ComboFix 10-03-12.04 - Denisko a Lenka 13.03.2010 11:44:04.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1429 [GMT 1:00]
Spuštěný z: c:\documents and settings\Denisko a Lenka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-13 do 2010-03-13 )))))))))))))))))))))))))))))))
.
2010-03-13 07:58 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-13 07:58 . 2010-03-13 07:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-13 07:58 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-12 13:58 . 2005-11-30 20:20 2314332 ----a-w- c:\windows\system32\Libmmd.dll
2010-03-12 13:58 . 2010-03-12 13:58 -------- d-----w- c:\program files\VDJ5
2010-03-12 12:07 . 2010-03-12 12:07 -------- d-----w- c:\program files\VirtualDJ
2010-03-11 14:14 . 2010-03-11 14:14 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-10 09:38 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-07 08:32 . 2010-03-07 08:32 -------- d-----w- c:\program files\CCleaner
2010-03-07 08:10 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-07 08:10 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-07 08:10 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-07 08:10 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-07 08:10 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-07 08:10 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-07 08:10 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-07 08:10 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-07 08:10 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-07 08:10 . 2010-03-07 08:10 -------- d-----w- c:\program files\Alwil Software
2010-03-07 08:00 . 2010-03-07 08:01 -------- d-----w- c:\program files\COMODO
2010-03-03 18:54 . 2010-03-03 18:54 276648 ----a-w- c:\windows\system32\guard32.dll
2010-03-03 18:54 . 2010-03-03 18:54 86720 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-03-03 18:54 . 2010-03-03 18:54 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-03-03 18:54 . 2010-03-03 18:54 214056 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-03-03 18:54 . 2010-03-03 18:54 15376 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-03-01 13:44 . 2010-03-01 13:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-25 14:53 . 2010-02-25 14:53 -------- d--h--we c:\documents and settings\All Users\AVP9
2010-02-21 08:35 . 2010-02-21 08:35 -------- d-----w- c:\program files\Quicksys
2010-02-18 20:26 . 2009-08-24 20:08 28160 ----a-w- c:\windows\system32\DfSdkBt.exe
2010-02-18 19:25 . 2010-03-08 12:53 -------- d-----w- c:\program files\Graffiti Studio 2.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-13 09:46 . 2009-12-30 18:28 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-03-07 18:43 . 2009-12-30 14:42 -------- d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2010-03-03 09:47 . 2009-12-30 18:20 -------- d-----w- c:\program files\Mozilla Sunbird
2010-03-01 14:08 . 2010-01-26 18:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-27 10:30 . 2010-01-23 07:52 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-26 13:55 . 2009-12-30 14:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-09 20:16 . 2009-12-30 17:43 -------- d-----w- c:\program files\Ashampoo
2010-02-07 20:37 . 2010-02-07 20:37 -------- d-----w- c:\program files\DsNET Corp
2010-01-30 18:06 . 2010-01-30 18:06 -------- d-----w- c:\program files\AGEIA Technologies
2010-01-30 17:31 . 2009-12-30 18:04 -------- d-----w- c:\program files\Google
2010-01-25 20:26 . 2010-01-25 19:57 84993 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-01-24 19:53 . 2010-01-24 19:53 -------- d-----w- c:\program files\Trend Micro
2010-01-20 20:14 . 2010-01-20 20:14 -------- d-----w- c:\program files\IZArc
2010-01-18 14:20 . 2010-01-18 14:20 -------- d-----w- c:\program files\Disney Interactive
2010-01-12 20:14 . 2010-01-12 20:14 -------- d-----w- c:\program files\uTorrent
2010-01-12 16:56 . 2009-12-30 19:26 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-01-12 16:56 . 2010-01-12 16:56 -------- d-----w- c:\program files\VSO
2009-12-31 16:50 . 2004-08-03 21:14 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 12:23 . 2009-12-31 12:23 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-12-30 18:26 . 2009-12-30 18:26 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-30 17:38 . 2009-12-30 17:38 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-12-30 17:34 . 2009-12-30 17:34 0 -c--a-w- c:\windows\nsreg.dat
2009-12-30 17:17 . 2001-10-25 14:00 77872 ----a-w- c:\windows\system32\perfc005.dat
2009-12-30 17:17 . 2001-10-25 14:00 428750 ----a-w- c:\windows\system32\perfh005.dat
2009-12-30 16:24 . 2009-12-30 14:16 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-30 16:24 . 2009-12-30 14:16 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-30 16:22 . 2009-12-30 14:16 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-30 14:13 . 2009-12-30 14:13 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-21 19:08 . 2004-08-17 13:49 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 07:42 . 2009-12-30 14:12 343552 -c--a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-25 6746112]
"nwiz"="nwiz.exe" [2005-05-25 1519616]
"SW20"="c:\windows\system32\sw20.exe" [2005-06-30 200704]
"SW24"="c:\windows\system32\sw24.exe" [2005-07-04 69632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-05-25 86016]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 90112]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2008-03-27 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2008-03-27 16040]
"RTBatteryMeter"="c:\program files\VibrateGameDeviceDriver\RFPIcon.exe" [2003-01-16 49152]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-03-03 1983760]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-03-09 2769336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnamon.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\frun.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnjswx.exe"=
"c:\\pc hry\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\Diagnostics\\LXDNdiag.exe"=
"c:\\pc hry\\EA Sports\\NHL 09\\nhl2009.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnlscn.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7.3.2010 9:10 162640]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [3.3.2010 19:54 214056]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [3.3.2010 19:54 25160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7.3.2010 9:10 19024]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO livePCsupport\CLPSLS.exe [12.2.2010 19:23 148744]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
S2 gupdate1ca897a8e401de4;Služba Google Update (gupdate1ca897a8e401de4);c:\program files\Google\Update\GoogleUpdate.exe [30.12.2009 19:04 133104]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [30.12.2009 15:44 98984]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [18.2.2010 21:26 406016]
S3 DynCal;Dynamic Calibration Service;c:\windows\system32\drivers\DynCal.sys [14.11.2003 3:46 8192]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
Obsah adresáře 'Naplánované úlohy'
2010-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-30 18:04]
2010-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-30 18:04]
.
.
------- Doplňkový sken -------
.
FF - ProfilePath - c:\documents and settings\Denisko a Lenka\Data aplikací\Mozilla\Firefox\Profiles\6cr8svwo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://sk.start3.mozilla.com/firefox?cl ... k:officialFF - prefs.js: keyword.URL -
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory:
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_USERS\S-1-5-21-1644491937-2139871995-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:65,d6,9b,18,58,2c,6e,7a,d5,e4,e5,0d,0a,b4,91,c2,29,56,d0,ca,9b,
f4,b6,4d,27,74,2e,72,f5,0f,0b,6e,83,26,e5,46,89,2d,03,d7,a1,32,00,b1,f2,f8,\
"rkeysecu"=hex:dd,61,6b,fa,f7,f4,4f,b5,d0,8c,63,2a,a0,cd,c6,ca
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(592)
c:\windows\system32\guard32.dll
- - - - - - - > 'lsass.exe'(648)
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(3144)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-03-13 11:48:56
ComboFix-quarantined-files.txt 2010-03-13 10:48
Před spuštěním: Volných bajtů: 25 638 719 488
Po spuštění: Volných bajtů: 25 619 980 288
- - End Of File - - 50DDB915B7AD2B8DF86BA6D33F0DB54A