Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Facebook vir 2

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Facebook vir 2

#1 Příspěvek od sengaX »

Dobrý den přeji! Prosím, prosím o pomoc - taky jsem skočila na špek a otevřela mail s přílohou obsahující vir :(
... tady log z RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by senga at 2010-03-19 12:01:58
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 232 GB (76%) free of 305 GB
Total RAM: 1789 MB (53% free)


======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000UA.job
C:\Windows\tasks\Wise Registry Cleaner 4.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-03-13 329312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0}]
FlashGetBHO - C:\Users\senga\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll [2009-08-10 353840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-18 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-08-16 962808]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-11-24 953800]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-04-04 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-20 6265376]
"Skytel"=C:\Windows\Skytel.exe [2008-08-20 1833504]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-07-19 13543968]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-07-19 92704]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2008-11-11 708608]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Ask and Record FLV Service"=C:\Program Files\Ask & Record Toolbar\FLVSrvc.exe [2009-03-10 156672]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-02-15 141608]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-03-13 202256]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-04 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-04-04 125952]
"Google Update"=C:\Users\senga\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 135664]

C:\Users\senga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"$INSTDIR\FlvDetector.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlvDetector.exe:*:Enabled:FGFlvDetector"
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.exe - open - "C:\Users\senga\AppData\Local\ave.exe" /START "%1" %*
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-03-19 12:01:58 ----D---- C:\rsit
2010-03-19 12:01:58 ----D---- C:\Program Files\trend micro
2010-03-17 11:10:02 ----D---- C:\ProgramData\Alwil Software
2010-03-17 10:37:28 ----A---- C:\Windows\system32\jscript.dll
2010-03-16 23:35:14 ----A---- C:\Windows\system32\occache.dll
2010-03-16 23:35:13 ----A---- C:\Windows\system32\msfeeds.dll
2010-03-16 23:35:13 ----A---- C:\Windows\system32\jsproxy.dll
2010-03-16 23:35:13 ----A---- C:\Windows\system32\iepeers.dll
2010-03-16 23:35:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-03-16 23:35:12 ----A---- C:\Windows\system32\ieui.dll
2010-03-16 23:35:11 ----A---- C:\Windows\system32\wininet.dll
2010-03-16 23:35:11 ----A---- C:\Windows\system32\iesetup.dll
2010-03-16 23:35:11 ----A---- C:\Windows\system32\iernonce.dll
2010-03-16 23:35:10 ----A---- C:\Windows\system32\msfeedssync.exe
2010-03-16 23:35:10 ----A---- C:\Windows\system32\iertutil.dll
2010-03-16 23:35:10 ----A---- C:\Windows\system32\ie4uinit.exe
2010-03-16 23:35:09 ----A---- C:\Windows\system32\urlmon.dll
2010-03-16 23:35:09 ----A---- C:\Windows\system32\ieUnatt.exe
2010-03-16 23:35:09 ----A---- C:\Windows\system32\iesysprep.dll
2010-03-16 23:35:09 ----A---- C:\Windows\system32\iedkcs32.dll
2010-03-16 23:35:07 ----A---- C:\Windows\system32\ieframe.dll
2010-03-16 23:35:06 ----A---- C:\Windows\system32\mshtml.dll
2010-03-16 23:34:01 ----A---- C:\Windows\system32\mshtmled.dll
2010-03-16 23:34:01 ----A---- C:\Windows\system32\icardie.dll
2010-03-16 23:34:00 ----A---- C:\Windows\system32\msls31.dll
2010-03-16 23:34:00 ----A---- C:\Windows\system32\mshtmler.dll
2010-03-16 23:34:00 ----A---- C:\Windows\system32\admparse.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\imgutil.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\ieakeng.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\dxtmsft.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\corpol.dll
2010-03-16 23:33:58 ----A---- C:\Windows\system32\licmgr10.dll
2010-03-16 23:33:58 ----A---- C:\Windows\system32\inseng.dll
2010-03-16 23:33:58 ----A---- C:\Windows\system32\dxtrans.dll
2010-03-16 23:33:57 ----A---- C:\Windows\system32\webcheck.dll
2010-03-16 23:33:57 ----A---- C:\Windows\system32\msrating.dll
2010-03-16 23:33:57 ----A---- C:\Windows\system32\ieaksie.dll
2010-03-16 23:33:56 ----A---- C:\Windows\system32\WinFXDocObj.exe
2010-03-16 23:33:56 ----A---- C:\Windows\system32\wextract.exe
2010-03-16 23:33:56 ----A---- C:\Windows\system32\mstime.dll
2010-03-16 23:33:56 ----A---- C:\Windows\system32\ieakui.dll
2010-03-16 23:33:55 ----A---- C:\Windows\system32\pngfilt.dll
2010-03-16 23:33:55 ----A---- C:\Windows\system32\advpack.dll
2010-03-16 23:33:54 ----A---- C:\Windows\system32\vbscript.dll
2010-03-16 23:33:54 ----A---- C:\Windows\system32\ieapfltr.dll
2010-03-16 23:33:53 ----A---- C:\Windows\system32\url.dll
2010-03-16 23:33:52 ----A---- C:\Windows\system32\mshta.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\SetDepNx.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\PDMSetup.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\iexpress.exe
2010-03-13 17:27:22 ----D---- C:\Program Files\Common Files\xing shared
2010-03-12 10:38:10 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-11 20:33:17 ----D---- C:\ProgramData\Sun
2010-03-11 20:33:16 ----D---- C:\Program Files\Common Files\Java
2010-03-11 20:32:47 ----A---- C:\Windows\system32\javaws.exe
2010-03-11 20:32:47 ----A---- C:\Windows\system32\javaw.exe
2010-03-11 20:32:47 ----A---- C:\Windows\system32\java.exe
2010-03-11 09:58:04 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-11 09:58:00 ----A---- C:\Windows\system32\httpapi.dll
2010-03-01 23:13:27 ----D---- C:\Users\senga\AppData\Roaming\Apple Computer
2010-03-01 23:13:11 ----DC---- C:\Windows\system32\DRVSTORE
2010-03-01 23:13:11 ----A---- C:\Windows\system32\GEARAspi.dll
2010-03-01 23:12:33 ----D---- C:\Program Files\iPod
2010-03-01 23:12:29 ----D---- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-01 23:12:29 ----D---- C:\Program Files\iTunes
2010-03-01 23:11:55 ----D---- C:\Program Files\Bonjour
2010-02-24 14:10:20 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 14:07:58 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 14:07:57 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 14:07:56 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 14:07:56 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 14:07:56 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 14:07:55 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 14:07:52 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 14:07:52 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 14:07:52 ----A---- C:\Windows\system32\msdrm.dll
2010-02-21 15:14:34 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-02-21 15:13:26 ----D---- C:\Users\senga\AppData\Roaming\DAEMON Tools Lite
2010-02-21 15:13:22 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of files/folders modified in the last 1 months======

2010-03-19 12:01:59 ----D---- C:\Windows\Prefetch
2010-03-19 12:01:58 ----RD---- C:\Program Files
2010-03-19 12:01:56 ----D---- C:\Windows\Temp
2010-03-19 11:45:20 ----D---- C:\Windows\system32\Tasks
2010-03-19 11:23:12 ----D---- C:\Windows\System32
2010-03-19 11:23:12 ----D---- C:\Windows\inf
2010-03-19 11:23:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-19 07:15:54 ----SHD---- C:\System Volume Information
2010-03-18 12:52:01 ----D---- C:\Users\senga\AppData\Roaming\Skype
2010-03-18 09:28:56 ----D---- C:\Users\senga\AppData\Roaming\skypePM
2010-03-18 08:15:25 ----D---- C:\ProgramData\Real
2010-03-18 07:45:53 ----D---- C:\Windows\winsxs
2010-03-18 07:43:09 ----D---- C:\Windows\system32\catroot2
2010-03-17 11:12:40 ----D---- C:\Program Files\Alwil Software
2010-03-17 11:10:51 ----SHD---- C:\Windows\Installer
2010-03-17 11:10:02 ----HD---- C:\ProgramData
2010-03-17 10:37:14 ----D---- C:\Windows\system32\catroot
2010-03-16 23:55:30 ----D---- C:\Windows\rescache
2010-03-16 23:36:42 ----D---- C:\Windows\system32\migration
2010-03-16 23:36:42 ----D---- C:\Program Files\Internet Explorer
2010-03-16 23:36:41 ----D---- C:\Windows\system32\cs-CZ
2010-03-16 23:36:39 ----D---- C:\Windows\system32\en-US
2010-03-16 23:36:39 ----D---- C:\Windows\PolicyDefinitions
2010-03-16 23:33:23 ----D---- C:\Windows
2010-03-16 23:31:20 ----D---- C:\Windows\Debug
2010-03-16 23:18:13 ----A---- C:\Windows\xUninstall.bat
2010-03-16 23:18:12 ----D---- C:\Windows\JMCR_DIR
2010-03-15 20:58:14 ----D---- C:\Program Files\CCleaner
2010-03-13 17:29:21 ----D---- C:\Users\senga\AppData\Roaming\Real
2010-03-13 17:27:45 ----D---- C:\Program Files\Common Files\Real
2010-03-13 17:27:42 ----A---- C:\Windows\system32\rmoc3260.dll
2010-03-13 17:27:31 ----A---- C:\Windows\system32\pndx5032.dll
2010-03-13 17:27:31 ----A---- C:\Windows\system32\pndx5016.dll
2010-03-13 17:27:27 ----D---- C:\Program Files\Real
2010-03-13 17:27:22 ----D---- C:\Program Files\Common Files
2010-03-13 17:26:49 ----A---- C:\Windows\system32\pncrt.dll
2010-03-13 11:54:42 ----D---- C:\Program Files\Mozilla Firefox
2010-03-11 20:32:32 ----D---- C:\Program Files\Java
2010-03-11 12:40:59 ----D---- C:\Windows\system32\drivers
2010-03-11 12:40:59 ----D---- C:\Program Files\Windows Mail
2010-03-11 12:40:59 ----D---- C:\Program Files\Movie Maker
2010-03-09 12:24:05 ----A---- C:\Windows\system32\aswBoot.exe
2010-03-04 23:26:52 ----D---- C:\Users\senga\AppData\Roaming\BITS
2010-03-04 19:03:19 ----D---- C:\Downloads
2010-03-03 10:56:28 ----D---- C:\Users\senga\AppData\Roaming\ICQ
2010-03-01 23:12:31 ----D---- C:\Program Files\Common Files\Apple
2010-03-01 23:12:29 ----D---- C:\ProgramData\Apple Computer
2010-03-01 21:30:14 ----A---- C:\Windows\system32\mrt.exe
2010-02-26 22:55:37 ----A---- C:\Windows\cdplayer.ini
2010-02-25 08:46:38 ----RSD---- C:\Windows\Fonts
2010-02-24 10:16:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-22 19:46:20 ----D---- C:\Windows\system32\WDI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-03-09 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-04-04 350720]
R2 Aspi32;Aspi32; C:\Windows\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-03-09 51792]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-06-30 917504]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-04-04 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-20 2160792]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-19 7545824]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-04-01 14848]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-08-06 124928]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-04-04 134016]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-04-04 11264]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\Windows\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\Windows\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-04-04 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-04 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-04 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-04 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-04 6016]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-04-04 88576]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-04-04 83328]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-04 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-04 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-04-04 21504]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [2008-11-05 159744]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-19 196608]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-04-04 21504]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-04-04 523776]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-02-15 545576]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-04-04 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-04-04 917504]

-----------------EOF-----------------

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#2 Příspěvek od sengaX »

Omlouvám se, ale budu tu až v devět večer, za moment startuji do práce. :roll:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23301
Registrován: 23 říj 2008 08:02
Bydliště: Haná

Re: Facebook vir 2

#3 Příspěvek od motji »

Hezké odpoledne :)
Až tu budete :)

:arrow: Combofix stahněte takto:
- pravým myšítkem klikněte na odkaz combofixu --uložit jako.. ,a teď ho přejmenujte na Potvora.com a uložte.




:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe

- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#4 Příspěvek od sengaX »

Hezký večer! Provedla jsem a tady je log z Combofixu:

ComboFix 10-03-19.04 - senga 19.03.2010 21:30:53.1.1 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.420.1029.18.1789.1158 [GMT 1:00]
Spuštěný z: c:\users\senga\Desktop\Potvora.com
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
c:\program files\FlashGet Network
c:\program files\FlashGet Network\FlashGet 3\adns.dll
c:\program files\FlashGet Network\FlashGet 3\btcoreu.dll
c:\program files\FlashGet Network\FlashGet 3\BugReport.dll
c:\program files\FlashGet Network\FlashGet 3\BugReport.exe
c:\program files\FlashGet Network\FlashGet 3\cd1.ico
c:\program files\FlashGet Network\FlashGet 3\ckcore.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\14_43260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\28_83260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\atrc.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\Codecs.zip
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\cook.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\ddnt3260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\dnet3260.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\drv1.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\drv2.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\drvc.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\hxltcolor.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\raac.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\ralf.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv10.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv20.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv30.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\rv40.dll
c:\program files\FlashGet Network\FlashGet 3\codec\real\Codecs\sipr.dll
c:\program files\FlashGet Network\FlashGet 3\commonlib.dll
c:\program files\FlashGet Network\FlashGet 3\componentskrnl.dll
c:\program files\FlashGet Network\FlashGet 3\config\clients.met
c:\program files\FlashGet Network\FlashGet 3\config\cryptkey.dat
c:\program files\FlashGet Network\FlashGet 3\config\emfriends.met
c:\program files\FlashGet Network\FlashGet 3\config\known.met
c:\program files\FlashGet Network\FlashGet 3\config\known2_64.met
c:\program files\FlashGet Network\FlashGet 3\config\preferences.ini
c:\program files\FlashGet Network\FlashGet 3\config\server.met
c:\program files\FlashGet Network\FlashGet 3\config\server_met.old
c:\program files\FlashGet Network\FlashGet 3\corestat.dll
c:\program files\FlashGet Network\FlashGet 3\dbghelp.dll
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\css\lightbox.css
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\default.htm
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\banner.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\bullet.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\close.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\closelabel.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\download-icon.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\explorer.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\ftp.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\ftp_1.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\ftp_2.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\ftp_3.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\image.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\image_1.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\image_2.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\image_3.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\introTextBg.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\loading.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\nextlabel.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\prevlabel.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\software.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\software_1.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\software_2.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\software_3.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\vod.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\vod_1.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\vod_2.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\images\vod_3.gif
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\js\builder.js
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\js\effects.js
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\js\lightbox.js
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\js\prototype.js
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\data\js\scriptaculous.js
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\FGResDetector.exe
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\about.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\ftplist_tree_icon.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\option_icon.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\quickop_hide.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\quickop_show.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\statusbar_bk.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\tasktab_close.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_back.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_bk.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_close.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_forward.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\image\toolbar_refresh.png
c:\program files\FlashGet Network\FlashGet 3\FGResDetector_I\lang\l.eng.xml
c:\program files\FlashGet Network\FlashGet 3\Flashget3.exe
c:\program files\FlashGet Network\FlashGet 3\FlashGet3.xpi
c:\program files\FlashGet Network\FlashGet 3\FlashGetBHO3.dll
c:\program files\FlashGet Network\FlashGet 3\fnsArchive.dll
c:\program files\FlashGet Network\FlashGet 3\fnsDirectuix.dll
c:\program files\FlashGet Network\FlashGet 3\fnsLanguage_en.dll
c:\program files\FlashGet Network\FlashGet 3\fnsSecurity.dll
c:\program files\FlashGet Network\FlashGet 3\fnsScheduler.dll
c:\program files\FlashGet Network\FlashGet 3\fnsSkinX.dll
c:\program files\FlashGet Network\FlashGet 3\fnsStatistics.dll
c:\program files\FlashGet Network\FlashGet 3\game.ico
c:\program files\FlashGet Network\FlashGet 3\gdiplus.dll
c:\program files\FlashGet Network\FlashGet 3\GoogleToolbarInstaller_download_signed.exe
c:\program files\FlashGet Network\FlashGet 3\id3lib.dll
c:\program files\FlashGet Network\FlashGet 3\libem.dll
c:\program files\FlashGet Network\FlashGet 3\license.txt
c:\program files\FlashGet Network\FlashGet 3\lst_tz.bin
c:\program files\FlashGet Network\FlashGet 3\P2PCfg.ini
c:\program files\FlashGet Network\FlashGet 3\P2PCore.dll
c:\program files\FlashGet Network\FlashGet 3\P2SCore.dll
c:\program files\FlashGet Network\FlashGet 3\pncrt.dll
c:\program files\FlashGet Network\FlashGet 3\RdOldDb.dll
c:\program files\FlashGet Network\FlashGet 3\RealMediaSplitter.ax
c:\program files\FlashGet Network\FlashGet 3\SamplerCli.dll
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\BarSet.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\btn_check.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\btn_normal.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\btn_radio.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\desktoplink.ico
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\login_line.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\menu_icon.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\option_line.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\option_page_line.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\skin.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\statusbar_ad_bk.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\statusbar_ad_bk_long.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\SuspendLogo.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\SuspendNoLogo.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_backgrand.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_cancle.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_catgroy.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_group.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_new.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_open.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_option.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_pause.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_recly.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbar_start.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbarbutton_left.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbarbutton_middle.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\toolbarbutton_right.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\top_logotitle.gif
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\torrent.ico
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\userinfo_head.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\image\VistaStyleListItems.bmp
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\preview.png
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\skin.xml
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\loginfailed.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\loginsucc.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\msgnotify.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\sound\notify.wav
c:\program files\FlashGet Network\FlashGet 3\skin\international\default\topmain.png
c:\program files\FlashGet Network\FlashGet 3\SnapShot.dll
c:\program files\FlashGet Network\FlashGet 3\storage.dll
c:\program files\FlashGet Network\FlashGet 3\SysOptimize.exe
c:\program files\FlashGet Network\FlashGet 3\uninst.exe
c:\program files\FlashGet Network\FlashGet 3\unrar.dll
c:\program files\FlashGet Network\FlashGet 3\VodCore.dll
c:\program files\FlashGet Network\FlashGet 3\zlib.dll
c:\users\senga\AppData\Roaming\BITS
c:\users\senga\AppData\Roaming\BITS\BITS.ini
c:\users\senga\AppData\Roaming\BITS\DHTTable.dat
c:\users\senga\AppData\Roaming\BITS\ProxyList.ini
c:\users\senga\AppData\Roaming\FlashGetBHO
c:\users\senga\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
c:\users\senga\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
c:\users\senga\AppData\Roaming\FlashGetBHO\GetUrl.htm
c:\windows\system32\Connect.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-19 do 2010-03-19 )))))))))))))))))))))))))))))))
.

2010-03-19 11:01 . 2010-03-19 11:02 -------- d-----w- C:\rsit
2010-03-19 11:01 . 2010-03-19 11:02 -------- d-----w- c:\program files\trend micro
2010-03-17 14:36 . 2010-03-17 19:52 201216 --sha-w- c:\users\senga\AppData\Local\937405763.dll
2010-03-17 10:10 . 2010-03-17 10:10 -------- d-----w- c:\programdata\Alwil Software
2010-03-16 22:34 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2010-03-16 22:34 . 2009-03-08 11:31 48128 ----a-w- c:\windows\system32\mshtmler.dll
2010-03-16 22:34 . 2009-03-08 11:22 156160 ----a-w- c:\windows\system32\msls31.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-13 16:27 . 2010-03-13 16:27 329312 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-13 16:27 . 2010-03-13 16:27 300616 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-13 16:27 . 2010-03-13 16:27 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-13 16:22 . 2010-03-13 16:22 734728 ----a-w- c:\users\senga\AppData\Roaming\Real\RealPlayer\setup\AU_setup12.exe
2010-03-12 09:38 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-03-11 19:33 . 2010-03-11 19:33 -------- d-----w- c:\program files\Common Files\Java
2010-03-11 08:58 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-11 08:58 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-03-11 08:58 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-01 22:13 . 2010-03-01 22:23 -------- d-----w- c:\users\senga\AppData\Roaming\Apple Computer
2010-03-01 22:13 . 2010-03-01 22:13 -------- dc----w- c:\windows\system32\DRVSTORE
2010-03-01 22:13 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-01 22:13 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-03-01 22:12 . 2010-03-01 22:12 -------- d-----w- c:\program files\iPod
2010-03-01 22:12 . 2010-03-01 22:13 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-01 22:12 . 2010-03-01 22:13 -------- d-----w- c:\program files\iTunes
2010-03-01 22:11 . 2010-03-01 22:11 -------- d-----w- c:\program files\Bonjour
2010-03-01 22:01 . 2010-03-01 22:01 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-24 13:10 . 2010-01-23 09:44 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-24 13:07 . 2010-01-25 08:35 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 13:07 . 2010-01-25 08:34 511488 ----a-w- c:\windows\system32\RMActivate.exe
2010-02-24 13:07 . 2010-01-25 12:48 472064 ----a-w- c:\windows\system32\secproc.dll
2010-02-24 13:07 . 2010-01-25 08:35 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 13:07 . 2010-01-25 08:34 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 13:07 . 2010-01-25 12:48 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 13:07 . 2010-01-25 12:48 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 13:07 . 2010-01-25 12:48 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 13:07 . 2010-01-25 12:45 329216 ----a-w- c:\windows\system32\msdrm.dll
2010-02-23 21:53 . 2010-03-19 10:41 -------- d-----w- c:\users\senga\dwhelper
2010-02-21 14:14 . 2010-02-21 14:14 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-02-21 14:13 . 2010-02-21 14:13 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-21 14:13 . 2010-02-21 14:19 -------- d-----w- c:\users\senga\AppData\Roaming\DAEMON Tools Lite
2010-02-21 14:13 . 2010-02-21 14:13 -------- d-----w- c:\programdata\DAEMON Tools Lite

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 20:36 . 2007-01-08 21:15 598838 ----a-w- c:\windows\system32\perfh005.dat
2010-03-19 20:36 . 2007-01-08 21:15 115014 ----a-w- c:\windows\system32\perfc005.dat
2010-03-18 11:52 . 2009-12-21 10:00 -------- d-----w- c:\users\senga\AppData\Roaming\Skype
2010-03-18 08:28 . 2009-12-21 10:02 -------- d-----w- c:\users\senga\AppData\Roaming\skypePM
2010-03-17 10:12 . 2009-12-21 09:24 -------- d-----w- c:\program files\Alwil Software
2010-03-17 09:39 . 2009-12-21 08:29 680 ----a-w- c:\users\senga\AppData\Local\d3d9caps.dat
2010-03-16 22:18 . 2009-12-21 08:37 125 ----a-w- c:\windows\xUninstall.bat
2010-03-15 19:58 . 2009-12-24 11:20 -------- d-----w- c:\program files\CCleaner
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-13 16:27 . 2009-12-31 22:24 -------- d-----w- c:\program files\Common Files\Real
2010-03-13 16:27 . 2009-12-31 22:24 -------- d-----w- c:\program files\Real
2010-03-11 19:32 . 2010-02-02 18:23 -------- d-----w- c:\program files\Java
2010-03-11 11:40 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-03-09 15:11 . 2009-12-21 09:04 27839 ----a-w- c:\programdata\nvModes.dat
2010-03-09 11:24 . 2009-12-21 09:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-09 11:24 . 2009-12-21 09:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-09 11:12 . 2009-12-21 09:24 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-09 11:12 . 2009-12-21 09:24 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-09 11:09 . 2009-12-21 09:24 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-09 11:08 . 2009-12-21 09:24 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-03-09 11:08 . 2009-12-21 09:24 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-03 09:56 . 2009-12-21 10:27 -------- d-----w- c:\users\senga\AppData\Roaming\ICQ
2010-03-01 22:12 . 2010-01-03 17:24 -------- d-----w- c:\program files\Common Files\Apple
2010-03-01 22:12 . 2010-01-03 17:24 -------- d-----w- c:\programdata\Apple Computer
2010-02-25 07:49 . 2009-12-21 08:31 100432 ----a-w- c:\users\senga\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 09:16 . 2009-12-22 08:03 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-16 14:01 . 2010-02-16 14:01 -------- d-----w- c:\program files\Ask & Record Toolbar
2010-02-03 08:14 . 2010-02-02 21:01 -------- d-----w- c:\programdata\Norton
2010-02-02 21:01 . 2010-02-02 21:01 -------- d-----w- c:\programdata\Symantec
2010-02-02 21:01 . 2010-02-02 21:01 -------- d-----w- c:\programdata\NortonInstaller
2010-02-02 17:56 . 2010-02-02 17:56 -------- d-----w- c:\programdata\McAfee
2010-02-02 11:10 . 2010-02-02 11:10 -------- d-----w- c:\programdata\VistaCodecs
2010-01-30 17:58 . 2010-01-30 17:58 203776 ----a-w- c:\windows\system32\clrviddc.dll
2010-01-27 22:20 . 2009-12-21 08:55 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-01-27 22:17 . 2009-12-21 08:55 737280 ----a-w- c:\windows\iun6002.exe
2010-01-27 22:12 . 2010-01-27 22:11 10050902 ----a-w- c:\users\senga\Codecs6030_allin1.exe
2010-01-16 15:40 . 2010-01-16 15:40 618 ----a-w- c:\windows\eReg.dat
2010-01-02 06:38 . 2010-03-16 22:35 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-03-16 22:35 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-03-16 22:35 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-03-16 22:35 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-28 12:35 . 2010-02-10 07:09 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 07:09 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-10 07:09 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-10 07:09 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-10 07:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-10 07:09 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-10 07:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-10 07:09 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-10 07:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-28 12:28 . 2010-02-10 07:09 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-12-24 12:07 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-23 13:56 . 2009-12-23 13:56 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-21 10:02 . 2009-12-21 10:02 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-12-21 08:59 . 2009-12-21 08:59 87552 ----a-w- c:\users\senga\AppData\Local\mbr_rest.exe
2009-12-21 08:59 . 2009-12-21 08:59 87552 ----a-w- c:\users\senga\AppData\Local\mbr_inst.exe
2009-12-21 08:38 . 2009-12-21 08:38 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-12-21 08:37 . 2009-12-21 08:37 319488 ----a-w- c:\windows\HideWin.exe
2008-04-04 13:38 . 2008-04-04 12:57 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-04-04 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-04-04 125952]
"Google Update"="c:\users\senga\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-12-30 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-04-04 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-20 6265376]
"Skytel"="Skytel.exe" [2008-08-20 1833504]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-19 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-19 92704]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-11-11 708608]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Ask and Record FLV Service"="c:\program files\Ask & Record Toolbar\FLVSrvc.exe" [2009-03-10 156672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-13 202256]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

c:\users\senga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-21 691696]
R3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);c:\windows\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
R3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);c:\windows\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-03-09 51792]
S2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [2008-11-05 159744]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]

.
Obsah adresáře 'Naplánované úlohy'

2010-03-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000Core.job
- c:\users\senga\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 09:20]

2010-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000UA.job
- c:\users\senga\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 09:20]

2010-01-07 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner\WiseRegistryCleaner.exe [2010-01-07 22:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uInternet Settings,ProxyOverride = *.local
IE: Download All by FlashGet3 - c:\users\senga\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - c:\users\senga\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\senga\AppData\Roaming\Mozilla\Firefox\Profiles\s4ata9xl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\senga\AppData\Roaming\Mozilla\Firefox\Profiles\s4ata9xl.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashgetXpi.dll
FF - component: c:\users\senga\AppData\Roaming\Mozilla\Firefox\Profiles\s4ata9xl.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF - plugin: c:\users\senga\AppData\Local\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-FlashGet 3.0 Beta - c:\program files\FlashGet Network\FlashGet 3\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-19 21:41
Windows 6.0.6001 Service Pack 1 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-03-19 21:45:29
ComboFix-quarantined-files.txt 2010-03-19 20:45

Před spuštěním: Volných bajtů: 243 521 875 968
Po spuštění: Volných bajtů: 243 554 181 120

- - End Of File - - E4359015EA0D50C4BC9558205EA1CB76


Už teď se počítač chová slušněji. :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23301
Registrován: 23 říj 2008 08:02
Bydliště: Haná

Re: Facebook vir 2

#5 Příspěvek od motji »

Ještě mu trochu domluvíme :D

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Collect::
c:\users\senga\AppData\Local\937405763.dll

Folder::
c:\program files\DAEMON Tools Toolbar

DDS::
uStart Page = hxxp://www.daemon-search.com/startpage

-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#6 Příspěvek od sengaX »

po několika pokusech mi to pořád hlásí, že je nesprávně pojmenovaný CFScript.txt a Cobofix (potvora) se nerozjede :(

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#7 Příspěvek od sengaX »

Měla jsem to opravdu špatně pojmenované, vypustila jsem txt a rozjelo se to. Nový log z Combofixu:

ComboFix 10-03-19.04 - senga 19.03.2010 22:24:54.2.1 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.420.1029.18.1789.868 [GMT 1:00]
Spuštěný z: c:\users\senga\Desktop\Potvora.com
Použité ovládací přepínače :: c:\users\senga\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

file zipped: c:\users\senga\AppData\Local\937405763.dll
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\DAEMON Tools Toolbar
c:\program files\DAEMON Tools Toolbar\_DTLite.xml
c:\program files\DAEMON Tools Toolbar\DTToolbar.dll
c:\program files\DAEMON Tools Toolbar\Resources\about.ico
c:\program files\DAEMON Tools Toolbar\Resources\AboutWindow.ico
c:\program files\DAEMON Tools Toolbar\Resources\accept.ico
c:\program files\DAEMON Tools Toolbar\Resources\AddRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.ico
c:\program files\DAEMON Tools Toolbar\Resources\as.png
c:\program files\DAEMON Tools Toolbar\Resources\astro.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_home.ico
c:\program files\DAEMON Tools Toolbar\Resources\astro_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroburn_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\astroLite_16.ico
c:\program files\DAEMON Tools Toolbar\Resources\az.ico
c:\program files\DAEMON Tools Toolbar\Resources\b1.png
c:\program files\DAEMON Tools Toolbar\Resources\burn_files.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_image.ico
c:\program files\DAEMON Tools Toolbar\Resources\burn_imgs.ico
c:\program files\DAEMON Tools Toolbar\Resources\BurnImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\Config.ico
c:\program files\DAEMON Tools Toolbar\Resources\d.ico
c:\program files\DAEMON Tools Toolbar\Resources\d2.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\daemon_search_site.ico
c:\program files\DAEMON Tools Toolbar\Resources\dot_disabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_enabled.bmp
c:\program files\DAEMON Tools Toolbar\Resources\dot_on_over.bmp
c:\program files\DAEMON Tools Toolbar\Resources\download.ico
c:\program files\DAEMON Tools Toolbar\Resources\ds.ico
c:\program files\DAEMON Tools Toolbar\Resources\dsearch.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt-home.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_about.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_buy.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_download.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_faq.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_line.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_lite.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_manual.ico
c:\program files\DAEMON Tools Toolbar\Resources\dt_pro.ico
c:\program files\DAEMON Tools Toolbar\Resources\DTPro.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt16.ico
c:\program files\DAEMON Tools Toolbar\Resources\dtt32.ico
c:\program files\DAEMON Tools Toolbar\Resources\Dwnl.ico
c:\program files\DAEMON Tools Toolbar\Resources\emulation.ico
c:\program files\DAEMON Tools Toolbar\Resources\favicon.ico
c:\program files\DAEMON Tools Toolbar\Resources\features.ico
c:\program files\DAEMON Tools Toolbar\Resources\feedback.ico
c:\program files\DAEMON Tools Toolbar\Resources\forum.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrix.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixCristals.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixDownload.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixPlayOnline.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameCentrixTop.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameS.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\games_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\GameSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\gct16.ico
c:\program files\DAEMON Tools Toolbar\Resources\gd.ico
c:\program files\DAEMON Tools Toolbar\Resources\genre.xml
c:\program files\DAEMON Tools Toolbar\Resources\globe.ico
c:\program files\DAEMON Tools Toolbar\Resources\GrabImage.ico
c:\program files\DAEMON Tools Toolbar\Resources\hb.bmp
c:\program files\DAEMON Tools Toolbar\Resources\hb.ico
c:\program files\DAEMON Tools Toolbar\Resources\help.ico
c:\program files\DAEMON Tools Toolbar\Resources\hide.ico
c:\program files\DAEMON Tools Toolbar\Resources\home.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\image_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageS.ico
c:\program files\DAEMON Tools Toolbar\Resources\ImageSA.ico
c:\program files\DAEMON Tools Toolbar\Resources\ip.ico
c:\program files\DAEMON Tools Toolbar\Resources\lang.xml
c:\program files\DAEMON Tools Toolbar\Resources\lingvo.ico
c:\program files\DAEMON Tools Toolbar\Resources\m.ico
c:\program files\DAEMON Tools Toolbar\Resources\mail.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mail_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\mailc_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioConfig.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRadioStation.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuRSCur.ico
c:\program files\DAEMON Tools Toolbar\Resources\MenuTr.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount.ico
c:\program files\DAEMON Tools Toolbar\Resources\mount_n_drive.ico
c:\program files\DAEMON Tools Toolbar\Resources\next.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\next_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none.bmp
c:\program files\DAEMON Tools Toolbar\Resources\none_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\op.ico
c:\program files\DAEMON Tools Toolbar\Resources\play.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play.ico
c:\program files\DAEMON Tools Toolbar\Resources\play_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\play_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\pragma.ico
c:\program files\DAEMON Tools Toolbar\Resources\prev.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prev_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\prod.ico
c:\program files\DAEMON Tools Toolbar\Resources\Radio.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioBg.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioBgMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDisp_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioDown_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioE.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioG.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLDotMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeft.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLeftMask.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioLM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioN.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioR.ico
c:\program files\DAEMON Tools Toolbar\Resources\RadioRM.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioRU.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioVolume_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\RadioW.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rbcheck.ico
c:\program files\DAEMON Tools Toolbar\Resources\rbtxt.ico
c:\program files\DAEMON Tools Toolbar\Resources\refresh.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\refresh_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Rss.ico
c:\program files\DAEMON Tools Toolbar\Resources\Rss1.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssA1.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssClose.ico
c:\program files\DAEMON Tools Toolbar\Resources\rssL.bmp
c:\program files\DAEMON Tools Toolbar\Resources\rssOpen.ico
c:\program files\DAEMON Tools Toolbar\Resources\RssRefresh.ico
c:\program files\DAEMON Tools Toolbar\Resources\s2.ico
c:\program files\DAEMON Tools Toolbar\Resources\show.ico
c:\program files\DAEMON Tools Toolbar\Resources\size.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_lr.ico
c:\program files\DAEMON Tools Toolbar\Resources\size_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\size_rl.ico
c:\program files\DAEMON Tools Toolbar\Resources\skins.ico
c:\program files\DAEMON Tools Toolbar\Resources\spt.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop.ico
c:\program files\DAEMON Tools Toolbar\Resources\stop_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\stop_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\style.ico
c:\program files\DAEMON Tools Toolbar\Resources\SupportRequest.ico
c:\program files\DAEMON Tools Toolbar\Resources\timer.ico
c:\program files\DAEMON Tools Toolbar\Resources\TitleIcon.ico
c:\program files\DAEMON Tools Toolbar\Resources\toolbar.xml
c:\program files\DAEMON Tools Toolbar\Resources\trans.ico
c:\program files\DAEMON Tools Toolbar\Resources\Trash.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_disable.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\Trash_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\u.ico
c:\program files\DAEMON Tools Toolbar\Resources\unmount-all.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol.ico
c:\program files\DAEMON Tools Toolbar\Resources\vol_back.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_dott_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_mute_check.bmp
c:\program files\DAEMON Tools Toolbar\Resources\vol_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtClose_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_down.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_m.bmp
c:\program files\DAEMON Tools Toolbar\Resources\wBtText_under.bmp
c:\program files\DAEMON Tools Toolbar\Resources\web_resources.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search.ico
c:\program files\DAEMON Tools Toolbar\Resources\web_search_SA.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebS.ico
c:\program files\DAEMON Tools Toolbar\Resources\WebSa.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi0.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi1.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi10.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi11.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi12.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi13.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi14.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi2.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi3.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi4.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi5.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi6.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi7.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi8.ico
c:\program files\DAEMON Tools Toolbar\Resources\wi9.ico
c:\program files\DAEMON Tools Toolbar\uninst.exe
c:\users\senga\AppData\Local\937405763.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-19 do 2010-03-19 )))))))))))))))))))))))))))))))
.

2010-03-19 21:34 . 2010-03-19 21:34 -------- d-----w- c:\users\senga\AppData\Local\temp
2010-03-19 21:34 . 2010-03-19 21:34 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-19 21:34 . 2010-03-19 21:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-19 21:19 . 2010-03-19 21:20 -------- d-----w- C:\Potvora26856P
2010-03-19 21:17 . 2010-03-19 21:18 -------- d-----w- C:\Potvora19914P
2010-03-19 21:15 . 2010-03-19 21:16 -------- d-----w- C:\Potvora30134P
2010-03-19 21:11 . 2010-03-19 21:11 -------- d-----w- C:\Potvora31501P
2010-03-19 20:26 . 2010-03-19 20:45 -------- d-----w- C:\Potvora
2010-03-19 11:01 . 2010-03-19 11:02 -------- d-----w- C:\rsit
2010-03-19 11:01 . 2010-03-19 11:02 -------- d-----w- c:\program files\trend micro
2010-03-17 10:10 . 2010-03-17 10:10 -------- d-----w- c:\programdata\Alwil Software
2010-03-16 22:34 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
2010-03-16 22:34 . 2009-03-08 11:31 48128 ----a-w- c:\windows\system32\mshtmler.dll
2010-03-16 22:34 . 2009-03-08 11:22 156160 ----a-w- c:\windows\system32\msls31.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-13 16:27 . 2010-03-13 16:27 329312 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-13 16:27 . 2010-03-13 16:27 300616 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-13 16:27 . 2010-03-13 16:27 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-13 16:22 . 2010-03-13 16:22 734728 ----a-w- c:\users\senga\AppData\Roaming\Real\RealPlayer\setup\AU_setup12.exe
2010-03-12 09:38 . 2010-02-12 10:48 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-03-11 19:33 . 2010-03-11 19:33 -------- d-----w- c:\program files\Common Files\Java
2010-03-11 08:58 . 2010-02-20 23:39 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-11 08:58 . 2010-02-20 23:37 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-03-11 08:58 . 2010-02-20 21:18 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-01 22:13 . 2010-03-01 22:23 -------- d-----w- c:\users\senga\AppData\Roaming\Apple Computer
2010-03-01 22:13 . 2010-03-01 22:13 -------- dc----w- c:\windows\system32\DRVSTORE
2010-03-01 22:13 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-01 22:13 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-03-01 22:12 . 2010-03-01 22:12 -------- d-----w- c:\program files\iPod
2010-03-01 22:12 . 2010-03-01 22:13 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-01 22:12 . 2010-03-01 22:13 -------- d-----w- c:\program files\iTunes
2010-03-01 22:11 . 2010-03-01 22:11 -------- d-----w- c:\program files\Bonjour
2010-03-01 22:01 . 2010-03-01 22:01 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-24 13:10 . 2010-01-23 09:44 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-24 13:07 . 2010-01-25 08:35 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-02-24 13:07 . 2010-01-25 08:34 511488 ----a-w- c:\windows\system32\RMActivate.exe
2010-02-24 13:07 . 2010-01-25 12:48 472064 ----a-w- c:\windows\system32\secproc.dll
2010-02-24 13:07 . 2010-01-25 08:35 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 13:07 . 2010-01-25 08:34 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 13:07 . 2010-01-25 12:48 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2010-02-24 13:07 . 2010-01-25 12:48 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 13:07 . 2010-01-25 12:48 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-02-24 13:07 . 2010-01-25 12:45 329216 ----a-w- c:\windows\system32\msdrm.dll
2010-02-23 21:53 . 2010-03-19 10:41 -------- d-----w- c:\users\senga\dwhelper
2010-02-21 14:13 . 2010-02-21 14:13 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-21 14:13 . 2010-02-21 14:19 -------- d-----w- c:\users\senga\AppData\Roaming\DAEMON Tools Lite
2010-02-21 14:13 . 2010-02-21 14:13 -------- d-----w- c:\programdata\DAEMON Tools Lite

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 20:36 . 2007-01-08 21:15 598838 ----a-w- c:\windows\system32\perfh005.dat
2010-03-19 20:36 . 2007-01-08 21:15 115014 ----a-w- c:\windows\system32\perfc005.dat
2010-03-18 11:52 . 2009-12-21 10:00 -------- d-----w- c:\users\senga\AppData\Roaming\Skype
2010-03-18 08:28 . 2009-12-21 10:02 -------- d-----w- c:\users\senga\AppData\Roaming\skypePM
2010-03-17 10:12 . 2009-12-21 09:24 -------- d-----w- c:\program files\Alwil Software
2010-03-17 09:39 . 2009-12-21 08:29 680 ----a-w- c:\users\senga\AppData\Local\d3d9caps.dat
2010-03-16 22:18 . 2009-12-21 08:37 125 ----a-w- c:\windows\xUninstall.bat
2010-03-15 19:58 . 2009-12-24 11:20 -------- d-----w- c:\program files\CCleaner
2010-03-13 16:27 . 2010-03-13 16:27 118784 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-13 16:27 . 2009-12-31 22:24 -------- d-----w- c:\program files\Common Files\Real
2010-03-13 16:27 . 2009-12-31 22:24 -------- d-----w- c:\program files\Real
2010-03-11 19:32 . 2010-02-02 18:23 -------- d-----w- c:\program files\Java
2010-03-11 11:40 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-03-09 15:11 . 2009-12-21 09:04 27839 ----a-w- c:\programdata\nvModes.dat
2010-03-09 11:24 . 2009-12-21 09:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-09 11:24 . 2009-12-21 09:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-09 11:12 . 2009-12-21 09:24 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-09 11:12 . 2009-12-21 09:24 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-09 11:09 . 2009-12-21 09:24 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-09 11:08 . 2009-12-21 09:24 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-03-09 11:08 . 2009-12-21 09:24 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-03 09:56 . 2009-12-21 10:27 -------- d-----w- c:\users\senga\AppData\Roaming\ICQ
2010-03-01 22:12 . 2010-01-03 17:24 -------- d-----w- c:\program files\Common Files\Apple
2010-03-01 22:12 . 2010-01-03 17:24 -------- d-----w- c:\programdata\Apple Computer
2010-02-25 07:49 . 2009-12-21 08:31 100432 ----a-w- c:\users\senga\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 09:16 . 2009-12-22 08:03 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-16 14:01 . 2010-02-16 14:01 -------- d-----w- c:\program files\Ask & Record Toolbar
2010-02-03 08:14 . 2010-02-02 21:01 -------- d-----w- c:\programdata\Norton
2010-02-02 21:01 . 2010-02-02 21:01 -------- d-----w- c:\programdata\Symantec
2010-02-02 21:01 . 2010-02-02 21:01 -------- d-----w- c:\programdata\NortonInstaller
2010-02-02 17:56 . 2010-02-02 17:56 -------- d-----w- c:\programdata\McAfee
2010-02-02 11:10 . 2010-02-02 11:10 -------- d-----w- c:\programdata\VistaCodecs
2010-01-30 17:58 . 2010-01-30 17:58 203776 ----a-w- c:\windows\system32\clrviddc.dll
2010-01-27 22:20 . 2009-12-21 08:55 -------- d-----w- c:\program files\Codec Pack - All In 1
2010-01-27 22:17 . 2009-12-21 08:55 737280 ----a-w- c:\windows\iun6002.exe
2010-01-27 22:12 . 2010-01-27 22:11 10050902 ----a-w- c:\users\senga\Codecs6030_allin1.exe
2010-01-16 15:40 . 2010-01-16 15:40 618 ----a-w- c:\windows\eReg.dat
2010-01-02 06:38 . 2010-03-16 22:35 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-03-16 22:35 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-03-16 22:35 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-03-16 22:35 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-28 12:35 . 2010-02-10 07:09 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 07:09 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-10 07:09 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-10 07:09 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-10 07:09 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-10 07:09 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-10 07:09 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-10 07:09 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-10 07:09 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-28 12:28 . 2010-02-10 07:09 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-12-24 12:07 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-23 13:56 . 2009-12-23 13:56 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-21 10:02 . 2009-12-21 10:02 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-12-21 08:59 . 2009-12-21 08:59 87552 ----a-w- c:\users\senga\AppData\Local\mbr_rest.exe
2009-12-21 08:59 . 2009-12-21 08:59 87552 ----a-w- c:\users\senga\AppData\Local\mbr_inst.exe
2009-12-21 08:38 . 2009-12-21 08:38 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-12-21 08:37 . 2009-12-21 08:37 319488 ----a-w- c:\windows\HideWin.exe
2008-04-04 13:38 . 2008-04-04 12:57 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-04-04 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-04-04 125952]
"Google Update"="c:\users\senga\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-12-30 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-04-04 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2008-08-20 6265376]
"Skytel"="Skytel.exe" [2008-08-20 1833504]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-07-19 13543968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-07-19 92704]
"MGSysCtrl"="c:\program files\System Control Manager\MGSysCtrl.exe" [2008-11-11 708608]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Ask and Record FLV Service"="c:\program files\Ask & Record Toolbar\FLVSrvc.exe" [2009-03-10 156672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-13 202256]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

c:\users\senga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-02-21 691696]
R3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);c:\windows\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
R3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);c:\windows\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-03-09 51792]
S2 Micro Star SCM;Micro Star SCM;c:\program files\System Control Manager\MSIService.exe [2008-11-05 159744]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]

.
Obsah adresáře 'Naplánované úlohy'

2010-03-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000Core.job
- c:\users\senga\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 09:20]

2010-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000UA.job
- c:\users\senga\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 09:20]

2010-01-07 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner\WiseRegistryCleaner.exe [2010-01-07 22:48]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: Download All by FlashGet3 - c:\users\senga\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
IE: Download by FlashGet3 - c:\users\senga\AppData\Roaming\FlashGetBHO\GetUrl.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\senga\AppData\Roaming\Mozilla\Firefox\Profiles\s4ata9xl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8 ... &gfns=1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\senga\AppData\Roaming\Mozilla\Firefox\Profiles\s4ata9xl.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashgetXpi.dll
FF - component: c:\users\senga\AppData\Roaming\Mozilla\Firefox\Profiles\s4ata9xl.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF - plugin: c:\users\senga\AppData\Local\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-19 22:34
Windows 6.0.6001 Service Pack 1 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-03-19 22:38:17
ComboFix-quarantined-files.txt 2010-03-19 21:38
ComboFix2.txt 2010-03-19 20:45

Před spuštěním: Volných bajtů: 243 616 796 672
Po spuštění: Volných bajtů: 243 594 092 544

- - End Of File - - A80B291B6D672EAEF0FB03E40DC2BD55
Nahr nˇ probŘhlo ŁspŘçnŘ

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23301
Registrován: 23 říj 2008 08:02
Bydliště: Haná

Re: Facebook vir 2

#8 Příspěvek od motji »

:arrow: Dejte soubor otestovat na http://www.virustotal.com


c:\users\senga\AppData\Local\mbr_rest.exe
c:\users\senga\AppData\Local\mbr_inst.exe
c:\windows\xUninstall.bat

-Na virustotalu dáte procházet, a do spodního okénka nakopírujete přímo cestu k souboru a dáte odeslat
-z prohlížeče zkopírujete adresu ke stránce s výsledky



:arrow: Najděte soubor
c:\windows\xUninstall.bat
-klikněte na něj pravým myšítkem :arrow: otevřít v notepadu :arrow: text vložte zde
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#9 Příspěvek od sengaX »

Dobré pozdní ráno! :)

Výsledky testování souború:


c:\users\senga\AppData\Local\mbr_rest.exe

Stálý odkaz: analisis/780ff245c050c839348807eaa0030828db36c4156a911c0bb785ae57176241ec-1268984281


c:\users\senga\AppData\Local\mbr_inst.exe

Stálý odkaz: analisis/932d6737cc05dbec6b99f6253d436785b8ef13b33f1a0724f950473ab3b9ef05-1259408388


c:\windows\xUninstall.bat

Stálý odkaz: analisis/80b237762ea61deb2a7ce417ca3ec7b9052a2fbf71b927831fc6c08248c9e67d-1265552380


... a tady poslední soubor v notepadu:

"C:\Program Files\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" SilentDel

exit

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23301
Registrován: 23 říj 2008 08:02
Bydliště: Haná

Re: Facebook vir 2

#10 Příspěvek od motji »

Já nepotřebuju stálý odkaz, ale testy Vašeho souboru. Až se Vás zeptá, jestli testovat znovu, zvolte tuto možnost :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#11 Příspěvek od sengaX »

Omlouvám se. :oops:

Výsledek pro c:\users\senga\AppData\Local\mbr_rest.exe

http://www.virustotal.com/cs/analisis/7 ... 1269109278

pro c:\users\senga\AppData\Local\mbr_inst.exe

http://www.virustotal.com/cs/analisis/9 ... 1269109474

pro c:\windows\xUninstall.bat

http://www.virustotal.com/cs/analisis/8 ... 1269109835

a c:\windows\xUninstall.bat

"C:\Program Files\InstallShield Installation Information\{26604C7E-A313-4D12-867F-7C6E7820BE4C}\setup.exe" SilentDel

exit

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23301
Registrován: 23 říj 2008 08:02
Bydliště: Haná

Re: Facebook vir 2

#12 Příspěvek od motji »

Jak to ted vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#13 Příspěvek od sengaX »

Počítač funguje bez problémů, dokonce jdou i některé věci, které dřív nešly. Čekala jsem raději na Vaši kontrolu, abych mohla bez rizika podp :o ořit fórum ... Už můžu???

Jinak moc děkuji pomoc, za ochotu, trpělivost a shovívavost :worship: ... nevypadám teď před děckama jako úlný idiot. :D

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23301
Registrován: 23 říj 2008 08:02
Bydliště: Haná

Re: Facebook vir 2

#14 Příspěvek od motji »

Podpořit forum můžete :o , děkujeme :D
Ještě uklidíme :)

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

sengaX
Návštěvník
Návštěvník
Příspěvky: 17
Registrován: 18 bře 2010 21:53

Re: Facebook vir 2

#15 Příspěvek od sengaX »

ComboFix podle návodu nenalezen, vyhodila jsem jen Potvoru do koše. Odpoledne jsem prováděla CCleaner a Wise Registry Cleaner, ale postupovala jsem podle návodu, takže v PC by už nemělo nic zůstat.
Tady RSIT log:

Logfile of random's system information tool 1.06 (written by random/random)
Run by senga at 2010-03-20 20:17:28
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 232 GB (76%) free of 305 GB
Total RAM: 1789 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:17:59, on 20.3.2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\System Control Manager\MGSysCtrl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Ask & Record Toolbar\FLVSrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\senga\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\senga\Downloads\RSIT.exe
C:\Program Files\trend micro\senga.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Ask and Record FLV Service] "C:\Program Files\Ask & Record Toolbar\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\senga\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Micro Star SCM - Micro-Star Int'l Co., Ltd. - C:\Program Files\System Control Manager\MSIService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 6852 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4049098025-673099186-213311711-1000UA.job
C:\Windows\tasks\Wise Registry Cleaner 4.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-03-19 341600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-18 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2009-08-16 962808]
{32099AAC-C132-4136-9E9A-4E364A424E17}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-04-04 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-20 6265376]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-07-19 13543968]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-07-19 92704]
"MGSysCtrl"=C:\Program Files\System Control Manager\MGSysCtrl.exe [2008-11-11 708608]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"Ask and Record FLV Service"=C:\Program Files\Ask & Record Toolbar\FLVSrvc.exe [2009-03-10 156672]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-02-15 141608]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-03-19 202256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-04-04 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-04-04 125952]
"Google Update"=C:\Users\senga\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 135664]

C:\Users\senga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"$INSTDIR\FlvDetector.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlvDetector.exe:*:Enabled:FGFlvDetector"
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-03-20 20:17:28 ----D---- C:\rsit
2010-03-19 23:11:20 ----D---- C:\Program Files\Common Files\xing shared
2010-03-19 22:40:06 ----SHD---- C:\$RECYCLE.BIN
2010-03-19 22:40:03 ----D---- C:\Windows\temp
2010-03-19 22:23:55 ----D---- C:\Potvora24277P
2010-03-19 22:19:20 ----D---- C:\Potvora26856P
2010-03-19 22:17:56 ----D---- C:\Potvora19914P
2010-03-19 22:15:48 ----D---- C:\Potvora30134P
2010-03-19 22:11:40 ----D---- C:\Potvora31501P
2010-03-19 21:28:50 ----A---- C:\Windows\PEV.exe
2010-03-19 21:28:50 ----A---- C:\Windows\MBR.exe
2010-03-19 21:28:43 ----D---- C:\Windows\ERDNT
2010-03-19 21:26:56 ----D---- C:\Potvora
2010-03-19 12:01:58 ----D---- C:\Program Files\trend micro
2010-03-17 11:10:02 ----D---- C:\ProgramData\Alwil Software
2010-03-17 10:37:28 ----A---- C:\Windows\system32\jscript.dll
2010-03-16 23:35:14 ----A---- C:\Windows\system32\occache.dll
2010-03-16 23:35:13 ----A---- C:\Windows\system32\msfeeds.dll
2010-03-16 23:35:13 ----A---- C:\Windows\system32\jsproxy.dll
2010-03-16 23:35:13 ----A---- C:\Windows\system32\iepeers.dll
2010-03-16 23:35:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-03-16 23:35:12 ----A---- C:\Windows\system32\ieui.dll
2010-03-16 23:35:11 ----A---- C:\Windows\system32\wininet.dll
2010-03-16 23:35:11 ----A---- C:\Windows\system32\iesetup.dll
2010-03-16 23:35:11 ----A---- C:\Windows\system32\iernonce.dll
2010-03-16 23:35:10 ----A---- C:\Windows\system32\msfeedssync.exe
2010-03-16 23:35:10 ----A---- C:\Windows\system32\iertutil.dll
2010-03-16 23:35:10 ----A---- C:\Windows\system32\ie4uinit.exe
2010-03-16 23:35:09 ----A---- C:\Windows\system32\urlmon.dll
2010-03-16 23:35:09 ----A---- C:\Windows\system32\ieUnatt.exe
2010-03-16 23:35:09 ----A---- C:\Windows\system32\iesysprep.dll
2010-03-16 23:35:09 ----A---- C:\Windows\system32\iedkcs32.dll
2010-03-16 23:35:07 ----A---- C:\Windows\system32\ieframe.dll
2010-03-16 23:35:06 ----A---- C:\Windows\system32\mshtml.dll
2010-03-16 23:34:01 ----A---- C:\Windows\system32\mshtmled.dll
2010-03-16 23:34:01 ----A---- C:\Windows\system32\icardie.dll
2010-03-16 23:34:00 ----A---- C:\Windows\system32\msls31.dll
2010-03-16 23:34:00 ----A---- C:\Windows\system32\mshtmler.dll
2010-03-16 23:34:00 ----A---- C:\Windows\system32\admparse.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\imgutil.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\ieakeng.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\dxtmsft.dll
2010-03-16 23:33:59 ----A---- C:\Windows\system32\corpol.dll
2010-03-16 23:33:58 ----A---- C:\Windows\system32\licmgr10.dll
2010-03-16 23:33:58 ----A---- C:\Windows\system32\inseng.dll
2010-03-16 23:33:58 ----A---- C:\Windows\system32\dxtrans.dll
2010-03-16 23:33:57 ----A---- C:\Windows\system32\webcheck.dll
2010-03-16 23:33:57 ----A---- C:\Windows\system32\msrating.dll
2010-03-16 23:33:57 ----A---- C:\Windows\system32\ieaksie.dll
2010-03-16 23:33:56 ----A---- C:\Windows\system32\WinFXDocObj.exe
2010-03-16 23:33:56 ----A---- C:\Windows\system32\wextract.exe
2010-03-16 23:33:56 ----A---- C:\Windows\system32\mstime.dll
2010-03-16 23:33:56 ----A---- C:\Windows\system32\ieakui.dll
2010-03-16 23:33:55 ----A---- C:\Windows\system32\pngfilt.dll
2010-03-16 23:33:55 ----A---- C:\Windows\system32\advpack.dll
2010-03-16 23:33:54 ----A---- C:\Windows\system32\vbscript.dll
2010-03-16 23:33:54 ----A---- C:\Windows\system32\ieapfltr.dll
2010-03-16 23:33:53 ----A---- C:\Windows\system32\url.dll
2010-03-16 23:33:52 ----A---- C:\Windows\system32\mshta.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\SetDepNx.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\PDMSetup.exe
2010-03-16 23:33:51 ----A---- C:\Windows\system32\iexpress.exe
2010-03-12 10:38:10 ----A---- C:\Windows\system32\browserchoice.exe
2010-03-11 20:33:17 ----D---- C:\ProgramData\Sun
2010-03-11 20:33:16 ----D---- C:\Program Files\Common Files\Java
2010-03-11 20:32:47 ----A---- C:\Windows\system32\javaws.exe
2010-03-11 20:32:47 ----A---- C:\Windows\system32\javaw.exe
2010-03-11 20:32:47 ----A---- C:\Windows\system32\java.exe
2010-03-11 09:58:04 ----A---- C:\Windows\system32\nshhttp.dll
2010-03-11 09:58:00 ----A---- C:\Windows\system32\httpapi.dll
2010-03-01 23:13:27 ----D---- C:\Users\senga\AppData\Roaming\Apple Computer
2010-03-01 23:13:11 ----DC---- C:\Windows\system32\DRVSTORE
2010-03-01 23:13:11 ----A---- C:\Windows\system32\GEARAspi.dll
2010-03-01 23:12:33 ----D---- C:\Program Files\iPod
2010-03-01 23:12:29 ----D---- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-01 23:12:29 ----D---- C:\Program Files\iTunes
2010-03-01 23:11:55 ----D---- C:\Program Files\Bonjour
2010-02-24 14:10:20 ----A---- C:\Windows\system32\tzres.dll
2010-02-24 14:07:58 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-02-24 14:07:57 ----A---- C:\Windows\system32\RMActivate.exe
2010-02-24 14:07:56 ----A---- C:\Windows\system32\secproc.dll
2010-02-24 14:07:56 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-02-24 14:07:56 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-02-24 14:07:55 ----A---- C:\Windows\system32\secproc_isv.dll
2010-02-24 14:07:52 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-02-24 14:07:52 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-02-24 14:07:52 ----A---- C:\Windows\system32\msdrm.dll
2010-02-21 15:13:26 ----D---- C:\Users\senga\AppData\Roaming\DAEMON Tools Lite
2010-02-21 15:13:22 ----D---- C:\ProgramData\DAEMON Tools Lite

======List of files/folders modified in the last 1 months======

2010-03-20 20:16:52 ----D---- C:\Windows\System32
2010-03-20 20:16:52 ----D---- C:\Windows\inf
2010-03-20 20:16:52 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-03-20 20:10:11 ----D---- C:\Windows
2010-03-20 18:44:34 ----D---- C:\Windows\Debug
2010-03-20 18:00:27 ----D---- C:\Windows\system32\Tasks
2010-03-19 23:11:48 ----D---- C:\Program Files\Common Files\Real
2010-03-19 23:11:45 ----A---- C:\Windows\system32\rmoc3260.dll
2010-03-19 23:11:31 ----A---- C:\Windows\system32\pndx5032.dll
2010-03-19 23:11:31 ----A---- C:\Windows\system32\pndx5016.dll
2010-03-19 23:11:26 ----SHD---- C:\Windows\Installer
2010-03-19 23:11:25 ----D---- C:\Program Files\Real
2010-03-19 23:11:20 ----D---- C:\Program Files\Common Files
2010-03-19 23:10:50 ----A---- C:\Windows\system32\pncrt.dll
2010-03-19 22:34:37 ----A---- C:\Windows\system.ini
2010-03-19 22:34:07 ----RD---- C:\Program Files
2010-03-19 22:30:24 ----D---- C:\Windows\system32\drivers
2010-03-19 22:30:24 ----D---- C:\Windows\AppPatch
2010-03-19 21:29:54 ----D---- C:\Windows\Prefetch
2010-03-19 07:15:54 ----SHD---- C:\System Volume Information
2010-03-18 12:52:01 ----D---- C:\Users\senga\AppData\Roaming\Skype
2010-03-18 09:28:56 ----D---- C:\Users\senga\AppData\Roaming\skypePM
2010-03-18 08:15:25 ----D---- C:\ProgramData\Real
2010-03-18 07:45:53 ----D---- C:\Windows\winsxs
2010-03-18 07:43:09 ----D---- C:\Windows\system32\catroot2
2010-03-17 11:12:40 ----D---- C:\Program Files\Alwil Software
2010-03-17 11:10:02 ----D---- C:\ProgramData
2010-03-17 10:37:14 ----D---- C:\Windows\system32\catroot
2010-03-16 23:55:30 ----D---- C:\Windows\rescache
2010-03-16 23:36:42 ----D---- C:\Windows\system32\migration
2010-03-16 23:36:42 ----D---- C:\Program Files\Internet Explorer
2010-03-16 23:36:41 ----D---- C:\Windows\system32\cs-CZ
2010-03-16 23:36:39 ----D---- C:\Windows\system32\en-US
2010-03-16 23:36:39 ----D---- C:\Windows\PolicyDefinitions
2010-03-16 23:18:13 ----A---- C:\Windows\xUninstall.bat
2010-03-16 23:18:12 ----D---- C:\Windows\JMCR_DIR
2010-03-15 20:58:14 ----D---- C:\Program Files\CCleaner
2010-03-13 17:29:21 ----D---- C:\Users\senga\AppData\Roaming\Real
2010-03-13 11:54:42 ----D---- C:\Program Files\Mozilla Firefox
2010-03-11 20:32:32 ----D---- C:\Program Files\Java
2010-03-11 12:40:59 ----D---- C:\Program Files\Windows Mail
2010-03-11 12:40:59 ----D---- C:\Program Files\Movie Maker
2010-03-09 12:24:05 ----A---- C:\Windows\system32\aswBoot.exe
2010-03-04 19:03:19 ----D---- C:\Downloads
2010-03-03 10:56:28 ----D---- C:\Users\senga\AppData\Roaming\ICQ
2010-03-01 23:12:31 ----D---- C:\Program Files\Common Files\Apple
2010-03-01 23:12:29 ----D---- C:\ProgramData\Apple Computer
2010-03-01 21:30:14 ----A---- C:\Windows\system32\mrt.exe
2010-02-26 22:55:37 ----A---- C:\Windows\cdplayer.ini
2010-02-25 08:46:38 ----RSD---- C:\Windows\Fonts
2010-02-24 10:16:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-22 19:46:20 ----D---- C:\Windows\system32\WDI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2010-03-09 23376]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-04-04 350720]
R2 Aspi32;Aspi32; C:\Windows\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2010-03-09 51792]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2008-02-29 1202560]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-06-30 917504]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-04-04 14208]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-20 2160792]
R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [2008-08-07 97536]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-19 7545824]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-04-01 14848]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-08-06 124928]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-04-04 134016]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-04-04 11264]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\Windows\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\Windows\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-04-04 5632]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-04-04 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-04-04 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-04-04 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-04-04 6016]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-04-04 88576]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-04-04 83328]
S4 ErrDev;Ovladače chybového zařízení hardwaru Microsoft; C:\Windows\system32\drivers\errdev.sys [2008-04-04 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-04-04 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agrsmsvc.exe [2007-12-11 12800]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-04-04 21504]
R2 Micro Star SCM;Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [2008-11-05 159744]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-19 196608]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-02-15 545576]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-04-04 21504]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-04-04 523776]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-04-04 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-04-04 917504]

-----------------EOF-----------------

Počítač funguje bez problémů. :worship:

Odpovědět