ComboFix 12-06-08.02 - Bisovi 11.06.2012 8:04.6.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2813.2211 [GMT 2:00]
Spuštěný z: c:\documents and settings\Bisovi\Plocha\ComboFix.exe
Použité ovládací přepínače :: D:\CFScript.txt
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\TDSSKiller_Quarantine
c:\tdsskiller_quarantine\09.06.2012_10.44.58\susp0000\object.ini
c:\tdsskiller_quarantine\09.06.2012_10.44.58\susp0000\svc0000\object.ini
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AppleChargerSrv
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-11 do 2012-06-11 )))))))))))))))))))))))))))))))
.
.
2012-06-09 17:01 . 2012-06-09 17:01 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-06-09 08:21 . 2012-06-09 08:21 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
2012-06-09 08:21 . 2010-03-10 11:28 602912 ----a-w- c:\windows\system32\drivers\RTL8192su.sys
2012-06-09 08:21 . 2012-06-09 08:21 -------- d-----w- c:\windows\system32\RtlGina
2012-06-09 08:21 . 2009-02-05 00:49 451072 ----a-w- c:\windows\system32\ISSRemoveSP.exe
2012-06-06 18:00 . 2012-06-06 17:22 388608 ----a-w- c:\program files\HijackThis.exe
2012-06-06 17:11 . 2012-06-06 17:11 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\602XML
2012-06-06 17:11 . 2012-06-06 17:11 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\602Installer
2012-06-06 17:11 . 2012-06-06 17:18 -------- d-----w- c:\program files\Common Files\soft602
2012-06-06 17:11 . 2012-06-06 17:11 -------- d-----w- c:\program files\Software602
2012-06-05 15:14 . 2012-06-05 15:14 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\AskToolbar
2012-06-04 17:51 . 2012-06-04 17:51 -------- d-----w- c:\documents and settings\All Users\Data aplikací\boost_interprocess
2012-06-04 16:39 . 2010-04-30 13:28 911800 ----a-w- c:\windows\system32\drivers\etc\amtlib.dll
2012-06-04 14:28 . 2012-06-04 15:02 -------- d-----w- c:\program files\YourFileDownloader
2012-06-04 14:28 . 2012-06-04 14:30 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\YourFileDownloader
2012-06-03 09:04 . 2012-06-03 09:04 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\CRE
2012-06-03 09:04 . 2012-06-06 17:20 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\Conduit
2012-06-03 09:04 . 2012-06-03 09:04 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\Temp
2012-06-03 08:49 . 2012-06-03 08:49 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
2012-06-02 06:55 . 2012-06-05 16:10 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\AskToolbar
2012-06-02 06:52 . 2012-06-02 06:52 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\Avira
2012-06-02 06:46 . 2012-06-02 06:47 -------- d-----w- c:\documents and settings\Default User\Local Settings\Data aplikací\AskToolbar
2012-06-02 06:46 . 2012-04-27 08:20 137928 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-06-02 06:46 . 2012-04-24 22:32 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-06-02 06:46 . 2012-04-16 19:18 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-06-02 06:46 . 2012-06-02 06:47 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avira
2012-06-02 06:46 . 2012-06-02 06:46 -------- d-----w- c:\program files\Avira
2012-05-30 17:14 . 2012-05-30 17:14 -------- d-----w- c:\program files\Microsoft Synchronization Services
2012-05-30 17:13 . 2012-05-30 17:13 -------- d-----w- c:\program files\Microsoft.NET
2012-05-30 17:13 . 2012-05-30 17:13 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2012-05-30 17:13 . 2012-05-30 17:13 -------- d-----w- c:\documents and settings\All Users\Microsoft
2012-05-30 17:08 . 2012-05-30 17:08 -------- d-----w- c:\program files\Microsoft Analysis Services
2012-05-30 16:54 . 2008-04-14 06:53 299520 -c----w- c:\windows\system32\dllcache\drmclien.dll
2012-05-30 16:52 . 2008-04-13 22:10 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2012-05-25 17:42 . 2008-04-14 06:51 21504 ----a-w- c:\windows\system32\hidserv.dll
2012-05-25 17:42 . 2008-04-14 05:59 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2012-05-24 17:32 . 2001-08-17 19:47 12928 -c--a-w- c:\windows\system32\dllcache\dot4prt.sys
2012-05-24 17:32 . 2001-08-17 19:47 12928 ----a-w- c:\windows\system32\drivers\Dot4Prt.sys
2012-05-24 17:32 . 2001-10-24 09:43 23808 -c--a-w- c:\windows\system32\dllcache\dot4usb.sys
2012-05-24 17:32 . 2001-10-24 09:43 23808 ----a-w- c:\windows\system32\drivers\Dot4usb.sys
2012-05-24 17:32 . 2008-04-13 22:09 206976 ----a-w- c:\windows\system32\drivers\dot4.sys
2012-05-20 17:47 . 2012-05-20 17:47 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\OpenCandy
2012-05-18 11:25 . 2012-05-18 11:25 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2012-05-18 09:36 . 2012-06-09 17:02 -------- d-----w- c:\windows\system32\NtmsData
2012-05-16 16:26 . 2008-04-13 22:15 20608 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-05-14 16:30 . 2010-01-05 01:31 1714176 ----a-w- c:\windows\system32\drivers\athuw.sys
2012-05-14 16:30 . 2012-05-14 16:30 -------- d-----w- c:\windows\Options
2012-05-14 16:30 . 2010-01-05 01:31 1714176 ----a-w- c:\windows\system32\athuw.sys
2012-05-14 16:29 . 2012-05-14 16:29 -------- d-----w- c:\documents and settings\All Users\Data aplikací\TP-LINK
2012-05-13 09:36 . 2012-05-13 09:36 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\Publish Providers
2012-05-13 09:36 . 2012-05-18 08:46 -------- d---a-w- c:\documents and settings\All Users\Data aplikací\TEMP
2012-05-13 09:36 . 2012-05-13 09:36 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\Sony
2012-05-13 09:36 . 2012-05-13 09:36 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\Sony
2012-05-13 09:31 . 2012-05-13 09:31 -------- d-----w- c:\program files\Vstplugins
2012-05-13 09:31 . 2012-05-13 09:31 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Sony
2012-05-13 09:29 . 2012-05-17 16:35 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\Ahead
2012-05-13 09:14 . 2012-05-13 09:31 -------- d-----w- c:\program files\Sony
2012-05-13 09:11 . 2012-05-13 09:11 -------- d-----w- c:\program files\Sony Setup
2012-05-13 09:07 . 2012-05-13 09:07 -------- d-----w- c:\program files\Terminal Reality
2012-05-13 09:01 . 2012-05-18 11:27 -------- d-----w- c:\documents and settings\Bisovi\Data aplikací\Ahead
2012-05-13 09:00 . 2012-05-13 09:00 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Nero
2012-05-13 09:00 . 2012-05-13 09:01 -------- d-----w- c:\program files\Common Files\Ahead
2012-05-13 09:00 . 2012-05-13 09:00 -------- d-----w- c:\program files\Nero
2012-05-12 17:44 . 2012-05-12 17:44 -------- d-----w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\WMTools Downloaded Files
2012-05-12 17:29 . 2008-04-14 06:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2012-05-12 17:29 . 2008-04-13 22:16 38912 ----a-w- c:\windows\system32\drivers\avc.sys
2012-05-12 17:29 . 2008-04-13 22:16 48128 ----a-w- c:\windows\system32\drivers\61883.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-10 18:11 . 2012-04-02 17:55 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-10 18:11 . 2012-04-02 17:55 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-14 17:26 . 2012-04-02 15:32 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2012-04-14 17:26 . 2012-04-02 16:54 17488 ----a-w- c:\windows\gdrv.sys
2012-04-14 14:59 . 2012-04-02 16:54 17488 ----a-w- c:\windows\etdrv.sys
2012-04-11 15:35 . 2012-04-11 15:35 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2012-04-11 15:35 . 2012-04-10 13:56 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2012-04-11 15:35 . 2012-04-11 15:35 132224 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-04-11 15:35 . 2012-04-10 13:56 368480 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-04-11 13:33 . 2012-04-10 15:39 125472 ----a-w- c:\windows\system32\drivers\vididr.sys
2012-04-11 13:33 . 2012-04-11 13:33 83392 ----a-w- c:\windows\system32\drivers\vsflt53.sys
2012-04-10 16:41 . 2012-04-10 15:39 76768 ----a-w- c:\windows\system32\drivers\fltsrv.sys
2012-04-04 13:56 . 2012-04-03 16:32 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-02 19:20 . 2012-04-02 19:20 65536 ----a-r- c:\documents and settings\Bisovi\Data aplikací\Microsoft\Installer\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
2012-03-22 19:12 . 2012-03-22 19:12 4435968 ----a-w- c:\windows\system32\GPhotos.scr
2012-04-28 09:07 . 2012-04-02 17:01 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\Bisovi\Local Settings\Data aplikací\CRE ----
.
2012-04-17 15:42 . 2012-04-17 15:42 889356 ----a-w- c:\documents and settings\Bisovi\Local Settings\Data aplikací\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-09_06.05.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-06-09 08:21 . 2009-06-24 16:11 65536 c:\windows\system32\RtlGina\RtlGina.dll
- 2001-10-25 12:00 . 2012-06-09 05:46 68156 c:\windows\system32\perfc009.dat
+ 2001-10-25 12:00 . 2012-06-11 06:01 68156 c:\windows\system32\perfc009.dat
- 2001-10-25 12:00 . 2012-06-09 05:46 79062 c:\windows\system32\perfc005.dat
+ 2001-10-25 12:00 . 2012-06-11 06:01 79062 c:\windows\system32\perfc005.dat
- 2001-10-25 12:00 . 2012-06-09 05:46 435260 c:\windows\system32\perfh009.dat
+ 2001-10-25 12:00 . 2012-06-11 06:01 435260 c:\windows\system32\perfh009.dat
- 2001-10-25 12:00 . 2012-06-09 05:46 432004 c:\windows\system32\perfh005.dat
+ 2001-10-25 12:00 . 2012-06-11 06:01 432004 c:\windows\system32\perfh005.dat
+ 2012-06-10 18:11 . 2012-06-10 18:11 686280 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe
+ 2012-06-10 18:11 . 2012-06-10 18:11 465096 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.dll
+ 2012-04-02 17:55 . 2012-06-10 18:11 257224 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-06-09 08:21 . 2010-03-10 11:28 602912 c:\windows\Options\Cabs\rtl8192su.sys
+ 2012-04-02 23:03 . 2012-06-09 20:56 3569376 c:\windows\system32\FNTCACHE.DAT
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-06 102400]
"RTHDCPL"="RTHDCPL.EXE" [2011-08-09 20055144]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2012-03-19 73360]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-05 188416]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-05-01 348624]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2012-03-16 738944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
REALTEK 11n USB Wireless LAN Utility.lnk - c:\program files\Realtek\11n USB Wireless LAN Utility\RtWLan.exe [2012-6-9 937984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-11 20:43 640376 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Acrobat Speed Launcher]
2008-06-12 00:25 37232 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2012-06-07 17:54 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-04-04 13:56 462408 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-26 15:05 15026056 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"AdobeFlashPlayerUpdateSvc"=3 (0x3)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Realtek\\11n USB Wireless LAN Utility\\RtWLan.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1542:TCP"= 1542:TCP:Realtek WPS TCP Prot
"1542:UDP"= 1542:UDP:Realtek WPS UDP Prot
"53:UDP"= 53:UDP:Realtek AP UDP Prot
.
R0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\drivers\fltsrv.sys [10.4.2012 17:39 76768]
R0 vidsflt53;Acronis Disk Storage Filter (53);c:\windows\system32\drivers\vsflt53.sys [11.4.2012 15:33 83392]
R1 AppleCharger;AppleCharger;c:\windows\system32\drivers\AppleCharger.sys [2.4.2012 17:29 18544]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2.6.2012 8:46 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2.6.2012 8:46 86224]
R2 AntiVirWebService;Avira Web Protection;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [2.6.2012 8:46 465360]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [25.4.2012 19:33 24328]
R2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [16.3.2012 18:06 27016]
R2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [16.3.2012 18:07 497280]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3.4.2012 18:32 654408]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3.4.2012 18:32 22344]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [9.6.2012 10:21 602912]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2.4.2012 18:18 30392]
S2 yyivvkmo;Helper Image;c:\windows\system32\svchost.exe -k netsvcs [25.10.2001 14:00 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2.4.2012 18:44 1691480]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\androidusb.sys [11.4.2012 18:23 25728]
S3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [14.5.2012 18:30 1714176]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [10.4.2012 16:04 8704]
S3 etdrv;etdrv;c:\windows\etdrv.sys [2.4.2012 18:54 17488]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [10.4.2012 16:04 3072]
S3 L1c;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2.4.2012 17:39 75504]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [9.6.2012 19:01 40776]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [28.4.2012 11:07 129976]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 21:37 4640000]
S3 zgwhsmdm;ZTE WCDMA Handset USB Modem;c:\windows\system32\drivers\zgwhsmdm.sys [11.4.2012 18:23 106752]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
yyivvkmo
.
.
------- Doplňkový sken -------
.
uStart Page =
hxxp://www.idnes.cz/IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést do Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Připojit cíl vazby k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Připojit k existujícímu PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 109.108.107.106 109.108.109.108
TCP: Interfaces\{D25446CA-C0F1-4978-AAFA-8BE11186FF5B}: NameServer = 89.111.106.2,89.111.107.249
FF - ProfilePath - c:\documents and settings\Bisovi\Data aplikací\Mozilla\Firefox\Profiles\okm78hap.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-06-11 08:11
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(892)
c:\program files\Avira\AntiVir Desktop\avsda.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(1728)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\RTHDCPL.EXE
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2012-06-11 08:13:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-06-11 06:13
ComboFix2.txt 2012-06-10 13:12
ComboFix3.txt 2012-06-09 06:08
.
Před spuštěním: Volných bajtů: 46 527 602 688
Po spuštění: Volných bajtů: 46 453 940 224
.
- - End Of File - - E6E1FEF0B028E2D79B4EB84B14B406FE
SystemLook 30.07.11 by jpshortstuff
Log created at 08:15 on 11/06/2012 by Bisovi
Administrator - Elevation successful
========== filefind ==========
Searching for "yyivvkmo.*"
No files found.
-= EOF =-