Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Kontrola logu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Kontrola logu

#1 Příspěvek od mejl »

Zdravím, prosím o kontrolu logu. PC byl zřejmě něčím napaden (není můj takže nevím co přesně se s ním stalo - dostal se ke mě až když se ani nespustil). Nejdřív nešel nespustit windows (hlásilo to chybu že je poškozený soubor hal.dll). Tento problém jsem vyřešil pomocí konzole pro zotavení a teď bych chtěl zjistit čím to mohlo být...zda nějaká havěť nebo co...posílám tedy log z RSIT...předem děkuji za pomoc ;)

Logfile of random's system information tool 1.09 (written by random/random)
Run by Fujitsu-Siemens at 2012-11-29 12:26:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 55 GB (23%) free of 238 GB
Total RAM: 2047 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:31:35, on 29.11.2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IB Updater\ExtensionUpdaterService.exe
C:\WINDOWS\system32\dmwu.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DAEMON Tools Lite\daemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Fujitsu-Siemens\Plocha\RSIT.exe
C:\Program Files\trend micro\Fujitsu-Siemens.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?affID=116775 ... 15830d5a06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.certified-toolbar.com?si= ... e&tid=2938
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.certified-toolbar.com?si= ... bs=true&q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
R3 - URLSearchHook: (no name) - {d3f4b70a-92e0-4393-a0f3-976d03b1ebf5} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: IB Updater Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll
O3 - Toolbar: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - (no file)
O3 - Toolbar: (no name) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - (no file)
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
O3 - Toolbar: (no name) - {d3f4b70a-92e0-4393-a0f3-976d03b1ebf5} - (no file)
O3 - Toolbar: Softonic Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\WINDOWS\TEMP\E_SBE.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ICQ] ~"C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - http://icq.oberon-media.com/Gameshell/G ... meHost.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate1c99d971f8ce15e) (gupdate1c99d971f8ce15e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IB Updater - Unknown owner - C:\Program Files\IB Updater\ExtensionUpdaterService.exe
O23 - Service: IBUpdaterService - Unknown owner - C:\WINDOWS\system32\dmwu.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe

--
End of file - 10131 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Protected Search.job
C:\WINDOWS\tasks\RMAutoUpdate.job
C:\WINDOWS\tasks\RMSchedule.job
C:\WINDOWS\tasks\YourFile Update.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}]
Babylon toolbar helper - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll [2011-08-14 270960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403a-B9D2-65C292C39087}]
IB Updater - C:\Program Files\IB Updater\Extension32.dll [2012-10-09 172376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-09-06 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-10-30 1227736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Softonic Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-09-06 157672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo - C:\Program Files\Yontoo\YontooIEClient.dll [2012-10-12 194928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D}
{9421DD08-935F-4701-A9CA-22DF90AC4EA6}
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-07-17 691656]
{EEE6C35B-6118-11DC-9C72-001320C79847}
{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5}
{D4027C7F-154A-4066-A1AD-4243D8127440} - Softonic Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2011-08-23 1515688]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll [2012-10-30 1227736]
{98889811-442D-49dd-99D7-DC866BE87DBC} - Babylon Toolbar - C:\Program Files\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll [2011-08-14 237680]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2004-08-02 4493312]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2004-08-02 86016]
"BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"RemoteControl8"=C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240]
"PDVD8LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472]
"BDRegion"=C:\Program Files\Cyberlink\Shared Files\brs.exe [2009-05-02 91432]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2012-07-03 252848]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
""= []
"avast"=C:\Program Files\Alwil Software\Avast5\avastUI.exe [2012-10-30 4297136]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"EPSON SX100 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE [2008-02-05 188928]
"DAEMON Tools Lite"=C:\DAEMON Tools Lite\daemon.exe [2008-07-24 490952]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2006-02-10 2048000]
"ICQ"=~C:\Program Files\ICQ7.5\ICQ.exe silent loginmode=4 []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Documents and Settings\Fujitsu-Siemens\Dokumenty\ICQ6.5\ICQ.exe"="C:\Documents and Settings\Fujitsu-Siemens\Dokumenty\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
"C:\hry\far cry\Bin32\FarCry.exe"="C:\hry\far cry\Bin32\FarCry.exe:*:Enabled:Far Cry"
"C:\torrent\uTorrent.exe"="C:\torrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Vietcong\vietcong.exe"="C:\Program Files\Vietcong\vietcong.exe:*:Enabled:vietcong"
"C:\hry\wolfchanze\Wolfschanze\Wolfschanze.exe"="C:\hry\wolfchanze\Wolfschanze\Wolfschanze.exe:*:Enabled:Wolfschanze 1944"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe"="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Subagames\Metin2\metin2.bin"="C:\Program Files\Subagames\Metin2\metin2.bin:*:Enabled:metin2"
"C:\Program Files\EA GAMES\Medal of Honor Pacific Assault(tm) Demo\mohpa_demo.exe"="C:\Program Files\EA GAMES\Medal of Honor Pacific Assault(tm) Demo\mohpa_demo.exe:*:Disabled:Medal of Honor Pacific Assault(tm)"
"C:\Documents and Settings\Fujitsu-Siemens\Plocha\Ares.exe"="C:\Documents and Settings\Fujitsu-Siemens\Plocha\Ares.exe:*:Disabled:Ares p2p for windows"
"C:\Program Files\EA GAMES\MOHAA\MOHAA.exe"="C:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Disabled:Medal of Honor Allied Assault"
"C:\Program Files\fishsim2\fsserv.exe"="C:\Program Files\fishsim2\fsserv.exe:*:Disabled:fsserv"
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"="C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe:*:Disabled:CoD2MP_s"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Empire of Sports\NetworkDiagnostic.exe"="C:\Program Files\Empire of Sports\NetworkDiagnostic.exe:*:Enabled:Empire of Sports Network Diagnostic"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa.exe"="C:\Program Files\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa.exe:*:Enabled:Medal of Honor Pacific Assault(tm)"
"C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\PowerChallenge\PowerSoccer\PowerSoccer.exe"="C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\PowerChallenge\PowerSoccer\PowerSoccer.exe:*:Enabled:PowerSoccer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Fujitsu-Siemens\Dokumenty\Downloads\facebook-pic000934519.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Program Files\Counter-Strike 1.6\hl.exe"="C:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"C:\Program Files\Metin2\metin2client.bin"="C:\Program Files\Metin2\metin2client.bin:*:Enabled:Metin2Client"
"C:\Program Files\MotoGP2\motogp2.exe"="C:\Program Files\MotoGP2\motogp2.exe:*:Disabled:motogp2"
"C:\WINDOWS\system32\dmwu.exe"="C:\WINDOWS\system32\dmwu.exe:*:Enabled:dmwu"
"C:\WINDOWS\system32\ARFC\wrtc.exe"="C:\WINDOWS\system32\ARFC\wrtc.exe:*:Enabled:wrtc"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Capcom\MotoGP 08\Launcher.exe"="C:\Program Files\Capcom\MotoGP 08\Launcher.exe:*:Enabled:MotoGP 08"
"C:\Program Files\Capcom\MotoGP 08 Demo\MotoGP 08\Launcher.exe"="C:\Program Files\Capcom\MotoGP 08 Demo\MotoGP 08\Launcher.exe:*:Enabled:MotoGP 08"
"C:\Program Files\YourFileDownloader\Downloader.exe"="C:\Program Files\YourFileDownloader\Downloader.exe:*:Enabled:YourFile Downloader"
"C:\Program Files\YourFileDownloader\YourFile.exe"="C:\Program Files\YourFileDownloader\YourFile.exe:*:Enabled:YourFile Downloader"
"C:\Program Files\THQ\MotoGP URT 3 Demo\motogp_demo.exe"="C:\Program Files\THQ\MotoGP URT 3 Demo\motogp_demo.exe:*:Enabled:motogp_demo"
"C:\Program Files\THQ\MotoGP URT 3\motogp.exe"="C:\Program Files\THQ\MotoGP URT 3\motogp.exe:*:Enabled:motogp"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe"="C:\Program Files\CyberLink\PowerDVD8\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux3"=wdmaud.drv
"VIDC.MPG4"=mpg4c32.dll
"VIDC.MP42"=mpg4c32.dll

======List of files/folders created in the last 3 months======

2012-11-29 12:26:33 ----D---- C:\Program Files\trend micro
2012-11-29 12:26:32 ----D---- C:\rsit
2012-11-29 12:22:27 ----A---- C:\WINDOWS\OEWABLog.txt
2012-11-29 12:16:28 ----D---- C:\WINDOWS\Prefetch
2012-11-29 12:05:06 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2012-11-29 12:04:38 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2012-11-29 12:04:14 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2012-11-29 12:03:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980182$
2012-11-29 12:03:02 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2012-11-29 12:02:23 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2012-11-29 12:01:55 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2012-11-29 12:01:34 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2012-11-29 12:01:09 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2012-11-29 12:00:45 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2012-11-29 12:00:19 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2012-11-29 11:59:46 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2012-11-29 11:58:56 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2012-11-29 11:57:51 ----HDC---- C:\WINDOWS\$NtUninstallKB978207$
2012-11-29 11:57:34 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2012-11-29 11:57:17 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2012-11-29 11:56:42 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2012-11-29 11:56:24 ----HDC---- C:\WINDOWS\$NtUninstallKB976749$
2012-11-29 11:56:07 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2012-11-29 11:55:47 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2012-11-29 11:55:24 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2012-11-29 11:55:06 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2012-11-29 11:54:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2012-11-29 11:54:28 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2012-11-29 11:54:08 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2012-11-29 11:53:50 ----HDC---- C:\WINDOWS\$NtUninstallKB974455$
2012-11-29 11:53:31 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2012-11-29 11:53:13 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2012-11-29 11:52:53 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2012-11-29 11:52:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2012-11-29 11:52:13 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2012-11-29 11:51:54 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2012-11-29 11:51:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2012-11-29 11:51:15 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2012-11-29 11:50:55 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2012-11-29 11:50:40 ----HDC---- C:\WINDOWS\$NtUninstallKB972260$
2012-11-29 11:50:19 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2012-11-29 11:50:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2012-11-29 11:49:42 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2012-11-29 11:49:24 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2012-11-29 11:48:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2012-11-29 11:48:36 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2012-11-29 11:48:18 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2012-11-29 11:47:57 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2012-11-29 11:47:38 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2012-11-29 11:47:18 ----HDC---- C:\WINDOWS\$NtUninstallKB969897$
2012-11-29 11:46:58 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2012-11-29 11:46:38 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2012-11-29 11:46:17 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2012-11-29 11:45:43 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2012-11-29 11:45:04 ----HDC---- C:\WINDOWS\$NtUninstallKB982381_1$
2012-11-29 11:44:38 ----HDC---- C:\WINDOWS\$NtUninstallKB963027$
2012-11-29 11:44:21 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2012-11-29 11:44:02 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2012-11-29 11:43:45 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2012-11-29 11:42:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2012-11-29 11:42:40 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2012-11-29 11:42:21 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2012-11-29 11:41:56 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2012-11-29 11:41:38 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2012-11-29 11:41:19 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2012-11-29 11:41:01 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2012-11-29 11:40:44 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2012-11-29 11:40:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2012-11-29 11:40:00 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2012-11-29 11:39:42 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2012-11-29 11:39:25 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2012-11-29 11:39:09 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2012-11-29 11:38:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2012-11-29 11:38:34 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2012-11-29 11:37:57 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2012-11-29 11:37:33 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2012-11-29 11:37:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973687_1$
2012-11-29 11:36:51 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2012-11-29 11:36:35 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2012-11-29 11:36:05 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2012-11-29 11:35:37 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2012-11-29 11:35:01 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2012-11-29 11:34:16 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2012-11-29 11:33:30 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2012-11-29 11:31:53 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2012-11-29 11:30:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2012-11-29 11:30:02 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2012-11-29 11:29:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2012-11-29 11:29:04 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2012-11-29 11:28:30 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2012-11-29 11:27:50 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2012-11-29 11:26:46 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2012-11-29 11:25:08 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2012-11-29 11:24:11 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2012-11-29 11:23:37 ----D---- C:\WINDOWS\LastGood.Tmp
2012-11-29 11:15:02 ----A---- C:\WINDOWS\setuplog.txt
2012-11-29 11:12:48 ----D---- C:\WINDOWS\system32\cs
2012-11-29 11:12:48 ----D---- C:\WINDOWS\l2schemas
2012-11-29 11:12:47 ----D---- C:\WINDOWS\system32\bits
2012-11-29 10:58:29 ----D---- C:\WINDOWS\network diagnostic
2012-11-29 10:54:50 ----D---- C:\Program Files\CCleaner
2012-11-29 10:46:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2012-11-29 10:38:24 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2012-11-29 10:38:18 ----D---- C:\WINDOWS\EHome
2012-11-19 05:23:26 ----SHD---- C:\found.003
2012-11-19 04:32:56 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2012-11-19 04:32:09 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys
2012-11-19 04:30:51 ----ASH---- C:\pagefile.sys
2012-11-16 18:37:49 ----ASH---- C:\BOOT.BAK
2012-11-16 18:33:12 ----A---- C:\WINDOWS\UPGRADE.TXT
2012-11-16 18:33:06 ----D---- C:\WINDOWS\setup.pss
2012-11-16 15:40:33 ----A---- C:\WINDOWS\system32\unrar.dll
2012-11-16 15:40:21 ----D---- C:\Program Files\K-Lite Codec Pack
2012-11-15 06:47:18 ----SHD---- C:\found.002
2012-11-12 19:21:14 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2012-10-29 12:17:01 ----RHD---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\SecuROM
2012-10-26 13:19:36 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\YourFileDownloader
2012-10-25 21:43:52 ----D---- C:\Program Files\Yontoo
2012-10-25 21:43:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Tarma Installer
2012-10-25 21:43:32 ----D---- C:\Program Files\OnlineHD.TV
2012-10-25 20:39:12 ----D---- C:\Program Files\GotClip
2012-10-25 15:07:15 ----SHD---- C:\found.001
2012-10-20 21:26:59 ----D---- C:\Program Files\Vietcong
2012-10-20 11:56:47 ----A---- C:\WINDOWS\Launcher.exe
2012-10-20 11:56:46 ----D---- C:\Program Files\Protected Search
2012-10-20 11:54:14 ----D---- C:\Program Files\Red Sky
2012-10-14 13:11:36 ----D---- C:\Program Files\MSECache
2012-10-14 13:10:01 ----D---- C:\Program Files\DzSoft
2012-10-11 20:17:01 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\PhotoScape
2012-10-11 20:12:25 ----D---- C:\Program Files\PhotoScape
2012-10-11 20:10:14 ----D---- C:\Program Files\FilesFrog Update Checker
2012-10-11 20:09:53 ----D---- C:\WINDOWS\system32\ARFC
2012-10-11 20:09:53 ----A---- C:\WINDOWS\system32\msvcr100.dll
2012-10-11 20:09:53 ----A---- C:\WINDOWS\system32\msvcp100.dll
2012-10-11 20:09:53 ----A---- C:\WINDOWS\system32\ImHttpComm.dll
2012-10-11 20:09:53 ----A---- C:\WINDOWS\system32\dmwu.exe
2012-10-11 20:09:42 ----D---- C:\WINDOWS\system32\WNLT
2012-10-11 20:09:30 ----D---- C:\Program Files\IB Updater
2012-10-11 14:06:40 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Milestone
2012-10-11 13:30:04 ----D---- C:\Program Files\Milestone
2012-10-08 11:22:31 ----D---- C:\Program Files\Break For Games
2012-10-03 10:15:13 ----D---- C:\Program Files\PartyGaming
2012-09-30 08:18:45 ----SHD---- C:\found.000
2012-09-17 17:54:03 ----D---- C:\Program Files\GOG.com
2012-09-16 20:27:17 ----D---- C:\Program Files\MotoGP2
2012-09-16 18:55:36 ----A---- C:\WINDOWS\system32\msvcr90.dll
2012-09-16 18:55:36 ----A---- C:\WINDOWS\system32\msvcr80d.dll
2012-09-16 18:55:36 ----A---- C:\WINDOWS\system32\msvcr80.dll
2012-09-16 18:55:36 ----A---- C:\WINDOWS\system32\msvcr70.dll
2012-09-16 18:55:36 ----A---- C:\WINDOWS\system32\msvcp90.dll
2012-09-16 18:55:36 ----A---- C:\WINDOWS\system32\dwmapi.dll
2012-09-16 18:55:35 ----A---- C:\WINDOWS\system32\msvcp80.dll
2012-09-16 18:55:35 ----A---- C:\WINDOWS\system32\msvcp70.dll
2012-09-16 18:55:35 ----A---- C:\WINDOWS\system32\msvcm90.dll
2012-09-16 18:55:33 ----A---- C:\WINDOWS\system32\Vista.Emulation.dll
2012-09-16 18:55:33 ----A---- C:\WINDOWS\system32\nvapi.dll
2012-09-16 18:55:33 ----A---- C:\WINDOWS\system32\msvcm80.dll
2012-09-16 18:55:33 ----A---- C:\WINDOWS\system32\msjava.dll
2012-09-16 18:55:33 ----A---- C:\WINDOWS\system32\M2000Twn.dll
2012-09-16 18:55:26 ----A---- C:\WINDOWS\system32\D3DX10d_39.dll
2012-09-16 18:55:25 ----A---- C:\WINDOWS\system32\d3dx10.dll
2012-09-16 18:55:25 ----A---- C:\WINDOWS\system32\D3D10SDKLayers.DLL
2012-09-16 18:55:25 ----A---- C:\WINDOWS\system32\d2d1.dll
2012-09-16 18:55:25 ----A---- C:\WINDOWS\system32\CompressATI2.dll
2012-09-16 18:55:25 ----A---- C:\WINDOWS\system32\avrt.dll
2012-09-16 18:52:49 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Capcom
2012-09-16 09:42:04 ----D---- C:\Program Files\Capcom
2012-09-06 09:18:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ask
2012-09-06 09:18:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2012-09-06 09:18:46 ----D---- C:\Program Files\Common Files\Java
2012-09-06 09:18:26 ----A---- C:\WINDOWS\system32\npDeployJava1.dll
2012-09-06 09:18:26 ----A---- C:\WINDOWS\system32\deployJava1.dll
2012-09-06 09:18:25 ----A---- C:\WINDOWS\system32\javaws.exe
2012-09-06 09:17:52 ----A---- C:\WINDOWS\system32\WindowsAccessBridge.dll
2012-09-06 09:17:52 ----A---- C:\WINDOWS\system32\javaw.exe
2012-09-06 09:17:52 ----A---- C:\WINDOWS\system32\java.exe
2012-09-05 08:57:50 ----A---- C:\WINDOWS\system32\CleanMFT32.exe
2012-09-05 08:57:27 ----D---- C:\Program Files\Common Files\PC Tools
2012-09-05 08:57:25 ----D---- C:\Program Files\PC Tools Registry Mechanic

======List of files/folders modified in the last 3 months======

2012-11-29 12:26:33 ----RD---- C:\Program Files
2012-11-29 12:22:36 ----AD---- C:\WINDOWS\Temp
2012-11-29 12:22:34 ----SHD---- C:\WINDOWS\Installer
2012-11-29 12:22:27 ----D---- C:\WINDOWS
2012-11-29 12:22:14 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2012-11-29 12:22:13 ----D---- C:\WINDOWS\system32
2012-11-29 12:21:22 ----D---- C:\WINDOWS\Debug
2012-11-29 12:21:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2012-11-29 12:17:49 ----D---- C:\WINDOWS\system32\CatRoot2
2012-11-29 12:15:48 ----D---- C:\WINDOWS\system32\wbem
2012-11-29 12:15:48 ----D---- C:\WINDOWS\AppPatch
2012-11-29 12:15:47 ----RSD---- C:\WINDOWS\Fonts
2012-11-29 12:15:47 ----D---- C:\WINDOWS\system32\Setup
2012-11-29 12:15:46 ----D---- C:\WINDOWS\system32\drivers
2012-11-29 12:15:46 ----D---- C:\Program Files\Google
2012-11-29 12:15:03 ----D---- C:\WINDOWS\security
2012-11-29 12:14:56 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-11-29 12:12:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Norton
2012-11-29 12:12:26 ----SD---- C:\WINDOWS\Tasks
2012-11-29 12:06:54 ----D---- C:\WINDOWS\system32\CatRoot
2012-11-29 12:05:25 ----HD---- C:\WINDOWS\inf
2012-11-29 12:05:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2012-11-29 12:00:22 ----D---- C:\Program Files\Outlook Express
2012-11-29 11:55:29 ----D---- C:\Program Files\Movie Maker
2012-11-29 11:28:03 ----D---- C:\Program Files\Messenger
2012-11-29 11:25:14 ----D---- C:\Program Files\Common Files\Symantec Shared
2012-11-29 11:13:40 ----D---- C:\WINDOWS\WinSxS
2012-11-29 11:13:23 ----D---- C:\WINDOWS\ime
2012-11-29 11:13:22 ----D---- C:\WINDOWS\Help
2012-11-29 11:12:56 ----D---- C:\WINDOWS\system32\cs-CZ
2012-11-29 11:12:55 ----D---- C:\WINDOWS\system32\usmt
2012-11-29 11:12:51 ----D---- C:\Program Files\Internet Explorer
2012-11-29 11:12:47 ----D---- C:\WINDOWS\PeerNet
2012-11-29 11:07:24 ----D---- C:\WINDOWS\ServicePackFiles
2012-11-29 11:07:15 ----D---- C:\WINDOWS\system32\Restore
2012-11-29 11:07:14 ----D---- C:\WINDOWS\system32\npp
2012-11-29 11:07:12 ----D---- C:\WINDOWS\msagent
2012-11-29 11:07:10 ----D---- C:\WINDOWS\srchasst
2012-11-29 11:07:08 ----D---- C:\Program Files\NetMeeting
2012-11-29 11:07:06 ----D---- C:\WINDOWS\system32\Com
2012-11-29 11:07:03 ----D---- C:\Program Files\Windows Media Player
2012-11-29 11:07:02 ----D---- C:\Program Files\Windows NT
2012-11-29 11:06:50 ----D---- C:\Program Files\Common Files\System
2012-11-29 11:06:02 ----D---- C:\WINDOWS\system32\oobe
2012-11-29 11:05:52 ----D---- C:\WINDOWS\system
2012-11-29 11:04:15 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Media Player Classic
2012-11-29 11:03:07 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\uTorrent
2012-11-29 11:00:58 ----D---- C:\WINDOWS\Logs
2012-11-29 11:00:52 ----D---- C:\WINDOWS\Minidump
2012-11-29 10:51:41 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-11-29 10:29:27 ----D---- C:\Program Files\Mozilla Firefox
2012-11-29 10:29:23 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Mozilla
2012-11-29 10:24:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2012-11-27 14:36:52 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Skype
2012-11-19 05:29:59 ----RASH---- C:\boot.ini
2012-11-16 15:46:52 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\vlc
2012-11-15 19:37:09 ----D---- C:\Program Files\Essentials Codec Pack
2012-11-13 19:39:40 ----A---- C:\WINDOWS\NeroDigital.ini
2012-11-12 19:23:41 ----RSD---- C:\WINDOWS\assembly
2012-11-12 19:22:22 ----D---- C:\WINDOWS\system32\DirectX
2012-10-30 23:50:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2012-10-29 11:30:59 ----D---- C:\Program Files\THQ
2012-10-28 20:45:15 ----HD---- C:\Program Files\InstallShield Installation Information
2012-10-25 21:48:43 ----A---- C:\user.js
2012-10-25 15:09:46 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2012-10-20 11:57:16 ----D---- C:\Documents and Settings
2012-10-19 21:25:24 ----D---- C:\Program Files\Common Files
2012-10-19 21:15:18 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2012-10-19 14:49:53 ----D---- C:\Program Files\Electronic Arts
2012-10-19 14:46:42 ----D---- C:\Program Files\Euro Truck Simulator
2012-10-15 19:03:02 ----D---- C:\Program Files\Empire Interactive
2012-10-14 18:14:10 ----D---- C:\Program Files\uTorrent
2012-10-14 18:14:03 ----D---- C:\torrent
2012-10-14 13:13:32 ----D---- C:\Program Files\Microsoft Office
2012-10-14 13:13:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
2012-10-14 10:51:33 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2012-09-19 18:08:22 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Registry Mechanic
2012-09-19 18:07:48 ----SD---- C:\WINDOWS\Downloaded Program Files
2012-09-18 18:03:17 ----SD---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\Microsoft
2012-09-06 09:21:06 ----D---- C:\Documents and Settings\Fujitsu-Siemens\Data aplikací\PowerChallenge
2012-09-06 09:15:54 ----D---- C:\Program Files\Java

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 prohlp02;StarForce Protection Helper Driver v2; C:\WINDOWS\System32\drivers\prohlp02.sys [2004-08-09 114016]
R0 prosync1;StarForce Protection Synchronization Driver v1; C:\WINDOWS\System32\drivers\prosync1.sys [2004-07-19 7040]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-09-25 43528]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfhlp01;StarForce Protection Helper Driver; C:\WINDOWS\System32\drivers\sfhlp01.sys [2003-12-01 4832]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2005-05-16 6656]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2005-09-29 66048]
R0 SISAGP;SiS AGP Filter; C:\WINDOWS\system32\DRIVERS\SISAGPX.sys [2003-07-18 36992]
R0 SiSide;SiSide; C:\WINDOWS\system32\DRIVERS\siside.sys [2003-03-25 4096]
R0 SiSRaid;SiSRaid; C:\WINDOWS\system32\DRIVERS\SiSRaid.sys [2003-12-09 45568]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-01-18 717296]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-13 44672]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-10-30 25256]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2012-10-30 35928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-08-09 53920]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-10-30 97608]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\AN983.sys [2002-10-28 38528]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-02 2627328]
S0 djsgb;djsgb; C:\WINDOWS\system32\drivers\jhwiy.sys []
S0 jqkdozeghuhrt;jqkdozeghuhrt; C:\WINDOWS\system32\drivers\zjqwodjcj.sys []
S0 oemcjlzaimcbu;oemcjlzaimcbu; C:\WINDOWS\system32\drivers\jicypepgqb.sys []
S0 pzyrbi;pzyrbi; C:\WINDOWS\system32\drivers\lshsyztcbpwqp.sys []
S0 wftvmraotxs;wftvmraotxs; C:\WINDOWS\system32\drivers\mcqekdfvajznd.sys []
S3 ahffqmbj;ahffqmbj; \??\C:\WINDOWS\System32\Drivers\ahffqmbj.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-07-29 626977]
S3 art33ktd;art33ktd; C:\WINDOWS\system32\drivers\art33ktd.sys []
S3 BthEnum;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-13 17024]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-13 101120]
S3 BTHPORT;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 272128]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-13 18944]
S3 bunugghf;bunugghf; \??\C:\WINDOWS\System32\Drivers\bunugghf.sys []
S3 dcvagbro;dcvagbro; \??\C:\WINDOWS\System32\Drivers\dcvagbro.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-13 59136]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2012-10-30 44808]
R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 IB Updater;IB Updater; C:\Program Files\IB Updater\ExtensionUpdaterService.exe [2012-10-09 188760]
R2 IBUpdaterService;IBUpdaterService; C:\WINDOWS\system32\dmwu.exe [2012-10-02 1008496]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-09-06 161768]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-07-20 61440]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2004-08-02 114755]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service; C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2012-03-21 793048]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate1c99d971f8ce15e;Google Update Service (gupdate1c99d971f8ce15e); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-03-05 133104]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-03-05 133104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#2 Příspěvek od Rudy »

Zdravím!
Jen dotaz. Vy se zabýváte servisem PC výdělečně?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Re: Kontrola logu

#3 Příspěvek od mejl »

nezabývám...je to počítač známého...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#4 Příspěvek od Rudy »

OK. Dejte log ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Re: Kontrola logu

#5 Příspěvek od mejl »

zde je log z combofixu:

ComboFix 12-11-29.02 - Fujitsu-Siemens 29.11.2012 12:57:20.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1343 [GMT 1:00]
Spuštěný z: c:\documents and settings\Fujitsu-Siemens\Dokumenty\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Fujitsu-Siemens\Data aplikací\Bgm7fGCGHJ.txt
c:\documents and settings\Fujitsu-Siemens\Data aplikací\IK6fDMGl71.txt
c:\documents and settings\Fujitsu-Siemens\Plocha\call of duty
c:\documents and settings\Fujitsu-Siemens\Plocha\call of duty
c:\documents and settings\Fujitsu-Siemens\WINDOWS
c:\windows\system32\drivers\str.sys
c:\windows\system32\SET98.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-28 do 2012-11-29 )))))))))))))))))))))))))))))))
.
.
2012-11-29 11:26 . 2012-11-29 11:31 -------- d-----w- c:\program files\trend micro
2012-11-29 11:26 . 2012-11-29 11:31 -------- d-----w- C:\rsit
2012-11-29 10:12 . 2012-11-29 10:12 -------- d-----w- c:\windows\l2schemas
2012-11-29 10:12 . 2012-11-29 10:12 -------- d-----w- c:\windows\system32\cs
2012-11-29 10:12 . 2012-11-29 10:12 -------- d-----w- c:\windows\system32\bits
2012-11-29 09:54 . 2012-11-29 09:54 -------- d-----w- c:\program files\CCleaner
2012-11-29 09:46 . 2012-11-29 09:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-11-29 09:38 . 2012-11-29 09:38 -------- d-----w- c:\windows\EHome
2012-11-19 04:23 . 2012-11-19 04:23 -------- d-----w- C:\found.003
2012-11-19 03:32 . 2001-10-24 10:54 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-11-19 03:32 . 2001-10-24 10:54 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-11-19 03:32 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-11-19 03:30 . 2012-11-19 03:30 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Microsoft
2012-11-16 14:40 . 2012-06-09 17:21 178688 ----a-w- c:\windows\system32\unrar.dll
2012-11-16 14:40 . 2012-11-16 14:41 -------- d-----w- c:\program files\K-Lite Codec Pack
2012-11-15 05:47 . 2012-11-15 05:47 -------- d-----w- C:\found.002
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-30 22:51 . 2011-03-11 07:07 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2009-01-19 11:09 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2009-01-19 11:09 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2009-01-19 11:09 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2009-01-19 11:09 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-10-30 22:51 . 2009-01-19 11:09 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-10-30 22:51 . 2009-01-19 11:09 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-10-30 22:51 . 2009-01-19 11:09 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2011-02-06 09:03 41224 ----a-w- c:\windows\avastSS.scr
2012-10-30 22:50 . 2009-01-19 11:08 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-19 20:15 . 2009-04-14 13:24 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-10-02 15:20 . 2012-10-11 19:09 1008496 ----a-w- c:\windows\system32\dmwu.exe
2012-10-02 15:18 . 2012-10-11 19:09 28160 ----a-w- c:\windows\system32\ImHttpComm.dll
2012-09-06 08:16 . 2012-09-06 08:17 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-06 08:16 . 2009-05-20 15:34 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-06 08:16 . 2012-09-06 08:18 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-06 08:16 . 2012-09-06 08:18 746984 ----a-w- c:\windows\system32\deployJava1.dll
2004-12-07 07:13 . 2004-12-07 07:13 479432 ----a-w- c:\program files\dxsetup.exe
2004-12-07 07:13 . 2004-12-07 07:13 69832 ----a-w- c:\program files\DSETUP.dll
2004-12-07 07:13 . 2004-12-07 07:13 2249416 ----a-w- c:\program files\dsetup32.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-23 1515688]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-05-20 177464]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-08-23 19:20 1515688 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-23 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-08-23 1515688]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\daemon tools lite\daemon.exe" [2008-07-24 490952]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2006-02-10 2048000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-08-02 4493312]
"nwiz"="nwiz.exe" [2004-08-02 917504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-08-02 86016]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-05-02 91432]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\Fujitsu-Siemens\\Dokumenty\\ICQ6.5\\ICQ.exe"=
"c:\\torrent\\uTorrent.exe"=
"c:\\Program Files\\Vietcong\\vietcong.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\fishsim2\\fsserv.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Empire of Sports\\NetworkDiagnostic.exe"=
"c:\\Documents and Settings\\Fujitsu-Siemens\\Data aplikací\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Metin2\\metin2client.bin"=
"c:\\Program Files\\MotoGP2\\motogp2.exe"=
"c:\\WINDOWS\\system32\\dmwu.exe"=
"c:\\WINDOWS\\system32\\ARFC\\wrtc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\THQ\\MotoGP URT 3\\motogp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57258:TCP"= 57258:TCP:Pando Media Booster
"57258:UDP"= 57258:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.1.2009 17:20 717296]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11.3.2011 8:07 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19.1.2009 12:09 361032]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [15.5.2008 11:07 61424]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19.1.2009 12:09 21256]
R2 IB Updater;IB Updater;c:\program files\IB Updater\ExtensionUpdaterService.exe [11.10.2012 20:09 188760]
R2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [11.10.2012 20:09 1008496]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [5.9.2012 8:57 793048]
S0 djsgb;djsgb;c:\windows\system32\drivers\jhwiy.sys --> c:\windows\system32\drivers\jhwiy.sys [?]
S0 jqkdozeghuhrt;jqkdozeghuhrt;c:\windows\system32\drivers\zjqwodjcj.sys --> c:\windows\system32\drivers\zjqwodjcj.sys [?]
S0 oemcjlzaimcbu;oemcjlzaimcbu;c:\windows\system32\drivers\jicypepgqb.sys --> c:\windows\system32\drivers\jicypepgqb.sys [?]
S0 pzyrbi;pzyrbi;c:\windows\system32\drivers\lshsyztcbpwqp.sys --> c:\windows\system32\drivers\lshsyztcbpwqp.sys [?]
S0 wftvmraotxs;wftvmraotxs;c:\windows\system32\drivers\mcqekdfvajznd.sys --> c:\windows\system32\drivers\mcqekdfvajznd.sys [?]
S2 gupdate1c99d971f8ce15e;Google Update Service (gupdate1c99d971f8ce15e);c:\program files\Google\Update\GoogleUpdate.exe [5.3.2009 14:34 133104]
S3 ahffqmbj;ahffqmbj;\??\c:\windows\System32\Drivers\ahffqmbj.sys --> c:\windows\System32\Drivers\ahffqmbj.sys [?]
S3 bunugghf;bunugghf;\??\c:\windows\System32\Drivers\bunugghf.sys --> c:\windows\System32\Drivers\bunugghf.sys [?]
S3 dcvagbro;dcvagbro;\??\c:\windows\System32\Drivers\dcvagbro.sys --> c:\windows\System32\Drivers\dcvagbro.sys [?]
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2012-11-29 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-11-29 22:50]
.
2012-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 13:34]
.
2012-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 13:34]
.
2012-11-29 c:\windows\Tasks\Protected Search.job
- c:\program files\Protected Search\ProtectedSearch.exe [2012-10-20 07:43]
.
2012-11-29 c:\windows\Tasks\RMAutoUpdate.job
- c:\program files\PC Tools Registry Mechanic\SULauncher.exe [2012-09-05 10:23]
.
2012-11-16 c:\windows\Tasks\RMSchedule.job
- c:\program files\PC Tools Registry Mechanic\RegMech.exe [2012-09-05 10:22]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.babylon.com/?affID=116775&tt=311012_ctrl_4412_7&babsrc=HP_ss&mntrId=7c87b0ae0000000000000015830d5a06
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q=
mStart Page = hxxp://search.certified-toolbar.com?si=41460&home=true&tid=2938
mSearch Bar = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q=
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.254
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
URLSearchHooks-{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5} - (no file)
Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
Toolbar-{d3f4b70a-92e0-4393-a0f3-976d03b1ebf5} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
WebBrowser-{D3F4B70A-92E0-4393-A0F3-976D03B1EBF5} - (no file)
HKCU-Run-ICQ - ~c:\program files\ICQ7.5\ICQ.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-29 13:09
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(2348)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Celkový čas: 2012-11-29 13:15:03 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-29 12:14
.
Před spuštěním: Volných bajtů: 57 353 179 136
Po spuštění: Volných bajtů: 57 576 452 096
.
WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=""
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - DBB40A58023CBFE23B0937081C3FA907

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#6 Příspěvek od Rudy »

Ještě dočistíme. Přesuňte ComboFix na plochu. Otevřte poznámkový blok a zkopírujte do něj:
KillAll::

Folder::
c:\program files\Ask.com
c:\program files\SweetIM

Collect::
c:\windows\system32\drivers\zjqwodjcj.sys
c:\windows\system32\drivers\jhwiy.sys
c:\windows\system32\drivers\jicypepgqb.sys
c:\windows\system32\drivers\lshsyztcbpwqp.sys
c:\windows\system32\drivers\mcqekdfvajznd.sys
c:\windows\System32\Drivers\ahffqmbj.sys
c:\windows\System32\Drivers\bunugghf.sys
c:\windows\System32\Drivers\dcvagbro.sys


File::
c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

Driver::
djsgb
jqkdozeghuhrt
oemcjlzaimcbu
pzyrbi
wftvmraotxs
ahffqmbj
bunugghf
dcvagbro

Registry::
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
[-HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[-HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

Reboot::
Uložte na plochu jako CFScript.txt. Pak jej myší přetáhněte nad ikonu ComboFix a pusťte. CF se spustí a vykoná příkazy ze skriptu.

Obrázek
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Re: Kontrola logu

#7 Příspěvek od mejl »

zda zasilam novy log z combofixu:

ComboFix 12-11-29.02 - Fujitsu-Siemens 30.11.2012 9:19.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1431 [GMT 1:00]
Spuštěný z: c:\documents and settings\Fujitsu-Siemens\Dokumenty\Downloads\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Fujitsu-Siemens\Plocha\CFScript.txt.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\windows\Tasks\GoogleUpdateTaskMachineCore.job"
"c:\windows\Tasks\GoogleUpdateTaskMachineUA.job"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Fujitsu-Siemens\Plocha\Internet Explorer.lnk
c:\program files\Ask.com
c:\program files\Ask.com\assets\oobe\b.png
c:\program files\Ask.com\assets\oobe\bl.png
c:\program files\Ask.com\assets\oobe\br.png
c:\program files\Ask.com\assets\oobe\l.png
c:\program files\Ask.com\assets\oobe\pointer.png
c:\program files\Ask.com\assets\oobe\r.png
c:\program files\Ask.com\assets\oobe\t.png
c:\program files\Ask.com\assets\oobe\tl.png
c:\program files\Ask.com\assets\oobe\tr.png
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_97.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\precache.exe
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\Updater\config.xml
c:\program files\Ask.com\Updater\Updater.exe
c:\program files\Ask.com\UpdateTask.exe
c:\program files\SweetIM
c:\program files\SweetIM\Messenger\default.xml
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\program files\SweetIM\Messenger\mgAIMAuto.dll
c:\program files\SweetIM\Messenger\mgAIMMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgArchive.dll
c:\program files\SweetIM\Messenger\mgcommon.dll
c:\program files\SweetIM\Messenger\mgcommunication.dll
c:\program files\SweetIM\Messenger\mgconfig.dll
c:\program files\SweetIM\Messenger\mgFlashPlayer.dll
c:\program files\SweetIM\Messenger\mghooking.dll
c:\program files\SweetIM\Messenger\mgICQAuto.dll
c:\program files\SweetIM\Messenger\mgICQMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgIEPlayer.dll
c:\program files\SweetIM\Messenger\mglogger.dll
c:\program files\SweetIM\Messenger\mgMediaPlayer.dll
c:\program files\SweetIM\Messenger\mgMsnAuto.dll
c:\program files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgsimcommon.dll
c:\program files\SweetIM\Messenger\mgSweetIM.dll
c:\program files\SweetIM\Messenger\mgUpdateSupport.dll
c:\program files\SweetIM\Messenger\mgxml_wrapper.dll
c:\program files\SweetIM\Messenger\mgYahooAuto.dll
c:\program files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
c:\program files\SweetIM\Messenger\msvcp71.dll
c:\program files\SweetIM\Messenger\msvcr71.dll
c:\program files\SweetIM\Messenger\resources\images\AudibleButton.png
c:\program files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
c:\program files\SweetIM\Messenger\resources\images\EmoticonButton.png
c:\program files\SweetIM\Messenger\resources\images\NudgeButton.png
c:\program files\SweetIM\Messenger\resources\images\SoundFxButton.png
c:\program files\SweetIM\Messenger\resources\images\WinksButton.png
c:\program files\SweetIM\Messenger\SweetIM.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\ClearHist.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\conf\logger.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\default.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\mgcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgconfig.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mghooking.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mglogger.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\msvcp71.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\msvcr71.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\about.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\affid.dat
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\basis.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\clear-history.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim-over.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier.js
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dating.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\e_cards.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon_over.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\find.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\free_stuff.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\games.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\glitter.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\help.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\highlight.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\live.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\locales.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_16x16.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_32x32.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_about.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\more-search-providers.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\music.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\news.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\photos.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\search-current-site.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\shopping.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileySmile.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileyWink.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\sweetim_text.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\toolbar.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\version.txt
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\web-search.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ahffqmbj
-------\Service_bunugghf
-------\Service_dcvagbro
-------\Service_djsgb
-------\Service_jqkdozeghuhrt
-------\Service_oemcjlzaimcbu
-------\Service_pzyrbi
-------\Service_wftvmraotxs
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-10-28 do 2012-11-30 )))))))))))))))))))))))))))))))
.
.
2012-11-30 08:06 . 2012-11-30 08:06 -------- d-----w- c:\documents and settings\NetworkService\Data aplikací
2012-11-30 08:06 . 2012-11-30 08:06 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Microsoft
2012-11-30 08:04 . 2012-11-30 08:04 -------- d-----w- C:\found.004
2012-11-30 07:51 . 2012-11-30 07:51 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-11-30 07:51 . 2012-11-30 07:51 -------- d-sh--w- c:\documents and settings\Fujitsu-Siemens\IETldCache
2012-11-29 19:16 . 2012-08-28 15:18 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2012-11-29 19:13 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-11-29 19:10 . 2012-08-28 15:18 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-11-29 19:10 . 2012-08-28 15:18 630272 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2012-11-29 19:10 . 2012-08-28 15:18 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2012-11-29 19:10 . 2012-08-28 19:48 11111424 -c----w- c:\windows\system32\dllcache\ieframe.dll
2012-11-29 19:10 . 2012-08-28 15:18 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2012-11-29 19:10 . 2012-08-28 15:18 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-11-29 19:10 . 2012-08-28 15:18 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-11-29 19:07 . 2012-11-29 19:10 -------- dc-h--w- c:\windows\ie8
2012-11-29 17:28 . 2012-11-29 17:28 -------- d-----w- c:\program files\Common Files\Skype
2012-11-29 17:28 . 2012-11-29 17:28 -------- d-----r- c:\program files\Skype
2012-11-29 15:07 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2012-11-29 15:05 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2012-11-29 15:01 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2012-11-29 14:58 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2012-11-29 14:58 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2012-11-29 14:55 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2012-11-29 14:53 . 2009-03-08 03:33 759296 -c--a-w- c:\windows\system32\dllcache\VGX.dll
2012-11-29 14:45 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2012-11-29 14:45 . 2012-01-11 19:07 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-11-29 14:45 . 2012-01-11 19:07 3072 ------w- c:\windows\system32\iacenc.dll
2012-11-29 14:42 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2012-11-29 14:25 . 2012-11-29 14:25 -------- d-s---w- c:\windows\Cookies
2012-11-29 11:26 . 2012-11-29 11:31 -------- d-----w- c:\program files\trend micro
2012-11-29 11:26 . 2012-11-29 11:31 -------- d-----w- C:\rsit
2012-11-29 10:12 . 2012-11-29 10:12 -------- d-----w- c:\windows\l2schemas
2012-11-29 10:12 . 2012-11-29 10:12 -------- d-----w- c:\windows\system32\cs
2012-11-29 10:12 . 2012-11-29 10:12 -------- d-----w- c:\windows\system32\bits
2012-11-29 09:54 . 2012-11-29 09:54 -------- d-----w- c:\program files\CCleaner
2012-11-29 09:46 . 2012-11-29 09:46 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVAST Software
2012-11-29 09:38 . 2012-11-29 09:38 -------- d-----w- c:\windows\EHome
2012-11-19 04:23 . 2012-11-19 04:23 -------- d-----w- C:\found.003
2012-11-19 03:32 . 2001-10-24 10:54 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-11-19 03:32 . 2001-10-24 10:54 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-11-19 03:32 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-11-16 14:40 . 2012-06-09 17:21 178688 ----a-w- c:\windows\system32\unrar.dll
2012-11-16 14:40 . 2012-11-16 14:41 -------- d-----w- c:\program files\K-Lite Codec Pack
2012-11-15 05:47 . 2012-11-15 05:47 -------- d-----w- C:\found.002
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-30 22:51 . 2011-03-11 07:07 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51 . 2009-01-19 11:09 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-10-30 22:51 . 2009-01-19 11:09 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-10-30 22:51 . 2009-01-19 11:09 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-10-30 22:51 . 2009-01-19 11:09 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-10-30 22:51 . 2009-01-19 11:09 89752 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-10-30 22:51 . 2009-01-19 11:09 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-10-30 22:51 . 2009-01-19 11:09 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-10-30 22:51 . 2011-02-06 09:03 41224 ----a-w- c:\windows\avastSS.scr
2012-10-30 22:50 . 2009-01-19 11:08 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-10-22 19:57 . 2004-08-18 12:00 1866368 ----a-w- c:\windows\system32\win32k.sys
2012-10-19 20:15 . 2009-04-14 13:24 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2012-10-02 18:04 . 2004-08-18 12:00 58368 ----a-w- c:\windows\system32\synceng.dll
2012-10-02 15:20 . 2012-10-11 19:09 1008496 ----a-w- c:\windows\system32\dmwu.exe
2012-10-02 15:18 . 2012-10-11 19:09 28160 ----a-w- c:\windows\system32\ImHttpComm.dll
2012-09-06 08:16 . 2012-09-06 08:17 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-06 08:16 . 2009-05-20 15:34 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-06 08:16 . 2012-09-06 08:18 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-06 08:16 . 2012-09-06 08:18 746984 ----a-w- c:\windows\system32\deployJava1.dll
2004-12-07 07:13 . 2004-12-07 07:13 479432 ----a-w- c:\program files\dxsetup.exe
2004-12-07 07:13 . 2004-12-07 07:13 69832 ----a-w- c:\program files\DSETUP.dll
2004-12-07 07:13 . 2004-12-07 07:13 2249416 ----a-w- c:\program files\dsetup32.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 22:50 121528 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\daemon tools lite\daemon.exe" [2008-07-24 490952]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2006-02-10 2048000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-08-02 4493312]
"nwiz"="nwiz.exe" [2004-08-02 917504]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-08-02 86016]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-05-02 91432]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"avast"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2012-10-30 4297136]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\Fujitsu-Siemens\\Dokumenty\\ICQ6.5\\ICQ.exe"=
"c:\\torrent\\uTorrent.exe"=
"c:\\Program Files\\Vietcong\\vietcong.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\fishsim2\\fsserv.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Empire of Sports\\NetworkDiagnostic.exe"=
"c:\\Documents and Settings\\Fujitsu-Siemens\\Data aplikací\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\ICQ7.5\\ICQ.exe"=
"c:\\Program Files\\Metin2\\metin2client.bin"=
"c:\\Program Files\\MotoGP2\\motogp2.exe"=
"c:\\WINDOWS\\system32\\dmwu.exe"=
"c:\\WINDOWS\\system32\\ARFC\\wrtc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\THQ\\MotoGP URT 3\\motogp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57258:TCP"= 57258:TCP:Pando Media Booster
"57258:UDP"= 57258:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.1.2009 17:20 717296]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11.3.2011 8:07 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [19.1.2009 12:09 361032]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [15.5.2008 11:07 61424]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19.1.2009 12:09 21256]
R2 IB Updater;IB Updater;c:\program files\IB Updater\ExtensionUpdaterService.exe [11.10.2012 20:09 188760]
R2 IBUpdaterService;IBUpdaterService;c:\windows\system32\dmwu.exe [11.10.2012 20:09 1008496]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [5.9.2012 8:57 793048]
S2 gupdate1c99d971f8ce15e;Google Update Service (gupdate1c99d971f8ce15e);c:\program files\Google\Update\GoogleUpdate.exe [5.3.2009 14:34 133104]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [13.7.2012 13:28 160944]
.
Obsah adresáře 'Naplánované úlohy'
.
2012-11-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2012-11-30 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-11-29 22:50]
.
2012-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 13:34]
.
2012-11-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-05 13:34]
.
2012-11-30 c:\windows\Tasks\Protected Search.job
- c:\program files\Protected Search\ProtectedSearch.exe [2012-10-20 07:43]
.
2012-11-30 c:\windows\Tasks\RMAutoUpdate.job
- c:\program files\PC Tools Registry Mechanic\SULauncher.exe [2012-09-05 10:23]
.
2012-11-29 c:\windows\Tasks\RMSchedule.job
- c:\program files\PC Tools Registry Mechanic\RegMech.exe [2012-09-05 10:22]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://search.babylon.com/?affID=116775&tt=311012_ctrl_4412_7&babsrc=HP_ss&mntrId=7c87b0ae0000000000000015830d5a06
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q=
mSearch Bar = hxxp://search.certified-toolbar.com?si=41460&tid=2938&bs=true&q=
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.0.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-30 09:36
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'explorer.exe'(3408)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Celkový čas: 2012-11-30 09:42:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-11-30 08:42
ComboFix2.txt 2012-11-29 12:15
.
Před spuštěním: Volných bajtů: 54 671 896 576
Po spuštění: Volných bajtů: 54 639 304 704
.
- - End Of File - - D8FA82196DEE3F8E81C3A4FB3E24C2AD

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#8 Příspěvek od Rudy »

Log již vypadá OK. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Re: Kontrola logu

#9 Příspěvek od mejl »

no dnes při prvním spuštění to spadlo (modrá smrt) a potom se spustil chkdsk a opravil nějaké chyby...poté jsem provedl ten combofix a žádný jiný problém neregistruju...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#10 Příspěvek od Rudy »

Stáhněte, nainstalujte a spusťte CrystalDiskInfo: http://www.stahuj.centrum.cz/utility_a_ ... ldiskinfo/ a přes Úpravy>kopírovat sem dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Re: Kontrola logu

#11 Příspěvek od mejl »

zde je ten log:

----------------------------------------------------------------------------
CrystalDiskInfo 5.0.5 Shizuku Edition (C) 2008-2012 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows XP Home Edition SP3 [5.1 Build 2600] (x86)
Date : 2012/11/30 12:38:05

-- Controller Map ----------------------------------------------------------
+ SiS 5513 IDE UDMA Controller [ATA]
- Primární kanál IDE (0)
+ Sekundární kanál IDE (1)
- PHILIPS DROM6216
- ATAPI DVD A DH20A4P
+ SiS 180 RAID Controller [SCSI]
- Maxtor 7 Y250M0 SCSI Disk Device
+ AEHU09K5 IDE Controller [SCSI]
- JYPW 7W52ZKT SCSI CdRom Device
- JYPW 7W52ZKT SCSI CdRom Device
- JYPW 7W52ZKT SCSI CdRom Device
- JYPW 7W52ZKT SCSI CdRom Device

-- Disk List ---------------------------------------------------------------
(1) Maxtor 7Y250M0 : 251,0 GB [0/2/0, pd1]

----------------------------------------------------------------------------
(1) Maxtor 7Y250M0
----------------------------------------------------------------------------
Model : Maxtor 7Y250M0
Firmware : YAR511W0
Serial Number : Y66D0YNE
Disk Size : 251,0 GB (8,4/137,4/251,0)
Buffer Size : 7936 KB
Queue Depth : 1
# of Sectors : 490234752
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA/ATAPI-7
Minor Version : ATA/ATAPI-7 T13 1532D version 0
Transfer Mode : SATA/150
Power On Hours : 243 hod. (?)
Power On Count : 2593 krát
Temparature : 56 C (132 F)
Health Status : Dobrý
Features : S.M.A.R.T., APM, AAM, 48bit LBA
APM Level : 0000h [OFF]
AAM Level : C0FEh [ON]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
03 184 175 _63 000000004FED Čas na roztočení ploten
04 251 251 __0 000000001146 Počet spuštění/zastavení
05 253 253 _63 000000000000 Počet přemapovaných sektorů
06 253 253 100 000000000000 Počet dosáhnutí konce při čtení
07 253 252 __0 000000000000 Počet chybných hledání
08 244 234 187 00000000A6DB Čas potřebný na vyhledání
09 218 218 __0 00000000391A Hodin v činnosti
0A 253 252 157 000000000000 Počet opakovaných pokusů o roztočení ploten
0B 253 252 223 000000000000 Počet pokusů o překalibrování
0C 247 247 __0 000000000A21 Počet cyklů zapnutí zařízení
C0 253 253 __0 000000000000 Počet vypnutí disku
C1 253 253 __0 000000000000 Počet cyklů načítání/vymazání
C2 253 253 __0 000000000038 Teplota
C3 253 252 __0 000000000E53 Počet oprav chybného čtení
C4 253 253 __0 000000000000 Počet udalostí s číslem realokování sektorů
C5 253 253 __0 000000000000 Počet podezřelých sektorů
C6 253 253 __0 000000000000 Počet neopravitelných sektorů
C7 159 __1 __0 000000000115 Počet chyb v kontrolním součtu UltraDMA
C8 253 252 __0 000000000000 Počet chyb při zápisu sektorů
C9 253 252 __0 00000000006B Počet chyb při čtení programů z disku
CA 253 252 __0 000000000000 Počet chyb při směrování údajů
CB 253 252 180 000000000005 Počet chyb v kódech na opravu chyb
CC 253 252 __0 000000000000 Počet softvérově opravených chyb v opravných kódech
CD 253 252 __0 000000000000 Počet chyb způsobených vysokou teplotou
CF 253 252 __0 000000000000 Množství napětí potřebného na roztočení disku
D0 253 252 __0 000000000000 Počet vyslaných impulzů na roztočení disku při nedostatečném napájení
D1 191 189 __0 000000000000 Výkon při vyhledávaní na disku při interních testech disku
63 253 253 __0 000000000000 Neznámý
64 253 253 __0 000000000000 Neznámý
65 253 253 __0 000000000000 Neznámý

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 0040 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 5936 3644 3059 4E45 2020 2020 2020 2020 2020 2020
020: 0003 3E00 0004 5941 5235 3131 5730 4D61 7874 6F72
030: 2037 5932 3530 4D30 2020 2020 2020 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4000 0200 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 0000 0002 0000 0000 0000
080: 00FE 001E 7C6B 7F09 4003 7C49 3E01 4003 407F 0000
090: 0000 0000 FFFE 0000 C0FE 0000 0000 0000 0000 0000
100: 6380 1D38 0000 0000 0000 0000 0000 0000 0000 0000
110: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
120: 0000 0000 0000 0000 0000 0000 0000 0000 0009 0000
130: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
140: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
150: 0017 2044 0000 0000 0000 0000 0000 0000 0000 0384
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 A5A5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 03 27 00 B8 AF ED 4F 00 00 00 00 00 04 32
010: 00 FB FB 46 11 00 00 00 00 00 05 33 00 FD FD 00
020: 00 00 00 00 00 00 06 01 00 FD FD 00 00 00 00 00
030: 00 00 07 0A 00 FD FC 00 00 00 00 00 00 00 08 27
040: 00 F4 EA DB A6 00 00 00 00 00 09 32 00 DA DA 1A
050: 39 00 00 00 00 00 0A 2B 00 FD FC 00 00 00 00 00
060: 00 00 0B 2B 00 FD FC 00 00 00 00 00 00 00 0C 32
070: 00 F7 F7 21 0A 00 00 00 00 00 C0 32 00 FD FD 00
080: 00 00 00 00 00 00 C1 32 00 FD FD 00 00 00 00 00
090: 00 00 C2 32 00 FD FD 38 00 00 00 00 00 00 C3 0A
0A0: 00 FD FC 53 0E 00 00 00 00 00 C4 08 00 FD FD 00
0B0: 00 00 00 00 00 00 C5 08 00 FD FD 00 00 00 00 00
0C0: 00 00 C6 08 00 FD FD 00 00 00 00 00 00 00 C7 08
0D0: 00 9F 01 15 01 00 00 00 00 00 C8 0A 00 FD FC 00
0E0: 00 00 00 00 00 00 C9 0A 00 FD FC 6B 00 00 00 00
0F0: 00 00 CA 0A 00 FD FC 00 00 00 00 00 00 00 CB 0B
100: 00 FD FC 05 00 00 00 00 00 00 CC 0A 00 FD FC 00
110: 00 00 00 00 00 00 CD 0A 00 FD FC 00 00 00 00 00
120: 00 00 CF 2A 00 FD FC 00 00 00 00 00 00 00 D0 2A
130: 00 FD FC 00 00 00 00 00 00 00 D1 24 00 BF BD 00
140: 00 00 00 00 00 00 63 04 00 FD FD 00 00 00 00 00
150: 00 00 64 04 00 FD FD 00 00 00 00 00 00 00 65 04
160: 00 FD FD 00 00 00 00 00 00 00 82 00 6B 01 01 5B
170: 03 00 01 00 02 6A 00 00 00 00 00 00 00 00 00 00
180: 00 00 3B 00 00 00 67 F0 98 0F 02 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 33 00 B0 E3 4F 1C 30 00
1B0: 00 00 80 63 38 1D 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 8E

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 03 3F 00 00 00 00 00 00 00 00 00 00 04 00
010: 00 00 00 00 00 00 00 00 00 00 05 3F 00 00 00 00
020: 00 00 00 00 00 00 06 64 00 00 00 00 00 00 00 00
030: 00 00 07 00 00 00 00 00 00 00 00 00 00 00 08 BB
040: 00 00 00 00 00 00 00 00 00 00 09 00 00 00 00 00
050: 00 00 00 00 00 00 0A 9D 00 00 00 00 00 00 00 00
060: 00 00 0B DF 00 00 00 00 00 00 00 00 00 00 0C 00
070: 00 00 00 00 00 00 00 00 00 00 C0 00 00 00 00 00
080: 00 00 00 00 00 00 C1 00 00 00 00 00 00 00 00 00
090: 00 00 C2 00 00 00 00 00 00 00 00 00 00 00 C3 00
0A0: 00 00 00 00 00 00 00 00 00 00 C4 00 00 00 00 00
0B0: 00 00 00 00 00 00 C5 00 00 00 00 00 00 00 00 00
0C0: 00 00 C6 00 00 00 00 00 00 00 00 00 00 00 C7 00
0D0: 00 00 00 00 00 00 00 00 00 00 C8 00 00 00 00 00
0E0: 00 00 00 00 00 00 C9 00 00 00 00 00 00 00 00 00
0F0: 00 00 CA 00 00 00 00 00 00 00 00 00 00 00 CB B4
100: 00 00 00 00 00 00 00 00 00 00 CC 00 00 00 00 00
110: 00 00 00 00 00 00 CD 00 00 00 00 00 00 00 00 00
120: 00 00 CF 00 00 00 00 00 00 00 00 00 00 00 D0 00
130: 00 00 00 00 00 00 00 00 00 00 D1 00 00 00 00 00
140: 00 00 00 00 00 00 63 00 00 00 00 00 00 00 00 00
150: 00 00 64 00 00 00 00 00 00 00 00 00 00 00 65 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 61

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#12 Příspěvek od Rudy »

Disk je OK. Chkdsk chyby opravil. V případě opakování BSOD se ozvěte. :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mejl
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 30 čer 2008 17:15

Re: Kontrola logu

#13 Příspěvek od mejl »

ok ;) ...děkuji Vám za pomoc

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119390
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Kontrola logu

#14 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno