ComboFix 11-02-17.02 - Alan 18.02.2011 11:23:29.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2559.2052 [GMT 1:00]
Spuštěný z: c:\documents and settings\Alan\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Alan\Plocha\CFScript.txt
AV: ESET Smart Security 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *Enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý
FILE ::
"c:\windows\REGBK00.ZIP"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\logo1_.exe
c:\windows\REGBK00.ZIP
c:\windows\RUNDL132.EXE
c:\windows\rundll16.exe
c:\windows\system32\runouce.exe
c:\windows\VDLL.DLL
----- Souboroví replikátoři -----
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007912.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007913.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007914.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007915.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007916.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007917.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007918.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007919.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007920.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007921.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007922.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007923.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007924.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007925.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007926.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007927.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007928.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007929.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007930.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007931.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007932.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007933.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007934.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007935.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007936.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007937.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007938.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007939.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007940.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007941.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007942.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007943.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007944.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007945.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007946.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007947.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007948.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007949.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007950.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007951.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007952.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007953.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007954.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007955.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007956.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007957.exe
c:\system volume information\_restore{06A78DEF-E6DE-4A8C-8E3F-700478C03766}\RP31\A0007958.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-18 do 2011-02-18 )))))))))))))))))))))))))))))))
.
2011-02-17 22:36 . 2011-02-17 22:36 -------- d-----w- c:\documents and settings\Alan\DoctorWeb
2011-02-17 19:08 . 2011-02-17 19:08 -------- d-----w- c:\windows\Sun
2011-02-17 18:12 . 2011-02-17 18:12 -------- d---a-w- c:\windows\logo_1.exe
2011-02-17 18:07 . 2011-02-17 18:07 632064 ----a-w- c:\windows\system32\msvcr80.dll
2011-02-17 18:07 . 2011-02-17 18:07 554240 ----a-w- c:\windows\system32\msvcp80.dll
2011-02-17 18:07 . 2011-02-17 18:07 34048 ----a-w- c:\windows\system32\eEmpty.exe
2011-02-17 18:07 . 2008-04-14 03:22 137216 ----a-w- c:\windows\system32\T.COM
2011-02-17 18:07 . 2008-04-14 03:22 147968 ----a-w- c:\windows\R.COM
2011-02-17 18:07 . 2011-02-17 18:07 -------- d-----w- c:\program files\Common Files\MicroWorld
2011-02-17 18:07 . 2011-02-17 18:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MicroWorld
2011-02-14 11:36 . 2011-02-14 11:36 -------- d-----w- c:\documents and settings\Alan\dwhelper
2011-02-13 18:11 . 2011-02-13 18:11 -------- d-----w- c:\documents and settings\All Users\Data aplikací\FLEXnet
2011-02-13 17:47 . 2011-02-13 17:47 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2011-02-10 22:07 . 2011-02-15 16:21 -------- d-----w- c:\documents and settings\Alan\Local Settings\Data aplikací\iRinger
2011-02-10 14:19 . 2011-02-10 14:19 -------- d-----w- c:\documents and settings\All Users\Data aplikací\VOWSoft
2011-02-10 12:45 . 2011-02-10 12:47 -------- d-----w- C:\totalcmd
2011-02-10 12:45 . 2011-02-10 12:45 -------- d-----w- c:\documents and settings\Alan\Data aplikací\GHISLER
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\UC.PIF
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\RAR.PIF
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKZIP.PIF
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\PKUNZIP.PIF
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\NOCLOSE.PIF
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\LHA.PIF
2011-02-10 12:45 . 2010-12-17 06:56 545 ----a-w- c:\windows\ARJ.PIF
2011-02-10 10:54 . 2011-02-10 10:54 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-04 15:42 . 2011-02-04 15:42 -------- d-----w- c:\program files\iPod
2011-02-04 14:46 . 2011-02-04 14:46 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Apple
2011-01-31 14:03 . 2002-12-05 13:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2011-01-31 14:03 . 2002-12-02 14:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2011-01-31 14:03 . 2002-12-02 12:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2011-01-31 14:03 . 2002-12-02 12:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2011-01-31 14:03 . 2011-01-31 14:03 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2011-01-31 14:03 . 2011-01-31 14:03 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2011-01-31 14:03 . 2003-02-27 15:12 696320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2011-01-25 00:47 . 2011-01-25 00:47 -------- d-----w- c:\program files\Common Files\NetDragon
2011-01-25 00:47 . 2011-01-25 00:47 -------- d-----w- c:\documents and settings\Alan\Local Settings\Data aplikací\NetDragon
2011-01-24 14:04 . 2011-01-24 14:04 -------- d-----w- c:\documents and settings\LocalService\Data aplikací\Apple Computer
2011-01-24 14:03 . 2011-01-24 21:44 -------- d-----w- c:\documents and settings\Alan\Data aplikací\Apple Computer
2011-01-24 14:03 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2011-01-24 14:03 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2011-01-24 14:02 . 2011-02-04 15:44 -------- d-----w- c:\program files\iTunes
2011-01-24 14:02 . 2011-01-24 14:03 -------- d-----w- c:\documents and settings\All Users\Data aplikací\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-01-24 14:00 . 2011-01-24 14:00 -------- d-----w- c:\documents and settings\Alan\Local Settings\Data aplikací\Apple
2011-01-24 14:00 . 2011-01-24 14:00 -------- d-----w- c:\program files\Apple Software Update
2011-01-24 14:00 . 2010-09-28 14:44 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-01-24 14:00 . 2010-09-28 14:44 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-01-24 13:59 . 2011-01-24 13:59 -------- d-----w- c:\program files\Bonjour
2011-01-24 13:59 . 2011-02-04 15:42 -------- d-----w- c:\program files\Common Files\Apple
2011-01-24 13:59 . 2011-01-24 14:04 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Apple
2011-01-24 13:58 . 2011-02-04 15:30 -------- d-----w- c:\documents and settings\Alan\Local Settings\Data aplikací\Apple Computer
2011-01-24 09:06 . 2011-01-24 09:06 -------- d-----w- c:\documents and settings\Alan\Data aplikací\SafeIT Security
2011-01-24 09:03 . 2011-01-24 09:03 -------- dc-h--w- c:\documents and settings\All Users\Data aplikací\{A59E6D5C-0338-4373-92BF-8C484D4E82A6}
2011-01-24 09:03 . 2011-01-24 09:03 -------- d-----w- c:\program files\SafeIT Security
2011-01-24 09:03 . 2011-01-24 09:03 -------- d-----w- c:\program files\Common Files\SafeIT Security
2011-01-24 09:02 . 2011-01-24 09:02 -------- d-----w- c:\documents and settings\Alan\Local Settings\Data aplikací\PackageAware
2011-01-21 14:44 . 2011-01-21 14:44 440320 -c----w- c:\windows\system32\dllcache\shimgvw.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-13 18:26 . 2008-08-14 06:57 73312 ----a-w- c:\windows\system32\drivers\adfs.sys
2011-01-21 14:44 . 2003-04-16 12:00 440320 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-10 22:13 . 2011-01-10 22:13 348256 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSTAHost\CorelPHOTOPAINT\9.0\1033\ResourceCache.dll
2011-01-10 22:12 . 2011-01-10 22:12 348256 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\VSTAHost\CorelDRAW\9.0\1033\ResourceCache.dll
2011-01-10 22:08 . 2011-01-10 22:08 416 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2011-01-07 14:09 . 2003-04-16 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2011-01-07 14:09 . 2003-04-16 12:00 290048 ----a-w- c:\windows\system32\atmfd(2).dll
2011-01-04 23:59 . 2011-01-05 00:00 73728 ------w- c:\windows\system32\javacpl.cpl
2011-01-04 23:59 . 2011-01-05 00:00 472808 ------w- c:\windows\system32\deployJava1.dll
2011-01-04 22:33 . 2011-01-04 22:33 445016 ------w- c:\windows\system32\wrap_oal.dll
2010-12-31 14:04 . 2003-04-16 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-27 08:00 . 2011-01-09 13:57 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2010-12-22 12:34 . 2003-04-16 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:52 . 2003-04-16 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:52 . 2003-04-16 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:52 . 2003-04-16 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:25 . 2003-04-16 12:00 729088 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2011-01-05 11:40 38224 ------w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2011-01-05 11:40 20952 ------w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2004-08-17 22:44 385024 ------w- c:\windows\system32\html.iec
2010-12-16 22:57 . 2010-12-16 22:57 31088 ----a-w- c:\windows\system32\drivers\ElbyCDIO.sys
2010-12-09 15:15 . 2003-04-16 12:00 713216 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 15:14 . 2002-09-20 17:12 2029056 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-09 15:14 . 2003-04-16 12:00 2150912 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 14:30 . 2003-04-16 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-07 18:40 . 2011-01-09 13:57 183808 ----a-w- c:\windows\system32\xvidvfw.dll
2010-12-07 18:22 . 2011-01-09 13:57 810496 ----a-w- c:\windows\system32\xvidcore.dll
2010-12-01 19:06 . 2010-12-01 19:06 108104 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-26 04:17 . 2004-08-17 22:43 5555712 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-11-26 03:57 . 2009-05-16 02:55 16748544 ------w- c:\windows\system32\atioglxx.dll
2010-11-26 03:23 . 2009-05-16 02:26 471040 ------w- c:\windows\system32\atiok3x2.dll
2010-11-26 03:12 . 2011-01-04 20:23 311296 ------w- c:\windows\system32\atiiiexx.dll
2010-11-26 03:07 . 2009-05-16 01:35 57344 ------w- c:\windows\system32\aticalrt.dll
2010-11-26 03:07 . 2009-05-16 01:34 53248 ------w- c:\windows\system32\aticalcl.dll
2010-11-26 03:06 . 2009-05-16 01:33 4489216 ------w- c:\windows\system32\aticaldd.dll
2010-11-26 02:55 . 2011-01-04 20:23 462848 ------w- c:\windows\system32\ATIDEMGX.dll
2010-11-26 02:54 . 2004-08-17 22:49 302080 ----a-w- c:\windows\system32\ati2dvag.dll
2010-11-26 02:48 . 2004-08-17 22:49 3984864 ----a-w- c:\windows\system32\ati3duag.dll
2010-11-26 02:39 . 2009-05-16 02:30 53248 ------w- c:\windows\system32\drivers\ati2erec.dll
2010-11-26 02:34 . 2009-05-16 03:18 212992 ------w- c:\windows\system32\atipdlxx.dll
2010-11-26 02:34 . 2009-05-16 03:17 155648 ------w- c:\windows\system32\Oemdspif.dll
2010-11-26 02:34 . 2009-05-16 03:17 26112 ------w- c:\windows\system32\Ati2mdxx.exe
2010-11-26 02:34 . 2009-05-16 03:17 43520 ------w- c:\windows\system32\ati2edxx.dll
2010-11-26 02:34 . 2009-05-16 03:17 159744 ------w- c:\windows\system32\ati2evxx.dll
2010-11-26 02:32 . 2009-05-16 03:15 614400 ------w- c:\windows\system32\ati2evxx.exe
2010-11-26 02:32 . 2004-08-17 22:49 2669696 ----a-w- c:\windows\system32\ativvaxx.dll
2010-11-26 02:31 . 2009-05-16 03:14 53248 ------w- c:\windows\system32\ATIDDC.DLL
2010-11-26 02:30 . 2011-01-04 22:06 143360 ------w- c:\windows\system32\atiapfxx.exe
2010-11-26 02:26 . 2009-05-16 02:33 651264 ------w- c:\windows\system32\atikvmag.dll
2010-11-26 02:24 . 2009-05-16 02:31 196608 ------w- c:\windows\system32\atiadlxx.dll
2010-11-26 02:24 . 2009-05-16 02:31 17408 ------w- c:\windows\system32\atitvo32.dll
2010-11-26 02:18 . 2004-08-17 22:49 765952 ----a-w- c:\windows\system32\ati2cqag.dll
2010-11-26 02:16 . 2009-05-16 02:38 64512 ------w- c:\windows\system32\atimpc32.dll
2010-11-26 02:16 . 2009-05-16 02:38 64512 ------w- c:\windows\system32\amdpcom32.dll
2010-11-25 18:29 . 2010-11-25 18:29 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteCenter"="c:\program files\Creative\MediaSource\RemoteControl\RCMan.EXE" [2003-06-12 135168]
"Creative MediaSource Go"="c:\program files\Creative\MediaSource\Go\CTCMSGo.exe" [2003-05-29 131072]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2009-03-25 1840424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 118784]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-11 1468256]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-11-11 1505144]
"CTHelper"="CTHELPER.EXE" [2010-03-18 19456]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 57344]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-11-18 2219184]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"UMonit"="c:\windows\system32\umonit.exe" [2006-07-26 53248]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-12-20 443728]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2009-04-08 570664]
"EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2011-02-13 611712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\ASUS\Bluetooth Software\BTTray.exe [2008-4-14 596584]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-11-8 3986944]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverMax]
2010-11-18 09:44 9221024 ------w- c:\program files\Innovative Solutions\DriverMax\devices.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverMax_RESTART]
2010-11-18 09:44 9221024 ------w- c:\program files\Innovative Solutions\DriverMax\devices.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [29.8.2007 3:04 116264]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [29.7.2010 12:31 115008]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [18.11.2010 14:11 810144]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5.1.2011 12:40 363344]
R2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [8.11.2010 11:40 237568]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [8.11.2010 11:43 1060352]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [8.11.2010 11:43 484352]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [4.1.2011 23:06 101904]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [18.3.2010 20:39 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [18.3.2010 20:39 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [18.3.2010 20:39 566360]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5.1.2011 12:40 20952]
R3 PGR1394b;HS 3d Sensor IEEE 1394 Bus host controllers;c:\windows\system32\drivers\HS3dSensor1394.sys [5.1.2011 12:07 72704]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [5.1.2011 16:07 45736]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [18.3.2010 20:39 99416]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [4.1.2011 23:34 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [18.3.2010 20:39 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [18.3.2010 20:39 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [18.3.2010 20:39 100952]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [18.3.2010 20:39 566360]
S3 fixustor;fixustor;c:\windows\system32\drivers\fixustor.sys [5.1.2011 16:15 6016]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [10.3.2010 8:18 24216]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [10.1.2011 13:15 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [6.1.2011 14:23 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-11-22 13:18 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2011-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ASUS\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Alan\Data aplikací\Mozilla\Firefox\Profiles\jepw67px.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.cz/FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Harley Davidson: {2c088200-b973-11db-8314-0800200c9a66} - %profile%\extensions\{2c088200-b973-11db-8314-0800200c9a66}
FF - Ext: Oskar: {5b175400-2368-11de-8c30-0800200c9a66} - %profile%\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
FF - Ext: Flagfox: {1018e4d6-728f-4b20-ad56-37578a4de76b} - %profile%\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: Aero Fox XL: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
FF - Ext: Black Steel: {e2c58150-9d72-11dd-ad8b-0800200c9a66} - %profile%\extensions\{e2c58150-9d72-11dd-ad8b-0800200c9a66}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-18 11:37
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\umonit.exe?USB\V?J??52e&XJ??\???8???????XJ??8???`J??B\RO????8???????????????????????????h?????6~`J???????????b@?????????????????@$?|?????$?|??7~??@???:~????????????????????@???????????????t??????????????|`$?|?????$?|U$?|??????????????@
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(1004)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(708)
c:\windows\system32\btmmhook.dll
c:\windows\system32\ctagent.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\ASUS\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Photodex\ProShowProducer\ScsiAccess.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\CTHELPER.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Celkový čas: 2011-02-18 11:43:52 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-18 10:43
ComboFix2.txt 2011-02-17 23:36
Před spuštěním: Volných bajtů: 39 024 914 432
Po spuštění: Volných bajtů: 39 011 332 096
- - End Of File - - D0643C7812DD1EC01800D0425605829F