ComboFix 12-05-06.03 - Miroslav 06.05.2012 20:38:15.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1279.710 [GMT 2:00]
Spuštěný z: c:\documents and settings\Miroslav\Plocha\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\reghmf.exe
c:\windows\system32\roboot.exe
c:\windows\system32\UNWISE.EXE
.
Nakažená kopie c:\windows\system32\midimap.dll byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\NiwradSoft Shell Pack\Backup\midimap.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-04-06 do 2012-05-06 )))))))))))))))))))))))))))))))
.
.
2012-05-05 19:22 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-05 19:22 . 2012-05-05 19:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-28 04:23 . 2012-04-28 04:23 -------- d-----w- c:\documents and settings\Miroslav\Local Settings\Data aplikací\Sun
2012-04-28 03:18 . 2012-04-28 03:18 -------- d-----w- c:\program files\Common Files\Java
2012-04-28 03:08 . 2012-04-28 03:07 141312 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-28 03:08 . 2012-04-28 03:07 637848 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-04-28 03:08 . 2012-04-28 03:07 567696 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-28 03:07 . 2012-04-28 03:07 -------- d-----w- c:\program files\Java
2012-04-26 17:18 . 2001-08-17 19:51 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
2012-04-26 17:18 . 2008-04-14 06:51 27648 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2012-04-26 17:18 . 2008-04-14 06:51 27648 ----a-w- c:\windows\system32\irmon.dll
2012-04-26 17:18 . 2008-04-13 22:24 88192 -c--a-w- c:\windows\system32\dllcache\irda.sys
2012-04-26 17:18 . 2008-04-13 22:24 88192 ----a-w- c:\windows\system32\drivers\irda.sys
2012-04-26 17:18 . 2008-04-14 06:52 152064 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2012-04-26 17:18 . 2008-04-14 06:52 152064 ----a-w- c:\windows\system32\irftp.exe
2012-04-26 17:18 . 2008-04-14 06:52 8192 ----a-w- c:\windows\system32\wshirda.dll
2012-04-26 17:18 . 2004-12-01 07:43 31048 ----a-r- c:\windows\system32\drivers\uir1100a.sys
2012-04-25 17:12 . 2012-04-25 17:12 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 17:12 . 2012-04-21 01:18 97208 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-04-25 17:11 . 2012-04-21 01:16 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-25 17:11 . 2012-04-21 01:16 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-22 09:03 . 2012-04-22 09:03 -------- d-----w- c:\program files\MSXML 4.0
2012-04-22 09:03 . 2012-01-09 15:28 8576 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2012-04-22 09:02 . 2012-01-09 15:28 137600 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2012-04-22 09:02 . 2012-01-09 15:28 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2012-04-22 09:02 . 2012-01-09 15:28 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2012-04-22 09:02 . 2012-01-09 15:28 23168 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2012-04-22 09:02 . 2012-01-09 15:28 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2012-04-22 08:57 . 2012-04-22 08:57 73728 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\NewShortcut47_74B9CE5DF1F4447F982DCA29A461B529.exe
2012-04-22 08:57 . 2012-04-22 08:57 49152 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\Uninstall_QA_OTI_H_FE5D756F71E147C4972AD6775344B40B.exe
2012-04-22 08:57 . 2012-04-22 08:57 73728 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\NewShortcut46_74B9CE5DF1F4447F982DCA29A461B529.exe
2012-04-22 08:57 . 2012-04-22 08:57 53248 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\ARPPRODUCTICON.exe
2012-04-22 08:57 . 2012-04-22 08:57 49152 ----a-r- c:\documents and settings\Miroslav\Data aplikací\Microsoft\Installer\{7130468A-F53F-4698-8C09-A339EA3B05E6}\NewShortcut2_1C7B7089989A424FB39D41A32581C775.exe
2012-04-22 08:56 . 2012-04-22 08:56 -------- d-----w- c:\documents and settings\Miroslav\Local Settings\Data aplikací\Nokia
2012-04-22 08:55 . 2012-04-22 09:02 -------- d-----w- c:\program files\Nokia
2012-04-22 08:08 . 2012-04-22 08:08 -------- d-----w- c:\program files\ESET
2012-04-22 08:08 . 2012-04-22 08:08 -------- d-----w- c:\documents and settings\All Users\Data aplikací\ESET
2012-04-22 06:29 . 2006-11-22 08:01 693760 ----a-w- c:\windows\system32\drivers\hardlock.sys
2012-04-22 06:01 . 2012-04-22 15:09 -------- d-----w- c:\program files\TNod User & Password Finder
2012-04-22 06:00 . 2012-04-22 06:00 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\ESET
2012-04-11 19:34 . 2012-05-04 19:41 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-11 18:33 . 2008-04-13 22:15 26112 ----a-w- c:\windows\system32\drivers\usbser.sys
2012-04-11 18:31 . 2008-11-07 16:55 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2012-04-11 18:29 . 2012-04-22 11:36 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Nokia
2012-04-11 18:29 . 2012-04-11 18:33 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\PC Suite
2012-04-11 18:29 . 2012-04-11 18:29 -------- d-----w- c:\documents and settings\All Users\Data aplikací\PC Suite
2012-04-11 18:21 . 2012-04-11 18:21 -------- d-----w- c:\program files\Common Files\PCSuite
2012-04-11 18:21 . 2012-04-22 08:56 -------- d-----w- c:\program files\Common Files\Nokia
2012-04-11 18:19 . 2012-04-11 18:21 -------- d-----w- c:\program files\DIFX
2012-04-11 18:19 . 2008-08-26 07:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2012-04-11 18:18 . 2012-04-11 18:18 -------- d-----w- c:\program files\PC Connectivity Solution
2012-04-11 18:17 . 2011-11-01 08:07 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2012-04-11 18:17 . 2011-11-01 08:07 605696 ----a-w- c:\windows\system32\nmwcdcocls.dll
2012-04-11 18:17 . 2011-11-01 08:07 123904 ----a-w- c:\windows\system32\ccdcmbwu.dll
2012-04-11 18:17 . 2012-01-09 15:28 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2012-04-11 18:13 . 2012-04-22 08:41 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Installations
2012-04-10 18:32 . 2012-04-11 02:23 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\Kastner software
2012-04-10 18:31 . 2012-04-11 02:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\KASTNER software
2012-04-09 22:03 . 2012-04-09 22:03 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\pdfforge
2012-04-09 22:03 . 2012-03-14 16:23 54784 ----a-w- c:\windows\system32\pdfcmon.dll
2012-04-09 22:03 . 2004-03-08 23:00 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX
2012-04-09 22:03 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2012-04-09 22:03 . 2012-04-09 22:04 -------- d-----w- c:\program files\PDFCreator
2012-04-09 08:10 . 2012-04-15 17:12 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MyHeritage
2012-04-09 08:10 . 2012-04-09 08:12 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\MyHeritage
2012-04-09 08:10 . 2002-03-06 22:19 454656 ----a-w- c:\windows\system32\PaintX.dll
2012-04-09 08:10 . 2003-07-06 11:07 372736 ----a-w- c:\windows\system32\ijl15.dll
2012-04-09 08:10 . 2000-05-22 14:58 608448 ----a-w- c:\windows\system32\comctl32.ocx
2012-04-09 08:10 . 2012-04-09 08:10 -------- d-----w- c:\documents and settings\Miroslav\Data aplikací\The Complete Genealogy Reporter - FTB
2012-04-09 08:07 . 2012-04-15 17:12 -------- d-----w- c:\program files\MyHeritage
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-04 19:41 . 2012-02-28 22:44 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-21 00:10 . 2012-03-21 00:10 11167 ----a-w- c:\documents and settings\Miroslav\Data aplikací\mdbu.bin
2012-03-21 00:10 . 2012-03-21 00:10 11167 ----a-w- c:\documents and settings\Miroslav\Data aplikací\mdbu.bin
2012-03-21 00:10 . 2012-03-21 00:10 11167 ----a-w- c:\documents and settings\Miroslav\Data aplikací\mdbu.bin
2012-03-21 00:10 . 2012-03-21 00:10 11167 ----a-w- c:\documents and settings\Miroslav\Data aplikací\mdbu.bin
2012-03-13 16:51 . 2012-03-13 16:51 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2012-03-11 11:48 . 2012-03-11 11:48 2272 ----a-w- c:\windows\system32\w95inf16.dll
2012-03-11 11:48 . 2012-03-11 11:48 4608 ----a-w- c:\windows\system32\w95inf32.dll
2012-03-09 06:57 . 2012-03-10 20:04 545 ----a-w- c:\windows\UC.PIF
2012-03-09 06:57 . 2012-03-10 20:04 545 ----a-w- c:\windows\RAR.PIF
2012-03-09 06:57 . 2012-03-10 20:04 545 ----a-w- c:\windows\NOCLOSE.PIF
2012-03-09 06:57 . 2012-03-10 20:04 545 ----a-w- c:\windows\LHA.PIF
2012-03-09 06:57 . 2012-03-10 20:04 545 ----a-w- c:\windows\ARJ.PIF
2012-03-04 21:55 . 2012-03-04 21:54 191488 ----a-w- c:\windows\system32\hlvdd.dll
2012-03-03 00:45 . 2012-03-03 00:45 15872 ----a-w- c:\windows\system32\drivers\HMFAxCore56d706f6725c732df006697fd5ec3381.sys
2012-03-02 20:42 . 2004-08-17 13:49 219648 ----a-w- c:\windows\system32\uxtheme.dll
2012-03-01 10:59 . 2004-08-17 13:49 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-01 10:59 . 2004-08-17 13:49 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 10:59 . 2004-08-17 13:49 43520 ------w- c:\windows\system32\licmgr10.dll
2012-02-29 14:10 . 2004-08-17 13:49 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2004-08-17 13:49 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2004-08-17 13:44 385024 ------w- c:\windows\system32\html.iec
2012-02-07 09:02 . 2012-02-07 09:02 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2011-07-12 20:35 . 2012-02-28 23:12 104960 ----a-w- c:\program files\em-date.exe
2012-04-21 01:18 . 2012-04-25 17:12 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-14 07:51 . E7B375DFFB68A16659CA66474A280C47 . 806912 . . [2001.12.4414.700] . . c:\windows\NiwradSoft Shell Pack\Backup\comres.dll
[-] 2008-04-14 07:51 . 9BBABCB691B887769048255FA7047C05 . 1508864 . . [2001.12.4414.700] . . c:\windows\ServicePackFiles\i386\comres.dll
[-] 2008-04-14 07:51 . 9BBABCB691B887769048255FA7047C05 . 1508864 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
[7] 2004-08-17 13:49 . B44F68274AB7B8A54E9AD74AFF0EFAAC . 806912 . . [2001.12.4414.258] . . c:\windows\$NtServicePackUninstall$\comres.dll
.
[7] 2008-04-14 . CDDB1F8E1AEA356F3AD106F2CF9B7FEA . 507904 . . [5.1.2600.5512] . . c:\windows\NiwradSoft Shell Pack\Backup\winlogon.exe
[-] 2008-04-14 . 471341D353962A35DA3C6324D59D09C4 . 547328 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . 471341D353962A35DA3C6324D59D09C4 . 547328 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2004-08-17 . 221C29AE1B4CC61D11D8B27DE78B2307 . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
.
[7] 2010-08-23 . E145ADD7DAEF759C4F5FB80A180A9C30 . 617472 . . [5.82] . . c:\windows\NiwradSoft Shell Pack\Backup\comctl32.dll
[-] 2010-08-23 . 157577AE3ED2862091111184966FAB66 . 643072 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2010-08-23 . 157577AE3ED2862091111184966FAB66 . 643072 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2010-08-23 . 157577AE3ED2862091111184966FAB66 . 643072 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
[7] 2010-08-23 . 8A72A30FDC803DC06755D3B36D966F31 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[7] 2008-04-14 . 4F993463DC5F3F80D77A3D34D7BFBFED . 617472 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll
[7] 2008-04-14 . D7B7AE36A2EBA312AC4B53862019B3F5 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[7] 2004-08-17 . 876C658C44F2BF4AF050E5534A9F066F . 611328 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[7] 2004-08-17 . F76B3003366A205E05AFC0D034C7D3E9 . 1050624 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
[7] 2001-10-25 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
.
[7] 2008-04-14 . E16E0990967374E76F3E40CACAFD3D53 . 578560 . . [5.1.2600.5512] . . c:\windows\NiwradSoft Shell Pack\Backup\user32.dll
[-] 2008-04-14 . CCB32D10C69A89822E9134C0C4894BE1 . 578560 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . CCB32D10C69A89822E9134C0C4894BE1 . 578560 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[7] 2004-08-17 . 1B4CCC59980DA34E75F20E42B283B027 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\user32.dll
.
[-] 2008-04-14 . D63C59BB0CA2F83B62D003FD52863090 . 1541120 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 27AFD587C462E280EE046B8CCA3C2CD1 . 1034240 . . [6.00.2900.5512] . . c:\windows\NiwradSoft Shell Pack\Backup\explorer.exe
[-] 2008-04-14 . D63C59BB0CA2F83B62D003FD52863090 . 1541120 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2004-08-17 . 53114D57AB73A406AC7F602227781A99 . 1032704 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
[-] 2008-04-14 . 6915639F41228891A883B2DA59AA7429 . 277504 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[7] 2008-04-14 . FDEB1D02CAE38665CBF114F44E6B997E . 147968 . . [5.1.2600.5512] . . c:\windows\NiwradSoft Shell Pack\Backup\regedit.exe
[-] 2008-04-14 . 6915639F41228891A883B2DA59AA7429 . 277504 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regedit.exe
[7] 2004-08-17 . CB5A91928D94224E7E30EE277B45E8A3 . 147968 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regedit.exe
.
[7] 2011-11-01 . ED9B683C7A8BBAAAB9B377197D20832C . 1288192 . . [5.1.2600.6168] . . c:\windows\NiwradSoft Shell Pack\Backup\ole32.dll
[-] 2011-11-01 . 2AB08107D0AEB88B6CAA786EFBB48C6B . 1313280 . . [5.1.2600.6168] . . c:\windows\ServicePackFiles\i386\ole32.dll
[-] 2011-11-01 . 2AB08107D0AEB88B6CAA786EFBB48C6B . 1313280 . . [5.1.2600.6168] . . c:\windows\system32\ole32.dll
[-] 2011-11-01 . 2AB08107D0AEB88B6CAA786EFBB48C6B . 1313280 . . [5.1.2600.6168] . . c:\windows\system32\dllcache\ole32.dll
[7] 2011-11-01 . B5EEF42BC72418EECC3DD3D93B2B5F34 . 1288704 . . [5.1.2600.6168] . . c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
[7] 2010-07-16 . 6D1A3A355CA2AC64D2D5BAEC25C16427 . 1287680 . . [5.1.2600.6010] . . c:\windows\$NtUninstallKB2624667$\ole32.dll
[7] 2010-07-16 . C85BE0CF9C91EB64CECA1D639D71D4CC . 1288704 . . [5.1.2600.6010] . . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll
[7] 2008-04-14 . 21F836AAB269FF644E0E708B794B0DF7 . 1287168 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB979687$\ole32.dll
[7] 2004-08-17 . 7FE54C063DDA8EF226846510852E6B1B . 1281024 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ole32.dll
.
[7] 2008-04-14 . A756B8F0F7BAFBA6DFE39F7D169F2519 . 15360 . . [5.1.2600.5512] . . c:\windows\NiwradSoft Shell Pack\Backup\ctfmon.exe
[-] 2008-04-14 . 0415E09C0BCCBF8B5CD5A05889EFB962 . 40448 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . 0415E09C0BCCBF8B5CD5A05889EFB962 . 40448 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2004-08-17 . A5BAA91475167161DEA02BA3C4CA4F59 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
[7] 2008-04-14 . ED18ADEE4AA21EB26977260152D7241A . 345088 . . [5.1.2600.5512] . . c:\windows\NiwradSoft Shell Pack\Backup\hnetcfg.dll
[-] 2008-04-14 . FDE84E2C6D0E1F75D61D7CC111A1DA5A . 369152 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\hnetcfg.dll
[-] 2008-04-14 . FDE84E2C6D0E1F75D61D7CC111A1DA5A . 369152 . . [5.1.2600.5512] . . c:\windows\system32\hnetcfg.dll
[7] 2004-08-17 . FAABA83BE47C5B15F620FAA53267A9B8 . 345088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\hnetcfg.dll
.
[7] 2011-10-26 . 8AE4032D26FB72F39BEA8BB4D4F8AC30 . 2071552 . . [5.1.2600.6165] . . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[7] 2011-10-26 . 8AE4032D26FB72F39BEA8BB4D4F8AC30 . 2071552 . . [5.1.2600.6165] . . c:\windows\NiwradSoft Shell Pack\Backup\ntkrnlpa.exe
[-] 2011-10-26 . FDD5B5435ECC5E5AF6F405AEF371CEB1 . 2232704 . . [5.1.2600.6165] . . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2011-10-26 . FDD5B5435ECC5E5AF6F405AEF371CEB1 . 2232704 . . [5.1.2600.6165] . . c:\windows\system32\ntkrnlpa.exe
[-] 2011-10-26 . FDD5B5435ECC5E5AF6F405AEF371CEB1 . 2232704 . . [5.1.2600.6165] . . c:\windows\system32\dllcache\ntkrnlpa.exe
[7] 2011-10-26 . 64201EB5A7ECB3E7203ECCDB60FBE44E . 2071552 . . [5.1.2600.6165] . . c:\windows\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe
[7] 2010-12-09 . 40D176442F70573DBA0E05A7E40D3EBB . 2071552 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe
[7] 2009-02-09 . FF8A3F180A224AA27EBAB937CA027F4D . 2068352 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[7] 2008-04-14 . 4DEE41C45E803DB91A72FD1BA69C05EE . 2067968 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2633171$\ntkrnlpa.exe
[7] 2004-08-17 . E86DD06F2B8F919DDF23F78A3BF2AA23 . 2059008 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
.
[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\NiwradSoft Shell Pack\Backup\iexplore.exe
[-] 2009-03-08 . F68C1BAC147227B86FFB36828FF8BEDF . 510816 . . [8.00.6001.18702] . . c:\windows\ServicePackFiles\i386\iexplore.exe
[-] 2009-03-08 . F68C1BAC147227B86FFB36828FF8BEDF . 510816 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
[7] 2008-04-14 . 414AFE6E8CCDE984E16D5ED08624CEC6 . 93184 . . [6.00.2900.5512] . . c:\windows\ie8\iexplore.exe
[7] 2004-08-17 . 63E527C26AC3059EAD766C6C11746D07 . 93184 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\iexplore.exe
.
[7] 2011-10-26 . 702435ABA81209767F8AADD8813A1A73 . 2194944 . . [5.1.2600.6165] . . c:\windows\Driver Cache\i386\ntoskrnl.exe
[7] 2011-10-26 . 702435ABA81209767F8AADD8813A1A73 . 2194944 . . [5.1.2600.6165] . . c:\windows\NiwradSoft Shell Pack\Backup\ntoskrnl.exe
[-] 2011-10-26 . F3CCE8B39CC79D2C6B8C46DDD2AA7EC2 . 2356096 . . [5.1.2600.6165] . . c:\windows\ServicePackFiles\i386\ntoskrnl.exe
[-] 2011-10-26 . F3CCE8B39CC79D2C6B8C46DDD2AA7EC2 . 2356096 . . [5.1.2600.6165] . . c:\windows\system32\ntoskrnl.exe
[-] 2011-10-26 . F3CCE8B39CC79D2C6B8C46DDD2AA7EC2 . 2356096 . . [5.1.2600.6165] . . c:\windows\system32\dllcache\ntoskrnl.exe
[7] 2011-10-26 . BCA329B5A39AB25CC2DCCB3549EE30BF . 2194944 . . [5.1.2600.6165] . . c:\windows\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe
[7] 2010-12-09 . 8D222D8EF9B1951296F822583A044542 . 2194944 . . [5.1.2600.6055] . . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntoskrnl.exe
[7] 2009-02-10 . 97480EBFE1D4B547657BAD75AAAB1325 . 2191360 . . [5.1.2600.5755] . . c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[7] 2008-04-14 . C1536014AC1CB1D5397E31D9735E6571 . 2191104 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB2633171$\ntoskrnl.exe
[7] 2004-08-17 . 12C80E46DCEC9B82473D1B1B9DA1F16B . 2183168 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 40448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EM-DATE"="c:\program files\em-date.exe" [2011-07-12 104960]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2219184]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM-DATE]
2011-07-12 20:35 104960 ----a-w- c:\program files\em-date.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
2011-12-21 15:26 229376 ----a-w- c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 15:50 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware]
2012-04-04 13:56 462408 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSU_agent]
2012-02-28 13:53 190768 ----a-w- c:\program files\Nokia\Nokia Software Updater\nsu3ui_agent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2012-03-26 09:24 1516600 ----a-w- d:\program files\Nokia PC Suite\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
2004-06-10 10:54 286720 ----a-w- c:\windows\vsnpstd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 09:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NVIEW"=rundll32.exe nview.dll,nViewLoadHook
"CTFMON.EXE"=c:\windows\system32\ctfmon.exe
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /install
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\ICQ7.7\\ICQ.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [28.4.2010 8:17 115008]
R1 HMFAxCore56d706f6725c732df006697fd5ec3381;HMFAxCore56d706f6725c732df006697fd5ec3381;c:\windows\system32\drivers\HMFAxCore56d706f6725c732df006697fd5ec3381.sys [3.3.2012 2:45 15872]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [12.1.2011 16:41 810144]
R2 NSHE;Guardant Emulator Driver;c:\windows\system32\drivers\NSHE.SYS [4.3.2012 23:59 97792]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15.2.2012 14:30 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [11.4.2012 21:34 257696]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [13.3.2012 18:51 23456]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [1.3.2012 5:15 22640]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25.4.2012 19:12 129976]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.4.2012 11:02 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.4.2012 11:03 8576]
S3 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [21.4.2007 15:54 52080]
S3 uir1100a;UIR1100A;c:\windows\system32\drivers\uir1100a.sys [26.4.2012 19:18 31048]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-05-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 19:41]
.
2012-05-06 c:\windows\Tasks\User_Feed_Synchronization-{4C9AA047-09F5-4498-A134-1F4EC8165FDF}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
TCP: DhcpNameServer = 10.29.2.1 192.168.0.1
FF - ProfilePath - c:\documents and settings\Miroslav\Data aplikací\Mozilla\Firefox\Profiles\0lk5zctw.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.seznam.cz/?#obsahFF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=green ... =183666&p=FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autoFill - false
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.urlbar.hideGoButton - false
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=108298
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.id - 4419d34700000000000000e07dc2c92e
FF - user.js: extensions.BabylonToolbar_i.hardId - 4419d34700000000000000e07dc2c92e
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15400
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:30
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Hardlock Device Drivers - c:\windows\system32\UNWISE.EXE
AddRemove-Hardlock Gerätetreiber - c:\windows\system32\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-05-06 20:53
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1236)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'lsass.exe'(1292)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\psbase.dll
.
- - - - - - - > 'explorer.exe'(3104)
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\WPDShServiceObj.dll
d:\program files\Nokia PC Suite\Nokia PC Suite 7\PhoneBrowser.dll
d:\program files\Nokia PC Suite\Nokia PC Suite 7\NGSCM.DLL
d:\program files\Nokia PC Suite\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
d:\program files\Nokia PC Suite\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
.
**************************************************************************
.
Celkový čas: 2012-05-06 21:04:42 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-05-06 19:04
.
Před spuštěním: 1 089 581 056
Po spuštění: 1 052 209 152
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 973FF6B1E7FFE8E4B80CDFEC3A85B81A