Prosím o kontrolu logu
Napsal: 08 dub 2009 20:11
Mám v počítači nainstalovaný ESET Smart Security a stále mi píše hlášku, že mám infikovanou operační paměť a chod počítače je pomalý. Nejde to vyléčit ESETem. Přikládám log a prosím o jeho kontrolu případně co dál dělat. Děkuji
ComboFix 09-04-04.01 - Administrator 2009-04-08 18:52:06.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.767.443 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *disabled*
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-03-08 do 2009-04-08 )))))))))))))))))))))))))))))))
.
2009-04-08 18:39 . 2009-04-08 18:39 155 --a------ c:\windows\system32\SelfDel.bat
2009-04-08 18:38 . 2009-04-08 18:39 84,045 --a------ c:\windows\system32\ftp_non_crp.exe
2009-04-05 11:24 . 2009-04-05 11:24 <DIR> d-------- c:\program files\ESET
2009-04-05 10:31 . 2009-04-08 18:54 105,170 --a------ c:\windows\system32\drivers\14d595e7.sys
2009-04-05 10:28 . 2009-04-05 10:28 50,632 --a------ c:\windows\system32\drivers\MiniIcpt.sys
2009-04-05 10:25 . 2009-04-05 10:25 <DIR> d--hs---- C:\#GDATA.Trash.Store#
2009-04-05 10:25 . 2009-04-05 10:25 51,016 --a------ c:\windows\system32\drivers\GDTdiIcpt.sys
2009-04-05 10:25 . 2009-04-05 10:25 22,272 --a------ c:\windows\system32\drivers\GDNdisIc.sys
2009-04-05 10:24 . 2009-04-05 10:45 <DIR> d-------- c:\program files\G DATA
2009-04-05 10:24 . 2009-04-05 10:47 <DIR> d-------- c:\program files\Common Files\G DATA
2009-04-05 10:24 . 2009-04-05 10:45 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\G DATA
2009-04-05 10:07 . 2009-04-05 10:07 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-04-05 10:07 . 2009-04-05 10:07 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Symantec
2009-03-29 15:28 . 2009-03-29 15:28 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Windows Search
2009-03-28 23:48 . 2009-03-28 23:48 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Azureus
2009-03-28 23:48 . 2009-03-29 00:17 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Azureus
2009-03-28 23:47 . 2009-03-28 23:48 <DIR> d-------- c:\program files\Vuze
2009-03-28 23:46 . 2009-03-28 23:45 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-28 23:46 . 2009-03-28 23:45 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-28 23:45 . 2009-03-28 23:45 <DIR> d-------- c:\program files\Java
2009-03-28 09:26 . 2008-03-03 15:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2009-03-28 09:26 . 2008-03-03 19:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2009-03-28 09:14 . 2009-03-28 09:14 <DIR> d-------- c:\windows\system32\config\systemprofile\Data aplikací\ESET
2009-03-28 09:14 . 2009-03-28 09:14 <DIR> d-------- c:\windows\system32\config\systemprofile\Data aplikací\ESET
2009-03-21 16:27 . 2009-03-21 16:27 <DIR> d-------- c:\windows\zy_tmp
2009-03-21 16:27 . 2004-08-17 12:23 5,120 --a------ c:\windows\system32\tcusbdrv.dll
2009-03-21 13:31 . 2001-10-24 12:54 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-03-21 13:31 . 2001-10-24 12:54 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-03-21 13:30 . 2008-04-14 01:15 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-03-21 13:30 . 2008-04-14 01:15 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-03-21 12:00 . 2009-03-21 12:00 <DIR> d-------- c:\program files\MSXML 4.0
2009-03-20 23:28 . 2009-03-20 23:28 4,263 --a------ c:\windows\system32\FLSINSTU.INI
2009-03-20 23:05 . 2009-03-20 23:05 2,331,008 --a------ c:\windows\system32\TUKernel.exe
2009-03-20 23:03 . 2009-03-20 23:03 <DIR> d-------- c:\program files\Stardock
2009-03-20 23:03 . 2009-03-20 23:03 <DIR> d--h-c--- c:\documents and settings\All Users\Data aplikací\{B98A2B83-8BB0-42E7-AA1D-D6FA6E7C8F31}
2009-03-20 23:02 . 2009-03-20 23:02 603,904 --a------ c:\windows\system32\TUProgSt.exe
2009-03-20 23:02 . 2009-03-20 23:02 360,192 --a------ c:\windows\system32\TuneUpDefragService.exe
2009-03-20 23:02 . 2008-12-11 14:31 27,904 --a------ c:\windows\system32\uxtuneup.dll
2009-03-20 23:01 . 2009-03-20 23:02 <DIR> d-------- c:\program files\TuneUp Utilities 2009
2009-03-20 22:40 . 2009-03-20 22:40 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Styler
2009-03-20 22:37 . 2009-03-20 22:40 <DIR> d-------- c:\program files\Styler
2009-03-20 21:23 . 2002-08-12 17:20 27,264 --a------ c:\windows\system32\drivers\rndismpk.sys
2009-03-20 21:23 . 2002-08-12 17:20 11,136 --a------ c:\windows\system32\drivers\usb8023k.sys
2009-03-20 17:30 . 2009-03-20 17:30 256 --a------ C:\dk2.mem
2009-03-20 17:02 . 2009-03-20 17:02 <DIR> d-------- c:\program files\Common Files\Nokia
2009-03-20 17:02 . 2009-03-20 17:02 <DIR> d-------- c:\program files\Common Files\DESkey
2009-03-20 17:02 . 2009-03-20 17:02 2,325,304 --a------ c:\windows\system32\DK2INST.DLL
2009-03-20 17:01 . 2009-03-20 23:26 <DIR> d-------- c:\program files\Nokia
2009-03-20 17:01 . 2008-02-01 17:17 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2009-03-20 17:00 . 2009-03-20 17:00 <DIR> d-------- c:\program files\MSXML 6.0
2009-03-20 16:53 . 2008-04-14 08:52 219,648 --a------ c:\windows\system32\uxtheme.uxtender
2009-03-19 11:45 . 2009-03-19 11:45 131,976 --a------ c:\windows\system32\drivers\epfw.sys
2009-03-19 11:45 . 2009-03-19 11:45 55,768 --a------ c:\windows\system32\drivers\epfwtdi.sys
2009-03-19 11:45 . 2009-03-19 11:45 33,096 --a------ c:\windows\system32\drivers\epfwndis.sys
2009-03-19 11:44 . 2009-03-19 11:44 107,256 --a------ c:\windows\system32\drivers\ehdrv.sys
2009-03-19 11:41 . 2009-03-19 11:41 113,960 --a------ c:\windows\system32\drivers\eamon.sys
2009-03-15 10:17 . 2009-03-15 11:05 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\BMC
2009-03-15 10:15 . 2009-03-20 23:28 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-15 10:15 . 2009-03-15 10:15 91,136 --a------ c:\windows\system32\drivers\susbser.sys
2009-03-15 10:15 . 2008-04-14 01:15 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-03-15 10:15 . 2008-04-14 01:15 32,128 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-03-12 19:20 . 2009-03-12 19:20 <DIR> d-------- c:\program files\WinSCP
2009-03-12 18:12 . 2009-03-12 18:12 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\OpenOffice.org
2009-03-12 17:51 . 2009-03-12 17:53 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\vlc
2009-03-12 17:51 . 2009-03-14 19:04 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\dvdcss
2009-03-11 14:41 . 2009-03-11 14:41 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-03-11 14:40 . 2006-06-29 14:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-03-11 14:30 . 2009-03-11 14:40 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-11 14:29 . 2009-03-11 14:29 <DIR> d-------- c:\program files\Reference Assemblies
2009-03-11 14:28 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-11 14:28 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-11 14:28 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-11 14:28 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-11 14:28 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-11 14:28 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-11 14:28 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-11 14:22 . 2009-03-11 14:22 <DIR> d-------- c:\program files\Microsoft
2009-03-11 14:21 . 2009-03-11 14:21 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Windows Desktop Search
2009-03-11 14:20 . 2009-03-11 14:20 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-03-11 14:20 . 2009-03-11 14:20 <DIR> d-------- c:\program files\Windows Desktop Search
2009-03-11 14:18 . 2009-03-11 14:18 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-03-11 14:16 . 2009-03-11 14:16 <DIR> d-------- c:\windows\system32\LogFiles
2009-03-11 14:16 . 2009-03-11 14:17 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-03-11 14:13 . 2009-03-11 14:14 <DIR> d-------- c:\windows\system32\URTTemp
2009-03-11 09:00 . 2008-12-21 01:03 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-03-11 09:00 . 2007-04-17 11:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-03-11 09:00 . 2007-03-08 07:09 1,024,000 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-11 09:00 . 2008-12-21 01:03 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-03-11 09:00 . 2008-12-21 01:03 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-11 09:00 . 2008-12-21 01:03 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-03-11 09:00 . 2008-12-21 01:03 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-03-11 09:00 . 2008-12-21 01:03 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-11 09:00 . 2008-12-19 11:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-03-09 07:42 . 2008-10-16 15:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-09 07:42 . 2008-10-16 15:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-09 07:42 . 2008-10-16 15:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-03-08 22:16 . 2009-03-29 15:12 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\gtk-2.0
2009-03-08 22:16 . 2009-03-08 22:16 <DIR> d-------- c:\documents and settings\Administrator\.thumbnails
2009-03-08 22:15 . 2009-03-29 15:12 <DIR> d-------- c:\documents and settings\Administrator\.gimp-2.6
2009-03-08 22:15 . 2009-03-08 22:15 <DIR> d-------- c:\documents and settings\Administrator\.gegl-0.0
2009-03-08 22:13 . 2009-03-08 22:13 <DIR> d-------- c:\program files\GIMP-2.0
2009-03-08 11:34 . 2008-04-14 01:15 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-06 19:41 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Skype
2009-04-06 18:44 --------- d-----w c:\documents and settings\Administrator\Data aplikací\skypePM
2009-04-05 13:31 --------- d-----w c:\program files\foobar2000
2009-04-05 08:56 --------- d-----w c:\documents and settings\All Users\Data aplikací\ESET
2009-04-05 07:13 --------- d-----w c:\program files\Krteček 2.1.3
2009-03-29 12:42 --------- d-----w c:\program files\QIP Infium
2009-03-21 14:27 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-21 14:27 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-20 15:02 92,984 ----a-w c:\windows\system32\DNClnt32.dll
2009-03-20 15:02 92,984 ----a-w c:\windows\system32\dkcpanel.exe
2009-03-20 15:02 89,400 ----a-w c:\windows\system32\DNCP32.DLL
2009-03-20 15:02 76,600 ----a-w c:\windows\system32\dk2cp32.dll
2009-03-20 15:02 64,312 ----a-w c:\windows\system32\vercp32.dll
2009-03-20 15:02 49,720 ----a-w c:\windows\system32\drivers\dk2drv.sys
2009-03-20 15:02 32,208 ----a-w c:\windows\system32\dk2win16.dll
2009-03-20 15:02 30,520 ----a-w c:\windows\system32\DK2UInst.exe
2009-03-20 15:02 24,488 ----a-w c:\windows\system32\dk2vdd.dll
2009-03-20 15:02 18,360 ----a-w c:\windows\system32\drivers\DK2USB.sys
2009-03-20 15:02 14,856 ----a-w c:\windows\system32\drivers\dkpccard.sys
2009-03-20 15:02 11,576 ----a-w c:\windows\system32\DKCLINST.DLL
2009-03-20 14:53 219,648 ----a-w c:\windows\system32\uxtheme.dll
2009-03-17 18:02 --------- d-----w c:\program files\ICQ6.5
2009-03-17 18:02 --------- d-----w c:\documents and settings\Administrator\Data aplikací\ICQ
2009-03-11 12:29 --------- d-----w c:\program files\MSBuild
2009-03-11 06:50 --------- d-----w c:\documents and settings\All Users\Data aplikací\Microsoft Help
2009-03-07 21:24 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Media Player Classic
2009-03-07 10:40 --------- d-----w c:\program files\VideoLAN
2009-03-07 10:37 --------- d-----w c:\program files\Common Files\Skype
2009-03-07 10:37 --------- d-----w c:\documents and settings\All Users\Data aplikací\Skype
2009-03-07 10:37 --------- d-----r c:\program files\Skype
2009-03-07 10:25 --------- d-----w c:\documents and settings\Administrator\Data aplikací\PSpad
2009-03-07 10:24 --------- d-----w c:\program files\PSPad editor
2009-03-07 10:16 --------- d-----w c:\program files\OpenOffice.org 3
2009-03-07 09:52 --------- d-----w c:\program files\Microsoft Works
2009-03-07 09:20 --------- d--h--w c:\program files\CanonBJ
2009-03-07 09:20 --------- d--h--w c:\documents and settings\All Users\Data aplikací\CanonBJ
2009-03-07 09:16 --------- d-----w c:\documents and settings\Administrator\Data aplikací\QIP
2009-03-07 09:06 --------- d-----w c:\documents and settings\All Users\Data aplikací\ashampoo
2009-03-07 09:06 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Ashampoo
2009-03-07 09:05 --------- d-----w c:\program files\Ashampoo
2009-03-07 09:04 --------- d-----w c:\program files\Foxit Software
2009-03-07 09:04 --------- d-----w c:\program files\AskBarDis
2009-03-07 09:04 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Foxit
2009-03-07 08:51 --------- d-----w c:\documents and settings\Administrator\Data aplikací\TuneUp Software
2009-03-07 08:50 --------- d-sh--w c:\documents and settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-07 08:50 --------- d-----w c:\documents and settings\All Users\Data aplikací\TuneUp Software
2009-03-07 08:36 --------- d-----w c:\program files\SpeedProject
2009-03-07 08:36 --------- d-----w c:\documents and settings\Administrator\Data aplikací\SpeedProject
2009-03-07 08:13 --------- d-----w c:\program files\VIA
2009-03-07 08:05 --------- d-----w c:\program files\Opera
2009-03-07 07:18 --------- d-----w c:\documents and settings\Administrator\Data aplikací\ESET
2009-03-07 07:13 --------- d-----w c:\program files\7-Zip
2009-03-07 06:33 --------- d-----w c:\program files\microsoft frontpage
2009-02-09 14:07 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-04 05:57 11,702,272 ----a-w c:\windows\system32\atioglxx.dll
2009-02-04 05:03 290,816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-04 04:56 442,368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-04 04:55 324,096 ----a-w c:\windows\system32\ati2dvag.dll
2009-02-04 04:44 196,608 ----a-w c:\windows\system32\atipdlxx.dll
2009-02-04 04:44 155,648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-04 04:43 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2009-02-04 04:43 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-02-04 04:43 155,648 ----a-w c:\windows\system32\ati2evxx.dll
2009-02-04 04:41 602,112 ----a-w c:\windows\system32\ati2evxx.exe
2009-02-04 04:40 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-02-04 04:30 3,884,768 ----a-w c:\windows\system32\ati3duag.dll
2009-02-04 04:14 2,645,504 ----a-w c:\windows\system32\ativvaxx.dll
2009-02-04 03:58 49,664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-04 03:54 471,040 ----a-w c:\windows\system32\atikvmag.dll
2009-02-04 03:53 122,880 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-04 03:52 17,408 ----a-w c:\windows\system32\atitvo32.dll
2009-02-04 03:46 626,688 ----a-w c:\windows\system32\ati2cqag.dll
2009-02-04 03:44 307,200 ----a-w c:\windows\system32\atiiiexx.dll
2009-02-04 02:43 45,056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-04 02:42 45,056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-04 02:40 3,244,032 ----a-w c:\windows\system32\aticaldd.dll
2009-02-03 20:05 593,920 ------w c:\windows\system32\ati2sgag.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 13:58 333192 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"FLSDeviceControlPanel"="c:\windows\system32\FLSDEVCP.EXE" [2009-03-20 91696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-28 148888]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Styler.lnk - c:\documents and settings\Administrator\Data aplikacˇ\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-03-20 15086]
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Styler.lnk - c:\documents and settings\Administrator\Data aplikacˇ\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-03-20 15086]
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Styler.lnk - c:\documents and settings\Administrator\Data aplikacˇ\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-03-20 15086]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
TSS Instrument API Tray Utility.lnk - c:\program files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe [2007-12-07 77824]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Tss\\Instrument API\\bin\\root.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 dk2drv;DK2 WindowsNT Driver;c:\windows\system32\drivers\dk2drv.sys [2009-03-20 49720]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-03-19 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-03-19 731840]
R2 FLE5WNNT;FLE-5 WindowsNT Driver;c:\windows\system32\drivers\fle5wnnt.sys [2009-03-20 33404]
R2 FLSIFACE;FLSIface;c:\windows\system32\drivers\flsiface.sys [2009-03-20 13440]
R2 FLSPAR;FLSPar;c:\windows\system32\drivers\flspar.sys [2009-03-20 16314]
R2 FLSSER;FLSSer;c:\windows\system32\drivers\flsser.sys [2009-03-20 8344]
R2 FLSVCOM;FLSVCom;c:\windows\system32\drivers\flsvcom.sys [2009-03-20 34048]
R2 PARLDR2K;ParLdr2k;c:\windows\system32\drivers\parldr2k.sys [2009-03-20 10454]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-03-20 603904]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2008-04-14 69120]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2002-12-05 3584]
S3 G Data Tuner Service;G Data Tuner Service;c:\program files\G DATA\TotalCare\AVKTuner\AVKTunerService.exe --> c:\program files\G DATA\TotalCare\AVKTuner\AVKTunerService.exe [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2009-04-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 22:36]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
.
------- Asociace souborů -------
.
txtfile="c:\program files\PSPad editor\PSPad.exe" "%1"
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 18:54:06
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthtpdwqpqxumfasrnvpfyfsjwcdovphowf]
"imagepath"="\systemroot\system32\drivers\ovfsthssxckbmwoofbmkllnhlraddlkrdrwyqw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\14d595e7]
"ImagePath"="\SystemRoot\System32\drivers\14d595e7.sys"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\s-1-5-21-515967899-1383384898-1060284298-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\s-1-5-21-515967899-1383384898-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2009-04-08 18:55:49
ComboFix-quarantined-files.txt 2009-04-08 16:55:46
Před spuštěním: 9 309 700 096
Po spuštění: 9,725,366,272
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=K9V8AX /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=K9V8AX-BAK
306 --- E O F --- 2009-03-21 10:00:44
Malwarebytes' Anti-Malware 1.36
Verze databáze: 1952
Windows 5.1.2600 Service Pack 3
8.4.2009 20:11:17
mbam-log-2009-04-08 (20-11-17).txt
Typ skenu: Rychlý sken
Objektu skenováno: 70526
Uplynulý cas: 4 minute(s), 26 second(s)
Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)
Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)
Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované složky:
(Žádné zákerné položky nebyly zjišteny)
Infikované soubory:
(Žádné zákerné položky nebyly zjišteny)
ComboFix 09-04-04.01 - Administrator 2009-04-08 18:52:06.1 - NTFSx86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.767.443 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *disabled*
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-03-08 do 2009-04-08 )))))))))))))))))))))))))))))))
.
2009-04-08 18:39 . 2009-04-08 18:39 155 --a------ c:\windows\system32\SelfDel.bat
2009-04-08 18:38 . 2009-04-08 18:39 84,045 --a------ c:\windows\system32\ftp_non_crp.exe
2009-04-05 11:24 . 2009-04-05 11:24 <DIR> d-------- c:\program files\ESET
2009-04-05 10:31 . 2009-04-08 18:54 105,170 --a------ c:\windows\system32\drivers\14d595e7.sys
2009-04-05 10:28 . 2009-04-05 10:28 50,632 --a------ c:\windows\system32\drivers\MiniIcpt.sys
2009-04-05 10:25 . 2009-04-05 10:25 <DIR> d--hs---- C:\#GDATA.Trash.Store#
2009-04-05 10:25 . 2009-04-05 10:25 51,016 --a------ c:\windows\system32\drivers\GDTdiIcpt.sys
2009-04-05 10:25 . 2009-04-05 10:25 22,272 --a------ c:\windows\system32\drivers\GDNdisIc.sys
2009-04-05 10:24 . 2009-04-05 10:45 <DIR> d-------- c:\program files\G DATA
2009-04-05 10:24 . 2009-04-05 10:47 <DIR> d-------- c:\program files\Common Files\G DATA
2009-04-05 10:24 . 2009-04-05 10:45 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\G DATA
2009-04-05 10:07 . 2009-04-05 10:07 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2009-04-05 10:07 . 2009-04-05 10:07 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Symantec
2009-03-29 15:28 . 2009-03-29 15:28 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Windows Search
2009-03-28 23:48 . 2009-03-28 23:48 <DIR> d-------- c:\documents and settings\All Users\Data aplikací\Azureus
2009-03-28 23:48 . 2009-03-29 00:17 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Azureus
2009-03-28 23:47 . 2009-03-28 23:48 <DIR> d-------- c:\program files\Vuze
2009-03-28 23:46 . 2009-03-28 23:45 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-28 23:46 . 2009-03-28 23:45 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-28 23:45 . 2009-03-28 23:45 <DIR> d-------- c:\program files\Java
2009-03-28 09:26 . 2008-03-03 15:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2009-03-28 09:26 . 2008-03-03 19:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2009-03-28 09:14 . 2009-03-28 09:14 <DIR> d-------- c:\windows\system32\config\systemprofile\Data aplikací\ESET
2009-03-28 09:14 . 2009-03-28 09:14 <DIR> d-------- c:\windows\system32\config\systemprofile\Data aplikací\ESET
2009-03-21 16:27 . 2009-03-21 16:27 <DIR> d-------- c:\windows\zy_tmp
2009-03-21 16:27 . 2004-08-17 12:23 5,120 --a------ c:\windows\system32\tcusbdrv.dll
2009-03-21 13:31 . 2001-10-24 12:54 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2009-03-21 13:31 . 2001-10-24 12:54 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2009-03-21 13:30 . 2008-04-14 01:15 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-03-21 13:30 . 2008-04-14 01:15 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2009-03-21 12:00 . 2009-03-21 12:00 <DIR> d-------- c:\program files\MSXML 4.0
2009-03-20 23:28 . 2009-03-20 23:28 4,263 --a------ c:\windows\system32\FLSINSTU.INI
2009-03-20 23:05 . 2009-03-20 23:05 2,331,008 --a------ c:\windows\system32\TUKernel.exe
2009-03-20 23:03 . 2009-03-20 23:03 <DIR> d-------- c:\program files\Stardock
2009-03-20 23:03 . 2009-03-20 23:03 <DIR> d--h-c--- c:\documents and settings\All Users\Data aplikací\{B98A2B83-8BB0-42E7-AA1D-D6FA6E7C8F31}
2009-03-20 23:02 . 2009-03-20 23:02 603,904 --a------ c:\windows\system32\TUProgSt.exe
2009-03-20 23:02 . 2009-03-20 23:02 360,192 --a------ c:\windows\system32\TuneUpDefragService.exe
2009-03-20 23:02 . 2008-12-11 14:31 27,904 --a------ c:\windows\system32\uxtuneup.dll
2009-03-20 23:01 . 2009-03-20 23:02 <DIR> d-------- c:\program files\TuneUp Utilities 2009
2009-03-20 22:40 . 2009-03-20 22:40 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Styler
2009-03-20 22:37 . 2009-03-20 22:40 <DIR> d-------- c:\program files\Styler
2009-03-20 21:23 . 2002-08-12 17:20 27,264 --a------ c:\windows\system32\drivers\rndismpk.sys
2009-03-20 21:23 . 2002-08-12 17:20 11,136 --a------ c:\windows\system32\drivers\usb8023k.sys
2009-03-20 17:30 . 2009-03-20 17:30 256 --a------ C:\dk2.mem
2009-03-20 17:02 . 2009-03-20 17:02 <DIR> d-------- c:\program files\Common Files\Nokia
2009-03-20 17:02 . 2009-03-20 17:02 <DIR> d-------- c:\program files\Common Files\DESkey
2009-03-20 17:02 . 2009-03-20 17:02 2,325,304 --a------ c:\windows\system32\DK2INST.DLL
2009-03-20 17:01 . 2009-03-20 23:26 <DIR> d-------- c:\program files\Nokia
2009-03-20 17:01 . 2008-02-01 17:17 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2009-03-20 17:00 . 2009-03-20 17:00 <DIR> d-------- c:\program files\MSXML 6.0
2009-03-20 16:53 . 2008-04-14 08:52 219,648 --a------ c:\windows\system32\uxtheme.uxtender
2009-03-19 11:45 . 2009-03-19 11:45 131,976 --a------ c:\windows\system32\drivers\epfw.sys
2009-03-19 11:45 . 2009-03-19 11:45 55,768 --a------ c:\windows\system32\drivers\epfwtdi.sys
2009-03-19 11:45 . 2009-03-19 11:45 33,096 --a------ c:\windows\system32\drivers\epfwndis.sys
2009-03-19 11:44 . 2009-03-19 11:44 107,256 --a------ c:\windows\system32\drivers\ehdrv.sys
2009-03-19 11:41 . 2009-03-19 11:41 113,960 --a------ c:\windows\system32\drivers\eamon.sys
2009-03-15 10:17 . 2009-03-15 11:05 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\BMC
2009-03-15 10:15 . 2009-03-20 23:28 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-15 10:15 . 2009-03-15 10:15 91,136 --a------ c:\windows\system32\drivers\susbser.sys
2009-03-15 10:15 . 2008-04-14 01:15 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-03-15 10:15 . 2008-04-14 01:15 32,128 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-03-12 19:20 . 2009-03-12 19:20 <DIR> d-------- c:\program files\WinSCP
2009-03-12 18:12 . 2009-03-12 18:12 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\OpenOffice.org
2009-03-12 17:51 . 2009-03-12 17:53 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\vlc
2009-03-12 17:51 . 2009-03-14 19:04 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\dvdcss
2009-03-11 14:41 . 2009-03-11 14:41 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-03-11 14:40 . 2006-06-29 14:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-03-11 14:30 . 2009-03-11 14:40 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-11 14:29 . 2009-03-11 14:29 <DIR> d-------- c:\program files\Reference Assemblies
2009-03-11 14:28 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-11 14:28 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-11 14:28 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-11 14:28 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-11 14:28 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-11 14:28 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-11 14:28 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-11 14:22 . 2009-03-11 14:22 <DIR> d-------- c:\program files\Microsoft
2009-03-11 14:21 . 2009-03-11 14:21 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\Windows Desktop Search
2009-03-11 14:20 . 2009-03-11 14:20 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-03-11 14:20 . 2009-03-11 14:20 <DIR> d-------- c:\program files\Windows Desktop Search
2009-03-11 14:18 . 2009-03-11 14:18 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-03-11 14:16 . 2009-03-11 14:16 <DIR> d-------- c:\windows\system32\LogFiles
2009-03-11 14:16 . 2009-03-11 14:17 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-03-11 14:13 . 2009-03-11 14:14 <DIR> d-------- c:\windows\system32\URTTemp
2009-03-11 09:00 . 2008-12-21 01:03 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-03-11 09:00 . 2007-04-17 11:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-03-11 09:00 . 2007-03-08 07:09 1,024,000 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-11 09:00 . 2008-12-21 01:03 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-03-11 09:00 . 2008-12-21 01:03 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-11 09:00 . 2008-12-21 01:03 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-03-11 09:00 . 2008-12-21 01:03 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-03-11 09:00 . 2008-12-21 01:03 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-11 09:00 . 2008-12-19 11:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-03-09 07:42 . 2008-10-16 15:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-09 07:42 . 2008-10-16 15:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-09 07:42 . 2008-10-16 15:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-03-08 22:16 . 2009-03-29 15:12 <DIR> d-------- c:\documents and settings\Administrator\Data aplikací\gtk-2.0
2009-03-08 22:16 . 2009-03-08 22:16 <DIR> d-------- c:\documents and settings\Administrator\.thumbnails
2009-03-08 22:15 . 2009-03-29 15:12 <DIR> d-------- c:\documents and settings\Administrator\.gimp-2.6
2009-03-08 22:15 . 2009-03-08 22:15 <DIR> d-------- c:\documents and settings\Administrator\.gegl-0.0
2009-03-08 22:13 . 2009-03-08 22:13 <DIR> d-------- c:\program files\GIMP-2.0
2009-03-08 11:34 . 2008-04-14 01:15 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-06 19:41 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Skype
2009-04-06 18:44 --------- d-----w c:\documents and settings\Administrator\Data aplikací\skypePM
2009-04-05 13:31 --------- d-----w c:\program files\foobar2000
2009-04-05 08:56 --------- d-----w c:\documents and settings\All Users\Data aplikací\ESET
2009-04-05 07:13 --------- d-----w c:\program files\Krteček 2.1.3
2009-03-29 12:42 --------- d-----w c:\program files\QIP Infium
2009-03-21 14:27 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-21 14:27 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-20 15:02 92,984 ----a-w c:\windows\system32\DNClnt32.dll
2009-03-20 15:02 92,984 ----a-w c:\windows\system32\dkcpanel.exe
2009-03-20 15:02 89,400 ----a-w c:\windows\system32\DNCP32.DLL
2009-03-20 15:02 76,600 ----a-w c:\windows\system32\dk2cp32.dll
2009-03-20 15:02 64,312 ----a-w c:\windows\system32\vercp32.dll
2009-03-20 15:02 49,720 ----a-w c:\windows\system32\drivers\dk2drv.sys
2009-03-20 15:02 32,208 ----a-w c:\windows\system32\dk2win16.dll
2009-03-20 15:02 30,520 ----a-w c:\windows\system32\DK2UInst.exe
2009-03-20 15:02 24,488 ----a-w c:\windows\system32\dk2vdd.dll
2009-03-20 15:02 18,360 ----a-w c:\windows\system32\drivers\DK2USB.sys
2009-03-20 15:02 14,856 ----a-w c:\windows\system32\drivers\dkpccard.sys
2009-03-20 15:02 11,576 ----a-w c:\windows\system32\DKCLINST.DLL
2009-03-20 14:53 219,648 ----a-w c:\windows\system32\uxtheme.dll
2009-03-17 18:02 --------- d-----w c:\program files\ICQ6.5
2009-03-17 18:02 --------- d-----w c:\documents and settings\Administrator\Data aplikací\ICQ
2009-03-11 12:29 --------- d-----w c:\program files\MSBuild
2009-03-11 06:50 --------- d-----w c:\documents and settings\All Users\Data aplikací\Microsoft Help
2009-03-07 21:24 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Media Player Classic
2009-03-07 10:40 --------- d-----w c:\program files\VideoLAN
2009-03-07 10:37 --------- d-----w c:\program files\Common Files\Skype
2009-03-07 10:37 --------- d-----w c:\documents and settings\All Users\Data aplikací\Skype
2009-03-07 10:37 --------- d-----r c:\program files\Skype
2009-03-07 10:25 --------- d-----w c:\documents and settings\Administrator\Data aplikací\PSpad
2009-03-07 10:24 --------- d-----w c:\program files\PSPad editor
2009-03-07 10:16 --------- d-----w c:\program files\OpenOffice.org 3
2009-03-07 09:52 --------- d-----w c:\program files\Microsoft Works
2009-03-07 09:20 --------- d--h--w c:\program files\CanonBJ
2009-03-07 09:20 --------- d--h--w c:\documents and settings\All Users\Data aplikací\CanonBJ
2009-03-07 09:16 --------- d-----w c:\documents and settings\Administrator\Data aplikací\QIP
2009-03-07 09:06 --------- d-----w c:\documents and settings\All Users\Data aplikací\ashampoo
2009-03-07 09:06 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Ashampoo
2009-03-07 09:05 --------- d-----w c:\program files\Ashampoo
2009-03-07 09:04 --------- d-----w c:\program files\Foxit Software
2009-03-07 09:04 --------- d-----w c:\program files\AskBarDis
2009-03-07 09:04 --------- d-----w c:\documents and settings\Administrator\Data aplikací\Foxit
2009-03-07 08:51 --------- d-----w c:\documents and settings\Administrator\Data aplikací\TuneUp Software
2009-03-07 08:50 --------- d-sh--w c:\documents and settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-07 08:50 --------- d-----w c:\documents and settings\All Users\Data aplikací\TuneUp Software
2009-03-07 08:36 --------- d-----w c:\program files\SpeedProject
2009-03-07 08:36 --------- d-----w c:\documents and settings\Administrator\Data aplikací\SpeedProject
2009-03-07 08:13 --------- d-----w c:\program files\VIA
2009-03-07 08:05 --------- d-----w c:\program files\Opera
2009-03-07 07:18 --------- d-----w c:\documents and settings\Administrator\Data aplikací\ESET
2009-03-07 07:13 --------- d-----w c:\program files\7-Zip
2009-03-07 06:33 --------- d-----w c:\program files\microsoft frontpage
2009-02-09 14:07 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-04 05:57 11,702,272 ----a-w c:\windows\system32\atioglxx.dll
2009-02-04 05:03 290,816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-04 04:56 442,368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-04 04:55 324,096 ----a-w c:\windows\system32\ati2dvag.dll
2009-02-04 04:44 196,608 ----a-w c:\windows\system32\atipdlxx.dll
2009-02-04 04:44 155,648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-04 04:43 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2009-02-04 04:43 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-02-04 04:43 155,648 ----a-w c:\windows\system32\ati2evxx.dll
2009-02-04 04:41 602,112 ----a-w c:\windows\system32\ati2evxx.exe
2009-02-04 04:40 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-02-04 04:30 3,884,768 ----a-w c:\windows\system32\ati3duag.dll
2009-02-04 04:14 2,645,504 ----a-w c:\windows\system32\ativvaxx.dll
2009-02-04 03:58 49,664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-04 03:54 471,040 ----a-w c:\windows\system32\atikvmag.dll
2009-02-04 03:53 122,880 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-04 03:52 17,408 ----a-w c:\windows\system32\atitvo32.dll
2009-02-04 03:46 626,688 ----a-w c:\windows\system32\ati2cqag.dll
2009-02-04 03:44 307,200 ----a-w c:\windows\system32\atiiiexx.dll
2009-02-04 02:43 45,056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-04 02:42 45,056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-04 02:40 3,244,032 ----a-w c:\windows\system32\aticaldd.dll
2009-02-03 20:05 593,920 ------w c:\windows\system32\ati2sgag.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 13:58 333192 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"FLSDeviceControlPanel"="c:\windows\system32\FLSDEVCP.EXE" [2009-03-20 91696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-28 148888]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Styler.lnk - c:\documents and settings\Administrator\Data aplikacˇ\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-03-20 15086]
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Styler.lnk - c:\documents and settings\Administrator\Data aplikacˇ\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-03-20 15086]
c:\documents and settings\Administrator\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Styler.lnk - c:\documents and settings\Administrator\Data aplikacˇ\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-03-20 15086]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
TSS Instrument API Tray Utility.lnk - c:\program files\Common Files\Nokia\Tss\Instrument API\bin\tray.exe [2007-12-07 77824]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Tss\\Instrument API\\bin\\root.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 dk2drv;DK2 WindowsNT Driver;c:\windows\system32\drivers\dk2drv.sys [2009-03-20 49720]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-03-19 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-03-19 731840]
R2 FLE5WNNT;FLE-5 WindowsNT Driver;c:\windows\system32\drivers\fle5wnnt.sys [2009-03-20 33404]
R2 FLSIFACE;FLSIface;c:\windows\system32\drivers\flsiface.sys [2009-03-20 13440]
R2 FLSPAR;FLSPar;c:\windows\system32\drivers\flspar.sys [2009-03-20 16314]
R2 FLSSER;FLSSer;c:\windows\system32\drivers\flsser.sys [2009-03-20 8344]
R2 FLSVCOM;FLSVCom;c:\windows\system32\drivers\flsvcom.sys [2009-03-20 34048]
R2 PARLDR2K;ParLdr2k;c:\windows\system32\drivers\parldr2k.sys [2009-03-20 10454]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-03-20 603904]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2008-04-14 69120]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2002-12-05 3584]
S3 G Data Tuner Service;G Data Tuner Service;c:\program files\G DATA\TotalCare\AVKTuner\AVKTunerService.exe --> c:\program files\G DATA\TotalCare\AVKTuner\AVKTunerService.exe [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2009-04-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 22:36]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
.
------- Asociace souborů -------
.
txtfile="c:\program files\PSPad editor\PSPad.exe" "%1"
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-08 18:54:06
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ovfsthtpdwqpqxumfasrnvpfyfsjwcdovphowf]
"imagepath"="\systemroot\system32\drivers\ovfsthssxckbmwoofbmkllnhlraddlkrdrwyqw.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\14d595e7]
"ImagePath"="\SystemRoot\System32\drivers\14d595e7.sys"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\s-1-5-21-515967899-1383384898-1060284298-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\s-1-5-21-515967899-1383384898-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2009-04-08 18:55:49
ComboFix-quarantined-files.txt 2009-04-08 16:55:46
Před spuštěním: 9 309 700 096
Po spuštění: 9,725,366,272
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /TUTag=K9V8AX /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=K9V8AX-BAK
306 --- E O F --- 2009-03-21 10:00:44
Malwarebytes' Anti-Malware 1.36
Verze databáze: 1952
Windows 5.1.2600 Service Pack 3
8.4.2009 20:11:17
mbam-log-2009-04-08 (20-11-17).txt
Typ skenu: Rychlý sken
Objektu skenováno: 70526
Uplynulý cas: 4 minute(s), 26 second(s)
Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)
Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)
Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované položky dat registru:
(Žádné zákerné položky nebyly zjišteny)
Infikované složky:
(Žádné zákerné položky nebyly zjišteny)
Infikované soubory:
(Žádné zákerné položky nebyly zjišteny)