d541182237a831966e1039f903e7a987807c066dcc50fb6d1c2de0d208
SHA512: d929327d935a211527f1422402fa7686f38f2dcb076b332d63747bcd255715d2
7ddcedf57ca1e00d07dd44566968a432b8f7da1ff991a6961e12b0e66ba813f6
ssdeep: 768:yuwpjhKuCfAqgRgPLF4OiG2+e99Z3vjLtI1CZ0POugqcv1F7fo:lIgPLeG2+
e9rLWHPlfcNxo
PEiD..: Armadillo v1.71
TrID..: File type identification
Win32 Executable MS Visual C++ (generic) (62.7%)
Win32 Executable Generic (14.1%)
Win32 Dynamic Link Library (generic) (12.6%)
Win32 Executable MS Visual FoxPro 7 (3.7%)
Generic Win/DOS Executable (3.3%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x34a3
timedatestamp.....: 0x3caa052c (Tue Apr 02 19:23:24 2002)
machinetype.......: 0x14c (I386)
( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x59e0 0x6000 6.37 4b5c0f8271192563df1b32aa1a75557e
.rdata 0x7000 0xdb6 0x1000 4.86 9f84d171226835f6209d1e1006cc3952
.data 0x8000 0x2ca4 0x3000 0.69 041d37e1e8616ba1be2d41c10d106188
.rsrc 0xb000 0x620 0x1000 1.43 532c28634c63331447f94288b23040dd
( 6 imports )
> KERNEL32.dll: lstrlenA, GetModuleFileNameA, SetCurrentDirectoryA, CreateProcessA, FreeLibrary, CloseHandle, SetFilePointer, WriteFile, GetWindowsDirectoryA, GetSystemDirectoryA, GetVersionExA, LoadLibraryA, GetProcAddress, GetShortPathNameA, CreateFileA, GetFileAttributesA, RemoveDirectoryA, SetFileAttributesA, LCMapStringA, MultiByteToWideChar, RtlUnwind, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, WideCharToMultiByte, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetOEMCP, GetACP, GetLastError, ReadFile, HeapReAlloc, VirtualAlloc, HeapCreate, HeapDestroy, VirtualFree, GetStringTypeW, GetStringTypeA, LCMapStringW, HeapCompact, HeapAlloc, HeapFree, GetCPInfo, DeleteFileA, GetModuleHandleA, ExitProcess, TerminateProcess, GetCurrentProcess, GetVersion, GetStartupInfoA, GetCommandLineA, GetEnvironmentVariableA
> USER32.dll: GetWindow, GetSysColor, SendMessageA, DispatchMessageA, MessageBoxA, wsprintfA, SetDlgItemTextA, SetWindowTextA, EndDialog, DialogBoxParamA, DefWindowProcA, PostQuitMessage, RegisterClassA, LoadCursorA, LoadIconA, DestroyWindow, GetMessageA, CreateWindowExA
> GDI32.dll: CreateSolidBrush, CreateFontIndirectA, GetObjectA, SetBkColor, RemoveFontResourceA, GetStockObject, DeleteObject
> ADVAPI32.dll: RegOpenKeyExA, RegDeleteKeyA, RegCloseKey, RegDeleteValueA, RegSetValueExA, RegQueryValueExA, RegEnumKeyExA, RegOpenKeyA
> SHELL32.dll: SHGetSpecialFolderLocation, SHGetPathFromIDListA
> ole32.dll: OleUninitialize, OleInitialize
( 0 exports )