FB Vir
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
FB Vir
Logfile of random's system information tool 1.09 (written by random/random)
Run by Brko at 2011-07-25 21:25:17
Microsoft Windows 7 Home Premium
System drive C: has 17 GB (21%) free of 82 GB
Total RAM: 1015 MB (25% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:25, on 25.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Brko\AppData\Roaming\dwm.exe
C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\update.tray-7-0\svchost.exe
C:\Windows\update.tray-2-0\svchost.exe
C:\Windows\systemup.exe
C:\Windows\l1rezerv.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Users\Brko\AppData\Local\Temp\csrss.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\Downloads\RSIT.exe
C:\Program Files\trend micro\Brko.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62848
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Brko\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
F3 - REG:win.ini: load=C:\Users\Brko\AppData\Local\Temp\csrss.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL
O2 - BHO: GamePlayLabsBHO - {984A9162-8891-4D19-8CFE-17648BB4E1EC} - C:\Users\Brko\AppData\Local\Browser Plugin\BHO.dll
O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Stylish Profile\enlbrdr.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Brko\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Lišta Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [4StoryPrePatch] C:\Program Files\Gameforge4D\4Story\PrePatch.exe
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-7-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\Windows\update.tray-2-0\svchost.exe
O4 - HKLM\..\Run: [3088982.exe] "C:\Windows\Temp\3088982.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [960119.exe] "C:\Users\Brko\AppData\Local\Temp\960119.exe"
O4 - HKLM\..\Run: [9939699.exe] "C:\Users\Brko\AppData\Local\Temp\9939699.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [97453933-loader2.exe] "C:\Users\Brko\AppData\Local\Temp\97453933-loader2.exe"
O4 - HKLM\..\Run: [7365138-loader2.exe] "C:\Users\Brko\AppData\Local\Temp\7365138-loader2.exe"
O4 - HKLM\..\Run: [conhost] C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe
O4 - HKLM\..\Run: [9298242.exe] "C:\Windows\Temp\9298242.exe"
O4 - HKLM\..\Run: [8966450.exe] "C:\Windows\TEMP\8966450.exe"
O4 - HKLM\..\Run: [w_distrib.exe] "C:\Windows\update.3\svchost.exe" stand
O4 - HKCU\..\Run: [Google Update] "C:\Users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010\qip.exe" /autorun
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MIF5BA~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: QipGuard - QIP.ru - C:\Program Files\QipGuard\QipGuard.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 12368 bytes
======Scheduled tasks folder======
C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default
prefs.js - "browser.startup.homepage" - "http://centrum.cz/firefox"
prefs.js - "extensions.enabledItems" - "Cetrumcz@igeared:1.203.023.002, plugin@gameplaylabs.com:1.0, bkmrksync@nokia.com:1.0.0.736, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.8"
prefs.js - "keyword.URL" - "http://search.centrum.cz/index.php?tool ... m-1.0.0&q="
"Cetrumcz@igeared"=C:\Program Files\CentrumczToolbar\Firefox\Cetrumcz@igeared
"bkmrksync@nokia.com"=C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\2.0.40115.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat
C:\Program Files\Mozilla Firefox\plugins\
npnul32.dll
NPOFF12.DLL
nppdf32.dll
C:\Program Files\Mozilla Firefox\searchplugins\
Cetrumcz_igeared.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\extensions\
plugin@gameplaylabs.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class - C:\Users\Brko\AppData\Local\Browser Plugin\BHO.dll [2011-03-08 432640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
GdfrDUEn Class - C:\Program Files\Stylish Profile\enlbrdr.dll [2010-10-19 185856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Brko\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2011-02-01 150400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-06-21 1018680]
{D5D47440-0750-463D-BAEF-A47D02414806} - Lišta Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-11-22 7723552]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-11-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-11-22 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-11-22 150552]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-11-22 497024]
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"4StoryPrePatch"=C:\Program Files\Gameforge4D\4Story\PrePatch.exe [2010-10-20 319488]
"wxpdrv"=C:\Windows\services32.exe [2011-07-18 1170432]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-18 1170432]
"tray_ico1"=C:\Windows\update.tray-2-0\svchost.exe [2011-07-18 1170432]
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"3088982.exe"=C:\Windows\Temp\3088982.exe [2011-07-18 232960]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-25 256000]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-25 256000]
"960119.exe"=C:\Users\Brko\AppData\Local\Temp\960119.exe [2011-07-18 232960]
"9939699.exe"=C:\Users\Brko\AppData\Local\Temp\9939699.exe [2011-07-18 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-18 114176]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-23 232960]
"97453933-loader2.exe"=C:\Users\Brko\AppData\Local\Temp\97453933-loader2.exe [2011-07-21 245760]
"7365138-loader2.exe"=C:\Users\Brko\AppData\Local\Temp\7365138-loader2.exe [2011-07-22 249344]
"conhost"=C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe [2011-07-24 168960]
"9298242.exe"=C:\Windows\Temp\9298242.exe [2011-07-24 495616]
"8966450.exe"=C:\Windows\TEMP\8966450.exe [2011-07-25 256000]
"w_distrib.exe"=C:\Windows\update.3\svchost.exe [2011-07-25 272896]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
"DriverScanner"=C:\Program Files\Uniblue\DriverScanner\launcher.exe delay 20000 []
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Infium"=C:\Program Files\QIP 2010\qip.exe [2011-02-01 5856640]
"QIP Internet Guardian"=C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe [2011-02-01 187776]
"RDReminder"= []
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-11-22 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"msacm.lhacm"=lhacm.acm
"VIDC.FMVC"=fmcodec.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-25 21:09:08 ----D---- C:\Program Files\trend micro
2011-07-25 21:09:04 ----D---- C:\rsit
2011-07-25 20:46:01 ----A---- C:\Windows\w_distrib_iplist.txt
2011-07-25 20:45:32 ----HD---- C:\Windows\update.3
2011-07-23 18:07:31 ----AH---- C:\Windows\system32\ezsidmv.dat
2011-07-18 17:10:01 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-07-18 17:10:01 ----HD---- C:\Windows\update.tray-2-0
2011-07-18 16:53:57 ----A---- C:\Users\Brko\AppData\Roaming\dwm.exe
2011-07-18 16:44:47 ----D---- C:\Windows\ufa
2011-07-18 16:44:47 ----D---- C:\Windows\rpcminer
2011-07-18 16:44:47 ----D---- C:\Windows\phoenix
2011-07-18 16:43:42 ----A---- C:\Windows\unrar.exe
2011-07-18 16:42:18 ----A---- C:\Windows\l1rezerv.exe
2011-07-18 16:42:18 ----A---- C:\Windows\ddh_iplist.txt
2011-07-18 16:42:09 ----A---- C:\Windows\systemup.exe
2011-07-18 16:41:28 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-18 16:41:03 ----HD---- C:\Windows\update.2
2011-07-18 16:41:02 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-18 16:40:37 ----HD---- C:\Windows\update.5.0
2011-07-18 16:40:35 ----A---- C:\Windows\sysdriver32_.exe
2011-07-18 16:40:29 ----A---- C:\Windows\iplist.txt
2011-07-18 16:40:19 ----D---- C:\Windows\av_ico
2011-07-18 16:40:17 ----A---- C:\Windows\sysdriver32.exe
2011-07-18 16:39:47 ----A---- C:\Windows\front_ip_list.txt
2011-07-18 16:38:22 ----HD---- C:\Windows\update.1
2011-07-18 16:38:19 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-18 16:38:19 ----HD---- C:\Windows\update.tray-7-0
2011-07-18 16:24:06 ----A---- C:\Windows\winlog-ids.txt
2011-07-18 16:24:06 ----A---- C:\Windows\winlog-dirs.txt
2011-07-18 16:23:49 ----A---- C:\Windows\services32.exe
======List of files/folders modified in the last 1 month======
2011-07-25 21:25:23 ----D---- C:\Windows\Temp
2011-07-25 21:09:08 ----RD---- C:\Program Files
2011-07-25 21:09:08 ----D---- C:\Windows\Prefetch
2011-07-25 20:46:01 ----D---- C:\Windows
2011-07-25 16:31:18 ----D---- C:\Windows\System32
2011-07-25 16:31:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-25 16:31:14 ----D---- C:\Windows\inf
2011-07-25 16:29:01 ----SHD---- C:\System Volume Information
2011-07-25 16:16:24 ----D---- C:\Program Files\QIP 2010
2011-07-25 16:15:40 ----D---- C:\Program Files\Common Files\Akamai
2011-07-25 16:13:43 ----SD---- C:\Users\Brko\AppData\Roaming\Microsoft
2011-07-24 16:43:31 ----D---- C:\Users\Brko\AppData\Roaming\Skype
2011-07-24 16:08:26 ----D---- C:\Users\Brko\AppData\Roaming\skypePM
2011-07-24 08:18:34 ----D---- C:\Windows\system32\Tasks
2011-07-23 18:07:31 ----HD---- C:\ProgramData
2011-07-23 16:12:44 ----D---- C:\Program Files\World of Warcraft
2011-07-22 09:38:26 ----D---- C:\Windows\system32\config
2011-07-22 04:20:27 ----D---- C:\Windows\system32\catroot2
2011-07-21 22:02:01 ----D---- C:\Users\Brko\AppData\Roaming\ICQ
2011-07-18 22:25:00 ----D---- C:\Program Files\Mozilla Firefox
2011-07-18 22:00:46 ----D---- C:\AppServ
2011-07-18 17:04:58 ----SHD---- C:\Windows\Installer
2011-07-18 17:03:46 ----D---- C:\Windows\system32\drivers
2011-07-18 17:02:13 ----D---- C:\Windows\system32\catroot
2011-07-18 17:02:11 ----D---- C:\Windows\system32\DriverStore
2011-07-18 16:41:31 ----D---- C:\Windows\system32\drivers\etc
2011-07-02 11:32:27 ----D---- C:\Users\Brko\AppData\Roaming\uTorrent
2011-06-28 14:41:10 ----D---- C:\Windows\Minidump
2011-06-28 10:45:22 ----D---- C:\Program Files\Microsoft Silverlight
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-26 691696]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-11-22 86056]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-11-22 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-11-22 29472]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-11-22 18344]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-11-22 87040]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-11-22 4805120]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-22 2758240]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2010-11-22 13880]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2010-11-22 48640]
R3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2009-07-14 530944]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 axbx1v8b;axbx1v8b; C:\Windows\system32\drivers\axbx1v8b.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-03-21 17480]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2010-04-09 16472]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2010-04-09 11104]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 XDva365;XDva365; \??\C:\Windows\system32\XDva365.sys []
S3 XDva375;XDva375; \??\C:\Windows\system32\XDva375.sys []
S4 RsFx0102;RsFx0102 Driver; C:\Windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 582944]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-11 40999448]
R2 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
R2 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 QipGuard;QipGuard; C:\Program Files\QipGuard\QipGuard.exe [2011-02-01 187776]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-22 340992]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-24 495616]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-25 256000]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-18 1170432]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
S2 MySQL5;MySQL5; C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=C:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL5 []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
-----------------EOF-----------------
Run by Brko at 2011-07-25 21:25:17
Microsoft Windows 7 Home Premium
System drive C: has 17 GB (21%) free of 82 GB
Total RAM: 1015 MB (25% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:25, on 25.7.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\Brko\AppData\Roaming\dwm.exe
C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\update.tray-7-0\svchost.exe
C:\Windows\update.tray-2-0\svchost.exe
C:\Windows\systemup.exe
C:\Windows\l1rezerv.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\TeamViewer\Version6\TeamViewer.exe
C:\Users\Brko\AppData\Local\Temp\csrss.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brko\Downloads\RSIT.exe
C:\Program Files\trend micro\Brko.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://search13.net/search.php?clid=486&q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search13.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:62848
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Brko\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
F3 - REG:win.ini: load=C:\Users\Brko\AppData\Local\Temp\csrss.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: CentrumczToolbar BHO - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL
O2 - BHO: GamePlayLabsBHO - {984A9162-8891-4D19-8CFE-17648BB4E1EC} - C:\Users\Brko\AppData\Local\Browser Plugin\BHO.dll
O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Stylish Profile\enlbrdr.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\Brko\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: Lišta Centrum.cz Toolbar - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [4StoryPrePatch] C:\Program Files\Gameforge4D\4Story\PrePatch.exe
O4 - HKLM\..\Run: [wxpdrv] C:\Windows\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\Windows\update.tray-7-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\Windows\update.tray-2-0\svchost.exe
O4 - HKLM\..\Run: [3088982.exe] "C:\Windows\Temp\3088982.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\Windows\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\Windows\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [960119.exe] "C:\Users\Brko\AppData\Local\Temp\960119.exe"
O4 - HKLM\..\Run: [9939699.exe] "C:\Users\Brko\AppData\Local\Temp\9939699.exe"
O4 - HKLM\..\Run: [systemup] "C:\Windows\systemup.exe" stand
O4 - HKLM\..\Run: [l1rezerv.exe] "C:\Windows\l1rezerv.exe"
O4 - HKLM\..\Run: [97453933-loader2.exe] "C:\Users\Brko\AppData\Local\Temp\97453933-loader2.exe"
O4 - HKLM\..\Run: [7365138-loader2.exe] "C:\Users\Brko\AppData\Local\Temp\7365138-loader2.exe"
O4 - HKLM\..\Run: [conhost] C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe
O4 - HKLM\..\Run: [9298242.exe] "C:\Windows\Temp\9298242.exe"
O4 - HKLM\..\Run: [8966450.exe] "C:\Windows\TEMP\8966450.exe"
O4 - HKLM\..\Run: [w_distrib.exe] "C:\Windows\update.3\svchost.exe" stand
O4 - HKCU\..\Run: [Google Update] "C:\Users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Infium] "C:\Program Files\QIP 2010\qip.exe" /autorun
O4 - HKCU\..\Run: [QIP Internet Guardian] C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe /p
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra 'Tools' menuitem: StylishProfile - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Stylish Profile\ct.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MIF5BA~1\Office12\GRA32A~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (file missing)
O23 - Service: ESET Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: QipGuard - QIP.ru - C:\Program Files\QipGuard\QipGuard.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: srvbtcclient - Unknown owner - C:\Windows\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\Windows\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\Windows\sysdriver32.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: wxpdrivers - Unknown owner - C:\Windows\update.1\svchost.exe
--
End of file - 12368 bytes
======Scheduled tasks folder======
C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default
prefs.js - "browser.startup.homepage" - "http://centrum.cz/firefox"
prefs.js - "extensions.enabledItems" - "Cetrumcz@igeared:1.203.023.002, plugin@gameplaylabs.com:1.0, bkmrksync@nokia.com:1.0.0.736, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.8"
prefs.js - "keyword.URL" - "http://search.centrum.cz/index.php?tool ... m-1.0.0&q="
"Cetrumcz@igeared"=C:\Program Files\CentrumczToolbar\Firefox\Cetrumcz@igeared
"bkmrksync@nokia.com"=C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\2.0.40115.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
C:\Program Files\Mozilla Firefox\components\
browser.xpt
browserdirprovider.dll
brwsrcmp.dll
components.list
compreg.dat
FeedConverter.js
FeedProcessor.js
FeedWriter.js
fuelApplication.js
GPSDGeolocationProvider.js
jsconsole-clhandler.js
NetworkGeolocationProvider.js
nsAddonRepository.js
nsBadCertHandler.js
nsBlocklistService.js
nsBrowserContentHandler.js
nsBrowserGlue.js
nsContentDispatchChooser.js
nsContentPrefService.js
nsDefaultCLH.js
nsDownloadManagerUI.js
nsExtensionManager.js
nsFormAutoComplete.js
nsHandlerService.js
nsHelperAppDlg.js
nsINIProcessor.js
nsLivemarkService.js
nsLoginInfo.js
nsLoginManager.js
nsLoginManagerPrompter.js
nsMicrosummaryService.js
nsPlacesAutoComplete.js
nsPlacesDBFlush.js
nsPlacesTransactionsService.js
nsPrivateBrowsingService.js
nsProxyAutoConfig.js
nsSafebrowsingApplication.js
nsSearchService.js
nsSearchSuggestions.js
nsSessionStartup.js
nsSessionStore.js
nsSetDefaultBrowser.js
nsSidebar.js
nsTaggingService.js
nsTryToClose.js
nsUpdateService.js
nsUpdateServiceStub.js
nsUpdateTimerManager.js
nsUrlClassifierLib.js
nsUrlClassifierListManager.js
nsURLFormatter.js
nsWebHandlerApp.js
pluginGlue.js
storage-Legacy.js
storage-mozStorage.js
txEXSLTRegExFunctions.js
WebContentConverter.js
xpti.dat
C:\Program Files\Mozilla Firefox\plugins\
npnul32.dll
NPOFF12.DLL
nppdf32.dll
C:\Program Files\Mozilla Firefox\searchplugins\
Cetrumcz_igeared.xml
google.xml
jyxo-cz.xml
mall-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\extensions\
plugin@gameplaylabs.com
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{984A9162-8891-4D19-8CFE-17648BB4E1EC}]
GamePlayLabsBHO Class - C:\Users\Brko\AppData\Local\Browser Plugin\BHO.dll [2011-03-08 432640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
GdfrDUEn Class - C:\Program Files\Stylish Profile\enlbrdr.dll [2010-10-19 185856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\Brko\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2011-02-01 150400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-06 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-06-21 1018680]
{D5D47440-0750-463D-BAEF-A47D02414806} - Lišta Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-03-26 1286448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2010-11-22 7723552]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-11-22 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-11-22 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-11-22 150552]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2010-11-22 497024]
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"avast5"=C:\Program Files\Alwil Software\Avast5\avastUI.exe /nogui []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-03-30 937920]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"4StoryPrePatch"=C:\Program Files\Gameforge4D\4Story\PrePatch.exe [2010-10-20 319488]
"wxpdrv"=C:\Windows\services32.exe [2011-07-18 1170432]
"tray_ico"= []
"tray_ico0"=C:\Windows\update.tray-7-0\svchost.exe [2011-07-18 1170432]
"tray_ico1"=C:\Windows\update.tray-2-0\svchost.exe [2011-07-18 1170432]
"tray_ico2"= []
"tray_ico3"= []
"tray_ico4"= []
"3088982.exe"=C:\Windows\Temp\3088982.exe [2011-07-18 232960]
"sysdriver32.exe"=C:\Windows\sysdriver32.exe [2011-07-25 256000]
"sysdriver32_.exe"=C:\Windows\sysdriver32_.exe [2011-07-25 256000]
"960119.exe"=C:\Users\Brko\AppData\Local\Temp\960119.exe [2011-07-18 232960]
"9939699.exe"=C:\Users\Brko\AppData\Local\Temp\9939699.exe [2011-07-18 232960]
"systemup"=C:\Windows\systemup.exe [2011-07-18 114176]
"l1rezerv.exe"=C:\Windows\l1rezerv.exe [2011-07-23 232960]
"97453933-loader2.exe"=C:\Users\Brko\AppData\Local\Temp\97453933-loader2.exe [2011-07-21 245760]
"7365138-loader2.exe"=C:\Users\Brko\AppData\Local\Temp\7365138-loader2.exe [2011-07-22 249344]
"conhost"=C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe [2011-07-24 168960]
"9298242.exe"=C:\Windows\Temp\9298242.exe [2011-07-24 495616]
"8966450.exe"=C:\Windows\TEMP\8966450.exe [2011-07-25 256000]
"w_distrib.exe"=C:\Windows\update.3\svchost.exe [2011-07-25 272896]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
"DriverScanner"=C:\Program Files\Uniblue\DriverScanner\launcher.exe delay 20000 []
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Infium"=C:\Program Files\QIP 2010\qip.exe [2011-02-01 5856640]
"QIP Internet Guardian"=C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe [2011-02-01 187776]
"RDReminder"= []
"PC Suite Tray"=C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2010-12-21 1483264]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-11-22 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MIF5BA~1\Office12\GR469A~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"msacm.divxa32"=msaud32_divx.acm
"msacm.lhacm"=lhacm.acm
"VIDC.FMVC"=fmcodec.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-07-25 21:09:08 ----D---- C:\Program Files\trend micro
2011-07-25 21:09:04 ----D---- C:\rsit
2011-07-25 20:46:01 ----A---- C:\Windows\w_distrib_iplist.txt
2011-07-25 20:45:32 ----HD---- C:\Windows\update.3
2011-07-23 18:07:31 ----AH---- C:\Windows\system32\ezsidmv.dat
2011-07-18 17:10:01 ----HD---- C:\Windows\update.tray-2-0-lnk
2011-07-18 17:10:01 ----HD---- C:\Windows\update.tray-2-0
2011-07-18 16:53:57 ----A---- C:\Users\Brko\AppData\Roaming\dwm.exe
2011-07-18 16:44:47 ----D---- C:\Windows\ufa
2011-07-18 16:44:47 ----D---- C:\Windows\rpcminer
2011-07-18 16:44:47 ----D---- C:\Windows\phoenix
2011-07-18 16:43:42 ----A---- C:\Windows\unrar.exe
2011-07-18 16:42:18 ----A---- C:\Windows\l1rezerv.exe
2011-07-18 16:42:18 ----A---- C:\Windows\ddh_iplist.txt
2011-07-18 16:42:09 ----A---- C:\Windows\systemup.exe
2011-07-18 16:41:28 ----A---- C:\Windows\iecheck_iplist.txt
2011-07-18 16:41:03 ----HD---- C:\Windows\update.2
2011-07-18 16:41:02 ----A---- C:\Windows\btc_client_iplist.txt
2011-07-18 16:40:37 ----HD---- C:\Windows\update.5.0
2011-07-18 16:40:35 ----A---- C:\Windows\sysdriver32_.exe
2011-07-18 16:40:29 ----A---- C:\Windows\iplist.txt
2011-07-18 16:40:19 ----D---- C:\Windows\av_ico
2011-07-18 16:40:17 ----A---- C:\Windows\sysdriver32.exe
2011-07-18 16:39:47 ----A---- C:\Windows\front_ip_list.txt
2011-07-18 16:38:22 ----HD---- C:\Windows\update.1
2011-07-18 16:38:19 ----HD---- C:\Windows\update.tray-7-0-lnk
2011-07-18 16:38:19 ----HD---- C:\Windows\update.tray-7-0
2011-07-18 16:24:06 ----A---- C:\Windows\winlog-ids.txt
2011-07-18 16:24:06 ----A---- C:\Windows\winlog-dirs.txt
2011-07-18 16:23:49 ----A---- C:\Windows\services32.exe
======List of files/folders modified in the last 1 month======
2011-07-25 21:25:23 ----D---- C:\Windows\Temp
2011-07-25 21:09:08 ----RD---- C:\Program Files
2011-07-25 21:09:08 ----D---- C:\Windows\Prefetch
2011-07-25 20:46:01 ----D---- C:\Windows
2011-07-25 16:31:18 ----D---- C:\Windows\System32
2011-07-25 16:31:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-07-25 16:31:14 ----D---- C:\Windows\inf
2011-07-25 16:29:01 ----SHD---- C:\System Volume Information
2011-07-25 16:16:24 ----D---- C:\Program Files\QIP 2010
2011-07-25 16:15:40 ----D---- C:\Program Files\Common Files\Akamai
2011-07-25 16:13:43 ----SD---- C:\Users\Brko\AppData\Roaming\Microsoft
2011-07-24 16:43:31 ----D---- C:\Users\Brko\AppData\Roaming\Skype
2011-07-24 16:08:26 ----D---- C:\Users\Brko\AppData\Roaming\skypePM
2011-07-24 08:18:34 ----D---- C:\Windows\system32\Tasks
2011-07-23 18:07:31 ----HD---- C:\ProgramData
2011-07-23 16:12:44 ----D---- C:\Program Files\World of Warcraft
2011-07-22 09:38:26 ----D---- C:\Windows\system32\config
2011-07-22 04:20:27 ----D---- C:\Windows\system32\catroot2
2011-07-21 22:02:01 ----D---- C:\Users\Brko\AppData\Roaming\ICQ
2011-07-18 22:25:00 ----D---- C:\Program Files\Mozilla Firefox
2011-07-18 22:00:46 ----D---- C:\AppServ
2011-07-18 17:04:58 ----SHD---- C:\Windows\Installer
2011-07-18 17:03:46 ----D---- C:\Windows\system32\drivers
2011-07-18 17:02:13 ----D---- C:\Windows\system32\catroot
2011-07-18 17:02:11 ----D---- C:\Windows\system32\DriverStore
2011-07-18 16:41:31 ----D---- C:\Windows\system32\drivers\etc
2011-07-02 11:32:27 ----D---- C:\Users\Brko\AppData\Roaming\uTorrent
2011-06-28 14:41:10 ----D---- C:\Windows\Minidump
2011-06-28 10:45:22 ----D---- C:\Program Files\Microsoft Silverlight
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-11-26 691696]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
R1 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2006-07-24 5632]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2010-11-22 86056]
R3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\DRIVERS\btwavdt.sys [2010-11-22 108072]
R3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2010-11-22 29472]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2010-11-22 18344]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2010-11-22 87040]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-11-22 4805120]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2010-11-22 2758240]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2010-11-22 13880]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1E62x86.sys [2010-11-22 48640]
R3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2009-07-14 530944]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 axbx1v8b;axbx1v8b; C:\Windows\system32\drivers\axbx1v8b.sys []
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys []
S3 EagleXNt;EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys []
S3 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-03-21 17480]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 pwdrvio;pwdrvio; \??\C:\Windows\system32\pwdrvio.sys [2010-04-09 16472]
S3 pwdspio;pwdspio; \??\C:\Windows\system32\pwdspio.sys [2010-04-09 11104]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 XDva365;XDva365; \??\C:\Windows\system32\XDva365.sys []
S3 XDva375;XDva375; \??\C:\Windows\system32\XDva375.sys []
S4 RsFx0102;RsFx0102 Driver; C:\Windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Akamai;Akamai NetSession Interface; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-01 582944]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
R2 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [2008-07-11 40999448]
R2 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
R2 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
R2 PSI_SVC_2;Protexis Licensing V2; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 QipGuard;QipGuard; C:\Program Files\QipGuard\QipGuard.exe [2011-02-01 187776]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-07-10 98840]
R2 srvbtcclient;srvbtcclient; C:\Windows\update.5.0\svchost.exe [2011-07-22 340992]
R2 srviecheck;srviecheck; C:\Windows\update.2\svchost.exe [2011-07-24 495616]
R2 srvsysdriver32;srvsysdriver32; C:\Windows\sysdriver32.exe [2011-07-25 256000]
R2 TeamViewer6;TeamViewer 6; C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
R2 W3SVC;@%windir%\system32\inetsrv\iisres.dll,-30003; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 wxpdrivers;wxpdrivers; C:\Windows\update.1\svchost.exe [2011-07-18 1170432]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-12-08 628736]
R3 WAS;@%windir%\system32\inetsrv\iisres.dll,-30001; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe []
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
S2 MySQL5;MySQL5; C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=C:\Program Files\MySQL\MySQL Server 5.0\my.ini MySQL5 []
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe []
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service; c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS); c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
-----------------EOF-----------------
Re: FB Vir
Zdravim a pekny vecer preji
Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com
Aplikujte exeHelper by Raktor
Aplikujte RogueKiller
Jeste znovu RogueKiller ale nyni s moznosti 3 a pote jeste jednou s moznosti 4
RKill, eXeHelper i RogueKiller by mely udelat logy, vlozte mi je sem
- Pokud ho havet blokuje, pouzijte jeden z nasledujicich
motji napsal: Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr
Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif - Ulozte nejlepena plochu a ukoncete vsechny aplikace (jinak to udela RKill za Vas)
- Spustte tradicne dvojklikem - program probehne temer okamzite a ukonci i svou cinnost
- RKill ukonci vsechny ne-systemove procesy - tedy i procesy, pod kterymi bezi havet
- Ted nerestartujte PC - prisli byste o ucinek RKillu
- Linky ke stazeni
- COM soubor http://vyosek.ic.cz/BE/exeHelper.com
- SCR soubor http://vyosek.ic.cz/BE/exeHelper.scr
- Utilitu staci spustit jako Spravce (klik pravym mysidlem), probehne oprava a vznikne log exehelperlog.txt
stell napsal: pouzijes RogueKiller>.spustis>>stlac 2> [enter] log vloz sem
http://www.viry.cz/forum/viewtopic.php? ... 05#p981205
Re: FB Vir
Rkill probehl normalne.... log v pohode...
ale u exeHelper to po spusteni pise ze " Program prestal pracovat " .....
ale u exeHelper to po spusteni pise ze " Program prestal pracovat " .....
Re: FB Vir
Pokracujte na RogueKiller
Re: FB Vir
RKilll :
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 26.07.2011 at 8:04:23.
Operating System: Windows 7 Home Premium
Processes terminated by Rkill or while it was running:
C:\Windows\system32\taskeng.exe
C:\Users\Brko\AppData\Roaming\dwm.exe
C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe
C:\Users\Brko\AppData\Local\Temp\csrss.exe
C:\Windows\sysdriver32_.exe
C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe
--- ATTENTION ---
Windows was configured to use a proxy! Proxy settings have been removed.
The Proxy Server that was configured is: http=127.0.0.1:62848
If this was a valid setting, please double-click on the rk-proxy.reg file on your desktop and allow the data to be merged to restore your proxy settings.
Rkill completed on 26.07.2011 at 8:07:19.
Roguekill ( vyber 2 )
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: Brko [Admin rights]
Mode: Remove -- Date : 07/26/2011 08:09:12
Bad processes: 0
Registry Entries: 22
[SUSP PATH] HKCU\[...]\Run : QIP Internet Guardian (C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe /p) -> DELETED
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\Windows\services32.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3088982.exe ("C:\Windows\Temp\3088982.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\Windows\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\Windows\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 960119.exe ("C:\Users\Brko\AppData\Local\Temp\960119.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9939699.exe ("C:\Users\Brko\AppData\Local\Temp\9939699.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("C:\Windows\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("C:\Windows\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 97453933-loader2.exe ("C:\Users\Brko\AppData\Local\Temp\97453933-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 7365138-loader2.exe ("C:\Users\Brko\AppData\Local\Temp\7365138-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : conhost (C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9298242.exe ("C:\Windows\Temp\9298242.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 8966450.exe ("C:\Windows\Temp\8966450.exe") -> DELETED
[SUSP PATH] HKCU\[...]\Winlogon : Shell (explorer.exe,C:\Users\Brko\AppData\Roaming\dwm.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\Brko\AppData\Local\Temp\csrss.exe) -> DELETED
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
Roguekiller ( vyber 3)
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: Brko [Admin rights]
Mode: HOSTSFix -- Date : 07/26/2011 08:09:34
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Roguekill (moznost 4 )
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: Brko [Admin rights]
Mode: ProxyFix -- Date : 07/26/2011 08:09:44
Bad processes: 0
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Rkill was run on 26.07.2011 at 8:04:23.
Operating System: Windows 7 Home Premium
Processes terminated by Rkill or while it was running:
C:\Windows\system32\taskeng.exe
C:\Users\Brko\AppData\Roaming\dwm.exe
C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe
C:\Users\Brko\AppData\Local\Temp\csrss.exe
C:\Windows\sysdriver32_.exe
C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe
--- ATTENTION ---
Windows was configured to use a proxy! Proxy settings have been removed.
The Proxy Server that was configured is: http=127.0.0.1:62848
If this was a valid setting, please double-click on the rk-proxy.reg file on your desktop and allow the data to be merged to restore your proxy settings.
Rkill completed on 26.07.2011 at 8:07:19.
Roguekill ( vyber 2 )
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: Brko [Admin rights]
Mode: Remove -- Date : 07/26/2011 08:09:12
Bad processes: 0
Registry Entries: 22
[SUSP PATH] HKCU\[...]\Run : QIP Internet Guardian (C:\Users\Brko\AppData\Roaming\QipGuard\QipGuard.exe /p) -> DELETED
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\Windows\services32.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3088982.exe ("C:\Windows\Temp\3088982.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\Windows\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\Windows\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 960119.exe ("C:\Users\Brko\AppData\Local\Temp\960119.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9939699.exe ("C:\Users\Brko\AppData\Local\Temp\9939699.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : systemup ("C:\Windows\systemup.exe" stand) -> DELETED
[SUSP PATH] HKLM\[...]\Run : l1rezerv.exe ("C:\Windows\l1rezerv.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 97453933-loader2.exe ("C:\Users\Brko\AppData\Local\Temp\97453933-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 7365138-loader2.exe ("C:\Users\Brko\AppData\Local\Temp\7365138-loader2.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : conhost (C:\Users\Brko\AppData\Roaming\Microsoft\conhost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 9298242.exe ("C:\Windows\Temp\9298242.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 8966450.exe ("C:\Windows\Temp\8966450.exe") -> DELETED
[SUSP PATH] HKCU\[...]\Winlogon : Shell (explorer.exe,C:\Users\Brko\AppData\Roaming\dwm.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\Brko\AppData\Local\Temp\csrss.exe) -> DELETED
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
Roguekiller ( vyber 3)
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: Brko [Admin rights]
Mode: HOSTSFix -- Date : 07/26/2011 08:09:34
Bad processes: 0
HOSTS File:
127.0.0.1 localhost
127.0.0.1 vkontakte.ru
127.0.0.1 www.vkontakte.ru
127.0.0.1 login.vk.com
127.0.0.1 vk.com
127.0.0.1 www.vk.com
127.0.0.1 odnoklassniki.ru
127.0.0.1 www.odnoklassniki.ru
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Roguekill (moznost 4 )
RogueKiller V5.2.8 [07/23/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html
Operating System: Windows 7 (6.1.7600 ) 32 bits version
Started in : Normal mode
User: Brko [Admin rights]
Mode: ProxyFix -- Date : 07/26/2011 08:09:44
Bad processes: 0
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Re: FB Vir
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: FB Vir
ComboFix 11-07-26.02 - Brko 26.07.2011 11:20:15.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.1015.506 [GMT 2:00]
Spuštěný z: c:\users\Brko\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Brko\AppData\Local\Browser Plugin\BHO.dll
c:\users\Brko\AppData\Roaming\dwm.exe
c:\users\Brko\AppData\Roaming\Microsoft\conhost.exe
c:\windows\services32.exe
c:\windows\sysdriver32_.exe
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.3
c:\windows\update.3\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-2-0\svchost.exe
c:\windows\update.tray-7-0\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 09:36 . 2011-07-26 09:40 -------- d-----w- c:\users\Brko\AppData\Local\temp
2011-07-26 09:36 . 2011-07-26 09:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-25 19:09 . 2011-07-25 19:25 -------- d-----w- c:\program files\trend micro
2011-07-25 19:09 . 2011-07-25 19:10 -------- d-----w- C:\rsit
2011-07-18 15:10 . 2011-07-26 09:35 -------- d--h--w- c:\windows\update.tray-2-0
2011-07-18 15:10 . 2011-07-18 15:10 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-07-18 14:44 . 2011-07-18 14:44 -------- d-----w- c:\windows\rpcminer
2011-07-18 14:44 . 2011-07-18 14:44 -------- d-----w- c:\windows\phoenix
2011-07-18 14:44 . 2011-07-18 14:44 -------- d-----w- c:\windows\ufa
2011-07-18 14:43 . 2011-07-18 14:44 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:42 . 2011-07-23 06:46 232960 ----a-w- c:\windows\l1rezerv.exe
2011-07-18 14:42 . 2011-07-18 14:42 114176 ----a-w- c:\windows\systemup.exe
2011-07-18 14:40 . 2011-07-18 15:12 -------- d-----w- c:\windows\av_ico
2011-07-18 14:40 . 2011-07-25 14:21 256000 ----a-w- c:\windows\sysdriver32.exe
2011-07-18 14:38 . 2011-07-26 09:35 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-18 14:38 . 2011-07-18 14:38 -------- d--h--w- c:\windows\update.tray-7-0-lnk
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 17:04 . 2011-03-07 15:05 2568 --sha-w- c:\programdata\KGyGaAvL.sys
2010-10-01 07:11 . 2011-01-01 20:04 462112 ----a-w- c:\program files\Common Files\ZugoInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-10-19 07:47 185856 ----a-w- c:\program files\Stylish Profile\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Infium"="c:\program files\QIP 2010\qip.exe" [2011-02-01 5856640]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-22 7723552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-11-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-11-22 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-11-22 150552]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2010-11-22 497024]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"4StoryPrePatch"="c:\program files\Gameforge4D\4Story\PrePatch.exe" [2010-10-20 319488]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R2 MySQL5;MySQL5;c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=c:\program files\MySQL\MySQL Server 5.0\my.ini MySQL5 [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 16472]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 11104]
R3 XDva365;XDva365;c:\windows\system32\XDva365.sys [x]
R3 XDva375;XDva375;c:\windows\system32\XDva375.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-26 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
S2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [2011-02-01 187776]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-11-22 29472]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-22 87040]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-27 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-06 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
uCustomizeSearch = hxxp://search13.net/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/index.php?toolbar=centrum-1.0.0&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-DriverScanner - c:\program files\Uniblue\DriverScanner\launcher.exe
HKCU-Run-RDReminder - (no file)
HKLM-Run-SuperHybridEngine - AsusSender.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico0 - c:\windows\update.tray-7-0\svchost.exe
HKLM-Run-tray_ico1 - c:\windows\update.tray-2-0\svchost.exe
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
HKLM-Run-w_distrib.exe - c:\windows\update.3\svchost.exe
AddRemove-avast5 - c:\program files\Alwil Software\Avast5\aswRunDll.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL5]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL5"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2024)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\NetworkExplorer.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\System32\hgcpl.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version6\TeamViewer.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2011-07-26 11:46:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-26 09:46
.
Před spuštěním: Volných bajtů: 17 584 582 656
Po spuštění: Volných bajtů: 20 445 900 800
.
- - End Of File - - 735E5C35B34F8C6239A72D3A4BD8040D
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.1015.506 [GMT 2:00]
Spuštěný z: c:\users\Brko\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Brko\AppData\Local\Browser Plugin\BHO.dll
c:\users\Brko\AppData\Roaming\dwm.exe
c:\users\Brko\AppData\Roaming\Microsoft\conhost.exe
c:\windows\services32.exe
c:\windows\sysdriver32_.exe
c:\windows\update.1
c:\windows\update.1\svchost.exe
c:\windows\update.2
c:\windows\update.2\svchost.exe
c:\windows\update.3
c:\windows\update.3\svchost.exe
c:\windows\update.5.0
c:\windows\update.5.0\svchost.exe
c:\windows\update.tray-2-0\svchost.exe
c:\windows\update.tray-7-0\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_srviecheck
-------\Service_srvsysdriver32
-------\Service_wxpdrivers
-------\Service_srvbtcclient
-------\Service_srvbtcclient
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 09:36 . 2011-07-26 09:40 -------- d-----w- c:\users\Brko\AppData\Local\temp
2011-07-26 09:36 . 2011-07-26 09:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-25 19:09 . 2011-07-25 19:25 -------- d-----w- c:\program files\trend micro
2011-07-25 19:09 . 2011-07-25 19:10 -------- d-----w- C:\rsit
2011-07-18 15:10 . 2011-07-26 09:35 -------- d--h--w- c:\windows\update.tray-2-0
2011-07-18 15:10 . 2011-07-18 15:10 -------- d--h--w- c:\windows\update.tray-2-0-lnk
2011-07-18 14:44 . 2011-07-18 14:44 -------- d-----w- c:\windows\rpcminer
2011-07-18 14:44 . 2011-07-18 14:44 -------- d-----w- c:\windows\phoenix
2011-07-18 14:44 . 2011-07-18 14:44 -------- d-----w- c:\windows\ufa
2011-07-18 14:43 . 2011-07-18 14:44 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:42 . 2011-07-23 06:46 232960 ----a-w- c:\windows\l1rezerv.exe
2011-07-18 14:42 . 2011-07-18 14:42 114176 ----a-w- c:\windows\systemup.exe
2011-07-18 14:40 . 2011-07-18 15:12 -------- d-----w- c:\windows\av_ico
2011-07-18 14:40 . 2011-07-25 14:21 256000 ----a-w- c:\windows\sysdriver32.exe
2011-07-18 14:38 . 2011-07-26 09:35 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-18 14:38 . 2011-07-18 14:38 -------- d--h--w- c:\windows\update.tray-7-0-lnk
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 17:04 . 2011-03-07 15:05 2568 --sha-w- c:\programdata\KGyGaAvL.sys
2010-10-01 07:11 . 2011-01-01 20:04 462112 ----a-w- c:\program files\Common Files\ZugoInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-10-19 07:47 185856 ----a-w- c:\program files\Stylish Profile\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-03-21 07:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Infium"="c:\program files\QIP 2010\qip.exe" [2011-02-01 5856640]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2010-12-21 1483264]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-22 7723552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-11-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-11-22 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-11-22 150552]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2010-11-22 497024]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"4StoryPrePatch"="c:\program files\Gameforge4D\4Story\PrePatch.exe" [2010-10-20 319488]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R2 MySQL5;MySQL5;c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=c:\program files\MySQL\MySQL Server 5.0\my.ini MySQL5 [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-11-22 136176]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 16472]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 11104]
R3 XDva365;XDva365;c:\windows\system32\XDva365.sys [x]
R3 XDva375;XDva375;c:\windows\system32\XDva375.sys [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-26 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-06-21 246584]
S2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [2011-02-01 187776]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-11-22 29472]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-22 87040]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-27 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-06 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
uCustomizeSearch = hxxp://search13.net/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/index.php?toolbar=centrum-1.0.0&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKCU-Run-DriverScanner - c:\program files\Uniblue\DriverScanner\launcher.exe
HKCU-Run-RDReminder - (no file)
HKLM-Run-SuperHybridEngine - AsusSender.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico0 - c:\windows\update.tray-7-0\svchost.exe
HKLM-Run-tray_ico1 - c:\windows\update.tray-2-0\svchost.exe
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
HKLM-Run-w_distrib.exe - c:\windows\update.3\svchost.exe
AddRemove-avast5 - c:\program files\Alwil Software\Avast5\aswRunDll.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL5]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL5"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(2024)
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\NetworkExplorer.dll
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\System32\hgcpl.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version6\TeamViewer.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2011-07-26 11:46:06 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-26 09:46
.
Před spuštěním: Volných bajtů: 17 584 582 656
Po spuštění: Volných bajtů: 20 445 900 800
.
- - End Of File - - 735E5C35B34F8C6239A72D3A4BD8040D
Re: FB Vir
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Folder:: c:\windows\update.tray-2-0 c:\windows\update.tray-2-0-lnk c:\windows\rpcminer c:\windows\phoenix c:\windows\ufa c:\windows\av_ico c:\windows\update.tray-7-0 c:\windows\update.tray-7-0-lnk c:\program files\Stylish Profile c:\program files\Common Files\TortoiseOverlays c:\program files\ICQ6Toolbar File:: C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job C:\Windows\tasks\GoogleUpdateTaskMachineCore.job C:\Windows\tasks\GoogleUpdateTaskMachineUA.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job Collect:: c:\windows\sysdriver32.exe c:\windows\unrar.exe c:\windows\l1rezerv.exe c:\windows\systemup.exe c:\windows\system32\XDva365.sys c:\windows\system32\XDva375.sys Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"=- "Infium"=- "PC Suite Tray"=- [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"=- "Adobe Reader Speed Launcher"=- "Adobe ARM"=- "4StoryPrePatch"=- [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000000 "DisableThumbnailCache"=dword:00000000 Driver:: gupdate gupdatem XDva365 XDva375 ICQ Service Akamai iissvcs apphost apphostsvc NetSvc:: Akamai iissvcs apphost DDS:: uStart Page = hxxp://qip.ru uDefault_Search_URL = hxxp://search.qip.ru uSearchAssistant = hxxp://search.qip.ru/ie uCustomizeSearch = hxxp://search13.net/ Firefox:: FF - ProfilePath - c:\users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\ FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search FF - prefs.js: keyword.URL - hxxp://search.centrum.cz/index.php?tool ... m-1.0.0&q= RegLock:: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: FB Vir
ComboFix 11-07-26.02 - Brko 26.07.2011 20:45:03.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.1015.308 [GMT 2:00]
Spuštěný z: c:\users\Brko\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Brko\Desktop\CFScript.TXT
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\tasks\DLL-files.com Fixer_MONTHLY.job"
"c:\windows\tasks\DLL-files.com Fixer_UPDATES.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job"
.
file zipped: c:\windows\l1rezerv.exe
file zipped: c:\windows\sysdriver32.exe
file zipped: c:\windows\systemup.exe
file zipped: c:\windows\unrar.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\TortoiseOverlays
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\License.txt
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\Stylish Profile
c:\program files\Stylish Profile\ct.htm
c:\program files\Stylish Profile\enlbrdr.dll
c:\program files\Stylish Profile\hoticon.ico
c:\program files\Stylish Profile\tomapi.js
c:\program files\Stylish Profile\tommain.js
c:\program files\Stylish Profile\uninstall.exe
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_NOD_AV_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\update.tray-2-0-lnk
c:\windows\update.tray-2-0-lnk\svchost.exe
c:\windows\update.tray-2-0
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0-lnk\svchost.exe
c:\windows\update.tray-7-0
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA365
-------\Legacy_XDVA375
-------\Service_Akamai
-------\Service_AppHostSvc
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_ICQ Service
-------\Service_XDva365
-------\Service_XDva375
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 19:00 . 2011-07-26 19:03 -------- d-----w- c:\users\Brko\AppData\Local\temp
2011-07-25 19:09 . 2011-07-25 19:25 -------- d-----w- c:\program files\trend micro
2011-07-25 19:09 . 2011-07-25 19:10 -------- d-----w- C:\rsit
2011-07-18 14:43 . 2011-07-26 18:44 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:42 . 2011-07-26 18:44 232960 ----a-w- c:\windows\l1rezerv.exe
2011-07-18 14:42 . 2011-07-26 18:44 114176 ----a-w- c:\windows\systemup.exe
2011-07-18 14:40 . 2011-07-26 18:44 256000 ----a-w- c:\windows\sysdriver32.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 17:04 . 2011-03-07 15:05 2568 --sha-w- c:\programdata\KGyGaAvL.sys
2010-10-01 07:11 . 2011-01-01 20:04 462112 ----a-w- c:\program files\Common Files\ZugoInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-22 7723552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-11-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-11-22 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-11-22 150552]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2010-11-22 497024]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R2 MySQL5;MySQL5;c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=c:\program files\MySQL\MySQL Server 5.0\my.ini MySQL5 [x]
R3 CFcatchme;CFcatchme;c:\users\Brko\AppData\Local\Temp\CFcatchme.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 16472]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 11104]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-26 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [2011-02-01 187776]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-11-22 29472]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-22 87040]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-27 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-06 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{C5994560-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994561-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994562-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994563-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994564-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994565-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994566-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994567-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994568-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-Stylish Profile - c:\program files\Stylish Profile\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL5]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL5"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3884)
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\System32\pnidui.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\taskhost.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version6\TeamViewer.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2011-07-26 21:08:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-26 19:08
ComboFix2.txt 2011-07-26 09:46
.
Před spuštěním: Volných bajtů: 19 693 346 816
Po spuštění: Volných bajtů: 19 946 733 568
.
- - End Of File - - A2836240454F824C214C3478E9F11A5B
Nahr nˇ probŘhlo ŁspŘçnŘ
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.420.1029.18.1015.308 [GMT 2:00]
Spuštěný z: c:\users\Brko\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Brko\Desktop\CFScript.TXT
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\tasks\DLL-files.com Fixer_MONTHLY.job"
"c:\windows\tasks\DLL-files.com Fixer_UPDATES.job"
"c:\windows\tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\tasks\GoogleUpdateTaskMachineUA.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job"
"c:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job"
.
file zipped: c:\windows\l1rezerv.exe
file zipped: c:\windows\sysdriver32.exe
file zipped: c:\windows\systemup.exe
file zipped: c:\windows\unrar.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Common Files\TortoiseOverlays
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\CVSClassic\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Modern\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Straight\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\Subclipse\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\AddedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\ConflictIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\DeletedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\IgnoredIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\LockedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\ModifiedIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\NormalIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\ReadOnlyIcon.ico
c:\program files\Common Files\TortoiseOverlays\icons\XPStyle\UnversionedIcon.ico
c:\program files\Common Files\TortoiseOverlays\License.txt
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\Stylish Profile
c:\program files\Stylish Profile\ct.htm
c:\program files\Stylish Profile\enlbrdr.dll
c:\program files\Stylish Profile\hoticon.ico
c:\program files\Stylish Profile\tomapi.js
c:\program files\Stylish Profile\tommain.js
c:\program files\Stylish Profile\uninstall.exe
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\av_ico\ico_NOD_AV_START.ico
c:\windows\av_ico\ico_NOD_SYSINSP.ico
c:\windows\av_ico\ico_NOD_SYSRESC.ico
c:\windows\av_ico\ico_NOD_TXT.ico
c:\windows\av_ico\ico_NOD_UNINSTALL.ico
c:\windows\phoenix
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\rpcminer
c:\windows\rpcminer\bitcoinminercuda_10.cubin
c:\windows\rpcminer\bitcoinminercuda_11.cubin
c:\windows\rpcminer\bitcoinminercuda_20.cubin
c:\windows\rpcminer\bitcoinmineropencl.cl
c:\windows\rpcminer\cudart32_32_16.dll
c:\windows\rpcminer\curllib.dll
c:\windows\rpcminer\libeay32.dll
c:\windows\rpcminer\libsasl.dll
c:\windows\rpcminer\openldap.dll
c:\windows\rpcminer\rpcminer-4way.exe
c:\windows\rpcminer\rpcminer-cpu.exe
c:\windows\rpcminer\rpcminer-cuda.exe
c:\windows\rpcminer\rpcminer-opencl.exe
c:\windows\rpcminer\ssleay32.dll
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\update.tray-2-0-lnk
c:\windows\update.tray-2-0-lnk\svchost.exe
c:\windows\update.tray-2-0
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0-lnk\svchost.exe
c:\windows\update.tray-7-0
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_XDVA365
-------\Legacy_XDVA375
-------\Service_Akamai
-------\Service_AppHostSvc
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_ICQ Service
-------\Service_XDva365
-------\Service_XDva375
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-06-26 do 2011-07-26 )))))))))))))))))))))))))))))))
.
.
2011-07-26 19:00 . 2011-07-26 19:03 -------- d-----w- c:\users\Brko\AppData\Local\temp
2011-07-25 19:09 . 2011-07-25 19:25 -------- d-----w- c:\program files\trend micro
2011-07-25 19:09 . 2011-07-25 19:10 -------- d-----w- C:\rsit
2011-07-18 14:43 . 2011-07-26 18:44 246272 ----a-w- c:\windows\unrar.exe
2011-07-18 14:42 . 2011-07-26 18:44 232960 ----a-w- c:\windows\l1rezerv.exe
2011-07-18 14:42 . 2011-07-26 18:44 114176 ----a-w- c:\windows\systemup.exe
2011-07-18 14:40 . 2011-07-26 18:44 256000 ----a-w- c:\windows\sysdriver32.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-06 17:04 . 2011-03-07 15:05 2568 --sha-w- c:\programdata\KGyGaAvL.sys
2010-10-01 07:11 . 2011-01-01 20:04 462112 ----a-w- c:\program files\Common Files\ZugoInstaller.exe
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-22 7723552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-11-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-11-22 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-11-22 150552]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2010-11-22 497024]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [x]
R2 MySQL5;MySQL5;c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=c:\program files\MySQL\MySQL Server 5.0\my.ini MySQL5 [x]
R3 CFcatchme;CFcatchme;c:\users\Brko\AppData\Local\Temp\CFcatchme.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-04-09 16472]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-04-09 11104]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-11 47128]
R4 RsFx0102;RsFx0102 Driver;c:\windows\system32\DRIVERS\RsFx0102.sys [2008-07-10 242712]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2008-07-11 369688]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-26 691696]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 QipGuard;QipGuard;c:\program files\QipGuard\QipGuard.exe [2011-02-01 187776]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-11-22 29472]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-22 87040]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-06-27 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-06 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files\Dll-Files.com Fixer\DLLFixer.exe [2011-03-25 17:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-23 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000Core.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1519488970-593827328-2664369111-1000UA.job
- c:\users\Brko\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-22 16:32]
.
.
------- Doplňkový sken -------
.
uSearchAssistant = hxxp://search.qip.ru/ie
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\users\Brko\AppData\Roaming\Mozilla\Firefox\Profiles\fxyg0nng.default\
FF - prefs.js: browser.startup.homepage - hxxp://centrum.cz/firefox
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Lišta Centrum.cz Toolbar em:version=1.203.023.002 em:displayname=Lišta Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Lišta Centrum.cz Toolbar em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: GamePlayLabs Plugin: plugin@gameplaylabs.com - %profile%\extensions\plugin@gameplaylabs.com
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{C5994560-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994561-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994562-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994563-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994564-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994565-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994566-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994567-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
ShellIconOverlayIdentifiers-{C5994568-53D9-4125-87C9-F193FC689CB2} - c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
AddRemove-Stylish Profile - c:\program files\Stylish Profile\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MySQL5]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL5"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'Explorer.exe'(3884)
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_cze.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\System32\pnidui.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\taskhost.exe
c:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\TeamViewer\Version6\TeamViewer.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2011-07-26 21:08:22 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-07-26 19:08
ComboFix2.txt 2011-07-26 09:46
.
Před spuštěním: Volných bajtů: 19 693 346 816
Po spuštění: Volných bajtů: 19 946 733 568
.
- - End Of File - - A2836240454F824C214C3478E9F11A5B
Nahr nˇ probŘhlo ŁspŘçnŘ
Re: FB Vir
- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:reg [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost] "netsvcs"=hex(7):41,00,65,00,4C,00,6F,00,6F,00,6B,00,75,00,\ 70,00,53,00,76,00,63,00,00,00,41,00,70,00,70,00,49,00,6E,00,66,00,6F,00,\ 00,00,41,00,75,00,64,00,69,00,6F,00,53,00,72,00,76,00,00,00,42,00,44,00,\ 45,00,53,00,56,00,43,00,00,00,42,00,49,00,54,00,53,00,00,00,62,00,72,00,\ 6F,00,77,00,73,00,65,00,72,00,00,00,43,00,65,00,72,00,74,00,50,00,72,00,\ 6F,00,70,00,53,00,76,00,63,00,00,00,45,00,61,00,70,00,48,00,6F,00,73,00,\ 74,00,00,00,46,00,61,00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,\ 69,00,74,00,63,00,68,00,69,00,6E,00,67,00,43,00,6F,00,6D,00,70,00,61,00,\ 74,00,69,00,62,00,69,00,6C,00,69,00,74,00,79,00,00,00,67,00,70,00,73,00,\ 76,00,63,00,00,00,68,00,65,00,6C,00,70,00,73,00,76,00,63,00,00,00,68,00,\ 6B,00,6D,00,73,00,76,00,63,00,00,00,49,00,61,00,73,00,00,00,49,00,4B,00,\ 45,00,45,00,58,00,54,00,00,00,69,00,70,00,68,00,6C,00,70,00,73,00,76,00,\ 63,00,00,00,49,00,72,00,6D,00,6F,00,6E,00,00,00,6C,00,61,00,6E,00,6D,00,\ 61,00,6E,00,73,00,65,00,72,00,76,00,65,00,72,00,00,00,4C,00,6F,00,67,00,\ 6F,00,6E,00,48,00,6F,00,75,00,72,00,73,00,00,00,4D,00,4D,00,43,00,53,00,\ 53,00,00,00,6D,00,73,00,69,00,73,00,63,00,73,00,69,00,00,00,4E,00,6C,00,\ 61,00,00,00,4E,00,74,00,6D,00,73,00,73,00,76,00,63,00,00,00,4E,00,57,00,\ 43,00,57,00,6F,00,72,00,6B,00,73,00,74,00,61,00,74,00,69,00,6F,00,6E,00,\ 00,00,4E,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6E,00,74,00,00,00,50,00,\ 43,00,41,00,75,00,64,00,69,00,74,00,00,00,50,00,72,00,6F,00,66,00,53,00,\ 76,00,63,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6F,00,00,00,52,00,\ 61,00,73,00,6D,00,61,00,6E,00,00,00,52,00,65,00,6D,00,6F,00,74,00,65,00,\ 61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,43,00,50,00,6F,00,6C,00,\ 69,00,63,00,79,00,53,00,76,00,63,00,00,00,73,00,65,00,63,00,6C,00,6F,00,\ 67,00,6F,00,6E,00,00,00,53,00,45,00,4E,00,53,00,00,00,53,00,65,00,73,00,\ 73,00,69,00,6F,00,6E,00,45,00,6E,00,76,00,00,00,53,00,68,00,61,00,72,00,\ 65,00,64,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,68,00,65,00,\ 6C,00,6C,00,48,00,57,00,44,00,65,00,74,00,65,00,63,00,74,00,69,00,6F,00,\ 6E,00,00,00,73,00,63,00,68,00,65,00,64,00,75,00,6C,00,65,00,00,00,53,00,\ 52,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,\ 69,00,73,00,72,00,76,00,00,00,54,00,65,00,72,00,6D,00,53,00,65,00,72,00,\ 76,00,69,00,63,00,65,00,00,00,54,00,68,00,65,00,6D,00,65,00,73,00,00,00,75,00,\ 70,00,6C,00,6F,00,61,00,64,00,6D,00,67,00,72,00,00,00,77,00,65,00,72,00,\ 63,00,70,00,6C,00,73,00,75,00,70,00,70,00,6F,00,72,00,74,00,00,00,77,00,\ 69,00,6E,00,6D,00,67,00,6D,00,74,00,00,00,57,00,6D,00,64,00,6D,00,50,00,\ 6D,00,53,00,70,00,00,00,57,00,6D,00,69,00,00,00,77,00,75,00,61,00,75,00,\ 73,00,65,00,72,00,76,00,00,00,00,00 :files c:\windows\unrar.exe c:\windows\l1rezerv.exe c:\windows\systemup.exe c:\windows\sysdriver32.exe %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: FB Vir
All processes killed
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\"netsvcs"|hex(7):41,00,65,00,4C,00,6F,00,6F,00,6B,00,75,00,70,00,53,00,76,00,63,00,00,00,41,00,70,00,70,00,49,00,6E,00,66,00,6F,00,00,00,41,00,75,00,64,00,69,00,6F,00,53,00,72,00,76,00,00,00,42,00,44,00,45,00,53,00,56,00,43,00,00,00,42,00,49,00,54,00,53,00,00,00,62,00,72,00,6F,00,77,00,73,00,65,00,72,00,00,00,43,00,65,00,72,00,74,00,50,00,72,00,6F,00,70,00,53,00,76,00,63,00,00,00,45,00,61,00,70,00,48,00,6F,00,73,00,74,00,00,00,46,00,61,00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,69,00,6E,00,67,00,43,00,6F,00,6D,00,70,00,61,00,74,00,69,00,62,00,69,00,6C,00,69,00,74,00,79,00,00,00,67,00,70,00,73,00,76,00,63,00,00,00,68,00,65,00,6C,00,70,00,73,00,76,00,63,00,00,00,68,00,6B,00,6D,00,73,00,76,00,63,00,00,00,49,00,61,00,73,00,00,00,49,00,4B,00,45,00,45,00,58,00,54,00,00,00,69,00,70,00,68,00,6C,00,70,00,73,00,76,00,63,00,00,00,49,00,72,00,6D,00,6F,00,6E,00,00,00,6C,00,61,00,6E,00,6D,00,61,00,6E,00,73,00,65,00,72,00,76,00,65,00,72,00,00,00,4C,00,6F,00,67,00,6F,00,6E,00,48,00,6F,00,75,00,72,00,73,00,00,00,4D,00,4D,00,43,00,53,00,53,00,00,00,6D,00,73,00,69,00,73,00,63,00,73,00,69,00,00,00,4E,00,6C,00,61,00,00,00,4E,00,74,00,6D,00,73,00,73,00,76,00,63,00,00,00,4E,00,57,00,43,00,57,00,6F,00,72,00,6B,00,73,00,74,00,61,00,74,00,69,00,6F,00,6E,00,00,00,4E,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6E,00,74,00,00,00,50,00,43,00,41,00,75,00,64,00,69,00,74,00,00,00,50,00,72,00,6F,00,66,00,53,00,76,00,63,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6F,00,00,00,52,00,61,00,73,00,6D,00,61,00,6E,00,00,00,52,00,65,00,6D,00,6F,00,74,00,65,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,43,00,50,00,6F,00,6C,00,69,00,63,00,79,00,53,00,76,00,63,00,00,00,73,00,65,00,63,00,6C,00,6F,00,67,00,6F,00,6E,00,00,00,53,00,45,00,4E,00,53,00,00,00,53,00,65,00,73,00,73,00,69,00,6F,00,6E,00,45,00,6E,00,76,00,00,00,53,00,68,00,61,00,72,00,65,00,64,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,68,00,65,00,6C,00,6C,00,48,00,57,00,44,00,65,00,74,00,65,00,63,00,74,00,69,00,6F,00,6E,00,00,00,73,00,63,00,68,00,65,00,64,00,75,00,6C,00,65,00,00,00,53,00,52,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,54,00,65,00,72,00,6D,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,68,00,65,00,6D,00,65,00,73,00,00,00,75,00,70,00,6C,00,6F,00,61,00,64,00,6D,00,67,00,72,00,00,00,77,00,65,00,72,00,63,00,70,00,6C,00,73,00,75,00,70,00,70,00,6F,00,72,00,74,00,00,00,77,00,69,00,6E,00,6D,00,67,00,6D,00,74,00,00,00,57,00,6D,00,64,00,6D,00,50,00,6D,00,53,00,70,00,00,00,57,00,6D,00,69,00,00,00,77,00,75,00,61,00,75,00,73,00,65,00,72,00,76,00,00,00,00,00 /E : value set successfully!
========== FILES ==========
c:\windows\unrar.exe moved successfully.
c:\windows\l1rezerv.exe moved successfully.
c:\windows\systemup.exe moved successfully.
c:\windows\sysdriver32.exe moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Brko
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 31079390 bytes
->Java cache emptied: 51302 bytes
->FireFox cache emptied: 48873615 bytes
->Google Chrome cache emptied: 270086386 bytes
->Flash cache emptied: 8752712 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 342,00 mb
OTM by OldTimer - Version 3.1.18.0 log created on 07262011_213512
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\"netsvcs"|hex(7):41,00,65,00,4C,00,6F,00,6F,00,6B,00,75,00,70,00,53,00,76,00,63,00,00,00,41,00,70,00,70,00,49,00,6E,00,66,00,6F,00,00,00,41,00,75,00,64,00,69,00,6F,00,53,00,72,00,76,00,00,00,42,00,44,00,45,00,53,00,56,00,43,00,00,00,42,00,49,00,54,00,53,00,00,00,62,00,72,00,6F,00,77,00,73,00,65,00,72,00,00,00,43,00,65,00,72,00,74,00,50,00,72,00,6F,00,70,00,53,00,76,00,63,00,00,00,45,00,61,00,70,00,48,00,6F,00,73,00,74,00,00,00,46,00,61,00,73,00,74,00,55,00,73,00,65,00,72,00,53,00,77,00,69,00,74,00,63,00,68,00,69,00,6E,00,67,00,43,00,6F,00,6D,00,70,00,61,00,74,00,69,00,62,00,69,00,6C,00,69,00,74,00,79,00,00,00,67,00,70,00,73,00,76,00,63,00,00,00,68,00,65,00,6C,00,70,00,73,00,76,00,63,00,00,00,68,00,6B,00,6D,00,73,00,76,00,63,00,00,00,49,00,61,00,73,00,00,00,49,00,4B,00,45,00,45,00,58,00,54,00,00,00,69,00,70,00,68,00,6C,00,70,00,73,00,76,00,63,00,00,00,49,00,72,00,6D,00,6F,00,6E,00,00,00,6C,00,61,00,6E,00,6D,00,61,00,6E,00,73,00,65,00,72,00,76,00,65,00,72,00,00,00,4C,00,6F,00,67,00,6F,00,6E,00,48,00,6F,00,75,00,72,00,73,00,00,00,4D,00,4D,00,43,00,53,00,53,00,00,00,6D,00,73,00,69,00,73,00,63,00,73,00,69,00,00,00,4E,00,6C,00,61,00,00,00,4E,00,74,00,6D,00,73,00,73,00,76,00,63,00,00,00,4E,00,57,00,43,00,57,00,6F,00,72,00,6B,00,73,00,74,00,61,00,74,00,69,00,6F,00,6E,00,00,00,4E,00,77,00,73,00,61,00,70,00,61,00,67,00,65,00,6E,00,74,00,00,00,50,00,43,00,41,00,75,00,64,00,69,00,74,00,00,00,50,00,72,00,6F,00,66,00,53,00,76,00,63,00,00,00,52,00,61,00,73,00,61,00,75,00,74,00,6F,00,00,00,52,00,61,00,73,00,6D,00,61,00,6E,00,00,00,52,00,65,00,6D,00,6F,00,74,00,65,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,43,00,50,00,6F,00,6C,00,69,00,63,00,79,00,53,00,76,00,63,00,00,00,73,00,65,00,63,00,6C,00,6F,00,67,00,6F,00,6E,00,00,00,53,00,45,00,4E,00,53,00,00,00,53,00,65,00,73,00,73,00,69,00,6F,00,6E,00,45,00,6E,00,76,00,00,00,53,00,68,00,61,00,72,00,65,00,64,00,61,00,63,00,63,00,65,00,73,00,73,00,00,00,53,00,68,00,65,00,6C,00,6C,00,48,00,57,00,44,00,65,00,74,00,65,00,63,00,74,00,69,00,6F,00,6E,00,00,00,73,00,63,00,68,00,65,00,64,00,75,00,6C,00,65,00,00,00,53,00,52,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,61,00,70,00,69,00,73,00,72,00,76,00,00,00,54,00,65,00,72,00,6D,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,00,00,54,00,68,00,65,00,6D,00,65,00,73,00,00,00,75,00,70,00,6C,00,6F,00,61,00,64,00,6D,00,67,00,72,00,00,00,77,00,65,00,72,00,63,00,70,00,6C,00,73,00,75,00,70,00,70,00,6F,00,72,00,74,00,00,00,77,00,69,00,6E,00,6D,00,67,00,6D,00,74,00,00,00,57,00,6D,00,64,00,6D,00,50,00,6D,00,53,00,70,00,00,00,57,00,6D,00,69,00,00,00,77,00,75,00,61,00,75,00,73,00,65,00,72,00,76,00,00,00,00,00 /E : value set successfully!
========== FILES ==========
c:\windows\unrar.exe moved successfully.
c:\windows\l1rezerv.exe moved successfully.
c:\windows\systemup.exe moved successfully.
c:\windows\sysdriver32.exe moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Brko
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 31079390 bytes
->Java cache emptied: 51302 bytes
->FireFox cache emptied: 48873615 bytes
->Google Chrome cache emptied: 270086386 bytes
->Flash cache emptied: 8752712 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 342,00 mb
OTM by OldTimer - Version 3.1.18.0 log created on 07262011_213512
Re: FB Vir
Jak se chova PC 
Re: FB Vir
mno už nelaguje a na FB měto v pohode pusti... jedina vec je ta že mě to smazlo Avasta
je to normalni?
Re: FB Vir
Tak jeste uklidime
- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy



Přispějete na provoz fóra?