Dobrý den, prosím o radu, jak zjistit, jestli v PC není rootkit. Přiznám se, že jsem spustil Combofix, který sice cosi vymazal, ale po restartu to tam bylo zpět. viz log z Combofixu níže. Samozřejmě jsem vypnul obnovu systému a smazal všechny body obnovení. Bez výsledku.
...........................................................
ComboFix 12-04-24.01 - Jiřinka 25.04.2012 12:48:51.3.2 - x86
Microsoft Windows 7 Starter 6.1.7600.0.1250.420.1029.18.1014.410 [GMT 2:00]
Spuštěný z: c:\users\Ji°inka\Desktop\Kontrola a ŔiÜtýnÝ poŔÝtaŔe\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Jirinka\AppData\Roaming\64dlls.exe
c:\users\Jirinka\AppData\Roaming\intel64.exe
c:\users\Jirinka\AppData\Roaming\Kernel32.exe
c:\users\Jirinka\AppData\Roaming\localsys64.exe
c:\users\Jirinka\AppData\Roaming\ntos.exe
c:\users\Jirinka\AppData\Roaming\oembios.exe
c:\users\Jirinka\AppData\Roaming\sdra64.exe
c:\users\Jirinka\AppData\Roaming\sdra73.exe
c:\users\Jirinka\AppData\Roaming\swin32.exe
c:\users\Jirinka\AppData\Roaming\twex.exe
c:\users\Jirinka\AppData\Roaming\twext.exe
c:\users\Jirinka\AppData\Roaming\wsnpoema.exe
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-03-25 do 2012-04-25 )))))))))))))))))))))))))))))))
.
.
2012-04-25 11:01 . 2012-04-25 11:01 -------- d-----w- c:\users\Jiřinka\AppData\Local\temp
2012-04-25 11:01 . 2012-04-25 11:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-04-25 10:15 . 2012-04-25 10:15 -------- d-----w- c:\users\Jiřinka\AppData\Roaming\Malwarebytes
2012-04-25 10:14 . 2010-11-29 15:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-04-25 10:14 . 2012-04-25 10:14 -------- d-----w- c:\programdata\Malwarebytes
2012-04-25 10:14 . 2010-11-29 15:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-25 10:14 . 2012-04-25 10:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-25 09:59 . 2012-04-25 10:00 -------- d-----w- c:\program files\trend micro
2012-04-25 09:58 . 2012-04-25 10:00 -------- d-----w- C:\rsit
2012-04-25 08:24 . 2012-04-25 08:24 -------- d-----w- c:\programdata\Sophos
2012-04-25 08:23 . 2012-04-25 08:23 73728 ----a-r- c:\users\Jiřinka\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2012-04-25 08:23 . 2012-04-25 08:23 73728 ----a-r- c:\users\Jiřinka\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2012-04-25 08:23 . 2012-04-25 08:23 73728 ----a-r- c:\users\Jiřinka\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2012-04-25 08:23 . 2012-04-25 08:23 -------- d-----w- c:\program files\Sophos
2012-04-25 00:56 . 2012-04-25 00:57 -------- d-----w- c:\windows\system32\SPReview
2012-04-25 00:52 . 2012-04-12 22:36 6734704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{90CA61B5-FC5C-40D1-8F6F-E8B332C69D7A}\mpengine.dll
2012-04-24 23:47 . 2012-04-24 23:47 -------- d-----w- c:\program files\Microsoft.NET
2012-04-24 23:43 . 2012-04-24 23:43 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2012-04-24 23:41 . 2012-04-24 23:50 -------- d-----w- c:\windows\SHELLNEW
2012-04-24 23:40 . 2012-04-24 23:40 -------- d-----r- C:\MSOCache
2012-04-24 22:47 . 2012-04-24 22:47 -------- d-----w- c:\program files\Haali
2012-04-24 22:47 . 2012-02-26 14:47 79360 ----a-w- c:\windows\system32\ff_vfw.dll
2012-04-24 22:47 . 2012-04-24 22:47 -------- d-----w- c:\program files\ffdshow
2012-04-24 22:45 . 2012-04-24 22:45 -------- d-----w- c:\program files\Fotosizer
2012-04-24 22:44 . 2012-04-24 23:36 -------- d-----w- c:\users\Jiřinka\AppData\Roaming\Skype
2012-04-24 22:44 . 2012-04-24 22:44 -------- d-----w- c:\program files\Common Files\Skype
2012-04-24 22:43 . 2012-04-24 22:44 -------- d-----r- c:\program files\Skype
2012-04-24 22:02 . 2012-04-24 22:02 -------- d-----w- c:\windows\system32\EventProviders
2012-04-24 21:58 . 2012-04-12 22:36 6734704 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-04-24 21:42 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2012-04-24 21:42 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2012-04-24 21:42 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2012-04-24 21:41 . 2012-03-06 05:59 3958128 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-24 21:41 . 2012-03-06 05:59 3902320 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-24 21:40 . 2010-09-14 06:07 276992 ----a-w- c:\windows\system32\wcncsvc.dll
2012-04-24 21:38 . 2011-02-18 05:33 31232 ----a-w- c:\windows\system32\prevhost.exe
2012-04-24 21:38 . 2011-02-24 05:32 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-04-24 21:38 . 2011-03-11 05:44 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2012-04-24 21:38 . 2011-03-11 05:44 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-04-24 21:38 . 2011-03-11 05:44 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2012-04-24 21:38 . 2011-03-11 05:39 1686016 ----a-w- c:\windows\system32\esent.dll
2012-04-24 21:38 . 2011-03-11 05:43 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2012-04-24 21:38 . 2011-03-11 05:44 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2012-04-24 21:38 . 2011-03-11 05:43 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2012-04-24 21:38 . 2011-03-11 05:43 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2012-04-24 21:38 . 2011-03-11 05:37 74240 ----a-w- c:\windows\system32\fsutil.exe
2012-04-24 21:36 . 2010-12-21 05:36 1389568 ----a-w- c:\windows\system32\msxml6.dll
2012-04-24 21:34 . 2010-11-02 04:46 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-04-24 21:34 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-04-24 21:34 . 2010-11-02 04:23 107520 ----a-w- c:\windows\system32\cdd.dll
2012-04-24 16:33 . 2012-04-24 16:32 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B1129944-9D9F-4D02-A7E8-14ECC052A4C7}\gapaengine.dll
2012-04-24 11:22 . 2012-04-24 21:58 -------- d-----w- c:\program files\Microsoft Security Client
2012-04-24 11:22 . 2010-04-09 07:24 240008 ----a-w- c:\windows\system32\drivers\netio.sys
2012-04-24 11:12 . 2012-04-24 11:12 -------- d-----w- c:\program files\CCleaner
2012-04-24 10:54 . 2012-04-24 10:54 -------- d-----w- c:\users\Jirinka
2012-04-24 10:13 . 2012-04-18 01:06 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C2CBB534-EE89-4B47-BAE8-725CF616E492}\mpengine.dll
2012-04-24 10:13 . 2012-01-31 12:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-04-10 22:41 . 2012-03-01 05:53 19312 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-10 22:41 . 2012-03-01 05:40 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-10 22:41 . 2012-03-01 05:49 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-04-10 22:41 . 2012-03-01 05:45 158720 ----a-w- c:\windows\system32\imagehlp.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-25 08:23 . 2012-04-25 08:23 73728 ----a-r- c:\users\Jiřinka\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2012-04-25 08:23 . 2012-04-25 08:23 73728 ----a-r- c:\users\Jiřinka\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2012-03-20 18:44 . 2011-04-27 13:25 74112 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-20 18:44 . 2011-04-18 11:18 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-12 13:45 . 2012-03-12 13:45 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-03-12 13:45 . 2012-03-12 13:45 161792 ----a-w- c:\windows\system32\msls31.dll
2012-03-12 13:45 . 2012-03-12 13:45 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-03-12 13:45 . 2012-03-12 13:45 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-03-12 13:45 . 2012-03-12 13:45 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-03-12 13:45 . 2012-03-12 13:45 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-03-12 13:45 . 2012-03-12 13:45 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-03-12 13:45 . 2012-03-12 13:45 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-03-12 13:45 . 2012-03-12 13:45 367104 ----a-w- c:\windows\system32\html.iec
2012-03-12 13:45 . 2012-03-12 13:45 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-03-12 13:45 . 2012-03-12 13:45 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-03-12 13:45 . 2012-03-12 13:45 203776 ----a-w- c:\windows\system32\webcheck.dll
2012-03-12 13:45 . 2012-03-12 13:45 152064 ----a-w- c:\windows\system32\wextract.exe
2012-03-12 13:45 . 2012-03-12 13:45 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-03-12 13:45 . 2012-03-12 13:45 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-03-12 13:45 . 2012-03-12 13:45 11776 ----a-w- c:\windows\system32\mshta.exe
2012-03-12 13:45 . 2012-03-12 13:45 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-03-12 13:45 . 2012-03-12 13:45 101888 ----a-w- c:\windows\system32\admparse.dll
2012-03-12 13:42 . 2012-03-12 13:42 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2012-03-12 13:42 . 2012-03-12 13:42 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2012-03-12 13:42 . 2012-03-12 13:42 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2012-03-12 13:42 . 2012-03-12 13:42 3181568 ----a-w- c:\windows\system32\mf.dll
2012-03-12 13:42 . 2012-03-12 13:42 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2012-02-15 05:44 . 2012-03-14 21:35 826368 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-15 04:22 . 2012-03-14 21:35 177152 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-15 04:22 . 2012-03-14 21:35 24064 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 05:41 . 2012-03-14 21:35 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-02-10 05:41 . 2012-03-14 21:35 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-02-10 05:41 . 2012-03-14 21:35 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-02-10 05:41 . 2012-03-14 21:35 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2012-02-10 05:41 . 2012-03-14 21:35 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-02-07 09:02 . 2012-02-07 09:02 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-03 04:01 . 2012-03-14 21:36 2341376 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-08-06 17:18 120104 ----a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-04-05 17356424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2009-06-02 1130504]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-06 7600672]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2009-08-06 707104]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-08-04 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-08-06 349480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"NortonOnlineBackupReminder"="c:\program files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" [2009-07-24 588648]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-18 1537320]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2009-8-14 708608]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-18 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 gupdate1ca99be1bf20502;Služba Google Update (gupdate1ca99be1bf20502);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-20 133104]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2012-04-05 158856]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-20 133104]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 74112]
R3 NisSrv;Kontrola sítě Microsoft;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 214952]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-24 167424]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
S2 Greg_Service;GRegService;c:\program files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2012-04-05 255376]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
.
Obsah adresáře 'Naplánované úlohy'
.
2012-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-20 10:48]
.
2012-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-20 10:48]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0405&m=aspire_one&r=27b512093545l03d4ww75w57823604
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Odeslat obrázek do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat stránku do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: postsignum.cz\www
TCP: DhcpNameServer = 192.168.2.1
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2012-04-25 13:07:42
ComboFix-quarantined-files.txt 2012-04-25 11:07
ComboFix2.txt 2012-04-25 08:10
ComboFix3.txt 2012-04-24 11:09
.
Před spuštěním: Volných bajtů: 201 696 903 168
Po spuštění: Volných bajtů: 201 744 117 760
.
- - End Of File - - 6898191EC91D2B63D5F3E2B7426BC288
Podezření na rootkit
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: Podezření na rootkit
A zde je i log z RSIT:
............................................................................
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jiřinka at 2012-04-25 19:08:25
Microsoft Windows 7 Starter
System drive C: has 192 GB (85%) free of 226 GB
Total RAM: 1014 MB (13% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:08:44, on 25.4.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jiřinka\Desktop\RSIT.exe
C:\Program Files\trend micro\Jiřinka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5w57823604
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate1ca99be1bf20502) (gupdate1ca99be1bf20502) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
--
End of file - 6979 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-06-02 1130504]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-06 7600672]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2009-08-06 707104]
"EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04 199464]
"mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-08-06 349480]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
"NortonOnlineBackupReminder"=C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-07-25 588648]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-06-18 1537320]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2012-03-12 203776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2012-04-25 19:02:36 ----D---- C:\Windows\temp
2012-04-25 13:07:54 ----SHD---- C:\$RECYCLE.BIN
2012-04-25 13:07:43 ----A---- C:\ComboFix.txt
2012-04-25 12:42:55 ----D---- C:\ComboFix
2012-04-25 12:15:00 ----D---- C:\Users\Jiřinka\AppData\Roaming\Malwarebytes
2012-04-25 12:14:53 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2012-04-25 12:14:51 ----D---- C:\ProgramData\Malwarebytes
2012-04-25 12:14:48 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-04-25 12:14:47 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-25 11:59:01 ----D---- C:\Program Files\trend micro
2012-04-25 11:58:58 ----D---- C:\rsit
2012-04-25 10:24:18 ----D---- C:\ProgramData\Sophos
2012-04-25 10:23:44 ----D---- C:\Program Files\Sophos
2012-04-25 02:56:59 ----D---- C:\Windows\system32\SPReview
2012-04-25 01:50:17 ----D---- C:\Program Files\Microsoft Visual Studio
2012-04-25 01:50:16 ----D---- C:\Program Files\Common Files\DESIGNER
2012-04-25 01:47:27 ----D---- C:\Program Files\Microsoft.NET
2012-04-25 01:43:03 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-04-25 01:41:58 ----D---- C:\Windows\SHELLNEW
2012-04-25 01:40:03 ----RD---- C:\MSOCache
2012-04-25 00:47:47 ----D---- C:\Program Files\Haali
2012-04-25 00:47:10 ----A---- C:\Windows\system32\ff_vfw.dll
2012-04-25 00:47:05 ----D---- C:\Program Files\ffdshow
2012-04-25 00:45:51 ----D---- C:\Program Files\Fotosizer
2012-04-25 00:44:32 ----D---- C:\Users\Jiřinka\AppData\Roaming\Skype
2012-04-25 00:44:09 ----D---- C:\Program Files\Common Files\Skype
2012-04-25 00:43:49 ----RD---- C:\Program Files\Skype
2012-04-25 00:02:43 ----D---- C:\Windows\system32\EventProviders
2012-04-24 23:53:09 ----A---- C:\Windows\system32\MRT.exe
2012-04-24 23:42:22 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2012-04-24 23:42:15 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2012-04-24 23:42:15 ----A---- C:\Windows\system32\drivers\ks.sys
2012-04-24 23:41:39 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-04-24 23:41:37 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-24 23:40:57 ----A---- C:\Windows\system32\wcncsvc.dll
2012-04-24 23:38:51 ----A---- C:\Windows\system32\prevhost.exe
2012-04-24 23:38:49 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2012-04-24 23:38:16 ----A---- C:\Windows\system32\drivers\nvstor.sys
2012-04-24 23:38:13 ----A---- C:\Windows\system32\drivers\nvraid.sys
2012-04-24 23:38:13 ----A---- C:\Windows\system32\drivers\ntfs.sys
2012-04-24 23:38:12 ----A---- C:\Windows\system32\esent.dll
2012-04-24 23:38:11 ----A---- C:\Windows\system32\drivers\amdsata.sys
2012-04-24 23:38:10 ----A---- C:\Windows\system32\drivers\storport.sys
2012-04-24 23:38:10 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2012-04-24 23:38:10 ----A---- C:\Windows\system32\drivers\amdxata.sys
2012-04-24 23:38:09 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2012-04-24 23:38:08 ----A---- C:\Windows\system32\fsutil.exe
2012-04-24 23:37:39 ----A---- C:\Windows\system32\xmllite.dll
2012-04-24 23:37:35 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2012-04-24 23:37:30 ----A---- C:\Windows\explorer.exe
2012-04-24 23:37:26 ----A---- C:\Windows\system32\mssrch.dll
2012-04-24 23:37:25 ----A---- C:\Windows\system32\tquery.dll
2012-04-24 23:37:23 ----A---- C:\Windows\system32\SearchIndexer.exe
2012-04-24 23:37:23 ----A---- C:\Windows\system32\mssvp.dll
2012-04-24 23:37:23 ----A---- C:\Windows\system32\mssph.dll
2012-04-24 23:37:22 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2012-04-24 23:37:21 ----A---- C:\Windows\system32\SearchFilterHost.exe
2012-04-24 23:37:21 ----A---- C:\Windows\system32\mssphtb.dll
2012-04-24 23:37:21 ----A---- C:\Windows\system32\msscntrs.dll
2012-04-24 23:37:14 ----A---- C:\Windows\system32\shell32.dll
2012-04-24 23:37:13 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-24 23:37:11 ----A---- C:\Windows\system32\XpsPrint.dll
2012-04-24 23:37:01 ----A---- C:\Windows\system32\upnp.dll
2012-04-24 23:36:59 ----A---- C:\Windows\system32\msxml6.dll
2012-04-24 23:36:57 ----A---- C:\Windows\system32\msxml3.dll
2012-04-24 23:36:55 ----A---- C:\Windows\system32\winhttp.dll
2012-04-24 23:36:55 ----A---- C:\Windows\system32\WebClnt.dll
2012-04-24 23:36:55 ----A---- C:\Windows\system32\davclnt.dll
2012-04-24 23:36:54 ----A---- C:\Windows\system32\wscsvc.dll
2012-04-24 23:36:54 ----A---- C:\Windows\system32\wscapi.dll
2012-04-24 23:36:54 ----A---- C:\Windows\system32\slwga.dll
2012-04-24 23:36:50 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-04-24 23:36:50 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-04-24 23:36:49 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-04-24 23:36:44 ----A---- C:\Windows\system32\FntCache.dll
2012-04-24 23:36:42 ----A---- C:\Windows\system32\drivers\fvevol.sys
2012-04-24 23:36:38 ----A---- C:\Windows\system32\secproc_isv.dll
2012-04-24 23:36:38 ----A---- C:\Windows\system32\secproc.dll
2012-04-24 23:36:37 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2012-04-24 23:36:37 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-04-24 23:36:37 ----A---- C:\Windows\system32\RMActivate.exe
2012-04-24 23:36:36 ----A---- C:\Windows\system32\secproc_ssp.dll
2012-04-24 23:36:35 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2012-04-24 23:36:33 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2012-04-24 23:34:02 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-04-24 23:34:01 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2012-04-24 23:34:01 ----A---- C:\Windows\system32\cdd.dll
2012-04-24 13:22:35 ----D---- C:\Program Files\Microsoft Security Client
2012-04-24 13:22:13 ----A---- C:\Windows\system32\drivers\netio.sys
2012-04-24 13:12:18 ----D---- C:\Program Files\CCleaner
2012-04-24 12:25:37 ----A---- C:\Windows\zip.exe
2012-04-24 12:25:37 ----A---- C:\Windows\SWSC.exe
2012-04-24 12:25:37 ----A---- C:\Windows\SWREG.exe
2012-04-24 12:25:37 ----A---- C:\Windows\sed.exe
2012-04-24 12:25:37 ----A---- C:\Windows\PEV.exe
2012-04-24 12:25:37 ----A---- C:\Windows\NIRCMD.exe
2012-04-24 12:25:37 ----A---- C:\Windows\MBR.exe
2012-04-24 12:25:37 ----A---- C:\Windows\grep.exe
2012-04-24 12:21:51 ----D---- C:\Windows\ERDNT
2012-04-24 12:21:36 ----D---- C:\Qoobox
2012-04-24 12:13:26 ----N---- C:\Windows\system32\MpSigStub.exe
2012-04-11 00:45:24 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-11 00:45:23 ----A---- C:\Windows\system32\iertutil.dll
2012-04-11 00:45:21 ----A---- C:\Windows\system32\jscript9.dll
2012-04-11 00:45:21 ----A---- C:\Windows\system32\jscript.dll
2012-04-11 00:45:18 ----A---- C:\Windows\system32\wininet.dll
2012-04-11 00:45:18 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-11 00:45:16 ----A---- C:\Windows\system32\url.dll
2012-04-11 00:45:15 ----A---- C:\Windows\system32\ieui.dll
2012-04-11 00:45:13 ----A---- C:\Windows\system32\urlmon.dll
2012-04-11 00:45:09 ----A---- C:\Windows\system32\ieframe.dll
2012-04-11 00:45:05 ----A---- C:\Windows\system32\mshtml.dll
2012-04-11 00:41:57 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-11 00:41:55 ----A---- C:\Windows\system32\wmi.dll
2012-04-11 00:41:54 ----A---- C:\Windows\system32\wintrust.dll
2012-04-11 00:41:53 ----A---- C:\Windows\system32\imagehlp.dll
======List of files/folders modified in the last 1 month======
2012-04-25 19:03:03 ----D---- C:\Windows\system32\config
2012-04-25 19:02:36 ----D---- C:\Windows
2012-04-25 18:58:34 ----D---- C:\Windows\System32
2012-04-25 18:58:34 ----D---- C:\Windows\inf
2012-04-25 18:58:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-25 18:58:06 ----D---- C:\Windows\Prefetch
2012-04-25 13:01:46 ----A---- C:\Windows\system.ini
2012-04-25 13:01:35 ----D---- C:\Windows\system32\drivers\etc
2012-04-25 12:55:29 ----D---- C:\Windows\system32\drivers
2012-04-25 12:55:29 ----D---- C:\Windows\AppPatch
2012-04-25 12:55:25 ----D---- C:\Program Files\Common Files
2012-04-25 12:39:26 ----D---- C:\Windows\Minidump
2012-04-25 12:14:51 ----D---- C:\ProgramData
2012-04-25 12:14:47 ----RD---- C:\Program Files
2012-04-25 10:23:56 ----SHD---- C:\Windows\Installer
2012-04-25 10:23:48 ----SD---- C:\Users\Jiřinka\AppData\Roaming\Microsoft
2012-04-25 10:12:22 ----SHD---- C:\System Volume Information
2012-04-25 09:35:04 ----D---- C:\Windows\winsxs
2012-04-25 09:32:55 ----D---- C:\Windows\system32\catroot2
2012-04-25 09:32:55 ----D---- C:\Windows\system32\catroot
2012-04-25 09:20:39 ----D---- C:\Windows\rescache
2012-04-25 09:12:57 ----D---- C:\Program Files\Windows Sidebar
2012-04-25 09:12:56 ----D---- C:\Windows\servicing
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Photo Viewer
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Media Player
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Mail
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Defender
2012-04-25 09:12:56 ----D---- C:\Program Files\DVD Maker
2012-04-25 09:12:56 ----D---- C:\Program Files\Common Files\System
2012-04-25 09:12:55 ----D---- C:\Windows\en-US
2012-04-25 09:12:54 ----D---- C:\Windows\system32\winrm
2012-04-25 09:12:54 ----D---- C:\Windows\system32\sysprep
2012-04-25 09:12:54 ----D---- C:\Windows\system32\slmgr
2012-04-25 09:12:54 ----D---- C:\Windows\system32\sk-SK
2012-04-25 09:12:54 ----D---- C:\Windows\system32\oobe
2012-04-25 09:12:54 ----D---- C:\Windows\system32\migwiz
2012-04-25 09:12:54 ----D---- C:\Windows\system32\en
2012-04-25 09:12:54 ----D---- C:\Windows\system32\Boot
2012-04-25 09:12:48 ----D---- C:\Windows\system32\en-US
2012-04-25 09:12:48 ----D---- C:\Windows\system32\drivers\en-US
2012-04-25 09:12:38 ----D---- C:\Windows\system32\WCN
2012-04-25 09:12:38 ----D---- C:\Windows\system32\DriverStore
2012-04-25 09:12:38 ----D---- C:\Windows\system32\Dism
2012-04-25 09:12:33 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2012-04-25 09:12:12 ----D---- C:\Windows\Speech
2012-04-25 09:04:26 ----D---- C:\ProgramData\Microsoft Help
2012-04-25 09:02:54 ----D---- C:\Program Files\Microsoft Office
2012-04-25 08:56:42 ----D---- C:\Windows\system32\Tasks
2012-04-25 08:56:32 ----D---- C:\Program Files\Acer
2012-04-25 08:56:30 ----HD---- C:\Program Files\InstallShield Installation Information
2012-04-25 04:00:14 ----D---- C:\Windows\Logs
2012-04-25 02:50:13 ----RSD---- C:\Windows\assembly
2012-04-25 02:46:12 ----D---- C:\Program Files\Common Files\microsoft shared
2012-04-25 02:41:03 ----A---- C:\Windows\win.ini
2012-04-25 01:51:13 ----D---- C:\Program Files\MSBuild
2012-04-25 01:48:24 ----RSD---- C:\Windows\Fonts
2012-04-25 01:47:28 ----SD---- C:\ProgramData\Microsoft
2012-04-25 01:38:45 ----D---- C:\Windows\SoftwareDistribution
2012-04-25 01:34:56 ----D---- C:\Program Files\Google
2012-04-25 01:31:56 ----D---- C:\ProgramData\Google
2012-04-25 01:01:25 ----D---- C:\Windows\debug
2012-04-25 00:43:47 ----D---- C:\ProgramData\Skype
2012-04-25 00:18:57 ----D---- C:\Windows\system32\cs-CZ
2012-04-24 13:15:42 ----D---- C:\Windows\Panther
2012-04-24 12:54:03 ----RD---- C:\Users
2012-04-24 12:17:25 ----D---- C:\ProgramData\McAfee
2012-04-24 12:12:58 ----D---- C:\Windows\Tasks
2012-04-15 21:19:56 ----D---- C:\Windows\Microsoft.NET
2012-04-11 23:17:00 ----D---- C:\Windows\system32\migration
2012-04-11 23:16:59 ----D---- C:\Program Files\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2009-03-26 21000]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-06 2657120]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-06-18 212400]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393216]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 18344]
S3 catchme;catchme; \??\C:\Users\JIINKA~1\AppData\Local\Temp\catchme.sys []
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 74112]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-06-24 167424]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 582944]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
R2 Greg_Service;GRegService; C:\Program Files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2012-04-05 255376]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
R2 RS_Service;Raw Socket Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 gupdate1ca99be1bf20502;Služba Google Update (gupdate1ca99be1bf20502); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-20 133104]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-04-05 158856]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-20 133104]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2012-03-26 214952]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
............................................................................
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jiřinka at 2012-04-25 19:08:25
Microsoft Windows 7 Starter
System drive C: has 192 GB (85%) free of 226 GB
Total RAM: 1014 MB (13% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:08:44, on 25.4.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Jiřinka\Desktop\RSIT.exe
C:\Program Files\trend micro\Jiřinka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 5w57823604
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate1ca99be1bf20502) (gupdate1ca99be1bf20502) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Live Updater Service - Acer Incorporated - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
--
End of file - 6979 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2009-06-05 186904]
"LManager"=C:\Program Files\Launch Manager\LManager.exe [2009-06-02 1130504]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-07-06 7600672]
"Acer ePower Management"=C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [2009-08-06 707104]
"EgisTecLiveUpdate"=C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe [2009-08-04 199464]
"mwlDaemon"=C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [2009-08-06 349480]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
"NortonOnlineBackupReminder"=C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivation.exe [2009-07-25 588648]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-06-18 1537320]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2012-03-26 931200]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2012-03-12 203776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"msacm.siren"=sirenacm.dll
"VIDC.FFDS"=ff_vfw.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2012-04-25 19:02:36 ----D---- C:\Windows\temp
2012-04-25 13:07:54 ----SHD---- C:\$RECYCLE.BIN
2012-04-25 13:07:43 ----A---- C:\ComboFix.txt
2012-04-25 12:42:55 ----D---- C:\ComboFix
2012-04-25 12:15:00 ----D---- C:\Users\Jiřinka\AppData\Roaming\Malwarebytes
2012-04-25 12:14:53 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2012-04-25 12:14:51 ----D---- C:\ProgramData\Malwarebytes
2012-04-25 12:14:48 ----A---- C:\Windows\system32\drivers\mbam.sys
2012-04-25 12:14:47 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2012-04-25 11:59:01 ----D---- C:\Program Files\trend micro
2012-04-25 11:58:58 ----D---- C:\rsit
2012-04-25 10:24:18 ----D---- C:\ProgramData\Sophos
2012-04-25 10:23:44 ----D---- C:\Program Files\Sophos
2012-04-25 02:56:59 ----D---- C:\Windows\system32\SPReview
2012-04-25 01:50:17 ----D---- C:\Program Files\Microsoft Visual Studio
2012-04-25 01:50:16 ----D---- C:\Program Files\Common Files\DESIGNER
2012-04-25 01:47:27 ----D---- C:\Program Files\Microsoft.NET
2012-04-25 01:43:03 ----D---- C:\Program Files\Microsoft Visual Studio 8
2012-04-25 01:41:58 ----D---- C:\Windows\SHELLNEW
2012-04-25 01:40:03 ----RD---- C:\MSOCache
2012-04-25 00:47:47 ----D---- C:\Program Files\Haali
2012-04-25 00:47:10 ----A---- C:\Windows\system32\ff_vfw.dll
2012-04-25 00:47:05 ----D---- C:\Program Files\ffdshow
2012-04-25 00:45:51 ----D---- C:\Program Files\Fotosizer
2012-04-25 00:44:32 ----D---- C:\Users\Jiřinka\AppData\Roaming\Skype
2012-04-25 00:44:09 ----D---- C:\Program Files\Common Files\Skype
2012-04-25 00:43:49 ----RD---- C:\Program Files\Skype
2012-04-25 00:02:43 ----D---- C:\Windows\system32\EventProviders
2012-04-24 23:53:09 ----A---- C:\Windows\system32\MRT.exe
2012-04-24 23:42:22 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2012-04-24 23:42:15 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2012-04-24 23:42:15 ----A---- C:\Windows\system32\drivers\ks.sys
2012-04-24 23:41:39 ----A---- C:\Windows\system32\ntkrnlpa.exe
2012-04-24 23:41:37 ----A---- C:\Windows\system32\ntoskrnl.exe
2012-04-24 23:40:57 ----A---- C:\Windows\system32\wcncsvc.dll
2012-04-24 23:38:51 ----A---- C:\Windows\system32\prevhost.exe
2012-04-24 23:38:49 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2012-04-24 23:38:16 ----A---- C:\Windows\system32\drivers\nvstor.sys
2012-04-24 23:38:13 ----A---- C:\Windows\system32\drivers\nvraid.sys
2012-04-24 23:38:13 ----A---- C:\Windows\system32\drivers\ntfs.sys
2012-04-24 23:38:12 ----A---- C:\Windows\system32\esent.dll
2012-04-24 23:38:11 ----A---- C:\Windows\system32\drivers\amdsata.sys
2012-04-24 23:38:10 ----A---- C:\Windows\system32\drivers\storport.sys
2012-04-24 23:38:10 ----A---- C:\Windows\system32\drivers\iaStorV.sys
2012-04-24 23:38:10 ----A---- C:\Windows\system32\drivers\amdxata.sys
2012-04-24 23:38:09 ----A---- C:\Windows\system32\drivers\USBSTOR.SYS
2012-04-24 23:38:08 ----A---- C:\Windows\system32\fsutil.exe
2012-04-24 23:37:39 ----A---- C:\Windows\system32\xmllite.dll
2012-04-24 23:37:35 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2012-04-24 23:37:30 ----A---- C:\Windows\explorer.exe
2012-04-24 23:37:26 ----A---- C:\Windows\system32\mssrch.dll
2012-04-24 23:37:25 ----A---- C:\Windows\system32\tquery.dll
2012-04-24 23:37:23 ----A---- C:\Windows\system32\SearchIndexer.exe
2012-04-24 23:37:23 ----A---- C:\Windows\system32\mssvp.dll
2012-04-24 23:37:23 ----A---- C:\Windows\system32\mssph.dll
2012-04-24 23:37:22 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2012-04-24 23:37:21 ----A---- C:\Windows\system32\SearchFilterHost.exe
2012-04-24 23:37:21 ----A---- C:\Windows\system32\mssphtb.dll
2012-04-24 23:37:21 ----A---- C:\Windows\system32\msscntrs.dll
2012-04-24 23:37:14 ----A---- C:\Windows\system32\shell32.dll
2012-04-24 23:37:13 ----A---- C:\Windows\system32\ntshrui.dll
2012-04-24 23:37:11 ----A---- C:\Windows\system32\XpsPrint.dll
2012-04-24 23:37:01 ----A---- C:\Windows\system32\upnp.dll
2012-04-24 23:36:59 ----A---- C:\Windows\system32\msxml6.dll
2012-04-24 23:36:57 ----A---- C:\Windows\system32\msxml3.dll
2012-04-24 23:36:55 ----A---- C:\Windows\system32\winhttp.dll
2012-04-24 23:36:55 ----A---- C:\Windows\system32\WebClnt.dll
2012-04-24 23:36:55 ----A---- C:\Windows\system32\davclnt.dll
2012-04-24 23:36:54 ----A---- C:\Windows\system32\wscsvc.dll
2012-04-24 23:36:54 ----A---- C:\Windows\system32\wscapi.dll
2012-04-24 23:36:54 ----A---- C:\Windows\system32\slwga.dll
2012-04-24 23:36:50 ----A---- C:\Windows\system32\drivers\usbport.sys
2012-04-24 23:36:50 ----A---- C:\Windows\system32\drivers\usbehci.sys
2012-04-24 23:36:49 ----A---- C:\Windows\system32\drivers\usbhub.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbohci.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbd.sys
2012-04-24 23:36:48 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2012-04-24 23:36:44 ----A---- C:\Windows\system32\FntCache.dll
2012-04-24 23:36:42 ----A---- C:\Windows\system32\drivers\fvevol.sys
2012-04-24 23:36:38 ----A---- C:\Windows\system32\secproc_isv.dll
2012-04-24 23:36:38 ----A---- C:\Windows\system32\secproc.dll
2012-04-24 23:36:37 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2012-04-24 23:36:37 ----A---- C:\Windows\system32\RMActivate_isv.exe
2012-04-24 23:36:37 ----A---- C:\Windows\system32\RMActivate.exe
2012-04-24 23:36:36 ----A---- C:\Windows\system32\secproc_ssp.dll
2012-04-24 23:36:35 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2012-04-24 23:36:33 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2012-04-24 23:34:02 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2012-04-24 23:34:01 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2012-04-24 23:34:01 ----A---- C:\Windows\system32\cdd.dll
2012-04-24 13:22:35 ----D---- C:\Program Files\Microsoft Security Client
2012-04-24 13:22:13 ----A---- C:\Windows\system32\drivers\netio.sys
2012-04-24 13:12:18 ----D---- C:\Program Files\CCleaner
2012-04-24 12:25:37 ----A---- C:\Windows\zip.exe
2012-04-24 12:25:37 ----A---- C:\Windows\SWSC.exe
2012-04-24 12:25:37 ----A---- C:\Windows\SWREG.exe
2012-04-24 12:25:37 ----A---- C:\Windows\sed.exe
2012-04-24 12:25:37 ----A---- C:\Windows\PEV.exe
2012-04-24 12:25:37 ----A---- C:\Windows\NIRCMD.exe
2012-04-24 12:25:37 ----A---- C:\Windows\MBR.exe
2012-04-24 12:25:37 ----A---- C:\Windows\grep.exe
2012-04-24 12:21:51 ----D---- C:\Windows\ERDNT
2012-04-24 12:21:36 ----D---- C:\Qoobox
2012-04-24 12:13:26 ----N---- C:\Windows\system32\MpSigStub.exe
2012-04-11 00:45:24 ----A---- C:\Windows\system32\mshtmled.dll
2012-04-11 00:45:23 ----A---- C:\Windows\system32\iertutil.dll
2012-04-11 00:45:21 ----A---- C:\Windows\system32\jscript9.dll
2012-04-11 00:45:21 ----A---- C:\Windows\system32\jscript.dll
2012-04-11 00:45:18 ----A---- C:\Windows\system32\wininet.dll
2012-04-11 00:45:18 ----A---- C:\Windows\system32\jsproxy.dll
2012-04-11 00:45:16 ----A---- C:\Windows\system32\url.dll
2012-04-11 00:45:15 ----A---- C:\Windows\system32\ieui.dll
2012-04-11 00:45:13 ----A---- C:\Windows\system32\urlmon.dll
2012-04-11 00:45:09 ----A---- C:\Windows\system32\ieframe.dll
2012-04-11 00:45:05 ----A---- C:\Windows\system32\mshtml.dll
2012-04-11 00:41:57 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2012-04-11 00:41:55 ----A---- C:\Windows\system32\wmi.dll
2012-04-11 00:41:54 ----A---- C:\Windows\system32\wintrust.dll
2012-04-11 00:41:53 ----A---- C:\Windows\system32\imagehlp.dll
======List of files/folders modified in the last 1 month======
2012-04-25 19:03:03 ----D---- C:\Windows\system32\config
2012-04-25 19:02:36 ----D---- C:\Windows
2012-04-25 18:58:34 ----D---- C:\Windows\System32
2012-04-25 18:58:34 ----D---- C:\Windows\inf
2012-04-25 18:58:34 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-04-25 18:58:06 ----D---- C:\Windows\Prefetch
2012-04-25 13:01:46 ----A---- C:\Windows\system.ini
2012-04-25 13:01:35 ----D---- C:\Windows\system32\drivers\etc
2012-04-25 12:55:29 ----D---- C:\Windows\system32\drivers
2012-04-25 12:55:29 ----D---- C:\Windows\AppPatch
2012-04-25 12:55:25 ----D---- C:\Program Files\Common Files
2012-04-25 12:39:26 ----D---- C:\Windows\Minidump
2012-04-25 12:14:51 ----D---- C:\ProgramData
2012-04-25 12:14:47 ----RD---- C:\Program Files
2012-04-25 10:23:56 ----SHD---- C:\Windows\Installer
2012-04-25 10:23:48 ----SD---- C:\Users\Jiřinka\AppData\Roaming\Microsoft
2012-04-25 10:12:22 ----SHD---- C:\System Volume Information
2012-04-25 09:35:04 ----D---- C:\Windows\winsxs
2012-04-25 09:32:55 ----D---- C:\Windows\system32\catroot2
2012-04-25 09:32:55 ----D---- C:\Windows\system32\catroot
2012-04-25 09:20:39 ----D---- C:\Windows\rescache
2012-04-25 09:12:57 ----D---- C:\Program Files\Windows Sidebar
2012-04-25 09:12:56 ----D---- C:\Windows\servicing
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Photo Viewer
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Media Player
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Mail
2012-04-25 09:12:56 ----D---- C:\Program Files\Windows Defender
2012-04-25 09:12:56 ----D---- C:\Program Files\DVD Maker
2012-04-25 09:12:56 ----D---- C:\Program Files\Common Files\System
2012-04-25 09:12:55 ----D---- C:\Windows\en-US
2012-04-25 09:12:54 ----D---- C:\Windows\system32\winrm
2012-04-25 09:12:54 ----D---- C:\Windows\system32\sysprep
2012-04-25 09:12:54 ----D---- C:\Windows\system32\slmgr
2012-04-25 09:12:54 ----D---- C:\Windows\system32\sk-SK
2012-04-25 09:12:54 ----D---- C:\Windows\system32\oobe
2012-04-25 09:12:54 ----D---- C:\Windows\system32\migwiz
2012-04-25 09:12:54 ----D---- C:\Windows\system32\en
2012-04-25 09:12:54 ----D---- C:\Windows\system32\Boot
2012-04-25 09:12:48 ----D---- C:\Windows\system32\en-US
2012-04-25 09:12:48 ----D---- C:\Windows\system32\drivers\en-US
2012-04-25 09:12:38 ----D---- C:\Windows\system32\WCN
2012-04-25 09:12:38 ----D---- C:\Windows\system32\DriverStore
2012-04-25 09:12:38 ----D---- C:\Windows\system32\Dism
2012-04-25 09:12:33 ----D---- C:\Windows\system32\Printing_Admin_Scripts
2012-04-25 09:12:12 ----D---- C:\Windows\Speech
2012-04-25 09:04:26 ----D---- C:\ProgramData\Microsoft Help
2012-04-25 09:02:54 ----D---- C:\Program Files\Microsoft Office
2012-04-25 08:56:42 ----D---- C:\Windows\system32\Tasks
2012-04-25 08:56:32 ----D---- C:\Program Files\Acer
2012-04-25 08:56:30 ----HD---- C:\Program Files\InstallShield Installation Information
2012-04-25 04:00:14 ----D---- C:\Windows\Logs
2012-04-25 02:50:13 ----RSD---- C:\Windows\assembly
2012-04-25 02:46:12 ----D---- C:\Program Files\Common Files\microsoft shared
2012-04-25 02:41:03 ----A---- C:\Windows\win.ini
2012-04-25 01:51:13 ----D---- C:\Program Files\MSBuild
2012-04-25 01:48:24 ----RSD---- C:\Windows\Fonts
2012-04-25 01:47:28 ----SD---- C:\ProgramData\Microsoft
2012-04-25 01:38:45 ----D---- C:\Windows\SoftwareDistribution
2012-04-25 01:34:56 ----D---- C:\Program Files\Google
2012-04-25 01:31:56 ----D---- C:\ProgramData\Google
2012-04-25 01:01:25 ----D---- C:\Windows\debug
2012-04-25 00:43:47 ----D---- C:\ProgramData\Skype
2012-04-25 00:18:57 ----D---- C:\Windows\system32\cs-CZ
2012-04-24 13:15:42 ----D---- C:\Windows\Panther
2012-04-24 12:54:03 ----RD---- C:\Users
2012-04-24 12:17:25 ----D---- C:\ProgramData\McAfee
2012-04-24 12:12:58 ----D---- C:\Windows\Tasks
2012-04-15 21:19:56 ----D---- C:\Windows\Microsoft.NET
2012-04-11 23:17:00 ----D---- C:\Windows\system32\migration
2012-04-11 23:16:59 ----D---- C:\Program Files\Internet Explorer
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 330264]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2012-03-20 171064]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-02 18992]
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-02 16432]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-02 60976]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-10-05 1221632]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2009-03-26 21000]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-07-06 2657120]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x86.sys [2009-07-27 51712]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-06-18 212400]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 78336]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 34816]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2011-04-28 393216]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 60416]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 86056]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\DRIVERS\btwavdt.sys [2009-07-01 108072]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 29472]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 18344]
S3 catchme;catchme; \??\C:\Users\JIINKA~1\AppData\Local\Temp\catchme.sys []
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 74112]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-06-24 167424]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 582944]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2009-08-06 727584]
R2 Greg_Service;GRegService; C:\Program Files\Acer\Registration\GregHSRW.exe [2009-06-04 1150496]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe [2009-06-05 354840]
R2 Live Updater Service;Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2012-04-05 255376]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2012-03-26 11552]
R2 MWLService;MyWinLocker Service; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2009-08-06 311592]
R2 RS_Service;Raw Socket Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
S2 gupdate1ca99be1bf20502;Služba Google Update (gupdate1ca99be1bf20502); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-20 133104]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-04-05 158856]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-01-20 133104]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2012-03-26 214952]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
-----------------EOF-----------------
Re: Podezření na rootkit
A je log z GMERu krátký:
..........................................................................................
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-04-25 19:14:43
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 TOSHIBA_ rev.FG00
Running: gmer.exe; Driver: C:\Users\JIINKA~1\AppData\Local\Temp\ugldypow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
..........................................................................................
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-04-25 19:14:43
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 TOSHIBA_ rev.FG00
Running: gmer.exe; Driver: C:\Users\JIINKA~1\AppData\Local\Temp\ugldypow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----

Přispějete na provoz fóra?