ComboFix 09-09-24.01 - Marek 25.09.2009 19:25.16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1023.407 [GMT 2:00]
Spuštěný z: c:\documents and settings\Marek\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Marek\Plocha\CFScript.txt
AV: F-Secure Profi Antivirus 8.01 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Profi Antivirus 8.01 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
* Vytvořen nový Bod Obnovení
FILE ::
"c:\windows\system32\eEmpty.exe"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Marek\temp
c:\documents and settings\Marek\temp\TeamViewer\Version4\Teamviewer_Resource.dll
c:\program files\Alwil Software
c:\program files\Common Files\Symantec Shared
c:\program files\Crawler
c:\program files\Crawler\Toolbar\adrkeys.dat
c:\program files\Crawler\Toolbar\COMMON_FF.dat
c:\program files\Crawler\Toolbar\confirm.dat
c:\program files\Crawler\Toolbar\ctbcomm.dll
c:\program files\Crawler\Toolbar\CTConf.dat
c:\program files\Crawler\Toolbar\CTipsDef.dll
c:\program files\Crawler\Toolbar\CToolbar.exe
c:\program files\Crawler\Toolbar\CUpdate.exe
c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
c:\program files\Crawler\Toolbar\firefox\components\xplugin.xpt
c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
c:\program files\Crawler\Toolbar\firefox\components\xshared.xpt
c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
c:\program files\Crawler\Toolbar\firefox\components\xsupport.xpt
c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
c:\program files\Crawler\Toolbar\firefox\chrome.manifest
c:\program files\Crawler\Toolbar\firefox\chrome\common.jar
c:\program files\Crawler\Toolbar\firefox\chrome\stwsg.jar
c:\program files\Crawler\Toolbar\firefox\install.ini
c:\program files\Crawler\Toolbar\firefox\install.rdf
c:\program files\Crawler\Toolbar\firefox\stwsg_ff.ini
c:\program files\Crawler\Toolbar\Languages\STWSG_CS.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_DE.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_EN.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_ES.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_FF.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_FR.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_IT.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_NL.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_PT-BR.cab
c:\program files\Crawler\Toolbar\Languages\STWSG_PT.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_CS.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_DE.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_EN.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_ES.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_FR.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_IT.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_NL.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_PL.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_PT-BR.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_PT.cab
c:\program files\Crawler\Toolbar\Languages\TBR5_RU.cab
c:\program files\Crawler\Toolbar\lookfor.dat
c:\program files\Crawler\Toolbar\majorse.dat
c:\program files\Crawler\Toolbar\rootmenu.dat
c:\program files\Crawler\Toolbar\services.dat
c:\program files\Crawler\Toolbar\STWSG_FF.dat
c:\program files\Crawler\Toolbar\STWSGLanguageAct\info.ini
c:\program files\Crawler\Toolbar\STWSGLanguageAct\language.ini
c:\program files\Crawler\Toolbar\TBR5LanguageAct\info.ini
c:\program files\Crawler\Toolbar\TBR5LanguageAct\language.ini
c:\program files\Crawler\Toolbar\Update\domains.cab
c:\program files\Crawler\Toolbar\WebSecurityGuard.dll
c:\program files\Crawler\Toolbar\WSGData\domains\domains_000.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_000_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_001.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_001_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_002.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_002_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_003.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_003_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_004.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_004_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_005.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_005_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_006.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_006_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_007.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_007_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_008.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_008_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_009.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_009_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_010.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_010_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_011.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_011_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_012.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_012_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_013.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_013_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_014.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_014_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_015.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_015_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_016.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_016_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_017.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_017_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_018.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_018_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_019.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_019_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_020.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_020_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_021.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_021_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_022.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_022_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_023.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_023_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_024.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_024_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_025.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_025_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_026.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_026_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_027.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_027_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_028.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_028_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_029.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_029_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_030.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_030_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_031.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_031_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_032.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_032_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_033.dat
c:\program files\Crawler\Toolbar\WSGData\domains\domains_033_diff.dat
c:\program files\Crawler\Toolbar\WSGData\domains\index.dat
c:\program files\Crawler\Toolbar\WSGData\g_S-1-5-21-1409082233-220523388-1801674531-1004.dat
c:\program files\Crawler\Toolbar\WSGData\g_S-1-5-21-1409082233-220523388-1801674531-1006.dat
c:\program files\Crawler\Toolbar\WSGData\g_S-1-5-21-1409082233-220523388-1801674531-1007.dat
c:\program files\Crawler\Toolbar\WSGData\ud_S-1-5-21-1409082233-220523388-1801674531-1004.dat
c:\program files\Crawler\Toolbar\WSGData\w_S-1-5-21-1409082233-220523388-1801674531-1004.dat
c:\program files\Crawler\Toolbar\WSGData\w_S-1-5-21-1409082233-220523388-1801674531-1006.dat
c:\program files\Crawler\Toolbar\WSGData\wfilter.dat
c:\program files\McAfee UnInstaller 6.5 Demo English
c:\program files\McAfee UnInstaller 6.5 Demo English\Contact.Txt
c:\program files\McAfee UnInstaller 6.5 Demo English\extra.cab
c:\program files\McAfee UnInstaller 6.5 Demo English\instmsia.exe
c:\program files\McAfee UnInstaller 6.5 Demo English\instmsiw.exe
c:\program files\McAfee UnInstaller 6.5 Demo English\Readme.txt
c:\program files\McAfee UnInstaller 6.5 Demo English\setup.exe
c:\program files\McAfee UnInstaller 6.5 Demo English\setup.ini
c:\program files\McAfee UnInstaller 6.5 Demo English\UNI.msi
c:\program files\McAfee UnInstaller 6.5 Demo English\UNI.pdf
c:\program files\NortonInstaller
c:\windows\logo_1.exe
c:\windows\RUNDL132.EXE
c:\windows\system32\eEmpty.exe
c:\windows\VDLL.DLL
.
((((((((((((((((((((((((( Soubory vytvořené od 2009-08-25 do 2009-09-25 )))))))))))))))))))))))))))))))
.
2009-09-25 12:11 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-25 12:11 . 2009-09-25 12:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-25 12:11 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-23 14:23 . 2009-09-25 12:35 -------- d-----w- c:\windows\system32\Adobe
2009-09-23 14:02 . 2009-09-23 14:02 -------- d-----w- c:\program files\Warp
2009-09-21 16:34 . 2009-09-22 17:00 -------- d-----w- c:\program files\Call of Juarez SP Demo
2009-09-21 15:15 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-20 13:28 . 2009-09-21 15:01 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-19 18:02 . 2009-09-19 18:18 33920 ----a-w- c:\windows\system32\drivers\fsbts.sys
2009-09-19 18:02 . 2008-12-04 13:57 79872 ----a-w- c:\windows\system32\drivers\fsdfw.sys
2009-09-19 18:00 . 2009-09-25 11:25 -------- d-----w- c:\program files\F-Secure
2009-09-19 15:30 . 2009-09-19 15:31 -------- d-----w- c:\program files\Security Task Manager
2009-09-19 09:33 . 2009-09-19 17:45 -------- d-----w- c:\program files\ESET
2009-09-18 17:23 . 2009-09-18 17:23 12 ----a-w- c:\documents and settings\Marek\USERDATA.DAT
2009-09-12 15:56 . 2009-09-12 16:03 -------- d-----w- c:\program files\ICQ6.5
2009-09-10 15:29 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-01 16:41 . 2009-09-01 16:43 -------- d-----w- c:\program files\Common Files\Jasc Software Inc
2009-09-01 16:40 . 2009-09-01 16:41 -------- d-----w- c:\program files\Jasc Software Inc
2009-09-01 16:33 . 2009-09-01 16:33 -------- d-----w- c:\program files\Bonjour
2009-09-01 16:05 . 2009-09-01 16:05 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-01 14:34 . 2009-09-01 14:34 160285 ----a-w- c:\windows\Sqirlz Morph Uninstaller.exe
2009-09-01 14:34 . 2009-09-01 14:34 -------- d-----w- c:\program files\Sqirlz Morph
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 15:11 . 2007-01-20 12:48 -------- d-----w- c:\program files\Lavasoft
2009-09-19 18:02 . 2004-08-18 12:00 95722 ----a-w- c:\windows\system32\perfc005.dat
2009-09-19 18:02 . 2004-08-18 12:00 467428 ----a-w- c:\windows\system32\perfh005.dat
2009-09-19 13:09 . 2009-07-28 08:44 -------- d-----w- c:\program files\Trend Micro
2009-09-12 15:57 . 2008-05-29 15:58 -------- d-----w- c:\program files\ICQ6
2009-09-05 16:41 . 2006-07-04 06:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-02 09:26 . 2008-11-06 15:38 -------- d-----w- c:\program files\NextUp Talker
2009-09-01 16:54 . 2006-07-10 07:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-31 14:44 . 2008-02-03 17:51 -------- d-----w- c:\program files\Toribash-3.1
2009-08-31 13:59 . 2009-08-09 10:20 -------- d-----w- c:\program files\Passware
2009-08-31 13:54 . 2009-04-13 16:45 -------- d-----w- c:\program files\Free Power Word to Pdf Converter
2009-08-31 13:54 . 2009-04-13 16:34 -------- d-----w- c:\program files\Free PDF to Word Doc Converter
2009-08-31 13:41 . 2008-06-02 12:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-31 13:39 . 2006-08-25 09:21 -------- d-----w- c:\program files\Sony Ericsson
2009-08-31 13:39 . 2006-08-25 09:21 -------- d-----w- c:\program files\Common Files\Teleca Shared
2009-08-31 13:37 . 2008-11-05 19:11 -------- d-----w- c:\program files\Text to Speech Maker
2009-08-31 13:23 . 2009-06-30 11:44 -------- d-----w- c:\program files\MumboJumbo
2009-08-31 13:23 . 2009-02-24 13:08 -------- d-----w- c:\program files\Wanadoo Edition
2009-08-31 13:13 . 2009-08-03 15:13 -------- d-----w- c:\program files\Actual Drawing
2009-08-31 13:13 . 2009-05-06 16:55 -------- d-----w- c:\program files\Acoustica Mixcraft
2009-08-22 18:03 . 2007-05-07 10:42 -------- d-----w- c:\program files\Rockstar Games
2009-08-13 13:33 . 2006-09-09 18:51 -------- d-----w- c:\program files\Java
2009-08-09 11:54 . 2006-09-09 18:52 -------- d-----w- c:\program files\Google
2009-08-08 09:53 . 2009-08-08 09:51 -------- d-----w- c:\program files\Canon
2009-08-08 09:50 . 2009-08-08 09:50 -------- d-----w- c:\program files\Common Files\Canon
2009-08-05 09:01 . 2004-08-18 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-01 16:38 . 2008-08-02 17:50 -------- d-----w- c:\program files\Windows Desktop Search
2009-08-01 15:00 . 2009-07-30 11:56 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-28 17:50 . 2009-07-28 17:50 -------- d-----w- c:\program files\PetrLite
2009-07-28 15:36 . 2009-07-28 15:36 -------- d-----w- c:\program files\CCleaner
2009-07-28 15:30 . 2009-07-28 15:30 118842 ------r- c:\windows\bwUnin-6.3.2.116-7681197L.exe
2009-07-28 15:25 . 2009-07-28 15:16 -------- d-----w- c:\program files\RegCleaner
2009-07-28 13:59 . 2009-07-28 13:58 -------- d-----w- c:\program files\Smarty Uninstaller Pro
2009-07-28 13:57 . 2009-07-28 13:57 -------- d-----w- c:\program files\VS Revo Group
2009-07-27 15:10 . 2006-07-05 17:26 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-25 03:23 . 2009-08-04 11:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:04 . 2004-08-18 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-18 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:59 . 2004-08-18 12:00 915456 ------w- c:\windows\system32\wininet.dll
2004-08-23 21:38 . 2004-08-23 21:38 3371 ----a-w- c:\program files\!!!readme.txt
2004-08-23 19:08 . 2004-08-23 19:08 83968 -c--a-w- c:\program files\NB_NB_2_12_37.xls
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
--- c:\documents and settings\Marek\USERDATA.DAT ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 12
Created time: 2009-09-18 17:23
Modified time: 2009-09-18 17:23
MD5: EC2D55B17F9393FD22C2D812C7A64CF8
SHA1: 25EF6234207358BB87E080718CFE8BC5F8681F12
---- Directory of c:\program files\Warp ----
2007-03-11 18:15 . 2007-03-11 18:15 843776 ----a-w- c:\program files\Warp\Warp.exe
2005-11-09 10:36 . 2005-11-09 10:36 9511 ----a-w- c:\program files\Warp\dubya.jpg
2005-11-09 10:36 . 2005-11-09 10:36 1712128 ----a-w- c:\program files\Warp\GdiPlus.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"Google Update"="c:\documents and settings\Marek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2009-06-20 133104]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2008-12-04 182936]
"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2008-12-04 957024]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PnkBstrB"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\Electronic Arts\\Need For Speed III\\nfs3.exe"=
"c:\\Program Files\\Sierra\\SWAT 4\\Content\\System\\Swat4.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Illusion Softworks\\Hidden & Dangerous 2\\hd2.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Sierra\\CoolPool\\coolpool.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Codemasters\\Worms 4 Totalni narez\\Worms 4 Mayhem.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\keyclone\\keyclone.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enGB-Win-Update-downloader.exe"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Marek\\Local Settings\\Data aplikací\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"11001:TCP"= 11001:TCP:H&D2 port 11001
"11001:UDP"= 11001:UDP:H&D2 port 11001
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"12001:UDP"= 12001:UDP:SMART WebServer Handshake Multicast Port
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [19.9.2009 20:02 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [19.9.2009 20:02 79872]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [21.9.2009 17:15 64160]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\F-Secure\HIPS\drivers\fshs.sys [19.9.2009 20:01 67808]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3.7.2009 16:49 1028432]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [19.9.2009 20:01 99960]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure\ORSP Client\fsorsp.exe [19.9.2009 20:01 55904]
S2 gupdate1ca18e6298cdd6;Google Update Service (gupdate1ca18e6298cdd6);c:\program files\Google\Update\GoogleUpdate.exe [9.8.2009 13:39 133104]
S3 axskbus;axskbus;c:\windows\system32\DRIVERS\axskbus.sys --> c:\windows\system32\DRIVERS\axskbus.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [20.2.2008 20:49 13352]
S3 M1000Srv;M5603C USB2.0 Camera Driver;c:\windows\system32\Drivers\M1000KNT.sys --> c:\windows\system32\Drivers\M1000KNT.sys [?]
S4 BackWeb Plug-in - 7681197;F-Secure Automatic Update;c:\progra~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE --> c:\progra~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [?]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [19.9.2009 20:01 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [19.9.2009 20:01 25184]
S4 SMART Web Server;SMART Web Server;c:\program files\SMART Technologies Inc\SMART Board Software\WebServer.exe [19.4.2007 7:42 759312]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Obsah adresáře 'Naplánované úlohy'
2009-09-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 15:14]
2009-06-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 11:42]
2009-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-09 11:38]
2009-09-25 c:\windows\Tasks\User_Feed_Synchronization-{CB8F93AA-F0A1-41BE-9268-229B640A54CD}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
2009-09-25 c:\windows\Tasks\User_Feed_Synchronization-{D8C6849B-BD9A-4B92-970F-E7635BC45510}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
LSP: c:\program files\F-Secure\FSPS\program\FSLSP.DLL
FF - ProfilePath - c:\documents and settings\Marek\Data aplikací\Mozilla\Firefox\Profiles\j2ggv3xx.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-CToolbar_UNINSTALL - c:\progra~1\Crawler\Toolbar\CToolbar.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-25 19:39
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1409082233-220523388-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:df,62,2c,55,b4,92,8c,81,8f,81,d7,2e,f6,2f,99,2a,af,76,f8,bb,39,8e,53,
3b,98,84,f3,a1,74,26,e8,39,f4,22,d8,75,d3,12,9d,76,c2,c3,f8,38,95,43,4a,2c,\
"??"=hex:a9,1b,d4,2d,84,8a,c8,cc,72,9b,3f,aa,56,b9,ca,9f
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'lsass.exe'(840)
c:\program files\F-Secure\FSPS\program\FSLSP.DLL
.
Celkový čas: 2009-09-25 19:42
ComboFix-quarantined-files.txt 2009-09-25 17:41
ComboFix2.txt 2009-09-25 16:43
Před spuštěním: Volných bajtů: 135 070 240 768
Po spuštění: Volných bajtů: 135 015 960 576
389 --- E O F --- 2009-09-10 19:27
AMD Athlon II X4 640 3.00Ghz Ram 4 GB, Win 7 64 bit, Grafika ATI Radeon HD 4600 series 1GB, HDD 600GB
Iphone 3g 16gb černý