Spravila som vsetko. Akurát ten posledný súbor na otestovanie mi to nenašlo v počítači (h:\windows\pchealth\helpctr\Config\Cache\Professional_32_1029.dat) takže ten nie je otestovaný.
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/04/03 11:43
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Hidden/Locked Files
-------------------
Path: H:\RootRepeal
Status: Visible to the Windows API, but not on disk.
Path: H:\WINDOWS\Prefetch\ROOTREPEAL.EXE-146CC66B.pf
Status: Visible to the Windows API, but not on disk.
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix 10-04-01.02 - dena . 04. 2010 12:08:15.4.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.2047.1690 [GMT 2:00]
Running from: h:\documents and settings\dena\Plocha\ComboFix.exe
Command switches used :: h:\documents and settings\dena\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100402-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((( Files Created from 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))))
.
2010-04-03 09:40 . 2010-04-03 09:40 -------- d-----w- H:\RootRepeal
2010-04-03 00:38 . 2010-04-03 00:38 -------- d-----w- h:\program files\Common Files\Java
2010-04-03 00:17 . 2010-04-03 00:17 -------- d-----w- h:\program files\Club Control
2010-04-02 18:23 . 2010-03-29 22:46 38224 ----a-w- h:\windows\system32\drivers\mbamswissarmy.sys
2010-04-02 18:23 . 2010-04-02 18:24 -------- d-----w- h:\program files\Malwarebytes' Anti-Malware
2010-04-02 18:23 . 2010-03-29 22:45 20824 ----a-w- h:\windows\system32\drivers\mbam.sys
2010-04-02 18:12 . 2010-04-02 18:12 -------- d-----w- h:\program files\Trend Micro
2010-04-02 16:57 . 2008-04-13 22:10 34688 -c--a-w- h:\windows\system32\dllcache\lbrtfdc.sys
2010-04-02 16:57 . 2008-04-13 22:10 34688 ----a-w- h:\windows\system32\drivers\lbrtfdc.sys
2010-04-02 16:56 . 2008-04-13 22:11 8576 -c--a-w- h:\windows\system32\dllcache\i2omgmt.sys
2010-04-02 16:56 . 2008-04-13 22:11 8576 ----a-w- h:\windows\system32\drivers\i2omgmt.sys
2010-04-02 16:56 . 2008-04-13 22:11 8192 -c--a-w- h:\windows\system32\dllcache\changer.sys
2010-04-02 16:56 . 2008-04-13 22:11 8192 ----a-w- h:\windows\system32\drivers\changer.sys
2010-03-31 20:39 . 2010-03-31 20:39 -------- d-----w- h:\program files\Codemasters
2010-03-27 20:58 . 2010-03-29 17:17 -------- d-----w- h:\program files\Games
2010-03-21 09:54 . 2010-03-21 09:54 -------- d-----w- h:\program files\Common Files\Program4Pc
2010-03-19 17:41 . 2010-03-20 23:26 2560 ----a-w- h:\windows\_MSRSTRT.EXE
2010-03-19 17:31 . 2008-04-26 15:14 42672 ------w- h:\windows\system32\wbsys.dll
2010-03-19 16:45 . 2010-03-19 16:45 -------- d-----w- h:\program files\Common Files\Stardock
2010-03-19 09:25 . 2010-03-19 09:25 -------- d-----w- h:\program files\Microsoft Silverlight
2010-03-18 14:56 . 2010-03-18 14:56 -------- d-----w- h:\program files\NVIDIA Corporation
2010-03-08 16:16 . 2010-03-31 11:32 -------- d-----w- h:\windows\ie8updates
2010-03-08 16:15 . 2010-02-12 10:03 293376 ------w- h:\windows\system32\browserchoice.exe
2010-03-08 16:12 . 2010-02-25 06:18 594432 -c----w- h:\windows\system32\dllcache\msfeeds.dll
2010-03-08 16:12 . 2010-02-25 06:18 1985536 -c----w- h:\windows\system32\dllcache\iertutil.dll
2010-03-08 16:12 . 2010-02-25 06:18 247808 -c----w- h:\windows\system32\dllcache\ieproxy.dll
2010-03-08 16:12 . 2010-02-25 06:18 12800 -c----w- h:\windows\system32\dllcache\xpshims.dll
2010-03-08 16:12 . 2010-02-25 06:18 55296 -c----w- h:\windows\system32\dllcache\msfeedsbs.dll
2010-03-08 16:12 . 2010-02-25 09:48 11070976 -c----w- h:\windows\system32\dllcache\ieframe.dll
2010-03-08 16:09 . 2010-03-08 16:09 -------- d-sh--w- h:\documents and settings\dena\IECompatCache
2010-03-08 16:09 . 2010-03-08 16:09 -------- d-sh--w- h:\documents and settings\dena\PrivacIE
2010-03-08 16:04 . 2010-03-08 16:04 -------- d-sh--w- h:\documents and settings\dena\IETldCache
2010-03-08 15:57 . 2010-03-08 15:58 -------- dc-h--w- h:\windows\ie8
2010-03-08 15:57 . 2010-03-08 15:58 -------- d-----w- h:\windows\system32\sk-SK
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-03 09:48 . 2010-01-15 17:35 3334156 ----a-w- h:\windows\Internet Logs\tvDebug.Zip
2010-04-03 00:37 . 2008-12-25 17:55 -------- d-----w- h:\program files\Java
2010-04-03 00:18 . 2008-12-12 16:41 6272 ----a-w- h:\windows\system32\drivers\splitter.sys
2010-04-03 00:17 . 2008-12-12 16:41 4992 ----a-w- h:\windows\system32\drivers\mspqm.sys
2010-04-03 00:17 . 2001-08-17 21:52 18688 ----a-w- h:\windows\system32\drivers\cdaudio.sys
2010-04-02 17:49 . 2010-04-02 17:50 3125248 ----a-w- h:\windows\Internet Logs\xDB15.tmp
2010-03-31 20:45 . 2008-12-28 18:03 108144 -c--a-w- h:\windows\system32\CmdLineExt.dll
2010-03-28 10:54 . 2001-10-25 14:00 439798 ----a-w- h:\windows\system32\perfh005.dat
2010-03-28 10:54 . 2001-10-25 14:00 82014 ----a-w- h:\windows\system32\perfc005.dat
2010-03-23 14:47 . 2010-03-24 14:18 8704 ----a-w- h:\windows\Internet Logs\xDB14.tmp
2010-03-22 22:02 . 2010-03-23 14:47 139776 ----a-w- h:\windows\Internet Logs\xDB13.tmp
2010-03-20 10:20 . 2010-03-20 20:21 8704 ----a-w- h:\windows\Internet Logs\xDB12.tmp
2010-03-20 10:16 . 2010-03-20 10:20 304640 ----a-w- h:\windows\Internet Logs\xDB11.tmp
2010-03-12 11:02 . 2010-03-13 12:26 8704 ----a-w- h:\windows\Internet Logs\xDB10.tmp
2010-03-12 09:04 . 2010-03-12 11:02 106496 ----a-w- h:\windows\Internet Logs\xDBF.tmp
2010-03-09 02:28 . 2008-12-25 17:55 411368 ----a-w- h:\windows\system32\deploytk.dll
2010-03-08 16:22 . 2010-03-08 16:23 3063296 ----a-w- h:\windows\Internet Logs\xDBE.tmp
2010-03-08 16:22 . 2010-03-08 16:23 172544 ----a-w- h:\windows\Internet Logs\xDBD.tmp
2010-03-01 15:25 . 2010-03-02 14:17 8704 ----a-w- h:\windows\Internet Logs\xDBC.tmp
2010-02-28 22:09 . 2010-03-01 15:25 491008 ----a-w- h:\windows\Internet Logs\xDBB.tmp
2010-02-25 06:18 . 2008-04-14 06:52 916480 ------w- h:\windows\system32\wininet.dll
2010-02-14 00:49 . 2010-02-14 08:57 3038720 ----a-w- h:\windows\Internet Logs\xDBA.tmp
2010-02-12 21:26 . 2008-12-12 16:39 -------- d--h--w- h:\program files\InstallShield Installation Information
2010-02-12 14:20 . 2010-02-13 10:05 8704 ----a-w- h:\windows\Internet Logs\xDB9.tmp
2010-02-11 21:04 . 2010-02-12 14:20 234496 ----a-w- h:\windows\Internet Logs\xDB8.tmp
2010-01-30 08:52 . 2010-01-31 08:45 8704 ----a-w- h:\windows\Internet Logs\xDB7.tmp
2010-01-29 20:18 . 2010-01-30 08:52 95232 ----a-w- h:\windows\Internet Logs\xDB6.tmp
2010-01-23 10:54 . 2010-01-24 10:21 8704 ----a-w- h:\windows\Internet Logs\xDB5.tmp
2010-01-23 10:52 . 2010-01-23 10:54 204800 ----a-w- h:\windows\Internet Logs\xDB3.tmp
2010-01-23 10:25 . 2008-12-25 14:18 721904 ----a-w- h:\windows\system32\drivers\sptd.sys
2010-01-18 15:56 . 2010-01-18 15:57 120320 ----a-w- h:\windows\Internet Logs\xDB2.tmp
2010-01-15 17:35 . 2010-01-16 10:10 8704 ----a-w- h:\windows\Internet Logs\xDB4.tmp
2010-01-15 17:33 . 2010-01-15 17:35 48640 ----a-w- h:\windows\Internet Logs\xDB1.tmp
2010-01-15 16:15 . 2010-01-15 16:15 56 ---ha-w- h:\windows\system32\ezsidmv.dat
2010-01-11 21:17 . 2010-01-11 21:17 278120 ----a-w- h:\windows\system32\nvmccs.dll
2010-01-11 21:17 . 2010-01-11 21:17 154216 ----a-w- h:\windows\system32\nvsvc32.exe
2010-01-11 21:17 . 2010-01-11 21:17 145000 ----a-w- h:\windows\system32\nvcolor.exe
2010-01-11 21:17 . 2010-01-11 21:17 13666408 ----a-w- h:\windows\system32\nvcpl.dll
2010-01-11 21:17 . 2010-01-11 21:17 110696 ----a-w- h:\windows\system32\nvmctray.dll
2010-01-11 21:17 . 2010-01-11 21:17 81920 ----a-w- h:\windows\system32\nvwddi.dll
2010-01-04 14:09 . 2008-04-14 06:51 17408 ----a-w- h:\windows\system32\alrsvc.dll
2010-01-04 14:08 . 2008-12-12 10:17 6656 ----a-w- h:\windows\system32\wuauserv.dll
.
------- Sigcheck -------
[-] 2008-05-11 . E3B22F050F840306FD522227F68046C5 . 1571840 . . [5.1.2600.5512] . . h:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-04-02_23.11.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-04-02 23:11 . 2010-04-02 23:11 16384 h:\windows\Temp\Perflib_Perfdata_7e8.dat
+ 2010-04-03 10:14 . 2010-04-03 10:14 16384 h:\windows\Temp\Perflib_Perfdata_7e8.dat
+ 2010-04-03 10:13 . 2010-04-03 10:13 16384 h:\windows\Temp\Perflib_Perfdata_20c.dat
+ 2001-08-17 21:52 . 2010-04-03 00:17 18688 h:\windows\system32\dllcache\cdaudio.sys
- 2001-08-17 21:52 . 2001-08-17 19:52 18688 h:\windows\system32\dllcache\cdaudio.sys
- 2009-07-12 11:07 . 2010-02-24 16:44 87716 h:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
+ 2009-07-12 11:07 . 2010-04-03 00:36 87716 h:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
- 2008-12-12 16:41 . 2008-04-13 23:15 6272 h:\windows\system32\dllcache\splitter.sys
+ 2008-12-12 16:41 . 2010-04-03 00:18 6272 h:\windows\system32\dllcache\splitter.sys
+ 2008-12-12 16:41 . 2010-04-03 00:17 4992 h:\windows\system32\dllcache\mspqm.sys
- 2008-12-12 16:41 . 2008-04-13 23:09 4992 h:\windows\system32\dllcache\mspqm.sys
+ 2010-04-03 00:37 . 2010-03-09 02:28 153376 h:\windows\system32\javaws.exe
+ 2010-04-03 00:37 . 2010-03-09 02:28 145184 h:\windows\system32\javaw.exe
- 2009-11-04 15:19 . 2009-10-11 03:17 145184 h:\windows\system32\javaw.exe
+ 2010-04-03 00:37 . 2010-03-09 02:28 145184 h:\windows\system32\java.exe
- 2009-11-04 15:19 . 2009-10-11 03:17 145184 h:\windows\system32\java.exe
+ 2010-04-03 00:38 . 2010-04-03 00:38 180224 h:\windows\Installer\457d9b.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"="h:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE" [2009-09-12 26624]
"AlcoholAutomount"="h:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="h:\program files\XpertVision\TBPanel.exe" [2008-01-29 2157064]
"avast!"="h:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"iTunesHelper"="h:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"ZoneAlarm Client"="h:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-11-22 1037192]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 16844800]
"NvMediaCenter"="h:\windows\system32\NvMcTray.dll" [2010-01-11 110696]
"NvCplDaemon"="h:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"SunJavaUpdateSched"="h:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
h:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia FastStart]
2009-02-26 16:04 2376992 ----a-w- h:\program files\Nokia\Nokia Music\NokiaMusic.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaOviSuite2]
2009-10-27 14:10 401728 ----a-w- h:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"h:\\Program Files\\Vuze\\Azureus.exe"=
"h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"h:\\Program Files\\iTunes\\iTunes.exe"=
"h:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"h:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"h:\\WINDOWS\\system32\\sessmgr.exe"=
"h:\\Program Files\\ICQ6.5\\ICQ.exe"=
"h:\\Program Files\\Messenger\\msmsgs.exe"=
R0 sptd;sptd;h:\windows\system32\drivers\sptd.sys [25. 12. 2008 16:18 721904]
R1 aswSP;avast! Self Protection;h:\windows\system32\drivers\aswSP.sys [26. 12. 2008 23:09 114768]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;h:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [27. 10. 2008 18:03 759072]
R2 aswFsBlk;aswFsBlk;h:\windows\system32\drivers\aswFsBlk.sys [26. 12. 2008 23:09 20560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-01-27 h:\windows\Tasks\AppleSoftwareUpdate.job
- h:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.sk/uDefault_Search_URL =
hxxp://www.Google.comuSearchAssistant =
hxxp://www.Google.com/uCustomizeSearch =
hxxp://www.Google.com/IE: E&xportovať do programu Microsoft Excel - h:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - h:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - h:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - h:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - h:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - h:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
FF - ProfilePath - h:\documents and settings\dena\Data aplikací\Mozilla\Firefox\Profiles\m607gfzq.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.sk/FF - plugin: h:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - h:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
h:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
h:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
h:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
h:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
h:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
h:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
h:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
h:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
h:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
h:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
h:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-03 12:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spae.sys >>UNKNOWN [0x8A684938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf763bf28
\Driver\ACPI -> ACPI.sys @ 0xf7495cb8
\Driver\atapi -> atapi.sys @ 0xf7978b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
user & kernel MBR OK
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3880)
h:\documents and settings\All Users\Data aplikací\LangSoft\TrnOEH.dll
h:\windows\system32\webcheck.dll
h:\windows\system32\WPDShServiceObj.dll
h:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
h:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
h:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_slk.nlr
h:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
h:\windows\system32\PortableDeviceTypes.dll
h:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
h:\windows\system32\nvsvc32.exe
h:\program files\Alwil Software\Avast4\aswUpdSv.exe
h:\program files\Alwil Software\Avast4\ashServ.exe
h:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
h:\program files\Bonjour\mDNSResponder.exe
h:\program files\Java\jre6\bin\jqs.exe
h:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
h:\program files\Alwil Software\Avast4\ashMaiSv.exe
h:\program files\Alwil Software\Avast4\ashWebSv.exe
h:\windows\RTHDCPL.EXE
h:\windows\system32\RUNDLL32.EXE
h:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-03 12:17:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-03 10:17
ComboFix2.txt 2010-04-02 23:17
Pre-Run: Volných bajtů: 70 848 294 912
Post-Run: Volných bajtů: 70 797 131 776
- - End Of File - - A89E1D123202B0480AC885DFD9DC993C
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.virustotal.com/cs/analisis/b ... 1270290242http://www.virustotal.com/cs/analisis/5 ... 1270290640http://www.virustotal.com/cs/analisis/3 ... 1270290948http://www.virustotal.com/cs/analisis/1 ... 1270291035