



Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)
Kód: Vybrat vše
:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[CreateRestorePoint]
:services
gupdate
AdobeFlashPlayerUpdateSvc
gupdatem
:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\WINDOWS\tasks\Adobe Flash Player Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Měsíční oznamování konce poskytování služeb pro Microsoft Windows XP.job
:otl
IE - HKLM\..\URLSearchHook: - No CLSID value found
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\URLSearchHook: - No CLSID value found
IE - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe File not found
O9 - Extra 'Tools' menuitem : ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe File not found
O15 - HKLM\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([etrading] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mojebanka.cz ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: ([]msn in My Computer)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: localhost ([]http in Internet)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([*] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([etrading] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([sign] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojebanka.cz ([www] https in Trusted sites)
O15 - HKU\S-1-5-21-329068152-1078081533-839522115-1003\..Trusted Domains: mojeplatba.cz ([www] https in Trusted sites)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
[2008.05.29 09:07:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ICQ Toolbar
[2008.09.19 19:33:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\pocitac\Data aplikací\ESET
[2013.05.12 13:19:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[29 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[3 C:\WINDOWS\Globalization\*.tmp files -> C:\WINDOWS\Globalization\*.tmp -> ]
[3 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\06620c7b1db9765396cb9665461ee743\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\06620c7b1db9765396cb9665461ee743\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\111513dc05eb541ecc5e6b3b1828572b\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\111513dc05eb541ecc5e6b3b1828572b\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\19dbc9ddb70fd9c4ebcebff519e945a6\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\19dbc9ddb70fd9c4ebcebff519e945a6\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\25c9064b7f6c54426934bec83d91c7fa\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\25c9064b7f6c54426934bec83d91c7fa\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\2e08f215e20e73d0029fbbcc34710bb8\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\2e08f215e20e73d0029fbbcc34710bb8\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\2e388494bddf17e38d98d1636abe38c5\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\2e388494bddf17e38d98d1636abe38c5\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\30ac3e25776f287599e730665baf9314\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\30ac3e25776f287599e730665baf9314\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\31cdb2744333b76b9c05de01d88e9723\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\31cdb2744333b76b9c05de01d88e9723\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\4714635eedfab2ea52e0ae109642cf08\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\4714635eedfab2ea52e0ae109642cf08\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\4a6ebf52efbec44d28d5c0135c216a55\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\4a6ebf52efbec44d28d5c0135c216a55\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\5bb95c58dabd9a23775b7de0f3523176\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\5bb95c58dabd9a23775b7de0f3523176\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\741de8ed746d624fbf64b4b2dfcc6b20\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\741de8ed746d624fbf64b4b2dfcc6b20\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\749a50d8acbc46b72e35cabcff87e207\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\749a50d8acbc46b72e35cabcff87e207\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7c4ef551e9870b02a2c4f2ccdb0f1681\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7c4ef551e9870b02a2c4f2ccdb0f1681\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\7f66daa47a40dc41b0d7fb589e125ac2\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\7f66daa47a40dc41b0d7fb589e125ac2\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\9500ee49543bc5a0500280fd21265403\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\9500ee49543bc5a0500280fd21265403\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\ad6d3a2b5d58e4a2aa3165693404efb8\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\ad6d3a2b5d58e4a2aa3165693404efb8\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\b4ccf90cba244e6dadbae18938ad1aee\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\bf374b2d169e42120c7c1270e9577152\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\bf374b2d169e42120c7c1270e9577152\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f0e463b1bba7747ae839cdace6593161\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f0e463b1bba7747ae839cdace6593161\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\f2eb137e9f93ae1346cdad7b147c0149\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\f2eb137e9f93ae1346cdad7b147c0149\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\fd674b0793556498419dc6d88ead9cda\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\fd674b0793556498419dc6d88ead9cda\*.tmp -> ]
[1 C:\WINDOWS\SoftwareDistribution\Download\fe61c629c8f74ff0b36cb17d266219b9\*.tmp files -> C:\WINDOWS\SoftwareDistribution\Download\fe61c629c8f74ff0b36cb17d266219b9\*.tmp -> ]
[19 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
[1 C:\WINDOWS\twain_32\*.tmp files -> C:\WINDOWS\twain_32\*.tmp -> ]
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:D1B5B4F1
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Po restartu se objevi novy log, ten sem dejte.