Prosim o kontrolu:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Mama at 2012-12-05 13:20:11
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 16 GB (27%) free of 57 GB
Total RAM: 447 MB (44% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:20:12, on 5. 12. 2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\RSIT.exe
C:\Program Files\trend micro\Mama.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource= ... =CT3220468
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm (file missing)
O9 - Extra 'Tools' menuitem: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm (file missing)
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Mama/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.jpg
--
End of file - 4809 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-602609370-725345543-1008Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-602609370-725345543-1008UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-05-06 716800]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG_TRAY]
C:\Program Files\AVG\AVG2012\avgtray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2012-02-27 136176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mama^Nabídka Start^Programy^Po spuštění^Orezávač obrazovky a spúšťač programu OneNote 2007.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-03-29 126976]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\QIP Infium\infium.exe"="C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:ENABLE"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG2012\avgmfapx.exe"="C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{081d7a2e-3c3c-11e0-959a-0017083ac8f8}]
shell\AutoRun\command - F:\APPInst.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23c5d3e4-0948-11de-9123-0017083ac8f8}]
shell\AutoRun\command - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
shell\open\command - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f39289f-325e-11de-9199-0017083ac8f8}]
shell\AutoRun\command - F:\g8k.exe
shell\open\command - F:\g8k.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4dd89c96-bf20-11de-92f7-0017083ac8f8}]
shell\AutoRun\command - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
shell\open\command - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b402c8c4-5655-11dc-8c6b-0017083ac8f8}]
shell\AutoRun\command - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
shell\open\command - F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
======File associations======
.reg - open - regedit.exe "%1" %*
.scr - open - "%1" %*
======List of files/folders created in the last 1 months======
2012-12-05 13:16:07 ----D---- C:\Program Files\trend micro
2012-12-05 13:16:04 ----D---- C:\rsit
2012-12-05 13:13:14 ----A---- C:\Program Files\RSIT.exe
2012-12-05 12:47:12 ----D---- C:\Documents and Settings\Mama\Data aplikací\Serif
2012-12-05 12:45:42 ----HD---- C:\WINDOWS\system32\GroupPolicy
2012-12-05 12:40:46 ----D---- C:\Documents and Settings\Mama\Data aplikací\Avira
2012-12-05 12:34:17 ----D---- C:\Program Files\Avira
2012-12-05 12:34:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2012-12-05 12:31:42 ----D---- C:\Program Files\Serif
2012-12-05 12:27:17 ----D---- C:\Program Files\RegCleaner
2012-12-02 12:20:32 ----D---- C:\Vampire.Diaries.S04.EN
2012-12-01 10:36:13 ----D---- C:\WINDOWS\pss
======List of files/folders modified in the last 1 months======
2012-12-05 13:20:11 ----D---- C:\WINDOWS\TEMP
2012-12-05 13:16:07 ----D---- C:\Program Files
2012-12-05 13:15:56 ----D---- C:\WINDOWS\system32\drivers
2012-12-05 12:47:08 ----D---- C:\WINDOWS\system32\CatRoot2
2012-12-05 12:45:42 ----D---- C:\WINDOWS\system32
2012-12-05 12:43:02 ----D---- C:\WINDOWS
2012-12-05 12:42:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2012-12-05 12:35:40 ----D---- C:\WINDOWS\system32\CatRoot
2012-12-05 12:32:46 ----SHD---- C:\WINDOWS\Installer
2012-12-05 12:32:05 ----D---- C:\WINDOWS\WinSxS
2012-12-05 12:24:52 ----D---- C:\Program Files\Common Files
2012-12-05 12:10:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2012-12-05 12:09:31 ----D---- C:\WINDOWS\inf
2012-12-05 12:07:27 ----D---- C:\WINDOWS\system32\dllcache
2012-12-05 12:03:15 ----DC---- C:\WINDOWS\system32\DRVSTORE
2012-12-05 12:00:09 ----HD---- C:\Program Files\InstallShield Installation Information
2012-12-05 11:59:53 ----D---- C:\Program Files\Ahead
2012-12-05 11:45:13 ----A---- C:\WINDOWS\win.ini
2012-12-05 11:43:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2012-12-05 11:43:03 ----D---- C:\WINDOWS\Fonts
2012-12-05 11:34:10 ----ASH---- C:\boot.ini
2012-12-05 11:34:10 ----A---- C:\WINDOWS\system.ini
2012-12-04 22:55:31 ----A---- C:\WINDOWS\WDICT32.INI
2012-12-04 18:18:18 ----D---- C:\WINDOWS\Prefetch
2012-12-02 23:31:34 ----D---- C:\Documents and Settings\Mama\Data aplikací\vlc
2012-12-02 12:20:09 ----D---- C:\Buffy originál
2012-11-27 20:48:46 ----D---- C:\Downloads
2012-11-24 16:35:49 ----SHD---- C:\WINDOWS\CSC
2012-11-11 11:20:38 ----D---- C:\Program Files\Lx_cats
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2012-11-16 133824]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2012-11-16 36552]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2007-02-28 15440]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2012-08-27 28520]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2007-09-29 271360]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2012-11-16 83432]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-13 88192]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2007-09-29 18048]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2006-04-05 12672]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2006-05-03 178176]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-06-07 152960]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-03-29 2873856]
R3 ATSWPDRV;AuthenTec TruePrint USB Driver (AES2500); C:\WINDOWS\system32\DRIVERS\ATSwpDrv.sys [2006-03-30 130432]
R3 b57w2k;Broadcom NetLink (TM) Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-10-26 142720]
R3 BCM43XX;Broadcom 802.11 - ovládač sieťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2006-11-01 604928]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2002-11-28 15360]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2006-04-05 995712]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2006-04-05 206976]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2004-06-21 78976]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2007-03-15 9856]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
R3 tifm21;tifm21; C:\WINDOWS\system32\drivers\tifm21.sys [2006-07-06 168448]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2006-04-05 726400]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 acgfb0s2;acgfb0s2; C:\WINDOWS\system32\drivers\acgfb0s2.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-05-22 17480]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys [2008-04-13 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\pfc027.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2007-03-27 47360]
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\WINDOWS\system32\DRIVERS\irstusb.sys [2001-08-17 26624]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tapvpn;TAP VPN Adapter; C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-01-23 27136]
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\DRIVERS\UIUSYS.SYS []
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sfc;sfc; C:\WINDOWS\system32\drivers\sfc.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\system32\DRIVERS\sr.sys [2008-04-14 73344]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2012-11-19 109344]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2012-11-19 85280]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-03-29 536576]
R2 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-04-07 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2009-04-07 189784]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-03-28 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 lxcc_device;lxcc_device; C:\WINDOWS\system32\lxcccoms.exe [2005-07-06 466944]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S4 STI Simulator;STI Simulator; C:\WINDOWS\System32\PAStiSvc.exe [2005-01-14 53248]
-----------------EOF-----------------

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
preventivka stareho kompu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: preventivka stareho kompu
Zdravim
Zapojte do PC vsechny USB klice (flashky, ext. disky apod.)


- Stahne a ulozte na plochu UsbFix http://www.viry.cz/forum/viewtopic.php?f=24&t=102308
- Spustte a kliknete na Deletion
- Po dokonceni sem vlozte log, pokud na Vas nevyskoci, najdete jej zde C:\UsbFix.txt
Re: preventivka stareho kompu
############################## | UsbFix V 7.096 | [Deletion]
User: Mama (Administrator) # SLAVOKNOTEBOOK
Updated 15/08/2012 by El Desaparecido
Started at 19:11:19 | 06/12/2012
Website: http://eldesaparecido.com
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: Hewlett-Packard (HP Compaq nx6325 (EY343EA#AKR)) (X86-based PC) # Notebook
CPU: Mobile AMD Sempron(tm) Processor 3500+ (1795)
RAM -> [Total : 447 | Free : 128]
BIOS: KBC Version 40.15
BOOT: Normal boot
OS: Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 6.0.2900.5512
SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 56 Gb (16 Mb free - 28%) [] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
F:\ -> Removable drive # 7 Gb (4 Mb free - 54%) [] # NTFS
G:\ -> Removable drive # 4 Gb (341 Mb free - 9%) [] # NTFS
H:\ -> Removable drive # 964 Mb (780 Mb free - 81%) [USB] # FAT
################## | Active Processes |
C:\WINDOWS\System32\smss.exe (828)
C:\WINDOWS\system32\winlogon.exe (956)
C:\WINDOWS\system32\services.exe (1000)
C:\WINDOWS\system32\lsass.exe (1012)
C:\WINDOWS\system32\Ati2evxx.exe (1184)
C:\WINDOWS\system32\svchost.exe (1204)
C:\WINDOWS\System32\svchost.exe (1328)
C:\WINDOWS\system32\Ati2evxx.exe (1484)
C:\WINDOWS\system32\spoolsv.exe (1884)
C:\Program Files\Avira\AntiVir Desktop\sched.exe (1932)
C:\WINDOWS\Explorer.EXE (628)
C:\Program Files\Analog Devices\Core\smax4pnp.exe (764)
C:\WINDOWS\system32\ctfmon.exe (772)
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (780)
C:\Program Files\Avira\AntiVir Desktop\avguard.exe (1764)
C:\WINDOWS\system32\PnkBstrA.exe (2008)
C:\WINDOWS\system32\PnkBstrB.exe (2028)
C:\WINDOWS\system32\svchost.exe (268)
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (1284)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2892)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2692)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3020)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3380)
C:\UsbFix\Go.exe (204)
################## | Stopped processes |
Stopped! C:\WINDOWS\system32\Ati2evxx.exe (1184)
Stopped! C:\WINDOWS\system32\Ati2evxx.exe (1484)
Stopped! C:\WINDOWS\system32\spoolsv.exe (1884)
Stopped! C:\Program Files\Avira\AntiVir Desktop\sched.exe (1932)
Stopped! C:\WINDOWS\Explorer.EXE (628)
Stopped! C:\Program Files\Analog Devices\Core\smax4pnp.exe (764)
Stopped! C:\WINDOWS\system32\ctfmon.exe (772)
Stopped! C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (780)
Stopped! C:\Program Files\Avira\AntiVir Desktop\avguard.exe (1764)
Stopped! C:\WINDOWS\system32\PnkBstrA.exe (2008)
Stopped! C:\WINDOWS\system32\PnkBstrB.exe (2028)
Stopped! C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (1284)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2892)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2692)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3020)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3380)
################## | Files # Infected Folders |
Deleted ! C:\WINDOWS\regedit.com
Deleted ! C:\Recycler\S-1-5-21-1659004503-602609370-725345543-1003
Deleted ! C:\Recycler\S-1-5-21-1659004503-602609370-725345543-1008
Deleted ! C:\Recycled\Recycled
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{081d7a2e-3c3c-11e0-959a-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{23c5d3e4-0948-11de-9123-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{3f39289f-325e-11de-9199-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{4dd89c96-bf20-11de-92f7-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{b402c8c4-5655-11dc-8c6b-0017083ac8f8}
################## | Listing |
[26/02/2002 - 17:54:28 | N | 824] C:\AUTOEXEC.BAT
[05/12/2012 - 11:34:10 | N | 258] C:\boot.ini
[25/10/2001 - 13:00:00 | N | 4952] C:\Bootfont.bin
[15/03/2007 - 18:29:36 | N | 512] C:\bootsect.dos
[18/06/2011 - 20:51:00 | D ] C:\Buffcool
[02/12/2012 - 12:20:09 | D ] C:\Buffy originál
[05/12/2012 - 13:41:36 | D ] C:\Config.Msi
[05/04/2003 - 08:05:34 | N | 4881] C:\CONFIG.SYS
[15/08/2002 - 22:59:16 | N | 18353] C:\COPYING
[05/12/2012 - 13:37:01 | D ] C:\Documents and Settings
[27/11/2012 - 20:48:46 | D ] C:\Downloads
[06/03/2004 - 00:36:22 | N | 512] C:\FDOSBOOT.BIN
[28/02/2008 - 15:34:32 | D ] C:\FOUND.000
[16/03/2008 - 12:33:10 | D ] C:\FOUND.001
[18/03/2008 - 12:57:50 | D ] C:\FOUND.002
[30/01/1997 - 23:00:00 | N | 447] C:\INFO.BOM
[15/03/2007 - 18:46:54 | N | 0] C:\IO.SYS
[24/09/2003 - 20:58:54 | N | 45908] C:\KERNEL.SYS
[20/09/2012 - 17:43:26 | N | 628986728] C:\Killtmonrskgdm.blRay-HD3D.mkv
[20/09/2012 - 17:43:54 | N | 84005] C:\Killtmonrskgdm.blRay-HD3D.srt
[01/12/2012 - 10:35:36 | N | 283304] C:\lxccscan.log
[26/11/2012 - 20:57:12 | N | 271219795] C:\misfits.4x05.hdtv_x264-fov.mp4
[28/11/2012 - 00:16:46 | N | 48944] C:\misfits.4x05.hdtv_x264-fov.srt
[15/03/2007 - 18:46:54 | N | 0] C:\MSDOS.SYS
[13/06/2008 - 17:42:06 | RHD ] C:\MSOCache
[15/03/2007 - 18:16:24 | D ] C:\NC
[03/08/2004 - 19:38:34 | N | 47564] C:\NTDETECT.COM
[16/10/2010 - 23:34:39 | N | 250576] C:\ntldr
[11/10/2011 - 21:07:01 | D ] C:\Onizuka Sensei
[06/12/2012 - 18:30:23 | ASH | 704643072] C:\pagefile.sys
[26/09/2003 - 00:04:34 | N | 7358] C:\POSTINST.BAT
[05/12/2012 - 13:35:26 | D ] C:\Program Files
[26/12/2007 - 20:58:48 | D ] C:\Qoobox
[28/04/2008 - 14:30:50 | D ] C:\Recycled
[06/12/2012 - 19:13:08 | SHD ] C:\RECYCLER
[20/11/2009 - 23:26:57 | RSHD ] C:\RESTORE
[28/10/2012 - 15:20:21 | D ] C:\STEP software
[25/04/2008 - 09:58:54 | SHD ] C:\System Volume Information
[06/12/2012 - 19:13:08 | D ] C:\UsbFix
[06/12/2012 - 19:13:09 | A | 3930] C:\UsbFix.txt
[02/12/2012 - 20:28:35 | D ] C:\Vampire.Diaries.S04.EN
[06/12/2012 - 19:13:06 | D ] C:\WINDOWS
[06/10/2012 - 13:47:16 | N | 33407] F:\103_cz.rar
[26/09/2012 - 18:52:07 | N | 21234] F:\401_cz.rar
[26/09/2012 - 20:06:53 | N | 23857] F:\402_cz (1).rar
[06/10/2012 - 13:48:09 | N | 26677] F:\403_cz.rar
[06/10/2012 - 13:49:59 | N | 22994] F:\404_cz.rar
[04/08/2012 - 17:32:05 | D ] F:\51
[04/08/2012 - 17:32:08 | D ] F:\53
[04/08/2012 - 17:46:23 | D ] F:\55
[29/11/2012 - 10:55:22 | N | 244869210] F:\Arrow.S01E07.HDTV.x264-LOL.[VTV].mp4
[21/01/2012 - 18:12:17 | RASHD ] F:\Autorun.inf
[19/11/2012 - 06:17:28 | N | 70044] F:\Dexter - 07x08 - Argentina.ASAP.English.C.orig.srt
[26/11/2012 - 07:18:34 | N | 69065] F:\Dexter - 07x09 - Helter Skelter.ASAP.English.HI.C.orig.srt
[12/11/2012 - 05:05:56 | N | 68704] F:\Dexter.S07E07.HDTV.x264-ASAP.srt
[12/11/2012 - 16:14:31 | N | 365720920] F:\Dexter.S07E07.HDTV.x264-ASAP.[VTV].mp4
[19/11/2012 - 09:53:52 | N | 395073547] F:\Dexter.S07E08.HDTV.x264-ASAP.mp4
[26/11/2012 - 13:04:58 | N | 442632225] F:\Dexter.S07E09.HDTV.x264-ASAP.mp4
[03/12/2012 - 18:12:21 | N | 410504457] F:\Dexter.S07E10.HDTV.x264-ASAP.mp4
[03/12/2012 - 18:21:12 | N | 69147] F:\Dexter.S07E10.HDTV.x264-ASAP_en1.srt
[27/06/2012 - 13:47:26 | N | 133822] F:\Driver Analysis for FRITZOVI-76AC45.html
[26/06/2012 - 20:36:16 | D ] F:\Driveri
[26/06/2012 - 19:08:33 | N | 8727784] F:\driverrobot_setup.exe
[04/08/2012 - 17:45:05 | D ] F:\Hack-Slash 016 (2012) (Digital) (Nahga-Empire)
[06/10/2012 - 13:56:06 | N | 14740185] F:\Journey into Mystery 625SK.rar
[09/11/2012 - 23:51:54 | N | 12442] F:\Koniec sveta sa dnes nekoná.docx
[09/08/2012 - 18:11:50 | N | 16604] F:\Káry čo ma desia.docx
[03/12/2012 - 18:22:38 | N | 51377] F:\Misfits - 04x06 - Series 4, Episode 6.FoV.English.C.orig.Addic7ed.com.srt
[19/11/2012 - 14:17:55 | N | 303138090] F:\misfits.4x04.hdtv_x264-fov.mp4
[03/12/2012 - 18:10:05 | N | 326115549] F:\Misfits.4x06.HDTV.x264-FoV.mp4
[05/11/2012 - 21:14:25 | N | 48209] F:\Misfits.S04E02.480p.HDTV.x264-SM.srt
[26/11/2012 - 12:58:04 | N | 222143107] F:\Misfits.S04E05.480p.HDTV.x264-SM.mkv
[26/11/2012 - 12:24:34 | N | 48417] F:\Misfits.S04E05.480p.HDTV.x264-SM.srt
[21/09/2012 - 21:10:00 | N | 13524] F:\O gume.docx
[08/05/2012 - 13:22:56 | N | 46592] F:\Pod hladinou.doc
[06/10/2012 - 14:02:55 | D ] F:\Revolution 2012 S01E03 HDTV x264-LOL[ettv]
[19/09/2012 - 22:18:18 | N | 15998] F:\románový export 11 prvý pokus.docx
[09/08/2012 - 22:01:26 | N | 19167] F:\románový export 8 prvý pokus.docx
[28/01/2012 - 19:03:18 | SHD ] F:\System Volume Information
[06/12/2012 - 19:09:44 | N | 1271879] F:\UsbFix.exe
[05/10/2012 - 20:53:46 | N | 18878] F:\Venuša.docx
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_SLAVOKNOTEBOOK.zip
http://eldesaparecido.com/upload.php
Thank you for your contribution.
################## | E.O.F |
User: Mama (Administrator) # SLAVOKNOTEBOOK
Updated 15/08/2012 by El Desaparecido
Started at 19:11:19 | 06/12/2012
Website: http://eldesaparecido.com
Forum: http://forum.eldesaparecido.com
Suspicious file ? : http://eldesaparecido.com/upload.php
Contact: contact@eldesaparecido.com
PC: Hewlett-Packard (HP Compaq nx6325 (EY343EA#AKR)) (X86-based PC) # Notebook
CPU: Mobile AMD Sempron(tm) Processor 3500+ (1795)
RAM -> [Total : 447 | Free : 128]
BIOS: KBC Version 40.15
BOOT: Normal boot
OS: Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 6.0.2900.5512
SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 56 Gb (16 Mb free - 28%) [] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
F:\ -> Removable drive # 7 Gb (4 Mb free - 54%) [] # NTFS
G:\ -> Removable drive # 4 Gb (341 Mb free - 9%) [] # NTFS
H:\ -> Removable drive # 964 Mb (780 Mb free - 81%) [USB] # FAT
################## | Active Processes |
C:\WINDOWS\System32\smss.exe (828)
C:\WINDOWS\system32\winlogon.exe (956)
C:\WINDOWS\system32\services.exe (1000)
C:\WINDOWS\system32\lsass.exe (1012)
C:\WINDOWS\system32\Ati2evxx.exe (1184)
C:\WINDOWS\system32\svchost.exe (1204)
C:\WINDOWS\System32\svchost.exe (1328)
C:\WINDOWS\system32\Ati2evxx.exe (1484)
C:\WINDOWS\system32\spoolsv.exe (1884)
C:\Program Files\Avira\AntiVir Desktop\sched.exe (1932)
C:\WINDOWS\Explorer.EXE (628)
C:\Program Files\Analog Devices\Core\smax4pnp.exe (764)
C:\WINDOWS\system32\ctfmon.exe (772)
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (780)
C:\Program Files\Avira\AntiVir Desktop\avguard.exe (1764)
C:\WINDOWS\system32\PnkBstrA.exe (2008)
C:\WINDOWS\system32\PnkBstrB.exe (2028)
C:\WINDOWS\system32\svchost.exe (268)
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (1284)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2892)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2692)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3020)
C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3380)
C:\UsbFix\Go.exe (204)
################## | Stopped processes |
Stopped! C:\WINDOWS\system32\Ati2evxx.exe (1184)
Stopped! C:\WINDOWS\system32\Ati2evxx.exe (1484)
Stopped! C:\WINDOWS\system32\spoolsv.exe (1884)
Stopped! C:\Program Files\Avira\AntiVir Desktop\sched.exe (1932)
Stopped! C:\WINDOWS\Explorer.EXE (628)
Stopped! C:\Program Files\Analog Devices\Core\smax4pnp.exe (764)
Stopped! C:\WINDOWS\system32\ctfmon.exe (772)
Stopped! C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (780)
Stopped! C:\Program Files\Avira\AntiVir Desktop\avguard.exe (1764)
Stopped! C:\WINDOWS\system32\PnkBstrA.exe (2008)
Stopped! C:\WINDOWS\system32\PnkBstrB.exe (2028)
Stopped! C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (1284)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2892)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (2692)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3020)
Stopped! C:\Documents and Settings\Mama\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe (3380)
################## | Files # Infected Folders |
Deleted ! C:\WINDOWS\regedit.com
Deleted ! C:\Recycler\S-1-5-21-1659004503-602609370-725345543-1003
Deleted ! C:\Recycler\S-1-5-21-1659004503-602609370-725345543-1008
Deleted ! C:\Recycled\Recycled
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{081d7a2e-3c3c-11e0-959a-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{23c5d3e4-0948-11de-9123-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{3f39289f-325e-11de-9199-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{4dd89c96-bf20-11de-92f7-0017083ac8f8}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{b402c8c4-5655-11dc-8c6b-0017083ac8f8}
################## | Listing |
[26/02/2002 - 17:54:28 | N | 824] C:\AUTOEXEC.BAT
[05/12/2012 - 11:34:10 | N | 258] C:\boot.ini
[25/10/2001 - 13:00:00 | N | 4952] C:\Bootfont.bin
[15/03/2007 - 18:29:36 | N | 512] C:\bootsect.dos
[18/06/2011 - 20:51:00 | D ] C:\Buffcool
[02/12/2012 - 12:20:09 | D ] C:\Buffy originál
[05/12/2012 - 13:41:36 | D ] C:\Config.Msi
[05/04/2003 - 08:05:34 | N | 4881] C:\CONFIG.SYS
[15/08/2002 - 22:59:16 | N | 18353] C:\COPYING
[05/12/2012 - 13:37:01 | D ] C:\Documents and Settings
[27/11/2012 - 20:48:46 | D ] C:\Downloads
[06/03/2004 - 00:36:22 | N | 512] C:\FDOSBOOT.BIN
[28/02/2008 - 15:34:32 | D ] C:\FOUND.000
[16/03/2008 - 12:33:10 | D ] C:\FOUND.001
[18/03/2008 - 12:57:50 | D ] C:\FOUND.002
[30/01/1997 - 23:00:00 | N | 447] C:\INFO.BOM
[15/03/2007 - 18:46:54 | N | 0] C:\IO.SYS
[24/09/2003 - 20:58:54 | N | 45908] C:\KERNEL.SYS
[20/09/2012 - 17:43:26 | N | 628986728] C:\Killtmonrskgdm.blRay-HD3D.mkv
[20/09/2012 - 17:43:54 | N | 84005] C:\Killtmonrskgdm.blRay-HD3D.srt
[01/12/2012 - 10:35:36 | N | 283304] C:\lxccscan.log
[26/11/2012 - 20:57:12 | N | 271219795] C:\misfits.4x05.hdtv_x264-fov.mp4
[28/11/2012 - 00:16:46 | N | 48944] C:\misfits.4x05.hdtv_x264-fov.srt
[15/03/2007 - 18:46:54 | N | 0] C:\MSDOS.SYS
[13/06/2008 - 17:42:06 | RHD ] C:\MSOCache
[15/03/2007 - 18:16:24 | D ] C:\NC
[03/08/2004 - 19:38:34 | N | 47564] C:\NTDETECT.COM
[16/10/2010 - 23:34:39 | N | 250576] C:\ntldr
[11/10/2011 - 21:07:01 | D ] C:\Onizuka Sensei
[06/12/2012 - 18:30:23 | ASH | 704643072] C:\pagefile.sys
[26/09/2003 - 00:04:34 | N | 7358] C:\POSTINST.BAT
[05/12/2012 - 13:35:26 | D ] C:\Program Files
[26/12/2007 - 20:58:48 | D ] C:\Qoobox
[28/04/2008 - 14:30:50 | D ] C:\Recycled
[06/12/2012 - 19:13:08 | SHD ] C:\RECYCLER
[20/11/2009 - 23:26:57 | RSHD ] C:\RESTORE
[28/10/2012 - 15:20:21 | D ] C:\STEP software
[25/04/2008 - 09:58:54 | SHD ] C:\System Volume Information
[06/12/2012 - 19:13:08 | D ] C:\UsbFix
[06/12/2012 - 19:13:09 | A | 3930] C:\UsbFix.txt
[02/12/2012 - 20:28:35 | D ] C:\Vampire.Diaries.S04.EN
[06/12/2012 - 19:13:06 | D ] C:\WINDOWS
[06/10/2012 - 13:47:16 | N | 33407] F:\103_cz.rar
[26/09/2012 - 18:52:07 | N | 21234] F:\401_cz.rar
[26/09/2012 - 20:06:53 | N | 23857] F:\402_cz (1).rar
[06/10/2012 - 13:48:09 | N | 26677] F:\403_cz.rar
[06/10/2012 - 13:49:59 | N | 22994] F:\404_cz.rar
[04/08/2012 - 17:32:05 | D ] F:\51
[04/08/2012 - 17:32:08 | D ] F:\53
[04/08/2012 - 17:46:23 | D ] F:\55
[29/11/2012 - 10:55:22 | N | 244869210] F:\Arrow.S01E07.HDTV.x264-LOL.[VTV].mp4
[21/01/2012 - 18:12:17 | RASHD ] F:\Autorun.inf
[19/11/2012 - 06:17:28 | N | 70044] F:\Dexter - 07x08 - Argentina.ASAP.English.C.orig.srt
[26/11/2012 - 07:18:34 | N | 69065] F:\Dexter - 07x09 - Helter Skelter.ASAP.English.HI.C.orig.srt
[12/11/2012 - 05:05:56 | N | 68704] F:\Dexter.S07E07.HDTV.x264-ASAP.srt
[12/11/2012 - 16:14:31 | N | 365720920] F:\Dexter.S07E07.HDTV.x264-ASAP.[VTV].mp4
[19/11/2012 - 09:53:52 | N | 395073547] F:\Dexter.S07E08.HDTV.x264-ASAP.mp4
[26/11/2012 - 13:04:58 | N | 442632225] F:\Dexter.S07E09.HDTV.x264-ASAP.mp4
[03/12/2012 - 18:12:21 | N | 410504457] F:\Dexter.S07E10.HDTV.x264-ASAP.mp4
[03/12/2012 - 18:21:12 | N | 69147] F:\Dexter.S07E10.HDTV.x264-ASAP_en1.srt
[27/06/2012 - 13:47:26 | N | 133822] F:\Driver Analysis for FRITZOVI-76AC45.html
[26/06/2012 - 20:36:16 | D ] F:\Driveri
[26/06/2012 - 19:08:33 | N | 8727784] F:\driverrobot_setup.exe
[04/08/2012 - 17:45:05 | D ] F:\Hack-Slash 016 (2012) (Digital) (Nahga-Empire)
[06/10/2012 - 13:56:06 | N | 14740185] F:\Journey into Mystery 625SK.rar
[09/11/2012 - 23:51:54 | N | 12442] F:\Koniec sveta sa dnes nekoná.docx
[09/08/2012 - 18:11:50 | N | 16604] F:\Káry čo ma desia.docx
[03/12/2012 - 18:22:38 | N | 51377] F:\Misfits - 04x06 - Series 4, Episode 6.FoV.English.C.orig.Addic7ed.com.srt
[19/11/2012 - 14:17:55 | N | 303138090] F:\misfits.4x04.hdtv_x264-fov.mp4
[03/12/2012 - 18:10:05 | N | 326115549] F:\Misfits.4x06.HDTV.x264-FoV.mp4
[05/11/2012 - 21:14:25 | N | 48209] F:\Misfits.S04E02.480p.HDTV.x264-SM.srt
[26/11/2012 - 12:58:04 | N | 222143107] F:\Misfits.S04E05.480p.HDTV.x264-SM.mkv
[26/11/2012 - 12:24:34 | N | 48417] F:\Misfits.S04E05.480p.HDTV.x264-SM.srt
[21/09/2012 - 21:10:00 | N | 13524] F:\O gume.docx
[08/05/2012 - 13:22:56 | N | 46592] F:\Pod hladinou.doc
[06/10/2012 - 14:02:55 | D ] F:\Revolution 2012 S01E03 HDTV x264-LOL[ettv]
[19/09/2012 - 22:18:18 | N | 15998] F:\románový export 11 prvý pokus.docx
[09/08/2012 - 22:01:26 | N | 19167] F:\románový export 8 prvý pokus.docx
[28/01/2012 - 19:03:18 | SHD ] F:\System Volume Information
[06/12/2012 - 19:09:44 | N | 1271879] F:\UsbFix.exe
[05/10/2012 - 20:53:46 | N | 18878] F:\Venuša.docx
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_SLAVOKNOTEBOOK.zip
http://eldesaparecido.com/upload.php
Thank you for your contribution.
################## | E.O.F |
Re: preventivka stareho kompu

- Ulozte nejlepe na Plochu
- U vsech polozek udelejte zatrzitko (tim je oznacite pro skenovani)
- Kliknete na Scan
- Po dokonceni skenu se objevi log FSS.txt ten sem vlozte