ComboFix 10-07-01.02 - Butterfly 2010-07-02 21:20:18.2.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.1.1029.18.1022.647 [GMT 2:00]
Spuštěný z: c:\documents and settings\Butterfly\Plocha\ComboFix.exe
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\etc\lmhosts . . . . nemohl být smazán
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-06-02 do 2010-07-02 )))))))))))))))))))))))))))))))
.
2010-07-02 06:14 . 2010-07-02 06:15 -------- d-----w- C:\rsit
2010-07-01 10:25 . 2010-07-02 06:15 -------- d-----w- c:\program files\Trend Micro
2010-07-01 09:01 . 2010-07-01 09:02 -------- d-----w- c:\program files\QuickTime
2010-07-01 07:58 . 2010-07-01 07:58 -------- d-----w- c:\documents and settings\Butterfly\KBCertifikat
2010-06-30 08:34 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-06-30 08:34 . 2010-06-08 16:10 790528 ----a-w- c:\windows\system32\xvidcore.dll
2010-06-30 08:34 . 2010-06-08 16:10 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2010-06-30 08:34 . 2010-06-28 08:00 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-30 08:33 . 2010-07-01 10:12 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-06-30 08:29 . 2010-06-30 08:29 -------- d-----w- c:\windows\system32\drivers\NSS
2010-06-30 08:29 . 2010-06-30 08:29 -------- d-----w- c:\program files\Norton Security Scan
2010-06-30 08:29 . 2010-06-30 08:29 -------- d-----w- c:\program files\NortonInstaller
2010-06-28 17:24 . 2010-06-23 11:51 69120 ----a-w- c:\windows\system32\zlcomm.dll
2010-06-28 17:24 . 2010-06-23 11:51 103936 ----a-w- c:\windows\system32\zlcommdb.dll
2010-06-28 17:24 . 2010-06-23 11:51 1238528 ----a-w- c:\windows\system32\zpeng25.dll
2010-06-28 17:24 . 2010-06-28 17:25 -------- d-----w- c:\windows\system32\ZoneLabs
2010-06-28 17:24 . 2010-06-28 17:24 -------- d-----w- c:\program files\Zone Labs
2010-06-28 12:18 . 2010-06-28 17:37 -------- d-----w- c:\program files\Crawler
2010-06-28 12:18 . 2010-06-28 12:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-28 12:18 . 2010-06-29 16:03 -------- d-----w- c:\program files\Spyware Terminator
2010-06-27 07:54 . 2010-07-02 19:30 -------- d-----w- c:\windows\Internet Logs
2010-06-26 21:46 . 2010-06-26 21:46 -------- d-----w- c:\program files\Common Files\Java
2010-06-26 20:51 . 2010-06-26 20:51 -------- d-----w- c:\program files\NetLimiter
2010-06-26 16:23 . 2010-06-26 16:25 -------- d-----w- c:\program files\Ultimate Process Manager
2010-06-26 15:21 . 2010-06-26 15:21 -------- d-s---w- c:\documents and settings\LocalService\Oblíbené položky
2010-06-26 15:12 . 2010-06-27 08:08 -------- d-----w- c:\program files\Sunbelt Software
2010-06-26 08:53 . 2010-06-26 08:55 -------- d-----w- c:\program files\Hide My IP
2010-06-23 19:30 . 2010-06-23 19:30 -------- d-----w- c:\program files\XP TCPIP Repair
2010-06-23 19:08 . 2010-06-23 19:08 -------- d-----w- c:\program files\VS Revo Group
2010-06-23 12:09 . 2010-06-14 14:39 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-21 08:05 . 2006-08-14 19:09 82816 ----a-w- c:\windows\system32\drivers\Rtnic.sys
2010-06-21 08:05 . 2006-08-14 19:09 82816 ----a-w- c:\windows\system32\drivers\Rtenic.sys
2010-06-21 07:53 . 2010-06-22 17:17 -------- d-----w- c:\program files\Driver Checker
2010-06-17 18:14 . 2010-06-25 12:41 217260 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-06-17 18:14 . 2010-06-25 12:41 217260 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-06-17 18:14 . 2010-06-25 12:41 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-06-17 17:46 . 2010-06-17 17:46 -------- d-----w- c:\program files\DAEMON Tools Pro
2010-06-17 14:05 . 2010-07-01 08:39 -------- d-----w- c:\program files\Opera 10.60 Beta
2010-06-17 13:59 . 2010-06-17 14:01 -------- dc-h--w- c:\windows\ie8
2010-06-17 05:46 . 2010-06-17 05:46 -------- d-sh--w- c:\documents and settings\Butterfly\wc
2010-06-17 05:45 . 2010-06-17 05:45 -------- d-----w- c:\program files\Software Informer
2010-06-17 05:43 . 2010-06-17 05:43 -------- d-----w- c:\program files\Flow
2010-06-13 21:07 . 2010-06-13 21:07 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-06-13 09:04 . 2010-06-13 09:04 55572 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-13 09:04 . 2010-06-13 09:04 -------- d-----w- c:\program files\Safari
2010-06-12 09:26 . 2010-06-12 09:26 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-11 08:29 . 2010-06-17 14:01 -------- d--h--w- c:\windows\msdownld.tmp
2010-06-11 08:19 . 2010-06-11 08:19 -------- d-----w- c:\program files\Secunia
2010-06-11 07:31 . 2010-06-27 09:06 -------- d-----w- c:\program files\AVG
2010-06-11 07:17 . 2010-06-11 07:18 94 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-06-10 21:43 . 2010-06-10 21:45 -------- d-----w- c:\program files\DVBViewerTE
2010-06-10 05:39 . 2010-06-08 15:16 64104 ----a-w- c:\windows\ALCMTR.EXE
2010-06-09 09:14 . 2010-06-23 11:30 -------- d-----w- c:\program files\Panda Security
2010-06-09 07:25 . 2010-05-06 10:35 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 17:01 . 2009-06-30 07:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2010-06-07 18:39 . 2007-08-31 10:52 56496 ----a-w- c:\windows\system32\wbhelp2.dll
2010-06-07 18:39 . 2007-08-31 10:52 33968 ----a-w- c:\windows\system32\anim.dll
2010-06-07 18:39 . 1999-11-22 13:50 4608 ----a-w- c:\windows\system32\W95INF32.DLL
2010-06-07 18:39 . 1999-11-22 13:50 2272 ----a-w- c:\windows\system32\W95INF16.DLL
2010-06-07 18:39 . 2010-06-07 18:50 -------- d-----w- c:\program files\WinUtilities
2010-06-06 07:45 . 2010-06-23 18:41 -------- d-----w- c:\program files\Defraggler
2010-06-05 08:04 . 2010-06-07 18:15 -------- d-----w- c:\program files\ScreenCamera
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-02 17:07 . 2010-03-08 11:38 -------- d-----w- c:\program files\Steam
2010-07-02 07:05 . 2010-07-02 07:07 1930240 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2010-07-02 07:05 . 2010-07-02 07:07 32256 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2010-07-01 22:26 . 2010-07-02 06:05 35328 ----a-w- c:\windows\Internet Logs\xDB8.tmp
2010-07-01 22:26 . 2010-07-02 06:05 1923584 ----a-w- c:\windows\Internet Logs\xDB9.tmp
2010-07-01 15:44 . 2010-07-01 17:48 1920000 ----a-w- c:\windows\Internet Logs\xDB7.tmp
2010-07-01 15:44 . 2010-07-01 17:48 161280 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2010-07-01 11:57 . 2010-02-12 21:12 -------- d-----w- c:\program files\Google
2010-07-01 08:49 . 2010-02-12 13:43 -------- d-----w- c:\program files\MSECache
2010-07-01 08:41 . 2010-02-12 04:39 -------- d-----w- c:\program files\Opera
2010-06-30 12:50 . 2010-04-17 16:00 -------- d-----w- c:\program files\ESET
2010-06-30 08:35 . 2010-03-03 21:53 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-06-29 22:23 . 2010-06-30 07:19 34304 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2010-06-29 18:45 . 2010-06-29 19:54 1780224 ----a-w- c:\windows\Internet Logs\xDB4.tmp
2010-06-29 18:45 . 2010-06-29 19:54 54272 ----a-w- c:\windows\Internet Logs\xDB3.tmp
2010-06-28 21:00 . 2010-06-29 11:44 19968 ----a-w- c:\windows\Internet Logs\xDB2.tmp
2010-06-28 19:33 . 2010-06-28 20:33 43520 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2010-06-28 17:57 . 2010-03-28 12:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-28 17:25 . 2010-02-24 16:13 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-06-27 07:44 . 2010-03-20 11:58 -------- d-----w- c:\program files\IObit
2010-06-26 21:43 . 2010-04-24 08:02 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-26 08:02 . 2010-02-28 20:04 -------- d-----w- c:\program files\PKR
2010-06-23 12:09 . 2010-02-27 09:18 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-23 11:47 . 2001-10-25 14:00 79424 ----a-w- c:\windows\system32\perfc005.dat
2010-06-23 11:47 . 2001-10-25 14:00 432386 ----a-w- c:\windows\system32\perfh005.dat
2010-06-21 08:10 . 2010-03-28 13:00 -------- d-----w- c:\program files\Realtek
2010-06-21 08:10 . 2010-02-09 21:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-20 13:34 . 2010-04-05 19:11 -------- d-----w- c:\program files\ICQ6.5
2010-06-20 07:43 . 2010-02-14 16:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-20 07:43 . 2010-06-20 07:43 311296 ----a-w- c:\windows\~DF7BF9.tmp
2010-06-20 07:43 . 2010-06-20 07:43 311296 ----a-w- c:\windows\~DF6E59.tmp
2010-06-20 07:42 . 2010-06-20 07:42 65536 ----a-w- c:\windows\~DF23ED.tmp
2010-06-17 18:15 . 2010-02-16 20:52 -------- d-----w- c:\program files\NVIDIA Corporation
2010-06-17 18:02 . 2010-05-08 08:47 -------- d-----w- c:\program files\BurnAware Free
2010-06-17 17:47 . 2010-02-28 21:24 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-06-14 14:45 . 2010-02-27 09:19 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-13 09:03 . 2010-05-31 19:58 -------- d-----w- c:\program files\Bonjour
2010-06-12 09:08 . 2010-04-24 08:05 -------- d-----w- c:\program files\DivX
2010-06-12 09:07 . 2010-04-24 08:27 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-12 09:06 . 2010-05-30 08:27 -------- d-----r- c:\program files\Skype
2010-06-12 09:01 . 2010-04-03 08:58 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-11 07:18 . 2010-02-17 18:37 133836 ----a-w- c:\windows\BricoPackUninst.cmd
2010-06-09 10:55 . 2010-02-16 21:52 -------- d-----w- c:\program files\Alwil Software
2010-06-08 15:16 . 2010-03-29 18:56 84584 ----a-w- c:\windows\SOUNDMAN.EXE
2010-06-08 15:16 . 2010-03-29 18:56 359016 ----a-w- c:\windows\vncutil.exe
2010-06-08 15:16 . 2010-03-29 18:56 1833576 ----a-w- c:\windows\SkyTel.exe
2010-06-08 15:16 . 2010-03-29 18:56 1489512 ----a-w- c:\windows\RtlUpd.exe
2010-06-08 15:16 . 2010-03-29 18:56 9721960 ----a-w- c:\windows\RTLCPL.EXE
2010-06-08 15:16 . 2010-03-29 18:56 6056040 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-06-08 15:16 . 2010-03-29 18:56 129640 ----a-w- c:\windows\RtkAudioService.exe
2010-06-08 15:16 . 2010-03-29 18:56 19552872 ----a-w- c:\windows\RTHDCPL.EXE
2010-06-08 15:16 . 2010-02-14 08:00 52840 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-06-08 15:16 . 2010-03-29 18:56 2180712 ----a-w- c:\windows\MicCal.exe
2010-06-08 15:16 . 2010-03-29 18:56 2815592 ----a-w- c:\windows\ALCWZRD.EXE
2010-06-07 23:57 . 2010-02-10 18:46 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-06-07 23:57 . 2010-02-10 18:46 10531200 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-06-07 23:57 . 2010-02-10 18:46 4554752 ----a-w- c:\windows\system32\nvcuda.dll
2010-06-07 23:57 . 2010-02-10 18:46 2632296 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-06-07 23:57 . 2010-02-10 18:46 232040 ----a-w- c:\windows\system32\nvcodins.dll
2010-06-07 23:57 . 2010-02-10 18:46 232040 ----a-w- c:\windows\system32\nvcod.dll
2010-06-07 23:57 . 2010-02-10 18:46 2165352 ----a-w- c:\windows\system32\nvcuvid.dll
2010-06-07 23:57 . 2010-02-10 18:46 15192064 ----a-w- c:\windows\system32\nvoglnt.dll
2010-06-07 23:57 . 2010-02-10 18:46 1359872 ----a-w- c:\windows\system32\nvapi.dll
2010-06-07 23:57 . 2010-02-10 18:46 10256384 ----a-w- c:\windows\system32\nvcompiler.dll
2010-06-07 23:57 . 2010-02-10 18:46 6300544 ----a-w- c:\windows\system32\nv4_disp.dll
2010-06-07 23:57 . 2010-02-10 18:46 2186342 ----a-w- c:\windows\system32\nvdata.bin
2010-06-07 18:20 . 2010-03-08 18:33 -------- d-----w- c:\program files\The KMPlayer
2010-06-04 11:58 . 2010-03-09 09:17 -------- d-----w- c:\program files\SlySoft
2010-05-31 20:00 . 2010-02-18 21:38 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-31 19:44 . 2010-05-31 19:44 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-05-28 11:04 . 2010-05-28 11:04 14896 ----a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-27 17:05 . 2010-04-12 18:53 -------- d-----w- c:\program files\Valve
2010-05-27 16:53 . 2010-05-27 17:23 -------- d-----w- c:\program files\AviSynth 2.5
2010-05-27 13:34 . 2010-02-10 22:42 -------- d-----w- c:\program files\CCleaner
2010-05-26 10:52 . 2010-05-26 10:46 -------- d-----w- c:\program files\VPN Anonymizer
2010-05-23 20:27 . 2010-05-22 08:13 -------- d-----w- c:\program files\VideoLAN
2010-05-23 20:11 . 2010-05-21 13:30 -------- d--h--w- c:\program files\Process Lasso
2010-05-22 07:58 . 2010-03-07 14:26 -------- d-----w- c:\program files\Microsoft Games
2010-05-20 20:15 . 2010-05-20 20:13 -------- d-----w- c:\program files\ScreenShots
2010-05-20 15:56 . 2010-05-20 15:56 -------- d-----w- c:\program files\Microsoft Research
2010-05-20 15:52 . 2010-05-20 15:52 -------- d-----w- c:\program files\Common Files\Windows Live
2010-05-18 14:35 . 2010-05-18 14:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 14:35 . 2010-05-18 14:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-12 19:03 . 2010-02-12 16:23 -------- d-----w- c:\program files\CyberLink
2010-05-12 16:41 . 2010-03-27 20:28 -------- d-----w- c:\program files\Trillian
2010-05-11 14:23 . 2010-02-12 21:17 -------- d-----w- c:\program files\Common Files\CyberLink
2010-05-11 14:20 . 2010-02-12 21:17 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-05-11 14:20 . 2010-02-12 16:23 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-05-11 14:20 . 2010-02-12 16:23 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-05-10 21:59 . 2010-05-09 11:02 -------- d-----w- c:\program files\DAP
2010-05-08 18:47 . 2010-05-08 18:47 -------- d-----w- c:\program files\LIUtilities
2010-05-06 10:35 . 2004-08-17 13:49 907264 ----a-w- c:\windows\system32\wininet.dll
2010-05-05 19:51 . 2010-02-12 21:53 -------- d-----w- c:\program files\QIP
2010-05-05 17:25 . 2010-02-11 19:56 -------- d-----w- c:\program files\Common Files\BinarySense
2010-05-02 08:09 . 2010-03-21 11:47 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 13:39 . 2010-02-25 20:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-02-25 20:28 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-28 16:45 . 2010-02-18 14:35 1251872 ----a-w- c:\windows\RtlExUpd.dll
2010-04-24 08:32 . 2010-03-19 16:35 8030 ----a-w- c:\program files\Common Files\unins000.dat
2010-04-24 08:31 . 2010-03-19 16:35 728858 ----a-w- c:\program files\Common Files\unins000.exe
2006-05-03 10:06 . 2010-04-01 18:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2010-04-01 18:54 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2010-04-01 18:54 216064 --sh--r- c:\windows\system32\nbDX.dll
.
------- Sigcheck -------
[-] 2009-08-06 . A089AB141D4E25E543EEC2230CB50BD6 . 68832 . . [7.4.7600.226] . . c:\windows\ServicePackFiles\i386\wuauclt.exe
[-] 2009-08-06 . A089AB141D4E25E543EEC2230CB50BD6 . 68832 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2009-08-06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226] . . c:\windows\system32\dllcache\wuauclt.exe
[-] 2010-05-06 . 05379DF185A4199865D8B1AA169C3FD3 . 6224896 . . [8.00.6001.18928] . . c:\windows\ServicePackFiles\i386\mshtml.dll
[-] 2010-05-06 . 05379DF185A4199865D8B1AA169C3FD3 . 6224896 . . [8.00.6001.18928] . . c:\windows\system32\mshtml.dll
[7] 2010-05-06 . 06B941C7749A9F071444B4C7563F36B5 . 5950976 . . [8.00.6001.18928] . . c:\windows\system32\dllcache\mshtml.dll
[7] 2010-05-06 . 3F88F981AA7BC20744E0D2C699F500EF . 5953024 . . [8.00.6001.23019] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
[7] 2010-02-26 . 23CB63CC448E14C4069E9CE40483E987 . 3094528 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\mshtml.dll
[7] 2010-02-25 . AC93856CC1D10E74986EA4E70D90748F . 5946880 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll
[7] 2010-01-05 . 5DA02EE50F8FC661964857F21A2AE606 . 3602944 . . [7.00.6000.21183] . . c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\mshtml.dll
[7] 2009-12-22 . 25B289964AE031D4ECF189B8CD50F306 . 3092480 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\mshtml.dll
[7] 2009-12-22 . 41A55A865F00CE20284132E8FDE1FFB3 . 3092480 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\mshtml.dll
[7] 2009-12-22 . BD2EE2BDF5954172F509A16EBEA06D85 . 3094528 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\mshtml.dll
[7] 2009-12-21 . BD424F12E808F3AA345C4816F7124F7C . 5945856 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[7] 2009-10-29 . 00EC3DE6B7C581CC2675CCD549B692D7 . 5940736 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\mshtml.dll
[7] 2009-10-29 . FC883BC594F028EF5D77B645AE91C914 . 5944320 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[7] 2009-03-08 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\mshtml.dll
[7] 2007-08-13 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . c:\windows\ie7updates\KB978207-IE7\mshtml.dll
[-] 2010-05-06 . C9C1E562FE51D92193AD5F19AB5F9E36 . 907264 . . [8.00.6001.18923] . . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2010-05-06 . C9C1E562FE51D92193AD5F19AB5F9E36 . 907264 . . [8.00.6001.18923] . . c:\windows\system32\wininet.dll
[7] 2010-05-06 . B7ECEF0CCF63119356E174A78C185171 . 916480 . . [8.00.6001.18923] . . c:\windows\system32\dllcache\wininet.dll
[7] 2010-05-06 . 72064DA077E9D6912F39438D97CC0C60 . 919040 . . [8.00.6001.23014] . . c:\windows\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
[7] 2010-02-26 . FD0F4E4BC28B18715BC1323ACD48E1A6 . 669696 . . [6.00.2900.5945] . . c:\windows\$hf_mig$\KB980182\SP3QFE\wininet.dll
[7] 2010-02-25 . 2E6504E28C7E0F753F68731861A94214 . 919040 . . [8.00.6001.22995] . . c:\windows\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll
[7] 2010-01-05 . 0D90D150ED0DD4C673C627C52D3F7149 . 841216 . . [7.00.6000.21183] . . c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\wininet.dll
[7] 2009-12-22 . A0C158A24DA9F9C48B5B067948B31AA4 . 669696 . . [6.00.2900.3660] . . c:\windows\$hf_mig$\KB978207\SP2QFE\wininet.dll
[7] 2009-12-22 . 50C587017A3F2FB5B1B1B4267CB2EA91 . 668160 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3GDR\wininet.dll
[7] 2009-12-22 . 5F072B7F1CF448D6ED5FF79511890E60 . 669696 . . [6.00.2900.5921] . . c:\windows\$hf_mig$\KB978207\SP3QFE\wininet.dll
[7] 2009-12-21 . 9256DA4AEE5E2C20FC6C126BDBC11997 . 916480 . . [8.00.6001.22967] . . c:\windows\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[7] 2009-10-29 . F651D2A69B7037D6063BC697CF296D8C . 916480 . . [8.00.6001.18854] . . c:\windows\ie8updates\KB978207-IE8\wininet.dll
[7] 2009-10-29 . 4941ADD731725AF468342E42B71F776C . 916480 . . [8.00.6001.22945] . . c:\windows\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[7] 2009-03-08 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702] . . c:\windows\ie8updates\KB976325-IE8\wininet.dll
[7] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie7updates\KB978207-IE7\wininet.dll
[-] 2008-04-14 . 71C54FF181A2C03921A74DB4D9ADD20E . 976384 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 71C54FF181A2C03921A74DB4D9ADD20E . 976384 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-06-08 19552872]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HLSW\\hlsw.exe"=
"c:\\Documents and Settings\\Butterfly\\Dokumenty\\My DAP Downloads\\TeamViewerPortable_en\\TeamViewer.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Steam\\steamapps\\cleverboy\\condition zero\\hl.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Valve\\hltv.exe"=
"c:\\Program Files\\Flow\\Flow.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Steam\\steamapps\\cleverboy\\counter-strike\\hl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-06-08 28552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2010-02-28 697328]
R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [2010-02-21 16896]
R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [2010-02-21 52224]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2010-02-09 13696]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-06-28 142592]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-06-14 1051976]
R3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [2010-03-17 18944]
R3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [2010-03-17 11520]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-21 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-03-29 1691480]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-06-13 23456]
S3 esihdrv;esihdrv; [x]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-02-25 38224]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-05-28 14896]
S3 tap0901_2gm;VPN Anonymizer Adapter;c:\windows\system32\drivers\tap0901_2gm.sys [2007-06-21 30720]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2010-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-25 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2010-06-14 14:48]
2010-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-21 20:33]
2010-06-30 c:\windows\Tasks\Norton Security Scan for Butterfly.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-30 08:22]
2010-07-02 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-796845957-879983540-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
2010-06-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-796845957-879983540-682003330-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://google.cz/IE: &Download with &DAP
IE: Download &all with DAP
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Zobrazit originál
FF - ProfilePath - c:\documents and settings\Butterfly\Data aplikací\Mozilla\Firefox\Profiles\s8h2coht.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Seznam
FF - prefs.js: browser.startup.homepage -
www.google.czFF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- NASTAVENÍ FIREFOXU ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 600000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 600000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-02 21:31
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-796845957-879983540-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):78,29,7c,ae,b5,3d,f0,d2,64,dd,34,df,08,fb,70,87,4a,3b,ec,24,9f,
57,44,1d,e0,99,34,68,10,d1,9d,d3,07,54,73,22,09,3a,ab,46,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6bbadbfa-e8da-4a90-9241-1934d8476915}]
@Denied: (Full) (Everyone)
"Model"=dword:000000a1
"Therad"=dword:00000012
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(892)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\wscntfy.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
.
**************************************************************************
.
Celkový čas: 2010-07-02 21:35:09 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-07-02 19:35
Před spuštěním: Volných bajtů: 73,212,280,832
Po spuštění: Volných bajtů: 73,148,620,800
- - End Of File - - 05E1687B59119BEC515F9F59A56096EE