
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Facebook vrus - prosím o pomoc
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Facebook vrus - prosím o pomoc
Zde je log
Logfile of random's system information tool 1.09 (written by random/random)
Run by Honza at 2011-11-02 19:59:19
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 7 GB (18%) free of 36 GB
Total RAM: 511 MB (17% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:59:35, on 2.11.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS.0\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS.0\update.tray-3-0\svchost.exe
C:\WINDOWS.0\update.tray-2-0\svchost.exe
C:\WINDOWS.0\update.tray-12-0\svchost.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\WINDOWS.0\system32\IProsetMonitor.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\WINDOWS.0\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS.0\update.5.0\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.5.0\svchost.exe
C:\WINDOWS.0\sysdriver32.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\update.1\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS.0\system32\wbem\wmiapsrv.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.tray-2-0-lnk\svchost.exe
C:\WINDOWS.0\ufa\ufa.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\RSIT.exe
C:\Program Files\trend micro\Honza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/#utm_source=icq&u ... um=generic
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qstatsrv.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Corsair Add-on - {B4FBA8C3-2083-4ED8-A35B-148478739826} - C:\Program Files\Corsair Addon\corsair.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS.0\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [UUSeeMediaCenter] "C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EasyDownloads] "C:\Program Files\Easy Downloads\easydownloads.exe" -tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [wxpdrv] C:\WINDOWS.0\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\WINDOWS.0\update.tray-3-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\WINDOWS.0\update.tray-2-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico2] C:\WINDOWS.0\update.tray-12-0\svchost.exe
O4 - HKLM\..\Run: [899047.exe] "C:\WINDOWS.0\TEMP\899047.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\WINDOWS.0\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\WINDOWS.0\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [3581810.exe] "C:\DOCUME~1\HONZA~1.HON\LOCALS~1\Temp\3581810.exe"
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [2080618.exe] "C:\WINDOWS.0\TEMP\2080618.exe"
O4 - HKLM\..\Run: [4013456.exe] "C:\WINDOWS.0\TEMP\4013456.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.914
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Global Startup: SolidWorks Nástroj pro stahování na pozadí.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS.0\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS.0\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS.0\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Firewall (avgfws) - Unknown owner - C:\Program Files\AVG\AVG2012\avgfws.exe (file missing)
O23 - Service: AVGIDSAgent - Unknown owner - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (file missing)
O23 - Service: AVG WatchDog (avgwd) - Unknown owner - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Intel Corporation - C:\WINDOWS.0\system32\IProsetMonitor.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS.0\system32\PnkBstrA.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: srvbtcclient - Unknown owner - C:\WINDOWS.0\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\WINDOWS.0\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\WINDOWS.0\sysdriver32.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe (file missing)
O23 - Service: wxpdrivers - Cronosoft - C:\WINDOWS.0\update.1\svchost.exe
--
End of file - 14104 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/#utm_source=icq&u ... um=generic"
prefs.js - "extensions.enabledItems" - "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5, {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, jqs@sun.com:1.0, {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.16.1, QipCounter@qip.ru:1.0, {32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, engine@conduit.com:3.3.3.2, {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.5.0.12, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6"
prefs.js - "keyword.URL" - "http://zinkwink.com/?clid=c088e56028bc4 ... &keywords="
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{cb84136f-9c44-433a-9048-c5cd9df1dc16}"=C:\Program Files\PC Tools Security\BDT\Firefox\
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG2012\Firefox4\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS.0\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=E:\Program Files\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
corsair@corsair.com
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npdnu.dll
npdnu.xpt
npdnupdater2.dll
npdnupdater2.xpt
npEModelPlugin.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npuuseep.dll
npwachk.dll
nsEModelPlugin.xpt
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
babylon.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\extensions\
avg@toolbar
engine@conduit.com
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\searchplugins\
aol-web-search.xml
askcom.xml
icq-search.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
qip-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2011-06-29 1937736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll [2011-05-20 1144784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qstatsrv.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-12-13 141184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-09-21 3853984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll []
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2011-06-29 1937736]
{B4FBA8C3-2083-4ED8-A35B-148478739826} - Corsair Add-on - C:\Program Files\Corsair Addon\corsair.dll [2011-09-22 797184]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll [2011-05-20 1144784]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS.0\system32\NvCpl.dll [2006-03-09 7561216]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS.0\system32\NvMcTray.dll [2006-03-09 86016]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [2002-06-26 90112]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2011-07-11 74752]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe []
"UUSeeMediaCenter"=C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-07-05 421888]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]
"EasyDownloads"=C:\Program Files\Easy Downloads\easydownloads.exe -tray []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"KernelFaultCheck"=C:\WINDOWS.0\system32\dumprep 0 -k []
"wxpdrv"=C:\WINDOWS.0\services32.exe [2011-10-28 1201152]
"tray_ico"= []
"tray_ico0"=C:\WINDOWS.0\update.tray-3-0\svchost.exe [2011-10-28 1201152]
"tray_ico1"=C:\WINDOWS.0\update.tray-2-0\svchost.exe [2011-10-28 1201152]
"tray_ico2"=C:\WINDOWS.0\update.tray-12-0\svchost.exe [2011-10-28 1201152]
"tray_ico3"= []
"tray_ico4"= []
"899047.exe"=C:\WINDOWS.0\TEMP\899047.exe [2011-10-28 258048]
"sysdriver32.exe"=C:\WINDOWS.0\sysdriver32.exe [2011-11-02 257024]
"sysdriver32_.exe"=C:\WINDOWS.0\sysdriver32_.exe [2011-11-02 257024]
"3581810.exe"=C:\DOCUME~1\HONZA~1.HON\LOCALS~1\Temp\3581810.exe [2011-10-28 258048]
"PCTools FGuard"=C:\Program Files\PC Tools Security\BDT\FGuard.exe [2011-05-20 247760]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe []
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe []
"2080618.exe"=C:\WINDOWS.0\TEMP\2080618.exe [2011-11-02 257024]
"4013456.exe"=C:\WINDOWS.0\TEMP\4013456.exe [2011-11-02 1942528]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.914 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS.0\system32\ctfmon.exe [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\BitTorrent.exe [2011-07-11 400760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
E:\Program Files\QIP 2010\qip.exe [2011-07-18 6812032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\QipGuard\QipGuard.exe [2010-12-13 187776]
C:\Documents and Settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění
SolidWorks Nástroj pro stahování na pozadí.lnk - C:\Program Files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
"EnableSecureUIAPaths"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMMyDocs"=1
"NoResolveTrack"=1
"LinkResolveIgnoreLinkInfo "=1
"NoSharedDocuments"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceClassicControlPanel"=1
"NoDriveTypeAutoRun"=0xB5000000
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uusee\UUSeePlayer.exe"="C:\Program Files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer"
"C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"="C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe:*:Enabled:C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"
"C:\WINDOWS.0\update.1\svchost.exe"="C:\WINDOWS.0\update.1\svchost.exe:*:Enabled:C:\WINDOWS.0\update.1\svchost.exe"
"C:\WINDOWS.0\update.tray-3-0\svchost.exe"="C:\WINDOWS.0\update.tray-3-0\svchost.exe:*:Enabled:C:\WINDOWS.0\update.tray-3-0\svchost.exe"
"C:\WINDOWS.0\update.2\svchost.exe"="C:\WINDOWS.0\update.2\svchost.exe:*:Enabled:C:\WINDOWS.0\update.2\svchost.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS.0\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS.0\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MIDI1"=SYNCOR11.DLL
======List of files/folders created in the last 1 month======
2011-11-02 19:21:16 ----D---- C:\Program Files\trend micro
2011-11-02 19:21:15 ----D---- C:\rsit
2011-10-30 13:34:13 ----HD---- C:\WINDOWS.0\update.tray-12-0-lnk
2011-10-30 13:34:13 ----HD---- C:\WINDOWS.0\update.tray-12-0
2011-10-30 13:33:06 ----D---- C:\Program Files\ASK.COM
2011-10-30 13:32:42 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\AVG2012
2011-10-30 13:31:16 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\AVG Secure Search
2011-10-30 13:29:18 ----D---- C:\WINDOWS.0\system32\drivers\AVG
2011-10-30 13:29:05 ----SHD---- C:\Config.Msi
2011-10-30 12:45:05 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\MFAData
2011-10-29 18:59:18 ----HD---- C:\WINDOWS.0\update.tray-2-0-lnk
2011-10-29 18:59:18 ----HD---- C:\WINDOWS.0\update.tray-2-0
2011-10-29 18:13:15 ----A---- C:\WINDOWS.0\BDTSupport.dll
2011-10-29 18:13:14 ----A---- C:\WINDOWS.0\SGDetectionTool.dll
2011-10-29 18:13:14 ----A---- C:\WINDOWS.0\PCTBDRes.dll
2011-10-29 18:13:14 ----A---- C:\WINDOWS.0\PCTBDCore.dll
2011-10-29 18:07:50 ----A---- C:\WINDOWS.0\system32\drivers\Cat.DB
2011-10-29 18:06:19 ----D---- C:\Program Files\PC Tools Security
2011-10-29 18:06:18 ----AD---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\TEMP
2011-10-29 11:00:32 ----D---- C:\WINDOWS.0\ufa
2011-10-29 11:00:32 ----D---- C:\WINDOWS.0\rpcminer
2011-10-29 11:00:32 ----D---- C:\WINDOWS.0\phoenix
2011-10-29 11:00:03 ----A---- C:\WINDOWS.0\btc_client_iplist.txt
2011-10-29 10:59:20 ----HD---- C:\WINDOWS.0\update.5.0
2011-10-28 22:32:04 ----A---- C:\WINDOWS.0\unrar.exe
2011-10-28 22:30:10 ----A---- C:\WINDOWS.0\iecheck_iplist.txt
2011-10-28 22:29:32 ----HD---- C:\WINDOWS.0\update.2
2011-10-28 22:28:54 ----A---- C:\WINDOWS.0\iplist.txt
2011-10-28 22:28:33 ----A---- C:\WINDOWS.0\sysdriver32_.exe
2011-10-28 22:28:19 ----A---- C:\WINDOWS.0\sysdriver32.exe
2011-10-28 22:27:38 ----A---- C:\WINDOWS.0\front_ip_list.txt
2011-10-28 22:27:23 ----D---- C:\WINDOWS.0\av_ico
2011-10-28 22:25:45 ----HD---- C:\WINDOWS.0\update.1
2011-10-28 22:25:41 ----HD---- C:\WINDOWS.0\update.tray-3-0-lnk
2011-10-28 22:25:41 ----HD---- C:\WINDOWS.0\update.tray-3-0
2011-10-28 22:14:39 ----A---- C:\WINDOWS.0\winlog-ids.txt
2011-10-28 22:14:39 ----A---- C:\WINDOWS.0\winlog-dirs.txt
2011-10-28 22:14:18 ----A---- C:\WINDOWS.0\services32.exe
2011-10-26 18:20:13 ----D---- C:\Program Files\ICQ6Toolbar
2011-10-26 18:19:34 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\ICQ
2011-10-26 18:18:52 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\ICQ
2011-10-21 21:43:55 ----D---- C:\WINDOWS.0\Minidump
2011-10-21 21:15:00 ----D---- C:\WINDOWS.0\ie8updates
2011-10-21 21:12:21 ----D---- C:\WINDOWS.0\WBEM
2011-10-21 21:09:44 ----HDC---- C:\WINDOWS.0\ie8
2011-10-21 21:09:44 ----D---- C:\WINDOWS.0\system32\cs-CZ
2011-10-21 21:08:24 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\ESET
2011-10-21 21:00:55 ----A---- C:\WINDOWS.0\system32\javaws.exe
2011-10-21 21:00:55 ----A---- C:\WINDOWS.0\system32\javaw.exe
2011-10-21 21:00:54 ----A---- C:\WINDOWS.0\system32\java.exe
2011-10-21 20:56:12 ----A---- C:\WINDOWS.0\system32\MRT.exe
2011-10-21 05:44:07 ----HD---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Common Files
2011-10-20 21:02:28 ----D---- C:\Program Files\Corsair Addon
2011-10-20 20:51:26 ----D---- C:\Program Files\BabylonToolbar
2011-10-20 20:51:15 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Babylon
2011-10-20 20:51:15 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Babylon
2011-10-16 20:41:50 ----AH---- C:\WINDOWS.0\system32\Converter_sysquict.dat
2011-10-16 20:41:42 ----D---- C:\Program Files\Agree Free MP3 to M4A AAC Converter
2011-10-14 19:31:59 ----HDC---- C:\WINDOWS.0\$NtUninstallKB919880$
2011-10-14 19:11:03 ----D---- C:\Program Files\NVIDIA Corporation
2011-10-14 19:11:00 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\SolidWorks
2011-10-14 19:01:56 ----D---- C:\SolidWorks Data
2011-10-14 18:59:42 ----D---- C:\WINDOWS.0\SxsCaPendDel
2011-10-14 18:39:43 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\EDrawings
2011-10-14 18:38:53 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2011-10-14 18:38:26 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\DassaultSystemes
2011-10-14 18:38:26 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\DassaultSystemes
2011-10-14 18:29:37 ----A---- C:\WINDOWS.0\eDrawingOfficeAutomator.INI
2011-10-14 18:29:33 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2011-10-14 18:28:50 ----D---- C:\Program Files\SolidWorks Corp
2011-10-14 18:26:52 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2011-10-14 18:26:28 ----D---- C:\WINDOWS.0\SolidWorks
2011-10-14 18:26:22 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\SolidWorks
2011-10-14 18:24:28 ----D---- C:\WINDOWS.0\system32\appmgmt
2011-10-12 19:07:06 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Skype
2011-10-12 19:06:50 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Skype
2011-10-11 20:28:25 ----D---- C:\Program Files\iTunes
======List of files/folders modified in the last 1 month======
2011-11-02 19:49:51 ----D---- C:\WINDOWS.0
2011-11-02 19:49:36 ----D---- C:\WINDOWS.0\Temp
2011-11-02 19:48:40 ----D---- C:\Program Files
2011-11-02 19:47:57 ----D---- C:\WINDOWS.0\system32\drivers
2011-11-02 19:47:29 ----SHD---- C:\WINDOWS.0\Installer
2011-11-02 19:46:32 ----D---- C:\Program Files\DsNET Corp
2011-11-02 19:46:24 ----D---- C:\WINDOWS.0\system32
2011-11-02 18:53:14 ----D---- C:\WINDOWS.0\system32\CatRoot2
2011-11-02 18:53:06 ----HD---- C:\WINDOWS.0\inf
2011-10-30 13:36:25 ----A---- C:\boot.ini
2011-10-30 13:31:12 ----D---- C:\Program Files\Common Files
2011-10-29 18:58:14 ----SHD---- C:\System Volume Information
2011-10-29 18:10:10 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\BitTorrent
2011-10-29 18:07:17 ----D---- C:\WINDOWS.0\WinSxS
2011-10-26 18:21:30 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-24 16:50:11 ----SD---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft
2011-10-22 23:18:59 ----RSHDC---- C:\WINDOWS.0\system32\dllcache
2011-10-22 23:18:56 ----HD---- C:\WINDOWS.0\$hf_mig$
2011-10-22 08:51:01 ----D---- C:\WINDOWS.0\system32\CatRoot_bak
2011-10-22 08:51:01 ----D---- C:\WINDOWS.0\system32\CatRoot
2011-10-21 21:54:32 ----D---- C:\Program Files\iPod
2011-10-21 21:46:14 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Aiseesoft Studio
2011-10-21 21:19:07 ----D---- C:\WINDOWS.0\Help
2011-10-21 21:19:07 ----D---- C:\Program Files\Internet Explorer
2011-10-21 21:11:57 ----D---- C:\WINDOWS.0\Media
2011-10-21 21:01:17 ----D---- C:\Program Files\Common Files\Java
2011-10-21 21:00:30 ----D---- C:\Program Files\Java
2011-10-21 14:59:54 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\DiskAid
2011-10-21 06:15:25 ----D---- C:\Program Files\Opera
2011-10-16 20:41:55 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\GetRightToGo
2011-10-16 09:44:12 ----D---- C:\Temp
2011-10-15 08:39:01 ----D---- C:\WINDOWS.0\Microsoft.NET
2011-10-15 08:39:00 ----RSHD---- C:\WINDOWS.0\assembly
2011-10-14 19:28:40 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Microsoft Help
2011-10-14 19:23:23 ----D---- C:\WINDOWS.0\system32\config
2011-10-14 19:14:21 ----RSD---- C:\WINDOWS.0\Fonts
2011-10-14 19:11:04 ----D---- C:\Program Files\Microsoft Office
2011-10-14 19:11:04 ----D---- C:\Program Files\Common Files\DESIGNER
2011-10-14 19:06:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-10-14 19:05:54 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-10-14 19:03:45 ----D---- C:\Program Files\MSECache
2011-10-12 19:07:26 ----RD---- C:\Program Files\Skype
2011-10-11 20:25:36 ----DC---- C:\WINDOWS.0\system32\DRVSTORE
2011-10-11 20:25:25 ----D---- C:\WINDOWS.0\system32\ReinstallBackups
2011-10-11 20:24:50 ----D---- C:\Program Files\Bonjour
2011-10-03 04:06:03 ----A---- C:\WINDOWS.0\system32\deployJava1.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS.0\system32\DRIVERS\agp440.sys [2004-08-03 42368]
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS.0\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS.0\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
R0 PxHelp20;PxHelp20; C:\WINDOWS.0\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS.0\system32\DRIVERS\avgldx86.sys [2011-07-11 229840]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS.0\system32\DRIVERS\avgmfx86.sys [2011-08-08 40016]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS.0\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
R1 ehdrv;ehdrv; C:\WINDOWS.0\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS.0\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 epfwtdir;epfwtdir; C:\WINDOWS.0\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS.0\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 epfw;epfw; C:\WINDOWS.0\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R3 aeaudio;aeaudio; C:\WINDOWS.0\system32\drivers\aeaudio.sys [2002-08-22 98752]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS.0\system32\DRIVERS\avgfwdx.sys [2011-05-23 30944]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS.0\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134608]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS.0\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS.0\system32\DRIVERS\AVGIDSShim.Sys [2011-07-11 16720]
R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS.0\system32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS.0\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS.0\system32\DRIVERS\hidusb.sys [2002-12-05 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS.0\system32\DRIVERS\mouhid.sys [2006-01-16 12160]
R3 nv;nv; C:\WINDOWS.0\system32\DRIVERS\nv4_mini.sys [2006-03-09 3650368]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS.0\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 smwdm;smwdm; C:\WINDOWS.0\system32\drivers\smwdm.sys [2002-08-23 549672]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS.0\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS.0\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 92c8cea0;92c8cea0; C:\WINDOWS.0\2697906322:1832333663.exe []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS.0\system32\DRIVERS\avgfwdx.sys [2011-05-23 30944]
S3 cpudrv;cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys []
S3 eamon;eamon; C:\WINDOWS.0\system32\DRIVERS\eamon.sys [2011-08-09 154136]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS.0\System32\Drivers\usbaapl.sys [2011-05-10 42496]
S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS.0\system32\DRIVERS\lgusbbus.sys [2008-11-11 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS.0\system32\DRIVERS\lgusbdiag.sys [2008-11-11 19968]
S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS.0\system32\DRIVERS\lgusbmodem.sys [2008-11-11 24832]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS.0\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS.0\System32\drivers\ws2ifsl.sys [2002-12-05 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-09 55144]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe [2011-05-20 337872]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS.0\system32\IProsetMonitor.exe [2011-04-11 112800]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS.0\system32\nvsvc32.exe [2006-03-09 143436]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS.0\system32\PnkBstrA.exe [2011-07-11 75064]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-07-15 45056]
R2 srvbtcclient;srvbtcclient; C:\WINDOWS.0\update.5.0\svchost.exe [2011-10-29 344576]
R2 srviecheck;srviecheck; C:\WINDOWS.0\update.2\svchost.exe [2011-11-02 1942528]
R2 srvsysdriver32;srvsysdriver32; C:\WINDOWS.0\sysdriver32.exe [2011-11-02 257024]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS.0\system32\wdfmgr.exe [2005-01-28 38912]
R2 wxpdrivers;wxpdrivers; C:\WINDOWS.0\update.1\svchost.exe [2011-10-28 1201152]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-10-09 821608]
S2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2012\avgfws.exe []
S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe []
S2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe []
S2 vToolbarUpdater;vToolbarUpdater; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2011-01-08 87336]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-10-14 1044816]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 idsvc;Windows CardSpace; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2011-10-14 79360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.09 (written by random/random)
Run by Honza at 2011-11-02 19:59:19
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 7 GB (18%) free of 36 GB
Total RAM: 511 MB (17% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:59:35, on 2.11.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS.0\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS.0\update.tray-3-0\svchost.exe
C:\WINDOWS.0\update.tray-2-0\svchost.exe
C:\WINDOWS.0\update.tray-12-0\svchost.exe
C:\Program Files\PC Tools Security\BDT\FGuard.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
C:\WINDOWS.0\system32\IProsetMonitor.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS.0\system32\nvsvc32.exe
C:\WINDOWS.0\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS.0\update.5.0\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.5.0\svchost.exe
C:\WINDOWS.0\sysdriver32.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\update.1\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS.0\system32\wbem\wmiapsrv.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.2\svchost.exe
C:\WINDOWS.0\update.tray-2-0-lnk\svchost.exe
C:\WINDOWS.0\ufa\ufa.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\RSIT.exe
C:\Program Files\trend micro\Honza.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/#utm_source=icq&u ... um=generic
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: PC Tools Browser Guard - {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (file missing)
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qstatsrv.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll (file missing)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: aTube Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (file missing)
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Corsair Add-on - {B4FBA8C3-2083-4ED8-A35B-148478739826} - C:\Program Files\Corsair Addon\corsair.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS.0\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [UUSeeMediaCenter] "C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EasyDownloads] "C:\Program Files\Easy Downloads\easydownloads.exe" -tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [wxpdrv] C:\WINDOWS.0\services32.exe
O4 - HKLM\..\Run: [tray_ico0] C:\WINDOWS.0\update.tray-3-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico1] C:\WINDOWS.0\update.tray-2-0\svchost.exe
O4 - HKLM\..\Run: [tray_ico2] C:\WINDOWS.0\update.tray-12-0\svchost.exe
O4 - HKLM\..\Run: [899047.exe] "C:\WINDOWS.0\TEMP\899047.exe"
O4 - HKLM\..\Run: [sysdriver32.exe] "C:\WINDOWS.0\sysdriver32.exe" rezerv
O4 - HKLM\..\Run: [sysdriver32_.exe] "C:\WINDOWS.0\sysdriver32_.exe" rezerv
O4 - HKLM\..\Run: [3581810.exe] "C:\DOCUME~1\HONZA~1.HON\LOCALS~1\Temp\3581810.exe"
O4 - HKLM\..\Run: [PCTools FGuard] C:\Program Files\PC Tools Security\BDT\FGuard.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [2080618.exe] "C:\WINDOWS.0\TEMP\2080618.exe"
O4 - HKLM\..\Run: [4013456.exe] "C:\WINDOWS.0\TEMP\4013456.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.914
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Global Startup: SolidWorks Nástroj pro stahování na pozadí.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS.0\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (file missing)
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS.0\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS.0\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Firewall (avgfws) - Unknown owner - C:\Program Files\AVG\AVG2012\avgfws.exe (file missing)
O23 - Service: AVGIDSAgent - Unknown owner - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (file missing)
O23 - Service: AVG WatchDog (avgwd) - Unknown owner - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe
O23 - Service: SW Distributed TS Coordinator Service (CoordinatorServiceHost) - Dassault Systemes SolidWorks Corp. - C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Intel Corporation - C:\WINDOWS.0\system32\IProsetMonitor.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS.0\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS.0\system32\PnkBstrA.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: srvbtcclient - Unknown owner - C:\WINDOWS.0\update.5.0\svchost.exe
O23 - Service: srviecheck - Unknown owner - C:\WINDOWS.0\update.2\svchost.exe
O23 - Service: srvsysdriver32 - Unknown owner - C:\WINDOWS.0\sysdriver32.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe (file missing)
O23 - Service: wxpdrivers - Cronosoft - C:\WINDOWS.0\update.1\svchost.exe
--
End of file - 14104 bytes
=========Mozilla firefox=========
ProfilePath - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/#utm_source=icq&u ... um=generic"
prefs.js - "extensions.enabledItems" - "{800b5000-a755-47e1-992b-48a1c1357f07}:1.1.5, {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, jqs@sun.com:1.0, {0b38152b-1b20-484d-a11f-5e04a9b0661f}:5.6.16.1, QipCounter@qip.ru:1.0, {32a1fd71-835e-4b11-8e54-886fda0b4c89}:1.1, engine@conduit.com:3.3.3.2, {88c7f2aa-f93f-432c-8f0e-b7d85967a527}:3.5.0.12, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6"
prefs.js - "keyword.URL" - "http://zinkwink.com/?clid=c088e56028bc4 ... &keywords="
"{20a82645-c095-46ed-80e3-08825760534b}"=c:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{cb84136f-9c44-433a-9048-c5cd9df1dc16}"=C:\Program Files\PC Tools Security\BDT\Firefox\
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG2012\Firefox4\
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\WINDOWS.0\system32\Macromed\Flash\NPSWF32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=E:\Program Files\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\WINDOWS.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
C:\Program Files\Mozilla Firefox\extensions\
corsair@corsair.com
{800b5000-a755-47e1-992b-48a1c1357f07}
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
C:\Program Files\Mozilla Firefox\plugins\
np-mswmp.dll
npdeployJava1.dll
npdnu.dll
npdnu.xpt
npdnupdater2.dll
npdnupdater2.xpt
npEModelPlugin.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npuuseep.dll
npwachk.dll
nsEModelPlugin.xpt
QuickTimePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt
C:\Program Files\Mozilla Firefox\searchplugins\
babylon.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml
C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\extensions\
avg@toolbar
engine@conduit.com
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{800b5000-a755-47e1-992b-48a1c1357f07}
C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\searchplugins\
aol-web-search.xml
askcom.xml
icq-search.xml
icqplugin-1.xml
icqplugin-2.xml
icqplugin-3.xml
icqplugin-4.xml
icqplugin.gif
icqplugin.src
icqplugin.xml
qip-search.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - C:\Program Files\Winamp Toolbar\winamptb.dll [2011-06-29 1937736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll [2011-05-20 1144784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qstatsrv.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2010-12-13 141184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
AVG Security Toolbar - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-09-21 3853984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-10-18 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - aTube Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll []
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2011-06-29 1937736]
{B4FBA8C3-2083-4ED8-A35B-148478739826} - Corsair Add-on - C:\Program Files\Corsair Addon\corsair.dll [2011-09-22 797184]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll [2011-05-20 1144784]
{95B7759C-8C7F-4BF1-B163-73684A933233} - AVG Security Toolbar - C:\Program Files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS.0\system32\NvCpl.dll [2006-03-09 7561216]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS.0\system32\NvMcTray.dll [2006-03-09 86016]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [2002-06-26 90112]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2011-07-11 74752]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
""= []
"ApnUpdater"=C:\Program Files\Ask.com\Updater\Updater.exe []
"UUSeeMediaCenter"=C:\Program Files\Common Files\uusee\UUSeeMediaCenter.exe []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-07-05 421888]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]
"EasyDownloads"=C:\Program Files\Easy Downloads\easydownloads.exe -tray []
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"KernelFaultCheck"=C:\WINDOWS.0\system32\dumprep 0 -k []
"wxpdrv"=C:\WINDOWS.0\services32.exe [2011-10-28 1201152]
"tray_ico"= []
"tray_ico0"=C:\WINDOWS.0\update.tray-3-0\svchost.exe [2011-10-28 1201152]
"tray_ico1"=C:\WINDOWS.0\update.tray-2-0\svchost.exe [2011-10-28 1201152]
"tray_ico2"=C:\WINDOWS.0\update.tray-12-0\svchost.exe [2011-10-28 1201152]
"tray_ico3"= []
"tray_ico4"= []
"899047.exe"=C:\WINDOWS.0\TEMP\899047.exe [2011-10-28 258048]
"sysdriver32.exe"=C:\WINDOWS.0\sysdriver32.exe [2011-11-02 257024]
"sysdriver32_.exe"=C:\WINDOWS.0\sysdriver32_.exe [2011-11-02 257024]
"3581810.exe"=C:\DOCUME~1\HONZA~1.HON\LOCALS~1\Temp\3581810.exe [2011-10-28 258048]
"PCTools FGuard"=C:\Program Files\PC Tools Security\BDT\FGuard.exe [2011-05-20 247760]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe []
"vProt"=C:\Program Files\AVG Secure Search\vprot.exe []
"2080618.exe"=C:\WINDOWS.0\TEMP\2080618.exe [2011-11-02 257024]
"4013456.exe"=C:\WINDOWS.0\TEMP\4013456.exe [2011-11-02 1942528]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"=cmd.exe /c start http://www.avg.com/ww.special-uninstall ... er=9.0.914 []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS.0\system32\ctfmon.exe [2004-08-17 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\BitTorrent.exe [2011-07-11 400760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
E:\Program Files\QIP 2010\qip.exe [2011-07-18 6812032]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\QipGuard\QipGuard.exe [2010-12-13 187776]
C:\Documents and Settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění
SolidWorks Nástroj pro stahování na pozadí.lnk - C:\Program Files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\wxpdrivers]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
"EnableSecureUIAPaths"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMMyDocs"=1
"NoResolveTrack"=1
"LinkResolveIgnoreLinkInfo "=1
"NoSharedDocuments"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceClassicControlPanel"=1
"NoDriveTypeAutoRun"=0xB5000000
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uusee\UUSeePlayer.exe"="C:\Program Files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer"
"C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"="C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe:*:Enabled:C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"
"C:\WINDOWS.0\update.1\svchost.exe"="C:\WINDOWS.0\update.1\svchost.exe:*:Enabled:C:\WINDOWS.0\update.1\svchost.exe"
"C:\WINDOWS.0\update.tray-3-0\svchost.exe"="C:\WINDOWS.0\update.tray-3-0\svchost.exe:*:Enabled:C:\WINDOWS.0\update.tray-3-0\svchost.exe"
"C:\WINDOWS.0\update.2\svchost.exe"="C:\WINDOWS.0\update.2\svchost.exe:*:Enabled:C:\WINDOWS.0\update.2\svchost.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS.0\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS.0\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"MIDI1"=SYNCOR11.DLL
======List of files/folders created in the last 1 month======
2011-11-02 19:21:16 ----D---- C:\Program Files\trend micro
2011-11-02 19:21:15 ----D---- C:\rsit
2011-10-30 13:34:13 ----HD---- C:\WINDOWS.0\update.tray-12-0-lnk
2011-10-30 13:34:13 ----HD---- C:\WINDOWS.0\update.tray-12-0
2011-10-30 13:33:06 ----D---- C:\Program Files\ASK.COM
2011-10-30 13:32:42 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\AVG2012
2011-10-30 13:31:16 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\AVG Secure Search
2011-10-30 13:29:18 ----D---- C:\WINDOWS.0\system32\drivers\AVG
2011-10-30 13:29:05 ----SHD---- C:\Config.Msi
2011-10-30 12:45:05 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\MFAData
2011-10-29 18:59:18 ----HD---- C:\WINDOWS.0\update.tray-2-0-lnk
2011-10-29 18:59:18 ----HD---- C:\WINDOWS.0\update.tray-2-0
2011-10-29 18:13:15 ----A---- C:\WINDOWS.0\BDTSupport.dll
2011-10-29 18:13:14 ----A---- C:\WINDOWS.0\SGDetectionTool.dll
2011-10-29 18:13:14 ----A---- C:\WINDOWS.0\PCTBDRes.dll
2011-10-29 18:13:14 ----A---- C:\WINDOWS.0\PCTBDCore.dll
2011-10-29 18:07:50 ----A---- C:\WINDOWS.0\system32\drivers\Cat.DB
2011-10-29 18:06:19 ----D---- C:\Program Files\PC Tools Security
2011-10-29 18:06:18 ----AD---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\TEMP
2011-10-29 11:00:32 ----D---- C:\WINDOWS.0\ufa
2011-10-29 11:00:32 ----D---- C:\WINDOWS.0\rpcminer
2011-10-29 11:00:32 ----D---- C:\WINDOWS.0\phoenix
2011-10-29 11:00:03 ----A---- C:\WINDOWS.0\btc_client_iplist.txt
2011-10-29 10:59:20 ----HD---- C:\WINDOWS.0\update.5.0
2011-10-28 22:32:04 ----A---- C:\WINDOWS.0\unrar.exe
2011-10-28 22:30:10 ----A---- C:\WINDOWS.0\iecheck_iplist.txt
2011-10-28 22:29:32 ----HD---- C:\WINDOWS.0\update.2
2011-10-28 22:28:54 ----A---- C:\WINDOWS.0\iplist.txt
2011-10-28 22:28:33 ----A---- C:\WINDOWS.0\sysdriver32_.exe
2011-10-28 22:28:19 ----A---- C:\WINDOWS.0\sysdriver32.exe
2011-10-28 22:27:38 ----A---- C:\WINDOWS.0\front_ip_list.txt
2011-10-28 22:27:23 ----D---- C:\WINDOWS.0\av_ico
2011-10-28 22:25:45 ----HD---- C:\WINDOWS.0\update.1
2011-10-28 22:25:41 ----HD---- C:\WINDOWS.0\update.tray-3-0-lnk
2011-10-28 22:25:41 ----HD---- C:\WINDOWS.0\update.tray-3-0
2011-10-28 22:14:39 ----A---- C:\WINDOWS.0\winlog-ids.txt
2011-10-28 22:14:39 ----A---- C:\WINDOWS.0\winlog-dirs.txt
2011-10-28 22:14:18 ----A---- C:\WINDOWS.0\services32.exe
2011-10-26 18:20:13 ----D---- C:\Program Files\ICQ6Toolbar
2011-10-26 18:19:34 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\ICQ
2011-10-26 18:18:52 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\ICQ
2011-10-21 21:43:55 ----D---- C:\WINDOWS.0\Minidump
2011-10-21 21:15:00 ----D---- C:\WINDOWS.0\ie8updates
2011-10-21 21:12:21 ----D---- C:\WINDOWS.0\WBEM
2011-10-21 21:09:44 ----HDC---- C:\WINDOWS.0\ie8
2011-10-21 21:09:44 ----D---- C:\WINDOWS.0\system32\cs-CZ
2011-10-21 21:08:24 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\ESET
2011-10-21 21:00:55 ----A---- C:\WINDOWS.0\system32\javaws.exe
2011-10-21 21:00:55 ----A---- C:\WINDOWS.0\system32\javaw.exe
2011-10-21 21:00:54 ----A---- C:\WINDOWS.0\system32\java.exe
2011-10-21 20:56:12 ----A---- C:\WINDOWS.0\system32\MRT.exe
2011-10-21 05:44:07 ----HD---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Common Files
2011-10-20 21:02:28 ----D---- C:\Program Files\Corsair Addon
2011-10-20 20:51:26 ----D---- C:\Program Files\BabylonToolbar
2011-10-20 20:51:15 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Babylon
2011-10-20 20:51:15 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Babylon
2011-10-16 20:41:50 ----AH---- C:\WINDOWS.0\system32\Converter_sysquict.dat
2011-10-16 20:41:42 ----D---- C:\Program Files\Agree Free MP3 to M4A AAC Converter
2011-10-14 19:31:59 ----HDC---- C:\WINDOWS.0\$NtUninstallKB919880$
2011-10-14 19:11:03 ----D---- C:\Program Files\NVIDIA Corporation
2011-10-14 19:11:00 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\SolidWorks
2011-10-14 19:01:56 ----D---- C:\SolidWorks Data
2011-10-14 18:59:42 ----D---- C:\WINDOWS.0\SxsCaPendDel
2011-10-14 18:39:43 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\EDrawings
2011-10-14 18:38:53 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2011-10-14 18:38:26 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\DassaultSystemes
2011-10-14 18:38:26 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\DassaultSystemes
2011-10-14 18:29:37 ----A---- C:\WINDOWS.0\eDrawingOfficeAutomator.INI
2011-10-14 18:29:33 ----D---- C:\Program Files\Common Files\SolidWorks Shared
2011-10-14 18:28:50 ----D---- C:\Program Files\SolidWorks Corp
2011-10-14 18:26:52 ----D---- C:\Program Files\Common Files\Manažer instalací SolidWorks
2011-10-14 18:26:28 ----D---- C:\WINDOWS.0\SolidWorks
2011-10-14 18:26:22 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\SolidWorks
2011-10-14 18:24:28 ----D---- C:\WINDOWS.0\system32\appmgmt
2011-10-12 19:07:06 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Skype
2011-10-12 19:06:50 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Skype
2011-10-11 20:28:25 ----D---- C:\Program Files\iTunes
======List of files/folders modified in the last 1 month======
2011-11-02 19:49:51 ----D---- C:\WINDOWS.0
2011-11-02 19:49:36 ----D---- C:\WINDOWS.0\Temp
2011-11-02 19:48:40 ----D---- C:\Program Files
2011-11-02 19:47:57 ----D---- C:\WINDOWS.0\system32\drivers
2011-11-02 19:47:29 ----SHD---- C:\WINDOWS.0\Installer
2011-11-02 19:46:32 ----D---- C:\Program Files\DsNET Corp
2011-11-02 19:46:24 ----D---- C:\WINDOWS.0\system32
2011-11-02 18:53:14 ----D---- C:\WINDOWS.0\system32\CatRoot2
2011-11-02 18:53:06 ----HD---- C:\WINDOWS.0\inf
2011-10-30 13:36:25 ----A---- C:\boot.ini
2011-10-30 13:31:12 ----D---- C:\Program Files\Common Files
2011-10-29 18:58:14 ----SHD---- C:\System Volume Information
2011-10-29 18:10:10 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\BitTorrent
2011-10-29 18:07:17 ----D---- C:\WINDOWS.0\WinSxS
2011-10-26 18:21:30 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-24 16:50:11 ----SD---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\Microsoft
2011-10-22 23:18:59 ----RSHDC---- C:\WINDOWS.0\system32\dllcache
2011-10-22 23:18:56 ----HD---- C:\WINDOWS.0\$hf_mig$
2011-10-22 08:51:01 ----D---- C:\WINDOWS.0\system32\CatRoot_bak
2011-10-22 08:51:01 ----D---- C:\WINDOWS.0\system32\CatRoot
2011-10-21 21:54:32 ----D---- C:\Program Files\iPod
2011-10-21 21:46:14 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Aiseesoft Studio
2011-10-21 21:19:07 ----D---- C:\WINDOWS.0\Help
2011-10-21 21:19:07 ----D---- C:\Program Files\Internet Explorer
2011-10-21 21:11:57 ----D---- C:\WINDOWS.0\Media
2011-10-21 21:01:17 ----D---- C:\Program Files\Common Files\Java
2011-10-21 21:00:30 ----D---- C:\Program Files\Java
2011-10-21 14:59:54 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\DiskAid
2011-10-21 06:15:25 ----D---- C:\Program Files\Opera
2011-10-16 20:41:55 ----D---- C:\Documents and Settings\Honza.HONZA-714D35E86\Data aplikací\GetRightToGo
2011-10-16 09:44:12 ----D---- C:\Temp
2011-10-15 08:39:01 ----D---- C:\WINDOWS.0\Microsoft.NET
2011-10-15 08:39:00 ----RSHD---- C:\WINDOWS.0\assembly
2011-10-14 19:28:40 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Microsoft Help
2011-10-14 19:23:23 ----D---- C:\WINDOWS.0\system32\config
2011-10-14 19:14:21 ----RSD---- C:\WINDOWS.0\Fonts
2011-10-14 19:11:04 ----D---- C:\Program Files\Microsoft Office
2011-10-14 19:11:04 ----D---- C:\Program Files\Common Files\DESIGNER
2011-10-14 19:06:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-10-14 19:05:54 ----D---- C:\Program Files\Microsoft Visual Studio 8
2011-10-14 19:03:45 ----D---- C:\Program Files\MSECache
2011-10-12 19:07:26 ----RD---- C:\Program Files\Skype
2011-10-11 20:25:36 ----DC---- C:\WINDOWS.0\system32\DRVSTORE
2011-10-11 20:25:25 ----D---- C:\WINDOWS.0\system32\ReinstallBackups
2011-10-11 20:24:50 ----D---- C:\Program Files\Bonjour
2011-10-03 04:06:03 ----A---- C:\WINDOWS.0\system32\deployJava1.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS.0\system32\DRIVERS\agp440.sys [2004-08-03 42368]
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS.0\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS.0\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
R0 PxHelp20;PxHelp20; C:\WINDOWS.0\System32\Drivers\PxHelp20.sys [2011-03-04 45648]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS.0\system32\DRIVERS\avgldx86.sys [2011-07-11 229840]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS.0\system32\DRIVERS\avgmfx86.sys [2011-08-08 40016]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS.0\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
R1 ehdrv;ehdrv; C:\WINDOWS.0\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
R1 epfwtdi;epfwtdi; C:\WINDOWS.0\system32\DRIVERS\epfwtdi.sys [2011-08-04 61936]
R1 epfwtdir;epfwtdir; C:\WINDOWS.0\system32\DRIVERS\epfwtdir.sys [2011-08-04 103112]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS.0\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R2 epfw;epfw; C:\WINDOWS.0\system32\DRIVERS\epfw.sys [2011-08-04 147480]
R3 aeaudio;aeaudio; C:\WINDOWS.0\system32\drivers\aeaudio.sys [2002-08-22 98752]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS.0\system32\DRIVERS\avgfwdx.sys [2011-05-23 30944]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS.0\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134608]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS.0\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS.0\system32\DRIVERS\AVGIDSShim.Sys [2011-07-11 16720]
R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS.0\system32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS.0\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS.0\system32\DRIVERS\hidusb.sys [2002-12-05 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS.0\system32\DRIVERS\mouhid.sys [2006-01-16 12160]
R3 nv;nv; C:\WINDOWS.0\system32\DRIVERS\nv4_mini.sys [2006-03-09 3650368]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS.0\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 smwdm;smwdm; C:\WINDOWS.0\system32\drivers\smwdm.sys [2002-08-23 549672]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS.0\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS.0\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 92c8cea0;92c8cea0; C:\WINDOWS.0\2697906322:1832333663.exe []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS.0\system32\DRIVERS\avgfwdx.sys [2011-05-23 30944]
S3 cpudrv;cpudrv; \??\C:\Program Files\SystemRequirementsLab\cpudrv.sys []
S3 eamon;eamon; C:\WINDOWS.0\system32\DRIVERS\eamon.sys [2011-08-09 154136]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS.0\System32\Drivers\usbaapl.sys [2011-05-10 42496]
S3 usbbus;LGE Mobile Composite USB Device; C:\WINDOWS.0\system32\DRIVERS\lgusbbus.sys [2008-11-11 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\WINDOWS.0\system32\DRIVERS\lgusbdiag.sys [2008-11-11 19968]
S3 USBModem;LGE Mobile USB Modem; C:\WINDOWS.0\system32\DRIVERS\lgusbmodem.sys [2008-11-11 24832]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS.0\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS.0\System32\drivers\ws2ifsl.sys [2002-12-05 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-09 55144]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe [2011-05-20 337872]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS.0\system32\IProsetMonitor.exe [2011-04-11 112800]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-10-03 153376]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS.0\system32\nvsvc32.exe [2006-03-09 143436]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS.0\system32\PnkBstrA.exe [2011-07-11 75064]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-07-15 45056]
R2 srvbtcclient;srvbtcclient; C:\WINDOWS.0\update.5.0\svchost.exe [2011-10-29 344576]
R2 srviecheck;srviecheck; C:\WINDOWS.0\update.2\svchost.exe [2011-11-02 1942528]
R2 srvsysdriver32;srvsysdriver32; C:\WINDOWS.0\sysdriver32.exe [2011-11-02 257024]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS.0\system32\wdfmgr.exe [2005-01-28 38912]
R2 wxpdrivers;wxpdrivers; C:\WINDOWS.0\update.1\svchost.exe [2011-10-28 1201152]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-10-09 821608]
S2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2012\avgfws.exe []
S2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe []
S2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe []
S2 vToolbarUpdater;vToolbarUpdater; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2011-01-08 87336]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2011-10-14 1044816]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-08 136120]
S3 idsvc;Windows CardSpace; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SolidWorks Licensing Service;SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [2011-10-14 79360]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Re: Facebook vrus - prosím o pomoc
Zdravim a pekny vecer preji
Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe


- Ukoncete vsechny programy
- Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
- Zvolte moznost 2 a potvrte enterem
- Utilita provede svou cinnost a da log - ten sem vlozte
- Nyni znovu, ale zvolte moznost 3 a pote jeste 4 - logy opet vlozte
Re: Facebook vrus - prosím o pomoc
Zde jsou logy
1:
RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: Remove -- Date : 11/02/2011 20:28:26
Bad processes: 16
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-7-0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-3-0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-2-0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-12-0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- C:\WINDOWS.0\sysdriver32.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32_.exe -- C:\WINDOWS.0\sysdriver32_.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- C:\WINDOWS.0\update.5.0\svchost.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- C:\WINDOWS.0\update.2\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.5.0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- C:\WINDOWS.0\sysdriver32.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- C:\WINDOWS.0\update.1\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.2\svchost.exe -> KILLED [TermProc]
[SERVICE] srvbtcclient -- C:\WINDOWS.0\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srviecheck -- C:\WINDOWS.0\update.2\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- C:\WINDOWS.0\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- C:\WINDOWS.0\update.1\svchost.exe srv -> STOPPED
Registry Entries: 33
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\WINDOWS.0\services32.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico0 (C:\WINDOWS.0\update.tray-7-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico1 (C:\WINDOWS.0\update.tray-3-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico2 (C:\WINDOWS.0\update.tray-2-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico3 (C:\WINDOWS.0\update.tray-12-0\svchost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 899047.exe ("C:\WINDOWS.0\TEMP\899047.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\WINDOWS.0\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\WINDOWS.0\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3581810.exe ("C:\DOCUME~1\HONZA~1.HON\LOCALS~1\Temp\3581810.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 2080618.exe ("C:\WINDOWS.0\TEMP\2080618.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4013456.exe ("C:\WINDOWS.0\TEMP\4013456.exe") -> DELETED
[SUSP PATH] HKCU\[...]\Winlogon : Shell (C:\Documents and Settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\92c8cea0\X) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\WINDOWS.0\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\WINDOWS.0\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\WINDOWS.0\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\WINDOWS.0\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\WINDOWS.0\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\WINDOWS.0\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\WINDOWS.0\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\WINDOWS.0\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\WINDOWS.0\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\WINDOWS.0\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\WINDOWS.0\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\WINDOWS.0\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SRVBTCCLIENT () -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SRVIECHECK () -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SRVSYSDRIVER32 () -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_WXPDRIVERS () -> DELETED
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED ()
Particular Files / Folders:
Driver: [LOADED]
HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
2:
RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: HOSTSFix -- Date : 11/02/2011 20:29:07
Bad processes: 0
Driver: [LOADED]
HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
3:
RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: ProxyFix -- Date : 11/02/2011 20:29:30
Bad processes: 0
Driver: [LOADED]
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
1:
RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: Remove -- Date : 11/02/2011 20:28:26
Bad processes: 16
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-7-0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-3-0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-2-0\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.tray-12-0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- C:\WINDOWS.0\sysdriver32.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32_.exe -- C:\WINDOWS.0\sysdriver32_.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- C:\WINDOWS.0\update.5.0\svchost.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- C:\WINDOWS.0\update.2\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.5.0\svchost.exe -> KILLED [TermProc]
[SUSP PATH] sysdriver32.exe -- C:\WINDOWS.0\sysdriver32.exe -> KILLED [TermProc]
[HJ NAME] svchost.exe -- C:\WINDOWS.0\update.1\svchost.exe -> KILLED [TermProc]
[SVCHOST] svchost.exe -- C:\WINDOWS.0\update.2\svchost.exe -> KILLED [TermProc]
[SERVICE] srvbtcclient -- C:\WINDOWS.0\update.5.0\svchost.exe srv -> STOPPED
[SERVICE] srviecheck -- C:\WINDOWS.0\update.2\svchost.exe srv -> STOPPED
[SERVICE] srvsysdriver32 -- C:\WINDOWS.0\sysdriver32.exe srv -> STOPPED
[SERVICE] wxpdrivers -- C:\WINDOWS.0\update.1\svchost.exe srv -> STOPPED
Registry Entries: 33
[SUSP PATH] HKLM\[...]\Run : wxpdrv (C:\WINDOWS.0\services32.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico0 (C:\WINDOWS.0\update.tray-7-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico1 (C:\WINDOWS.0\update.tray-3-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico2 (C:\WINDOWS.0\update.tray-2-0\svchost.exe) -> DELETED
[HJ NAME] HKLM\[...]\Run : tray_ico3 (C:\WINDOWS.0\update.tray-12-0\svchost.exe) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 899047.exe ("C:\WINDOWS.0\TEMP\899047.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32.exe ("C:\WINDOWS.0\sysdriver32.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : sysdriver32_.exe ("C:\WINDOWS.0\sysdriver32_.exe" rezerv) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 3581810.exe ("C:\DOCUME~1\HONZA~1.HON\LOCALS~1\Temp\3581810.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 2080618.exe ("C:\WINDOWS.0\TEMP\2080618.exe") -> DELETED
[SUSP PATH] HKLM\[...]\Run : 4013456.exe ("C:\WINDOWS.0\TEMP\4013456.exe") -> DELETED
[SUSP PATH] HKCU\[...]\Winlogon : Shell (C:\Documents and Settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\92c8cea0\X) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\WINDOWS.0\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\WINDOWS.0\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\WINDOWS.0\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\WINDOWS.0\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\WINDOWS.0\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\WINDOWS.0\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\WINDOWS.0\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\WINDOWS.0\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvbtcclient (C:\WINDOWS.0\update.5.0\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srviecheck (C:\WINDOWS.0\update.2\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : srvsysdriver32 (C:\WINDOWS.0\sysdriver32.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\services : wxpdrivers (C:\WINDOWS.0\update.1\svchost.exe srv) -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SRVBTCCLIENT () -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SRVIECHECK () -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_SRVSYSDRIVER32 () -> DELETED
[BLACKLIST] HKLM\[...]\Root : LEGACY_WXPDRIVERS () -> DELETED
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : UpdatesDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED ()
Particular Files / Folders:
Driver: [LOADED]
HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
2:
RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: HOSTSFix -- Date : 11/02/2011 20:29:07
Bad processes: 0
Driver: [LOADED]
HOSTS File:
127.0.0.1 localhost
127.0.0.1 facebook.com
127.0.0.1 www.facebook.com
127.0.0.1 af-za.facebook.com
127.0.0.1 az-az.facebook.com
127.0.0.1 id-id.facebook.com
127.0.0.1 ms-my.facebook.com
127.0.0.1 bs-ba.facebook.com
127.0.0.1 ca-es.facebook.com
127.0.0.1 cs-cz.facebook.com
127.0.0.1 cy-gb.facebook.com
127.0.0.1 da-dk.facebook.com
127.0.0.1 de-de.facebook.com
127.0.0.1 et-ee.facebook.com
127.0.0.1 en-gb.facebook.com
127.0.0.1 es-la.facebook.com
127.0.0.1 eo-eo.facebook.com
127.0.0.1 eu-es.facebook.com
127.0.0.1 tl-ph.facebook.com
127.0.0.1 fo-fo.facebook.com
[...]
Resetted HOSTS:
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
3:
RogueKiller V6.1.6 [11/01/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo.com/forum/files/fi ... guekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User: Honza [Admin rights]
Mode: ProxyFix -- Date : 11/02/2011 20:29:30
Bad processes: 0
Driver: [LOADED]
Registry Entries: 0
Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
Re: Facebook vrus - prosím o pomoc
Super, jdeme dale
PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK

- Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
- Pokud mate Win XP spustte pod uctem Spravce\Administratora
- Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
- Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
- Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
- Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
- Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
- Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
- Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
Re: Facebook vrus - prosím o pomoc
Log CF
ComboFix 11-11-02.03 - Honza 02.11.2011 20:51:20.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.316 [GMT 1:00]
Spuštěný z: c:\documents and settings\Honza.HONZA-714D35E86\Plocha\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0\X
c:\program files\Corsair Addon
c:\program files\Corsair Addon\corsair.dll
c:\program files\Corsair Addon\uninstall.exe
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome.manifest
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\constants.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\events.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\netutils.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\searcher.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\searcher.xul
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\utils.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\install.rdf
c:\windows.0\$NtUninstallKB41879$
c:\windows.0\$NtUninstallKB41879$\2462633632\@
c:\windows.0\$NtUninstallKB41879$\2462633632\L\hxwgrnns
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@00000001
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@000000c0
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@000000cb
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@000000cf
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@80000000
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@800000c0
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@800000cb
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@800000cf
c:\windows.0\$NtUninstallKB41879$\3979956749
c:\windows.0\2697906322
c:\windows.0\av_ico
c:\windows.0\av_ico\ico_avast_desktop.ico
c:\windows.0\av_ico\ico_avast_start.ico
c:\windows.0\av_ico\ico_NOD_AV_START.ico
c:\windows.0\av_ico\ico_NOD_SS_START.ico
c:\windows.0\av_ico\ico_NOD_SYSINSP.ico
c:\windows.0\av_ico\ico_NOD_SYSRESC.ico
c:\windows.0\av_ico\ico_NOD_TXT.ico
c:\windows.0\av_ico\ico_NOD_UNINSTALL.ico
c:\windows.0\msmqinst.log
c:\windows.0\phoenix
c:\windows.0\phoenix\kernels\phatk\__init__.py
c:\windows.0\phoenix\kernels\phatk\__init__.pyc
c:\windows.0\phoenix\kernels\phatk\BFIPatcher.py
c:\windows.0\phoenix\kernels\phatk\kernel.cl
c:\windows.0\phoenix\kernels\poclbm\__init__.py
c:\windows.0\phoenix\kernels\poclbm\__init__.pyc
c:\windows.0\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows.0\phoenix\kernels\poclbm\kernel.cl
c:\windows.0\phoenix\phoenix.exe
c:\windows.0\rpcminer
c:\windows.0\rpcminer\bitcoinminercuda_10.cubin
c:\windows.0\rpcminer\bitcoinminercuda_11.cubin
c:\windows.0\rpcminer\bitcoinminercuda_20.cubin
c:\windows.0\rpcminer\bitcoinmineropencl.cl
c:\windows.0\rpcminer\cudart32_32_16.dll
c:\windows.0\rpcminer\curllib.dll
c:\windows.0\rpcminer\libeay32.dll
c:\windows.0\rpcminer\libsasl.dll
c:\windows.0\rpcminer\openldap.dll
c:\windows.0\rpcminer\rpcminer-4way.exe
c:\windows.0\rpcminer\rpcminer-cpu.exe
c:\windows.0\rpcminer\rpcminer-cuda.exe
c:\windows.0\rpcminer\rpcminer-opencl.exe
c:\windows.0\rpcminer\ssleay32.dll
c:\windows.0\sysdriver32_.exe
c:\windows.0\update.1
c:\windows.0\update.1\svchost.exe
c:\windows.0\update.2
c:\windows.0\update.2\svchost.exe
c:\windows.0\update.5.0
c:\windows.0\update.5.0\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SRVBTCCLIENT
-------\Legacy_SRVIECHECK
-------\Legacy_SRVSYSDRIVER32
-------\Legacy_WXPDRIVERS
-------\Service_92c8cea0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-02 do 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\system32\wbem\snmp
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\srchasst
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\system32\xircom
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\msagent
2011-11-02 19:55 . 2011-11-02 19:55 -------- d-----w- c:\windows.0\LastGood.Tmp
2011-11-02 19:16 . 2011-11-02 19:16 -------- d--h--w- c:\windows.0\update.tray-7-0
2011-11-02 19:16 . 2011-11-02 19:16 -------- d--h--w- c:\windows.0\update.tray-7-0-lnk
2011-11-02 19:02 . 2011-09-06 21:36 20568 ----a-w- c:\windows.0\system32\drivers\aswFsBlk.sys
2011-11-02 19:02 . 2011-09-06 21:37 320856 ----a-w- c:\windows.0\system32\drivers\aswSP.sys
2011-11-02 19:02 . 2011-09-06 21:36 34392 ----a-w- c:\windows.0\system32\drivers\aswRdr.sys
2011-11-02 19:02 . 2011-09-06 21:36 52568 ----a-w- c:\windows.0\system32\drivers\aswTdi.sys
2011-11-02 19:02 . 2011-09-06 21:38 442200 ----a-w- c:\windows.0\system32\drivers\aswSnx.sys
2011-11-02 19:02 . 2011-09-06 21:36 110552 ----a-w- c:\windows.0\system32\drivers\aswmon2.sys
2011-11-02 19:02 . 2011-09-06 21:36 104536 ----a-w- c:\windows.0\system32\drivers\aswmon.sys
2011-11-02 19:02 . 2011-09-06 21:33 30808 ----a-w- c:\windows.0\system32\drivers\aavmker4.sys
2011-11-02 19:01 . 2011-09-06 21:45 41184 ----a-w- c:\windows.0\avastSS.scr
2011-11-02 19:01 . 2011-09-06 21:45 199304 ----a-w- c:\windows.0\system32\aswBoot.exe
2011-11-02 18:44 . 2011-11-02 18:44 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Threat Expert
2011-11-02 18:41 . 2011-11-02 20:02 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0
2011-11-02 18:21 . 2011-11-02 18:59 -------- d-----w- c:\program files\trend micro
2011-11-02 18:21 . 2011-11-02 18:21 -------- d-----w- C:\rsit
2011-10-30 12:34 . 2011-10-30 12:34 -------- d--h--w- c:\windows.0\update.tray-12-0
2011-10-30 12:34 . 2011-10-30 12:34 -------- d--h--w- c:\windows.0\update.tray-12-0-lnk
2011-10-30 12:33 . 2011-10-30 12:33 -------- d-----w- c:\program files\ASK.COM
2011-10-30 12:32 . 2011-10-30 12:32 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG2012
2011-10-30 12:31 . 2011-10-30 12:31 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG Secure Search
2011-10-30 12:29 . 2011-10-30 12:30 -------- d-----w- c:\windows.0\system32\drivers\AVG
2011-10-30 11:45 . 2011-10-30 12:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\MFAData
2011-10-29 17:59 . 2011-10-29 17:59 -------- d--h--w- c:\windows.0\update.tray-2-0
2011-10-29 17:59 . 2011-10-29 17:59 -------- d--h--w- c:\windows.0\update.tray-2-0-lnk
2011-10-29 17:13 . 2011-05-20 09:44 767952 ----a-w- c:\windows.0\BDTSupport.dll
2011-10-29 17:13 . 2011-05-20 09:44 149456 ----a-w- c:\windows.0\SGDetectionTool.dll
2011-10-29 17:13 . 2011-05-20 09:44 2078672 ----a-w- c:\windows.0\PCTBDCore.dll
2011-10-29 17:13 . 2011-05-20 09:44 1533904 ----a-w- c:\windows.0\PCTBDRes.dll
2011-10-29 17:06 . 2011-10-29 17:58 -------- d-----w- c:\program files\PC Tools Security
2011-10-29 17:06 . 2011-11-02 20:06 -------- d---a-w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\TEMP
2011-10-29 10:07 . 2011-10-29 10:07 -------- d-----r- c:\documents and settings\NetworkService.NT AUTHORITY\Oblíbené položky
2011-10-29 10:00 . 2011-10-29 10:00 -------- d-----w- c:\windows.0\ufa
2011-10-28 21:32 . 2011-10-29 10:00 246272 ----a-w- c:\windows.0\unrar.exe
2011-10-28 21:28 . 2011-11-02 18:39 257024 ----a-w- c:\windows.0\sysdriver32.exe
2011-10-28 21:25 . 2011-10-28 21:25 -------- d--h--w- c:\windows.0\update.tray-3-0
2011-10-28 21:25 . 2011-10-28 21:25 -------- d--h--w- c:\windows.0\update.tray-3-0-lnk
2011-10-28 21:14 . 2011-10-28 21:14 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Nabídka Start
2011-10-28 21:14 . 2011-10-28 21:13 1201152 ----a-w- c:\windows.0\services32.exe
2011-10-26 17:20 . 2011-10-26 17:20 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2011-10-26 17:20 . 2011-10-26 17:20 -------- d-----w- c:\program files\ICQ6Toolbar
2011-10-26 17:19 . 2011-10-26 17:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\ICQ
2011-10-26 17:18 . 2011-10-26 18:19 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ICQ
2011-10-21 20:20 . 2011-10-21 20:20 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 20:19 . 2011-10-21 20:19 -------- d-sh--w- c:\documents and settings\Honza.HONZA-714D35E86\IETldCache
2011-10-21 20:13 . 2010-05-06 10:35 12800 -c----w- c:\windows.0\system32\dllcache\xpshims.dll
2011-10-21 20:13 . 2010-05-06 10:35 599040 -c----w- c:\windows.0\system32\dllcache\msfeeds.dll
2011-10-21 20:13 . 2010-05-06 10:35 55296 -c----w- c:\windows.0\system32\dllcache\msfeedsbs.dll
2011-10-21 20:13 . 2010-05-06 10:35 247808 -c----w- c:\windows.0\system32\dllcache\ieproxy.dll
2011-10-21 20:13 . 2010-05-06 10:35 1985536 -c----w- c:\windows.0\system32\dllcache\iertutil.dll
2011-10-21 20:13 . 2010-05-06 10:35 11076096 -c----w- c:\windows.0\system32\dllcache\ieframe.dll
2011-10-21 20:13 . 2010-05-06 10:35 743424 -c----w- c:\windows.0\system32\dllcache\iedvtool.dll
2011-10-21 20:09 . 2011-10-21 20:13 -------- dc-h--w- c:\windows.0\ie8
2011-10-21 20:09 . 2011-10-21 20:12 -------- d-----w- c:\windows.0\system32\cs-CZ
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\ESET
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ESET
2011-10-21 20:07 . 2011-10-21 20:07 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 04:44 . 2011-10-21 04:44 -------- d--h--w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Common Files
2011-10-21 04:36 . 2011-10-21 04:36 12536 ----a-w- c:\windows.0\system32\avgrsstx.dll.install_backup
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\program files\BabylonToolbar
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Babylon
2011-10-16 19:41 . 2011-10-16 19:42 -------- d-----w- c:\program files\Agree Free MP3 to M4A AAC Converter
2011-10-14 18:46 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\SolidWorks
2011-10-14 18:31 . 2006-09-20 11:54 1286656 -c----w- c:\windows.0\system32\dllcache\ole32.dll
2011-10-14 18:11 . 2011-10-14 18:11 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-14 18:11 . 2011-10-14 18:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\SolidWorks
2011-10-14 18:01 . 2011-10-14 18:30 -------- d-----w- C:\SolidWorks Data
2011-10-14 17:59 . 2011-10-15 07:20 -------- d-----w- c:\windows.0\SxsCaPendDel
2011-10-14 17:39 . 2011-10-14 17:39 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\EDrawings
2011-10-14 17:38 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\DassaultSystemes
2011-10-14 17:29 . 2011-10-14 18:41 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2011-10-14 17:28 . 2011-10-14 18:11 -------- d-----w- c:\program files\SolidWorks Corp
2011-10-14 17:26 . 2011-10-14 18:03 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2011-10-14 17:26 . 2011-10-14 18:01 -------- d-----w- c:\windows.0\SolidWorks
2011-10-14 17:26 . 2011-10-25 19:47 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\SolidWorks
2011-10-12 18:07 . 2011-10-27 12:17 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Skype
2011-10-12 18:06 . 2011-10-12 18:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Skype
2011-10-11 19:28 . 2011-10-11 19:29 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 03:06 . 2011-07-10 12:09 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2011-10-03 00:37 . 2011-07-10 12:09 73728 ----a-w- c:\windows.0\system32\javacpl.cpl
2011-09-13 05:30 . 2011-09-13 05:30 32592 ----a-w- c:\windows.0\system32\drivers\avgrkx86.sys
2011-08-30 21:05 . 2011-08-30 21:05 83816 ----a-w- c:\windows.0\system32\dns-sd.exe
2011-08-30 21:05 . 2011-08-30 21:05 73064 ----a-w- c:\windows.0\system32\dnssd.dll
2011-08-30 21:05 . 2011-08-30 21:05 50536 ----a-w- c:\windows.0\system32\jdns_sd.dll
2011-08-30 21:05 . 2011-08-30 21:05 178536 ----a-w- c:\windows.0\system32\dnssdX.dll
2011-08-15 11:55 . 2011-07-10 12:11 404640 ----a-w- c:\windows.0\system32\FlashPlayerCPLApp.cpl
2011-08-09 12:24 . 2011-08-09 12:24 154136 ----a-w- c:\windows.0\system32\drivers\eamon.sys
2011-08-09 07:37 . 2011-08-09 07:37 39824 ----a-w- c:\windows.0\system32\drivers\epfwndis.sys
2011-08-08 05:08 . 2011-08-08 05:08 40016 ----a-w- c:\windows.0\system32\drivers\avgmfx86.sys
2011-09-30 20:26 . 2011-07-11 15:17 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . 8F31505484A190D5B22274708799F4EC . 59904 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\regsvc.dll
.
[-] 2008-04-14 . 3FF232A7731621B8902D81D42418C93C . 192512 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\schedsvc.dll
.
[-] 2008-04-14 . BECD5271DC4E3B7C3D035F790FCBC1E5 . 71680 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ssdpsrv.dll
.
c:\windows.0\System32\regsvc.dll ... chybí !!
c:\windows.0\System32\schedsvc.dll ... chybí !!
c:\windows.0\System32\ssdpsrv.dll ... chybí !!
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows.0\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows.0\system32\NvMcTray.dll" [2006-03-09 86016]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 90112]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-05-20 247760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstall ... er=9.0.914" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-17 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows.0\system32\tscupgrd.exe" [2004-08-17 44544]
.
c:\documents and settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění\
SolidWorks Nástroj pro stahování na pozadí.lnk - c:\program files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe [2011-10-14 1834280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2011-07-11 11:36 400760 ----a-w- c:\program files\BitTorrent\BitTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
2011-07-18 13:26 6812032 ----a-w- e:\program files\QIP 2010\qip.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 16:06 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
2010-12-13 14:06 187776 ----a-w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\QipGuard\QipGuard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS.0\\update.tray-3-0\\svchost.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows.0\system32\drivers\AVGIDSEH.sys [11.7.2011 1:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows.0\system32\drivers\avgrkx86.sys [13.9.2011 6:30 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows.0\system32\drivers\avgldx86.sys [11.7.2011 1:13 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows.0\system32\drivers\avgtdix.sys [11.7.2011 1:14 295248]
R1 ehdrv;ehdrv;c:\windows.0\system32\drivers\ehdrv.sys [4.8.2011 8:20 118104]
R1 epfwtdir;epfwtdir;c:\windows.0\system32\drivers\epfwtdir.sys [4.8.2011 8:20 103112]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [29.10.2011 18:13 337872]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows.0\system32\IPROSetMonitor.exe [10.7.2011 13:27 112800]
R3 Avgfwdx;Avgfwdx;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows.0\system32\drivers\AVGIDSDriver.sys [11.7.2011 1:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows.0\system32\drivers\AVGIDSFilter.sys [11.7.2011 1:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows.0\system32\drivers\AVGIDSShim.sys [11.7.2011 1:14 16720]
S2 aswFsBlk;aswFsBlk;aswFsBlk.sys --> aswFsBlk.sys [?]
S2 avgfws;AVG Firewall;"c:\program files\AVG\AVG2012\avgfws.exe" --> c:\program files\AVG\AVG2012\avgfws.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;"c:\program files\AVG\AVG2012\AVGIDSAgent.exe" --> c:\program files\AVG\AVG2012\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG2012\avgwdsvc.exe" --> c:\program files\AVG\AVG2012\avgwdsvc.exe [?]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe --> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [8.1.2011 7:17 87336]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [18.12.2009 10:58 11336]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/#utm_source=icq&utm_medium=generic
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: Add to Google Photos Screensa&ver - c:\windows.0\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/#utm_source=icq&utm_medium=generic
FF - prefs.js: keyword.URL - hxxp://zinkwink.com/?clid=c088e56028bc43cdb48605665aad7edd&prt=corsairzwbho&tmp=nemo_results&keywords=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{B4FBA8C3-2083-4ED8-A35B-148478739826} - c:\program files\Corsair Addon\corsair.dll
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{B4FBA8C3-2083-4ED8-A35B-148478739826} - c:\program files\Corsair Addon\corsair.dll
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
HKLM-Run-UUSeeMediaCenter - c:\program files\Common Files\uusee\UUSeeMediaCenter.exe
HKLM-Run-EasyDownloads - c:\program files\Easy Downloads\easydownloads.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico4 - (no file)
HKLM-Run-AVG_TRAY - c:\program files\AVG\AVG2012\avgtray.exe
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
AddRemove-AVG - c:\program files\AVG\AVG2012\avgmfapx.exe
AddRemove-Corsair Addon - c:\program files\Corsair Addon\uninstall.exe
AddRemove-Tournament Shark - c:\program files\Poker Pro Labs\Tournament Shark\TournamentSharkUpdate.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-02 21:06
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(152)
c:\windows.0\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows.0\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows.0\system32\wdfmgr.exe
c:\windows.0\system32\RUNDLL32.EXE
c:\program files\Common Files\Manac:\windows.0\system32\wuauclt.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows.0\system32\wbem\wmiapsrv.exe
c:\windows.0\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-11-02 21:11:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-02 20:11
.
Před spuštěním: 6 607 618 048
Po spuštění: 7 451 156 480
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0="Microsoft Windows XP Professional" /noexecute=AlwaysOff /fastdetect
.
- - End Of File - - 44E972F5EE88FB8D7ACE8C6F89566F57
ComboFix 11-11-02.03 - Honza 02.11.2011 20:51:20.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.316 [GMT 1:00]
Spuštěný z: c:\documents and settings\Honza.HONZA-714D35E86\Plocha\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0\X
c:\program files\Corsair Addon
c:\program files\Corsair Addon\corsair.dll
c:\program files\Corsair Addon\uninstall.exe
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome.manifest
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\constants.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\events.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\netutils.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\searcher.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\searcher.xul
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\chrome\content\utils.js
c:\program files\Mozilla Firefox\extensions\corsair@corsair.com\install.rdf
c:\windows.0\$NtUninstallKB41879$
c:\windows.0\$NtUninstallKB41879$\2462633632\@
c:\windows.0\$NtUninstallKB41879$\2462633632\L\hxwgrnns
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@00000001
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@000000c0
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@000000cb
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@000000cf
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@80000000
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@800000c0
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@800000cb
c:\windows.0\$NtUninstallKB41879$\2462633632\U\@800000cf
c:\windows.0\$NtUninstallKB41879$\3979956749
c:\windows.0\2697906322
c:\windows.0\av_ico
c:\windows.0\av_ico\ico_avast_desktop.ico
c:\windows.0\av_ico\ico_avast_start.ico
c:\windows.0\av_ico\ico_NOD_AV_START.ico
c:\windows.0\av_ico\ico_NOD_SS_START.ico
c:\windows.0\av_ico\ico_NOD_SYSINSP.ico
c:\windows.0\av_ico\ico_NOD_SYSRESC.ico
c:\windows.0\av_ico\ico_NOD_TXT.ico
c:\windows.0\av_ico\ico_NOD_UNINSTALL.ico
c:\windows.0\msmqinst.log
c:\windows.0\phoenix
c:\windows.0\phoenix\kernels\phatk\__init__.py
c:\windows.0\phoenix\kernels\phatk\__init__.pyc
c:\windows.0\phoenix\kernels\phatk\BFIPatcher.py
c:\windows.0\phoenix\kernels\phatk\kernel.cl
c:\windows.0\phoenix\kernels\poclbm\__init__.py
c:\windows.0\phoenix\kernels\poclbm\__init__.pyc
c:\windows.0\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows.0\phoenix\kernels\poclbm\kernel.cl
c:\windows.0\phoenix\phoenix.exe
c:\windows.0\rpcminer
c:\windows.0\rpcminer\bitcoinminercuda_10.cubin
c:\windows.0\rpcminer\bitcoinminercuda_11.cubin
c:\windows.0\rpcminer\bitcoinminercuda_20.cubin
c:\windows.0\rpcminer\bitcoinmineropencl.cl
c:\windows.0\rpcminer\cudart32_32_16.dll
c:\windows.0\rpcminer\curllib.dll
c:\windows.0\rpcminer\libeay32.dll
c:\windows.0\rpcminer\libsasl.dll
c:\windows.0\rpcminer\openldap.dll
c:\windows.0\rpcminer\rpcminer-4way.exe
c:\windows.0\rpcminer\rpcminer-cpu.exe
c:\windows.0\rpcminer\rpcminer-cuda.exe
c:\windows.0\rpcminer\rpcminer-opencl.exe
c:\windows.0\rpcminer\ssleay32.dll
c:\windows.0\sysdriver32_.exe
c:\windows.0\update.1
c:\windows.0\update.1\svchost.exe
c:\windows.0\update.2
c:\windows.0\update.2\svchost.exe
c:\windows.0\update.5.0
c:\windows.0\update.5.0\svchost.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_SRVBTCCLIENT
-------\Legacy_SRVIECHECK
-------\Legacy_SRVSYSDRIVER32
-------\Legacy_WXPDRIVERS
-------\Service_92c8cea0
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-02 do 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\system32\wbem\snmp
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\srchasst
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\system32\xircom
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\msagent
2011-11-02 19:55 . 2011-11-02 19:55 -------- d-----w- c:\windows.0\LastGood.Tmp
2011-11-02 19:16 . 2011-11-02 19:16 -------- d--h--w- c:\windows.0\update.tray-7-0
2011-11-02 19:16 . 2011-11-02 19:16 -------- d--h--w- c:\windows.0\update.tray-7-0-lnk
2011-11-02 19:02 . 2011-09-06 21:36 20568 ----a-w- c:\windows.0\system32\drivers\aswFsBlk.sys
2011-11-02 19:02 . 2011-09-06 21:37 320856 ----a-w- c:\windows.0\system32\drivers\aswSP.sys
2011-11-02 19:02 . 2011-09-06 21:36 34392 ----a-w- c:\windows.0\system32\drivers\aswRdr.sys
2011-11-02 19:02 . 2011-09-06 21:36 52568 ----a-w- c:\windows.0\system32\drivers\aswTdi.sys
2011-11-02 19:02 . 2011-09-06 21:38 442200 ----a-w- c:\windows.0\system32\drivers\aswSnx.sys
2011-11-02 19:02 . 2011-09-06 21:36 110552 ----a-w- c:\windows.0\system32\drivers\aswmon2.sys
2011-11-02 19:02 . 2011-09-06 21:36 104536 ----a-w- c:\windows.0\system32\drivers\aswmon.sys
2011-11-02 19:02 . 2011-09-06 21:33 30808 ----a-w- c:\windows.0\system32\drivers\aavmker4.sys
2011-11-02 19:01 . 2011-09-06 21:45 41184 ----a-w- c:\windows.0\avastSS.scr
2011-11-02 19:01 . 2011-09-06 21:45 199304 ----a-w- c:\windows.0\system32\aswBoot.exe
2011-11-02 18:44 . 2011-11-02 18:44 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Threat Expert
2011-11-02 18:41 . 2011-11-02 20:02 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0
2011-11-02 18:21 . 2011-11-02 18:59 -------- d-----w- c:\program files\trend micro
2011-11-02 18:21 . 2011-11-02 18:21 -------- d-----w- C:\rsit
2011-10-30 12:34 . 2011-10-30 12:34 -------- d--h--w- c:\windows.0\update.tray-12-0
2011-10-30 12:34 . 2011-10-30 12:34 -------- d--h--w- c:\windows.0\update.tray-12-0-lnk
2011-10-30 12:33 . 2011-10-30 12:33 -------- d-----w- c:\program files\ASK.COM
2011-10-30 12:32 . 2011-10-30 12:32 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG2012
2011-10-30 12:31 . 2011-10-30 12:31 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG Secure Search
2011-10-30 12:29 . 2011-10-30 12:30 -------- d-----w- c:\windows.0\system32\drivers\AVG
2011-10-30 11:45 . 2011-10-30 12:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\MFAData
2011-10-29 17:59 . 2011-10-29 17:59 -------- d--h--w- c:\windows.0\update.tray-2-0
2011-10-29 17:59 . 2011-10-29 17:59 -------- d--h--w- c:\windows.0\update.tray-2-0-lnk
2011-10-29 17:13 . 2011-05-20 09:44 767952 ----a-w- c:\windows.0\BDTSupport.dll
2011-10-29 17:13 . 2011-05-20 09:44 149456 ----a-w- c:\windows.0\SGDetectionTool.dll
2011-10-29 17:13 . 2011-05-20 09:44 2078672 ----a-w- c:\windows.0\PCTBDCore.dll
2011-10-29 17:13 . 2011-05-20 09:44 1533904 ----a-w- c:\windows.0\PCTBDRes.dll
2011-10-29 17:06 . 2011-10-29 17:58 -------- d-----w- c:\program files\PC Tools Security
2011-10-29 17:06 . 2011-11-02 20:06 -------- d---a-w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\TEMP
2011-10-29 10:07 . 2011-10-29 10:07 -------- d-----r- c:\documents and settings\NetworkService.NT AUTHORITY\Oblíbené položky
2011-10-29 10:00 . 2011-10-29 10:00 -------- d-----w- c:\windows.0\ufa
2011-10-28 21:32 . 2011-10-29 10:00 246272 ----a-w- c:\windows.0\unrar.exe
2011-10-28 21:28 . 2011-11-02 18:39 257024 ----a-w- c:\windows.0\sysdriver32.exe
2011-10-28 21:25 . 2011-10-28 21:25 -------- d--h--w- c:\windows.0\update.tray-3-0
2011-10-28 21:25 . 2011-10-28 21:25 -------- d--h--w- c:\windows.0\update.tray-3-0-lnk
2011-10-28 21:14 . 2011-10-28 21:14 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Nabídka Start
2011-10-28 21:14 . 2011-10-28 21:13 1201152 ----a-w- c:\windows.0\services32.exe
2011-10-26 17:20 . 2011-10-26 17:20 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2011-10-26 17:20 . 2011-10-26 17:20 -------- d-----w- c:\program files\ICQ6Toolbar
2011-10-26 17:19 . 2011-10-26 17:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\ICQ
2011-10-26 17:18 . 2011-10-26 18:19 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ICQ
2011-10-21 20:20 . 2011-10-21 20:20 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 20:19 . 2011-10-21 20:19 -------- d-sh--w- c:\documents and settings\Honza.HONZA-714D35E86\IETldCache
2011-10-21 20:13 . 2010-05-06 10:35 12800 -c----w- c:\windows.0\system32\dllcache\xpshims.dll
2011-10-21 20:13 . 2010-05-06 10:35 599040 -c----w- c:\windows.0\system32\dllcache\msfeeds.dll
2011-10-21 20:13 . 2010-05-06 10:35 55296 -c----w- c:\windows.0\system32\dllcache\msfeedsbs.dll
2011-10-21 20:13 . 2010-05-06 10:35 247808 -c----w- c:\windows.0\system32\dllcache\ieproxy.dll
2011-10-21 20:13 . 2010-05-06 10:35 1985536 -c----w- c:\windows.0\system32\dllcache\iertutil.dll
2011-10-21 20:13 . 2010-05-06 10:35 11076096 -c----w- c:\windows.0\system32\dllcache\ieframe.dll
2011-10-21 20:13 . 2010-05-06 10:35 743424 -c----w- c:\windows.0\system32\dllcache\iedvtool.dll
2011-10-21 20:09 . 2011-10-21 20:13 -------- dc-h--w- c:\windows.0\ie8
2011-10-21 20:09 . 2011-10-21 20:12 -------- d-----w- c:\windows.0\system32\cs-CZ
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\ESET
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ESET
2011-10-21 20:07 . 2011-10-21 20:07 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 04:44 . 2011-10-21 04:44 -------- d--h--w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Common Files
2011-10-21 04:36 . 2011-10-21 04:36 12536 ----a-w- c:\windows.0\system32\avgrsstx.dll.install_backup
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\program files\BabylonToolbar
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Babylon
2011-10-16 19:41 . 2011-10-16 19:42 -------- d-----w- c:\program files\Agree Free MP3 to M4A AAC Converter
2011-10-14 18:46 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\SolidWorks
2011-10-14 18:31 . 2006-09-20 11:54 1286656 -c----w- c:\windows.0\system32\dllcache\ole32.dll
2011-10-14 18:11 . 2011-10-14 18:11 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-14 18:11 . 2011-10-14 18:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\SolidWorks
2011-10-14 18:01 . 2011-10-14 18:30 -------- d-----w- C:\SolidWorks Data
2011-10-14 17:59 . 2011-10-15 07:20 -------- d-----w- c:\windows.0\SxsCaPendDel
2011-10-14 17:39 . 2011-10-14 17:39 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\EDrawings
2011-10-14 17:38 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\DassaultSystemes
2011-10-14 17:29 . 2011-10-14 18:41 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2011-10-14 17:28 . 2011-10-14 18:11 -------- d-----w- c:\program files\SolidWorks Corp
2011-10-14 17:26 . 2011-10-14 18:03 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2011-10-14 17:26 . 2011-10-14 18:01 -------- d-----w- c:\windows.0\SolidWorks
2011-10-14 17:26 . 2011-10-25 19:47 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\SolidWorks
2011-10-12 18:07 . 2011-10-27 12:17 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Skype
2011-10-12 18:06 . 2011-10-12 18:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Skype
2011-10-11 19:28 . 2011-10-11 19:29 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 03:06 . 2011-07-10 12:09 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2011-10-03 00:37 . 2011-07-10 12:09 73728 ----a-w- c:\windows.0\system32\javacpl.cpl
2011-09-13 05:30 . 2011-09-13 05:30 32592 ----a-w- c:\windows.0\system32\drivers\avgrkx86.sys
2011-08-30 21:05 . 2011-08-30 21:05 83816 ----a-w- c:\windows.0\system32\dns-sd.exe
2011-08-30 21:05 . 2011-08-30 21:05 73064 ----a-w- c:\windows.0\system32\dnssd.dll
2011-08-30 21:05 . 2011-08-30 21:05 50536 ----a-w- c:\windows.0\system32\jdns_sd.dll
2011-08-30 21:05 . 2011-08-30 21:05 178536 ----a-w- c:\windows.0\system32\dnssdX.dll
2011-08-15 11:55 . 2011-07-10 12:11 404640 ----a-w- c:\windows.0\system32\FlashPlayerCPLApp.cpl
2011-08-09 12:24 . 2011-08-09 12:24 154136 ----a-w- c:\windows.0\system32\drivers\eamon.sys
2011-08-09 07:37 . 2011-08-09 07:37 39824 ----a-w- c:\windows.0\system32\drivers\epfwndis.sys
2011-08-08 05:08 . 2011-08-08 05:08 40016 ----a-w- c:\windows.0\system32\drivers\avgmfx86.sys
2011-09-30 20:26 . 2011-07-11 15:17 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . 8F31505484A190D5B22274708799F4EC . 59904 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\regsvc.dll
.
[-] 2008-04-14 . 3FF232A7731621B8902D81D42418C93C . 192512 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\schedsvc.dll
.
[-] 2008-04-14 . BECD5271DC4E3B7C3D035F790FCBC1E5 . 71680 . . [5.1.2600.5512] . . c:\windows.0\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ssdpsrv.dll
.
c:\windows.0\System32\regsvc.dll ... chybí !!
c:\windows.0\System32\schedsvc.dll ... chybí !!
c:\windows.0\System32\ssdpsrv.dll ... chybí !!
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows.0\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows.0\system32\NvMcTray.dll" [2006-03-09 86016]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 90112]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2011-07-11 74752]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-05-20 247760]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstall ... er=9.0.914" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-17 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows.0\system32\tscupgrd.exe" [2004-08-17 44544]
.
c:\documents and settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění\
SolidWorks Nástroj pro stahování na pozadí.lnk - c:\program files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe [2011-10-14 1834280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
2011-07-11 11:36 400760 ----a-w- c:\program files\BitTorrent\BitTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
2011-07-18 13:26 6812032 ----a-w- e:\program files\QIP 2010\qip.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 16:06 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian]
2010-12-13 14:06 187776 ----a-w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\QipGuard\QipGuard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS.0\\update.tray-3-0\\svchost.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows.0\system32\drivers\AVGIDSEH.sys [11.7.2011 1:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows.0\system32\drivers\avgrkx86.sys [13.9.2011 6:30 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows.0\system32\drivers\avgldx86.sys [11.7.2011 1:13 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows.0\system32\drivers\avgtdix.sys [11.7.2011 1:14 295248]
R1 ehdrv;ehdrv;c:\windows.0\system32\drivers\ehdrv.sys [4.8.2011 8:20 118104]
R1 epfwtdir;epfwtdir;c:\windows.0\system32\drivers\epfwtdir.sys [4.8.2011 8:20 103112]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [29.10.2011 18:13 337872]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows.0\system32\IPROSetMonitor.exe [10.7.2011 13:27 112800]
R3 Avgfwdx;Avgfwdx;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows.0\system32\drivers\AVGIDSDriver.sys [11.7.2011 1:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows.0\system32\drivers\AVGIDSFilter.sys [11.7.2011 1:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows.0\system32\drivers\AVGIDSShim.sys [11.7.2011 1:14 16720]
S2 aswFsBlk;aswFsBlk;aswFsBlk.sys --> aswFsBlk.sys [?]
S2 avgfws;AVG Firewall;"c:\program files\AVG\AVG2012\avgfws.exe" --> c:\program files\AVG\AVG2012\avgfws.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;"c:\program files\AVG\AVG2012\AVGIDSAgent.exe" --> c:\program files\AVG\AVG2012\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG2012\avgwdsvc.exe" --> c:\program files\AVG\AVG2012\avgwdsvc.exe [?]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe --> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [8.1.2011 7:17 87336]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [18.12.2009 10:58 11336]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.centrum.cz/#utm_source=icq&utm_medium=generic
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: Add to Google Photos Screensa&ver - c:\windows.0\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 10.0.0.138
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.2.9&q=
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/#utm_source=icq&utm_medium=generic
FF - prefs.js: keyword.URL - hxxp://zinkwink.com/?clid=c088e56028bc43cdb48605665aad7edd&prt=corsairzwbho&tmp=nemo_results&keywords=
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{B4FBA8C3-2083-4ED8-A35B-148478739826} - c:\program files\Corsair Addon\corsair.dll
Toolbar-{95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\AVG Secure Search\8.0.0.34\AVG Secure Search_toolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{B4FBA8C3-2083-4ED8-A35B-148478739826} - c:\program files\Corsair Addon\corsair.dll
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
HKLM-Run-UUSeeMediaCenter - c:\program files\Common Files\uusee\UUSeeMediaCenter.exe
HKLM-Run-EasyDownloads - c:\program files\Easy Downloads\easydownloads.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico4 - (no file)
HKLM-Run-AVG_TRAY - c:\program files\AVG\AVG2012\avgtray.exe
HKLM-Run-vProt - c:\program files\AVG Secure Search\vprot.exe
AddRemove-AVG - c:\program files\AVG\AVG2012\avgmfapx.exe
AddRemove-Corsair Addon - c:\program files\Corsair Addon\uninstall.exe
AddRemove-Tournament Shark - c:\program files\Poker Pro Labs\Tournament Shark\TournamentSharkUpdate.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-02 21:06
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(152)
c:\windows.0\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows.0\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows.0\system32\wdfmgr.exe
c:\windows.0\system32\RUNDLL32.EXE
c:\program files\Common Files\Manac:\windows.0\system32\wuauclt.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows.0\system32\wbem\wmiapsrv.exe
c:\windows.0\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2011-11-02 21:11:19 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-02 20:11
.
Před spuštěním: 6 607 618 048
Po spuštění: 7 451 156 480
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0="Microsoft Windows XP Professional" /noexecute=AlwaysOff /fastdetect
.
- - End Of File - - 44E972F5EE88FB8D7ACE8C6F89566F57
Re: Facebook vrus - prosím o pomoc
Prosim o chvili strpeni, uz pisu docistovaci skript
Re: Facebook vrus - prosím o pomoc

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: File:: c:\windows.0\unrar.exe c:\windows.0\sysdriver32.exe c:\windows.0\services32.exe C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe Folder:: c:\windows.0\LastGood.Tmp c:\windows.0\update.tray-7-0 c:\windows.0\update.tray-7-0-lnk c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0 c:\windows.0\update.tray-12-0 c:\windows.0\update.tray-12-0-lnk c:\program files\ASK.COM c:\windows.0\update.tray-2-0 c:\windows.0\update.tray-2-0-lnk c:\windows.0\ufa c:\windows.0\update.tray-3-0 c:\windows.0\update.tray-3-0-lnk c:\program files\ICQ6Toolbar c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\ESET c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ESET c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\ESET c:\program files\BabylonToolbar Restore:: c:\windows.0\System32\regsvc.dll c:\windows.0\System32\schedsvc.dll c:\windows.0\System32\ssdpsrv.dll Mia:: c:\windows.0\System32\regsvc.dll c:\windows.0\System32\schedsvc.dll c:\windows.0\System32\ssdpsrv.dll Registry:: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WinampAgent"=- "Adobe ARM"=- "QuickTime Task"=- "iTunesHelper"=- "SunJavaUpdateSched"=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "AvgUninstallURL"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QIP Internet Guardian] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000000 "DisableThumbnailCache"=dword:00000000 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS.0\\update.tray-3-0\\svchost.exe"=- "C:\Documents and Settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"=- DDS:: uStart Page = hxxp://www.centrum.cz/#utm_source=icq&u ... um=generic uDefault_Search_URL = hxxp://search.qip.ru uSearchAssistant = hxxp://search.qip.ru/ie Firefox:: FF - ProfilePath - c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.icq.com/search/afe_result ... r=1.2.9&q= FF - prefs.js: browser.search.selectedEngine - ICQ Search FF - prefs.js: browser.startup.homepage - hxxp://www.centrum.cz/#utm_source=icq&u ... um=generic FF - prefs.js: keyword.URL - hxxp://zinkwink.com/?clid=c088e56028bc4 ... &keywords= Reboot::
- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte

Re: Facebook vrus - prosím o pomoc
Log
ComboFix 11-11-02.03 - Honza 02.11.2011 22:02:02.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.261 [GMT 1:00]
Spuštěný z: c:\documents and settings\Honza.HONZA-714D35E86\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Honza.HONZA-714D35E86\Plocha\CFScript.txt
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
FILE ::
"c:\documents and settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"
"c:\windows.0\services32.exe"
"c:\windows.0\sysdriver32.exe"
"c:\windows.0\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ASK.COM
c:\program files\BabylonToolbar
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarEng.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\ICQ6Toolbar\voucher.bmp
c:\program files\ICQ6Toolbar\voucher2.bmp
c:\windows.0\ufa
c:\windows.0\ufa\ufa.exe
c:\windows.0\update.tray-12-0-lnk
c:\windows.0\update.tray-12-0-lnk\svchost.exe
c:\windows.0\update.tray-12-0
c:\windows.0\update.tray-12-0\svchost.exe
c:\windows.0\update.tray-2-0-lnk
c:\windows.0\update.tray-2-0-lnk\svchost.exe
c:\windows.0\update.tray-2-0
c:\windows.0\update.tray-2-0\svchost.exe
c:\windows.0\update.tray-3-0-lnk
c:\windows.0\update.tray-3-0-lnk\svchost.exe
c:\windows.0\update.tray-3-0
c:\windows.0\update.tray-3-0\svchost.exe
c:\windows.0\update.tray-7-0-lnk
c:\windows.0\update.tray-7-0-lnk\svchost.exe
c:\windows.0\update.tray-7-0
c:\windows.0\update.tray-7-0\svchost.exe
.
c:\windows.0\System32\regsvc.dll . . . je infikován!!
.
c:\windows.0\System32\schedsvc.dll . . . je infikován!!
.
c:\windows.0\System32\ssdpsrv.dll . . . je infikován!!
.
c:\windows.0\System32\regsvc.dll . . . chybí !!
.
c:\windows.0\System32\schedsvc.dll . . . chybí !!
.
c:\windows.0\System32\ssdpsrv.dll . . . chybí !!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-02 do 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\system32\wbem\snmp
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\srchasst
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\msagent
2011-11-02 19:02 . 2011-09-06 21:36 20568 ----a-w- c:\windows.0\system32\drivers\aswFsBlk.sys
2011-11-02 19:02 . 2011-09-06 21:37 320856 ----a-w- c:\windows.0\system32\drivers\aswSP.sys
2011-11-02 19:02 . 2011-09-06 21:36 34392 ----a-w- c:\windows.0\system32\drivers\aswRdr.sys
2011-11-02 19:02 . 2011-09-06 21:36 52568 ----a-w- c:\windows.0\system32\drivers\aswTdi.sys
2011-11-02 19:02 . 2011-09-06 21:38 442200 ----a-w- c:\windows.0\system32\drivers\aswSnx.sys
2011-11-02 19:02 . 2011-09-06 21:36 110552 ----a-w- c:\windows.0\system32\drivers\aswmon2.sys
2011-11-02 19:02 . 2011-09-06 21:36 104536 ----a-w- c:\windows.0\system32\drivers\aswmon.sys
2011-11-02 19:02 . 2011-09-06 21:33 30808 ----a-w- c:\windows.0\system32\drivers\aavmker4.sys
2011-11-02 19:01 . 2011-09-06 21:45 41184 ----a-w- c:\windows.0\avastSS.scr
2011-11-02 19:01 . 2011-09-06 21:45 199304 ----a-w- c:\windows.0\system32\aswBoot.exe
2011-11-02 18:44 . 2011-11-02 18:44 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Threat Expert
2011-11-02 18:41 . 2011-11-02 20:02 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0
2011-11-02 18:21 . 2011-11-02 18:59 -------- d-----w- c:\program files\trend micro
2011-11-02 18:21 . 2011-11-02 18:21 -------- d-----w- C:\rsit
2011-10-30 12:32 . 2011-10-30 12:32 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG2012
2011-10-30 12:31 . 2011-10-30 12:31 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG Secure Search
2011-10-30 12:29 . 2011-10-30 12:30 -------- d-----w- c:\windows.0\system32\drivers\AVG
2011-10-30 11:45 . 2011-10-30 12:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\MFAData
2011-10-29 17:13 . 2011-05-20 09:44 767952 ----a-w- c:\windows.0\BDTSupport.dll
2011-10-29 17:13 . 2011-05-20 09:44 149456 ----a-w- c:\windows.0\SGDetectionTool.dll
2011-10-29 17:13 . 2011-05-20 09:44 2078672 ----a-w- c:\windows.0\PCTBDCore.dll
2011-10-29 17:13 . 2011-05-20 09:44 1533904 ----a-w- c:\windows.0\PCTBDRes.dll
2011-10-29 17:06 . 2011-10-29 17:58 -------- d-----w- c:\program files\PC Tools Security
2011-10-29 17:06 . 2011-11-02 21:12 -------- d---a-w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\TEMP
2011-10-29 10:07 . 2011-10-29 10:07 -------- d-----r- c:\documents and settings\NetworkService.NT AUTHORITY\Oblíbené položky
2011-10-28 21:32 . 2011-10-29 10:00 246272 ----a-w- c:\windows.0\unrar.exe
2011-10-28 21:28 . 2011-11-02 18:39 257024 ----a-w- c:\windows.0\sysdriver32.exe
2011-10-28 21:14 . 2011-10-28 21:14 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Nabídka Start
2011-10-28 21:14 . 2011-10-28 21:13 1201152 ----a-w- c:\windows.0\services32.exe
2011-10-26 17:20 . 2011-10-26 17:20 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2011-10-26 17:19 . 2011-10-26 17:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\ICQ
2011-10-26 17:18 . 2011-10-26 18:19 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ICQ
2011-10-21 20:20 . 2011-10-21 20:20 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 20:19 . 2011-10-21 20:19 -------- d-sh--w- c:\documents and settings\Honza.HONZA-714D35E86\IETldCache
2011-10-21 20:13 . 2010-05-06 10:35 12800 -c----w- c:\windows.0\system32\dllcache\xpshims.dll
2011-10-21 20:13 . 2010-05-06 10:35 599040 -c----w- c:\windows.0\system32\dllcache\msfeeds.dll
2011-10-21 20:13 . 2010-05-06 10:35 55296 -c----w- c:\windows.0\system32\dllcache\msfeedsbs.dll
2011-10-21 20:13 . 2010-05-06 10:35 247808 -c----w- c:\windows.0\system32\dllcache\ieproxy.dll
2011-10-21 20:13 . 2010-05-06 10:35 1985536 -c----w- c:\windows.0\system32\dllcache\iertutil.dll
2011-10-21 20:13 . 2010-05-06 10:35 11076096 -c----w- c:\windows.0\system32\dllcache\ieframe.dll
2011-10-21 20:13 . 2010-05-06 10:35 743424 -c----w- c:\windows.0\system32\dllcache\iedvtool.dll
2011-10-21 20:09 . 2011-10-21 20:13 -------- dc-h--w- c:\windows.0\ie8
2011-10-21 20:09 . 2011-10-21 20:12 -------- d-----w- c:\windows.0\system32\cs-CZ
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\ESET
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ESET
2011-10-21 20:07 . 2011-10-21 20:07 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 04:44 . 2011-10-21 04:44 -------- d--h--w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Common Files
2011-10-21 04:36 . 2011-10-21 04:36 12536 ----a-w- c:\windows.0\system32\avgrsstx.dll.install_backup
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Babylon
2011-10-16 19:41 . 2011-10-16 19:42 -------- d-----w- c:\program files\Agree Free MP3 to M4A AAC Converter
2011-10-14 18:46 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\SolidWorks
2011-10-14 18:31 . 2006-09-20 11:54 1286656 -c----w- c:\windows.0\system32\dllcache\ole32.dll
2011-10-14 18:11 . 2011-10-14 18:11 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-14 18:11 . 2011-10-14 18:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\SolidWorks
2011-10-14 18:01 . 2011-10-14 18:30 -------- d-----w- C:\SolidWorks Data
2011-10-14 17:59 . 2011-10-15 07:20 -------- d-----w- c:\windows.0\SxsCaPendDel
2011-10-14 17:39 . 2011-10-14 17:39 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\EDrawings
2011-10-14 17:38 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\DassaultSystemes
2011-10-14 17:29 . 2011-10-14 18:41 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2011-10-14 17:28 . 2011-10-14 18:11 -------- d-----w- c:\program files\SolidWorks Corp
2011-10-14 17:26 . 2011-10-14 18:03 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2011-10-14 17:26 . 2011-10-14 18:01 -------- d-----w- c:\windows.0\SolidWorks
2011-10-14 17:26 . 2011-10-25 19:47 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\SolidWorks
2011-10-12 18:07 . 2011-10-27 12:17 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Skype
2011-10-12 18:06 . 2011-10-12 18:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Skype
2011-10-11 19:28 . 2011-10-11 19:29 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 03:06 . 2011-07-10 12:09 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2011-10-03 00:37 . 2011-07-10 12:09 73728 ----a-w- c:\windows.0\system32\javacpl.cpl
2011-09-13 05:30 . 2011-09-13 05:30 32592 ----a-w- c:\windows.0\system32\drivers\avgrkx86.sys
2011-08-30 21:05 . 2011-08-30 21:05 83816 ----a-w- c:\windows.0\system32\dns-sd.exe
2011-08-30 21:05 . 2011-08-30 21:05 73064 ----a-w- c:\windows.0\system32\dnssd.dll
2011-08-30 21:05 . 2011-08-30 21:05 50536 ----a-w- c:\windows.0\system32\jdns_sd.dll
2011-08-30 21:05 . 2011-08-30 21:05 178536 ----a-w- c:\windows.0\system32\dnssdX.dll
2011-08-15 11:55 . 2011-07-10 12:11 404640 ----a-w- c:\windows.0\system32\FlashPlayerCPLApp.cpl
2011-08-09 12:24 . 2011-08-09 12:24 154136 ----a-w- c:\windows.0\system32\drivers\eamon.sys
2011-08-09 07:37 . 2011-08-09 07:37 39824 ----a-w- c:\windows.0\system32\drivers\epfwndis.sys
2011-08-08 05:08 . 2011-08-08 05:08 40016 ----a-w- c:\windows.0\system32\drivers\avgmfx86.sys
2011-09-30 20:26 . 2011-07-11 15:17 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-02_20.06.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-02 21:12 . 2011-11-02 21:12 16384 c:\windows.0\temp\Perflib_Perfdata_218.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows.0\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows.0\system32\NvMcTray.dll" [2006-03-09 86016]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 90112]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-05-20 247760]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-17 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows.0\system32\tscupgrd.exe" [2004-08-17 44544]
.
c:\documents and settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění\
SolidWorks Nástroj pro stahování na pozadí.lnk - c:\program files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe [2011-10-14 1834280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows.0\system32\drivers\AVGIDSEH.sys [11.7.2011 1:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows.0\system32\drivers\avgrkx86.sys [13.9.2011 6:30 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows.0\system32\drivers\avgldx86.sys [11.7.2011 1:13 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows.0\system32\drivers\avgtdix.sys [11.7.2011 1:14 295248]
R1 ehdrv;ehdrv;c:\windows.0\system32\drivers\ehdrv.sys [4.8.2011 8:20 118104]
R1 epfwtdir;epfwtdir;c:\windows.0\system32\drivers\epfwtdir.sys [4.8.2011 8:20 103112]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [29.10.2011 18:13 337872]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows.0\system32\IPROSetMonitor.exe [10.7.2011 13:27 112800]
R3 Avgfwdx;Avgfwdx;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows.0\system32\drivers\AVGIDSDriver.sys [11.7.2011 1:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows.0\system32\drivers\AVGIDSFilter.sys [11.7.2011 1:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows.0\system32\drivers\AVGIDSShim.sys [11.7.2011 1:14 16720]
S2 aswFsBlk;aswFsBlk;aswFsBlk.sys --> aswFsBlk.sys [?]
S2 avgfws;AVG Firewall;"c:\program files\AVG\AVG2012\avgfws.exe" --> c:\program files\AVG\AVG2012\avgfws.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;"c:\program files\AVG\AVG2012\AVGIDSAgent.exe" --> c:\program files\AVG\AVG2012\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG2012\avgwdsvc.exe" --> c:\program files\AVG\AVG2012\avgwdsvc.exe [?]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe --> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [8.1.2011 7:17 87336]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [18.12.2009 10:58 11336]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: Add to Google Photos Screensa&ver - c:\windows.0\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-02 22:12
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2372)
c:\windows.0\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows.0\system32\nvsvc32.exe
c:\windows.0\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows.0\system32\wdfmgr.exe
c:\windows.0\system32\wscntfy.exe
c:\windows.0\system32\wbem\wmiapsrv.exe
c:\windows.0\system32\RUNDLL32.EXE
c:\program files\Common Files\Manac:\windows.0\system32\wuauclt.exe
.
**************************************************************************
.
Celkový čas: 2011-11-02 22:17:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-02 21:17
ComboFix2.txt 2011-11-02 20:11
.
Před spuštěním: 7 454 011 392
Po spuštění: 7 425 466 368
.
- - End Of File - - 3C0E41B0033CD57F02BF85EA3D2960AC
ComboFix 11-11-02.03 - Honza 02.11.2011 22:02:02.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.261 [GMT 1:00]
Spuštěný z: c:\documents and settings\Honza.HONZA-714D35E86\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Honza.HONZA-714D35E86\Plocha\CFScript.txt
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
FILE ::
"c:\documents and settings\Honza.HONZA-714D35E86\Plocha\Flash-Player.exe"
"c:\windows.0\services32.exe"
"c:\windows.0\sysdriver32.exe"
"c:\windows.0\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\ASK.COM
c:\program files\BabylonToolbar
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarEng.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll
c:\program files\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll
c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt
c:\program files\ICQ6Toolbar\voucher.bmp
c:\program files\ICQ6Toolbar\voucher2.bmp
c:\windows.0\ufa
c:\windows.0\ufa\ufa.exe
c:\windows.0\update.tray-12-0-lnk
c:\windows.0\update.tray-12-0-lnk\svchost.exe
c:\windows.0\update.tray-12-0
c:\windows.0\update.tray-12-0\svchost.exe
c:\windows.0\update.tray-2-0-lnk
c:\windows.0\update.tray-2-0-lnk\svchost.exe
c:\windows.0\update.tray-2-0
c:\windows.0\update.tray-2-0\svchost.exe
c:\windows.0\update.tray-3-0-lnk
c:\windows.0\update.tray-3-0-lnk\svchost.exe
c:\windows.0\update.tray-3-0
c:\windows.0\update.tray-3-0\svchost.exe
c:\windows.0\update.tray-7-0-lnk
c:\windows.0\update.tray-7-0-lnk\svchost.exe
c:\windows.0\update.tray-7-0
c:\windows.0\update.tray-7-0\svchost.exe
.
c:\windows.0\System32\regsvc.dll . . . je infikován!!
.
c:\windows.0\System32\schedsvc.dll . . . je infikován!!
.
c:\windows.0\System32\ssdpsrv.dll . . . je infikován!!
.
c:\windows.0\System32\regsvc.dll . . . chybí !!
.
c:\windows.0\System32\schedsvc.dll . . . chybí !!
.
c:\windows.0\System32\ssdpsrv.dll . . . chybí !!
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-10-02 do 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\system32\wbem\snmp
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\srchasst
2011-11-02 20:05 . 2011-11-02 20:05 -------- d-----w- c:\windows.0\msagent
2011-11-02 19:02 . 2011-09-06 21:36 20568 ----a-w- c:\windows.0\system32\drivers\aswFsBlk.sys
2011-11-02 19:02 . 2011-09-06 21:37 320856 ----a-w- c:\windows.0\system32\drivers\aswSP.sys
2011-11-02 19:02 . 2011-09-06 21:36 34392 ----a-w- c:\windows.0\system32\drivers\aswRdr.sys
2011-11-02 19:02 . 2011-09-06 21:36 52568 ----a-w- c:\windows.0\system32\drivers\aswTdi.sys
2011-11-02 19:02 . 2011-09-06 21:38 442200 ----a-w- c:\windows.0\system32\drivers\aswSnx.sys
2011-11-02 19:02 . 2011-09-06 21:36 110552 ----a-w- c:\windows.0\system32\drivers\aswmon2.sys
2011-11-02 19:02 . 2011-09-06 21:36 104536 ----a-w- c:\windows.0\system32\drivers\aswmon.sys
2011-11-02 19:02 . 2011-09-06 21:33 30808 ----a-w- c:\windows.0\system32\drivers\aavmker4.sys
2011-11-02 19:01 . 2011-09-06 21:45 41184 ----a-w- c:\windows.0\avastSS.scr
2011-11-02 19:01 . 2011-09-06 21:45 199304 ----a-w- c:\windows.0\system32\aswBoot.exe
2011-11-02 18:44 . 2011-11-02 18:44 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Threat Expert
2011-11-02 18:41 . 2011-11-02 20:02 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0
2011-11-02 18:21 . 2011-11-02 18:59 -------- d-----w- c:\program files\trend micro
2011-11-02 18:21 . 2011-11-02 18:21 -------- d-----w- C:\rsit
2011-10-30 12:32 . 2011-10-30 12:32 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG2012
2011-10-30 12:31 . 2011-10-30 12:31 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\AVG Secure Search
2011-10-30 12:29 . 2011-10-30 12:30 -------- d-----w- c:\windows.0\system32\drivers\AVG
2011-10-30 11:45 . 2011-10-30 12:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\MFAData
2011-10-29 17:13 . 2011-05-20 09:44 767952 ----a-w- c:\windows.0\BDTSupport.dll
2011-10-29 17:13 . 2011-05-20 09:44 149456 ----a-w- c:\windows.0\SGDetectionTool.dll
2011-10-29 17:13 . 2011-05-20 09:44 2078672 ----a-w- c:\windows.0\PCTBDCore.dll
2011-10-29 17:13 . 2011-05-20 09:44 1533904 ----a-w- c:\windows.0\PCTBDRes.dll
2011-10-29 17:06 . 2011-10-29 17:58 -------- d-----w- c:\program files\PC Tools Security
2011-10-29 17:06 . 2011-11-02 21:12 -------- d---a-w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\TEMP
2011-10-29 10:07 . 2011-10-29 10:07 -------- d-----r- c:\documents and settings\NetworkService.NT AUTHORITY\Oblíbené položky
2011-10-28 21:32 . 2011-10-29 10:00 246272 ----a-w- c:\windows.0\unrar.exe
2011-10-28 21:28 . 2011-11-02 18:39 257024 ----a-w- c:\windows.0\sysdriver32.exe
2011-10-28 21:14 . 2011-10-28 21:14 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Nabídka Start
2011-10-28 21:14 . 2011-10-28 21:13 1201152 ----a-w- c:\windows.0\services32.exe
2011-10-26 17:20 . 2011-10-26 17:20 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2011-10-26 17:19 . 2011-10-26 17:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\ICQ
2011-10-26 17:18 . 2011-10-26 18:19 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ICQ
2011-10-21 20:20 . 2011-10-21 20:20 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 20:19 . 2011-10-21 20:19 -------- d-sh--w- c:\documents and settings\Honza.HONZA-714D35E86\IETldCache
2011-10-21 20:13 . 2010-05-06 10:35 12800 -c----w- c:\windows.0\system32\dllcache\xpshims.dll
2011-10-21 20:13 . 2010-05-06 10:35 599040 -c----w- c:\windows.0\system32\dllcache\msfeeds.dll
2011-10-21 20:13 . 2010-05-06 10:35 55296 -c----w- c:\windows.0\system32\dllcache\msfeedsbs.dll
2011-10-21 20:13 . 2010-05-06 10:35 247808 -c----w- c:\windows.0\system32\dllcache\ieproxy.dll
2011-10-21 20:13 . 2010-05-06 10:35 1985536 -c----w- c:\windows.0\system32\dllcache\iertutil.dll
2011-10-21 20:13 . 2010-05-06 10:35 11076096 -c----w- c:\windows.0\system32\dllcache\ieframe.dll
2011-10-21 20:13 . 2010-05-06 10:35 743424 -c----w- c:\windows.0\system32\dllcache\iedvtool.dll
2011-10-21 20:09 . 2011-10-21 20:13 -------- dc-h--w- c:\windows.0\ie8
2011-10-21 20:09 . 2011-10-21 20:12 -------- d-----w- c:\windows.0\system32\cs-CZ
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\ESET
2011-10-21 20:08 . 2011-10-21 20:08 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\ESET
2011-10-21 20:07 . 2011-10-21 20:07 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\ESET
2011-10-21 04:44 . 2011-10-21 04:44 -------- d--h--w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Common Files
2011-10-21 04:36 . 2011-10-21 04:36 12536 ----a-w- c:\windows.0\system32\avgrsstx.dll.install_backup
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Babylon
2011-10-20 19:51 . 2011-10-20 19:51 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Babylon
2011-10-16 19:41 . 2011-10-16 19:42 -------- d-----w- c:\program files\Agree Free MP3 to M4A AAC Converter
2011-10-14 18:46 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\SolidWorks
2011-10-14 18:31 . 2006-09-20 11:54 1286656 -c----w- c:\windows.0\system32\dllcache\ole32.dll
2011-10-14 18:11 . 2011-10-14 18:11 -------- d-----w- c:\program files\NVIDIA Corporation
2011-10-14 18:11 . 2011-10-14 18:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\SolidWorks
2011-10-14 18:01 . 2011-10-14 18:30 -------- d-----w- C:\SolidWorks Data
2011-10-14 17:59 . 2011-10-15 07:20 -------- d-----w- c:\windows.0\SxsCaPendDel
2011-10-14 17:39 . 2011-10-14 17:39 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\EDrawings
2011-10-14 17:38 . 2011-10-14 18:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Local Settings\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\DassaultSystemes
2011-10-14 17:38 . 2011-10-14 17:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\DassaultSystemes
2011-10-14 17:29 . 2011-10-14 18:41 -------- d-----w- c:\program files\Common Files\SolidWorks Shared
2011-10-14 17:28 . 2011-10-14 18:11 -------- d-----w- c:\program files\SolidWorks Corp
2011-10-14 17:26 . 2011-10-14 18:03 -------- d-----w- c:\program files\Common Files\Manažer instalací SolidWorks
2011-10-14 17:26 . 2011-10-14 18:01 -------- d-----w- c:\windows.0\SolidWorks
2011-10-14 17:26 . 2011-10-25 19:47 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\SolidWorks
2011-10-12 18:07 . 2011-10-27 12:17 -------- d-----w- c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Skype
2011-10-12 18:06 . 2011-10-12 18:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Data aplikací\Skype
2011-10-11 19:28 . 2011-10-11 19:29 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-03 03:06 . 2011-07-10 12:09 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2011-10-03 00:37 . 2011-07-10 12:09 73728 ----a-w- c:\windows.0\system32\javacpl.cpl
2011-09-13 05:30 . 2011-09-13 05:30 32592 ----a-w- c:\windows.0\system32\drivers\avgrkx86.sys
2011-08-30 21:05 . 2011-08-30 21:05 83816 ----a-w- c:\windows.0\system32\dns-sd.exe
2011-08-30 21:05 . 2011-08-30 21:05 73064 ----a-w- c:\windows.0\system32\dnssd.dll
2011-08-30 21:05 . 2011-08-30 21:05 50536 ----a-w- c:\windows.0\system32\jdns_sd.dll
2011-08-30 21:05 . 2011-08-30 21:05 178536 ----a-w- c:\windows.0\system32\dnssdX.dll
2011-08-15 11:55 . 2011-07-10 12:11 404640 ----a-w- c:\windows.0\system32\FlashPlayerCPLApp.cpl
2011-08-09 12:24 . 2011-08-09 12:24 154136 ----a-w- c:\windows.0\system32\drivers\eamon.sys
2011-08-09 07:37 . 2011-08-09 07:37 39824 ----a-w- c:\windows.0\system32\drivers\epfwndis.sys
2011-08-08 05:08 . 2011-08-08 05:08 40016 ----a-w- c:\windows.0\system32\drivers\avgmfx86.sys
2011-09-30 20:26 . 2011-07-11 15:17 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-02_20.06.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-02 21:12 . 2011-11-02 21:12 16384 c:\windows.0\temp\Perflib_Perfdata_218.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows.0\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"NvMediaCenter"="c:\windows.0\system32\NvMcTray.dll" [2006-03-09 86016]
"Smapp"="c:\program files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 90112]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2011-05-20 247760]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-17 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows.0\system32\tscupgrd.exe" [2004-08-17 44544]
.
c:\documents and settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění\
SolidWorks Nástroj pro stahování na pozadí.lnk - c:\program files\Common Files\Manažer instalací SolidWorks\BackgroundDownloading\sldBgDwld.exe [2011-10-14 1834280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows.0\system32\drivers\AVGIDSEH.sys [11.7.2011 1:14 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows.0\system32\drivers\avgrkx86.sys [13.9.2011 6:30 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows.0\system32\drivers\avgldx86.sys [11.7.2011 1:13 229840]
R1 Avgtdix;AVG TDI Driver;c:\windows.0\system32\drivers\avgtdix.sys [11.7.2011 1:14 295248]
R1 ehdrv;ehdrv;c:\windows.0\system32\drivers\ehdrv.sys [4.8.2011 8:20 118104]
R1 epfwtdir;epfwtdir;c:\windows.0\system32\drivers\epfwtdir.sys [4.8.2011 8:20 103112]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [29.10.2011 18:13 337872]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows.0\system32\IPROSetMonitor.exe [10.7.2011 13:27 112800]
R3 Avgfwdx;Avgfwdx;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows.0\system32\drivers\AVGIDSDriver.sys [11.7.2011 1:14 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows.0\system32\drivers\AVGIDSFilter.sys [11.7.2011 1:14 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows.0\system32\drivers\AVGIDSShim.sys [11.7.2011 1:14 16720]
S2 aswFsBlk;aswFsBlk;aswFsBlk.sys --> aswFsBlk.sys [?]
S2 avgfws;AVG Firewall;"c:\program files\AVG\AVG2012\avgfws.exe" --> c:\program files\AVG\AVG2012\avgfws.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;"c:\program files\AVG\AVG2012\AVGIDSAgent.exe" --> c:\program files\AVG\AVG2012\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;"c:\program files\AVG\AVG2012\avgwdsvc.exe" --> c:\program files\AVG\AVG2012\avgwdsvc.exe [?]
S2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe --> c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [?]
S3 Avgfwfd;AVG network filter service;c:\windows.0\system32\drivers\avgfwdx.sys [23.5.2011 1:03 30944]
S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [8.1.2011 7:17 87336]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [18.12.2009 10:58 11336]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23.9.2005 6:01 2799808]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://search.qip.ru/ie
IE: Add to Google Photos Screensa&ver - c:\windows.0\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} -
FF - ProfilePath - c:\documents and settings\Honza.HONZA-714D35E86\Data aplikací\Mozilla\Firefox\Profiles\frgg680j.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-02 22:12
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2372)
c:\windows.0\system32\webcheck.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows.0\system32\nvsvc32.exe
c:\windows.0\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows.0\system32\wdfmgr.exe
c:\windows.0\system32\wscntfy.exe
c:\windows.0\system32\wbem\wmiapsrv.exe
c:\windows.0\system32\RUNDLL32.EXE
c:\program files\Common Files\Manac:\windows.0\system32\wuauclt.exe
.
**************************************************************************
.
Celkový čas: 2011-11-02 22:17:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-11-02 21:17
ComboFix2.txt 2011-11-02 20:11
.
Před spuštěním: 7 454 011 392
Po spuštění: 7 425 466 368
.
- - End Of File - - 3C0E41B0033CD57F02BF85EA3D2960AC
Re: Facebook vrus - prosím o pomoc

- Vice info mate zde http://www.viry.cz/forum/viewtopic.php?f=46&t=86100

Re: Facebook vrus - prosím o pomoc
Splněno co dále 

Re: Facebook vrus - prosím o pomoc
Dame si dalsi skript pro ComboFix - postup je stejny
Kód: Vybrat vše
KillAll::
Folder::
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0
Collect::
c:\windows.0\unrar.exe
c:\windows.0\sysdriver32.exe
c:\windows.0\services32.exe
Reboot::
Re: Facebook vrus - prosím o pomoc
Log má moc znaku url zde http://czshare.com/2207299/log.txt
Re: Facebook vrus - prosím o pomoc

- Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
- Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
Kód: Vybrat vše
:files c:\windows.0\unrar.exe c:\windows.0\sysdriver32.exe c:\windows.0\services32.exe c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0 %windir%\system32\*.tmp.dll /s %windir%\system32\SET*.tmp /s %windir%\*.tmp :commands [RESETHOSTS] [EMPTYTEMP] [EMPTYFLASH]
- Kliknete na cervene tlacitko MoveIt!
- Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
Re: Facebook vrus - prosím o pomoc
All processes killed
========== FILES ==========
c:\windows.0\unrar.exe moved successfully.
c:\windows.0\sysdriver32.exe moved successfully.
c:\windows.0\services32.exe moved successfully.
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0\U folder moved successfully.
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0 folder moved successfully.
File/Folder C:\WINDOWS.0\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS.0\system32\SET*.tmp not found.
C:\WINDOWS.0\002519_.tmp moved successfully.
C:\WINDOWS.0\SET3.tmp moved successfully.
C:\WINDOWS.0\SET4.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS.0\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: All Users.WINDOWS.0
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User.WINDOWS.0
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Honza
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 6455952 bytes
User: Honza.HONZA-714D35E86
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 354991 bytes
->Java cache emptied: 6005459 bytes
->FireFox cache emptied: 43791718 bytes
->Opera cache emptied: 18423194 bytes
->Flash cache emptied: 66147 bytes
User: HONZA~1~HON
User: Karel Navrtil
->Temp folder emptied: 0 bytes
User: Karel Navrátil
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 43353349 bytes
->Opera cache emptied: 240 bytes
->Flash cache emptied: 1957 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49554 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34306 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 113,00 mb
[EMPTYFLASH]
User: All Users
User: All Users.WINDOWS.0
User: Default User
User: Default User.WINDOWS.0
User: Honza
User: Honza.HONZA-714D35E86
->Flash cache emptied: 0 bytes
User: HONZA~1~HON
User: Karel Navrtil
User: Karel Navrátil
->Flash cache emptied: 0 bytes
User: LocalService
User: LocalService.NT AUTHORITY
User: NetworkService
User: NetworkService.NT AUTHORITY
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 11062011_201101
Files moved on Reboot...
File C:\WINDOWS.0\temp\_avast_\Webshlock.txt not found!
Registry entries deleted on Reboot...
========== FILES ==========
c:\windows.0\unrar.exe moved successfully.
c:\windows.0\sysdriver32.exe moved successfully.
c:\windows.0\services32.exe moved successfully.
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0\U folder moved successfully.
c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Data aplikací\92c8cea0 folder moved successfully.
File/Folder C:\WINDOWS.0\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS.0\system32\SET*.tmp not found.
C:\WINDOWS.0\002519_.tmp moved successfully.
C:\WINDOWS.0\SET3.tmp moved successfully.
C:\WINDOWS.0\SET4.tmp moved successfully.
========== COMMANDS ==========
C:\WINDOWS.0\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: All Users.WINDOWS.0
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User.WINDOWS.0
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Honza
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->FireFox cache emptied: 6455952 bytes
User: Honza.HONZA-714D35E86
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 354991 bytes
->Java cache emptied: 6005459 bytes
->FireFox cache emptied: 43791718 bytes
->Opera cache emptied: 18423194 bytes
->Flash cache emptied: 66147 bytes
User: HONZA~1~HON
User: Karel Navrtil
->Temp folder emptied: 0 bytes
User: Karel Navrátil
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 43353349 bytes
->Opera cache emptied: 240 bytes
->Flash cache emptied: 1957 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49554 bytes
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34306 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 113,00 mb
[EMPTYFLASH]
User: All Users
User: All Users.WINDOWS.0
User: Default User
User: Default User.WINDOWS.0
User: Honza
User: Honza.HONZA-714D35E86
->Flash cache emptied: 0 bytes
User: HONZA~1~HON
User: Karel Navrtil
User: Karel Navrátil
->Flash cache emptied: 0 bytes
User: LocalService
User: LocalService.NT AUTHORITY
User: NetworkService
User: NetworkService.NT AUTHORITY
Total Flash Files Cleaned = 0,00 mb
OTM by OldTimer - Version 3.1.19.0 log created on 11062011_201101
Files moved on Reboot...
File C:\WINDOWS.0\temp\_avast_\Webshlock.txt not found!
Registry entries deleted on Reboot...
Re: Facebook vrus - prosím o pomoc

- Prejmenujte ComboFix na Uninstall
- Spustte jej
- Tohle smaze Combofix a jeho slozky

- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)

- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC

- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte

- http://download.avg.com/filedir/util/su ... 1_1184.exe
- http://download.eset.com/special/ESETUninstaller.exe navod zde http://www.viry.cz/forum/viewtopic.php?p=889437#p889437
- http://files.avast.com/files/eng/aswclear.exe

Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy

