tak tady je log z Combofixu.
ComboFix 09-04-14.09 - HUBKA 14.04.2009 19:27.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.511.203 [GMT 2:00]
Spuštěný z: c:\documents and settings\HUBKA\WINDOWS\Plocha\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *enabled*
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HUBKA\Data aplikací\inst.exe
c:\windows\regedit.com
c:\windows\system32\_003673_.tmp.dll
c:\windows\system32\_003674_.tmp.dll
c:\windows\system32\_003675_.tmp.dll
c:\windows\system32\_003676_.tmp.dll
c:\windows\system32\_003682_.tmp.dll
c:\windows\system32\_003683_.tmp.dll
c:\windows\system32\_003684_.tmp.dll
c:\windows\system32\_003685_.tmp.dll
c:\windows\system32\_003686_.tmp.dll
c:\windows\system32\_003687_.tmp.dll
c:\windows\system32\_003688_.tmp.dll
c:\windows\system32\_003689_.tmp.dll
c:\windows\system32\_003690_.tmp.dll
c:\windows\system32\_003691_.tmp.dll
c:\windows\system32\_003692_.tmp.dll
c:\windows\system32\_003693_.tmp.dll
c:\windows\system32\_003694_.tmp.dll
c:\windows\system32\_003695_.tmp.dll
c:\windows\system32\_003696_.tmp.dll
c:\windows\system32\_003697_.tmp.dll
c:\windows\system32\_003698_.tmp.dll
c:\windows\system32\_003699_.tmp.dll
c:\windows\system32\_003700_.tmp.dll
c:\windows\system32\_003701_.tmp.dll
c:\windows\system32\_003702_.tmp.dll
c:\windows\system32\_003703_.tmp.dll
c:\windows\system32\_003704_.tmp.dll
c:\windows\system32\_003705_.tmp.dll
c:\windows\system32\_003706_.tmp.dll
c:\windows\system32\_003707_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003712_.tmp.dll
c:\windows\system32\_003713_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003719_.tmp.dll
c:\windows\system32\_003720_.tmp.dll
c:\windows\system32\_003721_.tmp.dll
c:\windows\system32\_003722_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003724_.tmp.dll
c:\windows\system32\_003725_.tmp.dll
c:\windows\system32\_003726_.tmp.dll
c:\windows\system32\_003727_.tmp.dll
c:\windows\system32\_003728_.tmp.dll
c:\windows\system32\_003729_.tmp.dll
c:\windows\system32\_003730_.tmp.dll
c:\windows\system32\_003731_.tmp.dll
c:\windows\system32\_003732_.tmp.dll
c:\windows\system32\_003733_.tmp.dll
c:\windows\system32\_003734_.tmp.dll
c:\windows\system32\_003735_.tmp.dll
c:\windows\system32\_003736_.tmp.dll
c:\windows\system32\_003737_.tmp.dll
c:\windows\system32\_003738_.tmp.dll
c:\windows\system32\_003739_.tmp.dll
c:\windows\system32\_003740_.tmp.dll
c:\windows\system32\_003741_.tmp.dll
c:\windows\system32\_003742_.tmp.dll
c:\windows\system32\_003743_.tmp.dll
c:\windows\system32\_003744_.tmp.dll
c:\windows\system32\_003745_.tmp.dll
c:\windows\system32\_003746_.tmp.dll
c:\windows\system32\_003747_.tmp.dll
c:\windows\system32\_003748_.tmp.dll
c:\windows\system32\_003749_.tmp.dll
c:\windows\system32\_003750_.tmp.dll
c:\windows\system32\_003751_.tmp.dll
c:\windows\system32\_003752_.tmp.dll
c:\windows\system32\_003753_.tmp.dll
c:\windows\system32\_003754_.tmp.dll
c:\windows\system32\_003755_.tmp.dll
c:\windows\system32\_003756_.tmp.dll
c:\windows\system32\_003757_.tmp.dll
c:\windows\system32\_003758_.tmp.dll
c:\windows\system32\_003759_.tmp.dll
c:\windows\system32\_003760_.tmp.dll
c:\windows\system32\_003761_.tmp.dll
c:\windows\system32\_003762_.tmp.dll
c:\windows\system32\_003763_.tmp.dll
c:\windows\system32\_003764_.tmp.dll
c:\windows\system32\_003765_.tmp.dll
c:\windows\system32\_003766_.tmp.dll
c:\windows\system32\_003767_.tmp.dll
c:\windows\system32\_003768_.tmp.dll
c:\windows\system32\_003769_.tmp.dll
c:\windows\system32\_003770_.tmp.dll
c:\windows\system32\_003771_.tmp.dll
c:\windows\system32\_003772_.tmp.dll
c:\windows\system32\_003774_.tmp.dll
c:\windows\system32\_003775_.tmp.dll
c:\windows\system32\_003777_.tmp.dll
c:\windows\system32\_003778_.tmp.dll
c:\windows\system32\_003779_.tmp.dll
c:\windows\system32\_003780_.tmp.dll
c:\windows\system32\_003782_.tmp.dll
c:\windows\system32\_003783_.tmp.dll
c:\windows\system32\_003784_.tmp.dll
c:\windows\system32\_003785_.tmp.dll
c:\windows\system32\_003786_.tmp.dll
c:\windows\system32\_003787_.tmp.dll
c:\windows\system32\_003788_.tmp.dll
c:\windows\system32\_003789_.tmp.dll
c:\windows\system32\_003790_.tmp.dll
c:\windows\system32\_003791_.tmp.dll
c:\windows\system32\_003792_.tmp.dll
c:\windows\system32\_003793_.tmp.dll
c:\windows\system32\_003794_.tmp.dll
c:\windows\system32\_003795_.tmp.dll
c:\windows\system32\_003796_.tmp.dll
c:\windows\system32\_003797_.tmp.dll
c:\windows\system32\_003799_.tmp.dll
c:\windows\system32\_003800_.tmp.dll
c:\windows\system32\_003801_.tmp.dll
c:\windows\system32\_003802_.tmp.dll
c:\windows\system32\_003803_.tmp.dll
c:\windows\system32\_003805_.tmp.dll
c:\windows\system32\_003806_.tmp.dll
c:\windows\system32\_003808_.tmp.dll
c:\windows\system32\_003809_.tmp.dll
c:\windows\system32\_003810_.tmp.dll
c:\windows\system32\_003811_.tmp.dll
c:\windows\system32\_003813_.tmp.dll
c:\windows\system32\_003814_.tmp.dll
c:\windows\system32\_003815_.tmp.dll
c:\windows\system32\_003816_.tmp.dll
c:\windows\system32\_003817_.tmp.dll
c:\windows\system32\_003818_.tmp.dll
c:\windows\system32\_003819_.tmp.dll
c:\windows\system32\_003820_.tmp.dll
c:\windows\system32\_003821_.tmp.dll
c:\windows\system32\_003822_.tmp.dll
c:\windows\system32\_003823_.tmp.dll
c:\windows\system32\_003824_.tmp.dll
c:\windows\system32\_003825_.tmp.dll
c:\windows\system32\_003826_.tmp.dll
c:\windows\system32\_003827_.tmp.dll
c:\windows\system32\_003828_.tmp.dll
c:\windows\system32\_003830_.tmp.dll
c:\windows\system32\_003831_.tmp.dll
c:\windows\system32\_003832_.tmp.dll
c:\windows\system32\_003833_.tmp.dll
c:\windows\system32\_003834_.tmp.dll
c:\windows\system32\_003836_.tmp.dll
c:\windows\system32\_003837_.tmp.dll
c:\windows\system32\_003839_.tmp.dll
c:\windows\system32\_003840_.tmp.dll
c:\windows\system32\_003841_.tmp.dll
c:\windows\system32\_003842_.tmp.dll
c:\windows\system32\_003844_.tmp.dll
c:\windows\system32\_003845_.tmp.dll
c:\windows\system32\_003846_.tmp.dll
c:\windows\system32\_003847_.tmp.dll
c:\windows\system32\_003848_.tmp.dll
c:\windows\system32\_003849_.tmp.dll
c:\windows\system32\_003850_.tmp.dll
c:\windows\system32\_003851_.tmp.dll
c:\windows\system32\_003852_.tmp.dll
c:\windows\system32\_003853_.tmp.dll
c:\windows\system32\_003854_.tmp.dll
c:\windows\system32\_003855_.tmp.dll
c:\windows\system32\_003857_.tmp.dll
c:\windows\system32\_003859_.tmp.dll
c:\windows\system32\_003861_.tmp.dll
c:\windows\system32\_003862_.tmp.dll
c:\windows\system32\_003863_.tmp.dll
c:\windows\system32\_003867_.tmp.dll
c:\windows\system32\_003868_.tmp.dll
c:\windows\system32\_003870_.tmp.dll
c:\windows\system32\_003873_.tmp.dll
c:\windows\system32\_003875_.tmp.dll
c:\windows\system32\_003876_.tmp.dll
c:\windows\system32\_003877_.tmp.dll
c:\windows\system32\_003878_.tmp.dll
c:\windows\system32\_003881_.tmp.dll
c:\windows\system32\_003882_.tmp.dll
c:\windows\system32\_003883_.tmp.dll
c:\windows\system32\_003884_.tmp.dll
c:\windows\system32\_003885_.tmp.dll
c:\windows\system32\_003890_.tmp.dll
c:\windows\system32\_005799_.tmp.dll
c:\windows\system32\_005800_.tmp.dll
c:\windows\system32\_005801_.tmp.dll
c:\windows\system32\_005802_.tmp.dll
c:\windows\system32\_005810_.tmp.dll
c:\windows\system32\_005811_.tmp.dll
c:\windows\system32\_005812_.tmp.dll
c:\windows\system32\_005814_.tmp.dll
c:\windows\system32\_005815_.tmp.dll
c:\windows\system32\_005818_.tmp.dll
c:\windows\system32\_005819_.tmp.dll
c:\windows\system32\_005821_.tmp.dll
c:\windows\system32\_005822_.tmp.dll
c:\windows\system32\_005823_.tmp.dll
c:\windows\system32\_005825_.tmp.dll
c:\windows\system32\_005828_.tmp.dll
c:\windows\system32\_005829_.tmp.dll
c:\windows\system32\_005833_.tmp.dll
c:\windows\system32\_005834_.tmp.dll
c:\windows\system32\_005836_.tmp.dll
c:\windows\system32\_005839_.tmp.dll
c:\windows\system32\_005841_.tmp.dll
c:\windows\system32\_005842_.tmp.dll
c:\windows\system32\_005843_.tmp.dll
c:\windows\system32\_005844_.tmp.dll
c:\windows\system32\_005845_.tmp.dll
c:\windows\system32\_005848_.tmp.dll
c:\windows\system32\_005849_.tmp.dll
c:\windows\system32\_005850_.tmp.dll
c:\windows\system32\_005851_.tmp.dll
c:\windows\system32\_005852_.tmp.dll
c:\windows\system32\_005857_.tmp.dll
c:\windows\system32\_005859_.tmp.dll
c:\windows\system32\pthreadGC2.dll
c:\windows\system32\taskmgr.com
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-03-14 do 2009-04-14 )))))))))))))))))))))))))))))))
.
2009-04-14 16:48 . 2009-04-14 16:48 -------- d-----w c:\documents and settings\HUBKA\Data aplikací\Malwarebytes
2009-04-14 16:48 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-14 16:48 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-14 16:48 . 2009-04-14 16:48 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-14 16:48 . 2009-04-14 16:48 -------- d-----w c:\documents and settings\All Users\Data aplikací\Malwarebytes
2009-04-14 07:39 . 2009-04-14 07:39 -------- d-----w c:\program files\Trend Micro
2009-04-10 16:39 . 2009-04-10 16:39 -------- d-----w c:\documents and settings\HUBKA\Data aplikací\Media Player Classic
2009-04-10 16:25 . 2008-10-03 12:30 414 ----a-w c:\windows\system32\lame_acm.xml
2009-04-10 16:25 . 2008-09-24 18:41 839680 ----a-w c:\windows\system32\lameACM.acm
2009-04-10 16:25 . 2007-09-21 00:52 118784 ----a-w c:\windows\system32\ac3acm.acm
2009-04-10 16:25 . 2004-01-25 16:18 217088 ----a-w c:\windows\system32\yv12vfw.dll
2009-04-10 16:25 . 2008-12-11 00:33 86016 ----a-w c:\windows\system32\dpl100.dll
2009-04-10 16:25 . 2008-12-07 18:08 795648 ----a-w c:\windows\system32\xvidcore.dll
2009-04-10 16:25 . 2008-12-07 18:08 130048 ----a-w c:\windows\system32\xvidvfw.dll
2009-04-10 16:25 . 2008-11-06 16:37 3596288 ----a-w c:\windows\system32\qt-dx331.dll
2009-04-10 16:25 . 2008-11-06 16:33 684032 ----a-w c:\windows\system32\divx.dll
2009-04-10 16:25 . 2009-03-02 18:10 67584 ----a-w c:\windows\system32\ff_vfw.dll
2009-04-10 16:25 . 2007-07-10 16:10 547 ----a-w c:\windows\system32\ff_vfw.dll.manifest
2009-04-10 16:25 . 2009-04-10 16:25 -------- d-----w c:\program files\K-Lite Codec Pack
2009-04-07 07:34 . 2009-04-07 07:34 -------- d-----w c:\program files\MOBILedit!
2009-04-06 19:13 . 2009-04-06 19:13 -------- d-----w c:\program files\AC3Filter
2009-04-01 12:03 . 2009-04-01 12:03 -------- d-----w C:\TiskProRadost
2009-03-24 08:24 . 2009-03-24 08:24 -------- d-----w c:\program files\Album Maker
2009-03-24 08:17 . 2009-03-24 08:17 -------- d-sh--r C:\sys
2009-03-24 08:16 . 2009-03-24 08:16 -------- d-----w c:\program files\Magic Photo Editor
2009-03-23 16:09 . 2009-03-23 16:09 45 ---h--w c:\windows\dwin6988.dat
2009-03-20 14:33 . 2009-03-20 14:33 -------- d-----w c:\documents and settings\Administrator\Local Settings\Data aplikací\O&O
2009-03-19 15:46 . 2009-04-14 17:34 53634 ----a-w c:\windows\system32\oodbs.lor
2009-03-19 10:18 . 2009-03-19 10:18 0 ----a-w c:\windows\oodcnt.INI
2009-03-19 10:18 . 2009-03-19 10:18 -------- d-----w c:\windows\system32\oodag
2009-03-19 08:15 . 2009-03-19 08:15 -------- d-----w c:\documents and settings\HUBKA\Local Settings\Data aplikací\O&O
2009-03-19 08:14 . 2009-03-19 08:14 -------- d-----w c:\program files\OO Software
2009-03-19 06:47 . 2009-03-19 06:47 -------- d-----w c:\program files\QuickTime
2009-03-19 06:46 . 2009-03-19 06:47 -------- d-----w c:\program files\Apple Software Update
2009-03-18 13:06 . 2009-03-18 13:06 -------- d-----w c:\program files\CCleaner
2009-03-18 08:36 . 2009-03-24 08:24 10127591 ----a-w c:\windows\system32\TiskProRadost_AlbumMaker_uninstaller.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-10 15:45 . 2009-02-09 19:50 737280 ----a-w c:\windows\iun6002.exe
2009-03-18 10:13 . 2006-02-16 21:29 247886 ---h--w C:\treeinfo.wc
2009-03-18 08:32 . 2002-09-23 10:00 75262 ----a-w c:\windows\system32\perfc005.dat
2009-03-18 08:32 . 2002-09-23 10:00 403046 ----a-w c:\windows\system32\perfh005.dat
2009-03-12 15:57 . 2009-03-12 15:57 -------- d--h--w c:\documents and settings\All Users\Data aplikací\CanonIJScan
2009-03-12 15:56 . 2009-03-12 15:56 -------- d-----w c:\documents and settings\HUBKA\Data aplikací\Canon
2009-03-11 16:22 . 2009-03-11 16:22 -------- d-----w c:\program files\ICQ6Toolbar
2009-03-11 16:21 . 2009-03-11 16:21 -------- d-----w c:\documents and settings\All Users\Data aplikací\ICQ
2009-03-11 16:15 . 2009-03-11 16:15 -------- d-----w c:\program files\ICQ6.5
2009-03-01 15:38 . 2009-03-01 15:38 -------- d-----w c:\documents and settings\All Users\Data aplikací\VirtualFarm
2009-03-01 14:36 . 2009-03-01 14:36 -------- d-----w c:\program files\Robomoucha
2009-03-01 13:42 . 2009-03-01 13:42 -------- d-----w c:\program files\ABC
2009-02-19 11:16 . 2009-02-19 11:16 86528 ----a-w c:\windows\bnetunin.exe
2009-02-19 11:16 . 2007-02-03 11:22 61440 ----a-w c:\windows\diabswun.exe
2009-02-19 10:03 . 2009-02-19 10:03 579464 ----a-w c:\windows\system32\SymNeti.dll
2009-02-19 10:03 . 2009-02-19 10:03 207240 ----a-w c:\windows\system32\SymRedir.dll
2009-02-19 09:31 . 2009-02-19 09:31 9844 ----a-w c:\windows\system32\drivers\SymRedir.cat
2009-02-19 09:31 . 2009-02-19 09:31 31280 ----a-w c:\windows\system32\drivers\SymIM.sys
2009-02-19 09:31 . 2009-02-19 09:31 1611 ----a-w c:\windows\system32\drivers\SymRedir.inf
2009-02-19 09:31 . 2009-02-19 09:31 41008 ----a-w c:\windows\system32\drivers\symndisv.sys
2009-02-19 09:31 . 2009-02-19 09:31 96560 ----a-w c:\windows\system32\drivers\symfw.sys
2009-02-19 09:31 . 2009-02-19 09:31 38576 ----a-w c:\windows\system32\drivers\symids.sys
2009-02-19 09:31 . 2009-02-19 09:31 37424 ----a-w c:\windows\system32\drivers\symndis.sys
2009-02-19 09:31 . 2009-02-19 09:31 22320 ----a-w c:\windows\system32\drivers\symredrv.sys
2009-02-19 09:31 . 2009-02-19 09:31 184496 ----a-w c:\windows\system32\drivers\symtdi.sys
2009-02-19 09:31 . 2009-02-19 09:31 13616 ----a-w c:\windows\system32\drivers\symdns.sys
2009-02-19 08:33 . 2009-02-19 08:33 4632168 ----a-w c:\program files\SweetImSetup.exe
2009-02-18 16:37 . 2009-02-18 16:36 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-02-18 16:37 . 2009-02-18 16:36 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-02-18 16:33 . 2009-02-18 16:33 1107296 ----a-w c:\windows\system32\WdfCoInstaller01007.dll
2009-02-18 16:33 . 2008-11-05 07:23 24616 ----a-w c:\windows\system32\drivers\ggsemc.sys
2009-02-18 16:33 . 2008-11-05 07:23 13224 ----a-w c:\windows\system32\drivers\ggflt.sys
2009-02-18 12:07 . 2009-02-18 12:07 -------- d-----w c:\documents and settings\HUBKA\Data aplikací\Alawar
2009-02-18 12:07 . 2009-02-18 12:07 -------- d-----w c:\program files\Katčin Rybí krámek
2009-02-14 13:03 . 2009-02-14 13:03 -------- d-----w c:\documents and settings\HUBKA\Data aplikací\ArcSoft
2009-02-09 13:19 . 2008-10-24 18:13 1846272 ----a-w c:\windows\system32\win32k.sys
2009-02-09 13:19 . 2008-10-24 18:13 1846272 ----a-w c:\windows\system32\dllcache\win32k.sys
2009-02-08 14:15 . 2008-12-21 15:43 140471 ----a-w C:\pokus.txt
2009-02-03 08:03 . 2007-06-16 15:42 47360 ----a-w c:\documents and settings\HUBKA\Data aplikací\pcouffin.sys
2009-01-16 19:30 . 2006-05-19 15:10 3594752 ------w c:\windows\system32\dllcache\mshtml.dll
2009-01-04 14:49 . 2009-01-04 14:49 81920 ----a-w c:\documents and settings\HUBKA\Data aplikací\ezpinst.exe
2008-09-25 14:49 . 2004-12-03 20:57 92080 ----a-w c:\documents and settings\HUBKA\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
2007-06-23 17:33 . 2007-06-23 17:33 125 ----a-w c:\documents and settings\HUBKA\Local Settings\Data aplikací\fusioncache.dat
2004-12-13 20:05 . 2004-12-13 19:59 1234 ----a-w c:\program files\GPRSpeed Plus Client setup.log
2004-03-11 11:27 . 2004-12-29 19:50 40960 ----a-w c:\program files\Uninstall_CDS.exe
2007-08-24 18:2008-02-20 14:36 52:00 . c:\program files\mozilla firefox\components\coFFPlgn.dll
.
------- Sigcheck -------
[-] 2004-08-17 13:49 14336 DFBA2915B0BF58ABB288CD4C9318CB3F c:\windows\system32\svchost.exe
[-] 2004-08-17 13:49 14336 DFBA2915B0BF58ABB288CD4C9318CB3F c:\windows\ServicePackFiles\i386\svchost.exe
[-] 2008-04-14 03:22 14336 BE4A520E29B6391F49E79CCC52044D93 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\svchost.exe
[-] 2004-08-17 13:49 82944 382E9B87F1282E697C67AF84E34E35E2 c:\windows\system32\ws2_32.dll
[-] 2004-08-17 13:49 82944 382E9B87F1282E697C67AF84E34E35E2 c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 03:22 82432 951D473917C51F21496D914CF6E5DDD1 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ws2_32.dll
[-] 2004-08-17 13:49 502272 221C29AE1B4CC61D11D8B27DE78B2307 c:\windows\system32\winlogon.exe
[-] 2004-08-17 13:49 502272 221C29AE1B4CC61D11D8B27DE78B2307 c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 03:22 507904 CDDB1F8E1AEA356F3AD106F2CF9B7FEA c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\winlogon.exe
[-] 2004-08-03 21:14 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\system32\drivers\ndis.sys
[-] 2004-08-03 21:14 182912 558635D3AF1C7546D26067D5D9B6959E c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-13 19:20 182656 1DF7F42665C94B825322FAE71721130D c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ndis.sys
[-] 2004-08-03 21:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\system32\drivers\ip6fw.sys
[-] 2004-08-03 21:00 29056 4448006B6BC60E6C027932CFC38D6855 c:\windows\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 18:53 36608 3BB22519A194418D5FEC05D800A19AD0 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ip6fw.sys
[-] 2004-08-17 13:49 108544 6E401E61F952FBBF708AFBECEFAFAE81 c:\windows\system32\services.exe
[-] 2004-08-17 13:49 108544 6E401E61F952FBBF708AFBECEFAFAE81 c:\windows\ServicePackFiles\i386\services.exe
[-] 2008-04-14 03:22 108544 F0D2AE69035092BF22DAD6B50FAB85C2 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\services.exe
[-] 2004-08-17 13:49 13312 82A362FE1D4980B71B588D9C10748511 c:\windows\system32\lsass.exe
[-] 2004-08-17 13:49 13312 82A362FE1D4980B71B588D9C10748511 c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-14 03:22 13312 ED0A176354487CEED65B80A7148AB739 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\lsass.exe
[-] 2004-08-17 13:49 15360 A5BAA91475167161DEA02BA3C4CA4F59 c:\windows\system32\ctfmon.exe
[-] 2004-08-17 13:49 15360 A5BAA91475167161DEA02BA3C4CA4F59 c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 03:22 15360 A756B8F0F7BAFBA6DFE39F7D169F2519 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\ctfmon.exe
[-] 2004-08-17 13:49 24576 836F7960362FF95C5D49E40B891F2CFC c:\windows\system32\userinit.exe
[-] 2004-08-17 13:49 24576 836F7960362FF95C5D49E40B891F2CFC c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2008-04-14 03:22 26112 7DC1830F22E7D275B438127B68030239 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\userinit.exe
[-] 2004-08-17 13:49 295936 2F5919F2F6EE7A845893D9C3AA2BC56A c:\windows\system32\termsrv.dll
[-] 2004-08-17 13:49 295936 2F5919F2F6EE7A845893D9C3AA2BC56A c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-14 03:22 295936 A75DD6FC3DBEE4FFF5EBC9F2C28BB66E c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\termsrv.dll
[-] 2004-08-17 13:49 17408 134B95A1D8FAFD74A68E4B2116DEFA7D c:\windows\system32\powrprof.dll
[-] 2004-08-17 13:49 17408 134B95A1D8FAFD74A68E4B2116DEFA7D c:\windows\ServicePackFiles\i386\powrprof.dll
[-] 2008-04-14 03:21 17408 9FA69781CAA7A1DA981A24F240A61A60 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\powrprof.dll
[-] 2004-08-17 13:49 110080 2413635113361E54B62F0C40E4E4DAE6 c:\windows\system32\imm32.dll
[-] 2004-08-17 13:49 110080 2413635113361E54B62F0C40E4E4DAE6 c:\windows\ServicePackFiles\i386\imm32.dll
[-] 2008-04-14 03:21 110080 6C60CA8AC7470AC01CFD3D24C7283CD1 c:\windows\SoftwareDistribution\Download\8fb85d68ee3649be8b622da7b69408ee\imm32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-05-28 95800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-24 714608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-11-03 2540800]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0lsdelete\
0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\WINDOWS\\System32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Plánovač automatické aktualizace LiveUpdate;Plánovač automatické aktualizace LiveUpdate;c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-08-31 243064]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
R3 FlyPCI;FlyPCI;c:\progra~1\FLY200~1\FlyPCI.sys [2003-10-10 4134]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2009-02-18 13224]
R3 GT680xNT;USB Scanner Driver; [x]
R3 k510bus;Sony Ericsson K510 Driver driver (WDM);c:\windows\system32\DRIVERS\k510bus.sys [2007-06-23 58288]
R3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;c:\windows\system32\DRIVERS\k510mdfl.sys [2007-06-23 8336]
R3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;c:\windows\system32\DRIVERS\k510mdm.sys [2007-06-23 94064]
R3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\k510mgmt.sys [2007-06-23 85408]
R3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\k510obex.sys [2007-06-23 83344]
S0 hotcore2;hotcore2;c:\windows\system32\drivers\hotcore2.sys [2006-10-02 30808]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-17 101936]
S3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2003-07-18 24608]
S3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\DRIVERS\psched.sys [2004-08-03 69120]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - COMHOST
.
Obsah adresáře 'Naplánované úlohy'
2009-04-06 c:\windows\Tasks\Norton Internet Security - Prověřit tento počítač - HUBKA.job
- c:\program files\Norton Internet Security\Aplikace Norton AntiVirus\Navw32.exe [2007-08-26 16:19]
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-PowerBar - (no file)
Notify-dimsntfy - (no file)
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://seznam.cz/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page =
hxxp://www.seznam.cz/uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/keyword/%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HUBKA\Data aplikací\Mozilla\Firefox\Profiles\qdaiptsp.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/FF - prefs.js: keyword.URL -
hxxp://search.icq.com/search/afe_result ... id=afex&q=FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-14 19:36
Windows 5.1.2600 Service Pack 2 FAT NTAPI
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="78D8777ABE18292A243AC7DA27BD1B1C1F5E05DA52C9257816EACA90B820A86DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B9808E1555D407F3A47B47E47A68A0556CFDEC023768A70461FF1D6E6BC35F7158537CA4749B83F58C0F3B91C236E735A81EF544AAFE2B755387C35492A6FDD3C361904B9EE5BF998211C6D7F93153AF1AE75637CCBF891CA39FBB4CC28A8BA281ECBF01E186EFD2D6F35190EC5B5524972B8AB9F3F14486C731BF13DED59C356617DA94A5FBB0FEEC60E73455A0D302FFCCB207CCE7E19A34BCA3DCC087CA4693D9C7AF93690E3D5D539E689C9D5B39913FE67BD9709B3FA3BBE179056157AA67CE0E54A62BD2602600D8EA25BD5B71D8CE95BF406083E25CF70B9818AA657F783C29E3E7C1A76B7BFA2BD3BADD286F756690B97DDD051772A1B8FFDAF3A416C47008E3CEF7F68DB5B597A63B118E009F09B397C35417AE8803EB7469EDBB134D397D08E7ECA80FA35527C8EAFF2FAD56E63DB5F7838B9989A1E0780889B17264651B6633DDD3C436074B292BE36FC8379689D63E4990546D7C38436EF9054BCD134C3CD141F098603E8BEACCD3902604E15DD8A8D4C45D6277BEB552FD03E143A0FB2C4C0774BBDD89EF3FB9E571BDBBA192E3ED9BCD6528F54AA2D6FFA1FEFDCF1EDA053535903B1C8DE03476DCB0A2667D4CA84D90C67A9A367F5B2AEB5B4A6B196A0B0A67D94F05BBA2AB15F0CA087B74C601B98276623007846CA8F32ED99690268126678D50D12FA3C9913C87E6A85C41382EE65443C47E79DDF48BD484C74B77D040BFACD11E9C26813F360A26F8E1FDB6FD970194B9977DBEE056F966AF3744967932F271D26EDC203EF2830CBD673176DD86A223AD99AC746F5D6CDAE4EA91C70012DB0644C8942A3F9E76F47258905DBEE68C084B0F58A8BCF7508EE2B7A27285985DD2EA656438289DA4C3D05624A6C24F2FABB8A68B0B4CAC1838FF940016B27BAC5D543C9838018B2569F45B06F270488F686177FAB0EA4A5A18CE807236BF5C3A149740EA7D52591427179D9DFE51E98829CCA80D1379D7EE8F1EE10ED2DD70CD18ED0803689B211674BF8F7ED570689904CDD615C25791E8263C5CEA287E372D93AB1B21C7AC73CC1D9DD5A4BFE543233F7CBCDE79D814C3D16E9EDE72933C95EF8366926D96E92F05C070313B224E1A591D5A5773E83C18B569AC7499362D9AC88BE9F8A2F368ABA299A29409E9458C225007C6EF5CDAC0180606DB21894DCB2BE7381DE52B0890426FB38324049CB0DCE911A9709B7AF5988022377636F0202013E719F72F5EC5BD059CBAFEA6AE32941187A1F0E96DF72F10D62CE701BECD34CCB04AB902084ED3920"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(3332)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SYSTEM32\SCARDSVR.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\windows\SYSTEM32\OODAG.EXE
c:\program files\ANALOG DEVICES\SOUNDMAX\SMAGENT.EXE
.
**************************************************************************
.
Celkový čas: ~,10time:~,-3machine was rebootedCombobatch-by
ComboFix-quarantined-files.txt 2009-04-14 17:40
Před spuštěním: Volných bajtů: 90 556 497 920
Po spuštění: Volných bajtů: 90 465 665 024
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
C:\ = "Nezn mě operaźnˇ syst‚m na jednotce C:"
492 --- E O F --- 2009-03-23 18:02