Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Regrio
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 05 čer 2012 20:30

Kontrola logu

#1 Příspěvek od Regrio »

Zdravím, přibližně před 5-6 dny se mi zpomalil internet (stahování, načítání videí streamů atd.). Zkoušel jsem PC pročistit Ccleanerem, antivirem a SuperAntiSpywarem, ale nic nepomohlo. Mám podezření na nějaký vir nebo spíše viry, který dělaj nepořádek. Prosím o kontrolu logu a předem díky :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Dasty at 2012-06-05 21:24:59
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 87 GB (55%) free of 157 GB
Total RAM: 3070 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:24, on 5.6.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG2012\avgfws.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\ZyXEL\G-302v3\G-302v3.exe
C:\Documents and Settings\Dasty\Data aplikací\Dropbox\bin\Dropbox.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\Dasty\Plocha\RSIT.exe
C:\Program Files\trend micro\Dasty.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-117609710-1390067357-1801674531-1010\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Dropbox.lnk = ?
O4 - Global Startup: ZyXEL G-302 v3 Utility.lnk = C:\Program Files\ZyXEL\G-302v3\G-302v3.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 9276820171
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\DOCUME~1\Dasty\LOCALS~1\Temp\1707031.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: Hi-Rez Studios Authenticate and Update Service (HiPatchService) - Unknown owner - D:\Games\Global Agenda\HiPatchService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 9886 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\ASC5_AutoUpdate.job
C:\WINDOWS\tasks\SmartDefrag_Startup.job
C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task b058fe08-77b7-4a89-a76d-2c759e31ba2e.job

=========Mozilla firefox=========

ProfilePath - C:\Documents and Settings\Dasty\Data aplikací\Mozilla\Firefox\Profiles\uwk8cm9f.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "extensions.enabledItems" - "{20a82645-c095-46ed-80e3-08825760534b}:1.1, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5, {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26, jqs@sun.com:1.0, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.24"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"jqs@sun.com"=C:\Program Files\Java\jre6\lib\deploy\jqs\ff
"{1E73965B-8B48-48be-9C8D-68B920ABC1C4}"=C:\Program Files\AVG\AVG2012\Firefox4\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 11.2.202.235 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
NPOFF12.DLL
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
npwachk.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
answers.xml
bing.xml
creativecommons.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Documents and Settings\Dasty\Data aplikací\Mozilla\Firefox\Profiles\uwk8cm9f.default\searchplugins\
askcom.xml
daemon-search.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG2012\avgssie.dll [2011-11-11 1378144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2011-06-12 4221328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-08-31 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-08-31 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-06-27 16875008]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2008-06-18 77824]
"AlcWzrd"=C:\WINDOWS\ALCWZRD.EXE [2008-06-19 2808832]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2008-06-19 57344]
"Kernel and Hardware Abstraction Layer"=C:\WINDOWS\KHALMNPR.EXE [2009-06-17 55824]
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2012-02-20 59240]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-10-24 421888]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2012-05-15 15504192]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2012-05-15 1634112]
"AVG_TRAY"=C:\Program Files\AVG\AVG2012\avgtray.exe [2012-01-24 2416480]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Advanced SystemCare 5"=C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe [2012-03-06 574296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe [2012-03-06 574296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
c:\program files\itunes\ituneshelper.exe [2012-03-27 421736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2012-06-05 3905920]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
c:\program files\unlocker\unlockerassistant.exe [2010-07-04 17408]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
ZyXEL G-302 v3 Utility.lnk - C:\Program Files\ZyXEL\G-302v3\G-302v3.exe

C:\Documents and Settings\Dasty\Nabídka Start\Programy\Po spuštění
Dropbox.lnk - C:\Documents and Settings\Dasty\Data aplikací\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\DOCUME~1\Dasty\LOCALS~1\Temp\1707031.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2011-05-04 551296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL [2011-06-12 4221328]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2011-07-19 113024]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\!SASCORE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avas_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avmgma_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\avss_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\gozer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tpavdrw_service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoResolveSearch"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Winamp\winamp.exe"="C:\Program Files\Winamp\winamp.exe:*:Enabled:Winamp"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"D:\Games\Assassins Creed Brotherhood\ACBSP.exe"="D:\Games\Assassins Creed Brotherhood\ACBSP.exe:*:Enabled:Assassin's Creed Brotherhood"
"D:\Games\Assassins Creed Brotherhood\ACBMP.exe"="D:\Games\Assassins Creed Brotherhood\ACBMP.exe:*:Enabled:Assassin's Creed Brotherhood Multiplayer"
"D:\Games\Assassins Creed Brotherhood\AssassinsCreedBrotherhood.exe"="D:\Games\Assassins Creed Brotherhood\AssassinsCreedBrotherhood.exe:*:Enabled:Assassin's Creed Brotherhood Update"
"D:\Games\Assassins Creed Brotherhood\UPlayBrowser.exe"="D:\Games\Assassins Creed Brotherhood\UPlayBrowser.exe:*:Enabled:Assassin's Creed Brotherhood Uplay"
"D:\Games\League of Legends\lol.launcher.exe"="D:\Games\League of Legends\lol.launcher.exe:*:Enabled:League of Legends Launcher"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office14\ONENOTE.EXE:*:Enabled:Microsoft OneNote"
"C:\Program Files\Microsoft Office\Office14\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office14\GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace"
"C:\Documents and Settings\Dasty\Data aplikací\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\Dasty\Data aplikací\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"D:\Games\Assassins Creed Revelations\ACRSP.exe"="D:\Games\Assassins Creed Revelations\ACRSP.exe:*:Enabled:Assassin's Creed Revelations"
"D:\Games\Assassins Creed Revelations\ACRMP.exe"="D:\Games\Assassins Creed Revelations\ACRMP.exe:*:Enabled:Assassin's Creed Revelations Multiplayer"
"D:\Games\Assassins Creed Revelations\AssassinsCreedRevelations.exe"="D:\Games\Assassins Creed Revelations\AssassinsCreedRevelations.exe:*:Enabled:Assassin's Creed Revelations Update"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"E:\Games\Mass Effect 2\Binaries\MassEffect2.exe"="E:\Games\Mass Effect 2\Binaries\MassEffect2.exe:*:Enabled:Mass Effect 2 Game"
"E:\Games\Mass Effect 2\MassEffect2Launcher.exe"="E:\Games\Mass Effect 2\MassEffect2Launcher.exe:*:Enabled:Mass Effect 2 Launcher"
"E:\Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe"="E:\Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe:*:Enabled:Mass Effect™ 3"
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe"="C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"E:\Games\Diablo III\Diablo III.exe"="E:\Games\Diablo III\Diablo III.exe:*:Enabled:Diablo III"
"C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\AVG\AVG2012\avgmfapx.exe"="C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG2012\avgnsx.exe"="C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG2012\avgdiagex.exe"="C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostika 2012"
"C:\Program Files\AVG\AVG2012\avgemcx.exe"="C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Obecná kontrola pošty"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"msacm.voxacm160"=vct3216.acm
"msacm.scg726"=scg726.acm
"msacm.alf2cd"=alf2cd.acm
"msacm.ac3acm"=AC3ACM.acm
"vidc.dvsd"=mcdvd_32.dll
"vidc.xvid"=xvidvfw.dll
"vidc.DIVX"=DivX.dll
"vidc.mpg4"=mpg4c32.dll
"vidc.mp42"=mpg4c32.dll
"vidc.mp43"=mpg4c32.dll
"msacm.vorbis"=vorbis.acm
"vidc.yv12"=yv12vfw.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======List of files/folders created in the last 1 month======

2012-06-05 21:24:59 ----D---- C:\rsit
2012-06-05 21:24:59 ----D---- C:\Program Files\trend micro
2012-06-05 18:34:19 ----SHD---- C:\Config.Msi
2012-06-05 18:17:52 ----D---- C:\Rbackup
2012-06-05 18:02:39 ----D---- C:\Program Files\Perfect Uninstaller
2012-06-05 17:24:33 ----D---- C:\Documents and Settings\Dasty\Data aplikací\Opera
2012-06-05 17:24:23 ----D---- C:\Program Files\Opera
2012-06-05 14:35:54 ----D---- C:\Program Files\Dropbox
2012-06-05 00:20:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2718704$
2012-06-04 22:15:39 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2012-06-02 15:14:18 ----A---- C:\bdlog.txt
2012-06-02 15:10:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\BDLogging
2012-06-02 15:09:48 ----N---- C:\WINDOWS\system32\spmsgXP_2k3.dll
2012-06-02 15:09:38 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2012-06-02 14:26:31 ----D---- C:\Documents and Settings\Dasty\Data aplikací\QuickScan
2012-06-01 02:41:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2467659$
2012-06-01 02:41:20 ----D---- C:\WINDOWS\ie8updates
2012-06-01 02:39:43 ----HDC---- C:\WINDOWS\ie8
2012-05-28 22:48:55 ----D---- C:\WINDOWS\system32\NtmsData
2012-05-28 22:15:50 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2012-05-28 21:45:10 ----D---- C:\Program Files\Common Files\TrustPort
2012-05-28 14:23:10 ----D---- C:\Documents and Settings\Dasty\Data aplikací\SUPERAntiSpyware.com
2012-05-28 14:22:44 ----D---- C:\Program Files\SUPERAntiSpyware
2012-05-28 14:22:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2012-05-28 14:22:24 ----D---- C:\keygen
2012-05-28 13:33:37 ----D---- C:\Program Files\PC Tools Security
2012-05-28 12:55:29 ----D---- C:\Program Files\ESET
2012-05-28 12:29:33 ----A---- C:\WINDOWS\system32\drivers\Cat.DB
2012-05-28 12:29:10 ----D---- C:\Program Files\Common Files\PC Tools
2012-05-28 12:29:10 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-05-26 01:18:33 ----D---- C:\Documents and Settings\Dasty\Data aplikací\DarknessII
2012-05-25 15:50:09 ----D---- C:\Program Files\Common Files\Bitdefender
2012-05-25 15:50:09 ----D---- C:\Program Files\Bitdefender
2012-05-25 15:38:19 ----HDC---- C:\WINDOWS\$NtUninstallKB2492386$
2012-05-25 15:37:10 ----D---- C:\WINDOWS\system32\WindowsPowerShell
2012-05-25 15:37:09 ----D---- C:\WINDOWS\system32\winrm
2012-05-25 15:37:09 ----D---- C:\WINDOWS\system32\GroupPolicy
2012-05-25 15:37:02 ----HDC---- C:\WINDOWS\$968930Uinstall_KB968930$
2012-05-25 15:37:01 ----D---- C:\WINDOWS\$NtUninstallKB968930$
2012-05-25 15:35:38 ----HDC---- C:\WINDOWS\$NtUninstallbasecsp$
2012-05-25 15:35:04 ----A---- C:\WINDOWS\system32\RegistryDefragBootTime.exe
2012-05-25 15:02:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\IObit
2012-05-25 10:50:17 ----D---- C:\Program Files\IObit
2012-05-25 10:50:17 ----D---- C:\Documents and Settings\Dasty\Data aplikací\IObit
2012-05-15 15:13:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard Entertainment
2012-05-13 13:53:40 ----A---- C:\WINDOWS\RTacDbg.txt
2012-05-13 13:52:50 ----A---- C:\WINDOWS\system32\drivers\rtl8185.sys
2012-05-13 13:52:43 ----RA---- C:\WINDOWS\system32\drivers\EAPPkt.sys
2012-05-13 13:52:43 ----A---- C:\WINDOWS\system32\drivers\SjyPkt.sys
2012-05-13 13:52:41 ----D---- C:\Program Files\ZyXEL
2012-05-11 00:09:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2659262$
2012-05-11 00:04:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2686509$
2012-05-11 00:04:34 ----HDC---- C:\WINDOWS\$NtUninstallKB2695962$
2012-05-11 00:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2676562$

======List of files/folders modified in the last 1 month======

2012-06-05 21:25:07 ----D---- C:\WINDOWS\Prefetch
2012-06-05 21:24:59 ----RD---- C:\Program Files
2012-06-05 21:22:31 ----D---- C:\WINDOWS\Temp
2012-06-05 21:22:28 ----D---- C:\Documents and Settings\Dasty\Data aplikací\Winamp
2012-06-05 20:53:27 ----D---- C:\Documents and Settings\Dasty\Data aplikací\Dropbox
2012-06-05 20:53:13 ----D---- C:\WINDOWS\system32\CatRoot2
2012-06-05 20:53:05 ----D---- C:\WINDOWS
2012-06-05 20:52:29 ----D---- C:\WINDOWS\system32
2012-06-05 20:51:06 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-06-05 20:43:52 ----D---- C:\Program Files\Mozilla Firefox
2012-06-05 20:18:32 ----D---- C:\WINDOWS\system32\drivers
2012-06-05 19:16:59 ----RSD---- C:\WINDOWS\assembly
2012-06-05 19:16:59 ----D---- C:\WINDOWS\Microsoft.NET
2012-06-05 18:53:38 ----SD---- C:\WINDOWS\Tasks
2012-06-05 18:45:42 ----SHD---- C:\WINDOWS\Installer
2012-06-05 18:44:56 ----D---- C:\WINDOWS\WinSxS
2012-06-05 18:44:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-06-05 18:35:37 ----D---- C:\WINDOWS\system32\config
2012-06-05 18:26:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-06-05 18:26:54 ----HD---- C:\WINDOWS\inf
2012-06-05 18:26:24 ----HD---- C:\WINDOWS\$hf_mig$
2012-06-05 17:32:44 ----D---- C:\Program Files\DsNET Corp
2012-06-05 17:30:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2012-06-05 17:28:11 ----D---- C:\Program Files\thriXXX
2012-06-05 16:35:00 ----D---- C:\WINDOWS\system32\drivers\AVG
2012-06-05 16:01:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG2012
2012-06-05 15:33:57 ----D---- C:\Program Files\NVIDIA Corporation
2012-06-05 14:53:13 ----D---- C:\WINDOWS\system32\CatRoot
2012-06-05 14:22:25 ----D---- C:\WINDOWS\system32\drivers\etc
2012-06-02 02:43:24 ----D---- C:\Program Files\Internet Explorer
2012-06-01 11:52:05 ----D---- C:\WINDOWS\system32\cs-cz
2012-06-01 11:52:04 ----D---- C:\WINDOWS\Media
2012-06-01 11:52:04 ----D---- C:\WINDOWS\Help
2012-06-01 11:52:03 ----D---- C:\WINDOWS\AppPatch
2012-06-01 02:36:54 ----D---- C:\WINDOWS\Debug
2012-06-01 00:18:01 ----D---- C:\Program Files\DAEMON Tools Toolbar
2012-05-31 15:22:06 ----A---- C:\WINDOWS\system32\crypt32.dll
2012-05-31 15:08:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-05-28 22:48:55 ----D---- C:\WINDOWS\repair
2012-05-28 22:48:42 ----D---- C:\WINDOWS\Registration
2012-05-28 21:45:10 ----D---- C:\Program Files\Common Files
2012-05-28 14:04:05 ----SHD---- C:\System Volume Information
2012-05-28 12:20:18 ----D---- C:\Program Files\Spybot - Search & Destroy
2012-05-28 12:20:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2012-05-28 12:18:43 ----D---- C:\Program Files\Image-Line
2012-05-26 10:47:55 ----D---- C:\Documents and Settings\Dasty\Data aplikací\DAEMON Tools Lite
2012-05-25 15:43:26 ----D---- C:\WINDOWS\security
2012-05-25 15:37:09 ----D---- C:\WINDOWS\system32\wbem
2012-05-25 12:15:32 ----D---- C:\WINDOWS\Logs
2012-05-25 12:15:30 ----D---- C:\Documents and Settings\Dasty\Data aplikací\uTorrent
2012-05-25 10:32:59 ----D---- C:\Program Files\VstPlugins
2012-05-25 10:29:35 ----D---- C:\Program Files\AVS4YOU
2012-05-25 10:29:27 ----D---- C:\Program Files\Common Files\AVSMedia
2012-05-15 16:12:03 ----D---- C:\Program Files\QIP
2012-05-15 16:02:17 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\OpenCL.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvgenco32.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvdispco32.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2012-05-15 12:18:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2012-05-15 11:40:26 ----A---- C:\WINDOWS\system32\nvwddi.dll
2012-05-15 11:40:02 ----A---- C:\WINDOWS\system32\nvcpl.dll
2012-05-15 11:40:02 ----A---- C:\WINDOWS\system32\nvcolor.exe
2012-05-15 11:40:01 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2012-05-15 11:40:01 ----A---- C:\WINDOWS\system32\nvmctray.dll
2012-05-14 21:42:18 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2012-05-13 13:52:41 ----HD---- C:\Program Files\InstallShield Installation Information
2012-05-11 00:09:09 ----D---- C:\WINDOWS\system32\XPSViewer

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2011-08-08 40016]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2011-03-04 218688]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2011-03-04 21035]
R2 EAPPkt;Realtek EAPPkt Protocol; C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2006-11-15 38144]
R2 LBeepKE;LBeepKE; C:\WINDOWS\System32\Drivers\LBeepKE.sys [2009-06-17 10384]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2011-05-23 30944]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134608]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
R3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-06-27 4742656]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2009-06-17 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2009-06-17 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2009-06-17 37392]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\WINDOWS\System32\Drivers\LUsbFilt.Sys [2009-06-17 28560]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2012-05-15 14014656]
R3 rtl8185;G-302 v3 802.11g Wireless PCI Adapter Driver; C:\WINDOWS\system32\DRIVERS\rtl8185.sys [2009-10-06 823936]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-06-16 109184]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2009-07-14 444136]
S0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2011-07-06 436792]
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2011-05-23 30944]
S3 cpuz134;cpuz134; \??\C:\DOCUME~1\Dasty\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys []
S3 L8042mou;SetPoint PS/2 Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\L8042mou.Sys [2009-06-17 63248]
S3 LMouKE;SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2009-06-17 79248]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2011-07-01 26624]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS\system32\DRIVERS\taphss.sys [2012-01-05 32768]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2012-02-15 43520]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 !SASCORE;SAS Core Service; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [2011-08-12 116608]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5; C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe [2012-03-14 913752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2012-02-27 55144]
R2 avgfws;AVG Firewall; C:\Program Files\AVG\AVG2012\avgfws.exe [2011-11-23 2391832]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 390504]
R2 GEST Service;GEST Service for program management.; C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe [2008-07-11 80392]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2011-08-31 153376]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2012-05-15 164160]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-05-15 1262400]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2011-05-26 75136]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2012-05-14 214520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service; D:\Games\Global Agenda\HiPatchService.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-04 257696]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2012-03-27 821608]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe [2009-07-20 121360]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 WinRM;Windows Remote Management (WS-Management); C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#2 Příspěvek od vyosek »

Zdravim a pekny vecer preji :)

Vas log se studuje Obrázek a pracuje se na nem Obrázek.
Prosim o strpeni!Obrázek
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#3 Příspěvek od vyosek »

:arrow: Trvate na antiviru avg ? U nas neni moc obliben - vyssi zatez systemu, slabsi detekce. Ja bych byl pro zmenu, ale vy rozhodnete

:arrow: Odinstalujte Advanced SystemCare 5 a nasledne i vse od IOBit - jsou to cinske smejdy a spise jen skodi nez jsou uzitkem. Hledaji nesmyslne a neexistujici problemy, databazi haveti ukradli jine renomovane spolecnosti

:arrow: Stahnete RogueKiller http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
  • Ukoncete vsechny programy
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Pockejte na dokonceni PreScanu
  • Zvolte moznost Prohledat (scan)
  • Po dokonceni skenu kliknete na Zpráva (Report)- otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Regrio
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 05 čer 2012 20:30

Re: Kontrola logu

#4 Příspěvek od Regrio »

Co se antiviru týče, tak s tím zápasím už delší dobu. Tento PC nepoužívám jen já takže najít něco co by pochytalo většinu havěti je těžké. Prohlížel jsem X webů s hodnocením free antivirů a pokaždý jsou v pořadí jinak. Pokud mě poradíte, který je "nejlepší" budu jenom rád :)
Log:
RogueKiller V7.5.3 [06/05/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Dasty [Práva správce]
Mód: Kontrola -- Datum: 06/05/2012 22:14:58

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[APPINIT_DLL] HKLM\[...]\Windows : AppInit_DLLs (C:\DOCUME~1\Dasty\LOCALS~1\Temp\1707031.dll) -> FOUND

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
[...]


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST31000520AS +++++
--- User ---
[MBR] 4ef87cf953db5ed6b5503c72726950fc
[BSP] 732df4a1c6ccbc3cc490692971726d9e : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 953859 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SAMSUNG HD502IJ +++++
--- User ---
[MBR] 5d69f7d4b8c1c361d57106db2e98782d
[BSP] 991fa983f11a82b50c3be6494fb72f7b : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 156931 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 321396390 | Size: 319997 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[1].txt >>
RKreport[1].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#5 Příspěvek od vyosek »

:arrow: Odinstalujte avg a pouzijte jeste tenhle remover http://www.avast.com/cs-cz/free-antivirus-download

:arrow: Nainstalujte Avast Free http://www.avast.com/cs-cz/free-antivirus-download

:arrow: Spustte znovu RogueKiller
  • Pokud pouzivate Win Vista ci W7, kliknete na RogueKiller pravym a dejte Run As Administrator ci Spustit jako spravce
  • Zvolte moznost Prohledat a pote Smazat a nasledne Zprava - otevre se log, ten sem vlozte
  • Pak kliknete na Oprava Host a Zprava - otevre se log, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Regrio
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 05 čer 2012 20:30

Re: Kontrola logu

#6 Příspěvek od Regrio »

Na ten remover se vám asi nezkopíroval odkaz :)

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#7 Příspěvek od vyosek »

"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Regrio
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 05 čer 2012 20:30

Re: Kontrola logu

#8 Příspěvek od Regrio »

Log 1:
RogueKiller V7.5.3 [06/05/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Dasty [Práva správce]
Mód: Odebrat -- Datum: 06/05/2012 23:10:15

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Záznamy Registrů: 2 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[APPINIT_DLL] HKLM\[...]\Windows : AppInit_DLLs (C:\DOCUME~1\Dasty\LOCALS~1\Temp\1707031.dll) -> REPLACED ()

¤¤¤ Zvláštní soubory / Složky: ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
[...]


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: ST31000520AS +++++
--- User ---
[MBR] 4ef87cf953db5ed6b5503c72726950fc
[BSP] 732df4a1c6ccbc3cc490692971726d9e : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 953859 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SAMSUNG HD502IJ +++++
--- User ---
[MBR] 5d69f7d4b8c1c361d57106db2e98782d
[BSP] 991fa983f11a82b50c3be6494fb72f7b : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 156931 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 321396390 | Size: 319997 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt






Log 2:
RogueKiller V7.5.3 [06/05/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Podpora: http://www.geekstogo.com/forum/files/fi ... guekiller/
Operační systém: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Spuštěno v: Normální režim
Uživatel: Dasty [Práva správce]
Mód: Oprava HOSTS -- Datum: 06/05/2012 23:11:02

¤¤¤ Škodlivé procesy: 0 ¤¤¤

¤¤¤ Ovladač: [NAHRÁNO] ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
[...]


¤¤¤ Resetovaný HOSTS: ¤¤¤


Dokončeno : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#9 Příspěvek od vyosek »

:arrow: Stahnete RKill http://download.bleepingcomputer.com/grinler/rkill.com PROSIM CTETE DUKLADNE NAVOD - TATO UTILITA MA VELKOU SCHOPNOST MAZAT A JE NUTNE JI APLIKOVAT JEN NA DOPORUCENI, JINAK VAM MUZE JIT SYSTEM DO KYTEK
:arrow: Stahnete a ulozte na plochu Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete vsechny rezidentni bezpecnostní programy - firewally, antiviry, antispywary apod.
  • Pokud mate Win XP spustte pod uctem Spravce\Administratora
  • Pokud mate Win Vista ci Win 7, kliknete na Combofix pravym a dejte Run As Administrator ci Spustit jako spravce
  • Ihned po startu se zobrazi stranka s licencnim ujednanim, pokracujte kliknutim na Ano
  • Pokud Vam CF nabidne instalaci Konzoly pro zotaveni, tak souhlaste
  • Dale postupujte dle pokynu, behem scanu nechte PC naprosto v klidu - nespoustejte zadne aplikace a neklikejte do zobrazujiciho se okna
  • Scan by mel trvat cca 10 min, ale pokud bude PC hodne zaneseno, muze se cas prodlouzit
  • Po dokonceni skenu a pripadnem restartu CF zobrazi log, pripadne jej najdete zde C:\ComboFix.txt, jeho obsah sem vlozte
  • Detailni postup vc. obrazku mate zde http://www.bleepingcomputer.com/combofi ... t-combofix
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Regrio
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 05 čer 2012 20:30

Re: Kontrola logu

#10 Příspěvek od Regrio »

Log:

ComboFix 12-06-05.04 - Dasty 06.06.2012 14:12:06.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3070.2421 [GMT 2:00]
Spuštěný z: c:\documents and settings\Dasty\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\avisynth.dll
c:\windows\system32\devil.dll
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-06 do 2012-06-06 )))))))))))))))))))))))))))))))
.
.
2012-06-05 20:54 . 2012-03-06 23:03 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-06-05 20:54 . 2012-03-06 23:01 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-06-05 20:54 . 2012-03-06 23:02 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-06-05 20:54 . 2012-03-06 23:01 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-06-05 20:54 . 2012-03-06 23:03 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-06-05 20:54 . 2012-03-06 23:01 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-06-05 20:54 . 2012-03-06 23:01 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-06-05 20:54 . 2012-03-06 22:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-06-05 20:54 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-06-05 20:54 . 2012-03-06 23:15 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-05 20:54 . 2012-06-05 20:54 -------- d-----w- c:\program files\AVAST Software
2012-06-05 20:54 . 2012-06-05 20:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-06-05 20:47 . 2012-06-05 20:47 -------- d-----w- c:\program files\CCleaner
2012-06-05 19:24 . 2012-06-05 19:25 -------- d-----w- C:\rsit
2012-06-05 19:24 . 2012-06-05 19:25 -------- d-----w- c:\program files\trend micro
2012-06-05 16:17 . 2012-06-05 16:17 -------- d-----w- C:\Rbackup
2012-06-05 16:02 . 2012-06-06 11:39 -------- d-----w- c:\program files\Perfect Uninstaller
2012-06-05 15:24 . 2012-06-05 15:27 -------- d-----w- c:\documents and settings\Dasty\Local Settings\Data aplikací\Opera
2012-06-05 15:24 . 2012-06-05 15:28 -------- d-----w- c:\program files\Opera
2012-06-05 12:35 . 2012-06-05 12:35 -------- d-----w- c:\program files\Dropbox
2012-06-05 12:27 . 2012-06-05 12:27 140356 ----a-w- c:\documents and settings\All Users\Data aplikací\1338899108.bdinstall.bin
2012-06-04 20:15 . 2012-06-04 20:15 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-04 20:15 . 2012-06-04 20:15 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-03 16:00 . 2012-06-03 16:00 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\QuickScan
2012-06-02 13:16 . 2012-06-02 13:16 -------- d-sh--w- c:\documents and settings\UpdatusUser.MYPC.001\IETldCache
2012-06-02 13:15 . 2012-06-02 13:15 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2012-06-02 13:12 . 2012-06-02 13:12 875179 ----a-w- c:\documents and settings\All Users\Data aplikací\1338639302.bdinstall.bin
2012-06-02 13:10 . 2012-06-02 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BDLogging
2012-06-02 13:09 . 2008-11-07 16:55 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2012-06-02 12:26 . 2012-06-02 12:26 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\QuickScan
2012-06-01 23:29 . 2012-06-01 23:29 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-06-01 09:52 . 2012-06-01 09:52 -------- d-sh--w- c:\documents and settings\Dasty\IETldCache
2012-06-01 00:41 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-06-01 00:41 . 2012-03-02 03:59 11082752 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-06-01 00:41 . 2012-03-01 10:59 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-06-01 00:41 . 2012-03-01 10:59 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-06-01 00:41 . 2012-03-01 10:59 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-06-01 00:41 . 2012-03-01 10:59 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-06-01 00:41 . 2012-03-01 10:59 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-06-01 00:41 . 2012-03-01 10:59 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-06-01 00:39 . 2012-06-01 00:41 -------- dc-h--w- c:\windows\ie8
2012-06-01 00:26 . 2012-06-01 00:26 -------- d-s---w- c:\documents and settings\Dasty\UserData
2012-05-28 20:48 . 2012-05-28 21:50 -------- d-----w- c:\windows\system32\NtmsData
2012-05-28 20:15 . 2012-06-05 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avira
2012-05-28 19:45 . 2012-05-28 19:58 -------- d-----w- c:\program files\Common Files\TrustPort
2012-05-28 12:23 . 2012-05-28 12:23 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\SUPERAntiSpyware.com
2012-05-28 12:22 . 2012-06-05 18:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-05-28 12:22 . 2012-05-28 12:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2012-05-28 12:22 . 2012-05-28 12:22 -------- d-----w- C:\keygen
2012-05-28 11:33 . 2012-05-28 12:04 -------- d-----w- c:\program files\PC Tools Security
2012-05-28 10:55 . 2012-05-28 10:55 -------- d-----w- c:\program files\ESET
2012-05-28 10:37 . 2011-05-20 09:44 149456 ----a-w- c:\windows\SGDetectionTool.dll0541.old
2012-05-28 10:37 . 2011-05-20 09:44 2078672 ----a-w- c:\windows\PCTBDCore.dll0541.old
2012-05-28 10:37 . 2011-05-20 09:44 767952 ----a-w- c:\windows\BDTSupport.dll0541.old
2012-05-28 10:29 . 2012-05-28 12:04 -------- d-----w- c:\program files\Common Files\PC Tools
2012-05-28 10:29 . 2012-05-28 12:01 -------- d---a-w- c:\documents and settings\All Users\Data aplikací\TEMP
2012-05-26 08:27 . 2012-05-26 08:27 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\IObit
2012-05-25 23:18 . 2012-05-26 10:25 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\DarknessII
2012-05-25 13:50 . 2012-05-25 13:50 84657 ----a-w- c:\documents and settings\All Users\Data aplikací\1337953786.bdinstall.bin
2012-05-25 13:50 . 2012-06-05 12:28 -------- d-----w- c:\program files\Bitdefender
2012-05-25 13:50 . 2012-06-05 12:26 -------- d-----w- c:\program files\Common Files\Bitdefender
2012-05-25 13:37 . 2012-05-25 13:37 -------- d-----w- c:\windows\system32\winrm
2012-05-25 13:37 . 2012-05-25 13:37 -------- d-----w- c:\windows\system32\GroupPolicy
2012-05-25 13:37 . 2012-05-25 13:37 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2012-05-25 13:02 . 2012-05-25 13:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\IObit
2012-05-25 08:50 . 2012-06-05 16:53 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\IObit
2012-05-25 08:50 . 2012-06-05 16:53 -------- d-----w- c:\program files\IObit
2012-05-15 13:13 . 2012-05-15 14:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Blizzard Entertainment
2012-05-13 11:52 . 2009-10-06 13:12 823936 ----a-w- c:\windows\system32\drivers\rtl8185.sys
2012-05-13 11:52 . 2006-11-15 14:23 38144 ----a-r- c:\windows\system32\drivers\EAPPkt.sys
2012-05-13 11:52 . 2002-10-02 07:57 13532 ----a-w- c:\windows\system32\drivers\SjyPkt.sys
2012-05-13 11:52 . 2012-05-13 11:52 -------- d-----w- c:\program files\ZyXEL
2012-05-07 22:45 . 2012-05-07 22:45 -------- d-----w- c:\documents and settings\Dasty\KBang
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-06 11:39 . 2011-03-03 19:44 16608 ----a-w- c:\windows\gdrv.sys
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-15 10:18 . 2011-10-17 14:01 883008 ----a-w- c:\windows\system32\nvgenco32.dll
2012-05-15 10:18 . 2011-10-17 14:01 1000768 ----a-w- c:\windows\system32\nvdispco32.dll
2012-05-15 10:18 . 2011-03-04 19:06 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:18 . 2011-03-04 19:06 6012928 ----a-w- c:\windows\system32\nvcuda.dll
2012-05-15 10:18 . 2011-03-04 19:06 2530624 ----a-w- c:\windows\system32\nvcuvid.dll
2012-05-15 10:18 . 2011-03-04 19:06 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-05-15 10:18 . 2011-03-04 19:06 18771968 ----a-w- c:\windows\system32\nvoglnt.dll
2012-05-15 10:18 . 2011-03-04 19:06 2359808 ----a-w- c:\windows\system32\nvapi.dll
2012-05-15 10:18 . 2011-03-04 19:06 17543168 ----a-w- c:\windows\system32\nvcompiler.dll
2012-05-15 10:18 . 2008-06-25 19:57 4373248 ----a-w- c:\windows\system32\nv4_disp.dll
2012-05-15 10:18 . 2008-06-25 19:57 14014656 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-05-15 09:40 . 2011-11-04 14:31 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-05-15 09:40 . 2011-11-04 14:31 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-05-15 09:40 . 2011-11-04 14:31 15504192 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-15 09:40 . 2011-11-04 14:31 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-05-15 09:40 . 2011-11-04 14:31 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-14 19:42 . 2011-03-12 15:20 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-05-14 19:42 . 2011-03-12 15:34 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-05-14 19:42 . 2011-03-12 15:20 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-05-14 19:42 . 2011-03-12 15:20 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-05-05 13:28 . 2012-04-14 10:27 4140192 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-04-11 13:55 . 2008-04-14 08:06 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 13:55 . 2008-04-14 12:00 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 13:55 . 2008-04-14 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-25 11:31 . 2011-12-01 19:12 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-27 16875008]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
"iTunesHelper"="c:\program files\itunes\ituneshelper.exe" [2012-03-27 421736]
"UnlockerAssistant"="c:\program files\unlocker\unlockerassistant.exe" [2010-07-04 17408]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Dasty\Nabídka Start\Programy\Po spuštění\
Dropbox.lnk - c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
GamePark klient 2.lnk - c:\program files\GamePark2\gpcl.exe [2012-5-2 409088]
ZyXEL G-302 v3 Utility.lnk - c:\program files\ZyXEL\G-302v3\G-302v3.exe [2012-5-13 1609216]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ------w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-01-20 09:20 1305408 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2012-06-05 18:19 3905920 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" -autorun
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"GEST"==
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.976\\Agent.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.998\\Agent.exe"=
"e:\\Games\\Diablo III\\Diablo III.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"57204:TCP"= 57204:TCP:Pando Media Booster
"57204:UDP"= 57204:UDP:Pando Media Booster
"6911:TCP"= 6911:TCP:League of Legends Launcher
"6911:UDP"= 6911:UDP:League of Legends Launcher
"6930:TCP"= 6930:TCP:League of Legends Launcher
"6930:UDP"= 6930:UDP:League of Legends Launcher
"6944:TCP"= 6944:TCP:League of Legends Launcher
"6944:UDP"= 6944:UDP:League of Legends Launcher
"6993:TCP"= 6993:TCP:League of Legends Launcher
"6993:UDP"= 6993:UDP:League of Legends Launcher
"8397:TCP"= 8397:TCP:League of Legends Launcher
"8397:UDP"= 8397:UDP:League of Legends Launcher
"6977:TCP"= 6977:TCP:League of Legends Launcher
"6977:UDP"= 6977:UDP:League of Legends Launcher
"6920:TCP"= 6920:TCP:League of Legends Launcher
"6920:UDP"= 6920:UDP:League of Legends Launcher
"6893:TCP"= 6893:TCP:League of Legends Launcher
"6893:UDP"= 6893:UDP:League of Legends Launcher
"6937:TCP"= 6937:TCP:League of Legends Launcher
"6937:UDP"= 6937:UDP:League of Legends Launcher
"6973:TCP"= 6973:TCP:League of Legends Launcher
"6973:UDP"= 6973:UDP:League of Legends Launcher
"8398:TCP"= 8398:TCP:League of Legends Launcher
"8398:UDP"= 8398:UDP:League of Legends Launcher
"8393:TCP"= 8393:TCP:League of Legends Lobby
"8393:UDP"= 8393:UDP:League of Legends Lobby
"8390:TCP"= 8390:TCP:League of Legends Game Client
"8390:UDP"= 8390:UDP:League of Legends Game Client
"5985:TCP"= 5985:TCP:*:Disabled:Vzdálená správa systému Windows
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [5.6.2012 22:54 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5.6.2012 22:54 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [4.3.2011 17:11 218688]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.6.2012 22:54 20696]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [13.5.2012 13:52 38144]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [3.3.2011 21:45 80392]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [3.3.2011 21:56 10384]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [7.12.2011 1:56 1262400]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6.7.2011 19:45 436792]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5.6.2012 22:54 136176]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;"d:\games\Global Agenda\HiPatchService.exe" --> d:\games\Global Agenda\HiPatchService.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4.6.2012 22:15 257696]
S3 cpuz134;cpuz134;\??\c:\docume~1\Dasty\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\Dasty\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5.6.2012 22:54 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12.6.2011 11:15 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25.4.2012 13:31 129976]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 21:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.4.2008 14:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - ASWSNX
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Obsah adresáře 'Naplánované úlohy'
.
2012-06-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-04 20:15]
.
2012-05-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2012-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-06-05 20:54]
.
2012-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-06-05 20:54]
.
2012-06-05 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task b058fe08-77b7-4a89-a76d-2c759e31ba2e.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 89.190.64.20 89.190.65.200
FF - ProfilePath - c:\documents and settings\Dasty\Data aplikací\Mozilla\Firefox\Profiles\uwk8cm9f.default\
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-06 14:15
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-117609710-1390067357-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:bd,77,d0,d7,db,eb,6d,b3,dd,92,08,82,4d,b3,ea,c2,94,74,20,17,92,52,6b,
ce,c1,a4,a7,9f,f0,2f,00,15,d2,4f,56,ac,4e,1a,76,09,67,e2,4f,f8,1b,c7,00,46,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
[HKEY_USERS\S-1-5-21-117609710-1390067357-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:17,ab,ed,a2,2c,7c,17,f7,b0,13,03,f7,85,9f,c6,df,78,2e,f8,fd,06,
7f,47,07,33,ed,fc,f1,b5,9c,8e,22,bb,66,e1,b8,52,56,72,c1,9d,35,88,5c,4f,81,\
"rkeysecu"=hex:0e,7c,46,58,c1,d9,06,d6,50,52,68,80,1c,d2,83,a9
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1192)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Celkový čas: 2012-06-06 14:16:30
ComboFix-quarantined-files.txt 2012-06-06 12:16
.
Před spuštěním: Volných bajtů: 97 961 455 616
Po spuštění: Volných bajtů: 98 530 140 160
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 0C0ED0E4018590AF245691BA0C7E4E86

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#11 Příspěvek od vyosek »

:arrow: Nasledujici soubory otestujte na VirusTotalu https://www.virustotal.com/cs/
  • c:\documents and settings\All Users\Data aplikací\1337953786.bdinstall.bin
    c:\documents and settings\All Users\Data aplikací\1338899108.bdinstall.bin
  • Kliknete na Choose file
  • Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
  • Kliknete na Scan It
  • Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse
    Obrázek
  • Vysledek analyzy sem vlozte (jako odkaz)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.


Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#13 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    RegNull::
    [HKEY_USERS\S-1-5-21-117609710-1390067357-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    [HKEY_USERS\S-1-5-21-117609710-1390067357-1801674531-1004\Software\SecuROM\License information*]
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Dasty\Data aplikací\Mozilla\Firefox\Profiles\uwk8cm9f.default\
    FF - user.js: browser.cache.memory.capacity - 65536
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.chrome.favicons - false
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.urlbar.autofill - true
    FF - user.js: browser.xul.error_pages.enabled - true
    FF - user.js: content.interrupt.parsing - true
    FF - user.js: content.max.tokenizing.time - 3000000
    FF - user.js: content.maxtextrun - 8191
    FF - user.js: content.notify.backoffcount - 5
    FF - user.js: content.notify.interval - 750000
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.switch.threshold - 750000
    FF - user.js: network.http.max-connections - 32
    FF - user.js: network.http.max-connections-per-server - 8
    FF - user.js: network.http.max-persistent-connections-per-proxy - 8
    FF - user.js: network.http.max-persistent-connections-per-server - 4
    FF - user.js: network.http.pipelining - true
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.proxy.pipelining - true
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: nglayout.initialpaint.delay - 0
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    
    Driver::
    gupdate
    AdvancedSystemCareService5
    gupdatem
    
    Registry::
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5985:TCP"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    
    Folder::
    c:\documents and settings\All Users\Data aplikací\Avira
    C:\keygen
    c:\program files\PC Tools Security
    c:\program files\ESET
    c:\documents and settings\All Users\Data aplikací\IObit
    c:\documents and settings\Dasty\Data aplikací\IObit
    c:\program files\IObit
    C:\Program Files\AVG
    
    File::
    C:\WINDOWS\tasks\Adobe Flash Player Updater.job
    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\ASC5_AutoUpdate.job
    C:\WINDOWS\tasks\SmartDefrag_Startup.job
    C:\WINDOWS\tasks\SUPERAntiSpyware Scheduled Task b058fe08-77b7-4a89-a76d-2c759e31ba2e.job
    
    SecCenter::
    {8decf618-9569-4340-b34a-d78d28969b66}
    FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Regrio
Návštěvník
Návštěvník
Příspěvky: 16
Registrován: 05 čer 2012 20:30

Re: Kontrola logu

#14 Příspěvek od Regrio »

Log:

ComboFix 12-06-05.04 - Dasty 07.06.2012 17:31:22.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.3070.2355 [GMT 2:00]
Spuštěný z: c:\documents and settings\Dasty\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Dasty\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\windows\tasks\Adobe Flash Player Updater.job"
"c:\windows\tasks\AppleSoftwareUpdate.job"
"c:\windows\tasks\ASC5_AutoUpdate.job"
"c:\windows\tasks\SmartDefrag_Startup.job"
"c:\windows\tasks\SUPERAntiSpyware Scheduled Task b058fe08-77b7-4a89-a76d-2c759e31ba2e.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\keygen
c:\program files\AVG
c:\program files\ESET
c:\program files\IObit
c:\program files\IObit\Advanced SystemCare 3\AWC.exe.bak
c:\program files\IObit\Advanced SystemCare 3\free-software-downloader.exe
c:\program files\IObit\Advanced SystemCare 3\License.dat
c:\program files\IObit\Advanced SystemCare 3\Registration.exe.bak
c:\program files\IObit\Advanced SystemCare 3\UpdateLog.txt
c:\program files\IObit\Smart Defrag 2\LatestNews\LatestNews.ini
c:\program files\PC Tools Security
c:\program files\PC Tools Security\BDT\BDTCloudCache.bin
c:\windows\tasks\Adobe Flash Player Updater.job
c:\windows\tasks\AppleSoftwareUpdate.job
c:\windows\tasks\SUPERAntiSpyware Scheduled Task b058fe08-77b7-4a89-a76d-2c759e31ba2e.job
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_GUPDATE
-------\Service_gupdate
-------\Service_gupdatem
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-05-07 do 2012-06-07 )))))))))))))))))))))))))))))))
.
.
2012-06-07 15:32 . 2012-06-07 15:32 -------- d-----w- c:\documents and settings\NetworkService\Data aplikací\Apple Computer
2012-06-07 12:03 . 2012-06-07 12:03 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2012-06-05 20:54 . 2012-03-06 23:03 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-06-05 20:54 . 2012-03-06 23:01 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-06-05 20:54 . 2012-03-06 23:02 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-06-05 20:54 . 2012-03-06 23:01 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-06-05 20:54 . 2012-03-06 23:03 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-06-05 20:54 . 2012-03-06 23:01 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-06-05 20:54 . 2012-03-06 23:01 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-06-05 20:54 . 2012-03-06 22:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-06-05 20:54 . 2012-03-06 23:15 41184 ----a-w- c:\windows\avastSS.scr
2012-06-05 20:54 . 2012-03-06 23:15 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-06-05 20:54 . 2012-06-05 20:54 -------- d-----w- c:\program files\AVAST Software
2012-06-05 20:54 . 2012-06-05 20:54 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-06-05 20:47 . 2012-06-05 20:47 -------- d-----w- c:\program files\CCleaner
2012-06-05 19:24 . 2012-06-05 19:25 -------- d-----w- C:\rsit
2012-06-05 19:24 . 2012-06-05 19:25 -------- d-----w- c:\program files\trend micro
2012-06-05 16:17 . 2012-06-05 16:17 -------- d-----w- C:\Rbackup
2012-06-05 16:02 . 2012-06-06 11:39 -------- d-----w- c:\program files\Perfect Uninstaller
2012-06-05 15:24 . 2012-06-05 15:27 -------- d-----w- c:\documents and settings\Dasty\Local Settings\Data aplikací\Opera
2012-06-05 15:24 . 2012-06-05 15:28 -------- d-----w- c:\program files\Opera
2012-06-05 12:35 . 2012-06-05 12:35 -------- d-----w- c:\program files\Dropbox
2012-06-05 12:27 . 2012-06-05 12:27 140356 ----a-w- c:\documents and settings\All Users\Data aplikací\1338899108.bdinstall.bin
2012-06-04 20:15 . 2012-06-04 20:15 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-04 20:15 . 2012-06-04 20:15 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-03 16:00 . 2012-06-03 16:00 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\QuickScan
2012-06-02 13:16 . 2012-06-02 13:16 -------- d-sh--w- c:\documents and settings\UpdatusUser.MYPC.001\IETldCache
2012-06-02 13:15 . 2012-06-02 13:15 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2012-06-02 13:12 . 2012-06-02 13:12 875179 ----a-w- c:\documents and settings\All Users\Data aplikací\1338639302.bdinstall.bin
2012-06-02 13:10 . 2012-06-02 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\BDLogging
2012-06-02 13:09 . 2008-11-07 16:55 16928 ------w- c:\windows\system32\spmsgXP_2k3.dll
2012-06-02 12:26 . 2012-06-02 12:26 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\QuickScan
2012-06-01 23:29 . 2012-06-01 23:29 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-06-01 09:52 . 2012-06-01 09:52 -------- d-sh--w- c:\documents and settings\Dasty\IETldCache
2012-06-01 00:41 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-06-01 00:41 . 2012-03-02 03:59 11082752 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-06-01 00:41 . 2012-03-01 10:59 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-06-01 00:41 . 2012-03-01 10:59 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-06-01 00:41 . 2012-03-01 10:59 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-06-01 00:41 . 2012-03-01 10:59 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-06-01 00:41 . 2012-03-01 10:59 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-06-01 00:41 . 2012-03-01 10:59 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-06-01 00:39 . 2012-06-01 00:41 -------- dc-h--w- c:\windows\ie8
2012-06-01 00:26 . 2012-06-01 00:26 -------- d-s---w- c:\documents and settings\Dasty\UserData
2012-05-28 20:48 . 2012-05-28 21:50 -------- d-----w- c:\windows\system32\NtmsData
2012-05-28 20:15 . 2012-06-05 13:10 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Avira
2012-05-28 19:45 . 2012-05-28 19:58 -------- d-----w- c:\program files\Common Files\TrustPort
2012-05-28 12:23 . 2012-05-28 12:23 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\SUPERAntiSpyware.com
2012-05-28 12:22 . 2012-06-05 18:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-05-28 12:22 . 2012-05-28 12:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2012-05-28 10:37 . 2011-05-20 09:44 149456 ----a-w- c:\windows\SGDetectionTool.dll0541.old
2012-05-28 10:37 . 2011-05-20 09:44 2078672 ----a-w- c:\windows\PCTBDCore.dll0541.old
2012-05-28 10:37 . 2011-05-20 09:44 767952 ----a-w- c:\windows\BDTSupport.dll0541.old
2012-05-28 10:29 . 2012-05-28 12:04 -------- d-----w- c:\program files\Common Files\PC Tools
2012-05-28 10:29 . 2012-05-28 12:01 -------- d---a-w- c:\documents and settings\All Users\Data aplikací\TEMP
2012-05-26 08:27 . 2012-05-26 08:27 -------- d-----w- c:\windows\system32\config\systemprofile\Data aplikací\IObit
2012-05-25 23:18 . 2012-05-26 10:25 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\DarknessII
2012-05-25 13:50 . 2012-05-25 13:50 84657 ----a-w- c:\documents and settings\All Users\Data aplikací\1337953786.bdinstall.bin
2012-05-25 13:50 . 2012-06-05 12:28 -------- d-----w- c:\program files\Bitdefender
2012-05-25 13:50 . 2012-06-05 12:26 -------- d-----w- c:\program files\Common Files\Bitdefender
2012-05-25 13:37 . 2012-05-25 13:37 -------- d-----w- c:\windows\system32\winrm
2012-05-25 13:37 . 2012-05-25 13:37 -------- d-----w- c:\windows\system32\GroupPolicy
2012-05-25 13:37 . 2012-05-25 13:37 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
2012-05-25 13:02 . 2012-05-25 13:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\IObit
2012-05-25 08:50 . 2012-06-05 16:53 -------- d-----w- c:\documents and settings\Dasty\Data aplikací\IObit
2012-05-15 13:13 . 2012-05-15 14:02 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Blizzard Entertainment
2012-05-13 11:52 . 2009-10-06 13:12 823936 ----a-w- c:\windows\system32\drivers\rtl8185.sys
2012-05-13 11:52 . 2006-11-15 14:23 38144 ----a-r- c:\windows\system32\drivers\EAPPkt.sys
2012-05-13 11:52 . 2002-10-02 07:57 13532 ----a-w- c:\windows\system32\drivers\SjyPkt.sys
2012-05-13 11:52 . 2012-05-13 11:52 -------- d-----w- c:\program files\ZyXEL
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-07 15:38 . 2011-03-03 19:44 16608 ----a-w- c:\windows\gdrv.sys
2012-05-31 13:22 . 2008-04-14 12:00 602112 ----a-w- c:\windows\system32\crypt32.dll
2012-05-15 10:18 . 2011-10-17 14:01 883008 ----a-w- c:\windows\system32\nvgenco32.dll
2012-05-15 10:18 . 2011-10-17 14:01 1000768 ----a-w- c:\windows\system32\nvdispco32.dll
2012-05-15 10:18 . 2011-03-04 19:06 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-05-15 10:18 . 2011-03-04 19:06 6012928 ----a-w- c:\windows\system32\nvcuda.dll
2012-05-15 10:18 . 2011-03-04 19:06 2530624 ----a-w- c:\windows\system32\nvcuvid.dll
2012-05-15 10:18 . 2011-03-04 19:06 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-05-15 10:18 . 2011-03-04 19:06 18771968 ----a-w- c:\windows\system32\nvoglnt.dll
2012-05-15 10:18 . 2011-03-04 19:06 2359808 ----a-w- c:\windows\system32\nvapi.dll
2012-05-15 10:18 . 2011-03-04 19:06 17543168 ----a-w- c:\windows\system32\nvcompiler.dll
2012-05-15 10:18 . 2008-06-25 19:57 4373248 ----a-w- c:\windows\system32\nv4_disp.dll
2012-05-15 10:18 . 2008-06-25 19:57 14014656 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-05-15 09:40 . 2011-11-04 14:31 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-05-15 09:40 . 2011-11-04 14:31 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-05-15 09:40 . 2011-11-04 14:31 15504192 ----a-w- c:\windows\system32\nvcpl.dll
2012-05-15 09:40 . 2011-11-04 14:31 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-05-15 09:40 . 2011-11-04 14:31 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-05-14 19:42 . 2011-03-12 15:20 137464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-05-14 19:42 . 2011-03-12 15:34 214520 ----a-w- c:\windows\system32\PnkBstrB.xtr
2012-05-14 19:42 . 2011-03-12 15:20 214520 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-05-14 19:42 . 2011-03-12 15:20 214520 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-05-05 13:28 . 2012-04-14 10:27 4140192 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-04-11 13:55 . 2008-04-14 08:06 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 13:55 . 2008-04-14 12:00 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 13:55 . 2008-04-14 12:00 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-25 11:31 . 2011-12-01 19:12 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-06_12.15.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-06-07 15:38 . 2012-06-07 15:38 16384 c:\windows\temp\Perflib_Perfdata_2f4.dat
+ 2012-06-07 15:38 . 2012-06-07 15:38 16384 c:\windows\temp\Perflib_Perfdata_2d4.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-06 23:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"RTHDCPL"="RTHDCPL.EXE" [2008-06-27 16875008]
"SoundMan"="SOUNDMAN.EXE" [2008-06-18 77824]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 2808832]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-05-15 15504192]
"NvMediaCenter"="NvMCTray.dll" [2012-05-15 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-05-15 1634112]
"iTunesHelper"="c:\program files\itunes\ituneshelper.exe" [2012-03-27 421736]
"UnlockerAssistant"="c:\program files\unlocker\unlockerassistant.exe" [2010-07-04 17408]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Dasty\Nabídka Start\Programy\Po spuštění\
Dropbox.lnk - c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
GamePark klient 2.lnk - c:\program files\GamePark2\gpcl.exe [2012-5-2 409088]
ZyXEL G-302 v3 Utility.lnk - c:\program files\ZyXEL\G-302v3\G-302v3.exe [2012-5-13 1609216]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ------w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.976\\Agent.exe"=
"c:\\Documents and Settings\\All Users\\Data aplikací\\Battle.net\\Agent\\Agent.998\\Agent.exe"=
"e:\\Games\\Diablo III\\Diablo III.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8396:TCP"= 8396:TCP:League of Legends Launcher
"8396:UDP"= 8396:UDP:League of Legends Launcher
"57204:TCP"= 57204:TCP:Pando Media Booster
"57204:UDP"= 57204:UDP:Pando Media Booster
"6911:TCP"= 6911:TCP:League of Legends Launcher
"6911:UDP"= 6911:UDP:League of Legends Launcher
"6930:TCP"= 6930:TCP:League of Legends Launcher
"6930:UDP"= 6930:UDP:League of Legends Launcher
"6944:TCP"= 6944:TCP:League of Legends Launcher
"6944:UDP"= 6944:UDP:League of Legends Launcher
"6993:TCP"= 6993:TCP:League of Legends Launcher
"6993:UDP"= 6993:UDP:League of Legends Launcher
"8397:TCP"= 8397:TCP:League of Legends Launcher
"8397:UDP"= 8397:UDP:League of Legends Launcher
"6977:TCP"= 6977:TCP:League of Legends Launcher
"6977:UDP"= 6977:UDP:League of Legends Launcher
"6920:TCP"= 6920:TCP:League of Legends Launcher
"6920:UDP"= 6920:UDP:League of Legends Launcher
"6893:TCP"= 6893:TCP:League of Legends Launcher
"6893:UDP"= 6893:UDP:League of Legends Launcher
"6937:TCP"= 6937:TCP:League of Legends Launcher
"6937:UDP"= 6937:UDP:League of Legends Launcher
"6973:TCP"= 6973:TCP:League of Legends Launcher
"6973:UDP"= 6973:UDP:League of Legends Launcher
"8398:TCP"= 8398:TCP:League of Legends Launcher
"8398:UDP"= 8398:UDP:League of Legends Launcher
"8393:TCP"= 8393:TCP:League of Legends Lobby
"8393:UDP"= 8393:UDP:League of Legends Lobby
"8390:TCP"= 8390:TCP:League of Legends Game Client
"8390:UDP"= 8390:UDP:League of Legends Game Client
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [5.6.2012 22:54 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5.6.2012 22:54 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [4.3.2011 17:11 218688]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5.6.2012 22:54 20696]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [13.5.2012 13:52 38144]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [3.3.2011 21:45 80392]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [3.3.2011 21:56 10384]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [7.12.2011 1:56 1262400]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6.7.2011 19:45 436792]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;"d:\games\Global Agenda\HiPatchService.exe" --> d:\games\Global Agenda\HiPatchService.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4.6.2012 22:15 257696]
S3 cpuz134;cpuz134;\??\c:\docume~1\Dasty\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> c:\docume~1\Dasty\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [12.6.2011 11:15 31125880]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25.4.2012 13:31 129976]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9.1.2010 21:37 4640000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [14.4.2008 14:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Obsah adresáře 'Naplánované úlohy'
.
2012-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-06-05 20:54]
.
2012-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-06-05 20:54]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
mStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Od&eslat do aplikace OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 89.190.64.20 89.190.65.200
FF - ProfilePath - c:\documents and settings\Dasty\Data aplikací\Mozilla\Firefox\Profiles\uwk8cm9f.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-07 17:38
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1196)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
- - - - - - - > 'explorer.exe'(2744)
c:\documents and settings\Dasty\Data aplikací\Dropbox\bin\DropboxExt.14.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\SOUNDMAN.EXE
c:\windows\system32\RunDLL32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Celkový čas: 2012-06-07 17:41:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-06-07 15:40
ComboFix2.txt 2012-06-06 12:16
.
Před spuštěním: Volných bajtů: 118 465 757 184
Po spuštění: Volných bajtů: 118 337 355 776
.
- - End Of File - - B66DC03C7C7A73D83CE14BE8B65FD50D

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Kontrola logu

#15 Příspěvek od vyosek »

Jak se chova nas pacient :???:
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět