trojan Delf
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
trojan Delf
Dobry den, AV mi nasel nejake trojany - zde vypis a nasledne log s rsit:
C:\Users\milo?\AppData\Local\Temp\1520133.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Users\milo?\AppData\Local\Temp\52450885-loader2.exe Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Users\milo?\AppData\Local\Temp\7572230.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Users\milo?\Documents\Flash-Player.exe Win32/Delf.QCZ trojský k??
C:\Windows\l1rezerv.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Windows\sysdriver32.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Windows\sysdriver32_.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Windows\systemup.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QQI trojský k??
C:\Windows\Temp\3507101.exe varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Windows\Temp\3947724.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Windows\Temp\9946843.exe varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Windows\update.1\svchost.exe Win32/Delf.QCZ trojský k??
C:\Windows\update.2\svchost.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Windows\update.5.0\svchost.exe varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Windows\update.tray-14-0\svchost.exe Win32/Delf.QCZ trojský k??
C:\Windows\update.tray-14-0-lnk\svchost.exe Win32/Delf.QCZ trojský k??
Logfile of random's system information tool 1.09 (written by random/random)
Run by miloň at 2011-07-25 10:34:44
Microsoft Windows 7 Home Premium
System drive C: has 544 GB (92%) free of 592 GB
Total RAM: 3894 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:48, on 25.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Windows\l1rezerv.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe
C:\Windows\update.tray-14-0-lnk\svchost.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Program Files\trend micro\miloň.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:65071
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-14-0\svchost.exe
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [52450885-loader2.exe] "C:\Users\miloň\AppData\Local\Temp\52450885-loader2.exe"
O4 - HKLM\..\Run: [7572230.exe] "C:\Users\MILO~1\AppData\Local\Temp\7572230.exe"
O4 - HKLM\..\Run: [1520133.exe] "C:\Users\MILO~1\AppData\Local\Temp\1520133.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EPSON SX125 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE /FU "C:\Windows\TEMP\E_S7AC5.tmp" /EF "HKCU"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243 (NisSrv) - Unknown owner - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Connect Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 12443 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" /silent
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"C:\Windows\l1rezerv.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
WLIDSvcM.exe 3032
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
Vodafone Mobile Broadband
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe"
"C:\Program Files\Realtek\RtVOsd\RtVOsd.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\update.tray-14-0-lnk\svchost.exe" tray 14-0 1
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe -Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8fb9f117-a5bb-490f-a1f3-58c1e9f27631 -SystemEventPortName:HostProcess-32672f70-5f7b-4e69-a6b7-846ac8b05512 -IoCancelEventPortName:HostProcess-21ae2ded-3e63-4647-9cb0-bcadc22f177a -NonStateChangingEventPortName:HostProcess-b821d418-93db-4b16-8996-adde5182c384 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:20099232-7c73-479d-b616-e51df9a9ad0a
C:\Windows\system32\sppsvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1639795865-839479953-694010524-100014_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1639795865-839479953-694010524-100014 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Users\miloň\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1639795865-839479953-694010524-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1639795865-839479953-694010524-1000UA.job
C:\Windows\tasks\HPCeeScheduleFormiloň.job
C:\Windows\tasks\PCConfidential.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-13 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-05-27 2096424]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"EPSON SX125 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE [2009-09-14 224768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe [2011-04-23 235168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\miloň\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-11 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryBooster]
C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe delay 20000 []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MobileBroadband"=C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2010-12-31 398848]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2009-12-03 976320]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-14-0\svchost.exe [2011-07-18 1170432]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-25 247296]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-25 247296]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-25 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-18 114176]
"52450885-loader2.exe"=C:\Users\miloň\AppData\Local\Temp\52450885-loader2.exe [2011-07-21 245760]
"7572230.exe"=C:\Users\MILO~1\AppData\Local\Temp\7572230.exe [2011-07-25 247296]
"1520133.exe"=C:\Users\MILO~1\AppData\Local\Temp\1520133.exe [2011-07-25 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-06-22 271360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2010-08-13 52920]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-25 10:34:44 ----D---- C:\rsit
2011-07-25 10:34:44 ----D---- C:\Program Files\trend micro
2011-07-25 09:21:54 ----D---- C:\Program Files (x86)\ESET
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\url.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\wininet.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\wextract.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\webcheck.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\vbscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\urlmon.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\url.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\occache.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msrating.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msls31.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshtml.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshta.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\jscript9.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\jscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\inseng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\imgutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iexpress.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iesetup.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iertutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iernonce.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iepeers.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieframe.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieapfltr.dat
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieakui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\icardie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\admparse.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\FntCache.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\DWrite.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-07-20 20:16:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-20 20:16:29 ----A---- C:\Windows\system32\d3d10warp.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\d2d1.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\cdd.dll
2011-07-20 18:51:47 ----D---- C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-07-18 17:22:14 ----A---- C:\Windows\EEventManager.INI
2011-07-18 16:42:42 ----D---- C:\Windows\ufa
2011-07-18 16:42:42 ----D---- C:\Windows\rpcminer
2011-07-18 16:42:42 ----D---- C:\Windows\phoenix
2011-07-18 16:42:38 ----A---- C:\Windows\unrar.exe
2011-07-18 16:41:04 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-18 16:40:58 ----A---- C:\Windows\ddh_iplist.txt
2011-07-18 16:40:51 ----A---- C:\Windows\systemup.exe
2011-07-18 16:40:51 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-18 16:40:50 ----A---- C:\Windows\l1rezerv.exe
2011-07-18 16:40:37 ----HD---- C:\Windows\update.2
2011-07-18 16:40:28 ----HD---- C:\Windows\update.5.0
2011-07-18 16:40:10 ----A---- C:\Windows\sysdriver32_.exe
2011-07-18 16:40:01 ----A---- C:\Windows\iplist.txt
2011-07-18 16:39:56 ----A---- C:\Windows\sysdriver32.exe
2011-07-18 16:39:45 ----D---- C:\Windows\av_ico
2011-07-18 16:39:30 ----A---- C:\Windows\front_ip_list.txt
2011-07-18 16:38:26 ----HD---- C:\Windows\update.1
2011-07-18 16:38:10 ----HD---- C:\Windows\update.tray-14-0-lnk
2011-07-18 16:38:10 ----HD---- C:\Windows\update.tray-14-0
2011-07-18 16:28:31 ----A---- C:\Windows\winlog-ids.txt
2011-07-18 16:28:31 ----A---- C:\Windows\winlog-dirs.txt
2011-07-16 19:51:21 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-16 19:51:21 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-16 19:51:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-16 19:51:20 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-16 17:09:40 ----D---- C:\Users\miloň\AppData\Roaming\Epson
2011-07-16 17:00:26 ----D---- C:\Program Files\Common Files\EPSON
2011-07-16 16:58:25 ----D---- C:\ProgramData\UDL
2011-07-16 16:56:58 ----D---- C:\Program Files\Epson Software
2011-07-16 16:56:48 ----D---- C:\Users\miloň\AppData\Roaming\InstallShield
2011-07-16 16:53:26 ----D---- C:\Program Files (x86)\Epson Software
2011-07-16 16:51:57 ----D---- C:\ProgramData\ABBYY
2011-07-16 16:51:57 ----D---- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2011-07-16 16:50:36 ----A---- C:\Windows\system32\E_GCINST.DLL
2011-07-16 16:50:26 ----A---- C:\Windows\system32\E_ILMGGE.DLL
2011-07-16 16:50:23 ----A---- C:\Windows\system32\E_IBCBGGE.DLL
2011-07-16 16:50:09 ----D---- C:\ProgramData\EPSON
2011-07-16 16:49:58 ----A---- C:\Windows\system32\esxw2ud.dll
2011-07-16 16:49:58 ----A---- C:\Windows\system32\esxcdev.dll
2011-07-16 16:49:58 ----A---- C:\Windows\system32\esdevapp.exe
2011-07-16 16:49:57 ----D---- C:\Program Files (x86)\epson
2011-07-15 10:52:25 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-15 10:52:25 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-15 10:52:24 ----A---- C:\Windows\system32\win32k.sys
2011-07-15 10:52:23 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-15 10:52:23 ----A---- C:\Windows\system32\kernel32.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\wow64win.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\wow64.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\winsrv.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\conhost.exe
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-15 10:52:21 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-15 10:52:21 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-15 10:52:17 ----A---- C:\Windows\SYSWOW64\user.exe
2011-07-08 14:38:41 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-08 14:38:41 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-08 14:38:41 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-08 14:23:11 ----D---- C:\Users\miloň\AppData\Roaming\Malwarebytes
2011-07-08 14:23:03 ----D---- C:\ProgramData\Malwarebytes
2011-07-08 14:23:00 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-07-08 14:17:15 ----D---- C:\Program Files (x86)\Microsoft Security Client
2011-07-08 14:16:41 ----D---- C:\Program Files\Microsoft Security Client
2011-07-08 14:16:27 ----D---- C:\Program Files\Defraggler
2011-07-08 14:16:16 ----A---- C:\Windows\system32\drivers\netio.sys
2011-07-08 14:15:54 ----D---- C:\Program Files\CCleaner
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-30 11:37:02 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-30 11:36:56 ----A---- C:\Windows\system32\mssrch.dll
2011-06-30 11:36:55 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-30 11:36:55 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-30 11:36:55 ----A---- C:\Windows\system32\tquery.dll
2011-06-30 11:36:55 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-30 11:36:55 ----A---- C:\Windows\system32\mssph.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-30 11:36:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\system32\mssvp.dll
2011-06-30 11:36:54 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-30 11:36:54 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-27 00:18:59 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-27 00:18:58 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-27 00:18:58 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-27 00:17:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-27 00:17:30 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-27 00:17:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-27 00:16:58 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-06-27 00:16:58 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-06-27 00:16:57 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-27 00:16:57 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-27 00:16:57 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-27 00:16:56 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-27 00:16:56 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-27 00:16:55 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-27 00:16:55 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-27 00:16:53 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-27 00:16:53 ----A---- C:\Windows\system32\inetcomm.dll
======List of files/folders modified in the last 1 month======
2011-07-25 10:34:45 ----D---- C:\Windows\Temp
2011-07-25 10:34:44 ----RD---- C:\Program Files
2011-07-25 10:28:50 ----D---- C:\Windows\System32
2011-07-25 10:28:50 ----D---- C:\Windows\inf
2011-07-25 10:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-25 09:26:47 ----D---- C:\Windows
2011-07-25 09:21:56 ----D---- C:\Windows\Downloaded Program Files
2011-07-25 09:21:54 ----RD---- C:\Program Files (x86)
2011-07-25 09:09:09 ----D---- C:\Windows\system32\config
2011-07-25 09:08:38 ----A---- C:\Windows\SYSWOW64\log.txt
2011-07-25 09:07:21 ----D---- C:\Windows\SYSWOW64\drivers
2011-07-25 09:00:13 ----SHD---- C:\System Volume Information
2011-07-25 09:00:06 ----D---- C:\Windows\SysWOW64
2011-07-25 08:59:59 ----D---- C:\Windows\system32\drivers
2011-07-25 08:59:55 ----D---- C:\Windows\system32\catroot
2011-07-25 08:59:52 ----D---- C:\Windows\system32\DriverStore
2011-07-25 08:52:48 ----D---- C:\Windows\system32\NDF
2011-07-22 15:44:47 ----D---- C:\Windows\debug
2011-07-22 15:42:34 ----SD---- C:\ProgramData\Microsoft
2011-07-22 15:42:28 ----SD---- C:\Users\miloň\AppData\Roaming\Microsoft
2011-07-22 03:32:13 ----D---- C:\Windows\system32\LogFiles
2011-07-21 20:38:35 ----D---- C:\Windows\system32\catroot2
2011-07-21 18:23:59 ----SHD---- C:\Windows\Installer
2011-07-21 18:23:59 ----D---- C:\Program Files (x86)\CyberLink
2011-07-21 18:19:12 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-21 18:19:07 ----D---- C:\ProgramData\CyberLink
2011-07-21 18:15:31 ----HD---- C:\ProgramData
2011-07-21 18:14:34 ----D---- C:\Program Files (x86)\Common Files
2011-07-21 17:43:56 ----D---- C:\Windows\system32\wbem
2011-07-21 16:08:35 ----D---- C:\Windows\TAPI
2011-07-21 16:08:34 ----D---- C:\Windows\SYSWOW64\wbem
2011-07-21 16:08:21 ----D---- C:\Windows\SYSWOW64\sppui
2011-07-21 16:08:20 ----D---- C:\Windows\SYSWOW64\Setup
2011-07-21 16:08:20 ----D---- C:\Windows\SYSWOW64\Recovery
2011-07-21 16:08:20 ----D---- C:\Windows\SYSWOW64\ras
2011-07-21 16:08:19 ----D---- C:\Windows\SYSWOW64\oobe
2011-07-21 16:08:17 ----D---- C:\Windows\SYSWOW64\migwiz
2011-07-21 16:08:06 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-07-21 16:08:01 ----D---- C:\Windows\SYSWOW64\InstallShield
2011-07-21 16:07:55 ----D---- C:\Windows\SYSWOW64\icsxml
2011-07-21 16:07:53 ----D---- C:\Windows\SYSWOW64\Dism
2011-07-21 16:07:50 ----D---- C:\Windows\SYSWOW64\com
2011-07-21 16:07:23 ----D---- C:\Windows\system32\sysprep
2011-07-21 16:07:23 ----D---- C:\Windows\system32\sppui
2011-07-21 16:07:18 ----D---- C:\Windows\system32\Setup
2011-07-21 16:07:18 ----D---- C:\Windows\system32\ras
2011-07-21 16:07:17 ----D---- C:\Windows\system32\oobe
2011-07-21 16:07:12 ----D---- C:\Windows\system32\migwiz
2011-07-21 16:07:04 ----D---- C:\Windows\system32\manifeststore
2011-07-21 16:06:59 ----D---- C:\Windows\system32\icsxml
2011-07-21 16:06:58 ----D---- C:\Windows\system32\ias
2011-07-21 15:58:21 ----D---- C:\Windows\system32\Dism
2011-07-21 15:58:20 ----D---- C:\Windows\system32\com
2011-07-21 15:58:20 ----D---- C:\Windows\system32\CodeIntegrity
2011-07-21 15:57:02 ----D---- C:\Windows\system32\AdvancedInstallers
2011-07-21 15:54:40 ----D---- C:\Windows\servicing
2011-07-21 15:54:39 ----D---- C:\Windows\Offline Web Pages
2011-07-21 15:53:17 ----RSD---- C:\Windows\Media
2011-07-21 15:53:14 ----D---- C:\Windows\L2Schemas
2011-07-21 15:50:18 ----D---- C:\Windows\diagnostics
2011-07-21 15:50:18 ----D---- C:\Windows\Cursors
2011-07-21 15:50:02 ----D---- C:\Windows\addins
2011-07-21 15:49:20 ----D---- C:\Program Files\Windows Mail
2011-07-21 15:49:10 ----D---- C:\Program Files\DVD Maker
2011-07-21 15:49:10 ----D---- C:\Program Files\Common Files\System
2011-07-21 15:49:08 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-07-21 15:48:50 ----D---- C:\Program Files (x86)\Windows Mail
2011-07-21 15:48:18 ----SHD---- C:\boot
2011-07-21 15:46:58 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-21 15:46:52 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-07-21 15:46:34 ----D---- C:\Program Files\Common Files
2011-07-21 15:46:27 ----D---- C:\Program Files\Internet Explorer
2011-07-21 15:46:19 ----D---- C:\Program Files\Windows Photo Viewer
2011-07-21 15:45:57 ----D---- C:\ProgramData\Hewlett-Packard
2011-07-21 15:45:57 ----D---- C:\ProgramData\FLEXnet
2011-07-21 15:45:02 ----RSD---- C:\Windows\assembly
2011-07-21 15:45:02 ----D---- C:\Windows\AppPatch
2011-07-21 15:45:02 ----D---- C:\Windows\AppCompat
2011-07-21 15:44:46 ----D---- C:\Windows\cs-CZ
2011-07-21 15:41:51 ----D---- C:\Windows\PolicyDefinitions
2011-07-21 15:40:59 ----D---- C:\Windows\system32\bg-BG
2011-07-21 15:40:59 ----D---- C:\Windows\system32\ar-SA
2011-07-21 15:40:30 ----D---- C:\Windows\system32\cs-CZ
2011-07-21 15:39:32 ----D---- C:\Windows\system32\de-DE
2011-07-21 15:39:32 ----D---- C:\Windows\system32\da-DK
2011-07-21 15:39:32 ----D---- C:\Windows\system32\cs
2011-07-21 15:39:30 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-07-21 15:39:26 ----D---- C:\Windows\system32\drivers\etc
2011-07-21 15:39:26 ----D---- C:\Windows\system32\drivers\en-US
2011-07-21 15:35:54 ----D---- C:\Windows\system32\en-US
2011-07-21 15:35:54 ----D---- C:\Windows\system32\el-GR
2011-07-21 15:35:49 ----D---- C:\Windows\system32\et-EE
2011-07-21 15:35:49 ----D---- C:\Windows\system32\es-ES
2011-07-21 15:35:48 ----D---- C:\Windows\system32\he-IL
2011-07-21 15:35:48 ----D---- C:\Windows\system32\fr-FR
2011-07-21 15:35:48 ----D---- C:\Windows\system32\fi-FI
2011-07-21 15:35:47 ----D---- C:\Windows\system32\hu-HU
2011-07-21 15:35:47 ----D---- C:\Windows\system32\hr-HR
2011-07-21 15:35:45 ----D---- C:\Windows\system32\it-IT
2011-07-21 15:35:44 ----D---- C:\Windows\system32\ko-KR
2011-07-21 15:35:44 ----D---- C:\Windows\system32\ja-JP
2011-07-21 15:35:43 ----D---- C:\Windows\system32\migration
2011-07-21 15:35:43 ----D---- C:\Windows\system32\lv-LV
2011-07-21 15:35:43 ----D---- C:\Windows\system32\lt-LT
2011-07-21 15:35:26 ----D---- C:\Windows\system32\nb-NO
2011-07-21 15:35:25 ----D---- C:\Windows\system32\nl-NL
2011-07-21 15:35:23 ----D---- C:\Windows\system32\pl-PL
2011-07-21 15:35:22 ----D---- C:\Windows\system32\pt-PT
2011-07-21 15:35:22 ----D---- C:\Windows\system32\pt-BR
2011-07-21 15:35:21 ----D---- C:\Windows\system32\sk-SK
2011-07-21 15:35:21 ----D---- C:\Windows\system32\ru-RU
2011-07-21 15:35:21 ----D---- C:\Windows\system32\ro-RO
2011-07-21 15:35:20 ----D---- C:\Windows\system32\sl-SI
2011-07-21 15:35:04 ----D---- C:\Windows\system32\sv-SE
2011-07-21 15:35:04 ----D---- C:\Windows\system32\sr-Latn-CS
2011-07-21 15:35:03 ----D---- C:\Windows\system32\Tasks
2011-07-21 15:35:01 ----D---- C:\Windows\system32\tr-TR
2011-07-21 15:35:01 ----D---- C:\Windows\system32\th-TH
2011-07-21 15:35:00 ----D---- C:\Windows\system32\uk-UA
2011-07-21 15:34:46 ----D---- C:\Windows\system32\WinBioPlugIns
2011-07-21 15:34:40 ----D---- C:\Windows\system32\zh-TW
2011-07-21 15:34:40 ----D---- C:\Windows\system32\zh-HK
2011-07-21 15:34:40 ----D---- C:\Windows\system32\zh-CN
2011-07-21 15:34:39 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-07-21 15:34:38 ----D---- C:\Windows\SYSWOW64\bg-BG
2011-07-21 15:34:38 ----D---- C:\Windows\SYSWOW64\ar-SA
2011-07-21 15:34:37 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-07-21 15:34:10 ----D---- C:\Windows\SYSWOW64\de-DE
2011-07-21 15:34:10 ----D---- C:\Windows\SYSWOW64\da-DK
2011-07-21 15:34:10 ----D---- C:\Windows\SYSWOW64\cs
2011-07-21 15:34:09 ----D---- C:\Windows\SYSWOW64\drivers\cs-CZ
2011-07-21 15:34:08 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-21 15:34:08 ----D---- C:\Windows\SYSWOW64\el-GR
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\he-IL
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\fr-FR
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\fi-FI
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\et-EE
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\es-ES
2011-07-21 15:34:04 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-07-21 15:34:04 ----D---- C:\Windows\SYSWOW64\hr-HR
2011-07-21 15:34:02 ----D---- C:\Windows\SYSWOW64\it-IT
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\lv-LV
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\lt-LT
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\ko-KR
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\ja-JP
2011-07-21 15:34:00 ----D---- C:\Windows\SYSWOW64\migration
2011-07-21 15:33:47 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-07-21 15:33:47 ----D---- C:\Windows\SYSWOW64\nl-NL
2011-07-21 15:33:47 ----D---- C:\Windows\SYSWOW64\nb-NO
2011-07-21 15:33:46 ----D---- C:\Windows\SYSWOW64\pt-PT
2011-07-21 15:33:46 ----D---- C:\Windows\SYSWOW64\pt-BR
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\sl-SI
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\ru-RU
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\uk-UA
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\tr-TR
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\th-TH
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\sv-SE
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS
2011-07-21 15:33:32 ----D---- C:\Windows\Tasks
2011-07-21 15:33:32 ----D---- C:\Windows\SYSWOW64\zh-TW
2011-07-21 15:33:32 ----D---- C:\Windows\SYSWOW64\zh-HK
2011-07-21 15:33:32 ----D---- C:\Windows\SYSWOW64\zh-CN
2011-07-21 15:33:31 ----D---- C:\Windows\twain_32
2011-07-21 15:33:03 ----D---- C:\Windows\winsxs
2011-07-21 15:17:46 ----D---- C:\Windows\registration
2011-07-20 21:39:50 ----D---- C:\Program Files (x86)\EasyBits For Kids
2011-07-20 21:10:19 ----D---- C:\Users\miloň\AppData\Roaming\_MDLogs
2011-07-20 20:18:38 ----D---- C:\Windows\Logs
2011-07-20 20:10:39 ----D---- C:\Windows\Prefetch
2011-07-20 20:06:28 ----D---- C:\Users\miloň\AppData\Roaming\SoftGrid Client
2011-07-20 18:58:37 ----D---- C:\Users\miloň\AppData\Roaming\Hewlett-Packard
2011-07-20 18:55:26 ----D---- C:\Windows\Help
2011-07-20 18:52:39 ----D---- C:\Program Files (x86)\Hewlett-Packard
2011-07-20 18:51:03 ----D---- C:\Users\miloň\AppData\Roaming\hpqLog
2011-07-20 18:50:49 ----D---- C:\SwSetup
2011-07-20 17:31:42 ----D---- C:\Windows\system32\wfp
2011-07-16 16:23:05 ----A---- C:\Windows\system32\MRT.exe
2011-07-08 14:38:35 ----D---- C:\Program Files (x86)\Java
2011-07-08 14:26:36 ----D---- C:\ProgramData\Norton
2011-07-08 14:19:27 ----D---- C:\Windows\pss
2011-07-08 14:17:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-07-02 12:22:57 ----D---- C:\Windows\Microsoft.NET
2011-07-01 12:45:00 ----RSD---- C:\Windows\Fonts
2011-06-27 04:23:34 ----D---- C:\Program Files (x86)\Microsoft Silverlight
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 BMLoad;Bytemobile Boot Time Load Driver; C:\Windows\system32\drivers\BMLoad.sys [2011-04-13 16512]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-04-13 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 188928]
R1 tcpipBM;Bytemobile Kernel Network Provider; \??\C:\Windows\system32\drivers\tcpipBM.sys [2011-04-13 39552]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 145920]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-06-22 6856704]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-06-22 264192]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
R3 BTMUSB;Motorola Bluetooth Radio Service; C:\Windows\System32\Drivers\btmusb.sys [2010-06-29 3232768]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-12-30 85504]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-03-13 2291616]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2010-06-22 10342240]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 40832]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2010-06-23 931168]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-05-27 320560]
R3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum; C:\Windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [2010-09-01 75776]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552448]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\Windows\System32\Drivers\btmcom.sys [2010-04-09 52736]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-12-30 117248]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\Windows\system32\DRIVERS\ewusbnet.sys [2010-12-31 419840]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-12-30 219008]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2009-07-23 113792]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-06-22 10342240]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 72064]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-09-23 225280]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-06-22 203264]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2011-02-23 125496]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 RtVOsdService;RtVOsdService Installer; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 VmbService;Vodafone Mobile Connect Service; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-09 1028096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-01-25 791608]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 12784]
S2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-25 340992]
S2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-25 495616]
S2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-25 247296]
S2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-18 1170432]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-11-09 647680]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-09-30 246520]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe []
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-16 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
C:\Users\milo?\AppData\Local\Temp\1520133.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Users\milo?\AppData\Local\Temp\52450885-loader2.exe Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Users\milo?\AppData\Local\Temp\7572230.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Users\milo?\Documents\Flash-Player.exe Win32/Delf.QCZ trojský k??
C:\Windows\l1rezerv.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Windows\sysdriver32.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Windows\sysdriver32_.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QCY trojský k??
C:\Windows\systemup.exe pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QQI trojský k??
C:\Windows\Temp\3507101.exe varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Windows\Temp\3947724.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Windows\Temp\9946843.exe varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Windows\update.1\svchost.exe Win32/Delf.QCZ trojský k??
C:\Windows\update.2\svchost.exe pravd?podobn? neznámý NewHeur_PE virus
C:\Windows\update.5.0\svchost.exe varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Windows\update.tray-14-0\svchost.exe Win32/Delf.QCZ trojský k??
C:\Windows\update.tray-14-0-lnk\svchost.exe Win32/Delf.QCZ trojský k??
Logfile of random's system information tool 1.09 (written by random/random)
Run by miloň at 2011-07-25 10:34:44
Microsoft Windows 7 Home Premium
System drive C: has 544 GB (92%) free of 592 GB
Total RAM: 3894 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:48, on 25.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
C:\Windows\l1rezerv.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe
C:\Windows\update.tray-14-0-lnk\svchost.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe
C:\Program Files\trend micro\miloň.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:65071
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-14-0\svchost.exe
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [52450885-loader2.exe] "C:\Users\miloň\AppData\Local\Temp\52450885-loader2.exe"
O4 - HKLM\..\Run: [7572230.exe] "C:\Users\MILO~1\AppData\Local\Temp\7572230.exe"
O4 - HKLM\..\Run: [1520133.exe] "C:\Users\MILO~1\AppData\Local\Temp\1520133.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [EPSON SX125 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE /FU "C:\Windows\TEMP\E_S7AC5.tmp" /EF "HKCU"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe -update activex
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Bluetooth Device Manager - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243 (NisSrv) - Unknown owner - c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Vodafone Mobile Connect Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 12443 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe" -service
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
C:\Windows\SysWOW64\ezSharedSvcHost.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" /silent
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
"C:\Windows\l1rezerv.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
"C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe"
WLIDSvcM.exe 3032
"C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE"
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
Vodafone Mobile Broadband
"C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe"
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe"
"C:\Program Files\Realtek\RtVOsd\RtVOsd.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\update.tray-14-0-lnk\svchost.exe" tray 14-0 1
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe -Embedding
"C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-8fb9f117-a5bb-490f-a1f3-58c1e9f27631 -SystemEventPortName:HostProcess-32672f70-5f7b-4e69-a6b7-846ac8b05512 -IoCancelEventPortName:HostProcess-21ae2ded-3e63-4647-9cb0-bcadc22f177a -NonStateChangingEventPortName:HostProcess-b821d418-93db-4b16-8996-adde5182c384 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:20099232-7c73-479d-b616-e51df9a9ad0a
C:\Windows\system32\sppsvc.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1639795865-839479953-694010524-100014_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1639795865-839479953-694010524-100014 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Users\miloň\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1639795865-839479953-694010524-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1639795865-839479953-694010524-1000UA.job
C:\Windows\tasks\HPCeeScheduleFormiloň.job
C:\Windows\tasks\PCConfidential.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-13 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2009-08-24 430592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-02-28 1089288]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-05-27 2096424]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1475072]
"EPSON SX125 Series"=C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE [2009-09-14 224768]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_ActiveX.exe [2011-04-23 235168]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Users\miloň\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-11 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryBooster]
C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe delay 20000 []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MobileBroadband"=C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [2010-12-31 398848]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"EEventManager"=C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [2009-12-03 976320]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-14-0\svchost.exe [2011-07-18 1170432]
"tray_ico1"= []
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-25 247296]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-25 247296]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-25 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-18 114176]
"52450885-loader2.exe"=C:\Users\miloň\AppData\Local\Temp\52450885-loader2.exe [2011-07-21 245760]
"7572230.exe"=C:\Users\MILO~1\AppData\Local\Temp\7572230.exe [2011-07-25 247296]
"1520133.exe"=C:\Users\MILO~1\AppData\Local\Temp\1520133.exe [2011-07-25 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-06-22 271360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2010-08-13 52920]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-25 10:34:44 ----D---- C:\rsit
2011-07-25 10:34:44 ----D---- C:\Program Files\trend micro
2011-07-25 09:21:54 ----D---- C:\Program Files (x86)\ESET
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\wextract.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\url.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\SetIEInstalledDate.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\RegisterIEPKEYs.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\pngfilt.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\occache.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msrating.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msls31.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshtmler.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\mshta.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\licmgr10.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\inseng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\imgutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iexpress.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iesysprep.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieapfltr.dat
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieakui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieaksie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ieakeng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\IEAdvpack.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\ie4uinit.exe
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\icardie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2011-07-20 20:17:33 ----A---- C:\Windows\SYSWOW64\admparse.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\wininet.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\wextract.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\webcheck.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\vbscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\urlmon.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\url.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\pngfilt.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\occache.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msrating.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msls31.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshtmler.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshtmled.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshtml.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\mshta.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msfeedssync.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\msfeeds.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\licmgr10.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\jsproxy.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\jscript9.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\jscript.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\inseng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\imgutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iexpress.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieUnatt.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iesysprep.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iesetup.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iertutil.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iernonce.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iepeers.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieframe.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\iedkcs32.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieapfltr.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieapfltr.dat
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieakui.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieaksie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ieakeng.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\IEAdvpack.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\ie4uinit.exe
2011-07-20 20:17:33 ----A---- C:\Windows\system32\icardie.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\dxtrans.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\dxtmsft.dll
2011-07-20 20:17:33 ----A---- C:\Windows\system32\admparse.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\XpsRasterService.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2011-07-20 20:16:29 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\XpsRasterService.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\FntCache.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\ExplorerFrame.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\DWrite.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2011-07-20 20:16:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2011-07-20 20:16:29 ----A---- C:\Windows\system32\d3d10warp.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\d2d1.dll
2011-07-20 20:16:29 ----A---- C:\Windows\system32\cdd.dll
2011-07-20 18:51:47 ----D---- C:\ProgramData\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-07-18 17:22:14 ----A---- C:\Windows\EEventManager.INI
2011-07-18 16:42:42 ----D---- C:\Windows\ufa
2011-07-18 16:42:42 ----D---- C:\Windows\rpcminer
2011-07-18 16:42:42 ----D---- C:\Windows\phoenix
2011-07-18 16:42:38 ----A---- C:\Windows\unrar.exe
2011-07-18 16:41:04 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-18 16:40:58 ----A---- C:\Windows\ddh_iplist.txt
2011-07-18 16:40:51 ----A---- C:\Windows\systemup.exe
2011-07-18 16:40:51 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-18 16:40:50 ----A---- C:\Windows\l1rezerv.exe
2011-07-18 16:40:37 ----HD---- C:\Windows\update.2
2011-07-18 16:40:28 ----HD---- C:\Windows\update.5.0
2011-07-18 16:40:10 ----A---- C:\Windows\sysdriver32_.exe
2011-07-18 16:40:01 ----A---- C:\Windows\iplist.txt
2011-07-18 16:39:56 ----A---- C:\Windows\sysdriver32.exe
2011-07-18 16:39:45 ----D---- C:\Windows\av_ico
2011-07-18 16:39:30 ----A---- C:\Windows\front_ip_list.txt
2011-07-18 16:38:26 ----HD---- C:\Windows\update.1
2011-07-18 16:38:10 ----HD---- C:\Windows\update.tray-14-0-lnk
2011-07-18 16:38:10 ----HD---- C:\Windows\update.tray-14-0
2011-07-18 16:28:31 ----A---- C:\Windows\winlog-ids.txt
2011-07-18 16:28:31 ----A---- C:\Windows\winlog-dirs.txt
2011-07-16 19:51:21 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-07-16 19:51:21 ----A---- C:\Windows\system32\KernelBase.dll
2011-07-16 19:51:20 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-16 19:51:20 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-16 19:51:19 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-07-16 19:51:18 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-07-16 17:09:40 ----D---- C:\Users\miloň\AppData\Roaming\Epson
2011-07-16 17:00:26 ----D---- C:\Program Files\Common Files\EPSON
2011-07-16 16:58:25 ----D---- C:\ProgramData\UDL
2011-07-16 16:56:58 ----D---- C:\Program Files\Epson Software
2011-07-16 16:56:48 ----D---- C:\Users\miloň\AppData\Roaming\InstallShield
2011-07-16 16:53:26 ----D---- C:\Program Files (x86)\Epson Software
2011-07-16 16:51:57 ----D---- C:\ProgramData\ABBYY
2011-07-16 16:51:57 ----D---- C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2011-07-16 16:50:36 ----A---- C:\Windows\system32\E_GCINST.DLL
2011-07-16 16:50:26 ----A---- C:\Windows\system32\E_ILMGGE.DLL
2011-07-16 16:50:23 ----A---- C:\Windows\system32\E_IBCBGGE.DLL
2011-07-16 16:50:09 ----D---- C:\ProgramData\EPSON
2011-07-16 16:49:58 ----A---- C:\Windows\system32\esxw2ud.dll
2011-07-16 16:49:58 ----A---- C:\Windows\system32\esxcdev.dll
2011-07-16 16:49:58 ----A---- C:\Windows\system32\esdevapp.exe
2011-07-16 16:49:57 ----D---- C:\Program Files (x86)\epson
2011-07-15 10:52:25 ----A---- C:\Windows\system32\drivers\BTHUSB.SYS
2011-07-15 10:52:25 ----A---- C:\Windows\system32\drivers\bthport.sys
2011-07-15 10:52:24 ----A---- C:\Windows\system32\win32k.sys
2011-07-15 10:52:23 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-07-15 10:52:23 ----A---- C:\Windows\system32\kernel32.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\wow64win.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\wow64.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\winsrv.dll
2011-07-15 10:52:22 ----A---- C:\Windows\system32\conhost.exe
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-07-15 10:52:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-07-15 10:52:21 ----A---- C:\Windows\system32\wow64cpu.dll
2011-07-15 10:52:21 ----A---- C:\Windows\system32\ntvdm64.dll
2011-07-15 10:52:17 ----A---- C:\Windows\SYSWOW64\user.exe
2011-07-08 14:38:41 ----A---- C:\Windows\SYSWOW64\javaws.exe
2011-07-08 14:38:41 ----A---- C:\Windows\SYSWOW64\javaw.exe
2011-07-08 14:38:41 ----A---- C:\Windows\SYSWOW64\java.exe
2011-07-08 14:23:11 ----D---- C:\Users\miloň\AppData\Roaming\Malwarebytes
2011-07-08 14:23:03 ----D---- C:\ProgramData\Malwarebytes
2011-07-08 14:23:00 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-07-08 14:17:15 ----D---- C:\Program Files (x86)\Microsoft Security Client
2011-07-08 14:16:41 ----D---- C:\Program Files\Microsoft Security Client
2011-07-08 14:16:27 ----D---- C:\Program Files\Defraggler
2011-07-08 14:16:16 ----A---- C:\Windows\system32\drivers\netio.sys
2011-07-08 14:15:54 ----D---- C:\Program Files\CCleaner
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\devobj.dll
2011-06-30 11:37:02 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2011-06-30 11:37:02 ----A---- C:\Windows\system32\umpnpmgr.dll
2011-06-30 11:36:56 ----A---- C:\Windows\system32\mssrch.dll
2011-06-30 11:36:55 ----A---- C:\Windows\SYSWOW64\tquery.dll
2011-06-30 11:36:55 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2011-06-30 11:36:55 ----A---- C:\Windows\system32\tquery.dll
2011-06-30 11:36:55 ----A---- C:\Windows\system32\SearchIndexer.exe
2011-06-30 11:36:55 ----A---- C:\Windows\system32\mssph.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\mssph.dll
2011-06-30 11:36:54 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2011-06-30 11:36:54 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\system32\SearchFilterHost.exe
2011-06-30 11:36:54 ----A---- C:\Windows\system32\mssvp.dll
2011-06-30 11:36:54 ----A---- C:\Windows\system32\mssphtb.dll
2011-06-30 11:36:54 ----A---- C:\Windows\system32\msscntrs.dll
2011-06-27 00:18:59 ----A---- C:\Windows\system32\drivers\dfsc.sys
2011-06-27 00:18:58 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-06-27 00:18:58 ----A---- C:\Windows\system32\drivers\afd.sys
2011-06-27 00:17:30 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2011-06-27 00:17:30 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-06-27 00:17:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2011-06-27 00:16:58 ----A---- C:\Windows\SYSWOW64\d3d10_1core.dll
2011-06-27 00:16:58 ----A---- C:\Windows\system32\d3d10_1core.dll
2011-06-27 00:16:57 ----A---- C:\Windows\SYSWOW64\d3d10_1.dll
2011-06-27 00:16:57 ----A---- C:\Windows\system32\drivers\srv2.sys
2011-06-27 00:16:57 ----A---- C:\Windows\system32\d3d10_1.dll
2011-06-27 00:16:56 ----A---- C:\Windows\system32\drivers\srvnet.sys
2011-06-27 00:16:56 ----A---- C:\Windows\system32\drivers\srv.sys
2011-06-27 00:16:55 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2011-06-27 00:16:55 ----A---- C:\Windows\system32\oleaut32.dll
2011-06-27 00:16:53 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2011-06-27 00:16:53 ----A---- C:\Windows\system32\inetcomm.dll
======List of files/folders modified in the last 1 month======
2011-07-25 10:34:45 ----D---- C:\Windows\Temp
2011-07-25 10:34:44 ----RD---- C:\Program Files
2011-07-25 10:28:50 ----D---- C:\Windows\System32
2011-07-25 10:28:50 ----D---- C:\Windows\inf
2011-07-25 10:28:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-25 09:26:47 ----D---- C:\Windows
2011-07-25 09:21:56 ----D---- C:\Windows\Downloaded Program Files
2011-07-25 09:21:54 ----RD---- C:\Program Files (x86)
2011-07-25 09:09:09 ----D---- C:\Windows\system32\config
2011-07-25 09:08:38 ----A---- C:\Windows\SYSWOW64\log.txt
2011-07-25 09:07:21 ----D---- C:\Windows\SYSWOW64\drivers
2011-07-25 09:00:13 ----SHD---- C:\System Volume Information
2011-07-25 09:00:06 ----D---- C:\Windows\SysWOW64
2011-07-25 08:59:59 ----D---- C:\Windows\system32\drivers
2011-07-25 08:59:55 ----D---- C:\Windows\system32\catroot
2011-07-25 08:59:52 ----D---- C:\Windows\system32\DriverStore
2011-07-25 08:52:48 ----D---- C:\Windows\system32\NDF
2011-07-22 15:44:47 ----D---- C:\Windows\debug
2011-07-22 15:42:34 ----SD---- C:\ProgramData\Microsoft
2011-07-22 15:42:28 ----SD---- C:\Users\miloň\AppData\Roaming\Microsoft
2011-07-22 03:32:13 ----D---- C:\Windows\system32\LogFiles
2011-07-21 20:38:35 ----D---- C:\Windows\system32\catroot2
2011-07-21 18:23:59 ----SHD---- C:\Windows\Installer
2011-07-21 18:23:59 ----D---- C:\Program Files (x86)\CyberLink
2011-07-21 18:19:12 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-07-21 18:19:07 ----D---- C:\ProgramData\CyberLink
2011-07-21 18:15:31 ----HD---- C:\ProgramData
2011-07-21 18:14:34 ----D---- C:\Program Files (x86)\Common Files
2011-07-21 17:43:56 ----D---- C:\Windows\system32\wbem
2011-07-21 16:08:35 ----D---- C:\Windows\TAPI
2011-07-21 16:08:34 ----D---- C:\Windows\SYSWOW64\wbem
2011-07-21 16:08:21 ----D---- C:\Windows\SYSWOW64\sppui
2011-07-21 16:08:20 ----D---- C:\Windows\SYSWOW64\Setup
2011-07-21 16:08:20 ----D---- C:\Windows\SYSWOW64\Recovery
2011-07-21 16:08:20 ----D---- C:\Windows\SYSWOW64\ras
2011-07-21 16:08:19 ----D---- C:\Windows\SYSWOW64\oobe
2011-07-21 16:08:17 ----D---- C:\Windows\SYSWOW64\migwiz
2011-07-21 16:08:06 ----D---- C:\Windows\SYSWOW64\manifeststore
2011-07-21 16:08:01 ----D---- C:\Windows\SYSWOW64\InstallShield
2011-07-21 16:07:55 ----D---- C:\Windows\SYSWOW64\icsxml
2011-07-21 16:07:53 ----D---- C:\Windows\SYSWOW64\Dism
2011-07-21 16:07:50 ----D---- C:\Windows\SYSWOW64\com
2011-07-21 16:07:23 ----D---- C:\Windows\system32\sysprep
2011-07-21 16:07:23 ----D---- C:\Windows\system32\sppui
2011-07-21 16:07:18 ----D---- C:\Windows\system32\Setup
2011-07-21 16:07:18 ----D---- C:\Windows\system32\ras
2011-07-21 16:07:17 ----D---- C:\Windows\system32\oobe
2011-07-21 16:07:12 ----D---- C:\Windows\system32\migwiz
2011-07-21 16:07:04 ----D---- C:\Windows\system32\manifeststore
2011-07-21 16:06:59 ----D---- C:\Windows\system32\icsxml
2011-07-21 16:06:58 ----D---- C:\Windows\system32\ias
2011-07-21 15:58:21 ----D---- C:\Windows\system32\Dism
2011-07-21 15:58:20 ----D---- C:\Windows\system32\com
2011-07-21 15:58:20 ----D---- C:\Windows\system32\CodeIntegrity
2011-07-21 15:57:02 ----D---- C:\Windows\system32\AdvancedInstallers
2011-07-21 15:54:40 ----D---- C:\Windows\servicing
2011-07-21 15:54:39 ----D---- C:\Windows\Offline Web Pages
2011-07-21 15:53:17 ----RSD---- C:\Windows\Media
2011-07-21 15:53:14 ----D---- C:\Windows\L2Schemas
2011-07-21 15:50:18 ----D---- C:\Windows\diagnostics
2011-07-21 15:50:18 ----D---- C:\Windows\Cursors
2011-07-21 15:50:02 ----D---- C:\Windows\addins
2011-07-21 15:49:20 ----D---- C:\Program Files\Windows Mail
2011-07-21 15:49:10 ----D---- C:\Program Files\DVD Maker
2011-07-21 15:49:10 ----D---- C:\Program Files\Common Files\System
2011-07-21 15:49:08 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-07-21 15:48:50 ----D---- C:\Program Files (x86)\Windows Mail
2011-07-21 15:48:18 ----SHD---- C:\boot
2011-07-21 15:46:58 ----D---- C:\Program Files (x86)\Internet Explorer
2011-07-21 15:46:52 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2011-07-21 15:46:34 ----D---- C:\Program Files\Common Files
2011-07-21 15:46:27 ----D---- C:\Program Files\Internet Explorer
2011-07-21 15:46:19 ----D---- C:\Program Files\Windows Photo Viewer
2011-07-21 15:45:57 ----D---- C:\ProgramData\Hewlett-Packard
2011-07-21 15:45:57 ----D---- C:\ProgramData\FLEXnet
2011-07-21 15:45:02 ----RSD---- C:\Windows\assembly
2011-07-21 15:45:02 ----D---- C:\Windows\AppPatch
2011-07-21 15:45:02 ----D---- C:\Windows\AppCompat
2011-07-21 15:44:46 ----D---- C:\Windows\cs-CZ
2011-07-21 15:41:51 ----D---- C:\Windows\PolicyDefinitions
2011-07-21 15:40:59 ----D---- C:\Windows\system32\bg-BG
2011-07-21 15:40:59 ----D---- C:\Windows\system32\ar-SA
2011-07-21 15:40:30 ----D---- C:\Windows\system32\cs-CZ
2011-07-21 15:39:32 ----D---- C:\Windows\system32\de-DE
2011-07-21 15:39:32 ----D---- C:\Windows\system32\da-DK
2011-07-21 15:39:32 ----D---- C:\Windows\system32\cs
2011-07-21 15:39:30 ----D---- C:\Windows\system32\drivers\cs-CZ
2011-07-21 15:39:26 ----D---- C:\Windows\system32\drivers\etc
2011-07-21 15:39:26 ----D---- C:\Windows\system32\drivers\en-US
2011-07-21 15:35:54 ----D---- C:\Windows\system32\en-US
2011-07-21 15:35:54 ----D---- C:\Windows\system32\el-GR
2011-07-21 15:35:49 ----D---- C:\Windows\system32\et-EE
2011-07-21 15:35:49 ----D---- C:\Windows\system32\es-ES
2011-07-21 15:35:48 ----D---- C:\Windows\system32\he-IL
2011-07-21 15:35:48 ----D---- C:\Windows\system32\fr-FR
2011-07-21 15:35:48 ----D---- C:\Windows\system32\fi-FI
2011-07-21 15:35:47 ----D---- C:\Windows\system32\hu-HU
2011-07-21 15:35:47 ----D---- C:\Windows\system32\hr-HR
2011-07-21 15:35:45 ----D---- C:\Windows\system32\it-IT
2011-07-21 15:35:44 ----D---- C:\Windows\system32\ko-KR
2011-07-21 15:35:44 ----D---- C:\Windows\system32\ja-JP
2011-07-21 15:35:43 ----D---- C:\Windows\system32\migration
2011-07-21 15:35:43 ----D---- C:\Windows\system32\lv-LV
2011-07-21 15:35:43 ----D---- C:\Windows\system32\lt-LT
2011-07-21 15:35:26 ----D---- C:\Windows\system32\nb-NO
2011-07-21 15:35:25 ----D---- C:\Windows\system32\nl-NL
2011-07-21 15:35:23 ----D---- C:\Windows\system32\pl-PL
2011-07-21 15:35:22 ----D---- C:\Windows\system32\pt-PT
2011-07-21 15:35:22 ----D---- C:\Windows\system32\pt-BR
2011-07-21 15:35:21 ----D---- C:\Windows\system32\sk-SK
2011-07-21 15:35:21 ----D---- C:\Windows\system32\ru-RU
2011-07-21 15:35:21 ----D---- C:\Windows\system32\ro-RO
2011-07-21 15:35:20 ----D---- C:\Windows\system32\sl-SI
2011-07-21 15:35:04 ----D---- C:\Windows\system32\sv-SE
2011-07-21 15:35:04 ----D---- C:\Windows\system32\sr-Latn-CS
2011-07-21 15:35:03 ----D---- C:\Windows\system32\Tasks
2011-07-21 15:35:01 ----D---- C:\Windows\system32\tr-TR
2011-07-21 15:35:01 ----D---- C:\Windows\system32\th-TH
2011-07-21 15:35:00 ----D---- C:\Windows\system32\uk-UA
2011-07-21 15:34:46 ----D---- C:\Windows\system32\WinBioPlugIns
2011-07-21 15:34:40 ----D---- C:\Windows\system32\zh-TW
2011-07-21 15:34:40 ----D---- C:\Windows\system32\zh-HK
2011-07-21 15:34:40 ----D---- C:\Windows\system32\zh-CN
2011-07-21 15:34:39 ----D---- C:\Windows\SYSWOW64\AdvancedInstallers
2011-07-21 15:34:38 ----D---- C:\Windows\SYSWOW64\bg-BG
2011-07-21 15:34:38 ----D---- C:\Windows\SYSWOW64\ar-SA
2011-07-21 15:34:37 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-07-21 15:34:10 ----D---- C:\Windows\SYSWOW64\de-DE
2011-07-21 15:34:10 ----D---- C:\Windows\SYSWOW64\da-DK
2011-07-21 15:34:10 ----D---- C:\Windows\SYSWOW64\cs
2011-07-21 15:34:09 ----D---- C:\Windows\SYSWOW64\drivers\cs-CZ
2011-07-21 15:34:08 ----D---- C:\Windows\SYSWOW64\en-US
2011-07-21 15:34:08 ----D---- C:\Windows\SYSWOW64\el-GR
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\he-IL
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\fr-FR
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\fi-FI
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\et-EE
2011-07-21 15:34:05 ----D---- C:\Windows\SYSWOW64\es-ES
2011-07-21 15:34:04 ----D---- C:\Windows\SYSWOW64\hu-HU
2011-07-21 15:34:04 ----D---- C:\Windows\SYSWOW64\hr-HR
2011-07-21 15:34:02 ----D---- C:\Windows\SYSWOW64\it-IT
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\lv-LV
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\lt-LT
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\ko-KR
2011-07-21 15:34:01 ----D---- C:\Windows\SYSWOW64\ja-JP
2011-07-21 15:34:00 ----D---- C:\Windows\SYSWOW64\migration
2011-07-21 15:33:47 ----D---- C:\Windows\SYSWOW64\pl-PL
2011-07-21 15:33:47 ----D---- C:\Windows\SYSWOW64\nl-NL
2011-07-21 15:33:47 ----D---- C:\Windows\SYSWOW64\nb-NO
2011-07-21 15:33:46 ----D---- C:\Windows\SYSWOW64\pt-PT
2011-07-21 15:33:46 ----D---- C:\Windows\SYSWOW64\pt-BR
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\sl-SI
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\sk-SK
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\ru-RU
2011-07-21 15:33:45 ----D---- C:\Windows\SYSWOW64\ro-RO
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\uk-UA
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\tr-TR
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\th-TH
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\sv-SE
2011-07-21 15:33:43 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS
2011-07-21 15:33:32 ----D---- C:\Windows\Tasks
2011-07-21 15:33:32 ----D---- C:\Windows\SYSWOW64\zh-TW
2011-07-21 15:33:32 ----D---- C:\Windows\SYSWOW64\zh-HK
2011-07-21 15:33:32 ----D---- C:\Windows\SYSWOW64\zh-CN
2011-07-21 15:33:31 ----D---- C:\Windows\twain_32
2011-07-21 15:33:03 ----D---- C:\Windows\winsxs
2011-07-21 15:17:46 ----D---- C:\Windows\registration
2011-07-20 21:39:50 ----D---- C:\Program Files (x86)\EasyBits For Kids
2011-07-20 21:10:19 ----D---- C:\Users\miloň\AppData\Roaming\_MDLogs
2011-07-20 20:18:38 ----D---- C:\Windows\Logs
2011-07-20 20:10:39 ----D---- C:\Windows\Prefetch
2011-07-20 20:06:28 ----D---- C:\Users\miloň\AppData\Roaming\SoftGrid Client
2011-07-20 18:58:37 ----D---- C:\Users\miloň\AppData\Roaming\Hewlett-Packard
2011-07-20 18:55:26 ----D---- C:\Windows\Help
2011-07-20 18:52:39 ----D---- C:\Program Files (x86)\Hewlett-Packard
2011-07-20 18:51:03 ----D---- C:\Users\miloň\AppData\Roaming\hpqLog
2011-07-20 18:50:49 ----D---- C:\SwSetup
2011-07-20 17:31:42 ----D---- C:\Windows\system32\wfp
2011-07-16 16:23:05 ----A---- C:\Windows\system32\MRT.exe
2011-07-08 14:38:35 ----D---- C:\Program Files (x86)\Java
2011-07-08 14:26:36 ----D---- C:\ProgramData\Norton
2011-07-08 14:19:27 ----D---- C:\Windows\pss
2011-07-08 14:17:23 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-07-02 12:22:57 ----D---- C:\Windows\Microsoft.NET
2011-07-01 12:45:00 ----RSD---- C:\Windows\Fonts
2011-06-27 04:23:34 ----D---- C:\Program Files (x86)\Microsoft Silverlight
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 BMLoad;Bytemobile Boot Time Load Driver; C:\Windows\system32\drivers\BMLoad.sys [2011-04-13 16512]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-04-13 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-10-24 188928]
R1 tcpipBM;Bytemobile Kernel Network Provider; \??\C:\Windows\system32\drivers\tcpipBM.sys [2011-04-13 39552]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-07-14 145920]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2010-06-22 6856704]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2010-06-22 264192]
R3 AtiHdmiService;ATI Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\AtiHdmi.sys [2010-05-06 125456]
R3 BTMUSB;Motorola Bluetooth Radio Service; C:\Windows\System32\Drivers\btmusb.sys [2010-06-29 3232768]
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2010-12-30 85504]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-03-13 2291616]
R3 intelkmd;intelkmd; C:\Windows\system32\DRIVERS\igdpmd64.sys [2010-06-22 10342240]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 40832]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2010-06-23 931168]
R3 Sftfs;Sftfs; C:\Windows\system32\DRIVERS\Sftfslh.sys [2009-12-02 721768]
R3 Sftplay;Sftplay; C:\Windows\system32\DRIVERS\Sftplaylh.sys [2009-12-02 269672]
R3 Sftredir;Sftredir; C:\Windows\system32\DRIVERS\Sftredirlh.sys [2009-12-02 25960]
R3 Sftvol;Sftvol; C:\Windows\system32\DRIVERS\Sftvollh.sys [2009-12-02 22376]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-05-27 320560]
R3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum; C:\Windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [2010-09-01 75776]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 552448]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 BTMCOM;Bluetooth Serial Port; C:\Windows\System32\Drivers\btmcom.sys [2010-04-09 52736]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-12-30 117248]
S3 ewusbnet;HUAWEI USB-NDIS miniport; C:\Windows\system32\DRIVERS\ewusbnet.sys [2010-12-31 419840]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2010-12-30 219008]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2009-07-23 113792]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-06-22 10342240]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 72064]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-09-23 225280]
S3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-06-23 344680]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2010-06-22 203264]
R2 Bluetooth OBEX Service;Bluetooth OBEX Service; C:\Program Files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
R2 cvhsvc;Client Virtualization Handler; C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Health Check Service;HP Health Check Service; C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2011-02-23 125496]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service; C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2010-05-19 73728]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 RtVOsdService;RtVOsdService Installer; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R2 SeaPort;SeaPort; C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-02-25 249648]
R2 sftlist;Application Virtualization Client; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 VmbService;Vodafone Mobile Connect Service; C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 Bluetooth Device Manager;Bluetooth Device Manager; C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-09 1028096]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe [2011-01-25 791608]
R3 sftvsa;Application Virtualization Service Agent; C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 12784]
S2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-25 340992]
S2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-25 495616]
S2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-25 247296]
S2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-18 1170432]
S3 BBSvc;Bing Bar Update Service; C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
S3 Bluetooth Media Service;Bluetooth Media Service; C:\Program Files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-11-09 647680]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe [2010-09-30 246520]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe []
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2011-01-16 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
-----------------EOF-----------------
Re: trojan Delf
Zdravim a pekny den preji
Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com
Aplikujte RogueKiller
Jeste znovu RogueKiller ale nyni s moznosti 3 a pote jeste jednou s moznosti 4
RKill i RogueKiller by mely udelat logy, vlozte mi je sem
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Pokud ho havet blokuje, pouzijte jeden z nasledujicich
motji napsal: Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr
Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne temer okamzite a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Ted nerestartujte PC - prisli byste o ucinek RKillu
stell napsal: pouzijes RogueKiller>.spustis>>stlac 2> [enter] log vloz sem
http://www.viry.cz/forum/viewtopic.php? ... 05#p981205
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: trojan Delf
tady jsou logy:
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 25.07.2011 at 12:23:58.
Operating System: Windows 7 Home Premium
Processes terminated by Rkill or while it was running:
C:\Windows\SysWOW64\grpconv.exe
Rkill completed on 25.07.2011 at 12:24:10.
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: miloň [Admin rights]
Mode: Remove -- Date : 07/25/2011 12:24:49
Bad processes: 4
[SVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED
[SUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED
[SUSP PATH] l1rezerv.exe -- c:\windows\l1rezerv.exe -> KILLED
[SUSP PATH] systemup.exe -- c:\windows\systemup.exe -> KILLED
Registry Entries: 3
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (http=127.0.0.1:65071) -> NOT REMOVED, USE PROXYFIX
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: miloň [Admin rights]
Mode: HOSTSFix -- Date : 07/25/2011 12:25:13
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: miloň [Admin rights]
Mode: ProxyFix -- Date : 07/25/2011 12:25:25
Bad processes: 0
Registry Entries: 1
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (http=127.0.0.1:65071) -> DELETED
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 25.07.2011 at 12:23:58.
Operating System: Windows 7 Home Premium
Processes terminated by Rkill or while it was running:
C:\Windows\SysWOW64\grpconv.exe
Rkill completed on 25.07.2011 at 12:24:10.
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: miloň [Admin rights]
Mode: Remove -- Date : 07/25/2011 12:24:49
Bad processes: 4
[SVCHOST] svchost.exe -- c:\windows\update.5.0\svchost.exe -> KILLED
[SUSP PATH] sysdriver32.exe -- c:\windows\sysdriver32.exe -> KILLED
[SUSP PATH] l1rezerv.exe -- c:\windows\l1rezerv.exe -> KILLED
[SUSP PATH] systemup.exe -- c:\windows\systemup.exe -> KILLED
Registry Entries: 3
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (http=127.0.0.1:65071) -> NOT REMOVED, USE PROXYFIX
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: miloň [Admin rights]
Mode: HOSTSFix -- Date : 07/25/2011 12:25:13
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: miloň [Admin rights]
Mode: ProxyFix -- Date : 07/25/2011 12:25:25
Bad processes: 0
Registry Entries: 1
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (http=127.0.0.1:65071) -> DELETED
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Re: trojan Delf
log z combofixu:
ComboFix 11-07-25.02 - miloň 25.07.2011 13:23:00.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3894.2528 [GMT 2:00]
Spuštěný z: c:\combofix\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-25 do 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- C:\rsit
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- c:\program files\trend micro
2011-07-25 07:21 . 2011-07-25 07:21 -------- d-----w- c:\program files (x86)\ESET
2011-07-25 06:59 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D9B2696-5165-48AE-A506-80D4FB69C77A}\mpengine.dll
2011-07-25 06:58 . 2011-07-13 04:53 8578896 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-25 06:51 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{49714986-E745-44AC-9B47-4C597BA0D62F}\mpengine.dll
2011-07-20 18:16 . 2011-07-20 18:16 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-20 16:51 . 2011-07-21 13:45 -------- d-----w- c:\programdata\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-07-19 20:58 . 2011-07-19 20:58 -------- d-----w- c:\users\Guest\AppData\Roaming\Epson
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\phoenix
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\rpcminer
2011-07-18 14:42 . 2011-07-21 13:33 -------- d-----w- c:\windows\ufa
2011-07-18 14:42 . 2011-07-18 14:42 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:39 . 2011-07-20 15:31 -------- d-----w- c:\windows\av_ico
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-16 15:09 . 2011-07-16 15:09 -------- d-----w- c:\users\miloň\AppData\Roaming\Epson
2011-07-16 14:49 . 2009-11-19 22:00 464384 ----a-w- c:\windows\system32\esxw2ud.dll
2011-07-16 14:49 . 2009-04-30 22:00 17408 ----a-w- c:\windows\system32\esxcdev.dll
2011-07-16 14:49 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
2011-07-16 14:49 . 2011-07-16 14:53 -------- d-----w- c:\program files (x86)\epson
2011-07-09 20:12 . 2011-06-07 08:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-08 13:21 . 2011-07-08 13:21 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\users\miloň\AppData\Roaming\Malwarebytes
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\programdata\Malwarebytes
2011-07-08 12:23 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-08 12:20 . 2011-07-08 12:20 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD08A8C-8142-44BF-AF83-BE3E8E71A907}\gapaengine.dll
2011-07-08 12:17 . 2011-07-08 12:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-07-08 12:16 . 2011-07-18 14:38 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-08 12:16 . 2011-07-08 12:16 -------- d-----w- c:\program files\Defraggler
2011-07-08 12:16 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
2011-07-08 12:15 . 2011-07-08 12:15 -------- d-----w- c:\program files\CCleaner
2011-06-30 09:37 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-30 09:37 . 2011-05-24 10:34 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-06-30 09:37 . 2011-05-24 10:34 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-06-30 09:37 . 2011-05-24 10:34 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-06-30 09:37 . 2011-05-24 10:32 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-06-26 22:18 . 2011-04-27 02:57 102400 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-26 22:18 . 2011-04-25 05:32 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-26 22:18 . 2011-04-25 02:44 499712 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-26 22:17 . 2011-05-04 02:51 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-26 22:17 . 2011-05-04 02:51 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-26 22:17 . 2011-05-04 02:51 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-26 22:16 . 2010-11-02 05:12 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-06-26 22:16 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-06-26 22:16 . 2011-04-29 03:12 399872 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-26 22:16 . 2011-01-17 06:17 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-06-26 22:16 . 2011-01-17 05:38 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-06-26 22:16 . 2011-04-29 03:13 461312 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-26 22:16 . 2011-04-29 03:12 161792 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-26 22:16 . 2010-12-18 06:13 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-26 22:16 . 2010-12-18 05:31 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-26 22:16 . 2011-05-03 05:21 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-26 22:16 . 2011-05-03 04:50 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-26 20:54 . 2011-07-19 21:40 -------- d-----w- c:\users\Guest\AppData\Local\CrashDumps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-25 11:30 . 2011-07-25 11:30 247296 ----a-w- c:\windows\sysdriver32_.exe
2011-07-25 11:30 . 2011-07-25 11:30 247296 ----a-w- c:\windows\sysdriver32.exe
2011-06-02 05:56 . 2011-07-15 08:52 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-01-10 11:57 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-08-13 15:55 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-12-31 398848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"tray_ico0"="c:\windows\update.tray-14-0\svchost.exe" [2011-07-18 1170432]
"sysdriver32.exe"="c:\windows\sysdriver32.exe" [2011-07-25 247296]
"sysdriver32_.exe"="c:\windows\sysdriver32_.exe" [2011-07-25 247296]
"8639813.exe"="c:\users\MILO~1\AppData\Local\Temp\8639813.exe" [2011-07-25 247296]
"4150067.exe"="c:\windows\TEMP\4150067.exe" [2011-07-25 247296]
"5691376.exe"="c:\windows\TEMP\5691376.exe" [2011-07-25 495616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 srviecheck;srviecheck;c:\windows\update.2\svchost.exe [2011-07-25 495616]
S2 srvsysdriver32;srvsysdriver32;c:\windows\sysdriver32.exe [2011-07-25 247296]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 VmbService;Vodafone Mobile Connect Service;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
S3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [x]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-09 1028096]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 09:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-21 c:\windows\Tasks\HPCeeScheduleFormiloň.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 01:53]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF5364.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico1 - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Wow6432Node-HKLM-Run-l1rezerv.exe - c:\windows\l1rezerv.exe
Wow6432Node-HKLM-Run-systemup - c:\windows\systemup.exe
SafeBoot-wxpdrivers
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\windows\TEMP\7192147.exe
.
**************************************************************************
.
Celkový čas: 2011-07-25 13:33:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-25 11:33
.
Před spuštěním: Volných bajtů: 570 518 163 456
Po spuštění: Volných bajtů: 569 969 446 912
.
- - End Of File - - A845644A704C97CCC243AED53952DC95
ComboFix 11-07-25.02 - miloň 25.07.2011 13:23:00.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3894.2528 [GMT 2:00]
Spuštěný z: c:\combofix\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\btc_client_iplist.txt
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\phoenix.rar
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-25 do 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- C:\rsit
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- c:\program files\trend micro
2011-07-25 07:21 . 2011-07-25 07:21 -------- d-----w- c:\program files (x86)\ESET
2011-07-25 06:59 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D9B2696-5165-48AE-A506-80D4FB69C77A}\mpengine.dll
2011-07-25 06:58 . 2011-07-13 04:53 8578896 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-25 06:51 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{49714986-E745-44AC-9B47-4C597BA0D62F}\mpengine.dll
2011-07-20 18:16 . 2011-07-20 18:16 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-20 16:51 . 2011-07-21 13:45 -------- d-----w- c:\programdata\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-07-19 20:58 . 2011-07-19 20:58 -------- d-----w- c:\users\Guest\AppData\Roaming\Epson
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\phoenix
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\rpcminer
2011-07-18 14:42 . 2011-07-21 13:33 -------- d-----w- c:\windows\ufa
2011-07-18 14:42 . 2011-07-18 14:42 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:39 . 2011-07-20 15:31 -------- d-----w- c:\windows\av_ico
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-16 15:09 . 2011-07-16 15:09 -------- d-----w- c:\users\miloň\AppData\Roaming\Epson
2011-07-16 14:49 . 2009-11-19 22:00 464384 ----a-w- c:\windows\system32\esxw2ud.dll
2011-07-16 14:49 . 2009-04-30 22:00 17408 ----a-w- c:\windows\system32\esxcdev.dll
2011-07-16 14:49 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
2011-07-16 14:49 . 2011-07-16 14:53 -------- d-----w- c:\program files (x86)\epson
2011-07-09 20:12 . 2011-06-07 08:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-08 13:21 . 2011-07-08 13:21 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\users\miloň\AppData\Roaming\Malwarebytes
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\programdata\Malwarebytes
2011-07-08 12:23 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-08 12:20 . 2011-07-08 12:20 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD08A8C-8142-44BF-AF83-BE3E8E71A907}\gapaengine.dll
2011-07-08 12:17 . 2011-07-08 12:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-07-08 12:16 . 2011-07-18 14:38 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-08 12:16 . 2011-07-08 12:16 -------- d-----w- c:\program files\Defraggler
2011-07-08 12:16 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
2011-07-08 12:15 . 2011-07-08 12:15 -------- d-----w- c:\program files\CCleaner
2011-06-30 09:37 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-30 09:37 . 2011-05-24 10:34 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-06-30 09:37 . 2011-05-24 10:34 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-06-30 09:37 . 2011-05-24 10:34 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-06-30 09:37 . 2011-05-24 10:32 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-06-26 22:18 . 2011-04-27 02:57 102400 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-26 22:18 . 2011-04-25 05:32 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-26 22:18 . 2011-04-25 02:44 499712 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-26 22:17 . 2011-05-04 02:51 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-26 22:17 . 2011-05-04 02:51 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-26 22:17 . 2011-05-04 02:51 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-26 22:16 . 2010-11-02 05:12 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-06-26 22:16 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-06-26 22:16 . 2011-04-29 03:12 399872 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-26 22:16 . 2011-01-17 06:17 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-06-26 22:16 . 2011-01-17 05:38 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-06-26 22:16 . 2011-04-29 03:13 461312 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-26 22:16 . 2011-04-29 03:12 161792 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-26 22:16 . 2010-12-18 06:13 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-26 22:16 . 2010-12-18 05:31 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-26 22:16 . 2011-05-03 05:21 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-26 22:16 . 2011-05-03 04:50 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-26 20:54 . 2011-07-19 21:40 -------- d-----w- c:\users\Guest\AppData\Local\CrashDumps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-25 11:30 . 2011-07-25 11:30 247296 ----a-w- c:\windows\sysdriver32_.exe
2011-07-25 11:30 . 2011-07-25 11:30 247296 ----a-w- c:\windows\sysdriver32.exe
2011-06-02 05:56 . 2011-07-15 08:52 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-01-10 11:57 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-08-13 15:55 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-12-31 398848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"tray_ico0"="c:\windows\update.tray-14-0\svchost.exe" [2011-07-18 1170432]
"sysdriver32.exe"="c:\windows\sysdriver32.exe" [2011-07-25 247296]
"sysdriver32_.exe"="c:\windows\sysdriver32_.exe" [2011-07-25 247296]
"8639813.exe"="c:\users\MILO~1\AppData\Local\Temp\8639813.exe" [2011-07-25 247296]
"4150067.exe"="c:\windows\TEMP\4150067.exe" [2011-07-25 247296]
"5691376.exe"="c:\windows\TEMP\5691376.exe" [2011-07-25 495616]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 srviecheck;srviecheck;c:\windows\update.2\svchost.exe [2011-07-25 495616]
S2 srvsysdriver32;srvsysdriver32;c:\windows\sysdriver32.exe [2011-07-25 247296]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 VmbService;Vodafone Mobile Connect Service;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
S3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [x]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-09 1028096]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 09:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-21 c:\windows\Tasks\HPCeeScheduleFormiloň.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 01:53]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF5364.cfxxe" [X]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
TCP: DhcpNameServer = 194.228.41.65 194.228.41.113
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-tray_ico - (no file)
Wow6432Node-HKLM-Run-tray_ico1 - (no file)
Wow6432Node-HKLM-Run-tray_ico2 - (no file)
Wow6432Node-HKLM-Run-tray_ico3 - (no file)
Wow6432Node-HKLM-Run-tray_ico4 - (no file)
Wow6432Node-HKLM-Run-l1rezerv.exe - c:\windows\l1rezerv.exe
Wow6432Node-HKLM-Run-systemup - c:\windows\systemup.exe
SafeBoot-wxpdrivers
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{E92D47A1-D27D-430A-8368-0BAFD956507D} - c:\program files (x86)\InstallShield Installation Information\{E92D47A1-D27D-430A-8368-0BAFD956507D}\setup.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\windows\TEMP\7192147.exe
.
**************************************************************************
.
Celkový čas: 2011-07-25 13:33:50 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-25 11:33
.
Před spuštěním: Volných bajtů: 570 518 163 456
Po spuštění: Volných bajtů: 569 969 446 912
.
- - End Of File - - A845644A704C97CCC243AED53952DC95
Re: trojan Delf
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Folder:: c:\windows\phoenix c:\windows\rpcminer c:\windows\ufa c:\windows\av_ico c:\windows\update.tray-14-0 c:\windows\update.tray-14-0-lnk c:\users\MILO~1\AppData\Local\Temp c:\windows\TEMP File:: c:\windows\unrar.exe c:\windows\sysdriver32_.exe c:\windows\sysdriver32.exe Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- "tray_ico0"=- "sysdriver32.exe"=- "sysdriver32_.exe"=- "8639813.exe"=- "4150067.exe"=- "5691376.exe"=- [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000000 "DisableThumbnailCache"=dword:00000000 "FirewallDisableNotify"=dword:00000000 "UpdatesDisableNotify"=dword:00000000 "AntiVirusDisableNotify"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "combofix"=- RegLock:: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: trojan Delf
tady je log:
ComboFix 11-07-25.02 - miloň 25.07.2011 17:04:15.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3894.2401 [GMT 2:00]
Spuštěný z: c:\combofix\ComboFix.exe
Použité ovládací přepínače :: c:\users\milo˛\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\proc_list1.log
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\TEMP\8291973.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srvsysdriver32
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-25 do 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- C:\rsit
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- c:\program files\trend micro
2011-07-25 07:21 . 2011-07-25 07:21 -------- d-----w- c:\program files (x86)\ESET
2011-07-25 06:59 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D9B2696-5165-48AE-A506-80D4FB69C77A}\mpengine.dll
2011-07-25 06:58 . 2011-07-13 04:53 8578896 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-25 06:51 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{49714986-E745-44AC-9B47-4C597BA0D62F}\mpengine.dll
2011-07-20 18:16 . 2011-07-20 18:16 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-20 16:51 . 2011-07-21 13:45 -------- d-----w- c:\programdata\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-07-19 20:58 . 2011-07-19 20:58 -------- d-----w- c:\users\Guest\AppData\Roaming\Epson
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\phoenix
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\rpcminer
2011-07-18 14:42 . 2011-07-21 13:33 -------- d-----w- c:\windows\ufa
2011-07-18 14:42 . 2011-07-18 14:42 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:39 . 2011-07-20 15:31 -------- d-----w- c:\windows\av_ico
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-16 15:09 . 2011-07-16 15:09 -------- d-----w- c:\users\miloň\AppData\Roaming\Epson
2011-07-16 14:49 . 2009-11-19 22:00 464384 ----a-w- c:\windows\system32\esxw2ud.dll
2011-07-16 14:49 . 2009-04-30 22:00 17408 ----a-w- c:\windows\system32\esxcdev.dll
2011-07-16 14:49 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
2011-07-16 14:49 . 2011-07-16 14:53 -------- d-----w- c:\program files (x86)\epson
2011-07-09 20:12 . 2011-06-07 08:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-08 13:21 . 2011-07-08 13:21 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\users\miloň\AppData\Roaming\Malwarebytes
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\programdata\Malwarebytes
2011-07-08 12:23 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-08 12:20 . 2011-07-08 12:20 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD08A8C-8142-44BF-AF83-BE3E8E71A907}\gapaengine.dll
2011-07-08 12:17 . 2011-07-08 12:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-07-08 12:16 . 2011-07-18 14:38 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-08 12:16 . 2011-07-08 12:16 -------- d-----w- c:\program files\Defraggler
2011-07-08 12:16 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
2011-07-08 12:15 . 2011-07-08 12:15 -------- d-----w- c:\program files\CCleaner
2011-06-30 09:37 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-30 09:37 . 2011-05-24 10:34 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-06-30 09:37 . 2011-05-24 10:34 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-06-30 09:37 . 2011-05-24 10:34 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-06-30 09:37 . 2011-05-24 10:32 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-06-26 22:18 . 2011-04-27 02:57 102400 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-26 22:18 . 2011-04-25 05:32 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-26 22:18 . 2011-04-25 02:44 499712 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-26 22:17 . 2011-05-04 02:51 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-26 22:17 . 2011-05-04 02:51 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-26 22:17 . 2011-05-04 02:51 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-26 22:16 . 2010-11-02 05:12 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-06-26 22:16 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-06-26 22:16 . 2011-04-29 03:12 399872 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-26 22:16 . 2011-01-17 06:17 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-06-26 22:16 . 2011-01-17 05:38 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-06-26 22:16 . 2011-04-29 03:13 461312 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-26 22:16 . 2011-04-29 03:12 161792 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-26 22:16 . 2010-12-18 06:13 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-26 22:16 . 2010-12-18 05:31 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-26 22:16 . 2011-05-03 05:21 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-26 22:16 . 2011-05-03 04:50 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-26 20:54 . 2011-07-19 21:40 -------- d-----w- c:\users\Guest\AppData\Local\CrashDumps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-02 05:56 . 2011-07-15 08:52 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-01-10 11:57 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-08-13 15:55 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-25_11.29.28 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-07-25 11:27 . 2011-07-25 11:27 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-07-25 15:09 . 2011-07-25 15:09 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 05:10 . 2011-07-25 11:30 41234 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-01-10 11:44 . 2011-07-25 11:30 19980 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1639795865-839479953-694010524-1000_UserData.bin
- 2011-01-10 10:35 . 2011-07-21 07:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-10 10:35 . 2011-07-25 12:51 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-10 10:35 . 2011-07-25 12:51 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-01-10 10:35 . 2011-07-21 07:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-25 12:51 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-21 07:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2011-07-25 14:45 14384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-01-30 07:55 . 2011-07-25 15:09 6670 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2011-07-25 11:28 . 2011-07-25 11:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-25 15:10 . 2011-07-25 15:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-25 11:28 . 2011-07-25 11:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-25 15:10 . 2011-07-25 15:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-01-11 13:31 . 2011-07-25 15:00 265040 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:01 . 2011-07-25 11:27 238332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-25 15:09 238332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-01-10 13:10 . 2011-07-25 15:09 413680 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1639795865-839479953-694010524-1000-8192.dat
- 2009-07-14 02:34 . 2011-07-25 07:22 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-07-25 11:39 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-12-31 398848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"tray_ico0"="c:\windows\update.tray-14-0\svchost.exe" [2011-07-18 1170432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 VmbService;Vodafone Mobile Connect Service;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
S3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [x]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-09 1028096]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 09:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-21 c:\windows\Tasks\HPCeeScheduleFormiloň.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 01:53]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF15940.cfxxe" [X]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-sysdriver32.exe - c:\windows\sysdriver32.exe
Wow6432Node-HKLM-Run-sysdriver32_.exe - c:\windows\sysdriver32_.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
.
**************************************************************************
.
Celkový čas: 2011-07-25 17:17:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-25 15:17
ComboFix2.txt 2011-07-25 11:33
.
Před spuštěním: Volných bajtů: 570 633 633 792
Po spuštění: Volných bajtů: 570 272 083 968
.
- - End Of File - - 3EFB78CCEC33C36A76522512D8E49F05
ComboFix 11-07-25.02 - miloň 25.07.2011 17:04:15.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.3894.2401 [GMT 2:00]
Spuštěný z: c:\combofix\ComboFix.exe
Použité ovládací přepínače :: c:\users\milo˛\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ddh_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\l1rezerv.exe
c:\windows\loader2.exe_ok
c:\windows\proc_list1.log
c:\windows\sysdriver32.exe
c:\windows\sysdriver32_.exe
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\systemup.exe
c:\windows\TEMP\8291973.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.5.0
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srvsysdriver32
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-25 do 2011-07-25 )))))))))))))))))))))))))))))))
.
.
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- C:\rsit
2011-07-25 08:34 . 2011-07-25 08:34 -------- d-----w- c:\program files\trend micro
2011-07-25 07:21 . 2011-07-25 07:21 -------- d-----w- c:\program files (x86)\ESET
2011-07-25 06:59 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7D9B2696-5165-48AE-A506-80D4FB69C77A}\mpengine.dll
2011-07-25 06:58 . 2011-07-13 04:53 8578896 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-07-25 06:51 . 2011-07-13 04:53 8578896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{49714986-E745-44AC-9B47-4C597BA0D62F}\mpengine.dll
2011-07-20 18:16 . 2011-07-20 18:16 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-20 16:51 . 2011-07-21 13:45 -------- d-----w- c:\programdata\{E91883C8-8CDC-46A4-A45F-CB40EB82ED60}
2011-07-19 20:58 . 2011-07-19 20:58 -------- d-----w- c:\users\Guest\AppData\Roaming\Epson
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\phoenix
2011-07-18 14:42 . 2011-07-21 13:41 -------- d-----w- c:\windows\rpcminer
2011-07-18 14:42 . 2011-07-21 13:33 -------- d-----w- c:\windows\ufa
2011-07-18 14:42 . 2011-07-18 14:42 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:39 . 2011-07-20 15:31 -------- d-----w- c:\windows\av_ico
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-18 14:38 . 2011-07-21 13:33 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-16 15:09 . 2011-07-16 15:09 -------- d-----w- c:\users\miloň\AppData\Roaming\Epson
2011-07-16 14:49 . 2009-11-19 22:00 464384 ----a-w- c:\windows\system32\esxw2ud.dll
2011-07-16 14:49 . 2009-04-30 22:00 17408 ----a-w- c:\windows\system32\esxcdev.dll
2011-07-16 14:49 . 2009-04-30 22:00 128392 ----a-w- c:\windows\system32\esdevapp.exe
2011-07-16 14:49 . 2011-07-16 14:53 -------- d-----w- c:\program files (x86)\epson
2011-07-09 20:12 . 2011-06-07 08:10 8873296 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-08 13:21 . 2011-07-08 13:21 -------- d-----w- c:\program files (x86)\Common Files\Java
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\users\miloň\AppData\Roaming\Malwarebytes
2011-07-08 12:23 . 2011-07-08 12:23 -------- d-----w- c:\programdata\Malwarebytes
2011-07-08 12:23 . 2011-05-29 07:11 25912 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-08 12:20 . 2011-07-08 12:20 601424 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7AD08A8C-8142-44BF-AF83-BE3E8E71A907}\gapaengine.dll
2011-07-08 12:17 . 2011-07-08 12:18 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2011-07-08 12:16 . 2011-07-18 14:38 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-08 12:16 . 2011-07-08 12:16 -------- d-----w- c:\program files\Defraggler
2011-07-08 12:16 . 2010-04-09 11:06 374664 ----a-w- c:\windows\system32\drivers\netio.sys
2011-07-08 12:15 . 2011-07-08 12:15 -------- d-----w- c:\program files\CCleaner
2011-06-30 09:37 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2011-06-30 09:37 . 2011-05-24 10:34 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2011-06-30 09:37 . 2011-05-24 10:34 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2011-06-30 09:37 . 2011-05-24 10:34 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-06-30 09:37 . 2011-05-24 10:32 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2011-06-26 22:18 . 2011-04-27 02:57 102400 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-26 22:18 . 2011-04-25 05:32 1896832 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-26 22:18 . 2011-04-25 02:44 499712 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-26 22:17 . 2011-05-04 02:51 287744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-26 22:17 . 2011-05-04 02:51 157696 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-26 22:17 . 2011-05-04 02:51 126464 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-26 22:16 . 2010-11-02 05:12 320512 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-06-26 22:16 . 2010-11-02 04:35 218624 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-06-26 22:16 . 2011-04-29 03:12 399872 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-26 22:16 . 2011-01-17 06:17 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2011-06-26 22:16 . 2011-01-17 05:38 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2011-06-26 22:16 . 2011-04-29 03:13 461312 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-26 22:16 . 2011-04-29 03:12 161792 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-26 22:16 . 2010-12-18 06:13 861184 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-26 22:16 . 2010-12-18 05:31 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
2011-06-26 22:16 . 2011-05-03 05:21 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-26 22:16 . 2011-05-03 04:50 740864 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-06-26 20:54 . 2011-07-19 21:40 -------- d-----w- c:\users\Guest\AppData\Local\CrashDumps
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-02 05:56 . 2011-07-15 08:52 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-24 17:14 . 2011-01-10 11:57 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-05-04 02:52 . 2010-08-13 15:55 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-25_11.29.28 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-07-25 11:27 . 2011-07-25 11:27 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2011-07-25 15:09 . 2011-07-25 15:09 13330 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\SoftGrid Client\Icon Cache\icon_ex.dat
+ 2009-07-14 05:10 . 2011-07-25 11:30 41234 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-01-10 11:44 . 2011-07-25 11:30 19980 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1639795865-839479953-694010524-1000_UserData.bin
- 2011-01-10 10:35 . 2011-07-21 07:38 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-10 10:35 . 2011-07-25 12:51 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-10 10:35 . 2011-07-25 12:51 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-01-10 10:35 . 2011-07-21 07:38 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-07-25 12:51 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-07-21 07:38 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2011-07-25 14:45 14384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2011-01-30 07:55 . 2011-07-25 15:09 6670 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2011-07-25 11:28 . 2011-07-25 11:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-07-25 15:10 . 2011-07-25 15:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-25 11:28 . 2011-07-25 11:28 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-25 15:10 . 2011-07-25 15:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-01-11 13:31 . 2011-07-25 15:00 265040 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 05:01 . 2011-07-25 11:27 238332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-07-25 15:09 238332 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-01-10 13:10 . 2011-07-25 15:09 413680 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1639795865-839479953-694010524-1000-8192.dat
- 2009-07-14 02:34 . 2011-07-25 07:22 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:34 . 2011-07-25 11:39 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-12-31 398848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManager.exe" [2009-12-03 976320]
"tray_ico0"="c:\windows\update.tray-14-0\svchost.exe" [2011-07-18 1170432]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service;c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 RtVOsdService;RtVOsdService Installer;c:\program files\Realtek\RtVOsd\RtVOsdService.exe [2010-06-17 315392]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files\Motorola\Bluetooth\audiosrv.exe [2010-05-20 1096968]
R3 BTMCOM;Bluetooth Serial Port;c:\windows\system32\Drivers\btmcom.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [x]
R3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-23 225280]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;c:\program files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-05-14 759048]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files\Motorola\Bluetooth\obexsrv.exe [2010-05-20 677128]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-02-28 821664]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-01-25 92216]
S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-02 483688]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 VmbService;Vodafone Mobile Connect Service;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 Bluetooth Device Manager;Bluetooth Device Manager;c:\program files\Motorola\Bluetooth\devmgrsrv.exe [2010-06-29 4181256]
S3 BTMUSB;Motorola Bluetooth Radio Service;c:\windows\system32\Drivers\btmusb.sys [x]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-11-09 1028096]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-02 209768]
S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-05-19 09:36 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2011-07-21 c:\windows\Tasks\HPCeeScheduleFormiloň.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-01-05 01:53]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"combofix"="c:\combofix\CF15940.cfxxe" [X]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.bing.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: {{bd707fe6-39f6-4bda-9265-86a76719bdc5} - c:\program files\Motorola\Bluetooth\btmiesend.htm
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
Wow6432Node-HKLM-Run-sysdriver32.exe - c:\windows\sysdriver32.exe
Wow6432Node-HKLM-Run-sysdriver32_.exe - c:\windows\sysdriver32_.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
.
**************************************************************************
.
Celkový čas: 2011-07-25 17:17:24 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-25 15:17
ComboFix2.txt 2011-07-25 11:33
.
Před spuštěním: Volných bajtů: 570 633 633 792
Po spuštění: Volných bajtů: 570 272 083 968
.
- - End Of File - - 3EFB78CCEC33C36A76522512D8E49F05
Re: trojan Delf
- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "combofix"=-[HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000000 "DisableThumbnailCache"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- "tray_ico0"=- :files c:\windows\update.tray-14-0 c:\windows\phoenix c:\windows\rpcminer c:\windows\ufa c:\windows\av_ico c:\windows\update.tray-14-0 c:\windows\update.tray-14-0-lnk c:\users\MILO~1\AppData\Local\Temp c:\windows\TEMP c:\windows\unrar.exe c:\windows\sysdriver32_.exe c:\windows\sysdriver32.exe %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: trojan Delf
zde log po OTM:
All processes killed
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\"combofix"|-[HKEY_LOCAL_MACHINE\software\microsoft\security center] /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\"FirewallOverride"|dword:00000000 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\"DisableThumbnailCache"|dword:00000000 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\tray_ico0 deleted successfully.
========== FILES ==========
c:\windows\update.tray-14-0 folder moved successfully.
c:\windows\phoenix\kernels\poclbm folder moved successfully.
c:\windows\phoenix\kernels\phatk folder moved successfully.
c:\windows\phoenix\kernels folder moved successfully.
c:\windows\phoenix folder moved successfully.
c:\windows\rpcminer folder moved successfully.
c:\windows\ufa folder moved successfully.
c:\windows\av_ico folder moved successfully.
File/Folder c:\windows\update.tray-14-0 not found.
c:\windows\update.tray-14-0-lnk folder moved successfully.
c:\users\MILO~1\AppData\Local\Temp\WPDNSE folder moved successfully.
c:\users\MILO~1\AppData\Local\Temp\Low folder moved successfully.
Folder move failed. c:\users\MILO~1\AppData\Local\Temp scheduled to be moved on reboot.
c:\windows\temp folder moved successfully.
c:\windows\unrar.exe moved successfully.
c:\windows\sysdriver32_.exe moved successfully.
c:\windows\sysdriver32.exe moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56502 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 103652 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 57294 bytes
User: miloň
->Temp folder emptied: 268814 bytes
->Temporary Internet Files folder emptied: 16131642 bytes
->Java cache emptied: 219350 bytes
->Google Chrome cache emptied: 1905008 bytes
->Flash cache emptied: 57958 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67978 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 18,00 mb
OTM by OldTimer - Version 3.1.18.0 log created on 07262011_085616
Files moved on Reboot...
c:\users\MILO~1\AppData\Local\Temp folder moved successfully.
File C:\Users\miloň\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
Registry entries deleted on Reboot...
All processes killed
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\"combofix"|-[HKEY_LOCAL_MACHINE\software\microsoft\security center] /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\"FirewallOverride"|dword:00000000 /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\"DisableThumbnailCache"|dword:00000000 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\tray_ico0 deleted successfully.
========== FILES ==========
c:\windows\update.tray-14-0 folder moved successfully.
c:\windows\phoenix\kernels\poclbm folder moved successfully.
c:\windows\phoenix\kernels\phatk folder moved successfully.
c:\windows\phoenix\kernels folder moved successfully.
c:\windows\phoenix folder moved successfully.
c:\windows\rpcminer folder moved successfully.
c:\windows\ufa folder moved successfully.
c:\windows\av_ico folder moved successfully.
File/Folder c:\windows\update.tray-14-0 not found.
c:\windows\update.tray-14-0-lnk folder moved successfully.
c:\users\MILO~1\AppData\Local\Temp\WPDNSE folder moved successfully.
c:\users\MILO~1\AppData\Local\Temp\Low folder moved successfully.
Folder move failed. c:\users\MILO~1\AppData\Local\Temp scheduled to be moved on reboot.
c:\windows\temp folder moved successfully.
c:\windows\unrar.exe moved successfully.
c:\windows\sysdriver32_.exe moved successfully.
c:\windows\sysdriver32.exe moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56502 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 103652 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 57294 bytes
User: miloň
->Temp folder emptied: 268814 bytes
->Temporary Internet Files folder emptied: 16131642 bytes
->Java cache emptied: 219350 bytes
->Google Chrome cache emptied: 1905008 bytes
->Flash cache emptied: 57958 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67978 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 18,00 mb
OTM by OldTimer - Version 3.1.18.0 log created on 07262011_085616
Files moved on Reboot...
c:\users\MILO~1\AppData\Local\Temp folder moved successfully.
File C:\Users\miloň\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!
Registry entries deleted on Reboot...
Re: trojan Delf
Jak se chova PC 
Re: trojan Delf
na prvni pohled celkem OK,ale zmizel AV od Microsoftu, zkusil sem otestovat na esetu on-line a stale dava stejne vysledky - trojan Delf
Re: trojan Delf
Dejte mi sem ty vysledky...
MSE preinstalujte
MSE preinstalujte
Re: trojan Delf
tady je:
C:\Qoobox\Quarantine\C\Windows\l1rezerv.exe.vir pravd?podobn? neznámý NewHeur_PE virus
C:\Qoobox\Quarantine\C\Windows\sysdriver32.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Qoobox\Quarantine\C\Windows\sysdriver32_.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Qoobox\Quarantine\C\Windows\systemup.exe.vir pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QQI trojský k??
C:\Qoobox\Quarantine\C\Windows\update.1\svchost.exe.vir Win32/Delf.QCZ trojský k??
C:\Qoobox\Quarantine\C\Windows\update.2\svchost.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Qoobox\Quarantine\C\Windows\update.5.0\svchost.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Users\milo?\Desktop\RK_Quarantine\l1rezerv.exe.vir pravd?podobn? neznámý NewHeur_PE virus
C:\Users\milo?\Desktop\RK_Quarantine\sysdriver32.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Users\milo?\Desktop\RK_Quarantine\systemup.exe.vir pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QQI trojský k??
C:\Users\milo?\Documents\Flash-Player.exe Win32/Delf.QCZ trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\sysdriver32.exe varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\sysdriver32_.exe varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\update.tray-14-0\svchost.exe Win32/Delf.QCZ trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\update.tray-14-0-lnk\svchost.exe Win32/Delf.QCZ trojský k??
C:\Qoobox\Quarantine\C\Windows\l1rezerv.exe.vir pravd?podobn? neznámý NewHeur_PE virus
C:\Qoobox\Quarantine\C\Windows\sysdriver32.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Qoobox\Quarantine\C\Windows\sysdriver32_.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Qoobox\Quarantine\C\Windows\systemup.exe.vir pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QQI trojský k??
C:\Qoobox\Quarantine\C\Windows\update.1\svchost.exe.vir Win32/Delf.QCZ trojský k??
C:\Qoobox\Quarantine\C\Windows\update.2\svchost.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Qoobox\Quarantine\C\Windows\update.5.0\svchost.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QPN trojský k??
C:\Users\milo?\Desktop\RK_Quarantine\l1rezerv.exe.vir pravd?podobn? neznámý NewHeur_PE virus
C:\Users\milo?\Desktop\RK_Quarantine\sysdriver32.exe.vir varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\Users\milo?\Desktop\RK_Quarantine\systemup.exe.vir pravd?podobn? varianta infiltrace Win32/TrojanDownloader.Delf.QQI trojský k??
C:\Users\milo?\Documents\Flash-Player.exe Win32/Delf.QCZ trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\sysdriver32.exe varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\sysdriver32_.exe varianta infiltrace Win32/TrojanDownloader.Delf.QRH trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\update.tray-14-0\svchost.exe Win32/Delf.QCZ trojský k??
C:\_OTM\MovedFiles\07262011_085616\c_windows\update.tray-14-0-lnk\svchost.exe Win32/Delf.QCZ trojský k??
Re: trojan Delf
Smazte pouze toto C:\Users\milo?\Documents\Flash-Player.exe Win32/Delf.QCZ trojský k?? - ostatni jsou zalohy utilit - havet je uz neskodna
Co PC, MSE uz funguje po preinstalovani
Co PC, MSE uz funguje po preinstalovani
Re: trojan Delf
vse vypada ok, diky
Re: trojan Delf
Tak jeste uklidime
Odinstalujte Combofix
T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
OTC http://oldtimer.geekstogo.com/OTC.exe
TFC http://oldtimer.geekstogo.com/TFC.exe
Stahnete Ccleaner (viz muj podpis)
Panel čistič
A pokud nejsou problemy ci dotazy, je to z me strany vse :turned:ti
- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy


Přispějete na provoz fóra?