Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

UFA.exe - facebook vir

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: UFA.exe - facebook vir

#31 Příspěvek od vyosek »

:arrow: Havet se usadila v bodech obnoveni - smazte je dle navodu kolegy riffa http://www.viry.cz/forum/viewtopic.php?f=11&t=47040

:arrow: Znovu TDSSKiller a log sem

:arrow: Napiste jak se chova PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

aragor
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 17 lis 2011 16:42

Re: UFA.exe - facebook vir

#32 Příspěvek od aragor »

PC se chová normálně

22:06:52.0750 3640 TDSS rootkit removing tool 2.6.19.0 Nov 16 2011 12:18:50
22:06:53.0093 3640 ============================================================
22:06:53.0093 3640 Current date / time: 2011/11/18 22:06:53.0093
22:06:53.0093 3640 SystemInfo:
22:06:53.0093 3640
22:06:53.0093 3640 OS Version: 5.1.2600 ServicePack: 2.0
22:06:53.0093 3640 Product type: Workstation
22:06:53.0093 3640 ComputerName: HERNIPC
22:06:53.0093 3640 UserName: Hráč
22:06:53.0093 3640 Windows directory: F:\WINDOWS
22:06:53.0093 3640 System windows directory: F:\WINDOWS
22:06:53.0093 3640 Processor architecture: Intel x86
22:06:53.0093 3640 Number of processors: 1
22:06:53.0093 3640 Page size: 0x1000
22:06:53.0093 3640 Boot type: Normal boot
22:06:53.0093 3640 ============================================================
22:06:53.0609 3640 Initialize success
22:06:58.0984 3768 ============================================================
22:06:58.0984 3768 Scan started
22:06:58.0984 3768 Mode: Manual;
22:06:58.0984 3768 ============================================================
22:06:59.0203 3768 Abiosdsk - ok
22:06:59.0218 3768 abp480n5 - ok
22:06:59.0250 3768 acedrv11 (27f954120babb8a00f8745d8f5bc9b82) F:\WINDOWS\system32\drivers\acedrv11.sys
22:06:59.0265 3768 acedrv11 - ok
22:06:59.0296 3768 ACPI (fa2fbcda96d2385f773b059fe5a125a6) F:\WINDOWS\system32\DRIVERS\ACPI.sys
22:06:59.0296 3768 ACPI - ok
22:06:59.0343 3768 ACPIEC (afdff022a01f0b11c776f0860c3b282f) F:\WINDOWS\system32\drivers\ACPIEC.sys
22:06:59.0343 3768 ACPIEC - ok
22:06:59.0359 3768 adpu160m - ok
22:06:59.0421 3768 aec (1ee7b434ba961ef845de136224c30fec) F:\WINDOWS\system32\drivers\aec.sys
22:06:59.0421 3768 aec - ok
22:06:59.0531 3768 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) F:\WINDOWS\System32\drivers\afd.sys
22:06:59.0531 3768 AFD - ok
22:06:59.0562 3768 Aha154x - ok
22:06:59.0578 3768 aic78u2 - ok
22:06:59.0593 3768 aic78xx - ok
22:06:59.0703 3768 ALCXWDM (c881453898eec64027274ebb3c8cbc0f) F:\WINDOWS\system32\drivers\ALCXWDM.SYS
22:06:59.0812 3768 ALCXWDM - ok
22:06:59.0828 3768 AliIde - ok
22:06:59.0875 3768 AmdK8 (59301936898ae62245a6f09c0aba9475) F:\WINDOWS\system32\DRIVERS\AmdK8.sys
22:06:59.0875 3768 AmdK8 - ok
22:06:59.0906 3768 Amfilter (779e01016ffc3eaf8190b2dbd852b9d0) F:\WINDOWS\system32\DRIVERS\Amfilter.sys
22:06:59.0906 3768 Amfilter - ok
22:06:59.0968 3768 AMON (687c3f2e78aeb209ade1cc265a2560bb) F:\WINDOWS\system32\drivers\amon.sys
22:06:59.0984 3768 AMON - ok
22:07:00.0031 3768 Amps2prt (c194327c210aade3f836869ae6b285a3) F:\WINDOWS\system32\DRIVERS\Amps2prt.sys
22:07:00.0031 3768 Amps2prt - ok
22:07:00.0078 3768 amsint - ok
22:07:00.0109 3768 Amusbprt (5139adcded43c45c486c75d7bf3a03a4) F:\WINDOWS\system32\DRIVERS\Amusbprt.sys
22:07:00.0109 3768 Amusbprt - ok
22:07:00.0156 3768 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) F:\WINDOWS\system32\DRIVERS\arp1394.sys
22:07:00.0156 3768 Arp1394 - ok
22:07:00.0187 3768 asc - ok
22:07:00.0187 3768 asc3350p - ok
22:07:00.0203 3768 asc3550 - ok
22:07:00.0265 3768 AsyncMac (02000abf34af4c218c35d257024807d6) F:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:07:00.0265 3768 AsyncMac - ok
22:07:00.0312 3768 atapi (cdfe4411a69c224bd1d11b2da92dac51) F:\WINDOWS\system32\DRIVERS\atapi.sys
22:07:00.0312 3768 atapi - ok
22:07:00.0343 3768 Atdisk - ok
22:07:00.0390 3768 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) F:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:07:00.0390 3768 Atmarpc - ok
22:07:00.0453 3768 audstub (d9f724aa26c010a217c97606b160ed68) F:\WINDOWS\system32\DRIVERS\audstub.sys
22:07:00.0453 3768 audstub - ok
22:07:00.0515 3768 Beep (da1f27d85e0d1525f6621372e7b685e9) F:\WINDOWS\system32\drivers\Beep.sys
22:07:00.0515 3768 Beep - ok
22:07:00.0515 3768 catchme - ok
22:07:00.0562 3768 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) F:\WINDOWS\system32\drivers\cbidf2k.sys
22:07:00.0562 3768 cbidf2k - ok
22:07:00.0593 3768 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) F:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:07:00.0593 3768 CCDECODE - ok
22:07:00.0625 3768 cd20xrnt - ok
22:07:00.0656 3768 Cdaudio (c1b486a7658353d33a10cc15211a873b) F:\WINDOWS\system32\drivers\Cdaudio.sys
22:07:00.0656 3768 Cdaudio - ok
22:07:00.0703 3768 Cdfs (cd7d5152df32b47f4e36f710b35aae02) F:\WINDOWS\system32\drivers\Cdfs.sys
22:07:00.0703 3768 Cdfs - ok
22:07:00.0750 3768 cdrbsdrv (351735695e9ead93de6af85d8beb1ca8) F:\WINDOWS\system32\drivers\cdrbsdrv.sys
22:07:00.0750 3768 cdrbsdrv - ok
22:07:00.0765 3768 cdrbsvsd - ok
22:07:00.0781 3768 Cdrom (af9c19b3100fe010496b1a27181fbf72) F:\WINDOWS\system32\DRIVERS\cdrom.sys
22:07:00.0781 3768 Cdrom - ok
22:07:00.0828 3768 Changer - ok
22:07:00.0875 3768 CmdIde - ok
22:07:00.0906 3768 Cpqarray - ok
22:07:00.0937 3768 CTIpHook - ok
22:07:00.0953 3768 dac2w2k - ok
22:07:00.0984 3768 dac960nt - ok
22:07:01.0031 3768 DCamUSBCompany (73d932edbbfc0b8e58f6a2c018fa2151) F:\WINDOWS\system32\DRIVERS\p35u.sys
22:07:01.0031 3768 DCamUSBCompany - ok
22:07:01.0078 3768 Disk (00ca44e4534865f8a3b64f7c0984bff0) F:\WINDOWS\system32\DRIVERS\disk.sys
22:07:01.0078 3768 Disk - ok
22:07:01.0156 3768 dmboot (e1968edec81c430108feb23ab07bdb14) F:\WINDOWS\system32\drivers\dmboot.sys
22:07:01.0187 3768 dmboot - ok
22:07:01.0234 3768 dmio (1b1520a82e396e46b9ae9fa6b03ff6c6) F:\WINDOWS\system32\drivers\dmio.sys
22:07:01.0234 3768 dmio - ok
22:07:01.0265 3768 dmload (e9317282a63ca4d188c0df5e09c6ac5f) F:\WINDOWS\system32\drivers\dmload.sys
22:07:01.0265 3768 dmload - ok
22:07:01.0328 3768 DMusic (a6f881284ac1150e37d9ae47ff601267) F:\WINDOWS\system32\drivers\DMusic.sys
22:07:01.0328 3768 DMusic - ok
22:07:01.0390 3768 dpti2o - ok
22:07:01.0406 3768 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) F:\WINDOWS\system32\drivers\drmkaud.sys
22:07:01.0406 3768 drmkaud - ok
22:07:01.0468 3768 dtscsi (12aca694b50ea53563c1e7c99e7bb27d) F:\WINDOWS\System32\Drivers\dtscsi.sys
22:07:01.0468 3768 Suspicious file (NoAccess): F:\WINDOWS\System32\Drivers\dtscsi.sys. md5: 12aca694b50ea53563c1e7c99e7bb27d
22:07:01.0468 3768 dtscsi ( LockedFile.Multi.Generic ) - warning
22:07:01.0468 3768 dtscsi - detected LockedFile.Multi.Generic (1)
22:07:01.0468 3768 EagleNT - ok
22:07:01.0515 3768 ENTECH (fd9fc82f134b1c91004ffc76a5ae494b) F:\WINDOWS\system32\DRIVERS\ENTECH.sys
22:07:01.0515 3768 ENTECH - ok
22:07:01.0578 3768 Fastfat (3117f595e9615e04f05a54fc15a03b20) F:\WINDOWS\system32\drivers\Fastfat.sys
22:07:01.0578 3768 Fastfat - ok
22:07:01.0625 3768 Fdc (ced2e8396a8838e59d8fd529c680e02c) F:\WINDOWS\system32\DRIVERS\fdc.sys
22:07:01.0625 3768 Fdc - ok
22:07:01.0640 3768 Fips (266dab58619b17bdf37fabbd48d875ca) F:\WINDOWS\system32\drivers\Fips.sys
22:07:01.0640 3768 Fips - ok
22:07:01.0687 3768 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) F:\WINDOWS\system32\DRIVERS\flpydisk.sys
22:07:01.0687 3768 Flpydisk - ok
22:07:01.0750 3768 FltMgr (3d234fb6d6ee875eb009864a299bea29) F:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:07:01.0750 3768 FltMgr - ok
22:07:01.0812 3768 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) F:\WINDOWS\system32\drivers\Fs_Rec.sys
22:07:01.0812 3768 Fs_Rec - ok
22:07:01.0859 3768 Ftdisk (4e664d8541db4a66b73a24257e322e1f) F:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:07:01.0859 3768 Ftdisk - ok
22:07:01.0890 3768 giveio (77ebf3e9386daa51551af429052d88d0) F:\WINDOWS\system32\giveio.sys
22:07:01.0937 3768 giveio - ok
22:07:01.0953 3768 GMSIPCI - ok
22:07:01.0968 3768 Gpc (c0f1d4a21de5a415df8170616703debf) F:\WINDOWS\system32\DRIVERS\msgpc.sys
22:07:01.0968 3768 Gpc - ok
22:07:02.0015 3768 hamachi (7929a161f9951d173ca9900fe7067391) F:\WINDOWS\system32\DRIVERS\hamachi.sys
22:07:02.0015 3768 hamachi - ok
22:07:02.0062 3768 HidUsb (1de6783b918f540149aa69943bdfeba8) F:\WINDOWS\system32\DRIVERS\hidusb.sys
22:07:02.0062 3768 HidUsb - ok
22:07:02.0078 3768 hpn - ok
22:07:02.0125 3768 HTTP (cb77bb47e67e84deb17ba29632501730) F:\WINDOWS\system32\Drivers\HTTP.sys
22:07:02.0125 3768 HTTP - ok
22:07:02.0156 3768 i2omgmt - ok
22:07:02.0187 3768 i2omp - ok
22:07:02.0234 3768 i8042prt (0f42de9909b5dbf2c48dd1a79d491af5) F:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:07:02.0234 3768 i8042prt - ok
22:07:02.0281 3768 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) F:\WINDOWS\system32\DRIVERS\imapi.sys
22:07:02.0281 3768 Imapi - ok
22:07:02.0343 3768 ini910u - ok
22:07:02.0375 3768 IntelIde - ok
22:07:02.0437 3768 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) F:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:07:02.0437 3768 Ip6Fw - ok
22:07:02.0484 3768 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) F:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:07:02.0484 3768 IpFilterDriver - ok
22:07:02.0531 3768 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) F:\WINDOWS\system32\DRIVERS\ipinip.sys
22:07:02.0531 3768 IpInIp - ok
22:07:02.0562 3768 IpNat (e2168cbc7098ffe963c6f23f472a3593) F:\WINDOWS\system32\DRIVERS\ipnat.sys
22:07:02.0578 3768 IpNat - ok
22:07:02.0625 3768 IPSec (64537aa5c003a6afeee1df819062d0d1) F:\WINDOWS\system32\DRIVERS\ipsec.sys
22:07:02.0625 3768 IPSec - ok
22:07:02.0671 3768 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) F:\WINDOWS\system32\DRIVERS\irenum.sys
22:07:02.0671 3768 IRENUM - ok
22:07:02.0703 3768 isapnp (1091528512e4dd7ed5fddcc4df1c53d7) F:\WINDOWS\system32\DRIVERS\isapnp.sys
22:07:02.0703 3768 isapnp - ok
22:07:02.0750 3768 k510bus (b1fe6feac5a501c89057a69c9f5e9d1f) F:\WINDOWS\system32\DRIVERS\k510bus.sys
22:07:02.0750 3768 k510bus - ok
22:07:02.0781 3768 k510mdfl (7a4ecca08560e8ff330acaa4128af7b0) F:\WINDOWS\system32\DRIVERS\k510mdfl.sys
22:07:02.0781 3768 k510mdfl - ok
22:07:02.0796 3768 k510mdm (094d532b727030c3b8b6bd3b743d9526) F:\WINDOWS\system32\DRIVERS\k510mdm.sys
22:07:02.0812 3768 k510mdm - ok
22:07:02.0843 3768 k510mgmt (ad67bfa00ba39c65551338ee001cdddd) F:\WINDOWS\system32\DRIVERS\k510mgmt.sys
22:07:02.0843 3768 k510mgmt - ok
22:07:02.0859 3768 k510obex (7d5094b00a47d871a48d035beb3a0922) F:\WINDOWS\system32\DRIVERS\k510obex.sys
22:07:02.0859 3768 k510obex - ok
22:07:02.0890 3768 Kbdclass (6f877bf8dc01a550cd666f3bedb2213c) F:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:07:02.0890 3768 Kbdclass - ok
22:07:02.0937 3768 kbdhid (065b5a83aa78c0c7047bf22e0ab5c821) F:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:07:02.0937 3768 kbdhid - ok
22:07:02.0984 3768 kmixer (ba5deda4d934e6288c2f66caf58d2562) F:\WINDOWS\system32\drivers\kmixer.sys
22:07:02.0984 3768 kmixer - ok
22:07:03.0015 3768 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) F:\WINDOWS\system32\drivers\KSecDD.sys
22:07:03.0015 3768 KSecDD - ok
22:07:03.0046 3768 lbrtfdc - ok
22:07:03.0125 3768 LVcKap (efe6cb9600a6bef09834be558d7cf04e) F:\WINDOWS\system32\DRIVERS\LVcKap.sys
22:07:03.0171 3768 LVcKap - ok
22:07:03.0265 3768 LVMVDrv (8895475987655aae944544e30004b290) F:\WINDOWS\system32\DRIVERS\LVMVDrv.sys
22:07:03.0312 3768 LVMVDrv - ok
22:07:03.0359 3768 LVPr2Mon (985875cf257e5900c3f779a6929920e2) F:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys
22:07:03.0359 3768 LVPr2Mon - ok
22:07:03.0406 3768 LVUSBSta (ccff53b1fcdfa9ede919e3bdbd10d0fd) F:\WINDOWS\system32\drivers\lvusbsta.sys
22:07:03.0406 3768 LVUSBSta - ok
22:07:03.0453 3768 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) F:\WINDOWS\system32\drivers\mnmdd.sys
22:07:03.0453 3768 mnmdd - ok
22:07:03.0531 3768 Modem (60210deb037846afe521ebf349964f6b) F:\WINDOWS\system32\drivers\Modem.sys
22:07:03.0531 3768 Modem - ok
22:07:03.0546 3768 Mouclass (b160ec94114715675509115986400fd9) F:\WINDOWS\system32\DRIVERS\mouclass.sys
22:07:03.0546 3768 Mouclass - ok
22:07:03.0593 3768 mouhid (bb269eba740737ab749b214d568b6812) F:\WINDOWS\system32\DRIVERS\mouhid.sys
22:07:03.0593 3768 mouhid - ok
22:07:03.0625 3768 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) F:\WINDOWS\system32\drivers\MountMgr.sys
22:07:03.0625 3768 MountMgr - ok
22:07:03.0640 3768 mraid35x - ok
22:07:03.0656 3768 MRxDAV (46edcc8f2db2f322c24f48785cb46366) F:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:07:03.0656 3768 MRxDAV - ok
22:07:03.0687 3768 MRxSmb (025af03ce51645c62f3b6907a7e2be5e) F:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:07:03.0687 3768 MRxSmb - ok
22:07:03.0734 3768 Msfs (561b3a4333ca2dbdba28b5b956822519) F:\WINDOWS\system32\drivers\Msfs.sys
22:07:03.0734 3768 Msfs - ok
22:07:03.0781 3768 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) F:\WINDOWS\system32\drivers\MSKSSRV.sys
22:07:03.0781 3768 MSKSSRV - ok
22:07:03.0812 3768 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) F:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:07:03.0812 3768 MSPCLOCK - ok
22:07:03.0843 3768 MSPQM (1988a33ff19242576c3d0ef9ce785da7) F:\WINDOWS\system32\drivers\MSPQM.sys
22:07:03.0843 3768 MSPQM - ok
22:07:03.0890 3768 mssmbios (469541f8bfd2b32659d5d463a6714bce) F:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:07:03.0906 3768 mssmbios - ok
22:07:03.0937 3768 MSTEE (bf13612142995096ab084f2db7f40f77) F:\WINDOWS\system32\drivers\MSTEE.sys
22:07:03.0937 3768 MSTEE - ok
22:07:03.0984 3768 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) F:\WINDOWS\system32\drivers\Mup.sys
22:07:03.0984 3768 Mup - ok
22:07:04.0015 3768 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) F:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:07:04.0015 3768 NABTSFEC - ok
22:07:04.0046 3768 NDIS (558635d3af1c7546d26067d5d9b6959e) F:\WINDOWS\system32\drivers\NDIS.sys
22:07:04.0046 3768 NDIS - ok
22:07:04.0078 3768 ndiscm (b797ee2ef919c95561dee78b72b33e5b) F:\WINDOWS\system32\DRIVERS\NetMotCM.sys
22:07:04.0078 3768 ndiscm - ok
22:07:04.0109 3768 NdisIP (520ce427a8b298f54112857bcf6bde15) F:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:07:04.0125 3768 NdisIP - ok
22:07:04.0156 3768 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) F:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:07:04.0156 3768 NdisTapi - ok
22:07:04.0187 3768 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) F:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:07:04.0187 3768 Ndisuio - ok
22:07:04.0234 3768 NdisWan (0b90e255a9490166ab368cd55a529893) F:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:07:04.0234 3768 NdisWan - ok
22:07:04.0250 3768 NDProxy (59fc3fb44d2669bc144fd87826bb571f) F:\WINDOWS\system32\drivers\NDProxy.sys
22:07:04.0250 3768 NDProxy - ok
22:07:04.0281 3768 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) F:\WINDOWS\system32\DRIVERS\netbios.sys
22:07:04.0281 3768 NetBIOS - ok
22:07:04.0328 3768 NetBT (0c80e410cd2f47134407ee7dd19cc86b) F:\WINDOWS\system32\DRIVERS\netbt.sys
22:07:04.0343 3768 NetBT - ok
22:07:04.0437 3768 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) F:\WINDOWS\system32\DRIVERS\nic1394.sys
22:07:04.0437 3768 NIC1394 - ok
22:07:04.0468 3768 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) F:\WINDOWS\system32\drivers\Npfs.sys
22:07:04.0468 3768 Npfs - ok
22:07:04.0500 3768 Ntfs (b78be402c3f63dd55521f73876951cdd) F:\WINDOWS\system32\drivers\Ntfs.sys
22:07:04.0515 3768 Ntfs - ok
22:07:04.0546 3768 Null (73c1e1f395918bc2c6dd67af7591a3ad) F:\WINDOWS\system32\drivers\Null.sys
22:07:04.0546 3768 Null - ok
22:07:04.0687 3768 nv (5645072033c2e51386e91bc137c0beb5) F:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:07:04.0781 3768 nv - ok
22:07:04.0812 3768 nvata (0344aa9113dc16eec379f4652020849d) F:\WINDOWS\system32\DRIVERS\nvata.sys
22:07:04.0812 3768 nvata - ok
22:07:04.0843 3768 NVENETFD (720cc533eecb65553bd86b139ca04433) F:\WINDOWS\system32\DRIVERS\NVENETFD.sys
22:07:04.0843 3768 NVENETFD - ok
22:07:04.0875 3768 nvnetbus (5f9f545cc5904dd8765f84ee1d056406) F:\WINDOWS\system32\DRIVERS\nvnetbus.sys
22:07:04.0875 3768 nvnetbus - ok
22:07:04.0921 3768 NVStrap (2cd7645c4cc2f643117f07d3ecdc66c0) F:\WINDOWS\system32\drivers\NVStrap.sys
22:07:04.0921 3768 NVStrap - ok
22:07:04.0968 3768 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) F:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:07:04.0984 3768 NwlnkFlt - ok
22:07:05.0031 3768 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) F:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:07:05.0031 3768 NwlnkFwd - ok
22:07:05.0078 3768 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) F:\WINDOWS\system32\DRIVERS\ohci1394.sys
22:07:05.0078 3768 ohci1394 - ok
22:07:05.0140 3768 Parport (76a18caa2fefb28a4ced38d76837e86e) F:\WINDOWS\system32\DRIVERS\parport.sys
22:07:05.0140 3768 Parport - ok
22:07:05.0187 3768 PartMgr (3334430c29dc338092f79c38ef7b4cd0) F:\WINDOWS\system32\drivers\PartMgr.sys
22:07:05.0187 3768 PartMgr - ok
22:07:05.0234 3768 ParVdm (1fae19d0457176318bba4a8795656ebc) F:\WINDOWS\system32\drivers\ParVdm.sys
22:07:05.0234 3768 ParVdm - ok
22:07:05.0265 3768 PCASp50 - ok
22:07:05.0312 3768 pccsmcfd (fd2041e9ba03db7764b2248f02475079) F:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
22:07:05.0312 3768 pccsmcfd - ok
22:07:05.0359 3768 PCI (b7979f37bb7b9df2230046134955e6e7) F:\WINDOWS\system32\DRIVERS\pci.sys
22:07:05.0359 3768 PCI - ok
22:07:05.0390 3768 PCIDump - ok
22:07:05.0406 3768 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) F:\WINDOWS\system32\DRIVERS\pciide.sys
22:07:05.0406 3768 PCIIde - ok
22:07:05.0453 3768 Pcmcia (90505755634407d4ef4c6dea60fc1df9) F:\WINDOWS\system32\drivers\Pcmcia.sys
22:07:05.0453 3768 Pcmcia - ok
22:07:05.0484 3768 PDCOMP - ok
22:07:05.0515 3768 PDFRAME - ok
22:07:05.0546 3768 PDRELI - ok
22:07:05.0578 3768 PDRFRAME - ok
22:07:05.0625 3768 pepifilter (1c23843f1f61a07e2aaaba80136cda19) F:\WINDOWS\system32\DRIVERS\lv302af.sys
22:07:05.0625 3768 pepifilter - ok
22:07:05.0656 3768 perc2 - ok
22:07:05.0671 3768 perc2hib - ok
22:07:05.0765 3768 PID_PEPI (87a74c342b9b291cb013093d5df7b916) F:\WINDOWS\system32\DRIVERS\LV302V32.SYS
22:07:05.0796 3768 PID_PEPI - ok
22:07:05.0859 3768 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) F:\WINDOWS\system32\DRIVERS\raspptp.sys
22:07:05.0859 3768 PptpMiniport - ok
22:07:05.0906 3768 Processor (9a10e4fd13824823da50d4758bd0a645) F:\WINDOWS\system32\DRIVERS\processr.sys
22:07:05.0906 3768 Processor - ok
22:07:05.0953 3768 PSched (48671f327553dcf1d27f6197f622a668) F:\WINDOWS\system32\DRIVERS\psched.sys
22:07:05.0953 3768 PSched - ok
22:07:05.0984 3768 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) F:\WINDOWS\system32\DRIVERS\ptilink.sys
22:07:05.0984 3768 Ptilink - ok
22:07:06.0000 3768 ql1080 - ok
22:07:06.0015 3768 Ql10wnt - ok
22:07:06.0062 3768 ql12160 - ok
22:07:06.0093 3768 ql1240 - ok
22:07:06.0109 3768 ql1280 - ok
22:07:06.0140 3768 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) F:\WINDOWS\system32\DRIVERS\rasacd.sys
22:07:06.0140 3768 RasAcd - ok
22:07:06.0203 3768 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) F:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:07:06.0203 3768 Rasl2tp - ok
22:07:06.0265 3768 RasPppoe (7306eeed8895454cbed4669be9f79faa) F:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:07:06.0265 3768 RasPppoe - ok
22:07:06.0281 3768 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) F:\WINDOWS\system32\DRIVERS\raspti.sys
22:07:06.0281 3768 Raspti - ok
22:07:06.0328 3768 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) F:\WINDOWS\system32\DRIVERS\rdbss.sys
22:07:06.0328 3768 Rdbss - ok
22:07:06.0343 3768 RDPCDD (4912d5b403614ce99c28420f75353332) F:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:07:06.0343 3768 RDPCDD - ok
22:07:06.0406 3768 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) F:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:07:06.0437 3768 rdpdr - ok
22:07:06.0546 3768 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) F:\WINDOWS\system32\drivers\RDPWD.sys
22:07:06.0578 3768 RDPWD - ok
22:07:06.0765 3768 redbook (aba13d33e1f888c9a68599a48a8840d6) F:\WINDOWS\system32\DRIVERS\redbook.sys
22:07:06.0765 3768 redbook - ok
22:07:06.0843 3768 RivaTuner32 (2c2e12d8355e2b8baee1876da0079195) F:\Program Files\RivaTuner v2.0 RC 16\RivaTuner32.sys
22:07:06.0843 3768 RivaTuner32 - ok
22:07:06.0921 3768 Secdrv (07f7f501ad50de2ba2d5842d9b6d6155) F:\WINDOWS\system32\DRIVERS\secdrv.sys
22:07:06.0921 3768 Secdrv - ok
22:07:06.0968 3768 serenum (a2d868aeeff612e70e213c451a70cafb) F:\WINDOWS\system32\DRIVERS\serenum.sys
22:07:06.0968 3768 serenum - ok
22:07:06.0984 3768 Serial (c1ddbc85251551a840212999da3d95f3) F:\WINDOWS\system32\DRIVERS\serial.sys
22:07:06.0984 3768 Serial - ok
22:07:07.0031 3768 sermouse (61490899036b14dedc24babd847d7001) F:\WINDOWS\system32\DRIVERS\sermouse.sys
22:07:07.0031 3768 sermouse - ok
22:07:07.0078 3768 sfdrv01 (4c0d673281178cb496011a2e28571fc8) F:\WINDOWS\system32\drivers\sfdrv01.sys
22:07:07.0078 3768 sfdrv01 - ok
22:07:07.0093 3768 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) F:\WINDOWS\system32\drivers\sfhlp02.sys
22:07:07.0093 3768 sfhlp02 - ok
22:07:07.0125 3768 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) F:\WINDOWS\system32\drivers\Sfloppy.sys
22:07:07.0125 3768 Sfloppy - ok
22:07:07.0140 3768 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) F:\WINDOWS\system32\drivers\sfvfs02.sys
22:07:07.0140 3768 sfvfs02 - ok
22:07:07.0187 3768 Simbad - ok
22:07:07.0250 3768 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) F:\WINDOWS\system32\DRIVERS\SLIP.sys
22:07:07.0250 3768 SLIP - ok
22:07:07.0281 3768 sonypvs1 (dfadfc2c86662f40759bf02add27d569) F:\WINDOWS\system32\DRIVERS\sonypvs1.sys
22:07:07.0296 3768 sonypvs1 - ok
22:07:07.0312 3768 Sparrow - ok
22:07:07.0343 3768 speedfan (5d6401db90ec81b71f8e2c5c8f0fef23) F:\WINDOWS\system32\speedfan.sys
22:07:07.0359 3768 speedfan - ok
22:07:07.0406 3768 splitter (0ce218578fff5f4f7e4201539c45c78f) F:\WINDOWS\system32\drivers\splitter.sys
22:07:07.0406 3768 splitter - ok
22:07:07.0468 3768 sptd (2e8d17d1b721e0fc2e8e956bb1057ce1) F:\WINDOWS\system32\Drivers\sptd.sys
22:07:07.0468 3768 Suspicious file (NoAccess): F:\WINDOWS\system32\Drivers\sptd.sys. md5: 2e8d17d1b721e0fc2e8e956bb1057ce1
22:07:07.0468 3768 sptd ( LockedFile.Multi.Generic ) - warning
22:07:07.0468 3768 sptd - detected LockedFile.Multi.Generic (1)
22:07:07.0515 3768 sr (a74035ea526db97d9d50d2143a55f5cf) F:\WINDOWS\system32\DRIVERS\sr.sys
22:07:07.0515 3768 sr - ok
22:07:07.0593 3768 Srv (e03b4ea274c9e509cca7f9f0cec24232) F:\WINDOWS\system32\DRIVERS\srv.sys
22:07:07.0593 3768 Srv - ok
22:07:07.0640 3768 streamip (284c57df5dc7abca656bc2b96a667afb) F:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:07:07.0640 3768 streamip - ok
22:07:07.0703 3768 swenum (03c1bae4766e2450219d20b993d6e046) F:\WINDOWS\system32\DRIVERS\swenum.sys
22:07:07.0703 3768 swenum - ok
22:07:07.0765 3768 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) F:\WINDOWS\system32\drivers\swmidi.sys
22:07:07.0765 3768 swmidi - ok
22:07:07.0781 3768 symc810 - ok
22:07:07.0796 3768 symc8xx - ok
22:07:07.0812 3768 sym_hi - ok
22:07:07.0828 3768 sym_u3 - ok
22:07:07.0875 3768 sysaudio (650ad082d46bac0e64c9c0e0928492fd) F:\WINDOWS\system32\drivers\sysaudio.sys
22:07:07.0875 3768 sysaudio - ok
22:07:07.0937 3768 Tcpip (1dbf125862891817f374f407626967f4) F:\WINDOWS\system32\DRIVERS\tcpip.sys
22:07:07.0953 3768 Tcpip - ok
22:07:07.0984 3768 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) F:\WINDOWS\system32\drivers\TDPIPE.sys
22:07:07.0984 3768 TDPIPE - ok
22:07:08.0031 3768 TDTCP (ed0580af02502d00ad8c4c066b156be9) F:\WINDOWS\system32\drivers\TDTCP.sys
22:07:08.0031 3768 TDTCP - ok
22:07:08.0062 3768 TermDD (a540a99c281d933f3d69d55e48727f47) F:\WINDOWS\system32\DRIVERS\termdd.sys
22:07:08.0062 3768 TermDD - ok
22:07:08.0093 3768 TosIde - ok
22:07:08.0140 3768 TrueSight (f69641efdb19acb4753b0155f7fdeed5) f:\windows\system32\drivers\TrueSight.sys
22:07:08.0156 3768 TrueSight - ok
22:07:08.0203 3768 Udfs (12f70256f140cd7d52c58c7048fde657) F:\WINDOWS\system32\drivers\Udfs.sys
22:07:08.0203 3768 Udfs - ok
22:07:08.0234 3768 ultra - ok
22:07:08.0265 3768 Update (aff2e5045961bbc0a602bb6f95eb1345) F:\WINDOWS\system32\DRIVERS\update.sys
22:07:08.0265 3768 Update - ok
22:07:08.0328 3768 usbaudio (45a0d14b26c35497ad93bce7e15c9941) F:\WINDOWS\system32\drivers\usbaudio.sys
22:07:08.0328 3768 usbaudio - ok
22:07:08.0375 3768 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) F:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:07:08.0375 3768 usbccgp - ok
22:07:08.0437 3768 usbehci (15e993ba2f6946b2bfbbfcd30398621e) F:\WINDOWS\system32\DRIVERS\usbehci.sys
22:07:08.0437 3768 usbehci - ok
22:07:08.0468 3768 usbhub (c72f40947f92cea56a8fb532edf025f1) F:\WINDOWS\system32\DRIVERS\usbhub.sys
22:07:08.0468 3768 usbhub - ok
22:07:08.0500 3768 usbohci (bdfe799a8531bad8a5a985821fe78760) F:\WINDOWS\system32\DRIVERS\usbohci.sys
22:07:08.0500 3768 usbohci - ok
22:07:08.0531 3768 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) F:\WINDOWS\system32\DRIVERS\usbprint.sys
22:07:08.0531 3768 usbprint - ok
22:07:08.0562 3768 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) F:\WINDOWS\system32\DRIVERS\usbscan.sys
22:07:08.0562 3768 usbscan - ok
22:07:08.0593 3768 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) F:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:07:08.0593 3768 usbstor - ok
22:07:08.0640 3768 vax347b (61aa77e5d9950ca59c0db7f24cfa21b3) F:\WINDOWS\system32\DRIVERS\vax347b.sys
22:07:08.0656 3768 vax347b - ok
22:07:08.0687 3768 vax347s (113e4b318bbaa7483ca4e582a4d63f49) F:\WINDOWS\system32\Drivers\vax347s.sys
22:07:08.0687 3768 vax347s - ok
22:07:08.0750 3768 vaxscsi (92cebc2bc7be2c8d49391b365569f306) F:\WINDOWS\System32\Drivers\vaxscsi.sys
22:07:08.0750 3768 Suspicious file (NoAccess): F:\WINDOWS\System32\Drivers\vaxscsi.sys. md5: 92cebc2bc7be2c8d49391b365569f306
22:07:08.0750 3768 vaxscsi ( LockedFile.Multi.Generic ) - warning
22:07:08.0750 3768 vaxscsi - detected LockedFile.Multi.Generic (1)
22:07:08.0796 3768 VgaSave (8a60edd72b4ea5aea8202daf0e427925) F:\WINDOWS\System32\drivers\vga.sys
22:07:08.0796 3768 VgaSave - ok
22:07:08.0812 3768 ViaIde - ok
22:07:08.0843 3768 VolSnap (cd8cce067f7e9cbd762c00bdddecaa34) F:\WINDOWS\system32\drivers\VolSnap.sys
22:07:08.0843 3768 VolSnap - ok
22:07:08.0890 3768 w810bus (5e8b60606fc4173b69cdecd964f22d28) F:\WINDOWS\system32\DRIVERS\w810bus.sys
22:07:08.0890 3768 w810bus - ok
22:07:08.0921 3768 w810mdfl (c0cc4f5a3c58b4c07ec4a82a5ae24714) F:\WINDOWS\system32\DRIVERS\w810mdfl.sys
22:07:08.0921 3768 w810mdfl - ok
22:07:08.0953 3768 w810mdm (2aafeedc3bfe14419cbce7ceea59dd05) F:\WINDOWS\system32\DRIVERS\w810mdm.sys
22:07:08.0953 3768 w810mdm - ok
22:07:08.0968 3768 w810mgmt (b0037db3f890d0ffcf7e35f356a435ec) F:\WINDOWS\system32\DRIVERS\w810mgmt.sys
22:07:08.0984 3768 w810mgmt - ok
22:07:09.0000 3768 w810obex (bf609636068f17246f94b490c5812483) F:\WINDOWS\system32\DRIVERS\w810obex.sys
22:07:09.0000 3768 w810obex - ok
22:07:09.0031 3768 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) F:\WINDOWS\system32\DRIVERS\wanarp.sys
22:07:09.0031 3768 Wanarp - ok
22:07:09.0046 3768 WDICA - ok
22:07:09.0093 3768 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) F:\WINDOWS\system32\drivers\wdmaud.sys
22:07:09.0093 3768 wdmaud - ok
22:07:09.0171 3768 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) F:\WINDOWS\System32\drivers\ws2ifsl.sys
22:07:09.0171 3768 WS2IFSL - ok
22:07:09.0203 3768 WSTCODEC (d5842484f05e12121c511aa93f6439ec) F:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:07:09.0218 3768 WSTCODEC - ok
22:07:09.0234 3768 MBR (0x1B8) (413fc2a0c716421b3158746d63736515) \Device\Harddisk0\DR0
22:07:09.0312 3768 \Device\Harddisk0\DR0 - ok
22:07:09.0312 3768 Boot (0x1200) (db9b8e6a22a4f76e584d600b40dcb492) \Device\Harddisk0\DR0\Partition0
22:07:09.0312 3768 \Device\Harddisk0\DR0\Partition0 - ok
22:07:09.0328 3768 Boot (0x1200) (cce3cc662f71d46739cd15e0cca49b27) \Device\Harddisk0\DR0\Partition1
22:07:09.0343 3768 \Device\Harddisk0\DR0\Partition1 - ok
22:07:09.0343 3768 Boot (0x1200) (ea0b6741385da5a2769b8624b3fbbebd) \Device\Harddisk0\DR0\Partition2
22:07:09.0343 3768 \Device\Harddisk0\DR0\Partition2 - ok
22:07:09.0359 3768 ============================================================
22:07:09.0359 3768 Scan finished
22:07:09.0359 3768 ============================================================
22:07:09.0359 3760 Detected object count: 3
22:07:09.0359 3760 Actual detected object count: 3
22:07:45.0640 3760 dtscsi ( LockedFile.Multi.Generic ) - skipped by user
22:07:45.0640 3760 dtscsi ( LockedFile.Multi.Generic ) - User select action: Skip
22:07:45.0640 3760 sptd ( LockedFile.Multi.Generic ) - skipped by user
22:07:45.0640 3760 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
22:07:45.0640 3760 vaxscsi ( LockedFile.Multi.Generic ) - skipped by user
22:07:45.0640 3760 vaxscsi ( LockedFile.Multi.Generic ) - User select action: Skip

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: UFA.exe - facebook vir

#33 Příspěvek od vyosek »

:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Nainstalujte Avast Free http://www.avast.com/cs-cz/free-antivirus-download

:arrow: Doporucuji provest defragmentaci disku
  • Nejjednodussi (ale nejmene ucinny) zpusob je pomoci utility ve windowsech
    • Kliknete na Tento pocitac, dale na disk kliknete pravym tlacitkem, vyberte Vlastnosti
    • prepnete se do zalozky Nastroje
    • Nyni vidite pomucky Defragmentace - spustte ji kliknutim na Defragmentovat
    • Toto provedte se vsemi disky
  • Dalsi moznosti (a mnou doporucenou) je pres programek Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
    • Program stahnete, nainstalujte (dejte fajfku pryc u yahoo toolbaru) a spustte
    • Kliknete na Analyzovat
    • Pokud je ve sloupci Fragmentováno vice jak 5%, doporucuji provest defragmentaci (klik na Defragmentovat)
    • Postup provedte se vsemi disky
  • Posledni moznost je pres jednoduchy programek JKDefrag http://www.stahuj.centrum.cz/utility_a_ ... /jkdefrag/
    • Vyhodou programku je, ze se neinstaluje
    • Staci tedy jen stahnout dle verze vaseho OS a rozbalit
    • Nasledne spustit pomoci souboru JKDefrag pripadne JKDefrag64
    • Probehne analyza disku a nasledne i defragmentace
:arrow: Dejte novy log z RSIT a napiste co PC
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

aragor
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 17 lis 2011 16:42

Re: UFA.exe - facebook vir

#34 Příspěvek od aragor »

místo avastu jsem tam nainstaloval MS SE

Logfile of random's system information tool 1.09 (written by random/random)
Run by Hráč at 2011-11-18 23:17:49
Systém Microsoft Windows XP Professional Service Pack 2
System drive F: has 16 GB (41%) free of 39 GB
Total RAM: 1023 MB (42% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:18:03, on 18.11.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
f:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
F:\Program Files\Java\jre6\bin\jqs.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\oodag.exe
F:\WINDOWS\system32\PnkBstrA.exe
F:\WINDOWS\system32\PnkBstrB.exe
F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\UAService7.exe
F:\WINDOWS\system32\wbem\wmiapsrv.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\SOUNDMAN.EXE
F:\Program Files\A4Tech\Mouse\Amoumain.exe
F:\WINDOWS\mHotkey.exe
F:\WINDOWS\StopHid.exe
F:\WINDOWS\system32\RUNDLL32.EXE
F:\WINDOWS\system32\LVComS.exe
F:\Program Files\parentalcontrol\parentalcontrol.exe
F:\Program Files\Common Files\Java\Java Update\jusched.exe
F:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
F:\Program Files\Logitech\QuickCam10\QuickCam10.exe
F:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
F:\WINDOWS\system32\ctfmon.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
F:\WINDOWS\system32\msiexec.exe
F:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
F:\Program Files\Microsoft Security Client\msseces.exe
F:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Hráč\Dokumenty\Stažené soubory\RSIT.exe
F:\Program Files\trend micro\Hráč.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=66019
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66019
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=66019
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
O2 - BHO: (no name) - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - (no file)
O2 - BHO: FastestTube BHO - {3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A} - F:\Program Files\FastestTube\1.2.12\WombatBHO.dll
O2 - BHO: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - F:\PROGRA~1\PARENT~1\PARENT~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - F:\PROGRA~1\PARENT~1\PARENT~1.DLL
O3 - Toolbar: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WheelMouse] F:\Program Files\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [StopHid] StopHid.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "F:\Program Files\RivaTuner v2.0 RC 16\RivaTuner.exe" /S
O4 - HKLM\..\Run: [LVComs] F:\WINDOWS\system32\LVComS.exe
O4 - HKLM\..\Run: [parentalcontrol] "F:\Program Files\parentalcontrol\parentalcontrol.exe" "F:\Program Files\parentalcontrol\parentalcontrol.dll" "parentalcontrol"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "F:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "F:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "F:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [MSC] "F:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://F:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - F:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.4 - {73C6DCFB-B606-47F3-BDFA-9A4FBF931E37} - F:\Program Files\ICQ7.4\ICQ.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - F:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - F:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bw+0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {2ED671D4-C6FD-48D1-9FF0-BDBA3A77DA29} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINDOWS\system32\browseui.dll
O23 - Service: Google Software Updater (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - F:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - f:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - F:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - F:\Program Files\Eset\nod32krn.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - F:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - F:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - F:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia - F:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - F:\WINDOWS\system32\UAService7.exe
O24 - Desktop Component 0: (no name) - file:///F:/DOCUME~1/HR6460~1/LOCALS~1/Temp/msohtml1/01/clip_image001.gif

--
End of file - 22726 bytes

======Scheduled tasks folder======

F:\WINDOWS\tasks\MP Scheduled Scan.job
F:\WINDOWS\tasks\MpIdleTask.job

=========Mozilla firefox=========

ProfilePath - F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default

prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:6.0.03, {4B3803EA-5230-4DC3-A7FC-33638F3D3542}:1.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.24"

"bkmrksync@nokia.com"=F:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\
"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=F:\Program Files\Crawler\firefox\
"jqs@sun.com"=F:\Program Files\Java\jre6\lib\deploy\jqs\ff


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=F:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=F:\WINDOWS\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=F:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=F:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=F:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=F:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18]
"Description"=Veetle TV Core
"Path"=F:\Program Files\Veetle\plugins\npVeetle.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18]
"Description"=Veetle TV Player
"Path"=F:\Program Files\Veetle\Player\npvlc.dll

F:\Program Files\Mozilla Firefox\extensions\
{800b5000-a755-47e1-992b-48a1c1357f07}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}

F:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsILegitCheckPlugin.xpt

F:\Program Files\Mozilla Firefox\plugins\
np32dsw.dll
npdeployJava1.dll
npLegitCheckPlugin.dll
NPOFFICE.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
QuickTimePlugin.class
ShockwavePlugin.class

F:\Program Files\Mozilla Firefox\searchplugins\
crawlersrch.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\
conduit.xml
icqplugin-1.xml
icqplugin-10.xml
icqplugin-11.xml
icqplugin-12.xml
icqplugin-13.xml
icqplugin-14.xml
icqplugin-15.xml
icqplugin-16.xml
icqplugin-17.xml
icqplugin-18.xml
icqplugin-19.xml
icqplugin-2.xml
icqplugin-20.xml
icqplugin-21.xml
icqplugin-22.xml
icqplugin-23.xml
icqplugin-24.xml
icqplugin-25.xml
icqplugin-26.xml
icqplugin-27.xml
icqplugin-28.xml
icqplugin-29.xml
icqplugin-3.xml
icqplugin-30.xml
icqplugin-31.xml
icqplugin-32.xml
icqplugin-33.xml
icqplugin-4.xml
icqplugin-5.xml
icqplugin-6.xml
icqplugin-7.xml
icqplugin-8.xml
icqplugin-9.xml
icqplugin.xml
sweetim.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2005-09-24 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E532CE8-C6D9-4A10-8ACE-4348C96E8B6A}]
FastestTubeBHO Class - F:\Program Files\FastestTube\1.2.12\WombatBHO.dll [2011-03-25 183296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931}]
Parental Control Toolbar - F:\PROGRA~1\PARENT~1\PARENT~1.DLL [2007-11-04 3072512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
F:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 853672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-17 305328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - F:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll [2011-06-08 1007160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - F:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-11-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - F:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-11-18 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431}
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - F:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
{4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - Parental Control Toolbar - F:\PROGRA~1\PARENT~1\PARENT~1.DLL [2007-11-04 3072512]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - F:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2011-08-17 305328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=F:\WINDOWS\SOUNDMAN.EXE [2005-10-24 90112]
"NvCplDaemon"=F:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"WheelMouse"=F:\Program Files\A4Tech\Mouse\Amoumain.exe [2006-02-17 163840]
"CHotkey"=F:\WINDOWS\mHotkey.exe [2004-12-27 550912]
"StopHid"=F:\WINDOWS\StopHid.exe [2003-10-06 40960]
"NvMediaCenter"=F:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"RivaTunerStartupDaemon"=F:\Program Files\RivaTuner v2.0 RC 16\RivaTuner.exe [2006-05-21 2375680]
"LVComs"=F:\WINDOWS\system32\LVComS.exe [1999-10-28 77824]
"parentalcontrol"=F:\Program Files\parentalcontrol\parentalcontrol.exe [2006-06-13 30720]
"SunJavaUpdateSched"=F:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"LogitechCommunicationsManager"=F:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe [2006-10-31 284184]
"LogitechQuickCamRibbon"=F:\Program Files\Logitech\QuickCam10\QuickCam10.exe [2006-11-15 746520]
"LVCOMSX"=F:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe [2006-11-15 244512]
"MSC"=F:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-09-09 68856]
"ctfmon.exe"=F:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - F:\WINDOWS\system32\upnpui.dll [2004-08-17 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"G:\Program files\S4\Exe\S4_Main.exe"="G:\Program files\S4\Exe\S4_Main.exe:*:Enabled:S4_Main"
"G:\Program files\Firefly Studios\Stronghold 2\Stronghold2.exe"="G:\Program files\Firefly Studios\Stronghold 2\Stronghold2.exe:*:Enabled:Stronghold 2"
"G:\Program files\AoE3\age3.exe"="G:\Program files\AoE3\age3.exe:*:Enabled:Age of Empires 3"
"G:\Program files\Stronghold Crusader\Stronghold Crusader.exe"="G:\Program files\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader"
"G:\Program files\TrackMania Nations ESWC Special Edition\TmNationsESWC.exe"="G:\Program files\TrackMania Nations ESWC Special Edition\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"F:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe"="F:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe:*:Enabled:Zoo Tycoon 2 Executable"
"F:\Program Files\ICQ7.4\ICQ.exe"="F:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"F:\Program Files\ICQ7.4\ICQ.exe"="F:\Program Files\ICQ7.4\ICQ.exe:*:Enabled:ICQ7.4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"VIDC.I420"=lvcodec2.dll
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"VIDC.YVYU"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=F:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=l3codecp.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.VDOM"=vdowave.drv
"VIDC.MPG4"=msscmc32.dll
"MSACM.LHACM"=lhacm.acm
"VIDC.TR20"=tr2032.dll
"msacm.voxacm119"=vdk32119.acm
"vidc.vivo"=ivvideo.dll
"VIDC.JPGL"=jpgl.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.JPEG"=JPEGCODE.DLL
"VIDC.MPEG"=JPEGCODE.DLL
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.VP60"=F:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=F:\WINDOWS\system32\vp6vfw.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv

======List of files/folders created in the last 1 month======

2011-11-18 23:17:50 ----D---- F:\Program Files\trend micro
2011-11-18 23:17:49 ----D---- F:\rsit
2011-11-18 23:16:31 ----N---- F:\WINDOWS\system32\MpSigStub.exe
2011-11-18 23:10:22 ----D---- F:\WINDOWS\LastGood
2011-11-18 23:09:42 ----D---- F:\Program Files\Microsoft Security Client
2011-11-18 23:04:33 ----A---- F:\WINDOWS\system32\wpa.bak
2011-11-18 23:04:31 ----A---- F:\WINDOWS\setuplog.txt
2011-11-18 22:53:03 ----HDC---- F:\WINDOWS\$NtUninstallKB914882$
2011-11-18 22:32:59 ----D---- F:\Documents and Settings\All Users\Data aplikací\Sun
2011-11-18 22:32:51 ----A---- F:\WINDOWS\system32\javaws.exe
2011-11-18 22:32:51 ----A---- F:\WINDOWS\system32\javaw.exe
2011-11-18 22:32:51 ----A---- F:\WINDOWS\system32\java.exe
2011-11-18 22:32:51 ----A---- F:\WINDOWS\system32\deployJava1.dll
2011-11-18 22:29:28 ----D---- F:\WINDOWS\system32\appmgmt
2011-11-18 18:59:09 ----SHD---- F:\RECYCLER
2011-11-18 18:56:04 ----D---- F:\Program Files\CCleaner
2011-11-18 17:47:45 ----D---- F:\WINDOWS\temp
2011-11-17 18:41:08 ----A---- F:\Boot.bak
2011-11-17 18:41:05 ----RASHD---- F:\cmdcons
2011-11-17 18:26:33 ----R---- F:\Uninstall.exe
2011-11-17 16:27:45 ----A---- F:\WINDOWS\system32\drivers\TrueSight.sys

======List of files/folders modified in the last 1 month======

2011-11-18 23:17:50 ----RD---- F:\Program Files
2011-11-18 23:16:39 ----SD---- F:\WINDOWS\Tasks
2011-11-18 23:16:31 ----D---- F:\WINDOWS\system32
2011-11-18 23:10:35 ----SHD---- F:\WINDOWS\Installer
2011-11-18 23:10:35 ----D---- F:\Config.Msi
2011-11-18 23:10:22 ----HD---- F:\WINDOWS\inf
2011-11-18 23:10:22 ----D---- F:\WINDOWS\system32\drivers
2011-11-18 23:10:22 ----D---- F:\WINDOWS
2011-11-18 23:10:21 ----D---- F:\WINDOWS\system32\CatRoot2
2011-11-18 23:10:20 ----SD---- F:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-11-18 23:05:19 ----A---- F:\WINDOWS\SchedLgU.Txt
2011-11-18 22:59:17 ----SD---- F:\WINDOWS\Downloaded Program Files
2011-11-18 22:53:01 ----HD---- F:\WINDOWS\$hf_mig$
2011-11-18 22:34:07 ----D---- F:\Program Files\Mozilla Firefox
2011-11-18 22:33:58 ----D---- F:\WINDOWS\Prefetch
2011-11-18 22:32:58 ----D---- F:\Program Files\Common Files\Java
2011-11-18 22:32:35 ----D---- F:\Program Files\Java
2011-11-18 22:29:27 ----DC---- F:\WINDOWS\system32\DRVSTORE
2011-11-18 22:01:44 ----D---- F:\WINDOWS\system32\Restore
2011-11-18 21:42:25 ----SHD---- F:\System Volume Information
2011-11-18 19:55:19 ----HD---- F:\WINDOWS\update.tray-3-0-lnk
2011-11-18 19:43:12 ----A---- F:\WINDOWS\bitcoind.exe
2011-11-18 18:59:09 ----D---- F:\WINDOWS\SoftwareDistribution
2011-11-18 18:59:09 ----D---- F:\WINDOWS\Minidump
2011-11-18 18:59:09 ----D---- F:\WINDOWS\Logs
2011-11-18 18:59:09 ----D---- F:\WINDOWS\Debug
2011-11-18 17:45:17 ----A---- F:\WINDOWS\system.ini
2011-11-18 17:44:48 ----D---- F:\WINDOWS\system32\drivers\etc
2011-11-18 17:43:15 ----D---- F:\WINDOWS\system32\config
2011-11-18 17:41:36 ----D---- F:\WINDOWS\AppPatch
2011-11-18 17:41:36 ----D---- F:\Program Files\Common Files
2011-11-18 13:03:58 ----D---- F:\Program Files\Crawler
2011-11-18 12:56:31 ----D---- F:\Program Files\Soft32
2011-11-18 12:56:31 ----D---- F:\Program Files\ConduitEngine
2011-11-18 12:56:31 ----D---- F:\Program Files\BS_Player
2011-11-17 18:56:21 ----D---- F:\Program Files\PC Connectivity Solution
2011-11-17 18:55:29 ----D---- F:\Documents and Settings
2011-11-17 18:54:35 ----DC---- F:\WINDOWS\$NtUninstallKB65020$
2011-11-17 18:41:08 ----RASH---- F:\boot.ini
2011-11-14 22:06:23 ----A---- F:\WINDOWS\btc_iplist.txt
2011-11-14 19:05:15 ----A---- F:\WINDOWS\NeroDigital.ini
2011-11-14 17:43:01 ----D---- F:\WINDOWS\system32\oodag
2011-11-10 14:17:12 ----HD---- F:\Program Files\InstallShield Installation Information
2011-10-30 11:38:29 ----A---- F:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; F:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 nvata;nvata; F:\WINDOWS\system32\DRIVERS\nvata.sys [2005-08-18 93568]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI VIA; F:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); F:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); F:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); F:\WINDOWS\System32\drivers\sfvfs02.sys [2005-11-03 63488]
R0 speedfan;speedfan; F:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; F:\WINDOWS\System32\Drivers\sptd.sys [2006-09-28 643072]
R0 vax347b;vax347b; F:\WINDOWS\system32\DRIVERS\vax347b.sys [2005-07-08 159616]
R0 vax347s;vax347s; F:\WINDOWS\System32\Drivers\vax347s.sys [2004-04-30 5248]
R1 AmdK8;AMD Processor Driver; F:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 Amfilter;A4Tech Mouse Filter Driver; F:\WINDOWS\system32\DRIVERS\Amfilter.sys [2006-01-11 8704]
R1 cdrbsdrv;cdrbsdrv; F:\WINDOWS\system32\drivers\cdrbsdrv.sys [2004-03-08 13567]
R1 kbdhid;Ovladač klávesnice standardu HID; F:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 MpFilter;Microsoft Malware Protection Driver; F:\WINDOWS\system32\DRIVERS\MpFilter.sys [2011-04-18 165648]
R1 MpKsl134445c3;MpKsl134445c3; \??\F:\Documents and Settings\All Users\Data aplikací\Microsoft\Microsoft Antimalware\Definition Updates\{5CE5A93D-F85A-4CF7-8526-F59729F64AD8}\MpKsl134445c3.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; F:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 acedrv11;acedrv11; \??\F:\WINDOWS\system32\drivers\acedrv11.sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); F:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-10-26 3786944]
R3 Amusbprt;A4Tech HID-compliant Mouse Driver; F:\WINDOWS\system32\DRIVERS\Amusbprt.sys [2006-05-09 13312]
R3 Arp1394;Protokol 1394 ARP Client; F:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 dtscsi;dtscsi; F:\WINDOWS\System32\Drivers\dtscsi.sys [2006-09-28 223128]
R3 HidUsb;Ovladač třídy standardu HID; F:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 LVPr2Mon;Logitech LVPr2Mon Driver; F:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys [2006-11-15 24736]
R3 mouhid;Ovladač myši standardu HID; F:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; F:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 nv;nv; F:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; F:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-05 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; F:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-05 12928]
R3 RivaTuner32;RivaTuner32; \??\F:\Program Files\RivaTuner v2.0 RC 16\RivaTuner32.sys []
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; F:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 vaxscsi;vaxscsi; F:\WINDOWS\System32\Drivers\vaxscsi.sys [2006-09-28 223128]
S0 NVStrap;NVStrap; F:\WINDOWS\system32\drivers\NVStrap.sys [2006-05-21 3712]
S1 cdrbsvsd;cdrbsvsd; F:\WINDOWS\system32\drivers\cdrbsvsd.sys []
S2 AMON;AMON; F:\WINDOWS\system32\drivers\amon.sys [2007-09-06 512096]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver; F:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2006-05-09 13824]
S3 CCDECODE;Dekodér Closed Caption; F:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 CTIpHook;CTIpHook; F:\WINDOWS\system32\Drivers\CTIpHook.sys []
S3 DCamUSBCompany;Logitech QuickCam Pro USB; F:\WINDOWS\system32\DRIVERS\p35u.sys [1999-10-28 90464]
S3 EagleNT;EagleNT; \??\F:\WINDOWS\system32\drivers\EagleNT.sys []
S3 ENTECH;ENTECH; \??\F:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; F:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-07-31 25280]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM); F:\WINDOWS\system32\DRIVERS\k510bus.sys [2007-01-02 58288]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter; F:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2007-01-02 8336]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver; F:\WINDOWS\system32\DRIVERS\k510mdm.sys [2007-01-02 94064]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM); F:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2007-01-02 85408]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface; F:\WINDOWS\system32\DRIVERS\k510obex.sys [2007-01-02 83344]
S3 LVcKap;Logitech AEC Driver; F:\WINDOWS\system32\DRIVERS\LVcKap.sys [2006-11-15 1678368]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; F:\WINDOWS\system32\DRIVERS\LVMVDrv.sys [2006-11-15 1962912]
S3 LVUSBSta;Logitech USB Monitor Filter; F:\WINDOWS\system32\drivers\lvusbsta.sys [2006-11-11 40352]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; F:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; F:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 ndiscm;Motorola SURFboard USB Cable Modem Windows Driver; F:\WINDOWS\system32\DRIVERS\NetMotCM.sys [2004-09-29 15360]
S3 NdisIP;Microsoft TV/Video Connection; F:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 PCASp50;PCASp50 NDIS Protocol Driver; F:\WINDOWS\System32\Drivers\PCASp50.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; F:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 pepifilter;Volume Adapter; F:\WINDOWS\system32\DRIVERS\lv302af.sys [2006-11-11 13344]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); F:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2006-11-11 933536]
S3 sermouse;Ovladač sériové myši; F:\WINDOWS\system32\DRIVERS\sermouse.sys [2001-10-24 17664]
S3 SLIP;BDA Slip De-Framer; F:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 sonypvs1;Sony Digital Imaging Video2; F:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 102220]
S3 streamip;BDA IPSink; F:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 TrueSight;TrueSight; \??\f:\windows\system32\drivers\TrueSight.sys []
S3 usbaudio;Ovladač zvukové karty USB (WDM); F:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbprint;Třída USB Printer; F:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; F:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; F:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 w810bus;Sony Ericsson W810 Driver driver (WDM); F:\WINDOWS\system32\DRIVERS\w810bus.sys [2006-02-20 58288]
S3 w810mdfl;Sony Ericsson W810 USB WMC Modem Filter; F:\WINDOWS\system32\DRIVERS\w810mdfl.sys [2006-02-20 8336]
S3 w810mdm;Sony Ericsson W810 USB WMC Modem Driver; F:\WINDOWS\system32\DRIVERS\w810mdm.sys [2006-02-20 94064]
S3 w810mgmt;Sony Ericsson W810 USB WMC Device Management Drivers (WDM); F:\WINDOWS\system32\DRIVERS\w810mgmt.sys [2006-02-20 85408]
S3 w810obex;Sony Ericsson W810 USB WMC OBEX Interface; F:\WINDOWS\system32\DRIVERS\w810obex.sys [2006-02-20 83344]
S3 WSTCODEC;Dálnopisný kodek světového standardu; F:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; F:\Program Files\Java\jre6\bin\jqs.exe [2011-11-18 153376]
R2 LVPrcSrv;Process Monitor; f:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe [2006-11-15 109344]
R2 MsMpSvc;Microsoft Antimalware Service; F:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2011-04-27 11736]
R2 NVSvc;NVIDIA Display Driver Service; F:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 O&O Defrag;O&O Defrag; F:\WINDOWS\system32\oodag.exe [2006-06-02 339456]
R2 PnkBstrA;PnkBstrA; F:\WINDOWS\system32\PnkBstrA.exe [2008-05-13 66872]
R2 PnkBstrB;PnkBstrB; F:\WINDOWS\system32\PnkBstrB.exe [2010-03-07 107832]
R2 StarWindService;StarWind iSCSI Service; F:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 UserAccess7;SecuROM User Access Service (V7); F:\WINDOWS\system32\UAService7.exe [2007-06-30 221184]
S2 LVSrvLauncher;LVSrvLauncher; F:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe [2006-11-15 101152]
S2 NOD32krn;NOD32 Kernel Service; F:\Program Files\Eset\nod32krn.exe []
S3 aspnet_state;ASP.NET State Service; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; F:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; F:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 gusvc;Google Software Updater; F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-16 182768]
S3 IDriverT;InstallDriver Table Manager; F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; F:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 ose;Office Source Engine; F:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; F:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-10-27 657408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; F:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: UFA.exe - facebook vir

#35 Příspěvek od vyosek »

:arrow: Jeste nam tam neco zustalo ale to bude rychlovka

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{BFC32E1D-EE75-4A48-BC60-104E11EE2431}"=-
    "{4B3803EA-5230-4DC3-A7FC-33638F3D3542}"=-
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}"=-
    [HKCU\Software\Microsoft\Internet Explorer\Main]
    "Start Page"=""
    [HKLM\Software\Microsoft\Internet Explorer\Search]
    "SearchAssistant"=""
    [HKLM\Software\Microsoft\Internet Explorer\Search]
    "CustomizeSearch"=""
    
    :services
    NOD32krn
    gusvc
    
    :files
    F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\conduit.xml
    F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin*.xml
    F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\sweetim.xml
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

aragor
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 17 lis 2011 16:42

Re: UFA.exe - facebook vir

#36 Příspěvek od aragor »

All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{BFC32E1D-EE75-4A48-BC60-104E11EE2431} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BFC32E1D-EE75-4A48-BC60-104E11EE2431}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\swg deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}\ not found.
HKCU\Software\Microsoft\Internet Explorer\Main\\"Start Page"|"" /E : value set successfully!
HKLM\Software\Microsoft\Internet Explorer\Search\\"SearchAssistant"|"" /E : value set successfully!
HKLM\Software\Microsoft\Internet Explorer\Search\\"CustomizeSearch"|"" /E : value set successfully!
========== SERVICES/DRIVERS ==========
Service NOD32krn stopped successfully!
Service NOD32krn deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!
========== FILES ==========
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\conduit.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-1.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-10.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-11.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-12.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-13.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-14.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-15.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-16.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-17.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-18.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-19.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-2.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-20.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-21.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-22.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-23.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-24.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-25.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-26.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-27.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-28.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-29.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-3.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-30.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-31.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-32.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-33.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-4.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-5.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-6.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-7.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-8.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin-9.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\icqplugin.xml moved successfully.
F:\Documents and Settings\Hráč\Data aplikací\Mozilla\Firefox\Profiles\7i492ifd.default\searchplugins\sweetim.xml moved successfully.
File/Folder F:\WINDOWS\system32\*.tmp.dll not found.
File/Folder F:\WINDOWS\system32\SET*.tmp not found.
File/Folder F:\WINDOWS\*.tmp not found.
========== COMMANDS ==========
F:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Hráè

User: Hráč
->Temp folder emptied: 734344 bytes
->Temporary Internet Files folder emptied: 3554170 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 28038850 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 456 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes

User: Lucie
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 4708 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 12894 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 31,00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: Hráè

User: Hráč
->Flash cache emptied: 0 bytes

User: LocalService

User: Lucie
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.19.0 log created on 11182011_233923

Files moved on Reboot...

Registry entries deleted on Reboot...

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: UFA.exe - facebook vir

#37 Příspěvek od vyosek »

Spustte znovu OTM a kliknete na CleanUp! - uklidi po sobe

A pokud nejsou problemy co dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

aragor
Návštěvník
Návštěvník
Příspěvky: 32
Registrován: 17 lis 2011 16:42

Re: UFA.exe - facebook vir

#38 Příspěvek od aragor »

Vypadá to, že je už vše v pořádku.

Děkuji Vám moc za poskytnutý čas, který jste byl ochoten věnovat mé pomoci.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: UFA.exe - facebook vir

#39 Příspěvek od vyosek »

Nemate zac, rad jsem pomohl :)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět