Ahoj, Tak tady je první log
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.orgVerze databáze: 6135
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
28.3.2011 0:34:20
mbam-log-2011-03-28 (00-34-20).txt
Typ kontroly: Rychlý test
Testované objekty: 151527
Uplynulý čas: 9 minut, 31 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
A tu je z Combofixu
ComboFix 11-03-26.02 - Mira 28.03.2011 1:00.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3066.2145 [GMT 2:00]
Spuštěný z: c:\users\Mira\Desktop\ComboFix.exe
AV: McAfee® Total Protection™ for Small Business *Disabled/Outdated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: McAfee® Total Protection™ for Small Business *Disabled/Outdated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý
.
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Mira\GoogleToolbarInstaller_en32_signed.exe
c:\users\Mira\videos\SetupCasino_5179c8_cs.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-02-27 do 2011-03-27 )))))))))))))))))))))))))))))))
.
.
2011-03-27 23:18 . 2011-03-27 23:19 -------- d-----w- c:\users\Mira\AppData\Local\temp
2011-03-27 23:18 . 2011-03-27 23:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-25 21:29 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{82AE08DE-468E-48B2-A150-4C6F37E06CF3}\mpengine.dll
2011-03-23 00:00 . 2011-03-23 00:00 388096 ----a-r- c:\users\Mira\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-23 00:00 . 2011-03-23 00:00 -------- d-----w- c:\program files\Trend Micro
2011-03-22 23:39 . 2011-03-22 23:39 -------- d-----w- c:\users\Mira\AppData\Local\ATI
2011-03-22 21:47 . 2011-03-27 22:23 -------- d---a-w- c:\windows\VDLL.DLL
2011-03-22 21:47 . 2011-03-22 21:47 -------- d---a-w- c:\windows\system32\runouce.exe
2011-03-22 21:47 . 2011-03-22 21:47 -------- d---a-w- c:\windows\rundll16.exe
2011-03-22 21:47 . 2011-03-22 21:47 -------- d---a-w- c:\windows\RUNDL132.EXE
2011-03-22 21:47 . 2011-03-22 21:47 -------- d---a-w- c:\windows\logo1_.exe
2011-03-22 21:47 . 2011-03-22 21:47 -------- d---a-w- c:\windows\logo_1.exe
2011-03-22 21:39 . 2011-03-22 21:39 632064 ----a-w- c:\windows\system32\msvcr80.dll
2011-03-22 21:39 . 2011-03-22 21:39 554240 ----a-w- c:\windows\system32\msvcp80.dll
2011-03-22 21:39 . 2011-03-22 21:39 34048 ----a-w- c:\windows\system32\eEmpty.exe
2011-03-22 21:39 . 2011-03-22 21:39 -------- d-----w- c:\program files\Common Files\MicroWorld
2011-03-22 21:39 . 2011-03-22 21:39 -------- d-----w- c:\programdata\MicroWorld
2011-03-22 20:38 . 2011-03-22 20:38 -------- d-----w- c:\users\Mira\AppData\Roaming\Malwarebytes
2011-03-22 20:38 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-22 20:38 . 2011-03-22 20:38 -------- d-----w- c:\programdata\Malwarebytes
2011-03-22 20:38 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-22 20:38 . 2011-03-22 20:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-20 19:39 . 2011-03-20 19:39 -------- d-----w- c:\programdata\2A35
2011-03-16 18:25 . 2011-03-20 19:46 -------- d-----w- c:\users\Mira\AppData\Local\iMesh
2011-03-16 18:24 . 2011-03-27 21:28 -------- d-----w- c:\program files\iMesh Applications
2011-03-16 18:23 . 2011-03-22 20:03 -------- d--h--w- c:\programdata\{8A4124D0-6AF6-4584-A7BF-4CDFECF4B129}
2011-03-14 10:47 . 2011-03-14 10:47 -------- d-----w- c:\users\Mira\AppData\Local\PackageAware
2011-03-13 19:25 . 2011-03-13 19:25 -------- d-----w- c:\program files\ABC
2011-03-13 12:08 . 2011-03-13 15:05 -------- d-----w- c:\program files\Scorpions WinCheater
2011-03-10 10:20 . 2011-03-10 10:34 -------- d-----w- c:\programdata\MGS
2011-03-10 10:19 . 2011-03-10 10:19 -------- d-----w- C:\Microgaming
2011-03-08 20:53 . 2011-02-19 05:33 802304 ----a-w- c:\windows\system32\FntCache.dll
2011-03-08 20:53 . 2011-02-19 05:32 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-03-08 20:53 . 2011-02-19 05:32 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-03-08 20:53 . 2010-12-23 05:28 850432 ----a-w- c:\windows\system32\sbe.dll
2011-03-08 20:53 . 2010-12-23 05:28 642048 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-08 20:53 . 2010-12-23 05:28 534528 ----a-w- c:\windows\system32\EncDec.dll
2011-03-08 20:53 . 2010-12-23 05:24 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-08 20:53 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\system32\mstscax.dll
2011-03-08 20:53 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\system32\mstsc.exe
2011-03-05 12:15 . 2011-03-05 12:15 297416 ----a-w- c:\users\Mira\quickloader.exe
2011-03-02 21:01 . 2011-03-02 21:02 -------- d-----w- c:\program files\Nová složka
2011-03-02 20:37 . 2011-03-02 20:37 -------- d-----w- c:\program files\Fotky monca
2011-03-02 18:16 . 2011-03-02 18:17 -------- d-----w- c:\program files\Fotky
2011-03-02 09:46 . 2011-03-02 09:46 -------- d-----w- c:\users\Mira\AppData\Local\Opera
2011-03-02 09:46 . 2011-03-22 20:03 -------- d-----w- c:\program files\Opera
2011-03-02 08:59 . 2011-03-02 08:59 3953640 ----a-w- c:\users\Mira\wd97vwr32.exe
2011-03-02 08:44 . 2011-03-02 08:44 570570144 ----a-w- c:\users\Mira\X16-32004Office2010CzechSingleImage32bit.exe
2011-03-02 08:25 . 2011-03-02 08:25 37033368 ----a-w- c:\users\Mira\AdbeRdr1000_cs_CZ.exe
2011-03-02 08:15 . 2011-03-02 08:15 5177938 ----a-w- c:\users\Mira\WordToPDF_setup.exe
2011-03-02 08:12 . 2011-03-02 08:13 6290105 ----a-w- c:\users\Mira\pdf2word.exe
2011-03-02 08:06 . 2011-03-02 08:06 -------- d-----w- c:\users\Mira\AppData\Roaming\skypePM
2011-03-02 07:58 . 2011-03-04 11:59 -------- d-----w- c:\users\Mira\AppData\Roaming\Skype
2011-03-02 07:54 . 2011-03-02 07:54 1029000 ----a-w- c:\users\Mira\SkypeSetup.exe
2011-02-26 11:22 . 2011-02-26 11:22 -------- d-----w- C:\591965b3ccf0c2340456
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-24 18:08 . 2010-07-24 09:19 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2011-03-24 18:08 . 2010-07-24 09:18 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-02-18 23:39 . 2010-07-17 19:57 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2011-02-06 10:19 . 2010-07-17 19:56 484160 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-02-03 05:45 . 2011-02-09 09:23 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-02 17:11 . 2010-12-11 21:59 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-29 14:13 . 2011-01-29 14:13 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-01-17 10:34 . 2011-01-17 10:34 13768192 ----a-w- c:\users\Mira\AGT_Pro_1.1b.msi
2011-01-07 07:31 . 2011-02-23 10:33 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-07 07:31 . 2011-02-23 10:33 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-07 07:27 . 2011-02-09 09:23 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-07 05:33 . 2011-02-09 09:23 294400 ----a-w- c:\windows\system32\atmfd.dll
2011-01-05 05:37 . 2011-02-09 09:24 428032 ----a-w- c:\windows\system32\vbscript.dll
2011-01-05 03:37 . 2011-02-09 09:24 2329088 ----a-w- c:\windows\system32\win32k.sys
2010-12-29 19:34 . 2010-12-29 19:34 7225344 ----a-w- c:\users\Mira\stanjamesDLCInstaller.msi
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPADVISOR"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-07-16 1668664]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2009-07-27 288312]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-08-25 186904]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2009-06-18 563736]
"WirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\Agent\Splash.exe" [2009-07-16 562496]
"McAfee Managed Services Tray"="c:\program files\McAfee\Managed VirusScan\Agent\StartMyAgtTry.Exe" [2009-07-16 95552]
"SiteAdvisor"="c:\program files\SiteAdvisor\6173\SiteAdv.exe" [2007-08-28 36640]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-05-18 1314816]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-30 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-01-29 685816]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 136176]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 massfilter;Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2010-02-22 9216]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-13 1120752]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-07-23 1343400]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-04 176128]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2009-07-08 26168]
S2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe [2009-07-16 221024]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2009-06-18 635416]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2009-05-05 228408]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 09:38]
.
2011-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-14 09:38]
.
2011-03-26 c:\windows\Tasks\HPCeeScheduleForMira.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-09-20 21:38]
.
.
------- Doplňkový sken -------
.
mStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... ll&pf=cmnbIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: {37DE6602-75DD-416B-AFA1-E69AE981F1C8} = 213.226.224.12,194.213.224.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll
Toolbar-{28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\IMESHA~1\MediaBar\ToolBar\imeshdtxmltbpi.dll
Toolbar-10 - (no file)
HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
AddRemove-LSI Soft Modem - c:\windows\agrsmdel
AddRemove-MVS - c:\program files\McAfee\Managed VirusScan\Agent\myinx
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-03-28 01:30:28
ComboFix-quarantined-files.txt 2011-03-27 23:30
.
Před spuštěním: Volných bajtů: 191 862 509 568
Po spuštění: Volných bajtů: 193 096 966 144
.
- - End Of File - - 7674FBACA62E16DC3ED3A410CB803E81