Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#1 Příspěvek od Maajk »

Dobry den,

chtel bych mistni guru moc poprosit o radu, jelikoz jsem jiz po x dennich (defakto) marnych snahach o znovudostani meho pc do bezneho stavu, opravdu sileny ...

K problemu - nejprve po nainstalovani TuneUp Utilities 2010 a snaze si zkontrolovat disk na chyby, mi zacal system hned po nejblizsim restartu stavkovat (pri bootovaci obrazovce okynek proste nahly restart), zkousel jsem vse mozne, az doslo na opravovani windowsu (resp. to preinstalovani se zachovanim uzivatelskych dat) ...

Nacez jsem zajasal, ze mam opet fncni system i s nainstalovanymi programi a nastavenym prostredim, ale ejhle ...
pri spousteni urcitych veci (a to po kazdem spusteni pocitace znovu a znovu) vyskakuje instalacni tabulka .. At uz chci zapnout excel, ci spustit akci, jenz si zada explorer (ne IE) - otevreni nejakeho disku, ci ovladacich panelu, apod. ... ,
tak mi nejprve naskoci informacni okno Microsoft installeru ...

Navic, prestal fungovat NOD (zkousel jsem verzi 4 a ta mi pri spusteni hazi "chyba pri komunikaci s jadrem programu).
Zaroven je nefunkcni defaultni windows firewall - otevru-li si jej z ovladacich panelu, tak jej nemuzu vypnout ani zapnout (veskera uvodni zalozka "Obecné" ma sedive zaklikavaci/zaskrtavaci formulare) ...

V Centru zabezpeceni jsou nasledujici informace: brana firewall - neni sledovano, automaticke aktualizace - zkontrolujte nastaveni a ochrana proti virum - vypnuto ...

Predtim bylo vse v poradku ("zelene" :-) ...

Cely system (XP SP II CZ) vyjma vyse zmineneho je ted dost nestabilni, nespolehlivy (dela, si co chce - viz. i widlacke zvuky - mam je vsechny ztlumene a presto jsou slyset pri prochazeni adresaru v pruzkumniku) a predevsim x krat zpomaleny ... Coz mi nejde na rozum, protoze o PC pravidelne pecuji a neinstaluji ptakoviny ...


Dokazal by mi prosim nekdo poradit, jak na patrne virove mrsky, ktere si ted paraziti ve strevech meho PC ?:(


Dekuji MNOHKRAT za kazdou radu ... :oops:

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#2 Příspěvek od Maajk »

pridavam log:
==================================================



Logfile of random's system information tool 1.06 (written by random/random)
Run by Majk at 2010-01-11 15:27:28
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 25 GB (33%) free of 77 GB
Total RAM: 3326 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:27:42, on 11. 1. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RevoTask.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe
C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MatLab\webserver\bin\win32\matlabserver.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NOD32\nod32krn.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\Program Files\Cyberlink\Shared Files\RichVideo.exe
C:\Program Files\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\PROGRA~1\OBJECT~1\DesktopX\dxwidget.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Object Desktop\DesktopX\DesktopX.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Majk\Plocha\RSIT.exe
C:\Program Files\trend micro\Majk.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.idnes.cz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = cache.sh.cvut.cz:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\WINDOWS\WebIE.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\WINDOWS\WebIE.dll
O4 - HKLM\..\Run: [RevoTaskbarApp] C:\WINDOWS\system32\RevoTask.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [Norton Ghost 12.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\DOCUME~1\Majk\LOCALS~1\Temp\E_S16E5.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [mRouterConfig] "C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_1_0
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: BlueSoleil.lnk = C:\Program Files\BlueSoleil\gprs.exe
O4 - Startup: c242 Silica Mailinfo.lnk = C:\Program Files\Object Desktop\c242SilicaMail1.exe
O4 - Startup: ihaupd32.exe
O4 - Startup: Miranda.lnk = C:\Program Files\Miranda IM\miranda32.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\WINDOWS\WebIE.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\WINDOWS\WebIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MatLab\webserver\bin\win32\matlabserver.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\3D Studio Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\NOD32\nod32krn.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared Files\RichVideo.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\BlueSoleil\StartSkysolSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 13163 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\WINDOWS\WebIE.dll [2008-03-23 491520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2006-12-18 231160]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\WINDOWS\WebIE.dll [2008-03-23 491520]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RevoTaskbarApp"=C:\WINDOWS\system32\RevoTask.exe [2004-06-14 221184]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2007-08-07 200704]
""= []
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-12-03 2213160]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-01-08 68640]
"LanguageShortcut"=C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
"PC Suite for Smartphones"=C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe [2007-12-25 548864]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2010-01-07 520024]
"Norton Ghost 12.0"=C:\Program Files\Norton Ghost\Agent\VProTray.exe [2008-11-12 2037096]
"Acrobat Assistant 7.0"=C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"=C:\Program Files\CursorXP\CursorXP.exe [2003-03-01 125440]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2007-12-13 1688872]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2009-08-27 247144]
"EPSON Stylus DX7400 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE [2007-04-12 182272]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"mRouterConfig"=C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe [2006-03-02 290816]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-04-13 2387968]
"updateMgr"=C:\Program Files\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe [2006-03-30 313472]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Documents and Settings\Majk\Nabídka Start\Programy\Po spuštění
BlueSoleil.lnk - C:\Program Files\BlueSoleil\gprs.exe
c242 Silica Mailinfo.lnk - C:\Program Files\Object Desktop\c242SilicaMail1.exe
ihaupd32.exe
Miranda.lnk - C:\Program Files\Miranda IM\miranda32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-09-29 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt]
crypts.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll [2008-05-02 72208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll [2005-01-31 49152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - C:\Program Files\Common Files\stardock\MCPCore.dll [2005-01-31 98304]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSecurityTab"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\VLC media player\vlc.exe"="C:\Program Files\VLC media player\vlc.exe:*:Enabled:VLC media player"
"C:\Program Files\Total Commander\TOTALCMD.EXE"="C:\Program Files\Total Commander\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"C:\Hry\Half-Life 2\hl2.exe"="C:\Hry\Half-Life 2\hl2.exe:*:Enabled:hl2"
"C:\Program Files\CZDC++\CZDC.exe"="C:\Program Files\CZDC++\CZDC.exe:*:Enabled:CZDC"
"C:\Program Files\3D Studio Max 9\3dsmax.exe"="C:\Program Files\3D Studio Max 9\3dsmax.exe:*:Enabled:Autodesk 3ds Max 9 32-bit"
"C:\Program Files\Autodesk\Backburner\monitor.exe"="C:\Program Files\Autodesk\Backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\Backburner\manager.exe"="C:\Program Files\Autodesk\Backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\Backburner\server.exe"="C:\Program Files\Autodesk\Backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Documents and Settings\Mishek\Dokumenty\Mir4nda-IM-0.7.1-Pack-v2.0\miranda32.exe"="C:\Documents and Settings\Mishek\Dokumenty\Mir4nda-IM-0.7.1-Pack-v2.0\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\CZDC++ (out)\CZDC.exe"="C:\Program Files\CZDC++ (out)\CZDC.exe:*:Enabled:CZDC"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Hry\NHL 2002\nhl2002.exe"="C:\Hry\NHL 2002\nhl2002.exe:*:Enabled:nhl2002"
"C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe"="C:\Program Files\Common Files\Nero\Nero Web\SetupX.exe:*:Enabled:Nero ControlCenter"
"C:\Program Files\totalcmd\totalcmd.exe"="C:\Program Files\totalcmd\totalcmd.exe:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE"="C:\WINDOWS\system32\spool\drivers\w32x86\3\HP1006MC.EXE:*:Enabled:SMLMProxy Module - HP1006MC.EXE"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe"="C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe:*:Enabled:mRouterRuntime Module"
"C:\Program Files\MyPhoneExplorer\MyPhoneExplorer.exe"="C:\Program Files\MyPhoneExplorer\MyPhoneExplorer.exe:*:Enabled:MyPhoneExplorer"
"C:\Program Files\BlueSoleil\BlueSoleil.exe"="C:\Program Files\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03d78b42-5f67-11dc-87da-806d6172696f}]
shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a251300-3813-11dd-88ec-0019d1a2db7b}]
shell\AutoRun\command - G:\
shell\explore\command - RECYCLER\autorun.exe -ExploreCurDir
shell\open\command - RECYCLER\autorun.exe -OpenCurDir

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{684cfbc9-c988-11dd-8950-0019d1a2db7b}]
shell\AutoRun\command - wd_windows_tools\WDSetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87199253-9b19-11de-8518-001fcf204e46}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL mONItInFO.eXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae342d70-51c9-11de-ab6a-001fcf204e46}]
shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d74af648-ed90-11de-b1cf-001fcf204e46}]
shell\AutoRun\command - setupSNK.exe


======File associations======

.scr - open - "C:\WINDOWS\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-01-11 15:27:29 ----D---- C:\Program Files\trend micro
2010-01-11 15:27:28 ----D---- C:\rsit
2010-01-11 15:16:34 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-01-11 15:16:28 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-01-11 15:16:22 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-01-11 15:16:16 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-01-11 15:16:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-01-11 15:16:05 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-01-11 15:15:56 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-01-11 15:15:50 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-01-11 15:15:43 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2010-01-11 15:15:37 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-01-11 15:15:31 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-01-11 15:15:21 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-01-11 15:15:15 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-01-11 15:15:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-01-11 15:15:04 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-01-11 15:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-01-11 15:14:44 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-01-11 15:14:36 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-01-11 15:14:28 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-01-11 15:14:22 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$
2010-01-11 15:14:13 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-01-11 15:14:07 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-01-11 15:14:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2010-01-11 15:13:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-01-11 15:13:48 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-01-11 15:13:35 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2010-01-11 15:13:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-01-11 15:13:22 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-01-11 15:12:49 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-01-11 15:12:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-01-11 15:12:37 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-01-11 15:12:32 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-01-11 15:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-01-11 15:12:20 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-01-11 15:12:14 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-01-11 15:12:05 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-01-11 15:11:58 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-01-11 15:11:52 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-01-11 15:11:46 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-01-11 15:11:40 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-01-11 15:11:34 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-01-11 15:11:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-01-11 15:11:18 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-01-11 15:11:13 ----HDC---- C:\WINDOWS\$NtUninstallKB901190$
2010-01-11 15:11:07 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-01-11 15:11:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-01-11 15:10:52 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2010-01-11 15:10:45 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-01-11 15:10:38 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-01-11 15:10:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-01-11 15:10:27 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2010-01-11 15:10:20 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-01-11 15:10:14 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-01-11 15:10:07 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-01-11 15:09:58 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-01-11 12:45:07 ----A---- C:\liom.exe
2010-01-11 03:03:52 ----D---- C:\Program Files\VITSOFT
2010-01-11 03:02:01 ----D---- C:\WINDOWS\system32\CatRoot_bak
2010-01-11 02:35:05 ----D---- C:\Program Files\ESET
2010-01-11 02:35:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-01-10 20:31:01 ----A---- C:\WINDOWS\system32\TUKernel.exe
2010-01-10 17:56:51 ----D---- C:\WINDOWS\Prefetch
2010-01-10 17:50:18 ----D---- C:\Program Files\msn gaming zone
2010-01-10 17:49:12 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-01-10 17:18:40 ----A---- C:\WINDOWS\pnplog.txt
2010-01-10 17:11:53 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-01-10 17:11:53 ----A---- C:\WINDOWS\system32\irclass.dll
2010-01-10 17:11:38 ----RA---- C:\WINDOWS\SET12A.tmp
2010-01-10 17:11:35 ----RA---- C:\WINDOWS\SET11E.tmp
2010-01-10 17:11:33 ----RA---- C:\WINDOWS\SET11B.tmp
2010-01-09 20:05:48 ----A---- C:\WINDOWS\system32\DROPPEDFILEOKppi1.tmp
2010-01-09 20:05:31 ----RSH---- C:\WINDOWS\System.exe
2010-01-09 19:22:04 ----D---- C:\Program Files\TuneUp Utilities
2010-01-09 18:01:21 ----SHD---- C:\Config.Msi
2010-01-09 17:59:30 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-01-09 17:58:42 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-01-08 18:21:44 ----A---- C:\WINDOWS\system32\lsdelete.exe
2010-01-07 19:20:20 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{83C91755-2546-441D-AC40-9A6B4B860800}
2010-01-07 19:20:14 ----D---- C:\Program Files\Lavasoft
2010-01-07 19:20:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-01-04 05:52:08 ----A---- C:\WINDOWS\Systems.exe
2010-01-04 01:21:11 ----A---- C:\WINDOWS\system32\javaws.exe
2010-01-04 01:21:11 ----A---- C:\WINDOWS\system32\javaw.exe
2010-01-04 01:21:11 ----A---- C:\WINDOWS\system32\java.exe

======List of files/folders modified in the last 1 months======

2010-01-11 15:27:29 ----RAD---- C:\Program Files
2010-01-11 15:25:05 ----D---- C:\WINDOWS\Temp
2010-01-11 15:23:09 ----SHD---- C:\WINDOWS\Installer
2010-01-11 15:23:00 ----D---- C:\Program Files\Mozilla Firefox
2010-01-11 15:22:25 ----D---- C:\Program Files\Microsoft ActiveSync
2010-01-11 15:21:57 ----D---- C:\WINDOWS
2010-01-11 15:21:57 ----A---- C:\WINDOWS\MAILTRAN.INI
2010-01-11 15:21:07 ----D---- C:\WINDOWS\system32
2010-01-11 15:19:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-01-11 15:19:52 ----D---- C:\WINDOWS\system32\wbem
2010-01-11 15:19:52 ----D---- C:\WINDOWS\system32\Setup
2010-01-11 15:19:52 ----D---- C:\WINDOWS\system32\drivers
2010-01-11 15:19:52 ----D---- C:\WINDOWS\AppPatch
2010-01-11 15:16:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-01-11 15:16:36 ----HD---- C:\WINDOWS\inf
2010-01-11 15:16:31 ----A---- C:\WINDOWS\imsins.BAK
2010-01-11 15:15:28 ----D---- C:\WINDOWS\system32\CatRoot2
2010-01-11 15:15:28 ----D---- C:\WINDOWS\system32\CatRoot
2010-01-11 15:15:20 ----HD---- C:\WINDOWS\$hf_mig$
2010-01-11 15:13:41 ----D---- C:\Program Files\Internet Explorer
2010-01-11 15:12:22 ----D---- C:\Program Files\Outlook Express
2010-01-11 15:06:55 ----D---- C:\Program Files\NOD32
2010-01-11 15:01:20 ----D---- C:\Program Files\CZDC++
2010-01-11 14:35:51 ----D---- C:\Program Files\LogonStudio
2010-01-11 13:51:53 ----A---- C:\WINDOWS\ODBC.INI
2010-01-11 13:31:53 ----D---- C:\WINDOWS\WinSxS
2010-01-11 13:31:52 ----D---- C:\WINDOWS\SxsCaPendDel
2010-01-11 13:27:55 ----D---- C:\Program Files\Adobe
2010-01-11 13:20:51 ----A---- C:\WINDOWS\LogonStudio.ini
2010-01-11 10:04:29 ----D---- C:\WINDOWS\Microsoft.NET
2010-01-11 09:23:06 ----D---- C:\Program Files\Norton Ghost
2010-01-11 02:52:45 ----ASH---- C:\boot.ini
2010-01-11 02:51:08 ----D---- C:\WINDOWS\system32\appmgmt
2010-01-11 02:49:57 ----SD---- C:\WINDOWS\Tasks
2010-01-11 02:48:38 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-01-11 02:06:35 ----D---- C:\WINDOWS\system32\config
2010-01-10 23:02:32 ----D---- C:\WINDOWS\SoftwareDistribution
2010-01-10 23:02:29 ----D---- C:\WINDOWS\Help
2010-01-10 21:01:04 ----D---- C:\WINDOWS\security
2010-01-10 20:23:03 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-01-10 20:21:01 ----D---- C:\Program Files\Loli Video Converter
2010-01-10 20:00:41 ----D---- C:\Documents and Settings\Majk\Data aplikací\Skype
2010-01-10 19:00:47 ----SHD---- C:\System Volume Information
2010-01-10 18:49:00 ----D---- C:\Hry
2010-01-10 18:48:34 ----D---- C:\Program Files\Foxit Software
2010-01-10 18:45:18 ----D---- C:\Program Files\Adobe Photoshop CS2
2010-01-10 18:41:25 ----D---- C:\Program Files\Color Scheme Editor
2010-01-10 18:39:01 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2010-01-10 18:06:56 ----D---- C:\WINDOWS\system32\usmt
2010-01-10 18:06:42 ----D---- C:\WINDOWS\ehome
2010-01-10 18:06:41 ----D---- C:\WINDOWS\ime
2010-01-10 18:06:39 ----RSD---- C:\WINDOWS\Fonts
2010-01-10 18:06:38 ----D---- C:\WINDOWS\Media
2010-01-10 18:06:23 ----D---- C:\WINDOWS\PeerNet
2010-01-10 18:06:06 ----D---- C:\WINDOWS\system32\npp
2010-01-10 18:05:56 ----D---- C:\WINDOWS\msagent
2010-01-10 18:03:22 ----D---- C:\WINDOWS\system32\1029
2010-01-10 18:03:10 ----D---- C:\WINDOWS\twain_32
2010-01-10 18:02:49 ----D---- C:\WINDOWS\system32\icsxml
2010-01-10 18:02:12 ----D---- C:\WINDOWS\system32\ias
2010-01-10 18:02:03 ----D---- C:\WINDOWS\system32\1033
2010-01-10 18:00:41 ----D---- C:\WINDOWS\Driver Cache
2010-01-10 17:59:18 ----D---- C:\WINDOWS\Registration
2010-01-10 17:57:50 ----D---- C:\WINDOWS\system32\Restore
2010-01-10 17:57:34 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-01-10 17:56:19 ----D---- C:\WINDOWS\system32\inetsrv
2010-01-10 17:50:13 ----D---- C:\Program Files\Windows Media Player
2010-01-10 17:49:59 ----A---- C:\WINDOWS\OEWABLog.txt
2010-01-10 17:49:52 ----A---- C:\WINDOWS\ODBCINST.INI
2010-01-10 17:49:14 ----RD---- C:\WINDOWS\Web
2010-01-10 17:49:07 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-01-10 17:48:55 ----A---- C:\WINDOWS\win.ini
2010-01-10 17:48:49 ----D---- C:\WINDOWS\system32\oobe
2010-01-10 17:48:47 ----D---- C:\WINDOWS\srchasst
2010-01-10 17:48:39 ----D---- C:\Program Files\Movie Maker
2010-01-10 17:48:28 ----D---- C:\Program Files\NetMeeting
2010-01-10 17:48:24 ----D---- C:\Program Files\Common Files\System
2010-01-10 17:47:36 ----D---- C:\WINDOWS\system32\Com
2010-01-10 17:47:06 ----D---- C:\Program Files\Windows NT
2010-01-10 17:11:59 ----A---- C:\WINDOWS\system.ini
2010-01-10 17:11:53 ----D---- C:\WINDOWS\system
2010-01-10 17:11:45 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2010-01-09 19:46:52 ----D---- C:\Program Files\TuneUp Utilities 2009
2010-01-09 18:00:14 ----D---- C:\Documents and Settings\Majk\Data aplikací\uTorrent
2010-01-09 17:59:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2010-01-09 17:22:06 ----D---- C:\Documents and Settings\Majk\Data aplikací\Lavasoft
2010-01-09 16:09:44 ----D---- C:\Documents and Settings\Majk\Data aplikací\skypePM
2010-01-07 19:22:09 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-01-07 12:21:36 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-01-07 12:20:22 ----D---- C:\Documents and Settings\Majk\Data aplikací\MyPhoneExplorer
2010-01-07 12:14:20 ----D---- C:\Program Files\Movavi VideoSuite 7
2010-01-07 12:13:51 ----D---- C:\Program Files\VS Revo Group
2010-01-05 20:02:08 ----D---- C:\Program Files\Common Files\Adobe
2010-01-04 01:21:09 ----D---- C:\Program Files\Java
2010-01-04 01:13:39 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-12-21 00:03:04 ----D---- C:\Program Files\BSPlayer Pro
2009-12-13 00:42:21 ----A---- C:\WINDOWS\NeroDigital.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-17 39936]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 KGootkit;KGootkit; C:\WINDOWS\System32\drivers\KGootkit.sys [2010-01-11 33888]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2007-08-07 33052]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 Prvflder;Prvflder; C:\WINDOWS\system32\DRIVERS\prvflder.sys [2006-04-21 70912]
R2 v2imount;Symantec V2i Mount Driver; C:\WINDOWS\system32\DRIVERS\v2imount.sys [2007-03-28 37864]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-09-29 2456064]
R3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2007-06-24 34312]
R3 BlueletSCOAudio;Bluetooth SCO Audio Service; C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [2007-06-24 27656]
R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2007-03-05 18320]
R3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2007-06-24 38920]
R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2007-06-15 254872]
R3 GEARAspiWDM;GearAspiWDM; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2007-03-28 15664]
R3 HECI;Intel(R) Management Engine Interface; C:\WINDOWS\system32\DRIVERS\HECI.sys [2007-03-13 44672]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\WINDOWS\system32\DRIVERS\L8042Kbd.sys [2008-02-29 20240]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2008-02-29 35344]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2008-02-29 36880]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-12-17 47360]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-08-11 14604]
R3 REVO;Service for Revo Driver (WDM); C:\WINDOWS\system32\drivers\revo.sys [2004-06-15 119680]
R3 REVOSENS;REVOSENS; C:\WINDOWS\system32\drivers\revosens.sys [2004-06-14 400640]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2001-10-25 5888]
R3 skbusenum;SKBus Enumerator; C:\WINDOWS\system32\DRIVERS\skbusenum.sys [2004-12-16 10880]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2007-03-05 34448]
R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2007-03-05 44304]
R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 10144]
R3 WmXlCore;Logitech WingMan Translation Layer Driver; C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 45504]
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM); C:\WINDOWS\system32\DRIVERS\zebrceb.sys [2008-01-15 63360]
S2 AMON;AMON; \??\C:\WINDOWS\system32\drivers\amon.sys []
S3 AVerBDA3x;AVerMedia SAA713x BDA Service; C:\WINDOWS\system32\DRIVERS\AVerBDA3x.sys [2006-12-14 1171456]
S3 Bluesdfu;Blues USB DFU; C:\WINDOWS\System32\Drivers\Bluesdfu.sys [2007-06-08 15616]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 ggflt;SEMC USB Flash Driver Filter; C:\WINDOWS\system32\DRIVERS\ggflt.sys [2009-11-19 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\WINDOWS\system32\DRIVERS\ggsemc.sys [2009-11-19 25512]
S3 GMFilter;GMFilter HID Filter Driver; C:\WINDOWS\system32\DRIVERS\GMFilter.sys [2005-08-23 21760]
S3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2008-02-18 96256]
S3 motccgp;Motorola USB Composite Device Driver; C:\WINDOWS\system32\DRIVERS\motccgp.sys []
S3 motccgpfl;MotCcgpFlService; C:\WINDOWS\system32\DRIVERS\motccgpfl.sys []
S3 MotDev;Motorola Inc. USB Device; C:\WINDOWS\system32\DRIVERS\motodrv.sys []
S3 motmodem;Motorola USB CDC ACM Driver; C:\WINDOWS\system32\DRIVERS\motmodem.sys []
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-17 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-17 10880]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\WINDOWS\system32\DRIVERS\s1018bus.sys [2009-11-19 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s1018mdfl.sys [2009-11-19 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s1018mdm.sys [2009-11-19 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s1018mgmt.sys [2009-11-19 108200]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\WINDOWS\system32\DRIVERS\s1018nd5.sys [2009-11-19 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s1018obex.sys [2009-11-19 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\WINDOWS\system32\DRIVERS\s1018unic.sys [2009-11-19 109736]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-05-01 61600]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-05-01 9360]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-05-01 97184]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-05-01 88688]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS); C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-05-01 18704]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-05-01 86560]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM); C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-05-01 90800]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbser;Motorola A1000 USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2004-08-17 25600]
S3 vaxscsi;vaxscsi; C:\WINDOWS\System32\Drivers\vaxscsi.sys [2008-04-01 223128]
S3 VProEventMonitor;Symantec Event Monitor Driver; C:\WINDOWS\system32\DRIVERS\vproeventmonitor.sys [2007-07-31 14072]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2004-08-17 31744]
S3 WimFltr;WimFltr; C:\WINDOWS\system32\DRIVERS\wimfltr.sys [2007-03-28 128104]
S3 WINIO;WINIO; \??\C:\WINDOWS\system32\winio.sys []
S3 WmFilter;Logitech Gaming HID Filter Driver; C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 22240]
S3 WmVirHid;Logitech Virtual Hid Device Driver; C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 5600]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 zebrbus;Sony Ericsson Composite Device driver; C:\WINDOWS\system32\DRIVERS\zebrbus.sys [2008-01-15 83200]
S3 zebrmdfl;Sony Ericsson Modem Filter; C:\WINDOWS\system32\DRIVERS\zebrmdfl.sys [2008-01-15 14848]
S3 zebrmdm;Sony Ericsson Port (WDM); C:\WINDOWS\system32\DRIVERS\zebrmdm.sys [2008-01-15 109568]
S3 zebrmdmc;Sony Ericsson mRouter Port (WDM); C:\WINDOWS\system32\DRIVERS\zebrmdmc.sys [2008-01-15 109568]
S3 zebrsce;Sony Ericsson PC-Connect Port; C:\WINDOWS\system32\DRIVERS\zebrsce.sys [2008-01-15 91264]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-09-29 483328]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2007-10-22 72704]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2007-09-12 554352]
R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\BlueSoleil\BTNtService.exe [2007-12-27 166520]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 matlabserver;MATLAB Server; C:\Program Files\MatLab\webserver\bin\win32\matlabserver.exe [2004-12-27 536576]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\NOD32\nod32krn.exe [2007-09-10 507904]
R2 Norton Ghost;Norton Ghost; C:\Program Files\Norton Ghost\Agent\VProSvc.exe [2008-11-12 3425632]
R2 prfldsvc;Private Folder Service; C:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe [2006-04-21 69632]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\Cyberlink\Shared Files\RichVideo.exe [2007-01-08 171040]
R2 Start BT in service;Start BT in service; C:\Program Files\BlueSoleil\StartSkysolSvc.exe [2007-12-27 51816]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2007-09-28 593920]
S2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-04-13 73728]
S2 mi-raysat_3dsmax9_32;mental ray 3.5 Satellite (32-bit); C:\Program Files\3D Studio Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe [2006-09-29 65536]
S2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
S2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-08-27 92008]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2007-09-18 72704]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-02-04 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-01-07 1028432]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2008-05-02 121360]
S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-09-12 2999664]
S3 Macromedia Licensing Service;Macromedia Licensing Service; C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe [2007-11-18 68096]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-06-14 74656]
S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol 120\StarWind\StarWindService.exe [2005-04-01 217600]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#3 Příspěvek od Roli »

Zdravím, i když si myslím že se jedná o hodně nakopnutý systém, zkusíme s tím i s těmi šmejdy něco udělat.

Tohle fixni v HJT :

O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_1_0
O4 - Startup: ihaupd32.exe


HJT najdeš zde :

C:\Program Files\trend micro\Majk

Fix znamená že spustíš HJT Obrázek

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

položka Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

položka Registry - tady vyčistíš registry; před použitím doporučuji udělat jejich zálohu, kterou Ccleaner nabízí,

čištění registru je třeba několikrát zopakovat !


Pak použij Mbam z mého podpisu.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#4 Příspěvek od Maajk »

Zdravim a dekuji za informace !

Mrsek je tam opravdu dost (vzhledem k tomu, co to zaclo naraz delat, jakoby se navzajem podporovaly:-), az me to opravdu zarazilo, jelikoz v PC mivam rad poradek - casto jej scannuji - poslednim ad-awarem, ktery je ale asi celkem k prdu, jak tak koukam ... mel jsem 2.5 NODa s poslednima aktualizacema, zapnuty windowsacky FW (Kerio jsem nekolikrat zkousel a vzdy me akorat pekne krklo:-), netropim na tom ptakoviny (leda obcas nejaky ten KG, ...) a takto se mi to sesype ? No, hruza .. je videt, ze clovek musi byt cim dal opatrnejsi ...


Jinak, jeste pred doporucenym HiJackem jsem zkusil UnHackMe (+reanimator), Spyware terminatora a naposled doporuceny Malware bytes a nektere problemy zmizly (treba to vyskakovani Microsoft Installera pri spousteni procesu jako pruzkumnik, office, ovladaci panely, apod. ... ) + mi prijde system uz rychlejsi, lec ...

... porad mi nejde:
- odinstalovat nektere programy
- zapnout windowsacky FW (nabidky jsou stale sedive - neklikatelne)
- nainstalovat SP III
- porad se ozyvaji zvuky v pruzkumniku, kdyz nemaji (mam nastavene schema komplet bez zvuku)


// EDIT:
po projeti Combofixem (ktery mi Reanimator oznacuje za malware) uz "funguje" defaultni XPacky firewall

co se tyce tech zvuku, tak jsem koukl podrobneji do schemat a
- nad skupinou zvuku pro pruzkumnik mam jednu prazdnou nazvanou "devenv" (nemam tuchu o tom, ze by to tam drive bylo)
- ve skupine zvuku pro pruzkumnika se mi dokola 4 sami aktivuji (at uz dam schema bez zvuku, ci je vymazu a schema ulozim jako jine a nasledne pouziji) - to vysvetluje to nechtene "rachtani" pri brouzdani po disku v exploreru, ale CO to muze mit na svedomi ?!
Naposledy upravil(a) Maajk dne 12 led 2010 00:26, celkem upraveno 1 x.

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#5 Příspěvek od Maajk »

tak - projeto i CCleanerem .. mam prihodit nejaky log ?

a co s temi flashkami, jak psal kolega, jenz pak svuj prispevek odmazl ?

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#6 Příspěvek od Maajk »

tak uz jsem z toho vazne nadrat :(
i 4. den, prestoze se blyskalo na bezproblemove casy, zacina PC opet vyhravat -
pres noc jsem nechal bezet detailni kontrolu NODem (v4) a Malwarebytes, pricemz rano koukam, ze NOD zahlasil po pulce testu krit. chybu ... tak restartuji a ejhle, po prihlaseni uzivatele to vyhodi hromadu chybovych oken - Explorer.Exe - chyba aplikace ("instrukce na adrese 0x7e379****" odkazovala na adresu paměi ...")
- a okno - Omezení spuštění dat ...

-> v tu ranu je to v pytli, nejdou nejak odklikat ci vyrusit pres spravce procesu ...
tudiz jedu opet pres nouzovy rezim, kde mne vyse zminene neotravuje ...


Prosim tedy moc o jakoukoli radu ... uz s tim bojuji 4. den a dochazeji mi sily i napady (o trpelivosti ani nemluve :( )

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#7 Příspěvek od Roli »

Ani jedna utilitka co jsi použil není všemocná, tak že bych se rád podíval na ten log z Combofix

který najdeš na C:/Combofix.txt, zda tam něco nezůstalo.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#8 Příspěvek od Maajk »

to verim .. koukam, ze te haveti je tolika, ze to jedna asi bohuzel fakt nezvladne (ostatne ted ani vicero) ...

takze, pridavam log z druheho scannu combofixem (log z prvniho testu bohuzel jiz nemam .. akorat vim, ze par veci sam odmazl ... )

Diky moc !

Jinak, nechapu, proc je v nem zminka o Ad-awaru, kdyz je davno odinstalovany (i zde recenzovanym windowsackym uninstallerem)
==================================================


ComboFix 10-01-11.01 - Majk . 01. 2010 23:58:26.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.3326.2744 [GMT 1:00]
Spuštěný z: c:\documents and settings\Majk\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-12-11 do 2010-01-11 )))))))))))))))))))))))))))))))
.

2010-01-11 22:35 . 2010-01-11 22:35 -------- d-----w- c:\windows\system32\Shared
2010-01-11 21:46 . 2010-01-11 21:46 -------- d-----w- c:\program files\CCleaner
2010-01-11 19:50 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 19:50 . 2010-01-11 19:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 19:50 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-11 18:35 . 2010-01-11 18:35 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-01-11 17:58 . 2008-06-14 18:00 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-01-11 17:58 . 2009-08-04 17:07 2059904 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-01-11 17:58 . 2009-08-04 17:07 2182528 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-01-11 17:58 . 2009-08-04 17:07 2138112 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-01-11 17:58 . 2009-08-04 17:07 2017792 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-01-11 17:57 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-01-11 16:24 . 2010-01-11 20:25 -------- d-----w- c:\program files\Crawler
2010-01-11 15:44 . 2001-10-25 12:00 6144 -c--a-w- c:\windows\system32\dllcache\pmxgl.dll
2010-01-11 15:43 . 2003-04-14 19:48 16384 -c--a-w- c:\windows\system32\dllcache\tcptsat.dll
2010-01-11 15:11 . 2001-10-25 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-01-11 15:11 . 2001-10-25 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-01-11 15:11 . 2001-10-25 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-01-11 15:11 . 2001-10-25 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-01-11 14:47 . 2010-01-11 21:26 24416 ----a-w- c:\windows\system32\drivers\regguard.sys
2010-01-11 14:35 . 2010-01-11 14:35 35040 ----a-w- c:\windows\system32\Partizan.exe
2010-01-11 14:35 . 2010-01-11 14:35 34760 ----a-w- c:\windows\system32\drivers\Partizan.sys
2010-01-11 14:35 . 2010-01-11 14:35 2 --shatr- c:\windows\winstart.bat
2010-01-11 14:34 . 2009-12-22 13:38 12752 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2010-01-11 14:34 . 2010-01-11 16:19 -------- d-----w- c:\program files\UnHackMe
2010-01-11 14:27 . 2010-01-11 21:36 -------- d-----w- c:\program files\trend micro
2010-01-11 14:27 . 2010-01-11 14:27 -------- d-----w- C:\rsit
2010-01-11 12:25 . 2010-01-11 12:25 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2010-01-11 02:03 . 2010-01-11 22:01 -------- d-----w- c:\program files\VITSOFT
2010-01-11 02:02 . 2010-01-11 02:02 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-01-11 01:35 . 2010-01-11 01:35 -------- d-----w- c:\program files\ESET
2010-01-10 19:31 . 2010-01-10 19:31 2290176 ----a-w- c:\windows\system32\TUKernel.exe
2010-01-10 16:48 . 2001-10-25 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2010-01-09 19:11 . 2010-01-09 19:11 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-09 18:22 . 2010-01-09 18:22 -------- d-----w- c:\program files\TuneUp Utilities
2010-01-09 16:59 . 2010-01-11 01:50 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-01-08 17:21 . 2010-01-07 18:21 15688 ----a-w- c:\windows\system32\lsdelete.exe
2010-01-08 15:32 . 2010-01-08 15:32 -------- d-----w- c:\documents and settings\NetworkService\Plocha
2010-01-07 18:22 . 2010-01-07 18:21 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-07 18:20 . 2010-01-11 16:21 -------- d-----w- c:\program files\Lavasoft
2010-01-04 04:52 . 2010-01-04 04:52 81920 ----a-w- c:\windows\Systems.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-11 21:31 . 2008-09-24 12:46 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-01-11 18:35 . 2008-11-05 14:14 -------- d-----w- c:\program files\MSECache
2010-01-11 16:13 . 2007-09-10 02:00 -------- d-----w- c:\program files\CZDC++
2010-01-11 15:50 . 2004-08-18 12:00 82642 ----a-w- c:\windows\system32\perfc005.dat
2010-01-11 15:50 . 2004-08-18 12:00 437336 ----a-w- c:\windows\system32\perfh005.dat
2010-01-11 15:35 . 2007-09-09 22:50 23588 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-11 14:51 . 2007-09-10 12:34 -------- d-----w- c:\program files\Common Files\stardock
2010-01-11 14:06 . 2007-09-10 00:48 -------- d-----w- c:\program files\NOD32
2010-01-11 13:35 . 2009-07-31 19:53 -------- d-----w- c:\program files\LogonStudio
2010-01-11 08:23 . 2009-03-15 15:42 -------- d-----w- c:\program files\Norton Ghost
2010-01-10 19:21 . 2008-02-20 21:41 -------- d-----w- c:\program files\Loli Video Converter
2010-01-10 17:48 . 2009-10-10 18:06 -------- d-----w- c:\program files\Foxit Software
2010-01-10 17:45 . 2007-09-18 12:26 -------- d-----w- c:\program files\Adobe Photoshop CS2
2010-01-10 17:41 . 2008-01-04 11:55 -------- d-----w- c:\program files\Color Scheme Editor
2010-01-09 19:05 . 2010-01-09 19:05 12 ----a-w- c:\windows\system32\DROPPEDFILEOKppi1.tmp
2010-01-09 18:46 . 2009-02-25 15:15 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-01-07 11:14 . 2009-11-28 10:12 -------- d-----w- c:\program files\Movavi VideoSuite 7
2010-01-07 11:13 . 2009-12-01 19:37 -------- d-----w- c:\program files\VS Revo Group
2010-01-05 19:02 . 2007-09-18 12:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-04 00:21 . 2007-09-10 03:45 -------- d-----w- c:\program files\Java
2009-12-20 23:03 . 2007-09-10 03:56 -------- d-----w- c:\program files\BSPlayer Pro
2009-12-05 17:25 . 2009-12-05 17:25 94208 ----a-w- c:\windows\system32\pkcs11wrapper.dll
2009-12-01 15:06 . 2009-11-28 15:35 -------- d-----w- c:\program files\NCH Software
2009-12-01 15:05 . 2007-09-09 23:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-29 18:31 . 2009-11-29 18:31 -------- d-----w- c:\program files\MIKSOFT
2009-11-28 11:26 . 2009-11-27 23:15 -------- d-----w- c:\program files\Pinnacle
2009-11-28 09:45 . 2009-11-28 09:05 -------- d-----w- c:\program files\MOVAVI VideoSuite 3.5
2009-11-27 22:29 . 2009-09-19 11:56 -------- d-----w- c:\program files\AviSynth 2.5
2009-11-25 15:02 . 2007-09-14 13:02 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-11-21 19:30 . 2007-12-17 21:02 -------- d-----w- c:\program files\CZDC++ (out)
2009-11-21 08:46 . 2009-11-21 08:46 86016 ----a-w- c:\windows\system32\frapsvid.dll
2009-11-20 19:07 . 2009-01-06 19:19 -------- d-----w- c:\program files\Bluetooth Remote Control 4
2009-11-19 18:13 . 2009-11-19 18:13 -------- d-----w- c:\program files\Phone Remote Control
2009-11-19 18:09 . 2009-11-19 16:17 -------- d-----w- c:\program files\ABC Amber vCard Converter
2009-11-19 16:23 . 2008-09-30 13:04 -------- d-----w- c:\program files\MyPhoneExplorer
2009-11-19 15:42 . 2009-11-19 15:42 26024 ----a-w- c:\windows\system32\drivers\s1018nd5.sys
2009-11-19 15:42 . 2009-11-19 15:42 12200 ----a-w- c:\windows\system32\drivers\s1018whnt.sys
2009-11-19 15:42 . 2009-11-19 15:42 12200 ----a-w- c:\windows\system32\drivers\s1018wh.sys
2009-11-19 15:42 . 2009-11-19 15:42 109736 ----a-w- c:\windows\system32\drivers\s1018unic.sys
2009-11-19 15:42 . 2009-11-19 15:42 104616 ----a-w- c:\windows\system32\drivers\s1018obex.sys
2009-11-19 15:42 . 2009-11-19 15:42 86696 ----a-w- c:\windows\system32\drivers\s1018bus.sys
2009-11-19 15:42 . 2009-11-19 15:42 15016 ----a-w- c:\windows\system32\drivers\s1018mdfl.sys
2009-11-19 15:42 . 2009-11-19 15:42 12200 ----a-w- c:\windows\system32\drivers\s1018cmnt.sys
2009-11-19 15:42 . 2009-11-19 15:42 12200 ----a-w- c:\windows\system32\drivers\s1018cm.sys
2009-11-19 15:42 . 2009-11-19 15:42 114472 ----a-w- c:\windows\system32\drivers\s1018mdm.sys
2009-11-19 15:42 . 2009-11-19 15:42 108200 ----a-w- c:\windows\system32\drivers\s1018mgmt.sys
2009-11-19 15:42 . 2009-11-19 15:42 10792 ----a-w- c:\windows\system32\drivers\s1018cr.sys
2009-11-19 14:28 . 2009-11-19 14:28 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-11-19 14:28 . 2009-11-19 14:28 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-11-19 12:44 . 2009-11-19 12:44 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2009-11-19 12:44 . 2009-11-19 12:44 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2009-11-19 12:44 . 2009-11-19 12:44 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2009-11-19 12:44 . 2008-09-30 13:07 -------- d-----w- c:\program files\Sony Ericsson
2009-11-17 11:19 . 2007-09-26 11:09 -------- d-----w- c:\program files\Adobe Acrobat 7.0
2009-10-29 05:48 . 2004-08-17 13:49 663040 ------w- c:\windows\system32\wininet.dll
2009-10-21 06:03 . 2004-08-17 13:49 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:03 . 2004-08-17 13:49 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-03 21:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-18 23:41 . 2009-10-26 15:19 638976 ----a-w- c:\windows\system32\semtempl.dll
2008-03-06 16:12 . 2008-03-05 20:02 72 --sha-w- c:\windows\S0E3F1BD6.tmp
.

((((((((((((((((((((((((((((( SnapShot@2010-01-11_22.44.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-04-19 12:55 . 2007-04-19 12:55 53088 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\DFUICOM.EXE
+ 2007-05-10 12:42 . 2007-05-10 12:42 450392 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\SOA.DLL
+ 2007-03-22 18:16 . 2007-03-22 18:16 134496 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\MSJSPP40.DLL
+ 2007-04-19 13:01 . 2007-04-19 13:01 238424 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\MSCDM.DLL
+ 2007-01-16 19:32 . 2007-01-16 19:32 136032 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\MSAEXP30.DLL
+ 2007-04-19 12:54 . 2007-04-19 12:54 169312 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\ACCWIZ.DLL
+ 2007-05-10 12:43 . 2007-05-10 12:43 6688096 c:\windows\Installer\$PatchCache$\Managed\5040110900063D11C8EF10054038389C\11.0.8173\MSACCESS.EXE
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2003-03-01 125440]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-27 247144]
"mRouterConfig"="c:\program files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" [2006-03-02 290816]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-04-13 2387968]
"UnHackMe Monitor"="c:\program files\UnHackMe\hackmon.exe" [2009-12-22 594144]
"DesktopX"="c:\program files\Object Desktop\DesktopX\DesktopX.exe" [2005-03-15 436224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RevoTaskbarApp"="c:\windows\system32\RevoTask.exe" [2004-06-14 221184]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"PC Suite for Smartphones"="c:\program files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" [2007-12-25 548864]
"Norton Ghost 12.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2008-11-12 2037096]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\Majk\Nabˇdka Start\Programy\po spuçtŘnˇ\
BlueSoleil.lnk - c:\program files\BlueSoleil\gprs.exe [2007-12-27 43608]
c242 Silica Mailinfo.lnk - c:\program files\Object Desktop\c242SilicaMail1.exe [2007-9-10 70144]
Miranda.lnk - c:\program files\Miranda IM\miranda32.exe [2007-9-10 459357]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-7-28 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 00:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 12:13 49152 ----a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0prestrt\0Partizan

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 14:50 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\VLC media player\\vlc.exe"=
"c:\\Program Files\\Total Commander\\TOTALCMD.EXE"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Hry\\Half-Life 2\\hl2.exe"=
"c:\\Program Files\\CZDC++\\CZDC.exe"=
"c:\\Program Files\\3D Studio Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Mishek\\Dokumenty\\Mir4nda-IM-0.7.1-Pack-v2.0\\miranda32.exe"=
"c:\\Program Files\\CZDC++ (out)\\CZDC.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\totalcmd\\totalcmd.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=
"c:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer.exe"=
"c:\\Program Files\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"6112:UDP"= 6112:UDP:Warcraft
"6112:TCP"= 6112:TCP:Warcraft III
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7. 1. 2010 19:22 64160]
R0 VirtualK;VirtaulK;c:\windows\system32\drivers\VirtualK.sys [10. 9. 2007 01:24 3968]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14. 5. 2009 15:47 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [14. 5. 2009 15:49 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14. 5. 2009 15:47 731840]
R2 Prvflder;Prvflder;c:\windows\system32\drivers\prvflder.sys [21. 4. 2006 07:22 70912]
R2 Start BT in service;Start BT in service;c:\program files\BlueSoleil\StartSkysolSvc.exe [27. 12. 2007 15:39 51816]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [11. 1. 2010 15:35 34760]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9. 11. 2007 00:46 717296]
S1 KGootkit;KGootkit;c:\windows\system32\drivers\KGootkit.sys --> c:\windows\system32\drivers\KGootkit.sys [?]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [27. 8. 2009 16:05 92008]
S3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\system32\drivers\AVerBDA3x.sys [25. 3. 2008 18:49 1171456]
S3 Bluesdfu;Blues USB DFU;c:\windows\system32\drivers\Bluesdfu.sys [8. 6. 2007 21:20 15616]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [19. 11. 2009 13:44 13224]
S3 GMFilter;GMFilter HID Filter Driver;c:\windows\system32\drivers\GMFilter.sys [10. 9. 2007 01:24 21760]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys --> c:\windows\system32\DRIVERS\motccgp.sys [?]
S3 RegGuard;RegGuard;c:\windows\system32\drivers\regguard.sys [11. 1. 2010 15:47 24416]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [19. 11. 2009 16:42 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [19. 11. 2009 16:42 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [19. 11. 2009 16:42 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [19. 11. 2009 16:42 108200]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [19. 11. 2009 16:42 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [19. 11. 2009 16:42 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [19. 11. 2009 16:42 109736]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [1. 4. 2008 00:46 223128]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - UnHackMeDrv

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-04-13 13:08 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.idnes.cz/
uInternet Settings,ProxyServer = cache.sh.cvut.cz:3128
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} -
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} -
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\Majk\Data aplikací\Mozilla\Firefox\Profiles\2od4nn1w.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.cz/ig?hl=cs&source=iglk
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\documents and settings\Majk\Data aplikací\Mozilla\Firefox\Profiles\2od4nn1w.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\Majk\Data aplikací\Mozilla\Firefox\Profiles\2od4nn1w.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\ebayAccessComponent.dll
FF - component: c:\documents and settings\Majk\Data aplikací\Mozilla\Firefox\Profiles\2od4nn1w.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\ebayShortcutMaker.dll
FF - plugin: c:\program files\Adobe Acrobat 7.0\Acrobat\browser\nppdf32.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft Research\HDView for Firefox\nphdview.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\Opera\program\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-12 00:02
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1000)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll

- - - - - - - > 'explorer.exe'(2312)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\msi.dll
c:\windows\system32\shdoclc.dll
c:\program files\Common Files\stardock\MCPCore.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Celkový čas: 2010-01-12 00:04:23
ComboFix-quarantined-files.txt 2010-01-11 23:04

Před spuštěním: Volných bajtů: 33 218 936 832
Po spuštění: Volných bajtů: 33 182 736 384

Current=4 Default=4 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 16A1EDF3F4448FDE6313EC7347FEE390

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#9 Příspěvek od Roli »

Nyní pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

File::  
c:\windows\system32\lsdelete.exe
c:\windows\system32\drivers\Lbd.sys
c:\windows\Systems.exe
c:\windows\system32\DROPPEDFILEOKppi1.tmp
c:\windows\S0E3F1BD6.tmp

Folder::
c:\program files\Lavasoft

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

Driver::
Lbd
Lavasoft Ad-Aware Service
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

po aplikaci na Tebe vypadne další log, dej ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#10 Příspěvek od Maajk »

tak problem - pri prvnim spusteni jsem v ComboFixu spatril, ze po analyze to neco odmazlo, nacez se to zastavilo a nevyplivlo mi to log ...

Zkousel jsem to pak nekolikrat krat opakovat a zastavi se to na/po fazi 50, treba i na pul hodiny, ale log to nevyplivne ... :(

Takze co ted ?:(

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#11 Příspěvek od Roli »

No co no použijeme něco jiného, nyní tedy přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Dále stáhni a spusť OTMoveIt

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files 
c:\*.tmp
c:\WINDOWS\System32\*.tmp
c:\WINDOWS\*.tmp
c:\program files\Lavasoft
c:\windows\system32\lsdelete.exe
c:\windows\system32\drivers\Lbd.sys
c:\windows\Systems.exe
c:\windows\system32\DROPPEDFILEOKppi1.tmp

:reg
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

:services
Lbd
Lavasoft Ad-Aware Service

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci obsah logu uloženého na C:\_OTMoveIt\MovedFiles\
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#12 Příspěvek od Maajk »

tak tady je ...

Mimochodem, NOD4ka mi porad nachazi viry dokola a dokola (i kdyz ne moc .. ale tzn. ze ho mam nekde chyceneho a ten ho porad rozesila dale ?) ... a taky se mi pokazde v nem stane, ze to hodi chybu aplikace a skonci to (zhruba stejne .. v polovine scannovani druhe partisny ... )

================================================================================
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder c:\*.tmp not found.
c:\WINDOWS\System32\CONFIG.TMP moved successfully.
c:\WINDOWS\System32\KERNEL.TMP moved successfully.
c:\WINDOWS\System32\SET4C9.tmp moved successfully.
c:\WINDOWS\System32\SET4CA.tmp moved successfully.
c:\WINDOWS\System32\SET4DB.tmp moved successfully.
c:\WINDOWS\System32\SET4F2.tmp moved successfully.
c:\WINDOWS\System32\SET51C.tmp moved successfully.
c:\WINDOWS\System32\SET535.tmp moved successfully.
c:\WINDOWS\System32\SET542.tmp moved successfully.
c:\WINDOWS\System32\SET553.tmp moved successfully.
c:\WINDOWS\System32\SET556.tmp moved successfully.
c:\WINDOWS\System32\SET557.tmp moved successfully.
c:\WINDOWS\System32\SET558.tmp moved successfully.
c:\WINDOWS\System32\SET55A.tmp moved successfully.
c:\WINDOWS\System32\SET55B.tmp moved successfully.
c:\WINDOWS\System32\SET55D.tmp moved successfully.
c:\WINDOWS\System32\SET56C.tmp moved successfully.
c:\WINDOWS\System32\SET571.tmp moved successfully.
c:\WINDOWS\System32\SET572.tmp moved successfully.
c:\WINDOWS\System32\SET573.tmp moved successfully.
c:\WINDOWS\System32\SET574.tmp moved successfully.
c:\WINDOWS\System32\SET575.tmp moved successfully.
c:\WINDOWS\System32\SET576.tmp moved successfully.
c:\WINDOWS\System32\SET577.tmp moved successfully.
c:\WINDOWS\System32\SET578.tmp moved successfully.
c:\WINDOWS\System32\SET579.tmp moved successfully.
c:\WINDOWS\System32\SET57A.tmp moved successfully.
c:\WINDOWS\System32\SET57B.tmp moved successfully.
c:\WINDOWS\System32\SET57E.tmp moved successfully.
c:\WINDOWS\System32\SET57F.tmp moved successfully.
c:\WINDOWS\System32\SET580.tmp moved successfully.
c:\WINDOWS\System32\SET581.tmp moved successfully.
c:\WINDOWS\System32\SET583.tmp moved successfully.
c:\WINDOWS\System32\SET584.tmp moved successfully.
c:\WINDOWS\System32\SET586.tmp moved successfully.
c:\WINDOWS\System32\SET594.tmp moved successfully.
c:\WINDOWS\002959_.tmp moved successfully.
c:\WINDOWS\003261_.tmp moved successfully.
c:\WINDOWS\msdownld.tmp folder moved successfully.
c:\WINDOWS\SET11B.tmp moved successfully.
c:\WINDOWS\SET11E.tmp moved successfully.
c:\WINDOWS\SET12A.tmp moved successfully.
c:\WINDOWS\SET3.tmp moved successfully.
c:\WINDOWS\SET4.tmp moved successfully.
c:\WINDOWS\SET8.tmp moved successfully.
c:\WINDOWS\SETD0.tmp moved successfully.
c:\WINDOWS\SETD3.tmp moved successfully.
c:\WINDOWS\SETDF.tmp moved successfully.
File/Folder c:\program files\Lavasoft not found.
File/Folder c:\windows\system32\lsdelete.exe not found.
File/Folder c:\windows\system32\drivers\Lbd.sys not found.
File/Folder c:\windows\Systems.exe not found.
File/Folder c:\windows\system32\DROPPEDFILEOKppi1.tmp not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service\ not found.
========== SERVICES/DRIVERS ==========
Error: No service named Lbd was found to stop!
Unable to stop service Lbd!
Error: No service named Lavasoft Ad-Aware Service was found to stop!
Unable to stop service Lavasoft Ad-Aware Service!
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: Maajk
->Temp folder emptied: 72686002 bytes
->Temporary Internet Files folder emptied: 1743346 bytes
->Java cache emptied: 13690471 bytes
->FireFox cache emptied: 47214569 bytes

User: Majk
->Temp folder emptied: 1521145 bytes
->Temporary Internet Files folder emptied: 3888389 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 42754583 bytes

User: Mishek
->Temp folder emptied: 1203 bytes
->Temporary Internet Files folder emptied: 112094 bytes
->Java cache emptied: 13426147 bytes
->FireFox cache emptied: 47236683 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 467456 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1429923626 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 180038 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1 597,00 mb


OTM by OldTimer - Version 3.1.5.0 log created on 01142010_154039

Files moved on Reboot...
File C:\WINDOWS\temp\Perflib_Perfdata_1338.dat not found!

Registry entries deleted on Reboot...

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#13 Příspěvek od Roli »

Nyní použij AVP Tool z mého podpisu.
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Maajk
Návštěvník
Návštěvník
Příspěvky: 12
Registrován: 11 led 2010 14:43

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#14 Příspěvek od Maajk »

tak, zvlastni situace ....
Daval-li jsem testovat za pomoci Kasperskyho pri nastaveni jako je uvedeno zde (http://www.viry.cz/forum/viewtopic.php?f=29&t=58179), pak mi to hazelo stejnou kritickou chybu behem druhe poloviny scannu jako u NODu (viz. prispevek vyse) a tim testovani proste skoncilo, ackoliv samotny program to neuzavrelo ....

Vcera vecer jsem prenastavil parametry testu (zapl jsem deep scan a peclivost testu jsem z tech tri moznosti nastavil tez na deep) .. a ejhle, projelo to az do konce ...



jinak log:

Autoscan: completed 8 hours ago (events: 2, objects: 592416, time: 02:42:16)
16. 1. 2010 00:56:32 Task started
16. 1. 2010 03:38:48 Task completed

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: kompletne rozhozeny system (pomaly, nefunkcni FW i A-V, ..)

#15 Příspěvek od Roli »

Ještě jednou použij OTMoveIt,

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe  

:reg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" 
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a251300-3813-11dd-88ec-0019d1a2db7b}]    

:files
C:\Documents and Settings\Majk\Nabídka Start\Programy\Po spuštění\ihaupd32.exe
C:\WINDOWS\system 32\digeste.dll
C:\WINDOWS\System32\drivers\KGootkit.sys

Driver::
KGootkit

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci obsah logu uloženého na C:\_OTMoveIt\MovedFiles\
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět