ComboFix 11-10-21.06 - pc 23.10.2011 14:00:01.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1019 [GMT 2:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\pc\Plocha\CFScript.txt
AV: AVG Anti-Virus 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Vytvořen nový Bod Obnovení
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
FILE ::
"c:\windows\Tasks\ASC4_PerformanceMonitor.job"
"c:\windows\Tasks\RegCure.job"
"c:\windows\Tasks\SmartDefrag_Startup.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ESET
c:\program files\ESET\ESET Smart Security\Drivers\eamon\eamon.cat
c:\program files\ESET\ESET Smart Security\Drivers\eamon\eamon.inf
c:\program files\ESET\ESET Smart Security\Drivers\eamon\eamon.sys
c:\program files\ESET\ESET Smart Security\Drivers\easdrv\easdrv.cat
c:\program files\ESET\ESET Smart Security\Drivers\easdrv\easdrv.inf
c:\program files\ESET\ESET Smart Security\Drivers\easdrv\easdrv.sys
c:\program files\ESET\ESET Smart Security\Drivers\epfw\epfw.cat
c:\program files\ESET\ESET Smart Security\Drivers\epfw\epfw.inf
c:\program files\ESET\ESET Smart Security\Drivers\epfw\epfw.sys
c:\program files\ESET\ESET Smart Security\Drivers\epfwndis\epfwnd_m.inf
c:\program files\ESET\ESET Smart Security\Drivers\epfwndis\epfwndis.cat
c:\program files\ESET\ESET Smart Security\Drivers\epfwndis\epfwndis.inf
c:\program files\ESET\ESET Smart Security\Drivers\epfwndis\epfwndis.sys
c:\program files\ESET\ESET Smart Security\Drivers\epfwtdi\epfwtdi.cat
c:\program files\ESET\ESET Smart Security\Drivers\epfwtdi\epfwtdi.inf
c:\program files\ESET\ESET Smart Security\Drivers\epfwtdi\epfwtdi.sys
c:\program files\ESET\ESET Smart Security\egui.exe
c:\program files\ESET\ESET Smart Security\eguiAmon.dll
c:\program files\ESET\ESET Smart Security\eguiAmonLang.dll
c:\program files\ESET\ESET Smart Security\eguiEmon.dll
c:\program files\ESET\ESET Smart Security\eguiEmonLang.dll
c:\program files\ESET\ESET Smart Security\eguiEpfw.dll
c:\program files\ESET\ESET Smart Security\eguiEpfwLang.dll
c:\program files\ESET\ESET Smart Security\eguiLang.dll
c:\program files\ESET\ESET Smart Security\eguiMailPlugins.dll
c:\program files\ESET\ESET Smart Security\eguiMailPluginsLang.dll
c:\program files\ESET\ESET Smart Security\eguiProduct.dll
c:\program files\ESET\ESET Smart Security\eguiScan.dll
c:\program files\ESET\ESET Smart Security\eguiScanLang.dll
c:\program files\ESET\ESET Smart Security\eguiSmon.dll
c:\program files\ESET\ESET Smart Security\eguiSmonLang.dll
c:\program files\ESET\ESET Smart Security\eguiUpdate.dll
c:\program files\ESET\ESET Smart Security\eguiUpdateLang.dll
c:\program files\ESET\ESET Smart Security\EHttpSrv.exe
c:\program files\ESET\ESET Smart Security\ekrn.exe
c:\program files\ESET\ESET Smart Security\ekrnAmon.dll
c:\program files\ESET\ESET Smart Security\ekrnEmon.dll
c:\program files\ESET\ESET Smart Security\ekrnEpfw.dll
c:\program files\ESET\ESET Smart Security\ekrnEpfwLang.dll
c:\program files\ESET\ESET Smart Security\ekrnLang.dll
c:\program files\ESET\ESET Smart Security\ekrnMailPlugins.dll
c:\program files\ESET\ESET Smart Security\ekrnMailPluginsLang.dll
c:\program files\ESET\ESET Smart Security\ekrnScan.dll
c:\program files\ESET\ESET Smart Security\ekrnScanLang.dll
c:\program files\ESET\ESET Smart Security\ekrnSmon.dll
c:\program files\ESET\ESET Smart Security\ekrnSmonEngine.dll
c:\program files\ESET\ESET Smart Security\ekrnSmonLang.dll
c:\program files\ESET\ESET Smart Security\ekrnUpdate.dll
c:\program files\ESET\ESET Smart Security\ekrnUpdateLang.dll
c:\program files\ESET\ESET Smart Security\em000_32.dat
c:\program files\ESET\ESET Smart Security\em001_32.dat
c:\program files\ESET\ESET Smart Security\em002_32.dat
c:\program files\ESET\ESET Smart Security\em003_32.dat
c:\program files\ESET\ESET Smart Security\em004_32.dat
c:\program files\ESET\ESET Smart Security\em005_32.dat
c:\program files\ESET\ESET Smart Security\em006_32.dat
c:\program files\ESET\ESET Smart Security\em008_32.dat
c:\program files\ESET\ESET Smart Security\em009_32.dat
c:\program files\ESET\ESET Smart Security\em010_32.dat
c:\program files\ESET\ESET Smart Security\eplgHooks.dll
c:\program files\ESET\ESET Smart Security\eplgOE.dll
c:\program files\ESET\ESET Smart Security\eplgOEEmon.dll
c:\program files\ESET\ESET Smart Security\eplgOELang.dll
c:\program files\ESET\ESET Smart Security\eplgOESmon.dll
c:\program files\ESET\ESET Smart Security\eplgOESmonLang.dll
c:\program files\ESET\ESET Smart Security\eplgOutlook.dll
c:\program files\ESET\ESET Smart Security\eplgOutlookEmon.dll
c:\program files\ESET\ESET Smart Security\eplgOutlookEmonLang.dll
c:\program files\ESET\ESET Smart Security\eplgOutlookLang.dll
c:\program files\ESET\ESET Smart Security\eplgOutlookSmon.dll
c:\program files\ESET\ESET Smart Security\eplgOutlookSmonLang.dll
c:\program files\ESET\ESET Smart Security\eset.chm
c:\program files\ESET\ESET Smart Security\eula.rtf
c:\program files\ESET\ESET Smart Security\http_dll.dll
c:\program files\ESET\ESET Smart Security\mfc80.dll
c:\program files\ESET\ESET Smart Security\mfc80u.dll
c:\program files\ESET\ESET Smart Security\Microsoft.VC80.CRT.manifest
c:\program files\ESET\ESET Smart Security\Microsoft.VC80.MFC.manifest
c:\program files\ESET\ESET Smart Security\Microsoft.VC80.MFCLOC.manifest
c:\program files\ESET\ESET Smart Security\mod_comp.dat
c:\program files\ESET\ESET Smart Security\msvcp80.dll
c:\program files\ESET\ESET Smart Security\msvcr80.dll
c:\program files\ESET\ESET Smart Security\shellExt.dll
c:\program files\ESET\ESET Smart Security\ShellExtLang.dll
c:\program files\ESET\ESET Smart Security\updater.dll
c:\windows\Tasks\ASC4_PerformanceMonitor.job
c:\windows\Tasks\RegCure.job
c:\windows\Tasks\SmartDefrag_Startup.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_EKRN
-------\Legacy_MPKSL0647119B
-------\Legacy_MPKSL1166A770
-------\Legacy_MPKSL2108AD60
-------\Legacy_MPKSL273747BD
-------\Legacy_MPKSL3950AA4D
-------\Legacy_MPKSL4CB2DE00
-------\Legacy_MPKSL5344B840
-------\Legacy_MPKSL6E5F7B94
-------\Legacy_MPKSL7A7B53B0
-------\Legacy_MPKSL7E3AD913
-------\Legacy_MPKSL89A59A73
-------\Legacy_MPKSL98C8A6AA
-------\Legacy_MPKSL99C856EE
-------\Legacy_MPKSL99E206D8
-------\Legacy_MPKSL9C261D15
-------\Legacy_MPKSL9FD907B9
-------\Legacy_MPKSLA17B13C0
-------\Legacy_MPKSLAC9B0BFD
-------\Legacy_MPKSLC403DD9A
-------\Legacy_MPKSLE1F85DEB
-------\Legacy_MPKSLE74EF5E7
-------\Legacy_MPKSLEC4A31B8
-------\Legacy_MPKSLF0FAEC78
-------\Legacy_MPKSLF10710EC
-------\Legacy_MPKSLF54890EE
-------\Legacy_MPKSLFF0F388F
-------\Service_ekrn
-------\Service_MpKsl0647119b
-------\Service_MpKsl1166a770
-------\Service_MpKsl2108ad60
-------\Service_MpKsl273747bd
-------\Service_MpKsl3950aa4d
-------\Service_MpKsl4cb2de00
-------\Service_MpKsl5344b840
-------\Service_MpKsl6e5f7b94
-------\Service_MpKsl7a7b53b0
-------\Service_MpKsl7e3ad913
-------\Service_MpKsl88bde0cd
-------\Service_MpKsl89a59a73
-------\Service_MpKsl98c8a6aa
-------\Service_MpKsl99c856ee
-------\Service_MpKsl99e206d8
-------\Service_MpKsl9c261d15
-------\Service_MpKsl9fd907b9
-------\Service_MpKsla17b13c0
-------\Service_MpKslac9b0bfd
-------\Service_MpKslc403dd9a
-------\Service_MpKsle1f85deb
-------\Service_MpKsle74ef5e7
-------\Service_MpKslec4a31b8
-------\Service_MpKslf0faec78
-------\Service_MpKslf10710ec
-------\Service_MpKslf54890ee
-------\Service_MpKslf873321d
-------\Service_MpKslff0f388f
-------\Service_EhttpSrv
-------\Service_EhttpSrv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-09-23 do 2011-10-23 )))))))))))))))))))))))))))))))
.
.
2011-10-22 12:32 . 2011-10-22 12:32 1409 ----a-w- c:\windows\QTFont.for
2011-10-21 21:05 . 2011-10-21 21:05 -------- d-----w- c:\documents and settings\pc\Local Settings\Data aplikací\Deployment
2011-10-21 15:28 . 2007-03-09 10:25 2321288 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-10-21 15:28 . 2011-10-18 00:28 6668624 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Windows Defender\Definition Updates\{B4126873-000C-4BE4-B169-764ABF60183D}\mpengine.dll
2011-10-17 19:30 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-10-16 12:41 . 2011-10-16 12:41 -------- d-----w- c:\documents and settings\pc\Data aplikací\Malwarebytes
2011-10-16 12:40 . 2011-10-16 12:40 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-10-16 12:40 . 2011-08-31 15:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-16 12:40 . 2011-10-16 12:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-01 13:33 . 2011-10-01 13:38 -------- d-----w- c:\program files\Blitzkrieg Anthology
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-14 19:15 . 2011-05-15 17:04 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-26 09:41 . 2010-03-18 08:09 613376 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2008-04-14 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2008-04-14 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 14:10 . 2008-04-14 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-09-05 13:56 . 2008-04-14 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-14 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:55 . 2008-04-14 12:00 370176 ----a-w- c:\windows\system32\html.iec
2011-08-19 14:33 . 2011-08-24 08:45 25944 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-08-17 13:49 . 2008-04-14 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-12 11:51 . 2009-10-25 08:31 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2011-06-16 04:30 . 2011-03-31 12:55 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-10-16_14.08.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-23 12:06 . 2011-10-23 12:06 16384 c:\windows\temp\Perflib_Perfdata_7ec.dat
+ 2011-01-25 12:12 . 2011-05-24 17:14 222080 c:\windows\system32\MpSigStub.exe
- 2011-01-25 12:12 . 2010-10-19 20:51 222080 c:\windows\system32\MpSigStub.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-05-28 95800]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-12-20 718720]
"NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2009-12-01 401728]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-03 16876032]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
.
c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\
GIGABYTE Gamer HUD Lite.lnk - c:\program files\GIGABYTE\Gamer HUD Lite\HUD.exe [2008-7-15 1952256]
.
c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\
GIGABYTE Gamer HUD Lite.lnk - c:\program files\GIGABYTE\Gamer HUD Lite\HUD.exe [2008-7-15 1952256]
.
c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\
GIGABYTE Gamer HUD Lite.lnk - c:\program files\GIGABYTE\Gamer HUD Lite\HUD.exe [2008-7-15 1952256]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
Philips Device Manager.lnk - c:\program files\Philips\GoGear Mix Device Manager\main.exe [2011-3-6 124816]
.
c:\documents and settings\pc\Nabídka Start\Programy\Po spuštění\
GIGABYTE Gamer HUD Lite.lnk - c:\program files\GIGABYTE\Gamer HUD Lite\HUD.exe [2008-7-15 1952256]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoThemesTab"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SmartDefragBootTime.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\myYearbook Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\myYearbook Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"38111:TCP"= 38111:TCP:cabal
"38125:TCP"= 38125:TCP:cabal1
"6800:UDP"= 6800:UDP:cabal2
"6899:UDP"= 6899:UDP:cabal3
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [22.2.2011 08:13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [16.3.2011 16:03 32592]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [24.8.2011 10:45 14776]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25.10.2009 14:33 691696]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7.1.2011 06:41 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [5.4.2011 00:59 297168]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [9.9.2011 18:41 328536]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18.8.2011 01:33 7390560]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [8.2.2011 05:33 269520]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\Common Files\MAGIX Services\Database\bin\FABS.exe [27.8.2009 18:09 1253376]
R2 UltiDev Cassini Web Server for ASP.NET 2.0;UltiDev Cassini Web Server for ASP.NET 2.0;c:\program files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.exe [8.2.2007 00:06 49152]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [14.4.2011 21:28 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [10.2.2011 07:53 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10.2.2011 07:53 27216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [16.1.2011 23:11 23456]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\Common Files\MAGIX Services\Database\bin\fbserver.exe [7.8.2008 12:10 3276800]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [27.12.2010 23:50 31124344]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [23.1.2010 09:29 136704]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 22:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.4.2008 14:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
S3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [10.12.2009 17:05 16640]
.
--- Ostatní služby/ovladače v paměti ---
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
.
------- Doplňkový sken -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\pc\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\documents and settings\pc\Data aplikací\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Od&oslať do programu OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: Interfaces\{8F7FE813-5F4A-4884-9BAD-DD1B4D363811}: NameServer = 10.0.0.254
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\et9n8qxb.default\
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-10-23 14:07
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1993962763-527237240-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EA754B58-BEA8-1968-1644-A4793E036387}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abmmikmonjfebnfeoolinfjmjghafbofdi"=hex:70,61,67,6d,6e,67,6f,66,6d,69,6e,6f,
65,64,68,67,69,70,69,65,63,70,64,70,65,6c,67,6d,62,70,70,6d,00,00
"mahmhjfnjmncjgamkacgiidafp"=hex:6f,61,6d,63,6e,6f,63,68,63,63,6f,63,67,64,6c,
6e,67,6c,6b,6a,6a,6e,65,66,63,68,63,61,6e,6e,00,6d
.
[HKEY_USERS\S-1-5-21-1993962763-527237240-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:4a,1d,8a,e4,0c,7f,19,fa,c1,48,85,94,ae,04,65,32,0a,82,a7,1e,6f,
49,a2,06,2f,74,a5,6f,c7,72,36,49,52,88,d0,fe,4e,2a,04,c0,80,fa,4f,9c,fa,98,\
"rkeysecu"=hex:f3,f1,c4,56,32,d4,7f,39,8b,09,61,53,42,13,ef,df
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(2936)
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~3\Office14\1029\GrooveIntlResource.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\UPHClean\uphclean.exe
c:\program files\AVG\AVG10\avgnsx.exe
c:\program files\AVG\AVG10\avgemcx.exe
c:\program files\AVG\AVG10\avgrsx.exe
c:\program files\AVG\AVG10\avgchsvx.exe
c:\program files\AVG\AVG10\avgcsrvx.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\program files\Common Files\Nokia\NoA\nokiaaserver.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\progra~1\COMMON~1\Nokia\MPLATF~1\NOKIAM~1.EXE
.
**************************************************************************
.
Celkový čas: 2011-10-23 14:10:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-10-23 12:10
ComboFix2.txt 2011-10-22 13:12
ComboFix3.txt 2011-10-16 14:10
ComboFix4.txt 2010-12-03 15:41
.
Před spuštěním: Volných bajtů: 36 608 270 336
Po spuštění: Volných bajtů: 36 586 848 256
.
- - End Of File - - 786EA80EC9FEF6B79ED368C353BCB8D6