doufám, že jsem vše udělal jak bylo napsáno.nedával jsem výběr vše, ale zkopíroval jsem co bylo v okně napsané od killer až po FixCSet:: log po proběhnutí scriptování...
ComboFix 12-02-27.02 - Táta 28.02.2012 14:57:39.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.767.502 [GMT 1:00]
Spuštěný z: c:\documents and settings\Tßta\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Tßta\Plocha\CFScript.txt
AV: Antivirový systém AVG 7.0.289 *Enabled/Outdated* {41564737-3200-1071-989B-0000E87B4FB1}
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-01-28 do 2012-02-28 )))))))))))))))))))))))))))))))
.
.
2012-02-28 12:36 . 2003-04-10 13:46 260096 ----a-w- c:\windows\system32\richtx32.ocx
2012-02-28 12:36 . 2001-11-20 16:09 278528 ----a-w- c:\windows\system32\mejlovani.dll
2012-02-28 12:36 . 1998-06-23 20:00 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX
2012-02-28 12:36 . 1996-06-13 18:24 53760 ----a-w- c:\windows\system32\ZlibTool.ocx
2012-02-28 12:36 . 2012-02-28 12:36 -------- d-----w- c:\program files\2HCS
2012-02-28 07:19 . 2012-02-28 07:19 -------- d-----w- c:\program files\TeamViewer
2012-02-27 09:23 . 2012-02-27 09:23 -------- d-----w- c:\documents and settings\Táta\Data aplikací\Malwarebytes
2012-02-27 09:23 . 2012-02-27 09:23 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2012-02-27 09:23 . 2012-02-27 09:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-27 09:23 . 2011-12-10 14:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-26 22:11 . 2012-02-26 22:11 -------- d-----w- c:\program files\Reference Assemblies
2012-02-26 20:29 . 2012-02-26 20:29 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2012-02-26 18:29 . 2012-02-23 16:11 24408 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-02-26 17:49 . 2001-08-17 21:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys
2012-02-26 17:49 . 2001-08-17 21:00 2944 ----a-w- c:\windows\system32\drivers\msmpu401.sys
2012-02-22 09:23 . 2012-02-22 09:23 -------- d-----w- c:\documents and settings\Táta\Local Settings\Data aplikací\PCHealth
2012-02-22 09:05 . 2012-02-22 09:05 -------- d-----w- c:\windows\system32\XPSViewer
2012-02-22 09:05 . 2012-02-22 09:05 -------- d-----w- c:\program files\MSBuild
2012-02-22 09:04 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2012-02-22 09:03 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2012-02-22 09:03 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2012-02-22 09:03 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2012-02-22 09:03 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2012-02-22 09:03 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2012-02-22 09:03 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2012-02-22 09:03 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2012-02-22 09:03 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2012-02-22 09:03 . 2012-02-22 09:04 -------- d-----w- C:\f50b39369c4fcb2f0514f47cc9f0
2012-02-21 15:02 . 2012-02-21 15:02 -------- d-----w- c:\documents and settings\Default User\Local Settings\Data aplikací\Microsoft Help
2012-02-21 14:28 . 2012-02-21 14:28 -------- d-sh--w- c:\documents and settings\Táta\IECompatCache
2012-02-21 14:23 . 2012-02-21 14:23 -------- d-sh--w- c:\documents and settings\Táta\PrivacIE
2012-02-21 14:20 . 2012-02-21 14:20 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-02-21 14:19 . 2012-02-21 14:19 -------- d-sh--w- c:\documents and settings\Táta\IETldCache
2012-02-21 14:09 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-02-21 14:07 . 2011-12-17 19:42 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-02-21 14:07 . 2011-12-17 19:42 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-02-21 14:07 . 2011-12-17 19:42 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-02-21 14:02 . 2012-02-21 14:07 -------- dc-h--w- c:\windows\ie8
2012-02-21 10:49 . 2012-02-21 10:49 -------- d-----w- c:\documents and settings\Táta\Local Settings\Data aplikací\Microsoft Help
2012-02-21 10:09 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2012-02-21 10:07 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2012-02-21 10:06 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2012-02-21 10:06 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2012-02-21 10:06 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2012-02-21 10:04 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2012-02-21 10:03 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2012-02-21 10:03 . 2012-02-21 10:03 -------- d-----w- c:\program files\HP
2012-02-21 10:00 . 2010-08-27 08:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2012-02-21 10:00 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2012-02-21 09:56 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2012-02-21 09:55 . 2012-02-21 09:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\HP
2012-02-21 09:55 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2012-02-21 09:55 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2012-02-21 09:55 . 2010-06-14 07:43 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2012-02-21 09:55 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2012-02-21 09:54 . 2012-02-21 09:54 -------- d-sh--w- c:\windows\ftpcache
2012-02-21 09:54 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2012-02-21 09:52 . 2012-02-21 09:52 -------- d-----w- c:\program files\Common Files\EPSON
2012-02-21 09:52 . 2007-04-10 11:06 8192 ----a-w- c:\windows\system32\E_DCINST.DLL
2012-02-21 09:52 . 2010-08-10 13:02 81408 ----a-w- c:\windows\system32\E_TD4BHEE.DLL
2012-02-21 09:40 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2012-02-21 09:40 . 2010-07-16 11:58 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2012-02-21 09:40 . 2008-04-21 21:15 216576 ----a-w- c:\program files\Windows NT\Accessories\SET1F3.tmp
2012-02-21 09:32 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2012-02-21 09:31 . 2010-08-16 08:45 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2012-02-20 11:54 . 2009-08-06 18:24 15072 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-02-20 11:26 . 2012-02-20 11:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\regid.1986-12.com.adobe
2012-02-20 11:16 . 2012-02-20 11:16 -------- d-----w- c:\program files\Common Files\Adobe AIR
2012-02-20 09:06 . 2011-03-04 19:44 126448 ------w- c:\windows\system32\pxinsi64.exe
2012-02-20 09:06 . 2011-03-04 19:44 123888 ------w- c:\windows\system32\pxcpyi64.exe
2012-02-20 09:06 . 2011-03-04 19:44 59888 ------w- c:\windows\system32\pxwma.dll
2012-02-20 08:49 . 2012-02-20 08:49 -------- d-----w- C:\output
2012-02-20 08:31 . 2012-02-20 10:00 -------- d-----w- c:\documents and settings\Táta\Data aplikací\PhotoScape
2012-02-20 08:29 . 2012-02-20 08:30 -------- d-----w- c:\program files\PhotoScape
2012-02-20 08:21 . 2012-02-20 08:24 -------- d-----w- c:\documents and settings\Táta\Data aplikací\Filter Forge 3
2012-02-20 07:48 . 2012-02-09 13:13 28992 ----a-w- c:\windows\system32\uxtuneup.dll
2012-02-17 11:00 . 2012-02-17 11:00 -------- d-----w- c:\documents and settings\Táta\Data aplikací\Mikrotik
2012-02-15 12:18 . 2012-02-20 08:17 -------- d-----w- c:\documents and settings\Táta\.gimp-2.6
2012-02-15 11:42 . 2012-02-15 11:42 -------- d-----w- c:\program files\XnView
2012-02-15 10:44 . 2012-02-15 10:44 -------- d-----w- c:\documents and settings\Táta\Data aplikací\inkscape
2012-02-15 10:40 . 2012-02-15 10:43 -------- d-----w- c:\program files\Inkscape
2012-02-09 13:45 . 2012-02-15 12:37 -------- d-----w- c:\documents and settings\Táta\Data aplikací\XnView
2012-02-09 12:26 . 2012-02-09 12:26 -------- d-----w- c:\documents and settings\Táta\Data aplikací\OpenOffice.org
2012-02-09 09:29 . 2008-04-14 07:52 33792 ------w- c:\windows\system32\mmcperf.exe
2012-02-09 09:25 . 2008-04-14 07:52 294912 ------w- c:\program files\Windows Media Player\dlimport.exe
2012-02-09 09:25 . 2008-04-14 07:52 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2012-02-09 09:23 . 2008-04-13 21:06 144384 ------w- c:\windows\system32\drivers\hdaudbus.sys
2012-02-09 09:23 . 2008-04-13 23:10 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2012-02-09 09:21 . 2006-12-28 23:31 19569 ----a-w- c:\windows\003272_.tmp
2012-02-09 08:31 . 2012-02-26 21:11 -------- d-----w- C:\ADDDESIGN
2012-02-08 12:12 . 2012-02-08 12:12 -------- d-----w- C:\SBD files
2012-02-08 12:12 . 2012-02-08 12:12 -------- d-----w- c:\program files\Cutting Technologies
2012-02-08 12:12 . 2012-02-08 12:12 -------- d-----w- C:\Hsprint
2012-02-08 12:05 . 2010-07-12 13:49 52552 ----a-w- c:\windows\system32\ftserui2.dll
2012-02-08 12:05 . 2010-07-12 13:49 67400 ----a-w- c:\windows\system32\ftcserco.dll
2012-02-08 12:05 . 2010-07-12 13:48 73032 ----a-w- c:\windows\system32\drivers\ftser2k.sys
2012-02-08 12:05 . 2010-07-12 13:50 198464 ----a-w- c:\windows\system32\ftd2xx.dll
2012-02-08 12:05 . 2010-07-12 13:50 105288 ----a-w- c:\windows\system32\ftbusui.dll
2012-02-08 12:05 . 2010-07-12 13:49 197952 ----a-w- c:\windows\system32\FTLang.dll
2012-02-08 12:05 . 2010-07-12 13:49 60104 ----a-w- c:\windows\system32\drivers\ftdibus.sys
2012-02-06 14:05 . 2012-02-06 14:05 -------- d-----w- c:\program files\OpenOffice.org 3
2012-02-06 08:56 . 2012-02-06 08:56 -------- d-----w- c:\documents and settings\Táta\Data aplikací\DWGeditor
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-09 13:13 . 2011-11-05 22:22 31552 -c--a-w- c:\windows\system32\TURegOpt.exe
2012-01-12 17:20 . 2004-08-17 13:44 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:42 . 2004-08-17 13:49 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-17 19:42 . 2004-08-17 13:49 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:42 . 2004-08-17 13:49 43520 ------w- c:\windows\system32\licmgr10.dll
2011-12-16 12:23 . 2004-08-17 13:44 385024 ------w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2012-02-27_20.55.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-02-27 20:58 . 2012-02-27 20:58 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\dab766b18e6fe0a8f53a93c56be7b40e\System.Windows.Presentation.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\31b65443e56a470d199f293085576e05\System.Web.DynamicData.Design.ni.dll
+ 2012-02-27 21:04 . 2012-02-27 21:04 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\c2a12bd4056b44f8005a7eb3af161e6a\System.Xml.Linq.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\fc63b434b2f253cd27625487f7b02ac0\System.Web.Routing.ni.dll
+ 2012-02-27 20:57 . 2012-02-27 20:57 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\67877f896b2b0e42286e838fe307f3fd\System.Web.RegularExpressions.ni.dll
+ 2012-02-27 20:57 . 2012-02-27 20:57 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\86650d4fb220f94f25bb5da42a03d454\System.Web.Extensions.Design.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\654465871e547e131668874de7c60b8c\System.Web.Entity.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\f0d6895f6e709d425cb5da6053c603d2\System.Web.Entity.Design.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\3f3b7dc7208e302e39a2dfb5b2cb953b\System.Web.DynamicData.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\e9cddd213343f15d611b14620d649bb0\System.Web.Abstractions.ni.dll
+ 2012-02-27 21:04 . 2012-02-27 21:04 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\c4c671c737b553db8e07664816475333\System.WorkflowServices.ni.dll
+ 2012-02-27 21:04 . 2012-02-27 21:04 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\248ea47105ff4af6ee75e6fdd5b450a1\System.Workflow.Runtime.ni.dll
+ 2012-02-27 21:04 . 2012-02-27 21:04 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\80a288b6611668160334668cc2608e4a\System.Workflow.ComponentModel.ni.dll
+ 2012-02-27 21:04 . 2012-02-27 21:04 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\4c27548df5897320840ee0d65db38742\System.Workflow.Activities.ni.dll
+ 2012-02-27 20:57 . 2012-02-27 20:57 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\e9ba004858dcdb5958d86f26f043f85a\System.Web.Services.ni.dll
+ 2012-02-27 20:57 . 2012-02-27 20:57 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\030cde14924eefebc06c240dbfe093a4\System.Web.Mobile.ni.dll
+ 2012-02-27 20:56 . 2012-02-27 20:56 2405888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\6379c8ca8ae11effb415139990923ff1\System.Web.Extensions.ni.dll
+ 2012-02-27 20:55 . 2012-02-27 20:55 11817472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
hpzsetup.LNK - D:\HPZstub.exe [N/A]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"H/PC Connection Agent"="c:\progra~1\MI3AA1~1\wcescomm.exe"
"LightScribe Control Panel"=c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"MyWebSearch Plugin"=rundll32 c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version7\\TeamViewer_Service.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"2024:TCP"= 2024:TCP:guyohzch
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [14.10.2007 15:05 685816]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [26.2.2012 19:29 24408]
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [23.4.2005 9:21 14912]
R2 TeamViewer7;TeamViewer 7;c:\program files\TeamViewer\Version7\TeamViewer_Service.exe [28.2.2012 8:19 2886528]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [9.2.2012 14:13 1529152]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [13.10.2011 17:33 10064]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [26.2.2012 21:29 136176]
S2 jrjsmvutg;Server Helper;c:\windows\system32\svchost.exe -k netsvcs [17.8.2004 14:49 14336]
S2 tscmgmt;Terminal Server Connection Manager;c:\windows\system32\tscmgmt.exe [17.8.2004 14:49 8192]
S3 abvqjki;abvqjki;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 adsgsq;adsgsq;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 afbdk;afbdk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 afnwhsr;afnwhsr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 bzrzxjbh;bzrzxjbh;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 cbzhyf;cbzhyf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ckacgrmz;ckacgrmz;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 corivuw;corivuw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 cwxhmm;cwxhmm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 cyphqy;cyphqy;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 daxbhk;daxbhk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 dbtxmk;dbtxmk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 dvhzf;dvhzf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 egkusi;egkusi;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 eizcej;eizcej;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 evlwjmsh;evlwjmsh;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 evqzsnunx;evqzsnunx;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 fjlfi;fjlfi;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 fjqefsb;fjqefsb;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gaxxmgbq;gaxxmgbq;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gfpoqbde;gfpoqbde;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gghjl;gghjl;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gipaixwn;gipaixwn;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [26.2.2012 21:29 136176]
S3 hiylzjrij;hiylzjrij;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 hjqbqwcm;hjqbqwcm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 hkzrnouy;hkzrnouy;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 idrmkl;idrmkl;\??\c:\docume~1\KraKen\LOCALS~1\Temp\idrmkl.sys --> c:\docume~1\KraKen\LOCALS~1\Temp\idrmkl.sys [?]
S3 igsiij;igsiij;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ihkad;ihkad;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ijhnsamdx;ijhnsamdx;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ipstvh;ipstvh;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jlqqui;jlqqui;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jpdezojbe;jpdezojbe;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jqcrrfw;jqcrrfw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jscptory;jscptory;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jygrwuyz;jygrwuyz;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 legvkhdh;legvkhdh;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ljepgj;ljepgj;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 lvtcdcz;lvtcdcz;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 lzqhtqb;lzqhtqb;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 mlnbpedm;mlnbpedm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ncnks;ncnks;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ngtdzciy;ngtdzciy;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 nrmxzyvl;nrmxzyvl;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 obmszr;obmszr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ohrjjjs;ohrjjjs;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 okesmnu;okesmnu;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ompsejc;ompsejc;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pepxxn;pepxxn;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pllgjgn;pllgjgn;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pnfxbja;pnfxbja;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ptzls;ptzls;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pvknfa;pvknfa;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pvwbcrisk;pvwbcrisk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pymcfu;pymcfu;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qigwd;qigwd;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qkfidfax;qkfidfax;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qqvapatz;qqvapatz;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qtgmhikf;qtgmhikf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 quivrcl;quivrcl;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 rbownqwm;rbownqwm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 rplwjiamu;rplwjiamu;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 sbusb;Sound Blaster USB Audio Driver;c:\windows\system32\DRIVERS\sbusb.sys --> c:\windows\system32\DRIVERS\sbusb.sys [?]
S3 smmufitk;smmufitk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 sonhzw;sonhzw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 spvmqe;spvmqe;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 sqylkl;sqylkl;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 stomqt;stomqt;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 sucuwcj;sucuwcj;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 suwwbzoeb;suwwbzoeb;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tdoke;tdoke;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tgdfz;tgdfz;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tnbefu;tnbefu;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tuxhrel;tuxhrel;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tvvdndsqg;tvvdndsqg;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tzsduqj;tzsduqj;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 uavdcvo;uavdcvo;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ucuexm;ucuexm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 vtnxuxin;vtnxuxin;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 wegoiriil;wegoiriil;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 wwyflsegb;wwyflsegb;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xgwua;xgwua;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xhsyvhxbw;xhsyvhxbw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xifcqf;xifcqf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xplvdwbsy;xplvdwbsy;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xyfnzrdb;xyfnzrdb;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yabmg;yabmg;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yekth;yekth;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ygbmst;ygbmst;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yogggdcub;yogggdcub;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yulpqlqk;yulpqlqk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yzziw;yzziw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 zjwvgxh;zjwvgxh;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 zrlwa;zrlwa;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
jrjsmvutg
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 11:47 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-02-26 20:29]
.
2012-02-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-02-26 20:29]
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.seznam.cz/uInternet Settings,ProxyServer = 10.0.10.1:3128
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = 10.0.10.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-02-28 15:04
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\abvqjki]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\adsgsq]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\afbdk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\afnwhsr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\bzrzxjbh]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\cbzhyf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ckacgrmz]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\corivuw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\cwxhmm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\cyphqy]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\daxbhk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\dbtxmk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\dvhzf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\egkusi]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\eizcej]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\evlwjmsh]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\evqzsnunx]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\fjlfi]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\fjqefsb]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\gaxxmgbq]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\gfpoqbde]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\gghjl]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\gipaixwn]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\hiylzjrij]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\hjqbqwcm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\hkzrnouy]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\igsiij]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ihkad]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ijhnsamdx]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ipstvh]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\jlqqui]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\jpdezojbe]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\jqcrrfw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\jscptory]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\jygrwuyz]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\legvkhdh]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ljepgj]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\lvtcdcz]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\lzqhtqb]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\mlnbpedm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ncnks]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ngtdzciy]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\nrmxzyvl]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\obmszr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ohrjjjs]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\okesmnu]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ompsejc]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\pepxxn]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\pllgjgn]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\pnfxbja]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ptzls]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\pvknfa]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\pvwbcrisk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\pymcfu]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\qigwd]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\qkfidfax]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\qqvapatz]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\qtgmhikf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\quivrcl]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\rbownqwm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\rplwjiamu]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\smmufitk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\sonhzw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\spvmqe]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\sqylkl]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\stomqt]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\sucuwcj]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\suwwbzoeb]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\tdoke]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\tgdfz]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\tnbefu]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\tuxhrel]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\tvvdndsqg]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\tzsduqj]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\uavdcvo]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ucuexm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\vtnxuxin]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\wegoiriil]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\wwyflsegb]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\xgwua]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\xhsyvhxbw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\xifcqf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\xplvdwbsy]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\xyfnzrdb]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\yabmg]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\yekth]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ygbmst]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\yogggdcub]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\yulpqlqk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\yzziw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\zjwvgxh]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\zrlwa]
"ImagePath"="\??\c:\windows\system32\01.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\jrjsmvutg]
"ServiceDll"="c:\windows\system32\phqreek.dll"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1757981266-1292428093-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{473CC802-2DB2-B9EC-A114-6D587B64B552}*]
"hakldljdbhiffoka"=hex:6a,61,69,6c,65,6d,69,6c,6f,66,62,6d,6c,6f,62,6d,6a,70,
6f,67,00,00
"iaembbacnagcgmlgko"=hex:6a,61,69,6c,65,6d,69,6c,6f,66,62,6d,6c,6f,62,6d,6a,70,
6f,67,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{473CC802-2DB2-B9EC-A114-6D587B64B552}\InProcServer32*]
"jagmmnjpcbhbpkdimncd"=hex:6a,61,69,6c,65,6d,69,6c,6f,66,62,6d,6c,6f,62,6d,6a,
70,6f,67,00,00
"iagmonlbhblleoomno"=hex:6a,61,69,6c,65,6d,69,6c,6f,66,62,6d,6c,6f,62,6d,6a,70,
6f,67,00,00
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3944)
c:\program files\TeamViewer\Version7\tv_w32.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
Celkový čas: 2012-02-28 15:07:01
ComboFix-quarantined-files.txt 2012-02-28 14:06
ComboFix2.txt 2012-02-27 20:58
.
Před spuštěním: Volných bajtů: 20 430 123 008
Po spuštění: Volných bajtů: 20 408 832 000
.
- - End Of File - - E464F98E3A50925A4E24A5C132F24AD9