
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Kontrola logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Kontrola logu
Zdravim, poprosim o kontrolu logu. PO ubgrade Avastu, ho nechcelo aktuailozavat, po odobrati nainstalovat Aviru, pri instalacii hacalo chybu, nakoniec nainstalovany antivir od Microsoftu. Teraz mi niektore aplikacie nechce nainstalovat. Hadze chybu c:/document/local/temp_nazov programu subor sa nenasiel.
Logfile of random's system information tool 1.09 (written by random/random)
Run by miki at 2011-08-06 12:26:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 4 GB (28%) free of 15 GB
Total RAM: 2047 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:26:52, on 6.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17098)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\Integrator.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\RSIT.exe
C:\Program Files\trend micro\miki.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://redirect.zonelabs.com/redirect/r ... hx644bu4g0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [speedfan] C:\Program Files\SpeedFan\speedfan.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AntiCrash.lnk = C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: COMODO System - Cleaner Service (Cleaner_Validator) - Unknown owner - C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
--
End of file - 7938 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\COMODO Updater.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
C:\WINDOWS\tasks\Úklid 1 kliknutím.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://sk.start3.mozilla.com/firefox?cl ... k:official"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6, abhere2@moztw.org:3.6.20101102, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8, {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.7, {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2, {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6, {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, jqs@sun.com:1.0, {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2, {54BB9F3F-07E5-486c-9B39-C7398B99391C}:4.0.2011021601, {20a82645-c095-46ed-80e3-08825760534b}:0.0.0, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, {37fa1426-b82d-11db-8314-0800200c9a66}:2.7.6, {cdbbb3f6-a50e-4b20-a154-5fcbb3bbf43d}:1.2.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://mystart.incredimail.com/?loc=ff_ ... v2&search="
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609]
"Description"=12.0.1.609
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsjsrealplayerplugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\extensions\
{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
{37E4D8EA-8BDA-4831-8EA1-89053939A250}
{37fa1426-b82d-11db-8314-0800200c9a66}
{54BB9F3F-07E5-486c-9B39-C7398B99391C}
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
C:\Documents and Settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-07-28 110592]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-11-21 7335936]
"nwiz"=nwiz.exe /install []
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-09-06 14850560]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-21 761945]
"ABLKSR"=C:\WINDOWS\ABLKSR\ABLKSR.exe [2006-01-02 61440]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-02-25 2834432]
"IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2006-08-02 802816]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2006-08-02 696320]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"speedfan"=C:\Program Files\SpeedFan\speedfan.exe [2008-04-22 3287552]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-12-03 14944136]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-04-13 399736]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Documents and Settings\miki\Nabídka Start\Programy\Po spuštění
AntiCrash.lnk - C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"msacm.divxa32"=msaud32_divx.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
======List of files/folders created in the last 1 month======
2011-08-06 12:26:33 ----D---- C:\Program Files\trend micro
2011-08-06 12:26:32 ----D---- C:\rsit
2011-08-06 12:25:58 ----A---- C:\RSIT.exe
2011-08-06 12:07:36 ----A---- C:\WINDOWS\ntbtlog.txt
2011-08-06 11:14:17 ----A---- C:\WINDOWS\system32\FTChipID.dll
2011-08-06 11:13:54 ----D---- C:\Program Files\WGSoft
2011-08-06 11:13:54 ----D---- C:\Documents and Settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-06 11:09:07 ----A---- C:\EasyObdII_Ver2_3_0.exe
2011-08-06 11:08:44 ----A---- C:\scantool_net115win.exe
2011-08-01 16:28:55 ----D---- C:\Program Files\Lamer
2011-08-01 16:23:51 ----A---- C:\lamersetup.exe
2011-08-01 16:18:53 ----A---- C:\gwave558.exe
2011-07-31 17:23:48 ----D---- C:\Documents and Settings\miki\Data aplikací\Help
2011-07-31 15:06:18 ----D---- C:\symbian
2011-07-27 12:48:44 ----A---- C:\WINDOWS\system32\muweb.dll
2011-07-27 12:48:44 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-07-26 12:28:00 ----SHD---- C:\RECYCLER
2011-07-26 11:27:20 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2011-07-26 11:15:37 ----D---- C:\Program Files\Microsoft Security Client
2011-07-26 11:07:40 ----AH---- C:\Documents and Settings\miki\Data aplikací\dach100.dll
2011-07-26 11:00:12 ----A---- C:\WINDOWS\zip.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\SWSC.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\SWREG.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\sed.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\PEV.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\NIRCMD.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\MBR.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\grep.exe
2011-07-26 10:59:59 ----HD---- C:\Qoobox
2011-07-23 11:27:49 ----A---- C:\WINDOWS\avastSS.scr
2011-07-23 11:27:38 ----D---- C:\Program Files\AVAST Software
2011-07-23 11:27:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-07-10 16:48:00 ----D---- C:\Program Files\NETGATE
2011-07-10 16:45:23 ----D---- C:\Program Files\The KMPlayer
2011-07-07 00:56:28 ----D---- C:\Program Files\Mv2Player
======List of files/folders modified in the last 1 month======
2011-08-06 12:26:39 ----D---- C:\Documents and Settings\miki\Data aplikací\uTorrent
2011-08-06 12:26:33 ----RD---- C:\Program Files
2011-08-06 12:23:01 ----SD---- C:\WINDOWS\Tasks
2011-08-06 12:22:01 ----D---- C:\Documents and Settings\miki\Data aplikací\Skype
2011-08-06 12:21:36 ----D---- C:\Documents and Settings\miki\Data aplikací\skypePM
2011-08-06 12:18:59 ----D---- C:\WINDOWS\Temp
2011-08-06 12:18:43 ----A---- C:\WINDOWS\wincmd.ini
2011-08-06 12:18:19 ----D---- C:\Program Files\SpeedFan
2011-08-06 12:18:11 ----D---- C:\WINDOWS\system32\Lang
2011-08-06 12:18:11 ----D---- C:\WINDOWS\system32\drivers
2011-08-06 12:17:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-06 12:13:46 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-06 12:07:36 ----HD---- C:\WINDOWS
2011-08-06 11:35:29 ----SHD---- C:\WINDOWS\Installer
2011-08-06 11:15:20 ----D---- C:\Program Files\Mozilla Firefox
2011-08-06 11:14:17 ----D---- C:\WINDOWS\system32
2011-08-06 03:04:29 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-06 03:01:35 ----D---- C:\WINDOWS\Prefetch
2011-08-04 12:02:04 ----D---- C:\Documents and Settings\miki\Data aplikací\vlc
2011-08-04 02:18:44 ----A---- C:\WINDOWS\NeroDigital.ini
2011-08-03 05:52:35 ----A---- C:\Settings.ini
2011-08-01 22:16:04 ----D---- C:\Downloads
2011-07-31 17:23:48 ----HD---- C:\totalcmd
2011-07-29 03:02:09 ----D---- C:\WINDOWS\WinSxS
2011-07-27 02:44:53 ----HD---- C:\WINDOWS\inf
2011-07-26 11:16:05 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-07-26 11:09:45 ----D---- C:\WINDOWS\ERDNT
2011-07-26 11:08:34 ----N---- C:\WINDOWS\system.ini
2011-07-26 11:07:25 ----D---- C:\WINDOWS\system32\drivers\etc
2011-07-26 11:06:19 ----D---- C:\WINDOWS\system32\config
2011-07-26 11:03:56 ----D---- C:\WINDOWS\AppPatch
2011-07-26 11:03:54 ----D---- C:\Program Files\Common Files
2011-07-26 11:03:29 ----D---- C:\WINDOWS\system32\wbem
2011-07-24 02:37:27 ----D---- C:\Program Files\uTorrent
2011-07-23 13:54:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-07-23 11:33:16 ----D---- C:\Program Files\Alwil Software
2011-07-23 11:25:26 ----HD---- C:\Documents and Settings
2011-07-20 14:01:30 ----D---- C:\Program Files\Spyware Terminator
2011-07-16 14:42:45 ----D---- C:\tor
2011-07-16 14:33:42 ----D---- C:\WINDOWS\Debug
2011-07-14 15:01:45 ----D---- C:\Program Files\Microsoft Bootvis
2011-07-14 14:36:42 ----RSHD---- C:\WINDOWS\system32\dllcache
2011-07-14 14:33:52 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2011-02-23 13496]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2009-02-25 129248]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2009-02-25 368736]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2009-02-25 441760]
R1 CFRMD;CFRMD; C:\WINDOWS\system32\DRIVERS\CFRMD.sys [2010-12-09 66584]
R1 CFRPD;CFRPD; C:\WINDOWS\system32\DRIVERS\CFRPD.sys [2010-12-09 33232]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKsl81fe7e55;MpKsl81fe7e55; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\MpKsl81fe7e55.sys []
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-02-25 21419]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-01-11 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-01-11 25888]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2006-08-02 12544]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2009-02-25 44384]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 Cam5603D;BisonCam, NB Pro; C:\WINDOWS\System32\Drivers\BisonCam.sys [2005-04-18 646656]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-08 3959808]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-18 5632]
R3 NETw3x32;Ovladač adaptéru Intel(R) PRO/Wireless 3945ABG pro Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw3x32.sys [2006-09-27 1709696]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-11-21 3600512]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2005-11-16 78976]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-05-26 839724]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-21 191936]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
R3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2005-11-22 108800]
R3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-09-15 36480]
R3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2005-12-01 62848]
R3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2005-11-15 36736]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 MpKsl19898a96;MpKsl19898a96; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys []
S1 MpKslddeb1f73;MpKslddeb1f73; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys []
S3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\miki\LOCALS~1\Temp\ASFWHide []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys []
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-10-23 427288]
R2 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 305600]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2006-08-02 434176]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-25 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-06-21 53248]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-11-21 143426]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2006-08-02 327680]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2006-08-02 937984]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-02-25 984576]
R2 TryAndDecideService;Acronis Try And Decide Service; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-23 495832]
R2 UxTuneUp;TuneUp Design Expansion; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by miki at 2011-08-06 12:26:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 4 GB (28%) free of 15 GB
Total RAM: 2047 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:26:52, on 6.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17098)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\Integrator.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\RSIT.exe
C:\Program Files\trend micro\miki.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://redirect.zonelabs.com/redirect/r ... hx644bu4g0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [speedfan] C:\Program Files\SpeedFan\speedfan.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AntiCrash.lnk = C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: COMODO System - Cleaner Service (Cleaner_Validator) - Unknown owner - C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
--
End of file - 7938 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\COMODO Updater.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
C:\WINDOWS\tasks\Úklid 1 kliknutím.job
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://sk.start3.mozilla.com/firefox?cl ... k:official"
prefs.js - "extensions.enabledItems" - "{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6, abhere2@moztw.org:3.6.20101102, {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8, {daf44bf7-a45e-4450-979c-91cf07434c3d}:1.5.7, {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2, {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6, {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}:6.0.06, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11, jqs@sun.com:1.0, {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2, {54BB9F3F-07E5-486c-9B39-C7398B99391C}:4.0.2011021601, {20a82645-c095-46ed-80e3-08825760534b}:0.0.0, {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1, {37fa1426-b82d-11db-8314-0800200c9a66}:2.7.6, {cdbbb3f6-a50e-4b20-a154-5fcbb3bbf43d}:1.2.6, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://mystart.incredimail.com/?loc=ff_ ... v2&search="
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=12.0.1.609]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprjplug;version=12.0.1.609]
"Description"=RealJukebox Netscape Plugin
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.609]
"Description"=RealPlayer(tm) HTML5VideoShim Plug-In
"Path"=C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.609]
"Description"=12.0.1.609
"Path"=C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=]
"Description"=
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nppl3260.xpt
nsjsrealplayerplugin.xpt
C:\Program Files\Mozilla Firefox\plugins\
npdeploytk.dll
nppdf32.dll
nppl3260.dll
nprjplug.dll
nprpjplug.dll
C:\Program Files\Mozilla Firefox\searchplugins\
atlas-sk.xml
azet-sk.xml
dunaj-sk.xml
eBay.xml
google.xml
slovnik-sk.xml
wikipedia-sk.xml
zoznam-sk.xml
C:\Documents and Settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\extensions\
{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
{37E4D8EA-8BDA-4831-8EA1-89053939A250}
{37fa1426-b82d-11db-8314-0800200c9a66}
{54BB9F3F-07E5-486c-9B39-C7398B99391C}
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
C:\Documents and Settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\searchplugins\
askcom.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-07-28 110592]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-11-21 7335936]
"nwiz"=nwiz.exe /install []
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-09-06 14850560]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2005-10-21 761945]
"ABLKSR"=C:\WINDOWS\ABLKSR\ABLKSR.exe [2006-01-02 61440]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2009-02-25 2834432]
"IntelZeroConfig"=C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2006-08-02 802816]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2006-08-02 696320]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"speedfan"=C:\Program Files\SpeedFan\speedfan.exe [2008-04-22 3287552]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-12-03 14944136]
"uTorrent"=C:\Program Files\uTorrent\uTorrent.exe [2011-04-13 399736]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2009-01-15 393216]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Documents and Settings\miki\Nabídka Start\Programy\Po spuštění
AntiCrash.lnk - C:\Program Files\Dachshund Software\AntiCrash\AntiCrash.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoResolveSearch"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.FFDS"=ff_vfw.dll
"msacm.divxa32"=msaud32_divx.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll
======List of files/folders created in the last 1 month======
2011-08-06 12:26:33 ----D---- C:\Program Files\trend micro
2011-08-06 12:26:32 ----D---- C:\rsit
2011-08-06 12:25:58 ----A---- C:\RSIT.exe
2011-08-06 12:07:36 ----A---- C:\WINDOWS\ntbtlog.txt
2011-08-06 11:14:17 ----A---- C:\WINDOWS\system32\FTChipID.dll
2011-08-06 11:13:54 ----D---- C:\Program Files\WGSoft
2011-08-06 11:13:54 ----D---- C:\Documents and Settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-06 11:09:07 ----A---- C:\EasyObdII_Ver2_3_0.exe
2011-08-06 11:08:44 ----A---- C:\scantool_net115win.exe
2011-08-01 16:28:55 ----D---- C:\Program Files\Lamer
2011-08-01 16:23:51 ----A---- C:\lamersetup.exe
2011-08-01 16:18:53 ----A---- C:\gwave558.exe
2011-07-31 17:23:48 ----D---- C:\Documents and Settings\miki\Data aplikací\Help
2011-07-31 15:06:18 ----D---- C:\symbian
2011-07-27 12:48:44 ----A---- C:\WINDOWS\system32\muweb.dll
2011-07-27 12:48:44 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-07-26 12:28:00 ----SHD---- C:\RECYCLER
2011-07-26 11:27:20 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2011-07-26 11:15:37 ----D---- C:\Program Files\Microsoft Security Client
2011-07-26 11:07:40 ----AH---- C:\Documents and Settings\miki\Data aplikací\dach100.dll
2011-07-26 11:00:12 ----A---- C:\WINDOWS\zip.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\SWSC.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\SWREG.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\sed.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\PEV.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\NIRCMD.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\MBR.exe
2011-07-26 11:00:12 ----A---- C:\WINDOWS\grep.exe
2011-07-26 10:59:59 ----HD---- C:\Qoobox
2011-07-23 11:27:49 ----A---- C:\WINDOWS\avastSS.scr
2011-07-23 11:27:38 ----D---- C:\Program Files\AVAST Software
2011-07-23 11:27:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-07-10 16:48:00 ----D---- C:\Program Files\NETGATE
2011-07-10 16:45:23 ----D---- C:\Program Files\The KMPlayer
2011-07-07 00:56:28 ----D---- C:\Program Files\Mv2Player
======List of files/folders modified in the last 1 month======
2011-08-06 12:26:39 ----D---- C:\Documents and Settings\miki\Data aplikací\uTorrent
2011-08-06 12:26:33 ----RD---- C:\Program Files
2011-08-06 12:23:01 ----SD---- C:\WINDOWS\Tasks
2011-08-06 12:22:01 ----D---- C:\Documents and Settings\miki\Data aplikací\Skype
2011-08-06 12:21:36 ----D---- C:\Documents and Settings\miki\Data aplikací\skypePM
2011-08-06 12:18:59 ----D---- C:\WINDOWS\Temp
2011-08-06 12:18:43 ----A---- C:\WINDOWS\wincmd.ini
2011-08-06 12:18:19 ----D---- C:\Program Files\SpeedFan
2011-08-06 12:18:11 ----D---- C:\WINDOWS\system32\Lang
2011-08-06 12:18:11 ----D---- C:\WINDOWS\system32\drivers
2011-08-06 12:17:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-06 12:13:46 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-06 12:07:36 ----HD---- C:\WINDOWS
2011-08-06 11:35:29 ----SHD---- C:\WINDOWS\Installer
2011-08-06 11:15:20 ----D---- C:\Program Files\Mozilla Firefox
2011-08-06 11:14:17 ----D---- C:\WINDOWS\system32
2011-08-06 03:04:29 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-06 03:01:35 ----D---- C:\WINDOWS\Prefetch
2011-08-04 12:02:04 ----D---- C:\Documents and Settings\miki\Data aplikací\vlc
2011-08-04 02:18:44 ----A---- C:\WINDOWS\NeroDigital.ini
2011-08-03 05:52:35 ----A---- C:\Settings.ini
2011-08-01 22:16:04 ----D---- C:\Downloads
2011-07-31 17:23:48 ----HD---- C:\totalcmd
2011-07-29 03:02:09 ----D---- C:\WINDOWS\WinSxS
2011-07-27 02:44:53 ----HD---- C:\WINDOWS\inf
2011-07-26 11:16:05 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-07-26 11:09:45 ----D---- C:\WINDOWS\ERDNT
2011-07-26 11:08:34 ----N---- C:\WINDOWS\system.ini
2011-07-26 11:07:25 ----D---- C:\WINDOWS\system32\drivers\etc
2011-07-26 11:06:19 ----D---- C:\WINDOWS\system32\config
2011-07-26 11:03:56 ----D---- C:\WINDOWS\AppPatch
2011-07-26 11:03:54 ----D---- C:\Program Files\Common Files
2011-07-26 11:03:29 ----D---- C:\WINDOWS\system32\wbem
2011-07-24 02:37:27 ----D---- C:\Program Files\uTorrent
2011-07-23 13:54:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-07-23 11:33:16 ----D---- C:\Program Files\Alwil Software
2011-07-23 11:25:26 ----HD---- C:\Documents and Settings
2011-07-20 14:01:30 ----D---- C:\Program Files\Spyware Terminator
2011-07-16 14:42:45 ----D---- C:\tor
2011-07-16 14:33:42 ----D---- C:\WINDOWS\Debug
2011-07-14 15:01:45 ----D---- C:\Program Files\Microsoft Bootvis
2011-07-14 14:36:42 ----RSHD---- C:\WINDOWS\system32\dllcache
2011-07-14 14:33:52 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 a347bus;a347bus; C:\WINDOWS\system32\DRIVERS\a347bus.sys [2004-04-30 160640]
R0 a347scsi;a347scsi; C:\WINDOWS\System32\Drivers\a347scsi.sys [2004-04-30 5248]
R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 risdptsk;risdptsk; C:\WINDOWS\system32\DRIVERS\risdptsk.sys [2005-07-14 27904]
R0 SmartDefragDriver;SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [2011-02-23 13496]
R0 snapman;Acronis Snapshots Manager; C:\WINDOWS\system32\DRIVERS\snapman.sys [2009-02-25 129248]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 tdrpman;Acronis Try&Decide and Restore Points filter; C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2009-02-25 368736]
R0 timounter;Acronis True Image Backup Archive Explorer; C:\WINDOWS\system32\DRIVERS\timntr.sys [2009-02-25 441760]
R1 CFRMD;CFRMD; C:\WINDOWS\system32\DRIVERS\CFRMD.sys [2010-12-09 66584]
R1 CFRPD;CFRPD; C:\WINDOWS\system32\DRIVERS\CFRPD.sys [2010-12-09 33232]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKsl81fe7e55;MpKsl81fe7e55; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\MpKsl81fe7e55.sys []
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2010-02-11 226880]
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.5.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2009-02-25 21419]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2011-01-11 281760]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2011-01-11 25888]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2006-08-02 12544]
R2 tifsfilter;Acronis True Image FS Filter; C:\WINDOWS\system32\DRIVERS\tifsfilt.sys [2009-02-25 44384]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 Cam5603D;BisonCam, NB Pro; C:\WINDOWS\System32\Drivers\BisonCam.sys [2005-04-18 646656]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-09-08 3959808]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-18 5632]
R3 NETw3x32;Ovladač adaptéru Intel(R) PRO/Wireless 3945ABG pro Windows XP 32 Bit; C:\WINDOWS\system32\DRIVERS\NETw3x32.sys [2006-09-27 1709696]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-11-21 3600512]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2005-11-16 78976]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-05-26 839724]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2005-10-21 191936]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
R3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2005-11-22 108800]
R3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-09-15 36480]
R3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2005-12-01 62848]
R3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
R3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2005-11-15 36736]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 MpKsl19898a96;MpKsl19898a96; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys []
S1 MpKslddeb1f73;MpKslddeb1f73; \??\C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys []
S3 ASFWHide;ASFWHide; \??\C:\DOCUME~1\miki\LOCALS~1\Temp\ASFWHide []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver; C:\WINDOWS\system32\DRIVERS\w39n51.sys []
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 vsdatant;vsdatant; C:\WINDOWS\system32\drivers\vsdatant.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2007-10-23 427288]
R2 Cleaner_Validator;COMODO System - Cleaner Service; C:\Program Files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [2010-12-09 305600]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2006-08-02 434176]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-02-25 152984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-06-21 53248]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-11-21 143426]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2006-08-02 327680]
R2 S24EventMonitor;Intel(R) PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2006-08-02 937984]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-02-25 984576]
R2 TryAndDecideService;Acronis Try And Decide Service; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2007-10-23 495832]
R2 UxTuneUp;TuneUp Design Expansion; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Také zdravím!
Toto je OK. Dejte ještě log z ComboFix.
Toto je OK. Dejte ještě log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
pote spustte aplikaci pod uctem s administratorskym opravnenim
hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.
v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se
jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine
aplikace ani nic jineho
behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)
upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,
pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k
nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
ComboFix 11-08-06.02 - miki 06.08.2011 21:23:39.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.812 [GMT 2:00]
Spuštěný z: c:\documents and settings\miki\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\miki\Data aplikací\dach100.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-06 do 2011-08-06 )))))))))))))))))))))))))))))))
.
.
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- c:\program files\trend micro
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- C:\rsit
2011-08-06 10:25 . 2011-08-06 10:26 781383 ----a-w- C:\RSIT.exe
2011-08-06 10:18 . 2011-08-06 10:18 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\MpKsl81fe7e55.sys
2011-08-06 09:14 . 2006-07-04 13:36 61440 ----a-w- c:\windows\system32\FTChipID.dll
2011-08-06 09:13 . 2011-08-06 10:29 -------- d-----w- c:\program files\WGSoft
2011-08-06 09:13 . 2011-08-06 09:13 -------- d-----w- c:\documents and settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-06 09:09 . 2011-08-06 09:10 3495365 ----a-w- C:\EasyObdII_Ver2_3_0.exe
2011-08-06 09:08 . 2011-08-06 09:08 462297 ----a-w- C:\scantool_net115win.exe
2011-08-02 08:32 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-02 08:31 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\mpengine.dll
2011-08-01 14:28 . 2011-08-01 14:28 -------- d-----w- c:\program files\Lamer
2011-08-01 14:23 . 2011-08-01 14:23 286842 ----a-w- C:\lamersetup.exe
2011-08-01 14:18 . 2011-08-01 14:21 3696770 ----a-w- C:\gwave558.exe
2011-07-31 22:47 . 2011-07-31 22:47 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Apple Computer
2011-07-31 15:23 . 2011-07-31 15:23 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Help
2011-07-31 13:06 . 2011-08-04 09:58 -------- d-----w- C:\symbian
2011-07-27 10:48 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-27 10:48 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-26 09:27 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-26 09:15 . 2011-07-26 09:16 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-23 09:27 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-23 09:27 . 2011-07-25 23:47 -------- d-----w- c:\program files\AVAST Software
2011-07-23 09:27 . 2011-07-23 09:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-07-23 09:25 . 2011-07-23 09:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\BlackHawk
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\program files\NETGATE
2011-07-10 14:45 . 2011-07-10 15:18 -------- d-----w- c:\program files\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-06 09:11 . 2011-08-06 09:09 11371776 ----a-w- C:\ScanMasterELM_DEMO_2.0.zip
2011-08-06 09:10 . 2011-08-06 09:09 2470792 ----a-w- C:\FULwOBD.ZIP
2011-08-06 09:09 . 2011-08-06 09:09 1261007 ----a-w- C:\CDM20802 WHQL Certified.zip
2011-08-01 14:23 . 2011-08-01 14:23 218046 ----a-w- C:\mpTrim.zip
2011-07-31 15:46 . 2011-07-31 15:45 1737986 ----a-w- C:\p3e0dfc590f7ff54ad33bd716061e0a79.zip
2011-06-06 11:35 . 2004-11-20 10:14 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 16:59 . 2011-05-08 13:50 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-07-26_09.08.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-18 20:51 . 2011-04-18 20:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-08-06 10:18 . 2011-08-06 10:18 16384 c:\windows\Temp\Perflib_Perfdata_4c8.dat
+ 2011-07-26 09:16 . 2011-07-26 09:16 49152 c:\windows\Installer\81f8b.msi
+ 2011-07-26 09:16 . 2011-07-26 09:16 28160 c:\windows\Installer\81f7c.msi
+ 2011-05-14 13:53 . 2011-08-06 10:17 49457 c:\windows\cscmondump.bin
+ 2011-04-18 20:51 . 2011-04-18 20:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-04-18 11:18 . 2011-04-18 11:18 165648 c:\windows\system32\drivers\MpFilter.sys
+ 2011-07-26 09:16 . 2011-07-26 09:16 785920 c:\windows\Installer\81f82.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 483840 c:\windows\Installer\81f75.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 301056 c:\windows\Installer\81f6f.msi
+ 2011-07-29 01:02 . 2011-07-29 01:02 223744 c:\windows\Installer\456c6c3.msi
+ 2011-01-11 11:10 . 2011-08-06 10:17 247964 c:\windows\CSC_ServiceDump.dat
+ 2011-04-18 20:51 . 2011-04-18 20:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-01-11 11:10 . 2011-08-06 10:17 1880208 c:\windows\CSC_ActiveCleanLog.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"speedfan"="c:\program files\SpeedFan\speedfan.exe" [2008-04-22 3287552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-13 399736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-07-28 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-02-24 2834432]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\miki\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"SMSERIAL"=sm56hlpr.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [25.2.2009 17:28 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25.2.2009 17:28 5248]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [19.4.2011 17:36 13496]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [9.12.2010 14:14 66584]
R1 CFRPD;CFRPD;c:\windows\system32\drivers\CFRPD.sys [9.12.2010 14:15 33232]
R1 MpKsl81fe7e55;MpKsl81fe7e55;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\MpKsl81fe7e55.sys [6.8.2011 12:18 28752]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.2.2009 0:40 138752]
S1 MpKsl19898a96;MpKsl19898a96;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys [?]
S1 MpKslddeb1f73;MpKslddeb1f73;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys [?]
S2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [9.12.2010 14:08 305600]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL81FE7E55
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
2011-08-06 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2011-08-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-08-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-05 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.asus.com
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=6&app=inclient&version=8.0.065.000&lang=en&locale=cs-CZ&date=-86400&link_id=9&dest=welcome&lic=j5hvqhisiu3s4he7bhx644bu4g0
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - user.js: nglayout.initialpaint.delay - 300
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-06 21:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\docume~1\miki\LOCALS~1\Temp\SkypeSetup.exe 19446152 bytes executable
c:\docume~1\miki\LOCALS~1\Temp\~DF60A.tmp 16384 bytes
c:\windows\TEMP\MpCmdRun.log 13818 bytes
c:\windows\TEMP\MpSigStub.log 3302 bytes
.
sken byl úspešně dokončen
skryté soubory: 4
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\miki\LOCALS~1\Temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="75CD3D7CFCD1D8D12AC306059B9B98A450966931C6EC00CEC8F4787DF39DEC93407322A3F7B3BB850983494187E550F448FA3C928825647666276840B23F33735CF668367F0C6ACC4EB3E310EBAA6E0FECBEBA930750EDB23571FCB7542949F0F57E40C6F9C4C522A6E7B200C4949136918A0DD774FA18314F2E4FC2E0E727C38831CC8AE30CE366143C03BEA2930D935D88D0AA17F393849D39E8E2714CF985E33EA35ECBD48D5C6B4E1B22A95AE633CAE91777C4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555C038D530D6EB345224BB663D6A8383CB5BF77613F4EC19CA007899D8BF33CAA9FB68A77E191B4D463504952B78708CF1121CEAE10E76603B056BBE004E20DD962B3A4F82A221ADC5FD54241D9A45F8A10CCB3BA4B2235E244C9053C7A99306497BCFB998ECFEB3C3082DABDF877DF37995C44CCCAB3CD8D584822668CD44406999C03CDD417A34DA22442D9778884EA73C7A67234600B6B49D91E7EAB4DA2F2FF5DB12C2ECC92B395F838CB7AC4B7BF1D491B6404F1D86BCCABFADB2DFF7986A489E580C4196B8A493880F8AE89D132FF4664D149D3B79F80547F0F154AA67FC86C092D316039D725AA462AEF04BD1CB7A879CE10670630B09910F2F1B7BA65DF028A684411EC28E125D1495901517C901B500BFE4CBBDA8553FC9C7BF628A9406735FE0A4F03177DB6C1904962DE73B6DE832971BCEA49A2EA3466B534E68430CF16A7D1E7799421F3F4894D43D6A4AE74BD2A98BEB5A3F1E450F9DEA223B998CA7DB429620CD9485F65B3623E1EB32593C68081D8E4386ED600F359EB29EDE54CEA7EB75CB442BFC69F4A8DB29DA43F2CC5A1ABC92E776B06519600B4AD6ECF3D2A90D29549952B6A016025D18CC61A744F41A594AF32838F5E31CD127C8B1C154A00823830BF0AA5927AD8A28F806AC9D6897E6793B491FEA863E177BFC31D528AD17D9197CFC920673E74942B9BC7E85C9735D59B01A3F50006D036CA37F0ED6D8C5C547F4016B4B2AC305C812A5DC6090E53796ED71B964312542950EC78A1C0BF6E5351E9DF8035E252D0FA3754A4599F974533037F29A5E378603314932E9935D3A7DC704BF3A09C6B15DB6748DFCA58D992457E8131C33450339A7542D632583C9B0E57C8BB303378CEFB7FEB286D9D32E92E7988542BBC7F12B2F516861D4C49E500DE3E9E38DD6367536040994BC54BC990C6AFB1F690B8EC5A9B814F11E5144D37928AC74CB5D2E136689210E3C68562C1119687312AD1AE49C99A8525FB04E278ACB69C3C4D276E09F27D50D27BF8DAF667084396E2559DBB2175B7B5AB8512841E6FB626495176ADD09BFDFB3DCFAFA22D2CC1A9CB71570B966AC91B5"
"OODEFRAG11.00.00.01WORKSTATION"="BFD22B63C8B48655597B365DFDC94074F3B5B3A041895098346461B6B6C6F275C8AFC321254798744B48D3597E157778783E7758C75973AFBCE9D3B1444ED0750DDF653F76BDB8C70877F0D7758A8E43F863B81E85FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B98084C99319E531D1CA20FDF1F2A5B8AC2E5130FE5C3FDAA5CF6425A1547122EAB257CA180C79ED214DCA7484B07E6216FBF4CD5F4401CF5639DC4EEFABC8AE24DAEFB158EBE665A3BA5BB3ED5BA1EA675130938BE61443F1F12985FE0F002DCDACAC5206E65A3EA8541A6CBBA6D29440278A63E4BB46E3B96613AD2F577637B531A1827997352B30C8208B15D1AB3906798C5248319198FF3286D214EB59D925AD175C0EB74F1D28C5445E30210711C9AB0CC5B3844C558089B37596065A2EA3839A7B626460660E633078951749367B41664871A417A234382E23A8894E8BE57ACB607EC9B16E2A0B0B77DD9BE556A762DF801BF694074BD38FD3C86A3EB414B9DF4E4C7FAADD862F1094F0D39F10DC0EF3CD5A36F25C332AA5A88FBC9AA93C48E73B7A340DCB2F9AFED44BF852AAD18EC23C424D6BB7980DE8D7B729026CF9C98099851193655D6381FD0AB17439E27476743837A97F6A96B73A653D5E6004E6852560589539A0FEB9824EDB406A6BBB405F86805548F56FBA9CF6F4BF5257A3DAD74D567CDCE5A411B9A08FA3EFEC7FEBE445DF70E0850CF9170F8F66334656D3EA842DC473317C02BC95F59BDD5E20618B350A8671D873AD1378831C114755EEBDCA9EA62FCC5860FF7BE1457CDC3B95B8C14BF867E0EA15505992926A0388E60314FE1465589C55421D0C165FB4B229548DFB8124C9B8149ED8AE02C2BDB8D0C76DDE99F58ADC2CA75A8CFC36AF8D797124C653CA009E91F3D1F2D7376B5002235607C9D171E5786573CFC5398748BF6CB58EA3384577E0EEFFEB79CBABC9C19A5C7EA7318EBF0DFDEE25D79F6877D0C87E7C1AE7829751138357FD0A40EB2AB38E7555A534B90F2D7DCD81D6B1E06F490BFB666EE459964F8B155B8D3689FD98E79340C36164A20C1492AABD1CC8D91610A6A1A4E164B0CCF475F03DB30D8677E19D148A1C8480BCEADE296F6C79288ACD6518971AA7D4C07AD1763C56D65D994C7CC54E904C89BE8F465521CE927425597B47B29B6B7B0A100CA8F0CCB64FD0EE718F6580E1C00A96BE957F73073EBF32231B9378F9587D4BE9BC3211B8361DD43F97B2BCD272561C27C21B53DAFF6D531B7915231C4E189CBFEBC66CE885829078D3292D064429210FB3271562B18FAE30D53A63B0B165E7040BEB500CA7A4C41C16FB24960CD764D1E0E3FE6C7C8973C49D6526E3D402455"
.
Celkový čas: 2011-08-06 21:29:42
ComboFix-quarantined-files.txt 2011-08-06 19:29
.
Před spuštěním: 4 295 367 680
Po spuštění: 4 367 523 328
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 5A9CFD42BEDB1B0A7A6B4BC12860D531
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.812 [GMT 2:00]
Spuštěný z: c:\documents and settings\miki\Plocha\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\miki\Data aplikací\dach100.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-06 do 2011-08-06 )))))))))))))))))))))))))))))))
.
.
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- c:\program files\trend micro
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- C:\rsit
2011-08-06 10:25 . 2011-08-06 10:26 781383 ----a-w- C:\RSIT.exe
2011-08-06 10:18 . 2011-08-06 10:18 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\MpKsl81fe7e55.sys
2011-08-06 09:14 . 2006-07-04 13:36 61440 ----a-w- c:\windows\system32\FTChipID.dll
2011-08-06 09:13 . 2011-08-06 10:29 -------- d-----w- c:\program files\WGSoft
2011-08-06 09:13 . 2011-08-06 09:13 -------- d-----w- c:\documents and settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-06 09:09 . 2011-08-06 09:10 3495365 ----a-w- C:\EasyObdII_Ver2_3_0.exe
2011-08-06 09:08 . 2011-08-06 09:08 462297 ----a-w- C:\scantool_net115win.exe
2011-08-02 08:32 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-02 08:31 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\mpengine.dll
2011-08-01 14:28 . 2011-08-01 14:28 -------- d-----w- c:\program files\Lamer
2011-08-01 14:23 . 2011-08-01 14:23 286842 ----a-w- C:\lamersetup.exe
2011-08-01 14:18 . 2011-08-01 14:21 3696770 ----a-w- C:\gwave558.exe
2011-07-31 22:47 . 2011-07-31 22:47 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Apple Computer
2011-07-31 15:23 . 2011-07-31 15:23 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Help
2011-07-31 13:06 . 2011-08-04 09:58 -------- d-----w- C:\symbian
2011-07-27 10:48 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-27 10:48 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-26 09:27 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-26 09:15 . 2011-07-26 09:16 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-23 09:27 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-23 09:27 . 2011-07-25 23:47 -------- d-----w- c:\program files\AVAST Software
2011-07-23 09:27 . 2011-07-23 09:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-07-23 09:25 . 2011-07-23 09:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\BlackHawk
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\program files\NETGATE
2011-07-10 14:45 . 2011-07-10 15:18 -------- d-----w- c:\program files\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-06 09:11 . 2011-08-06 09:09 11371776 ----a-w- C:\ScanMasterELM_DEMO_2.0.zip
2011-08-06 09:10 . 2011-08-06 09:09 2470792 ----a-w- C:\FULwOBD.ZIP
2011-08-06 09:09 . 2011-08-06 09:09 1261007 ----a-w- C:\CDM20802 WHQL Certified.zip
2011-08-01 14:23 . 2011-08-01 14:23 218046 ----a-w- C:\mpTrim.zip
2011-07-31 15:46 . 2011-07-31 15:45 1737986 ----a-w- C:\p3e0dfc590f7ff54ad33bd716061e0a79.zip
2011-06-06 11:35 . 2004-11-20 10:14 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 16:59 . 2011-05-08 13:50 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-13 18:40 . !HASH: COULD NOT OPEN FILE !!!!! . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-07-26_09.08.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-18 20:51 . 2011-04-18 20:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-08-06 10:18 . 2011-08-06 10:18 16384 c:\windows\Temp\Perflib_Perfdata_4c8.dat
+ 2011-07-26 09:16 . 2011-07-26 09:16 49152 c:\windows\Installer\81f8b.msi
+ 2011-07-26 09:16 . 2011-07-26 09:16 28160 c:\windows\Installer\81f7c.msi
+ 2011-05-14 13:53 . 2011-08-06 10:17 49457 c:\windows\cscmondump.bin
+ 2011-04-18 20:51 . 2011-04-18 20:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-04-18 11:18 . 2011-04-18 11:18 165648 c:\windows\system32\drivers\MpFilter.sys
+ 2011-07-26 09:16 . 2011-07-26 09:16 785920 c:\windows\Installer\81f82.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 483840 c:\windows\Installer\81f75.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 301056 c:\windows\Installer\81f6f.msi
+ 2011-07-29 01:02 . 2011-07-29 01:02 223744 c:\windows\Installer\456c6c3.msi
+ 2011-01-11 11:10 . 2011-08-06 10:17 247964 c:\windows\CSC_ServiceDump.dat
+ 2011-04-18 20:51 . 2011-04-18 20:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-01-11 11:10 . 2011-08-06 10:17 1880208 c:\windows\CSC_ActiveCleanLog.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"speedfan"="c:\program files\SpeedFan\speedfan.exe" [2008-04-22 3287552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-13 399736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-07-28 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-02-24 2834432]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\miki\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"SMSERIAL"=sm56hlpr.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [25.2.2009 17:28 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25.2.2009 17:28 5248]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [19.4.2011 17:36 13496]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [9.12.2010 14:14 66584]
R1 CFRPD;CFRPD;c:\windows\system32\drivers\CFRPD.sys [9.12.2010 14:15 33232]
R1 MpKsl81fe7e55;MpKsl81fe7e55;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5AAE4FB0-4BF4-41F9-97A5-6B894925CF71}\MpKsl81fe7e55.sys [6.8.2011 12:18 28752]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.2.2009 0:40 138752]
S1 MpKsl19898a96;MpKsl19898a96;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys [?]
S1 MpKslddeb1f73;MpKslddeb1f73;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys [?]
S2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [9.12.2010 14:08 305600]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL81FE7E55
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
2011-08-06 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2011-08-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-08-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-05 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.asus.com
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=6&app=inclient&version=8.0.065.000&lang=en&locale=cs-CZ&date=-86400&link_id=9&dest=welcome&lic=j5hvqhisiu3s4he7bhx644bu4g0
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - user.js: nglayout.initialpaint.delay - 300
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-06 21:27
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
.
c:\docume~1\miki\LOCALS~1\Temp\SkypeSetup.exe 19446152 bytes executable
c:\docume~1\miki\LOCALS~1\Temp\~DF60A.tmp 16384 bytes
c:\windows\TEMP\MpCmdRun.log 13818 bytes
c:\windows\TEMP\MpSigStub.log 3302 bytes
.
sken byl úspešně dokončen
skryté soubory: 4
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\miki\LOCALS~1\Temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="75CD3D7CFCD1D8D12AC306059B9B98A450966931C6EC00CEC8F4787DF39DEC93407322A3F7B3BB850983494187E550F448FA3C928825647666276840B23F33735CF668367F0C6ACC4EB3E310EBAA6E0FECBEBA930750EDB23571FCB7542949F0F57E40C6F9C4C522A6E7B200C4949136918A0DD774FA18314F2E4FC2E0E727C38831CC8AE30CE366143C03BEA2930D935D88D0AA17F393849D39E8E2714CF985E33EA35ECBD48D5C6B4E1B22A95AE633CAE91777C4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555C038D530D6EB345224BB663D6A8383CB5BF77613F4EC19CA007899D8BF33CAA9FB68A77E191B4D463504952B78708CF1121CEAE10E76603B056BBE004E20DD962B3A4F82A221ADC5FD54241D9A45F8A10CCB3BA4B2235E244C9053C7A99306497BCFB998ECFEB3C3082DABDF877DF37995C44CCCAB3CD8D584822668CD44406999C03CDD417A34DA22442D9778884EA73C7A67234600B6B49D91E7EAB4DA2F2FF5DB12C2ECC92B395F838CB7AC4B7BF1D491B6404F1D86BCCABFADB2DFF7986A489E580C4196B8A493880F8AE89D132FF4664D149D3B79F80547F0F154AA67FC86C092D316039D725AA462AEF04BD1CB7A879CE10670630B09910F2F1B7BA65DF028A684411EC28E125D1495901517C901B500BFE4CBBDA8553FC9C7BF628A9406735FE0A4F03177DB6C1904962DE73B6DE832971BCEA49A2EA3466B534E68430CF16A7D1E7799421F3F4894D43D6A4AE74BD2A98BEB5A3F1E450F9DEA223B998CA7DB429620CD9485F65B3623E1EB32593C68081D8E4386ED600F359EB29EDE54CEA7EB75CB442BFC69F4A8DB29DA43F2CC5A1ABC92E776B06519600B4AD6ECF3D2A90D29549952B6A016025D18CC61A744F41A594AF32838F5E31CD127C8B1C154A00823830BF0AA5927AD8A28F806AC9D6897E6793B491FEA863E177BFC31D528AD17D9197CFC920673E74942B9BC7E85C9735D59B01A3F50006D036CA37F0ED6D8C5C547F4016B4B2AC305C812A5DC6090E53796ED71B964312542950EC78A1C0BF6E5351E9DF8035E252D0FA3754A4599F974533037F29A5E378603314932E9935D3A7DC704BF3A09C6B15DB6748DFCA58D992457E8131C33450339A7542D632583C9B0E57C8BB303378CEFB7FEB286D9D32E92E7988542BBC7F12B2F516861D4C49E500DE3E9E38DD6367536040994BC54BC990C6AFB1F690B8EC5A9B814F11E5144D37928AC74CB5D2E136689210E3C68562C1119687312AD1AE49C99A8525FB04E278ACB69C3C4D276E09F27D50D27BF8DAF667084396E2559DBB2175B7B5AB8512841E6FB626495176ADD09BFDFB3DCFAFA22D2CC1A9CB71570B966AC91B5"
"OODEFRAG11.00.00.01WORKSTATION"="BFD22B63C8B48655597B365DFDC94074F3B5B3A041895098346461B6B6C6F275C8AFC321254798744B48D3597E157778783E7758C75973AFBCE9D3B1444ED0750DDF653F76BDB8C70877F0D7758A8E43F863B81E85FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B98084C99319E531D1CA20FDF1F2A5B8AC2E5130FE5C3FDAA5CF6425A1547122EAB257CA180C79ED214DCA7484B07E6216FBF4CD5F4401CF5639DC4EEFABC8AE24DAEFB158EBE665A3BA5BB3ED5BA1EA675130938BE61443F1F12985FE0F002DCDACAC5206E65A3EA8541A6CBBA6D29440278A63E4BB46E3B96613AD2F577637B531A1827997352B30C8208B15D1AB3906798C5248319198FF3286D214EB59D925AD175C0EB74F1D28C5445E30210711C9AB0CC5B3844C558089B37596065A2EA3839A7B626460660E633078951749367B41664871A417A234382E23A8894E8BE57ACB607EC9B16E2A0B0B77DD9BE556A762DF801BF694074BD38FD3C86A3EB414B9DF4E4C7FAADD862F1094F0D39F10DC0EF3CD5A36F25C332AA5A88FBC9AA93C48E73B7A340DCB2F9AFED44BF852AAD18EC23C424D6BB7980DE8D7B729026CF9C98099851193655D6381FD0AB17439E27476743837A97F6A96B73A653D5E6004E6852560589539A0FEB9824EDB406A6BBB405F86805548F56FBA9CF6F4BF5257A3DAD74D567CDCE5A411B9A08FA3EFEC7FEBE445DF70E0850CF9170F8F66334656D3EA842DC473317C02BC95F59BDD5E20618B350A8671D873AD1378831C114755EEBDCA9EA62FCC5860FF7BE1457CDC3B95B8C14BF867E0EA15505992926A0388E60314FE1465589C55421D0C165FB4B229548DFB8124C9B8149ED8AE02C2BDB8D0C76DDE99F58ADC2CA75A8CFC36AF8D797124C653CA009E91F3D1F2D7376B5002235607C9D171E5786573CFC5398748BF6CB58EA3384577E0EEFFEB79CBABC9C19A5C7EA7318EBF0DFDEE25D79F6877D0C87E7C1AE7829751138357FD0A40EB2AB38E7555A534B90F2D7DCD81D6B1E06F490BFB666EE459964F8B155B8D3689FD98E79340C36164A20C1492AABD1CC8D91610A6A1A4E164B0CCF475F03DB30D8677E19D148A1C8480BCEADE296F6C79288ACD6518971AA7D4C07AD1763C56D65D994C7CC54E904C89BE8F465521CE927425597B47B29B6B7B0A100CA8F0CCB64FD0EE718F6580E1C00A96BE957F73073EBF32231B9378F9587D4BE9BC3211B8361DD43F97B2BCD272561C27C21B53DAFF6D531B7915231C4E189CBFEBC66CE885829078D3292D064429210FB3271562B18FAE30D53A63B0B165E7040BEB500CA7A4C41C16FB24960CD764D1E0E3FE6C7C8973C49D6526E3D402455"
.
Celkový čas: 2011-08-06 21:29:42
ComboFix-quarantined-files.txt 2011-08-06 19:29
.
Před spuštěním: 4 295 367 680
Po spuštění: 4 367 523 328
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 5A9CFD42BEDB1B0A7A6B4BC12860D531
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:

Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.Collect::
c:\docume~1\miki\LOCALS~1\Temp\~DF60A.tmp
FCopy::
c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys | c:\windows\system32\drivers\atapi.sys

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
ComboFix 11-08-06.02 - miki 07.08.2011 12:16:42.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.901 [GMT 2:00]
Spuštěný z: c:\documents and settings\miki\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\miki\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\miki\Data aplikací\dach100.dll
.
.
--------------- FCopy ---------------
.
c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-07 do 2011-08-07 )))))))))))))))))))))))))))))))
.
.
2011-08-07 10:23 . 2011-08-07 10:23 64512 ---ha-w- c:\documents and settings\miki\Data aplikací\dach100.dll
2011-08-07 01:02 . 2011-08-07 01:02 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-08-06 23:48 . 2011-08-06 23:48 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2011-08-06 19:53 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DA7A3350-D9FC-4A6F-968A-5D123066E385}\mpengine.dll
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- c:\program files\trend micro
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- C:\rsit
2011-08-06 10:25 . 2011-08-06 10:26 781383 ----a-w- C:\RSIT.exe
2011-08-06 09:14 . 2006-07-04 13:36 61440 ----a-w- c:\windows\system32\FTChipID.dll
2011-08-06 09:13 . 2011-08-06 10:29 -------- d-----w- c:\program files\WGSoft
2011-08-06 09:13 . 2011-08-06 09:13 -------- d-----w- c:\documents and settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-06 09:09 . 2011-08-06 09:10 3495365 ----a-w- C:\EasyObdII_Ver2_3_0.exe
2011-08-06 09:08 . 2011-08-06 09:08 462297 ----a-w- C:\scantool_net115win.exe
2011-08-02 08:32 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-01 14:28 . 2011-08-01 14:28 -------- d-----w- c:\program files\Lamer
2011-08-01 14:23 . 2011-08-01 14:23 286842 ----a-w- C:\lamersetup.exe
2011-08-01 14:18 . 2011-08-01 14:21 3696770 ----a-w- C:\gwave558.exe
2011-07-31 22:47 . 2011-07-31 22:47 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Apple Computer
2011-07-31 15:23 . 2011-07-31 15:23 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Help
2011-07-31 13:06 . 2011-08-04 09:58 -------- d-----w- C:\symbian
2011-07-27 10:48 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-27 10:48 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-26 09:27 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-26 09:15 . 2011-07-26 09:16 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-23 09:27 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-23 09:27 . 2011-07-25 23:47 -------- d-----w- c:\program files\AVAST Software
2011-07-23 09:27 . 2011-07-23 09:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-07-23 09:25 . 2011-07-23 09:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\BlackHawk
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\program files\NETGATE
2011-07-10 14:45 . 2011-07-10 15:18 -------- d-----w- c:\program files\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-06 09:11 . 2011-08-06 09:09 11371776 ----a-w- C:\ScanMasterELM_DEMO_2.0.zip
2011-08-06 09:10 . 2011-08-06 09:09 2470792 ----a-w- C:\FULwOBD.ZIP
2011-08-06 09:09 . 2011-08-06 09:09 1261007 ----a-w- C:\CDM20802 WHQL Certified.zip
2011-08-01 14:23 . 2011-08-01 14:23 218046 ----a-w- C:\mpTrim.zip
2011-07-31 15:46 . 2011-07-31 15:45 1737986 ----a-w- C:\p3e0dfc590f7ff54ad33bd716061e0a79.zip
2011-06-06 11:35 . 2004-11-20 10:14 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 16:59 . 2011-05-08 13:50 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-18 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-07-26_09.08.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-18 20:51 . 2011-04-18 20:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-05-13 18:17 . 2011-05-13 18:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-13 23:06 . 2011-05-13 23:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-13 23:23 . 2011-05-13 23:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 16:37 . 2011-05-13 16:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2011-08-07 10:23 . 2011-08-07 10:23 16384 c:\windows\Temp\Perflib_Perfdata_794.dat
+ 2011-07-26 09:16 . 2011-07-26 09:16 49152 c:\windows\Installer\81f8b.msi
+ 2011-07-26 09:16 . 2011-07-26 09:16 28160 c:\windows\Installer\81f7c.msi
+ 2011-05-14 13:53 . 2011-08-07 10:22 66067 c:\windows\cscmondump.bin
+ 2011-04-18 20:51 . 2011-04-18 20:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-05-13 23:17 . 2011-05-13 23:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-13 23:12 . 2011-05-13 23:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-13 23:11 . 2011-05-13 23:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
+ 2011-04-18 11:18 . 2011-04-18 11:18 165648 c:\windows\system32\drivers\MpFilter.sys
+ 2011-07-26 09:16 . 2011-07-26 09:16 785920 c:\windows\Installer\81f82.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 483840 c:\windows\Installer\81f75.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 301056 c:\windows\Installer\81f6f.msi
+ 2011-07-29 01:02 . 2011-07-29 01:02 223744 c:\windows\Installer\456c6c3.msi
+ 2011-08-07 01:02 . 2011-08-07 01:02 470528 c:\windows\Installer\3285cb2.msi
+ 2011-08-07 01:01 . 2011-08-07 01:01 467456 c:\windows\Installer\3285ca6.msi
+ 2011-01-11 11:10 . 2011-08-07 10:22 265618 c:\windows\CSC_ServiceDump.dat
+ 2011-04-18 20:51 . 2011-04-18 20:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-05-13 18:04 . 2011-05-13 18:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-13 18:04 . 2011-05-13 18:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2011-01-11 11:10 . 2011-08-07 10:22 1893786 c:\windows\CSC_ActiveCleanLog.dat
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"speedfan"="c:\program files\SpeedFan\speedfan.exe" [2008-04-22 3287552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-13 399736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-07-28 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-02-24 2834432]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\miki\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"SMSERIAL"=sm56hlpr.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [25.2.2009 17:28 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25.2.2009 17:28 5248]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [19.4.2011 17:36 13496]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [9.12.2010 14:14 66584]
R1 CFRPD;CFRPD;c:\windows\system32\drivers\CFRPD.sys [9.12.2010 14:15 33232]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.2.2009 0:40 138752]
R2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [9.12.2010 14:08 305600]
S1 MpKsl19898a96;MpKsl19898a96;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys [?]
S1 MpKslddeb1f73;MpKslddeb1f73;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys [?]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
FastUserSwitchingCompatibility
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Schedule
Seclogon
SRService
Themes
TrkWks
W32Time
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
BITS
wuauserv
ShellHWDetection
helpsvc
napagent
hkmsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
2011-08-07 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2011-08-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-08-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-05 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.asus.com
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=6&app=inclient&version=8.0.065.000&lang=en&locale=cs-CZ&date=-86400&link_id=9&dest=welcome&lic=j5hvqhisiu3s4he7bhx644bu4g0
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - user.js: nglayout.initialpaint.delay - 300
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-07 12:23
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\miki\LOCALS~1\Temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="75CD3D7CFCD1D8D12AC306059B9B98A450966931C6EC00CEC8F4787DF39DEC93407322A3F7B3BB850983494187E550F448FA3C928825647666276840B23F33735CF668367F0C6ACC4EB3E310EBAA6E0FECBEBA930750EDB23571FCB7542949F0F57E40C6F9C4C522A6E7B200C4949136918A0DD774FA18314F2E4FC2E0E727C38831CC8AE30CE366143C03BEA2930D935D88D0AA17F393849D39E8E2714CF985E33EA35ECBD48D5C6B4E1B22A95AE633CAE91777C4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555C038D530D6EB345224BB663D6A8383CB5BF77613F4EC19CA007899D8BF33CAA9FB68A77E191B4D463504952B78708CF1121CEAE10E76603B056BBE004E20DD962B3A4F82A221ADC5FD54241D9A45F8A10CCB3BA4B2235E244C9053C7A99306497BCFB998ECFEB3C3082DABDF877DF37995C44CCCAB3CD8D584822668CD44406999C03CDD417A34DA22442D9778884EA73C7A67234600B6B49D91E7EAB4DA2F2FF5DB12C2ECC92B395F838CB7AC4B7BF1D491B6404F1D86BCCABFADB2DFF7986A489E580C4196B8A493880F8AE89D132FF4664D149D3B79F80547F0F154AA67FC86C092D316039D725AA462AEF04BD1CB7A879CE10670630B09910F2F1B7BA65DF028A684411EC28E125D1495901517C901B500BFE4CBBDA8553FC9C7BF628A9406735FE0A4F03177DB6C1904962DE73B6DE832971BCEA49A2EA3466B534E68430CF16A7D1E7799421F3F4894D43D6A4AE74BD2A98BEB5A3F1E450F9DEA223B998CA7DB429620CD9485F65B3623E1EB32593C68081D8E4386ED600F359EB29EDE54CEA7EB75CB442BFC69F4A8DB29DA43F2CC5A1ABC92E776B06519600B4AD6ECF3D2A90D29549952B6A016025D18CC61A744F41A594AF32838F5E31CD127C8B1C154A00823830BF0AA5927AD8A28F806AC9D6897E6793B491FEA863E177BFC31D528AD17D9197CFC920673E74942B9BC7E85C9735D59B01A3F50006D036CA37F0ED6D8C5C547F4016B4B2AC305C812A5DC6090E53796ED71B964312542950EC78A1C0BF6E5351E9DF8035E252D0FA3754A4599F974533037F29A5E378603314932E9935D3A7DC704BF3A09C6B15DB6748DFCA58D992457E8131C33450339A7542D632583C9B0E57C8BB303378CEFB7FEB286D9D32E92E7988542BBC7F12B2F516861D4C49E500DE3E9E38DD6367536040994BC54BC990C6AFB1F690B8EC5A9B814F11E5144D37928AC74CB5D2E136689210E3C68562C1119687312AD1AE49C99A8525FB04E278ACB69C3C4D276E09F27D50D27BF8DAF667084396E2559DBB2175B7B5AB8512841E6FB626495176ADD09BFDFB3DCFAFA22D2CC1A9CB71570B966AC91B5"
"OODEFRAG11.00.00.01WORKSTATION"="BFD22B63C8B48655597B365DFDC94074F3B5B3A041895098346461B6B6C6F275C8AFC321254798744B48D3597E157778783E7758C75973AFBCE9D3B1444ED0750DDF653F76BDB8C70877F0D7758A8E43F863B81E85FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B98084C99319E531D1CA20FDF1F2A5B8AC2E5130FE5C3FDAA5CF6425A1547122EAB257CA180C79ED214DCA7484B07E6216FBF4CD5F4401CF5639DC4EEFABC8AE24DAEFB158EBE665A3BA5BB3ED5BA1EA675130938BE61443F1F12985FE0F002DCDACAC5206E65A3EA8541A6CBBA6D29440278A63E4BB46E3B96613AD2F577637B531A1827997352B30C8208B15D1AB3906798C5248319198FF3286D214EB59D925AD175C0EB74F1D28C5445E30210711C9AB0CC5B3844C558089B37596065A2EA3839A7B626460660E633078951749367B41664871A417A234382E23A8894E8BE57ACB607EC9B16E2A0B0B77DD9BE556A762DF801BF694074BD38FD3C86A3EB414B9DF4E4C7FAADD862F1094F0D39F10DC0EF3CD5A36F25C332AA5A88FBC9AA93C48E73B7A340DCB2F9AFED44BF852AAD18EC23C424D6BB7980DE8D7B729026CF9C98099851193655D6381FD0AB17439E27476743837A97F6A96B73A653D5E6004E6852560589539A0FEB9824EDB406A6BBB405F86805548F56FBA9CF6F4BF5257A3DAD74D567CDCE5A411B9A08FA3EFEC7FEBE445DF70E0850CF9170F8F66334656D3EA842DC473317C02BC95F59BDD5E20618B350A8671D873AD1378831C114755EEBDCA9EA62FCC5860FF7BE1457CDC3B95B8C14BF867E0EA15505992926A0388E60314FE1465589C55421D0C165FB4B229548DFB8124C9B8149ED8AE02C2BDB8D0C76DDE99F58ADC2CA75A8CFC36AF8D797124C653CA009E91F3D1F2D7376B5002235607C9D171E5786573CFC5398748BF6CB58EA3384577E0EEFFEB79CBABC9C19A5C7EA7318EBF0DFDEE25D79F6877D0C87E7C1AE7829751138357FD0A40EB2AB38E7555A534B90F2D7DCD81D6B1E06F490BFB666EE459964F8B155B8D3689FD98E79340C36164A20C1492AABD1CC8D91610A6A1A4E164B0CCF475F03DB30D8677E19D148A1C8480BCEADE296F6C79288ACD6518971AA7D4C07AD1763C56D65D994C7CC54E904C89BE8F465521CE927425597B47B29B6B7B0A100CA8F0CCB64FD0EE718F6580E1C00A96BE957F73073EBF32231B9378F9587D4BE9BC3211B8361DD43F97B2BCD272561C27C21B53DAFF6D531B7915231C4E189CBFEBC66CE885829078D3292D064429210FB3271562B18FAE30D53A63B0B165E7040BEB500CA7A4C41C16FB24960CD764D1E0E3FE6C7C8973C49D6526E3D402455"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3564)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\windows\Integrator.exe
c:\windows\ATK0100\ATKOSD.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Celkový čas: 2011-08-07 12:27:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-07 10:27
ComboFix2.txt 2011-08-06 19:29
.
Před spuštěním: 4 291 267 072
Po spuštění: 4 315 252 736
.
- - End Of File - - 2D39A664142B689514BCCAC4A27220DC
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.901 [GMT 2:00]
Spuštěný z: c:\documents and settings\miki\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\miki\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\miki\Data aplikací\dach100.dll
.
.
--------------- FCopy ---------------
.
c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-07 do 2011-08-07 )))))))))))))))))))))))))))))))
.
.
2011-08-07 10:23 . 2011-08-07 10:23 64512 ---ha-w- c:\documents and settings\miki\Data aplikací\dach100.dll
2011-08-07 01:02 . 2011-08-07 01:02 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-08-06 23:48 . 2011-08-06 23:48 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2011-08-06 19:53 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{DA7A3350-D9FC-4A6F-968A-5D123066E385}\mpengine.dll
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- c:\program files\trend micro
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- C:\rsit
2011-08-06 10:25 . 2011-08-06 10:26 781383 ----a-w- C:\RSIT.exe
2011-08-06 09:14 . 2006-07-04 13:36 61440 ----a-w- c:\windows\system32\FTChipID.dll
2011-08-06 09:13 . 2011-08-06 10:29 -------- d-----w- c:\program files\WGSoft
2011-08-06 09:13 . 2011-08-06 09:13 -------- d-----w- c:\documents and settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-06 09:09 . 2011-08-06 09:10 3495365 ----a-w- C:\EasyObdII_Ver2_3_0.exe
2011-08-06 09:08 . 2011-08-06 09:08 462297 ----a-w- C:\scantool_net115win.exe
2011-08-02 08:32 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-01 14:28 . 2011-08-01 14:28 -------- d-----w- c:\program files\Lamer
2011-08-01 14:23 . 2011-08-01 14:23 286842 ----a-w- C:\lamersetup.exe
2011-08-01 14:18 . 2011-08-01 14:21 3696770 ----a-w- C:\gwave558.exe
2011-07-31 22:47 . 2011-07-31 22:47 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Apple Computer
2011-07-31 15:23 . 2011-07-31 15:23 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Help
2011-07-31 13:06 . 2011-08-04 09:58 -------- d-----w- C:\symbian
2011-07-27 10:48 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-27 10:48 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-26 09:27 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-26 09:15 . 2011-07-26 09:16 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-23 09:27 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-23 09:27 . 2011-07-25 23:47 -------- d-----w- c:\program files\AVAST Software
2011-07-23 09:27 . 2011-07-23 09:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-07-23 09:25 . 2011-07-23 09:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\BlackHawk
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\program files\NETGATE
2011-07-10 14:45 . 2011-07-10 15:18 -------- d-----w- c:\program files\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-06 09:11 . 2011-08-06 09:09 11371776 ----a-w- C:\ScanMasterELM_DEMO_2.0.zip
2011-08-06 09:10 . 2011-08-06 09:09 2470792 ----a-w- C:\FULwOBD.ZIP
2011-08-06 09:09 . 2011-08-06 09:09 1261007 ----a-w- C:\CDM20802 WHQL Certified.zip
2011-08-01 14:23 . 2011-08-01 14:23 218046 ----a-w- C:\mpTrim.zip
2011-07-31 15:46 . 2011-07-31 15:45 1737986 ----a-w- C:\p3e0dfc590f7ff54ad33bd716061e0a79.zip
2011-06-06 11:35 . 2004-11-20 10:14 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 16:59 . 2011-05-08 13:50 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-18 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot@2011-07-26_09.08.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-18 20:51 . 2011-04-18 20:51 51024 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_4ddc769f\vcomp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90rus.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90kor.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90jpn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90ita.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90cht.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 35664 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90chs.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90fra.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esp.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90esn.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 53584 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 63312 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90deu.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfcm90.dll
+ 2011-05-13 18:17 . 2011-05-13 18:17 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_452bf920\vcomp.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80KOR.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80JPN.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ITA.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHT.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80CHS.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80FRA.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ESP.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80ENU.dll
+ 2011-05-13 17:45 . 2011-05-13 17:45 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_6a5bb789\mfc80DEU.dll
+ 2011-05-13 23:06 . 2011-05-13 23:06 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80u.dll
+ 2011-05-13 23:23 . 2011-05-13 23:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfcm80.dll
+ 2011-05-13 16:37 . 2011-05-13 16:37 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_a4c618fa\ATL80.dll
+ 2011-08-07 10:23 . 2011-08-07 10:23 16384 c:\windows\Temp\Perflib_Perfdata_794.dat
+ 2011-07-26 09:16 . 2011-07-26 09:16 49152 c:\windows\Installer\81f8b.msi
+ 2011-07-26 09:16 . 2011-07-26 09:16 28160 c:\windows\Installer\81f7c.msi
+ 2011-05-14 13:53 . 2011-08-07 10:22 66067 c:\windows\cscmondump.bin
+ 2011-04-18 20:51 . 2011-04-18 20:51 653136 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 569680 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcm90.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 159048 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
+ 2011-05-13 23:17 . 2011-05-13 23:17 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
+ 2011-05-13 23:12 . 2011-05-13 23:12 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
+ 2011-05-13 23:11 . 2011-05-13 23:11 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcm80.dll
+ 2011-04-18 11:18 . 2011-04-18 11:18 165648 c:\windows\system32\drivers\MpFilter.sys
+ 2011-07-26 09:16 . 2011-07-26 09:16 785920 c:\windows\Installer\81f82.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 483840 c:\windows\Installer\81f75.msi
+ 2011-07-26 09:15 . 2011-07-26 09:15 301056 c:\windows\Installer\81f6f.msi
+ 2011-07-29 01:02 . 2011-07-29 01:02 223744 c:\windows\Installer\456c6c3.msi
+ 2011-08-07 01:02 . 2011-08-07 01:02 470528 c:\windows\Installer\3285cb2.msi
+ 2011-08-07 01:01 . 2011-08-07 01:01 467456 c:\windows\Installer\3285ca6.msi
+ 2011-01-11 11:10 . 2011-08-07 10:22 265618 c:\windows\CSC_ServiceDump.dat
+ 2011-04-18 20:51 . 2011-04-18 20:51 3781960 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
+ 2011-04-18 20:51 . 2011-04-18 20:51 3766600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90.dll
+ 2011-05-13 18:04 . 2011-05-13 18:04 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80u.dll
+ 2011-05-13 18:04 . 2011-05-13 18:04 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\mfc80.dll
+ 2011-01-11 11:10 . 2011-08-07 10:22 1893786 c:\windows\CSC_ActiveCleanLog.dat
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"speedfan"="c:\program files\SpeedFan\speedfan.exe" [2008-04-22 3287552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-13 399736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-07-28 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-02-24 2834432]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\miki\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"SMSERIAL"=sm56hlpr.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [25.2.2009 17:28 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25.2.2009 17:28 5248]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [19.4.2011 17:36 13496]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [9.12.2010 14:14 66584]
R1 CFRPD;CFRPD;c:\windows\system32\drivers\CFRPD.sys [9.12.2010 14:15 33232]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.2.2009 0:40 138752]
R2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [9.12.2010 14:08 305600]
S1 MpKsl19898a96;MpKsl19898a96;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys [?]
S1 MpKslddeb1f73;MpKslddeb1f73;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys [?]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
FastUserSwitchingCompatibility
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Schedule
Seclogon
SRService
Themes
TrkWks
W32Time
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
BITS
wuauserv
ShellHWDetection
helpsvc
napagent
hkmsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
2011-08-07 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2011-08-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-08-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-05 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.asus.com
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=6&app=inclient&version=8.0.065.000&lang=en&locale=cs-CZ&date=-86400&link_id=9&dest=welcome&lic=j5hvqhisiu3s4he7bhx644bu4g0
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - user.js: nglayout.initialpaint.delay - 300
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-07 12:23
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\miki\LOCALS~1\Temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="75CD3D7CFCD1D8D12AC306059B9B98A450966931C6EC00CEC8F4787DF39DEC93407322A3F7B3BB850983494187E550F448FA3C928825647666276840B23F33735CF668367F0C6ACC4EB3E310EBAA6E0FECBEBA930750EDB23571FCB7542949F0F57E40C6F9C4C522A6E7B200C4949136918A0DD774FA18314F2E4FC2E0E727C38831CC8AE30CE366143C03BEA2930D935D88D0AA17F393849D39E8E2714CF985E33EA35ECBD48D5C6B4E1B22A95AE633CAE91777C4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555C038D530D6EB345224BB663D6A8383CB5BF77613F4EC19CA007899D8BF33CAA9FB68A77E191B4D463504952B78708CF1121CEAE10E76603B056BBE004E20DD962B3A4F82A221ADC5FD54241D9A45F8A10CCB3BA4B2235E244C9053C7A99306497BCFB998ECFEB3C3082DABDF877DF37995C44CCCAB3CD8D584822668CD44406999C03CDD417A34DA22442D9778884EA73C7A67234600B6B49D91E7EAB4DA2F2FF5DB12C2ECC92B395F838CB7AC4B7BF1D491B6404F1D86BCCABFADB2DFF7986A489E580C4196B8A493880F8AE89D132FF4664D149D3B79F80547F0F154AA67FC86C092D316039D725AA462AEF04BD1CB7A879CE10670630B09910F2F1B7BA65DF028A684411EC28E125D1495901517C901B500BFE4CBBDA8553FC9C7BF628A9406735FE0A4F03177DB6C1904962DE73B6DE832971BCEA49A2EA3466B534E68430CF16A7D1E7799421F3F4894D43D6A4AE74BD2A98BEB5A3F1E450F9DEA223B998CA7DB429620CD9485F65B3623E1EB32593C68081D8E4386ED600F359EB29EDE54CEA7EB75CB442BFC69F4A8DB29DA43F2CC5A1ABC92E776B06519600B4AD6ECF3D2A90D29549952B6A016025D18CC61A744F41A594AF32838F5E31CD127C8B1C154A00823830BF0AA5927AD8A28F806AC9D6897E6793B491FEA863E177BFC31D528AD17D9197CFC920673E74942B9BC7E85C9735D59B01A3F50006D036CA37F0ED6D8C5C547F4016B4B2AC305C812A5DC6090E53796ED71B964312542950EC78A1C0BF6E5351E9DF8035E252D0FA3754A4599F974533037F29A5E378603314932E9935D3A7DC704BF3A09C6B15DB6748DFCA58D992457E8131C33450339A7542D632583C9B0E57C8BB303378CEFB7FEB286D9D32E92E7988542BBC7F12B2F516861D4C49E500DE3E9E38DD6367536040994BC54BC990C6AFB1F690B8EC5A9B814F11E5144D37928AC74CB5D2E136689210E3C68562C1119687312AD1AE49C99A8525FB04E278ACB69C3C4D276E09F27D50D27BF8DAF667084396E2559DBB2175B7B5AB8512841E6FB626495176ADD09BFDFB3DCFAFA22D2CC1A9CB71570B966AC91B5"
"OODEFRAG11.00.00.01WORKSTATION"="BFD22B63C8B48655597B365DFDC94074F3B5B3A041895098346461B6B6C6F275C8AFC321254798744B48D3597E157778783E7758C75973AFBCE9D3B1444ED0750DDF653F76BDB8C70877F0D7758A8E43F863B81E85FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B98084C99319E531D1CA20FDF1F2A5B8AC2E5130FE5C3FDAA5CF6425A1547122EAB257CA180C79ED214DCA7484B07E6216FBF4CD5F4401CF5639DC4EEFABC8AE24DAEFB158EBE665A3BA5BB3ED5BA1EA675130938BE61443F1F12985FE0F002DCDACAC5206E65A3EA8541A6CBBA6D29440278A63E4BB46E3B96613AD2F577637B531A1827997352B30C8208B15D1AB3906798C5248319198FF3286D214EB59D925AD175C0EB74F1D28C5445E30210711C9AB0CC5B3844C558089B37596065A2EA3839A7B626460660E633078951749367B41664871A417A234382E23A8894E8BE57ACB607EC9B16E2A0B0B77DD9BE556A762DF801BF694074BD38FD3C86A3EB414B9DF4E4C7FAADD862F1094F0D39F10DC0EF3CD5A36F25C332AA5A88FBC9AA93C48E73B7A340DCB2F9AFED44BF852AAD18EC23C424D6BB7980DE8D7B729026CF9C98099851193655D6381FD0AB17439E27476743837A97F6A96B73A653D5E6004E6852560589539A0FEB9824EDB406A6BBB405F86805548F56FBA9CF6F4BF5257A3DAD74D567CDCE5A411B9A08FA3EFEC7FEBE445DF70E0850CF9170F8F66334656D3EA842DC473317C02BC95F59BDD5E20618B350A8671D873AD1378831C114755EEBDCA9EA62FCC5860FF7BE1457CDC3B95B8C14BF867E0EA15505992926A0388E60314FE1465589C55421D0C165FB4B229548DFB8124C9B8149ED8AE02C2BDB8D0C76DDE99F58ADC2CA75A8CFC36AF8D797124C653CA009E91F3D1F2D7376B5002235607C9D171E5786573CFC5398748BF6CB58EA3384577E0EEFFEB79CBABC9C19A5C7EA7318EBF0DFDEE25D79F6877D0C87E7C1AE7829751138357FD0A40EB2AB38E7555A534B90F2D7DCD81D6B1E06F490BFB666EE459964F8B155B8D3689FD98E79340C36164A20C1492AABD1CC8D91610A6A1A4E164B0CCF475F03DB30D8677E19D148A1C8480BCEADE296F6C79288ACD6518971AA7D4C07AD1763C56D65D994C7CC54E904C89BE8F465521CE927425597B47B29B6B7B0A100CA8F0CCB64FD0EE718F6580E1C00A96BE957F73073EBF32231B9378F9587D4BE9BC3211B8361DD43F97B2BCD272561C27C21B53DAFF6D531B7915231C4E189CBFEBC66CE885829078D3292D064429210FB3271562B18FAE30D53A63B0B165E7040BEB500CA7A4C41C16FB24960CD764D1E0E3FE6C7C8973C49D6526E3D402455"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3564)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\windows\Integrator.exe
c:\windows\ATK0100\ATKOSD.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Celkový čas: 2011-08-07 12:27:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-08-07 10:27
ComboFix2.txt 2011-08-06 19:29
.
Před spuštěním: 4 291 267 072
Po spuštění: 4 315 252 736
.
- - End Of File - - 2D39A664142B689514BCCAC4A27220DC
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Ještě poprosím o sken MBR: http://www2.gmer.net/mbr/mbr.exe . Utilita vytvoří krátký log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: HTS541080G9AT00 rev.MB4OA60A -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Stale nejde neake programy instalovat
Windows 5.1.2600 Disk: HTS541080G9AT00 rev.MB4OA60A -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Stale nejde neake programy instalovat
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Tento soubor: c:\windows\system32\drivers\atapi.sys otestujte online na www.virustotal.com .
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
Ten sa uz testoval davnejsie, dokonca aj tu niekomu na fore som ho posielal a je cisty, je to neaky driwer myslim ku wifine, aj spyrware terminator mi ho stale ukazuje ako spyrware ale mozem ho otestovat zas
A nejde ani otestovat ked ho dam uploadnut nic sa nedeje
A nejde ani otestovat ked ho dam uploadnut nic sa nedeje
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
On je v logu tenhle záznam:
Zkuste spustit TDSSKiller: http://support.kaspersky.com/faq/?qid=208283363 . Postupujte podle kolegova návodu:
Což znamená, že s tím souborem není něco v pořádku.[-] 2004-08-18 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
Zkuste spustit TDSSKiller: http://support.kaspersky.com/faq/?qid=208283363 . Postupujte podle kolegova návodu:
Utilitu spustte a prikazte ji, at skenuje - klik na Start Scan
Pokud utilita najde infikekci, bude ji chtit lecit (Cure), povolte leceni kliknutim na Continue
Pokud utilita najde podezrely soubor (suspicious), bude jej chtit preskocit (Skip), povolte preskoceni kliknutim na Continue
Po dokonceni skenu bude mozna nutny restart PC, povolte jej kliknutim na Reboot now
Po restartu na Vas vyskoci log, pokud se tak nestane, najdete jej primo na disku, kde mate Windows (obvykle c:\) ve tvaru TDSSKiller.nejaka cisilka _log.txt - jeho obsah sem vlozte
Pokud restart nebude vyzadovan, kliknete na Close a nasledne na Report - vytvori se log - jeho obsah sem vlozte
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
2011/08/07 19:38:31.0437 4924 TDSS rootkit removing tool 2.5.14.0 Aug 5 2011 16:09:29
2011/08/07 19:38:31.0640 4924 ================================================================================
2011/08/07 19:38:31.0640 4924 SystemInfo:
2011/08/07 19:38:31.0640 4924
2011/08/07 19:38:31.0640 4924 OS Version: 5.1.2600 ServicePack: 3.0
2011/08/07 19:38:31.0640 4924 Product type: Workstation
2011/08/07 19:38:31.0640 4924 ComputerName: N-F3549D2047414
2011/08/07 19:38:31.0640 4924 UserName: miki
2011/08/07 19:38:31.0640 4924 Windows directory: C:\WINDOWS
2011/08/07 19:38:31.0640 4924 System windows directory: C:\WINDOWS
2011/08/07 19:38:31.0640 4924 Processor architecture: Intel x86
2011/08/07 19:38:31.0640 4924 Number of processors: 2
2011/08/07 19:38:31.0640 4924 Page size: 0x1000
2011/08/07 19:38:31.0640 4924 Boot type: Normal boot
2011/08/07 19:38:31.0640 4924 ================================================================================
2011/08/07 19:38:36.0093 4924 Initialize success
2011/08/07 19:38:39.0265 4668 ================================================================================
2011/08/07 19:38:39.0265 4668 Scan started
2011/08/07 19:38:39.0265 4668 Mode: Manual;
2011/08/07 19:38:39.0265 4668 ================================================================================
2011/08/07 19:38:40.0468 4668 a347bus (1f61cacacb521215f39061789147968c) C:\WINDOWS\system32\DRIVERS\a347bus.sys
2011/08/07 19:38:40.0500 4668 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
2011/08/07 19:38:40.0593 4668 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/08/07 19:38:40.0609 4668 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/08/07 19:38:40.0671 4668 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/08/07 19:38:40.0734 4668 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/08/07 19:38:40.0843 4668 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/08/07 19:38:40.0984 4668 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/08/07 19:38:41.0265 4668 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/08/07 19:38:41.0328 4668 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/08/07 19:38:41.0328 4668 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\atapi.sys. md5: cdfe4411a69c224bd1d11b2da92dac51
2011/08/07 19:38:41.0328 4668 atapi - detected LockedFile.Multi.Generic (1)
2011/08/07 19:38:41.0390 4668 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2011/08/07 19:38:41.0453 4668 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/08/07 19:38:41.0500 4668 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/08/07 19:38:41.0531 4668 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/08/07 19:38:41.0593 4668 Cam5603D (2230b842f43a204abd3ec6bdd39d793f) C:\WINDOWS\system32\Drivers\BisonCam.sys
2011/08/07 19:38:41.0750 4668 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/08/07 19:38:41.0781 4668 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/08/07 19:38:41.0843 4668 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/08/07 19:38:41.0859 4668 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/08/07 19:38:41.0890 4668 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/08/07 19:38:41.0937 4668 CFRMD (a6811f84b3df61e22e4f8749d9a8af61) C:\WINDOWS\system32\DRIVERS\CFRMD.sys
2011/08/07 19:38:42.0000 4668 CFRPD (e854bd45cfb2898108ceccba89b67d0d) C:\WINDOWS\system32\DRIVERS\CFRPD.sys
2011/08/07 19:38:42.0125 4668 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/08/07 19:38:42.0203 4668 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/08/07 19:38:42.0296 4668 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/08/07 19:38:42.0359 4668 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
2011/08/07 19:38:42.0468 4668 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
2011/08/07 19:38:42.0500 4668 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/08/07 19:38:42.0531 4668 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/08/07 19:38:42.0578 4668 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/08/07 19:38:42.0640 4668 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/08/07 19:38:42.0687 4668 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/08/07 19:38:42.0718 4668 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
2011/08/07 19:38:42.0734 4668 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/08/07 19:38:42.0796 4668 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/08/07 19:38:42.0843 4668 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/08/07 19:38:42.0875 4668 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/08/07 19:38:42.0921 4668 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
2011/08/07 19:38:42.0984 4668 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/08/07 19:38:43.0015 4668 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/08/07 19:38:43.0062 4668 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/08/07 19:38:43.0187 4668 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/08/07 19:38:43.0265 4668 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/08/07 19:38:43.0312 4668 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/08/07 19:38:43.0546 4668 IntcAzAudAddService (4b322f8c7b7af523d1c145c22eef4713) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/08/07 19:38:43.0765 4668 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/08/07 19:38:43.0796 4668 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/08/07 19:38:43.0843 4668 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/08/07 19:38:43.0890 4668 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/08/07 19:38:43.0937 4668 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/08/07 19:38:43.0968 4668 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/08/07 19:38:44.0015 4668 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/08/07 19:38:44.0046 4668 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/08/07 19:38:44.0109 4668 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/08/07 19:38:44.0140 4668 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/08/07 19:38:44.0187 4668 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/08/07 19:38:44.0265 4668 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
2011/08/07 19:38:44.0328 4668 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/08/07 19:38:44.0421 4668 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
2011/08/07 19:38:44.0437 4668 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/08/07 19:38:44.0484 4668 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/08/07 19:38:44.0500 4668 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/08/07 19:38:44.0562 4668 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
2011/08/07 19:38:44.0703 4668 MpKsl4e364ec5 (5f53edfead46fa7adb78eee9ecce8fdf) C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl4e364ec5.sys
2011/08/07 19:38:44.0765 4668 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/08/07 19:38:44.0828 4668 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/08/07 19:38:44.0937 4668 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/08/07 19:38:45.0031 4668 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/08/07 19:38:45.0109 4668 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/08/07 19:38:45.0140 4668 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/08/07 19:38:45.0156 4668 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/08/07 19:38:45.0187 4668 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/08/07 19:38:45.0234 4668 MTsensor (e333010a50bf603acc350f6019e9ce02) C:\WINDOWS\system32\DRIVERS\ATKACPI.sys
2011/08/07 19:38:45.0328 4668 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/08/07 19:38:45.0359 4668 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/08/07 19:38:45.0406 4668 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/08/07 19:38:45.0437 4668 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/08/07 19:38:45.0484 4668 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/08/07 19:38:45.0515 4668 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/08/07 19:38:45.0546 4668 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/08/07 19:38:45.0578 4668 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/08/07 19:38:45.0625 4668 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/08/07 19:38:45.0703 4668 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/08/07 19:38:45.0843 4668 NETw3x32 (e2f396f71a793a04839dbb6af304a026) C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
2011/08/07 19:38:45.0906 4668 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/08/07 19:38:45.0937 4668 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/08/07 19:38:46.0031 4668 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/08/07 19:38:46.0125 4668 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/08/07 19:38:46.0281 4668 nv (723f13c0ede32339338dac8ecaeb9979) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/08/07 19:38:46.0531 4668 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/08/07 19:38:46.0546 4668 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/08/07 19:38:46.0593 4668 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/08/07 19:38:46.0640 4668 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
2011/08/07 19:38:46.0687 4668 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/08/07 19:38:46.0718 4668 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/08/07 19:38:46.0734 4668 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/08/07 19:38:46.0796 4668 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/08/07 19:38:46.0828 4668 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/08/07 19:38:46.0984 4668 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/08/07 19:38:47.0015 4668 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/08/07 19:38:47.0046 4668 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/08/07 19:38:47.0078 4668 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/08/07 19:38:47.0203 4668 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/08/07 19:38:47.0234 4668 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/08/07 19:38:47.0250 4668 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/08/07 19:38:47.0265 4668 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/08/07 19:38:47.0343 4668 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/08/07 19:38:47.0453 4668 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/08/07 19:38:47.0484 4668 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/08/07 19:38:47.0546 4668 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/08/07 19:38:47.0609 4668 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
2011/08/07 19:38:47.0640 4668 risdptsk (ace2ce73d7b04eac48fb80482e05e770) C:\WINDOWS\system32\DRIVERS\risdptsk.sys
2011/08/07 19:38:47.0687 4668 RTL8023xp (d6e1b1bd04fad422af17fc4b810cb9af) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
2011/08/07 19:38:47.0718 4668 s24trans (2862adb14481ac28f98105ff33a99eb0) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/08/07 19:38:47.0812 4668 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2011/08/07 19:38:47.0843 4668 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/08/07 19:38:47.0890 4668 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\drivers\Serial.sys
2011/08/07 19:38:47.0937 4668 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/08/07 19:38:48.0000 4668 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/08/07 19:38:48.0046 4668 SmartDefragDriver (972dea0d8149d73c5b7a2c97b2e749e3) C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys
2011/08/07 19:38:48.0093 4668 smserial (34d634366fc57524f5932eaec40e4fcb) C:\WINDOWS\system32\DRIVERS\smserial.sys
2011/08/07 19:38:48.0296 4668 snapman (bcc773872041aa59bc9a6cf770fb32e2) C:\WINDOWS\system32\DRIVERS\snapman.sys
2011/08/07 19:38:48.0375 4668 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys
2011/08/07 19:38:48.0453 4668 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/08/07 19:38:48.0515 4668 sp_rsdrv2 (f0ae423958fddf7e9ec5e408cb171560) C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011/08/07 19:38:48.0546 4668 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/08/07 19:38:48.0640 4668 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/08/07 19:38:48.0703 4668 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/08/07 19:38:48.0734 4668 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/08/07 19:38:48.0781 4668 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/08/07 19:38:48.0921 4668 SynTP (9c29e8e9c1c48e9c8bc38f031df4720f) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/08/07 19:38:48.0984 4668 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/08/07 19:38:49.0093 4668 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/08/07 19:38:49.0125 4668 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
2011/08/07 19:38:49.0203 4668 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/08/07 19:38:49.0265 4668 tdrpman (603d59923828c6c213b84b14cbf32083) C:\WINDOWS\system32\DRIVERS\tdrpman.sys
2011/08/07 19:38:49.0359 4668 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/08/07 19:38:49.0406 4668 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/08/07 19:38:49.0437 4668 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
2011/08/07 19:38:49.0453 4668 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\WINDOWS\system32\DRIVERS\timntr.sys
2011/08/07 19:38:49.0515 4668 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/08/07 19:38:49.0625 4668 tosporte (d626e0af9232d8799d3a449530f3c220) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/08/07 19:38:49.0703 4668 Tosrfbd (294675c8e4316302efe14b1a1219d942) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/08/07 19:38:49.0765 4668 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/08/07 19:38:49.0828 4668 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/08/07 19:38:49.0906 4668 Tosrfhid (31b0145c289d2b3e3e9948345caa7b6f) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/08/07 19:38:50.0000 4668 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/08/07 19:38:50.0046 4668 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/08/07 19:38:50.0125 4668 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/08/07 19:38:50.0234 4668 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
2011/08/07 19:38:50.0296 4668 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/08/07 19:38:50.0375 4668 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/08/07 19:38:50.0453 4668 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/08/07 19:38:50.0484 4668 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/08/07 19:38:50.0531 4668 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/08/07 19:38:50.0562 4668 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/08/07 19:38:50.0593 4668 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/08/07 19:38:50.0640 4668 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/08/07 19:38:50.0718 4668 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/08/07 19:38:50.0781 4668 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/08/07 19:38:50.0875 4668 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/08/07 19:38:50.0906 4668 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/08/07 19:38:50.0984 4668 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/08/07 19:38:51.0015 4668 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/08/07 19:38:51.0109 4668 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/08/07 19:38:51.0234 4668 Boot (0x1200) (3e16bf7badc5a5b8e12f234f80e01d52) \Device\Harddisk0\DR0\Partition0
2011/08/07 19:38:51.0250 4668 Boot (0x1200) (32c1c7fa636bb93d179e208f23baccdf) \Device\Harddisk0\DR0\Partition1
2011/08/07 19:38:51.0265 4668 ================================================================================
2011/08/07 19:38:51.0265 4668 Scan finished
2011/08/07 19:38:51.0265 4668 ================================================================================
2011/08/07 19:38:51.0281 4284 Detected object count: 1
2011/08/07 19:38:51.0281 4284 Actual detected object count: 1
2011/08/07 19:38:57.0421 4284 LockedFile.Multi.Generic(atapi) - User select action: Skip
2011/08/07 19:38:31.0640 4924 ================================================================================
2011/08/07 19:38:31.0640 4924 SystemInfo:
2011/08/07 19:38:31.0640 4924
2011/08/07 19:38:31.0640 4924 OS Version: 5.1.2600 ServicePack: 3.0
2011/08/07 19:38:31.0640 4924 Product type: Workstation
2011/08/07 19:38:31.0640 4924 ComputerName: N-F3549D2047414
2011/08/07 19:38:31.0640 4924 UserName: miki
2011/08/07 19:38:31.0640 4924 Windows directory: C:\WINDOWS
2011/08/07 19:38:31.0640 4924 System windows directory: C:\WINDOWS
2011/08/07 19:38:31.0640 4924 Processor architecture: Intel x86
2011/08/07 19:38:31.0640 4924 Number of processors: 2
2011/08/07 19:38:31.0640 4924 Page size: 0x1000
2011/08/07 19:38:31.0640 4924 Boot type: Normal boot
2011/08/07 19:38:31.0640 4924 ================================================================================
2011/08/07 19:38:36.0093 4924 Initialize success
2011/08/07 19:38:39.0265 4668 ================================================================================
2011/08/07 19:38:39.0265 4668 Scan started
2011/08/07 19:38:39.0265 4668 Mode: Manual;
2011/08/07 19:38:39.0265 4668 ================================================================================
2011/08/07 19:38:40.0468 4668 a347bus (1f61cacacb521215f39061789147968c) C:\WINDOWS\system32\DRIVERS\a347bus.sys
2011/08/07 19:38:40.0500 4668 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
2011/08/07 19:38:40.0593 4668 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/08/07 19:38:40.0609 4668 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2011/08/07 19:38:40.0671 4668 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/08/07 19:38:40.0734 4668 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys
2011/08/07 19:38:40.0843 4668 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
2011/08/07 19:38:40.0984 4668 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/08/07 19:38:41.0265 4668 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/08/07 19:38:41.0328 4668 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/08/07 19:38:41.0328 4668 Suspicious file (NoAccess): C:\WINDOWS\system32\DRIVERS\atapi.sys. md5: cdfe4411a69c224bd1d11b2da92dac51
2011/08/07 19:38:41.0328 4668 atapi - detected LockedFile.Multi.Generic (1)
2011/08/07 19:38:41.0390 4668 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\WINDOWS\system32\DRIVERS\atksgt.sys
2011/08/07 19:38:41.0453 4668 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/08/07 19:38:41.0500 4668 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/08/07 19:38:41.0531 4668 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/08/07 19:38:41.0593 4668 Cam5603D (2230b842f43a204abd3ec6bdd39d793f) C:\WINDOWS\system32\Drivers\BisonCam.sys
2011/08/07 19:38:41.0750 4668 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/08/07 19:38:41.0781 4668 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/08/07 19:38:41.0843 4668 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/08/07 19:38:41.0859 4668 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/08/07 19:38:41.0890 4668 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/08/07 19:38:41.0937 4668 CFRMD (a6811f84b3df61e22e4f8749d9a8af61) C:\WINDOWS\system32\DRIVERS\CFRMD.sys
2011/08/07 19:38:42.0000 4668 CFRPD (e854bd45cfb2898108ceccba89b67d0d) C:\WINDOWS\system32\DRIVERS\CFRPD.sys
2011/08/07 19:38:42.0125 4668 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2011/08/07 19:38:42.0203 4668 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2011/08/07 19:38:42.0296 4668 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/08/07 19:38:42.0359 4668 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
2011/08/07 19:38:42.0468 4668 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
2011/08/07 19:38:42.0500 4668 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/08/07 19:38:42.0531 4668 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/08/07 19:38:42.0578 4668 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/08/07 19:38:42.0640 4668 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/08/07 19:38:42.0687 4668 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2011/08/07 19:38:42.0718 4668 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
2011/08/07 19:38:42.0734 4668 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/08/07 19:38:42.0796 4668 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/08/07 19:38:42.0843 4668 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/08/07 19:38:42.0875 4668 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/08/07 19:38:42.0921 4668 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
2011/08/07 19:38:42.0984 4668 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/08/07 19:38:43.0015 4668 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/08/07 19:38:43.0062 4668 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/08/07 19:38:43.0187 4668 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/08/07 19:38:43.0265 4668 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/08/07 19:38:43.0312 4668 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/08/07 19:38:43.0546 4668 IntcAzAudAddService (4b322f8c7b7af523d1c145c22eef4713) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/08/07 19:38:43.0765 4668 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/08/07 19:38:43.0796 4668 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/08/07 19:38:43.0843 4668 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/08/07 19:38:43.0890 4668 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/08/07 19:38:43.0937 4668 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/08/07 19:38:43.0968 4668 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/08/07 19:38:44.0015 4668 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/08/07 19:38:44.0046 4668 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/08/07 19:38:44.0109 4668 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/08/07 19:38:44.0140 4668 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/08/07 19:38:44.0187 4668 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/08/07 19:38:44.0265 4668 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\WINDOWS\system32\DRIVERS\lirsgt.sys
2011/08/07 19:38:44.0328 4668 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/08/07 19:38:44.0421 4668 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
2011/08/07 19:38:44.0437 4668 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/08/07 19:38:44.0484 4668 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/08/07 19:38:44.0500 4668 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/08/07 19:38:44.0562 4668 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
2011/08/07 19:38:44.0703 4668 MpKsl4e364ec5 (5f53edfead46fa7adb78eee9ecce8fdf) C:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl4e364ec5.sys
2011/08/07 19:38:44.0765 4668 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/08/07 19:38:44.0828 4668 MRxSmb (0dc719e9b15e902346e87e9dcd5751fa) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/08/07 19:38:44.0937 4668 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/08/07 19:38:45.0031 4668 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/08/07 19:38:45.0109 4668 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/08/07 19:38:45.0140 4668 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/08/07 19:38:45.0156 4668 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/08/07 19:38:45.0187 4668 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/08/07 19:38:45.0234 4668 MTsensor (e333010a50bf603acc350f6019e9ce02) C:\WINDOWS\system32\DRIVERS\ATKACPI.sys
2011/08/07 19:38:45.0328 4668 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
2011/08/07 19:38:45.0359 4668 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/08/07 19:38:45.0406 4668 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/08/07 19:38:45.0437 4668 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/08/07 19:38:45.0484 4668 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/08/07 19:38:45.0515 4668 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/08/07 19:38:45.0546 4668 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/08/07 19:38:45.0578 4668 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/08/07 19:38:45.0625 4668 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/08/07 19:38:45.0703 4668 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/08/07 19:38:45.0843 4668 NETw3x32 (e2f396f71a793a04839dbb6af304a026) C:\WINDOWS\system32\DRIVERS\NETw3x32.sys
2011/08/07 19:38:45.0906 4668 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/08/07 19:38:45.0937 4668 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/08/07 19:38:46.0031 4668 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/08/07 19:38:46.0125 4668 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/08/07 19:38:46.0281 4668 nv (723f13c0ede32339338dac8ecaeb9979) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/08/07 19:38:46.0531 4668 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/08/07 19:38:46.0546 4668 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/08/07 19:38:46.0593 4668 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/08/07 19:38:46.0640 4668 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
2011/08/07 19:38:46.0687 4668 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/08/07 19:38:46.0718 4668 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/08/07 19:38:46.0734 4668 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/08/07 19:38:46.0796 4668 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/08/07 19:38:46.0828 4668 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2011/08/07 19:38:46.0984 4668 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/08/07 19:38:47.0015 4668 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/08/07 19:38:47.0046 4668 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/08/07 19:38:47.0078 4668 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/08/07 19:38:47.0203 4668 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/08/07 19:38:47.0234 4668 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/08/07 19:38:47.0250 4668 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/08/07 19:38:47.0265 4668 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/08/07 19:38:47.0343 4668 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/08/07 19:38:47.0453 4668 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/08/07 19:38:47.0484 4668 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/08/07 19:38:47.0546 4668 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/08/07 19:38:47.0609 4668 rimsptsk (1bdba2d2d402415a78a4ba766dfe0f7b) C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
2011/08/07 19:38:47.0640 4668 risdptsk (ace2ce73d7b04eac48fb80482e05e770) C:\WINDOWS\system32\DRIVERS\risdptsk.sys
2011/08/07 19:38:47.0687 4668 RTL8023xp (d6e1b1bd04fad422af17fc4b810cb9af) C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
2011/08/07 19:38:47.0718 4668 s24trans (2862adb14481ac28f98105ff33a99eb0) C:\WINDOWS\system32\DRIVERS\s24trans.sys
2011/08/07 19:38:47.0812 4668 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2011/08/07 19:38:47.0843 4668 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/08/07 19:38:47.0890 4668 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\drivers\Serial.sys
2011/08/07 19:38:47.0937 4668 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/08/07 19:38:48.0000 4668 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/08/07 19:38:48.0046 4668 SmartDefragDriver (972dea0d8149d73c5b7a2c97b2e749e3) C:\WINDOWS\system32\Drivers\SmartDefragDriver.sys
2011/08/07 19:38:48.0093 4668 smserial (34d634366fc57524f5932eaec40e4fcb) C:\WINDOWS\system32\DRIVERS\smserial.sys
2011/08/07 19:38:48.0296 4668 snapman (bcc773872041aa59bc9a6cf770fb32e2) C:\WINDOWS\system32\DRIVERS\snapman.sys
2011/08/07 19:38:48.0375 4668 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) C:\WINDOWS\system32\speedfan.sys
2011/08/07 19:38:48.0453 4668 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/08/07 19:38:48.0515 4668 sp_rsdrv2 (f0ae423958fddf7e9ec5e408cb171560) C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011/08/07 19:38:48.0546 4668 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/08/07 19:38:48.0640 4668 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/08/07 19:38:48.0703 4668 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/08/07 19:38:48.0734 4668 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/08/07 19:38:48.0781 4668 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/08/07 19:38:48.0921 4668 SynTP (9c29e8e9c1c48e9c8bc38f031df4720f) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2011/08/07 19:38:48.0984 4668 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/08/07 19:38:49.0093 4668 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/08/07 19:38:49.0125 4668 Tcpip6 (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
2011/08/07 19:38:49.0203 4668 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/08/07 19:38:49.0265 4668 tdrpman (603d59923828c6c213b84b14cbf32083) C:\WINDOWS\system32\DRIVERS\tdrpman.sys
2011/08/07 19:38:49.0359 4668 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/08/07 19:38:49.0406 4668 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/08/07 19:38:49.0437 4668 tifsfilter (b0b3122bff3910e0ba97014045467778) C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
2011/08/07 19:38:49.0453 4668 timounter (13bfe330880ac0ce8672d00aa5aff738) C:\WINDOWS\system32\DRIVERS\timntr.sys
2011/08/07 19:38:49.0515 4668 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
2011/08/07 19:38:49.0625 4668 tosporte (d626e0af9232d8799d3a449530f3c220) C:\WINDOWS\system32\DRIVERS\tosporte.sys
2011/08/07 19:38:49.0703 4668 Tosrfbd (294675c8e4316302efe14b1a1219d942) C:\WINDOWS\system32\Drivers\tosrfbd.sys
2011/08/07 19:38:49.0765 4668 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
2011/08/07 19:38:49.0828 4668 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
2011/08/07 19:38:49.0906 4668 Tosrfhid (31b0145c289d2b3e3e9948345caa7b6f) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
2011/08/07 19:38:50.0000 4668 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
2011/08/07 19:38:50.0046 4668 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
2011/08/07 19:38:50.0125 4668 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
2011/08/07 19:38:50.0234 4668 tunmp (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
2011/08/07 19:38:50.0296 4668 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/08/07 19:38:50.0375 4668 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/08/07 19:38:50.0453 4668 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/08/07 19:38:50.0484 4668 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/08/07 19:38:50.0531 4668 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/08/07 19:38:50.0562 4668 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/08/07 19:38:50.0593 4668 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/08/07 19:38:50.0640 4668 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/08/07 19:38:50.0718 4668 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/08/07 19:38:50.0781 4668 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/08/07 19:38:50.0875 4668 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
2011/08/07 19:38:50.0906 4668 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/08/07 19:38:50.0984 4668 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/08/07 19:38:51.0015 4668 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/08/07 19:38:51.0109 4668 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
2011/08/07 19:38:51.0234 4668 Boot (0x1200) (3e16bf7badc5a5b8e12f234f80e01d52) \Device\Harddisk0\DR0\Partition0
2011/08/07 19:38:51.0250 4668 Boot (0x1200) (32c1c7fa636bb93d179e208f23baccdf) \Device\Harddisk0\DR0\Partition1
2011/08/07 19:38:51.0265 4668 ================================================================================
2011/08/07 19:38:51.0265 4668 Scan finished
2011/08/07 19:38:51.0265 4668 ================================================================================
2011/08/07 19:38:51.0281 4284 Detected object count: 1
2011/08/07 19:38:51.0281 4284 Actual detected object count: 1
2011/08/07 19:38:57.0421 4284 LockedFile.Multi.Generic(atapi) - User select action: Skip
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Ani TDSSKiller ho nepřekoppíroval, pouze ho ozančil za podezřelý. Zkuste ještě jednou CF s tímto skritem:
FCopy::
c:\windows\ServicePackFiles\i386\atapi.sys | c:\windows\system32\drivers\atapi.sys
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
ComboFix 11-08-06.02 - miki 08.08.2011 15:38:58.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1285 [GMT 2:00]
Spuštěný z: c:\documents and settings\miki\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\miki\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\miki\Data aplikací\dach100.dll
c:\windows\ST6UNST.000
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-08 do 2011-08-08 )))))))))))))))))))))))))))))))
.
.
2011-08-08 13:32 . 2011-08-08 13:32 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl5f3aca56.sys
2011-08-07 13:35 . 2011-08-07 13:35 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl4e364ec5.sys
2011-08-07 13:33 . 2011-08-07 13:33 -------- d-----w- c:\documents and settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-07 13:30 . 2006-07-04 13:36 61440 ----a-w- c:\windows\system32\FTChipID.dll
2011-08-07 13:30 . 2011-08-07 13:33 -------- d-----w- c:\program files\OBD-DIAG
2011-08-07 10:45 . 2011-08-07 12:45 -------- d-----w- c:\program files\ScanTool.net_win
2011-08-07 10:45 . 2005-03-26 18:33 152848 ----a-w- c:\windows\system32\COMDLG32.OCX
2011-08-07 10:45 . 2004-03-09 06:00 224016 ----a-w- c:\windows\system32\TABCTL32.OCX
2011-08-07 10:45 . 2000-10-10 08:01 162816 ----a-w- c:\windows\system32\MSCOMM32.OCX
2011-08-07 10:42 . 2011-08-07 10:42 249856 ------w- c:\windows\Setup1.exe
2011-08-07 10:42 . 2011-08-07 10:42 73216 ------w- c:\windows\ST6UNST.EXE
2011-08-07 10:35 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\mpengine.dll
2011-08-07 01:02 . 2011-08-07 01:02 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-08-06 23:48 . 2011-08-06 23:48 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- c:\program files\trend micro
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- C:\rsit
2011-08-06 09:13 . 2011-08-07 13:30 -------- d-----w- c:\program files\WGSoft
2011-08-02 08:32 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-01 14:28 . 2011-08-01 14:28 -------- d-----w- c:\program files\Lamer
2011-07-31 22:47 . 2011-07-31 22:47 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Apple Computer
2011-07-31 15:23 . 2011-07-31 15:23 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Help
2011-07-31 13:06 . 2011-08-04 09:58 -------- d-----w- C:\symbian
2011-07-27 10:48 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-27 10:48 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-26 09:27 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-26 09:15 . 2011-07-26 09:16 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-23 09:27 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-23 09:27 . 2011-07-25 23:47 -------- d-----w- c:\program files\AVAST Software
2011-07-23 09:27 . 2011-07-23 09:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-07-23 09:25 . 2011-07-23 09:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\BlackHawk
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\program files\NETGATE
2011-07-10 14:45 . 2011-07-10 15:18 -------- d-----w- c:\program files\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-07 11:28 . 2011-08-07 11:26 8364870 ----a-w- C:\Bluetooth-327.zip
2011-08-06 09:09 . 2011-08-06 09:09 1261007 ----a-w- C:\CDM20802 WHQL Certified.zip
2011-06-06 11:35 . 2004-11-20 10:14 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 16:59 . 2011-05-08 13:50 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-18 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot_2011-08-07_10.24.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-14 13:53 . 2011-08-07 13:27 66067 c:\windows\cscmondump.bin
- 2011-05-14 13:53 . 2011-08-07 10:22 66067 c:\windows\cscmondump.bin
+ 2009-02-24 21:37 . 2011-08-07 12:51 116560 c:\windows\system32\FNTCACHE.DAT
+ 2011-01-11 11:10 . 2011-08-07 13:27 366058 c:\windows\CSC_ServiceDump.dat
+ 2011-01-11 11:10 . 2011-08-07 13:27 1975340 c:\windows\CSC_ActiveCleanLog.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"speedfan"="c:\program files\SpeedFan\speedfan.exe" [2008-04-22 3287552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-13 399736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-07-28 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-02-24 2834432]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\miki\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"SMSERIAL"=sm56hlpr.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [25.2.2009 17:28 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25.2.2009 17:28 5248]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [19.4.2011 17:36 13496]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [9.12.2010 14:14 66584]
R1 CFRPD;CFRPD;c:\windows\system32\drivers\CFRPD.sys [9.12.2010 14:15 33232]
R1 MpKsl4e364ec5;MpKsl4e364ec5;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl4e364ec5.sys [7.8.2011 15:35 28752]
R1 MpKsl5f3aca56;MpKsl5f3aca56;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl5f3aca56.sys [8.8.2011 15:32 28752]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.2.2009 0:40 138752]
R2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [9.12.2010 14:08 305600]
S1 MpKsl19898a96;MpKsl19898a96;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys [?]
S1 MpKslddeb1f73;MpKslddeb1f73;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL5F3ACA56
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
FastUserSwitchingCompatibility
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Schedule
Seclogon
SRService
Themes
TrkWks
W32Time
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
BITS
wuauserv
ShellHWDetection
helpsvc
napagent
hkmsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
2011-08-08 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2011-08-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-08-08 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-08 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-05 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.asus.com
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=6&app=inclient&version=8.0.065.000&lang=en&locale=cs-CZ&date=-86400&link_id=9&dest=welcome&lic=j5hvqhisiu3s4he7bhx644bu4g0
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - user.js: nglayout.initialpaint.delay - 300
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-08 15:53
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\miki\LOCALS~1\Temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="75CD3D7CFCD1D8D12AC306059B9B98A450966931C6EC00CEC8F4787DF39DEC93407322A3F7B3BB850983494187E550F448FA3C928825647666276840B23F33735CF668367F0C6ACC4EB3E310EBAA6E0FECBEBA930750EDB23571FCB7542949F0F57E40C6F9C4C522A6E7B200C4949136918A0DD774FA18314F2E4FC2E0E727C38831CC8AE30CE366143C03BEA2930D935D88D0AA17F393849D39E8E2714CF985E33EA35ECBD48D5C6B4E1B22A95AE633CAE91777C4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555C038D530D6EB345224BB663D6A8383CB5BF77613F4EC19CA007899D8BF33CAA9FB68A77E191B4D463504952B78708CF1121CEAE10E76603B056BBE004E20DD962B3A4F82A221ADC5FD54241D9A45F8A10CCB3BA4B2235E244C9053C7A99306497BCFB998ECFEB3C3082DABDF877DF37995C44CCCAB3CD8D584822668CD44406999C03CDD417A34DA22442D9778884EA73C7A67234600B6B49D91E7EAB4DA2F2FF5DB12C2ECC92B395F838CB7AC4B7BF1D491B6404F1D86BCCABFADB2DFF7986A489E580C4196B8A493880F8AE89D132FF4664D149D3B79F80547F0F154AA67FC86C092D316039D725AA462AEF04BD1CB7A879CE10670630B09910F2F1B7BA65DF028A684411EC28E125D1495901517C901B500BFE4CBBDA8553FC9C7BF628A9406735FE0A4F03177DB6C1904962DE73B6DE832971BCEA49A2EA3466B534E68430CF16A7D1E7799421F3F4894D43D6A4AE74BD2A98BEB5A3F1E450F9DEA223B998CA7DB429620CD9485F65B3623E1EB32593C68081D8E4386ED600F359EB29EDE54CEA7EB75CB442BFC69F4A8DB29DA43F2CC5A1ABC92E776B06519600B4AD6ECF3D2A90D29549952B6A016025D18CC61A744F41A594AF32838F5E31CD127C8B1C154A00823830BF0AA5927AD8A28F806AC9D6897E6793B491FEA863E177BFC31D528AD17D9197CFC920673E74942B9BC7E85C9735D59B01A3F50006D036CA37F0ED6D8C5C547F4016B4B2AC305C812A5DC6090E53796ED71B964312542950EC78A1C0BF6E5351E9DF8035E252D0FA3754A4599F974533037F29A5E378603314932E9935D3A7DC704BF3A09C6B15DB6748DFCA58D992457E8131C33450339A7542D632583C9B0E57C8BB303378CEFB7FEB286D9D32E92E7988542BBC7F12B2F516861D4C49E500DE3E9E38DD6367536040994BC54BC990C6AFB1F690B8EC5A9B814F11E5144D37928AC74CB5D2E136689210E3C68562C1119687312AD1AE49C99A8525FB04E278ACB69C3C4D276E09F27D50D27BF8DAF667084396E2559DBB2175B7B5AB8512841E6FB626495176ADD09BFDFB3DCFAFA22D2CC1A9CB71570B966AC91B5"
"OODEFRAG11.00.00.01WORKSTATION"="BFD22B63C8B48655597B365DFDC94074F3B5B3A041895098346461B6B6C6F275C8AFC321254798744B48D3597E157778783E7758C75973AFBCE9D3B1444ED0750DDF653F76BDB8C70877F0D7758A8E43F863B81E85FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B98084C99319E531D1CA20FDF1F2A5B8AC2E5130FE5C3FDAA5CF6425A1547122EAB257CA180C79ED214DCA7484B07E6216FBF4CD5F4401CF5639DC4EEFABC8AE24DAEFB158EBE665A3BA5BB3ED5BA1EA675130938BE61443F1F12985FE0F002DCDACAC5206E65A3EA8541A6CBBA6D29440278A63E4BB46E3B96613AD2F577637B531A1827997352B30C8208B15D1AB3906798C5248319198FF3286D214EB59D925AD175C0EB74F1D28C5445E30210711C9AB0CC5B3844C558089B37596065A2EA3839A7B626460660E633078951749367B41664871A417A234382E23A8894E8BE57ACB607EC9B16E2A0B0B77DD9BE556A762DF801BF694074BD38FD3C86A3EB414B9DF4E4C7FAADD862F1094F0D39F10DC0EF3CD5A36F25C332AA5A88FBC9AA93C48E73B7A340DCB2F9AFED44BF852AAD18EC23C424D6BB7980DE8D7B729026CF9C98099851193655D6381FD0AB17439E27476743837A97F6A96B73A653D5E6004E6852560589539A0FEB9824EDB406A6BBB405F86805548F56FBA9CF6F4BF5257A3DAD74D567CDCE5A411B9A08FA3EFEC7FEBE445DF70E0850CF9170F8F66334656D3EA842DC473317C02BC95F59BDD5E20618B350A8671D873AD1378831C114755EEBDCA9EA62FCC5860FF7BE1457CDC3B95B8C14BF867E0EA15505992926A0388E60314FE1465589C55421D0C165FB4B229548DFB8124C9B8149ED8AE02C2BDB8D0C76DDE99F58ADC2CA75A8CFC36AF8D797124C653CA009E91F3D1F2D7376B5002235607C9D171E5786573CFC5398748BF6CB58EA3384577E0EEFFEB79CBABC9C19A5C7EA7318EBF0DFDEE25D79F6877D0C87E7C1AE7829751138357FD0A40EB2AB38E7555A534B90F2D7DCD81D6B1E06F490BFB666EE459964F8B155B8D3689FD98E79340C36164A20C1492AABD1CC8D91610A6A1A4E164B0CCF475F03DB30D8677E19D148A1C8480BCEADE296F6C79288ACD6518971AA7D4C07AD1763C56D65D994C7CC54E904C89BE8F465521CE927425597B47B29B6B7B0A100CA8F0CCB64FD0EE718F6580E1C00A96BE957F73073EBF32231B9378F9587D4BE9BC3211B8361DD43F97B2BCD272561C27C21B53DAFF6D531B7915231C4E189CBFEBC66CE885829078D3292D064429210FB3271562B18FAE30D53A63B0B165E7040BEB500CA7A4C41C16FB24960CD764D1E0E3FE6C7C8973C49D6526E3D402455"
.
Celkový čas: 2011-08-08 15:55:56
ComboFix-quarantined-files.txt 2011-08-08 13:55
ComboFix2.txt 2011-08-07 10:27
ComboFix3.txt 2011-08-06 19:29
.
Před spuštěním: 4 339 576 320
Po spuštění: 4 341 144 064
.
- - End Of File - - E6BC5D6AA4F97550C30DEF00AD63277F
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1285 [GMT 2:00]
Spuštěný z: c:\documents and settings\miki\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\miki\Plocha\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\miki\Data aplikací\dach100.dll
c:\windows\ST6UNST.000
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-08 do 2011-08-08 )))))))))))))))))))))))))))))))
.
.
2011-08-08 13:32 . 2011-08-08 13:32 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl5f3aca56.sys
2011-08-07 13:35 . 2011-08-07 13:35 28752 ----a-w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl4e364ec5.sys
2011-08-07 13:33 . 2011-08-07 13:33 -------- d-----w- c:\documents and settings\miki\Data aplikací\ScanMaster-ELM - DEMO
2011-08-07 13:30 . 2006-07-04 13:36 61440 ----a-w- c:\windows\system32\FTChipID.dll
2011-08-07 13:30 . 2011-08-07 13:33 -------- d-----w- c:\program files\OBD-DIAG
2011-08-07 10:45 . 2011-08-07 12:45 -------- d-----w- c:\program files\ScanTool.net_win
2011-08-07 10:45 . 2005-03-26 18:33 152848 ----a-w- c:\windows\system32\COMDLG32.OCX
2011-08-07 10:45 . 2004-03-09 06:00 224016 ----a-w- c:\windows\system32\TABCTL32.OCX
2011-08-07 10:45 . 2000-10-10 08:01 162816 ----a-w- c:\windows\system32\MSCOMM32.OCX
2011-08-07 10:42 . 2011-08-07 10:42 249856 ------w- c:\windows\Setup1.exe
2011-08-07 10:42 . 2011-08-07 10:42 73216 ------w- c:\windows\ST6UNST.EXE
2011-08-07 10:35 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\mpengine.dll
2011-08-07 01:02 . 2011-08-07 01:02 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-08-06 23:48 . 2011-08-06 23:48 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\PCHealth
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- c:\program files\trend micro
2011-08-06 10:26 . 2011-08-06 10:26 -------- d-----w- C:\rsit
2011-08-06 09:13 . 2011-08-07 13:30 -------- d-----w- c:\program files\WGSoft
2011-08-02 08:32 . 2011-07-20 07:44 6881616 ------w- c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-08-01 14:28 . 2011-08-01 14:28 -------- d-----w- c:\program files\Lamer
2011-07-31 22:47 . 2011-07-31 22:47 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Apple Computer
2011-07-31 15:23 . 2011-07-31 15:23 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\Help
2011-07-31 13:06 . 2011-08-04 09:58 -------- d-----w- C:\symbian
2011-07-27 10:48 . 2009-08-06 17:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-27 10:48 . 2009-08-06 17:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-07-26 09:27 . 2011-05-24 17:14 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-07-26 09:15 . 2011-07-26 09:16 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-23 09:27 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-23 09:27 . 2011-07-25 23:47 -------- d-----w- c:\program files\AVAST Software
2011-07-23 09:27 . 2011-07-23 09:27 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2011-07-23 09:25 . 2011-07-23 09:26 -------- d-----w- c:\documents and settings\Administrator
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\documents and settings\miki\Local Settings\Data aplikací\BlackHawk
2011-07-10 14:48 . 2011-07-10 14:48 -------- d-----w- c:\program files\NETGATE
2011-07-10 14:45 . 2011-07-10 15:18 -------- d-----w- c:\program files\The KMPlayer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-07 11:28 . 2011-08-07 11:26 8364870 ----a-w- C:\Bluetooth-327.zip
2011-08-06 09:09 . 2011-08-06 09:09 1261007 ----a-w- C:\CDM20802 WHQL Certified.zip
2011-06-06 11:35 . 2004-11-20 10:14 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-06-21 16:59 . 2011-05-08 13:50 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\atapi.sys
[-] 2004-08-18 12:00 . !HASH: COULD NOT OPEN FILE !!!!! . 95360 . . [------] . . c:\windows\system32\drivers\atapi.sys
[7] 2004-08-18 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot_2011-08-07_10.24.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-14 13:53 . 2011-08-07 13:27 66067 c:\windows\cscmondump.bin
- 2011-05-14 13:53 . 2011-08-07 10:22 66067 c:\windows\cscmondump.bin
+ 2009-02-24 21:37 . 2011-08-07 12:51 116560 c:\windows\system32\FNTCACHE.DAT
+ 2011-01-11 11:10 . 2011-08-07 13:27 366058 c:\windows\CSC_ServiceDump.dat
+ 2011-01-11 11:10 . 2011-08-07 13:27 1975340 c:\windows\CSC_ActiveCleanLog.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"speedfan"="c:\program files\SpeedFan\speedfan.exe" [2008-04-22 3287552]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-12-03 14944136]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-04-13 399736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-07-28 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-11-21 7335936]
"nwiz"="nwiz.exe" [2005-11-21 1519616]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-06 14850560]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-20 761945]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-02-24 2834432]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-01 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-01 696320]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
c:\documents and settings\miki\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
.
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^miki^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"SMSERIAL"=sm56hlpr.exe
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [25.2.2009 17:28 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [25.2.2009 17:28 5248]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [19.4.2011 17:36 13496]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [9.12.2010 14:14 66584]
R1 CFRPD;CFRPD;c:\windows\system32\drivers\CFRPD.sys [9.12.2010 14:15 33232]
R1 MpKsl4e364ec5;MpKsl4e364ec5;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl4e364ec5.sys [7.8.2011 15:35 28752]
R1 MpKsl5f3aca56;MpKsl5f3aca56;c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{90902074-E24E-43FB-90AE-5F1C1162C09F}\MpKsl5f3aca56.sys [8.8.2011 15:32 28752]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [25.2.2009 0:40 138752]
R2 Cleaner_Validator;COMODO System - Cleaner Service;c:\program files\COMODO\COMODO System-Cleaner\Cleaner_Validator.exe [9.12.2010 14:08 305600]
S1 MpKsl19898a96;MpKsl19898a96;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKsl19898a96.sys [?]
S1 MpKslddeb1f73;MpKslddeb1f73;\??\c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys --> c:\documents and settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{3006AF6A-A158-4E42-8BDA-7CAD6C6BD4B7}\MpKslddeb1f73.sys [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - MPKSL5F3ACA56
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
ERSvc
FastUserSwitchingCompatibility
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Schedule
Seclogon
SRService
Themes
TrkWks
W32Time
Wmi
WmdmPmSp
winmgmt
wscsvc
xmlprov
BITS
wuauserv
ShellHWDetection
helpsvc
napagent
hkmsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2011-08-05 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
2011-08-08 c:\windows\Tasks\COMODO Updater.job
- c:\program files\COMODO\COMODO System-Cleaner\Updater.exe [2010-12-09 12:08]
.
2011-08-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-08-08 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-08 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2506092425-3162163531-1768229718-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 10:33]
.
2011-08-05 c:\windows\Tasks\Úklid 1 kliknutím.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 13:13]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.asus.com
uInternet Connection Wizard,ShellNext = hxxp://redirect.zonelabs.com/redirect/route?oem=1025&prod=0&mode=6&app=inclient&version=8.0.065.000&lang=en&locale=cs-CZ&date=-86400&link_id=9&dest=welcome&lic=j5hvqhisiu3s4he7bhx644bu4g0
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\miki\Data aplikací\Mozilla\Firefox\Profiles\qy908vp5.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search=
FF - user.js: nglayout.initialpaint.delay - 300
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-08 15:53
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ASFWHide]
"ImagePath"="\??\c:\docume~1\miki\LOCALS~1\Temp\ASFWHide"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="75CD3D7CFCD1D8D12AC306059B9B98A450966931C6EC00CEC8F4787DF39DEC93407322A3F7B3BB850983494187E550F448FA3C928825647666276840B23F33735CF668367F0C6ACC4EB3E310EBAA6E0FECBEBA930750EDB23571FCB7542949F0F57E40C6F9C4C522A6E7B200C4949136918A0DD774FA18314F2E4FC2E0E727C38831CC8AE30CE366143C03BEA2930D935D88D0AA17F393849D39E8E2714CF985E33EA35ECBD48D5C6B4E1B22A95AE633CAE91777C4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B9808A2D97226D213B555C038D530D6EB345224BB663D6A8383CB5BF77613F4EC19CA007899D8BF33CAA9FB68A77E191B4D463504952B78708CF1121CEAE10E76603B056BBE004E20DD962B3A4F82A221ADC5FD54241D9A45F8A10CCB3BA4B2235E244C9053C7A99306497BCFB998ECFEB3C3082DABDF877DF37995C44CCCAB3CD8D584822668CD44406999C03CDD417A34DA22442D9778884EA73C7A67234600B6B49D91E7EAB4DA2F2FF5DB12C2ECC92B395F838CB7AC4B7BF1D491B6404F1D86BCCABFADB2DFF7986A489E580C4196B8A493880F8AE89D132FF4664D149D3B79F80547F0F154AA67FC86C092D316039D725AA462AEF04BD1CB7A879CE10670630B09910F2F1B7BA65DF028A684411EC28E125D1495901517C901B500BFE4CBBDA8553FC9C7BF628A9406735FE0A4F03177DB6C1904962DE73B6DE832971BCEA49A2EA3466B534E68430CF16A7D1E7799421F3F4894D43D6A4AE74BD2A98BEB5A3F1E450F9DEA223B998CA7DB429620CD9485F65B3623E1EB32593C68081D8E4386ED600F359EB29EDE54CEA7EB75CB442BFC69F4A8DB29DA43F2CC5A1ABC92E776B06519600B4AD6ECF3D2A90D29549952B6A016025D18CC61A744F41A594AF32838F5E31CD127C8B1C154A00823830BF0AA5927AD8A28F806AC9D6897E6793B491FEA863E177BFC31D528AD17D9197CFC920673E74942B9BC7E85C9735D59B01A3F50006D036CA37F0ED6D8C5C547F4016B4B2AC305C812A5DC6090E53796ED71B964312542950EC78A1C0BF6E5351E9DF8035E252D0FA3754A4599F974533037F29A5E378603314932E9935D3A7DC704BF3A09C6B15DB6748DFCA58D992457E8131C33450339A7542D632583C9B0E57C8BB303378CEFB7FEB286D9D32E92E7988542BBC7F12B2F516861D4C49E500DE3E9E38DD6367536040994BC54BC990C6AFB1F690B8EC5A9B814F11E5144D37928AC74CB5D2E136689210E3C68562C1119687312AD1AE49C99A8525FB04E278ACB69C3C4D276E09F27D50D27BF8DAF667084396E2559DBB2175B7B5AB8512841E6FB626495176ADD09BFDFB3DCFAFA22D2CC1A9CB71570B966AC91B5"
"OODEFRAG11.00.00.01WORKSTATION"="BFD22B63C8B48655597B365DFDC94074F3B5B3A041895098346461B6B6C6F275C8AFC321254798744B48D3597E157778783E7758C75973AFBCE9D3B1444ED0750DDF653F76BDB8C70877F0D7758A8E43F863B81E85FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79335D575E7D6A3B98089DB7CE019D40AA5C5D575E7D6A3B98084C99319E531D1CA20FDF1F2A5B8AC2E5130FE5C3FDAA5CF6425A1547122EAB257CA180C79ED214DCA7484B07E6216FBF4CD5F4401CF5639DC4EEFABC8AE24DAEFB158EBE665A3BA5BB3ED5BA1EA675130938BE61443F1F12985FE0F002DCDACAC5206E65A3EA8541A6CBBA6D29440278A63E4BB46E3B96613AD2F577637B531A1827997352B30C8208B15D1AB3906798C5248319198FF3286D214EB59D925AD175C0EB74F1D28C5445E30210711C9AB0CC5B3844C558089B37596065A2EA3839A7B626460660E633078951749367B41664871A417A234382E23A8894E8BE57ACB607EC9B16E2A0B0B77DD9BE556A762DF801BF694074BD38FD3C86A3EB414B9DF4E4C7FAADD862F1094F0D39F10DC0EF3CD5A36F25C332AA5A88FBC9AA93C48E73B7A340DCB2F9AFED44BF852AAD18EC23C424D6BB7980DE8D7B729026CF9C98099851193655D6381FD0AB17439E27476743837A97F6A96B73A653D5E6004E6852560589539A0FEB9824EDB406A6BBB405F86805548F56FBA9CF6F4BF5257A3DAD74D567CDCE5A411B9A08FA3EFEC7FEBE445DF70E0850CF9170F8F66334656D3EA842DC473317C02BC95F59BDD5E20618B350A8671D873AD1378831C114755EEBDCA9EA62FCC5860FF7BE1457CDC3B95B8C14BF867E0EA15505992926A0388E60314FE1465589C55421D0C165FB4B229548DFB8124C9B8149ED8AE02C2BDB8D0C76DDE99F58ADC2CA75A8CFC36AF8D797124C653CA009E91F3D1F2D7376B5002235607C9D171E5786573CFC5398748BF6CB58EA3384577E0EEFFEB79CBABC9C19A5C7EA7318EBF0DFDEE25D79F6877D0C87E7C1AE7829751138357FD0A40EB2AB38E7555A534B90F2D7DCD81D6B1E06F490BFB666EE459964F8B155B8D3689FD98E79340C36164A20C1492AABD1CC8D91610A6A1A4E164B0CCF475F03DB30D8677E19D148A1C8480BCEADE296F6C79288ACD6518971AA7D4C07AD1763C56D65D994C7CC54E904C89BE8F465521CE927425597B47B29B6B7B0A100CA8F0CCB64FD0EE718F6580E1C00A96BE957F73073EBF32231B9378F9587D4BE9BC3211B8361DD43F97B2BCD272561C27C21B53DAFF6D531B7915231C4E189CBFEBC66CE885829078D3292D064429210FB3271562B18FAE30D53A63B0B165E7040BEB500CA7A4C41C16FB24960CD764D1E0E3FE6C7C8973C49D6526E3D402455"
.
Celkový čas: 2011-08-08 15:55:56
ComboFix-quarantined-files.txt 2011-08-08 13:55
ComboFix2.txt 2011-08-07 10:27
ComboFix3.txt 2011-08-06 19:29
.
Před spuštěním: 4 339 576 320
Po spuštění: 4 341 144 064
.
- - End Of File - - E6BC5D6AA4F97550C30DEF00AD63277F
- Rudy
- Site Admin
- Příspěvky: 119506
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Kontrola logu
Nepřekopíroval se. Nabootujte z instal. CD WinXP. Až se poprvé objeví na dolní liště "R-opravit", stiskněte "R" a přihlašte se k instalaci Windows. Do přík. řádku zadejte:
pakcd c:\ --> Enter
a nakoneccopy c:\windows\ServicePackFiles\i386\atapi.sys c:\windows\system32\drivers\atapi.sys -->Enter
(enter stisknete po každém zadání). Po posledním příkazu se PC restartuje.exit -->Enter
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Kontrola logu
Hotovo co dalej?