Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

win32/olmarik v operační paměti

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

win32/olmarik v operační paměti

#1 Příspěvek od jsykora »

Dobrý den, prosím o pomoc, NOD32 Antivir 4 mi hlási: win32/olmarik v operační paměti. Nespecifikuje, jaký Olmarik. Ad-Aware ho také nacházel, spybot si ho nevšimne. Eolmarikremover ho najde, ale neumí odstranit.
Zkoušel jsem ho zlikvidovat sám, možná jsem udělal nějaký bordel.
log z RSIT

Logfile of random's system information tool 1.06 (written by random/random)
Run by Jarda at 2010-02-08 20:38:12
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 117 GB (47%) free of 249 GB
Total RAM: 3582 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:38:38, on 8.2.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18882)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\System32\wpcumi.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Jarda\AppData\Roaming\Maxthon2\Maxthon.exe
C:\totalcmd\TOTALCMD.EXE
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
J:\_antivir\RSIT.exe
C:\Program Files\trend micro\Jarda.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll (file missing)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [BVRPLiveUpdate] C:\Program Files\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\PROGRA~2\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [RGSC] D:\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [PMCLoader] C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.gigabyte.com.tw/object/Dldrv.ocx
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/ ... 10.115.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.4.1.cab
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} (Battlefield Heroes Updater) - https://www.battlefieldheroes.com/stati ... 0.21.0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: BGMYRQ - Sysinternals - www.sysinternals.com - C:\Users\Jarda\AppData\Local\Temp\BGMYRQ.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - D:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FKEKD - Sysinternals - www.sysinternals.com - C:\Users\Jarda\AppData\Local\Temp\FKEKD.exe
O23 - Service: Google Update Service (GoogleUpdateBeta) - Google Inc - C:\Windows\system32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: JLJORTUI - Sysinternals - www.sysinternals.com - C:\Users\Jarda\AppData\Local\Temp\JLJORTUI.exe
O23 - Service: JSIOH - Sysinternals - www.sysinternals.com - C:\Users\Jarda\AppData\Local\Temp\JSIOH.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Karta Smart Card SCardSvrDAUpdaterSvc (SCardSvrDAUpdaterSvc) - Unknown owner - C:\Windows\system32\acluig.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Centrum zabezpečení wscsvcBITS (wscsvcBITS) - Unknown owner - C:\Windows\system32\adtschemah.exe

--
End of file - 14093 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Daily 1).job
C:\Windows\tasks\Ad-Aware Update (Daily 2).job
C:\Windows\tasks\Ad-Aware Update (Daily 3).job
C:\Windows\tasks\Ad-Aware Update (Daily 4).job
C:\Windows\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-08-26 279944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-19 263280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-19 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-08-26 279944]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-19 263280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-07-06 4669440]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdc.exe [2007-01-24 563080]
"LogMeIn GUI"=C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2008-02-28 63048]
"Flashget"=C:\Program Files\FlashGet\flashget.exe [2007-09-25 2007088]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"UpdatePDRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-01-04 222504]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-01-30 992256]
"BVRPLiveUpdate"=C:\Program Files\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\PROGRA~2\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-10-23 202024]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-10 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-10 86960]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-10 218032]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\HOMERunner.exe []
"Steam"=C:\Program Files\Steam\Steam.exe [2009-10-24 1217808]
"RGSC"=D:\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent []
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-04-13 2387968]
"PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-11 39408]
"igndlm.exe"=C:\Program Files\Download Manager\DLM.exe [2009-10-27 1103216]

C:\Users\Jarda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=0
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-02-06 03:19:20 ----A---- C:\Windows\system32\winhttp.dll
2010-02-06 01:43:28 ----D---- C:\ProgramData\Spybot - Search & Destroy
2010-02-06 01:43:28 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-06 01:18:03 ----D---- C:\SysProt
2010-02-06 01:04:56 ----SD---- C:\ComboFix
2010-02-06 01:04:37 ----A---- C:\Windows\SWXCACLS.exe
2010-02-06 01:01:42 ----A---- C:\Windows\ntbtlog.txt
2010-02-06 00:56:37 ----SHD---- C:\$RECYCLE.BIN
2010-02-06 00:40:17 ----D---- C:\Windows\temp
2010-02-06 00:34:57 ----A---- C:\logcmbfix.txt
2010-02-06 00:33:27 ----A---- C:\Windows\zip.exe
2010-02-06 00:33:27 ----A---- C:\Windows\SWSC.exe
2010-02-06 00:33:27 ----A---- C:\Windows\SWREG.exe
2010-02-06 00:33:27 ----A---- C:\Windows\sed.exe
2010-02-06 00:33:27 ----A---- C:\Windows\PEV.exe
2010-02-06 00:33:27 ----A---- C:\Windows\NIRCMD.exe
2010-02-06 00:33:27 ----A---- C:\Windows\MBR.exe
2010-02-06 00:33:27 ----A---- C:\Windows\grep.exe
2010-02-06 00:33:20 ----D---- C:\Qoobox
2010-02-06 00:27:02 ----D---- C:\rsit
2010-02-06 00:27:02 ----D---- C:\Program Files\trend micro
2010-02-06 00:21:33 ----D---- C:\Program Files\CCleaner
2010-02-05 21:09:01 ----A---- C:\Windows\system32\kerberos.dll
2010-02-05 21:09:00 ----A---- C:\Windows\system32\schannel.dll
2010-01-31 21:49:12 ----A---- C:\Windows\GPInstall.exe
2010-01-27 20:41:24 ----D---- C:\ProgramData\PassMark
2010-01-27 20:41:20 ----D---- C:\Program Files\MonitorTest
2010-01-27 20:39:16 ----D---- C:\Program Files\Mihov Blank Screen
2010-01-21 21:12:08 ----A---- C:\Windows\system32\mshtml.dll
2010-01-21 21:12:07 ----A---- C:\Windows\system32\ieframe.dll
2010-01-21 21:12:06 ----A---- C:\Windows\system32\iertutil.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\wininet.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\urlmon.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\occache.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-21 21:12:04 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-21 21:12:03 ----A---- C:\Windows\system32\ieui.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\iepeers.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-21 21:12:02 ----A---- C:\Windows\system32\iesetup.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\iernonce.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-12 23:54:00 ----A---- C:\Windows\system32\t2embed.dll
2010-01-12 23:53:59 ----A---- C:\Windows\system32\fontsub.dll
2010-01-11 18:18:36 ----D---- C:\Users\Jarda\AppData\Roaming\HypoKalk
2010-01-11 18:00:52 ----D---- C:\Program Files\Komerční Banka
2010-01-10 13:57:45 ----HDC---- C:\ProgramData\{C2AE2ED8-999F-4EF7-AFD4-6772152D0F81}

======List of files/folders modified in the last 1 months======

2010-02-08 20:38:27 ----D---- C:\Windows\Prefetch
2010-02-08 20:30:10 ----D---- C:\Windows\System32
2010-02-08 20:28:32 ----D---- C:\Users\Jarda\AppData\Roaming\Skype
2010-02-08 20:28:01 ----D---- C:\Windows\Tasks
2010-02-08 20:18:55 ----SHD---- C:\System Volume Information
2010-02-08 20:18:38 ----D---- C:\Users\Jarda\AppData\Roaming\MxBoost
2010-02-08 20:14:56 ----D---- C:\ProgramData\NVIDIA
2010-02-08 20:14:54 ----D---- C:\Program Files\Steam
2010-02-08 20:10:00 ----D---- C:\Windows\system32\Tasks
2010-02-08 20:08:14 ----D---- C:\Users\Jarda\AppData\Roaming\skypePM
2010-02-08 20:08:13 ----D---- C:\Program Files\LogMeIn
2010-02-06 18:41:31 ----D---- C:\Windows\rescache
2010-02-06 14:12:55 ----D---- C:\Windows\winsxs
2010-02-06 14:12:47 ----D---- C:\Windows\system32\cs-CZ
2010-02-06 12:35:23 ----D---- C:\install
2010-02-06 12:24:35 ----D---- C:\Downloads
2010-02-06 03:19:04 ----D---- C:\Windows\system32\catroot2
2010-02-06 03:19:04 ----D---- C:\Windows\system32\catroot
2010-02-06 01:43:28 ----RD---- C:\Program Files
2010-02-06 01:43:28 ----D---- C:\ProgramData
2010-02-06 01:18:55 ----A---- C:\Windows\NeroDigital.ini
2010-02-06 01:06:46 ----D---- C:\Windows\system32\drivers
2010-02-06 01:01:42 ----D---- C:\Windows
2010-02-06 00:45:06 ----A---- C:\Windows\system.ini
2010-02-06 00:40:49 ----D---- C:\Windows\system32\config
2010-02-06 00:40:49 ----D---- C:\Boot
2010-02-06 00:40:29 ----D---- C:\Windows\ERDNT
2010-02-06 00:39:58 ----D---- C:\Program Files\pdfforge Toolbar
2010-02-06 00:37:32 ----D---- C:\Windows\AppPatch
2010-02-06 00:37:31 ----D---- C:\Program Files\Common Files
2010-02-06 00:23:44 ----D---- C:\Windows\Minidump
2010-02-06 00:23:44 ----D---- C:\Windows\Debug
2010-02-05 23:06:33 ----SHD---- C:\Windows\Installer
2010-02-05 20:24:11 ----D---- C:\NVIDIA
2010-02-05 19:55:54 ----D---- C:\ipaq 614c
2010-02-05 19:51:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-05 19:51:10 ----D---- C:\Windows\inf
2010-02-05 19:11:42 ----D---- C:\Program Files\Mozilla Firefox
2010-02-01 19:39:06 ----D---- C:\Windows\system32\LogFiles
2010-02-01 00:56:07 ----D---- C:\Program Files\Common Files\Steam
2010-01-31 21:49:17 ----D---- C:\Program Files\ModelH
2010-01-29 08:30:39 ----AD---- C:\ProgramData\TEMP
2010-01-27 23:31:32 ----D---- C:\Program Files\Internet Explorer
2010-01-26 23:53:07 ----D---- C:\rapid
2010-01-26 21:30:48 ----D---- C:\Program Files\JDownloader
2010-01-25 19:38:48 ----D---- C:\ProgramData\2DBoy
2010-01-22 18:47:49 ----D---- C:\Windows\system32\migration
2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-13 03:03:59 ----D---- C:\ProgramData\Microsoft Help
2010-01-13 03:02:58 ----D---- C:\Program Files\Windows Mail
2010-01-10 13:59:19 ----RSD---- C:\Windows\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATITool;ATITool Overclocking Utility; C:\Windows\system32\DRIVERS\ATITool.sys [2007-08-08 28968]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-15 281760]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-15 25888]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-10-17 47640]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-04-23 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-07-18 1841312]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-02-28 10144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-11-21 11515752]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-10-23 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-03-17 140288]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S1 EIO;EIO Driver; C:\Windows\system32\DRIVERS\EIO.sys []
S1 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Users\Jarda\AppData\Local\Temp\HWiNFO32.SYS []
S3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE; C:\Windows\system32\DRIVERS\3xHybrid.sys [2006-11-22 1121536]
S3 AteksoftAudio;WebCamera Plus Audio; C:\Windows\system32\drivers\ateksoftaudio.sys [2007-12-25 11776]
S3 catchme;catchme; \??\C:\Users\Jarda\AppData\Local\Temp\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2008-04-22 27672]
S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2007-06-27 53184]
S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2007-06-27 71488]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-03-23 15600]
S3 GKUPRO2D;GKUPRO2D; C:\Windows\System32\Drivers\GKUPRO2D.sys [2005-02-18 71168]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MarkFun_NT;MarkFun_NT; \??\C:\Program Files\markfun.w32 [2007-08-21 17912]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys []
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
S3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.08\RivaTuner32.sys [2008-03-10 9088]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\Windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108200]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]
S3 Ser2pl;Prolific2 Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys [2005-11-04 48640]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 USBCCID;Čtecí zařízení čipových karet USB; C:\Windows\system32\DRIVERS\usbccid.sys [2006-11-02 30208]
S3 winusb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-12-20 722416]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 GoogleUpdateBeta;Google Update Service; C:\Windows\system32\config\system [2010-02-08 23068672]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-04 1181328]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-04-13 73728]
R2 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe [2008-02-28 63040]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-11-20 122984]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-10-06 241734]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-10-23 382248]
S2 PEVSystemStart;PEVSystemStart; C:\ComboFix\PEV.cfxxe [2009-12-09 261632]
S2 SCardSvrDAUpdaterSvc;Karta Smart Card SCardSvrDAUpdaterSvc; C:\Windows\system32\acluig.exe srv []
S2 wscsvcBITS;Centrum zabezpečení wscsvcBITS; C:\Windows\system32\adtschemah.exe [2008-01-19 62976]
S3 BGMYRQ;BGMYRQ; C:\Users\Jarda\AppData\Local\Temp\BGMYRQ.exe [2010-02-06 535424]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; D:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FKEKD;FKEKD; C:\Users\Jarda\AppData\Local\Temp\FKEKD.exe [2010-02-06 445312]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-11 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 JLJORTUI;JLJORTUI; C:\Users\Jarda\AppData\Local\Temp\JLJORTUI.exe [2010-02-06 482176]
S3 JSIOH;JSIOH; C:\Users\Jarda\AppData\Local\Temp\JSIOH.exe [2010-02-06 445312]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-01-26 326792]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#2 Příspěvek od motji »

Dobrý večer :)
Log z combofixu , co jste už udělal, by nebyl?
Eolmarikremover ho najde kde?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#3 Příspěvek od jsykora »

eolmarikremover nezobrazí cestu infikovaného souboru, jen napíše "unable to clean the rootkit"
combofix jsem spouštěl v pátek, už nevím, kde by mohl být log

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#4 Příspěvek od motji »

Start -> Spustit -> napište
notepad "C:\ComboFix.txt"
Enter.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#5 Příspěvek od jsykora »

jo, je v rootu (pozor, je z 6.2)
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jarda at 2010-02-06 00:27:02
Microsoft« Windows VistaÖ Home Premium Service Pack 2
System drive C: has 118 GB (47%) free of 249 GB
Total RAM: 3582 MB (54% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Daily 1).job
C:\Windows\tasks\Ad-Aware Update (Daily 2).job
C:\Windows\tasks\Ad-Aware Update (Daily 3).job
C:\Windows\tasks\Ad-Aware Update (Daily 4).job
C:\Windows\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-08-26 279944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
PomocnÝk pro p°ihlßÜenÝ ke slu×bý Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-19 263280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-19 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2009-01-30 1114112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-08-26 279944]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-19 263280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-07-06 4669440]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdc.exe [2007-01-24 563080]
"LogMeIn GUI"=C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2008-02-28 63048]
"Flashget"=C:\Program Files\FlashGet\flashget.exe [2007-09-25 2007088]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"UpdatePDRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-01-04 222504]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-01-30 992256]
"BVRPLiveUpdate"=C:\Program Files\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\PROGRA~2\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-10-23 202024]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-10 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-10 86960]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-10 218032]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\HOMERunner.exe []
"Steam"=C:\Program Files\Steam\Steam.exe [2009-10-24 1217808]
"RGSC"=D:\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent []
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-04-13 2387968]
"PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-11 39408]
"igndlm.exe"=C:\Program Files\Download Manager\DLM.exe [2009-10-27 1103216]

C:\Users\Jarda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Vř°ezy obrazovky a spuÜtýnÝ aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=0
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2010-02-06 00:27:02 ----D---- C:\rsit
2010-02-06 00:27:02 ----D---- C:\Program Files\trend micro
2010-02-06 00:21:33 ----D---- C:\Program Files\CCleaner
2010-02-05 23:49:37 ----SD---- C:\ComboFix
2010-02-05 23:25:33 ----A---- C:\Windows\NIRCMD.exe
2010-02-05 23:25:33 ----A---- C:\Windows\MBR.exe
2010-02-05 23:18:05 ----A---- C:\Windows\SWXCACLS.exe
2010-02-05 21:09:01 ----A---- C:\Windows\system32\kerberos.dll
2010-02-05 21:09:00 ----A---- C:\Windows\system32\schannel.dll
2010-01-31 21:49:12 ----A---- C:\Windows\GPInstall.exe
2010-01-27 20:41:24 ----D---- C:\ProgramData\PassMark
2010-01-27 20:41:20 ----D---- C:\Program Files\MonitorTest
2010-01-27 20:39:16 ----D---- C:\Program Files\Mihov Blank Screen
2010-01-21 21:12:08 ----A---- C:\Windows\system32\mshtml.dll
2010-01-21 21:12:07 ----A---- C:\Windows\system32\ieframe.dll
2010-01-21 21:12:06 ----A---- C:\Windows\system32\iertutil.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\wininet.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\urlmon.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\occache.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-21 21:12:04 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-21 21:12:03 ----A---- C:\Windows\system32\ieui.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\iepeers.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-21 21:12:02 ----A---- C:\Windows\system32\iesetup.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\iernonce.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-12 23:54:00 ----A---- C:\Windows\system32\t2embed.dll
2010-01-12 23:53:59 ----A---- C:\Windows\system32\fontsub.dll
2010-01-11 18:18:36 ----D---- C:\Users\Jarda\AppData\Roaming\HypoKalk
2010-01-11 18:00:52 ----D---- C:\Program Files\KomerŔnÝ Banka
2010-01-10 13:57:45 ----HDC---- C:\ProgramData\{C2AE2ED8-999F-4EF7-AFD4-6772152D0F81}
2010-01-08 18:28:51 ----A---- C:\Windows\system32\ForceBindIP-Uninstaller.exe
2010-01-06 19:17:55 ----D---- C:\BDS
2010-01-04 22:25:53 ----D---- C:\Program Files\GameSpy Arcade
2010-01-04 22:22:48 ----D---- C:\Program Files\Download Manager
2010-01-04 22:21:27 ----D---- C:\Users\Jarda\AppData\Roaming\IGN_DLM
2010-01-03 15:25:36 ----SHD---- C:\ProgramData\SecuROM
2010-01-03 14:52:23 ----D---- C:\Windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2009-12-29 13:29:42 ----D---- C:\keygen
2009-12-19 11:53:49 ----D---- C:\Program Files\Winamp
2009-12-14 20:12:45 ----A---- C:\Windows\system32\javaws.exe
2009-12-14 20:12:45 ----A---- C:\Windows\system32\javaw.exe
2009-12-14 20:12:45 ----A---- C:\Windows\system32\java.exe
2009-12-12 11:14:39 ----A---- C:\Windows\system32\nshhttp.dll
2009-12-12 11:14:37 ----A---- C:\Windows\system32\httpapi.dll
2009-12-09 21:16:49 ----A---- C:\Windows\system32\rastls.dll
2009-12-08 20:43:33 ----D---- C:\Users\Jarda\AppData\Roaming\Broad Intelligence
2009-11-30 18:02:40 ----A---- C:\Windows\system32\xliveinstall.dll
2009-11-30 18:02:38 ----A---- C:\Windows\system32\xliveinstallhost.exe
2009-11-29 22:54:58 ----A---- C:\Windows\system32\lsdelete.exe
2009-11-29 21:09:22 ----HDC---- C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-29 21:09:12 ----D---- C:\ProgramData\Lavasoft
2009-11-29 21:09:12 ----D---- C:\Program Files\Lavasoft
2009-11-29 19:08:31 ----RA---- C:\Windows\PEV.exe
2009-11-29 19:08:30 ----A---- C:\Windows\zip.exe
2009-11-29 19:08:30 ----A---- C:\Windows\SWSC.exe
2009-11-29 19:08:30 ----A---- C:\Windows\SWREG.exe
2009-11-29 19:08:30 ----A---- C:\Windows\sed.exe
2009-11-29 19:08:30 ----A---- C:\Windows\grep.exe
2009-11-25 03:01:36 ----A---- C:\Windows\system32\tzres.dll
2009-11-25 00:46:26 ----A---- C:\Windows\system32\msxml6.dll
2009-11-25 00:46:24 ----A---- C:\Windows\system32\msxml3.dll
2009-11-23 23:14:59 ----D---- C:\ProgramData\BioWare
2009-11-23 22:29:27 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2009-11-23 22:18:12 ----D---- C:\Program Files\Common Files\BioWare
2009-11-23 19:19:00 ----D---- C:\Users\Jarda\AppData\Roaming\Google
2009-11-23 19:00:16 ----D---- C:\Program Files\JDownloader
2009-11-22 11:54:00 ----D---- C:\ProgramData\Apple Computer
2009-11-22 11:54:00 ----D---- C:\Program Files\QuickTime
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvvsvc.exe
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvsvc.dll
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvmctray.dll
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvcpl.dll
2009-11-20 18:53:04 ----A---- C:\Windows\system32\OpenCL.dll
2009-11-20 18:53:03 ----A---- C:\Windows\system32\nvwgf2um.dll
2009-11-20 18:53:03 ----A---- C:\Windows\system32\nvoglv32.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcuvid.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcuvenc.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcuda.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcompiler.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcod178.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcod.dll
2009-11-19 19:35:20 ----A---- C:\Windows\system32\XAudio2_5.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\xactengine3_5.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\D3DX9_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\d3dx11_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\d3dx10_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\d3dcsx_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2009-11-19 19:35:13 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-11-19 19:35:08 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-11-19 19:35:08 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-11-19 19:35:07 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-11-19 19:35:07 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-11-19 19:35:06 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-11-19 19:35:06 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-11-19 19:35:05 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-11-17 15:10:49 ----D---- C:\Program Files\Windows Portable Devices
2009-11-17 02:23:43 ----A---- C:\Windows\system32\UIRibbonRes.dll
2009-11-17 02:23:43 ----A---- C:\Windows\system32\UIRibbon.dll
2009-11-17 02:23:43 ----A---- C:\Windows\system32\UIAnimation.dll
2009-11-17 02:23:23 ----A---- C:\Windows\system32\WMPhoto.dll
2009-11-17 02:23:23 ----A---- C:\Windows\system32\cdd.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\xpsservices.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\XpsRasterService.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\XpsPrint.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-11-17 02:23:22 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\OpcServices.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\FntCache.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\dxgi.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\dxdiagn.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\dxdiag.exe
2009-11-17 02:23:22 ----A---- C:\Windows\system32\DWrite.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d11.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10warp.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10level9.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10core.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10_1core.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10_1.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d2d1.dll
2009-11-17 02:22:53 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2009-11-17 02:22:53 ----A---- C:\Windows\system32\wpdbusenum.dll
2009-11-17 02:22:53 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2009-11-17 02:22:49 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WPDSp.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\wpdshext.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WpdMtpUS.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WpdMtp.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WpdConns.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\wpd_ci.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-11-17 02:21:41 ----A---- C:\Windows\system32\UIAutomationCore.dll
2009-11-17 02:21:41 ----A---- C:\Windows\system32\oleaccrc.dll
2009-11-17 02:21:41 ----A---- C:\Windows\system32\oleacc.dll
2009-11-11 21:29:49 ----A---- C:\Windows\system32\WSDApi.dll
2009-11-11 18:39:03 ----D---- C:\ProgramData\Google
2009-11-11 18:38:46 ----D---- C:\Users\Jarda\AppData\Roaming\IrfanView
2009-11-11 18:38:45 ----D---- C:\Program Files\IrfanView
2009-11-08 23:54:32 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-11-08 23:54:32 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-11-08 23:54:31 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-11-08 23:54:29 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-11-08 23:54:28 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-11-08 23:54:28 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-11-08 23:54:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-11-08 23:54:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-11-08 23:54:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-11-08 10:31:45 ----D---- C:\Program Files\Common Files\Skype
2009-11-08 10:31:44 ----RD---- C:\Program Files\Skype

======List of files/folders modified in the last 3 months======

2010-02-06 00:27:02 ----RD---- C:\Program Files
2010-02-06 00:26:54 ----D---- C:\Windows\Temp
2010-02-06 00:23:44 ----D---- C:\Windows\Minidump
2010-02-06 00:23:44 ----D---- C:\Windows\Debug
2010-02-06 00:23:44 ----D---- C:\Windows
2010-02-06 00:17:19 ----D---- C:\Users\Jarda\AppData\Roaming\Skype
2010-02-06 00:12:11 ----D---- C:\Windows\Tasks
2010-02-06 00:12:11 ----D---- C:\Windows\system32\Tasks
2010-02-06 00:11:43 ----D---- C:\ProgramData\NVIDIA
2010-02-06 00:11:42 ----D---- C:\Windows\System32
2010-02-06 00:11:41 ----D---- C:\Program Files\Steam
2010-02-06 00:07:14 ----D---- C:\Users\Jarda\AppData\Roaming\skypePM
2010-02-06 00:01:03 ----D---- C:\Program Files\LogMeIn
2010-02-05 23:57:40 ----D---- C:\Qoobox
2010-02-05 23:32:27 ----D---- C:\Windows\system32\drivers
2010-02-05 23:32:27 ----D---- C:\Windows\AppPatch
2010-02-05 23:32:26 ----D---- C:\Program Files\Common Files
2010-02-05 23:18:07 ----D---- C:\Windows\Prefetch
2010-02-05 23:16:21 ----A---- C:\Windows\NeroDigital.ini
2010-02-05 23:14:10 ----SHD---- C:\System Volume Information
2010-02-05 23:06:33 ----SHD---- C:\Windows\Installer
2010-02-05 22:50:55 ----D---- C:\Users\Jarda\AppData\Roaming\MxBoost
2010-02-05 22:05:05 ----D---- C:\Windows\winsxs
2010-02-05 21:06:08 ----D---- C:\Windows\system32\catroot
2010-02-05 21:06:06 ----D---- C:\Windows\system32\catroot2
2010-02-05 20:24:11 ----D---- C:\NVIDIA
2010-02-05 19:55:54 ----D---- C:\ipaq 614c
2010-02-05 19:51:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-05 19:51:10 ----D---- C:\Windows\inf
2010-02-05 19:44:30 ----D---- C:\install
2010-02-05 19:11:42 ----D---- C:\Program Files\Mozilla Firefox
2010-02-03 20:31:32 ----D---- C:\Downloads
2010-02-01 19:39:06 ----D---- C:\Windows\system32\LogFiles
2010-02-01 00:56:07 ----D---- C:\Program Files\Common Files\Steam
2010-01-31 21:49:17 ----D---- C:\Program Files\ModelH
2010-01-29 08:30:39 ----AD---- C:\ProgramData\TEMP
2010-01-27 23:31:32 ----D---- C:\Program Files\Internet Explorer
2010-01-27 20:41:24 ----HD---- C:\ProgramData
2010-01-26 23:53:07 ----D---- C:\rapid
2010-01-25 19:38:48 ----D---- C:\ProgramData\2DBoy
2010-01-22 18:47:49 ----D---- C:\Windows\system32\migration
2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-13 03:03:59 ----D---- C:\ProgramData\Microsoft Help
2010-01-13 03:02:58 ----D---- C:\Program Files\Windows Mail
2010-01-10 13:59:19 ----RSD---- C:\Windows\assembly
2010-01-06 19:18:25 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-05 01:17:46 ----A---- C:\Windows\system32\mrt.exe
2010-01-04 22:21:27 ----SD---- C:\Windows\Downloaded Program Files
2010-01-03 14:52:21 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-12-26 12:48:36 ----DC---- C:\Windows\system32\DRVSTORE
2009-12-26 12:47:59 ----D---- C:\Program Files\Common Files\InstallShield
2009-12-26 12:44:41 ----D---- C:\Program Files\Nokia
2009-12-19 11:57:39 ----A---- C:\Windows\avisplitter.INI
2009-12-19 11:53:51 ----D---- C:\Program Files\Common Files\PX Storage Engine
2009-12-14 20:12:43 ----D---- C:\Program Files\Java
2009-12-13 17:38:01 ----SD---- C:\Users\Jarda\AppData\Roaming\Microsoft
2009-12-08 20:43:27 ----D---- C:\Program Files\MediaCoder
2009-12-02 16:22:50 ----D---- C:\Program Files\Avanquest update
2009-11-25 03:36:22 ----D---- C:\Windows\rescache
2009-11-25 03:18:06 ----D---- C:\Windows\system32\cs-CZ
2009-11-24 16:40:55 ----D---- C:\Program Files\WinRAR
2009-11-23 22:29:13 ----D---- C:\ProgramData\Media Center Programs
2009-11-23 18:46:43 ----D---- C:\Users\Jarda\AppData\Roaming\WinRAR
2009-11-21 19:08:43 ----D---- C:\Manta
2009-11-21 03:34:54 ----A---- C:\Windows\system32\nvudisp.exe
2009-11-21 03:34:54 ----A---- C:\Windows\system32\nvd3dum.dll
2009-11-21 03:34:54 ----A---- C:\Windows\system32\nvapi.dll
2009-11-20 18:56:35 ----D---- C:\Program Files\NVIDIA Corporation
2009-11-20 17:58:26 ----D---- C:\Program Files\DAEMON Tools Pro
2009-11-19 21:42:56 ----A---- C:\Windows\system32\NVUNINST.EXE
2009-11-17 15:10:48 ----D---- C:\Windows\system32\wbem
2009-11-17 15:10:47 ----D---- C:\Windows\system32\zh-HK
2009-11-17 15:10:47 ----D---- C:\Windows\system32\uk-UA
2009-11-17 15:10:47 ----D---- C:\Windows\system32\sl-SI
2009-11-17 15:10:47 ----D---- C:\Windows\system32\pt-PT
2009-11-17 15:10:47 ----D---- C:\Windows\system32\pt-BR
2009-11-17 15:10:47 ----D---- C:\Windows\system32\pl-PL
2009-11-17 15:10:47 ----D---- C:\Windows\system32\ko-KR
2009-11-17 15:10:47 ----D---- C:\Windows\system32\it-IT
2009-11-17 15:10:47 ----D---- C:\Windows\system32\hu-HU
2009-11-17 15:10:47 ----D---- C:\Windows\system32\hr-HR
2009-11-17 15:10:47 ----D---- C:\Windows\system32\he-IL
2009-11-17 15:10:47 ----D---- C:\Windows\system32\bg-BG
2009-11-17 15:10:46 ----D---- C:\Windows\system32\zh-TW
2009-11-17 15:10:46 ----D---- C:\Windows\system32\zh-CN
2009-11-17 15:10:46 ----D---- C:\Windows\system32\tr-TR
2009-11-17 15:10:46 ----D---- C:\Windows\system32\th-TH
2009-11-17 15:10:46 ----D---- C:\Windows\system32\sv-SE
2009-11-17 15:10:46 ----D---- C:\Windows\system32\sr-Latn-CS
2009-11-17 15:10:46 ----D---- C:\Windows\system32\sk-SK
2009-11-17 15:10:46 ----D---- C:\Windows\system32\nl-NL
2009-11-17 15:10:46 ----D---- C:\Windows\system32\lv-LV
2009-11-17 15:10:46 ----D---- C:\Windows\system32\lt-LT
2009-11-17 15:10:46 ----D---- C:\Windows\system32\ja-JP
2009-11-17 15:10:46 ----D---- C:\Windows\system32\fr-FR
2009-11-17 15:10:46 ----D---- C:\Windows\system32\fi-FI
2009-11-17 15:10:46 ----D---- C:\Windows\system32\et-EE
2009-11-17 15:10:46 ----D---- C:\Windows\system32\es-ES
2009-11-17 15:10:46 ----D---- C:\Windows\system32\el-GR
2009-11-17 15:10:46 ----D---- C:\Windows\system32\de-DE
2009-11-17 15:10:46 ----D---- C:\Windows\system32\ar-SA
2009-11-17 15:10:45 ----D---- C:\Windows\system32\ru-RU
2009-11-17 15:10:45 ----D---- C:\Windows\system32\ro-RO
2009-11-17 15:10:45 ----D---- C:\Windows\system32\nb-NO
2009-11-17 15:10:45 ----D---- C:\Windows\system32\en-US
2009-11-17 15:10:45 ----D---- C:\Windows\system32\da-DK
2009-11-16 23:28:07 ----D---- C:\Program Files\Mount&Blade
2009-11-11 18:39:19 ----D---- C:\Program Files\Google
2009-11-10 22:42:13 ----D---- C:\Users\Jarda\AppData\Roaming\Vso
2009-11-08 10:31:44 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATITool;ATITool Overclocking Utility; C:\Windows\system32\DRIVERS\ATITool.sys [2007-08-08 28968]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-15 281760]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-15 25888]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-10-17 47640]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-04-23 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-07-18 1841312]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-02-28 10144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-11-21 11515752]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-10-23 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-03-17 140288]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
R4 EOlmarikFix;EOlmarikFix; \??\C:\Users\Jarda\AppData\Local\Temp\EOlmalikFixer\EOlmarikFix.sys []
S1 EIO;EIO Driver; C:\Windows\system32\DRIVERS\EIO.sys []
S1 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Users\Jarda\AppData\Local\Temp\HWiNFO32.SYS []
S3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE; C:\Windows\system32\DRIVERS\3xHybrid.sys [2006-11-22 1121536]
S3 AteksoftAudio;WebCamera Plus Audio; C:\Windows\system32\drivers\ateksoftaudio.sys [2007-12-25 11776]
S3 catchme;catchme; \??\C:\Users\Jarda\AppData\Local\Temp\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 drmkaud;DekodÚr zvuk¨ DRM jßdra spoleŔnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2008-04-22 27672]
S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2007-06-27 53184]
S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2007-06-27 71488]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-03-23 15600]
S3 GKUPRO2D;GKUPRO2D; C:\Windows\System32\Drivers\GKUPRO2D.sys [2005-02-18 71168]
S3 HdAudAddService;OvladaŔ funkce Microsoft 1.1 UAA pro slu×bu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MarkFun_NT;MarkFun_NT; \??\C:\Program Files\markfun.w32 [2007-08-21 17912]
S3 MSKSSRV;Server proxy slu×by datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy sprßvce kvality datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jÝmka-jÝmka typu T datovřch proud¨ Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys []
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
S3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.08\RivaTuner32.sys [2008-03-10 9088]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\Windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108200]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]
S3 Ser2pl;Prolific2 Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys [2005-11-04 48640]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 usb_rndisx;AdaptÚr USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 USBCCID;LtecÝ za°ÝzenÝ Ŕipovřch karet USB; C:\Windows\system32\DRIVERS\usbccid.sys [2006-11-02 30208]
S3 winusb;OvladaŔ WinUsb; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-12-20 722416]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 GoogleUpdateBeta;Google Update Service; C:\Windows\system32\config\system [2010-02-06 22806528]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-04 1181328]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-04-13 73728]
R2 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe [2008-02-28 63040]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-11-20 122984]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-10-06 241734]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-10-23 382248]
S2 SCardSvrDAUpdaterSvc;Karta Smart Card SCardSvrDAUpdaterSvc; C:\Windows\system32\acluig.exe [2008-01-19 65536]
S2 SPService;SPService; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; D:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-11 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-01-26 326792]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#6 Příspěvek od motji »

Ale tohle je log ze Rsitu :roll: , já chtěla z combofixu - tento C:\logcmbfix.txt.
Chci vidět co combofix smazal :) .
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#7 Příspěvek od jsykora »

ale to je log z combofixu c:\logcmbfix.txt

Logfile of random's system information tool 1.06 (written by random/random)
Run by Jarda at 2010-02-06 00:27:02
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 118 GB (47%) free of 249 GB
Total RAM: 3582 MB (54% free)

HijackThis download failed

======Scheduled tasks folder======

C:\Windows\tasks\Ad-Aware Update (Daily 1).job
C:\Windows\tasks\Ad-Aware Update (Daily 2).job
C:\Windows\tasks\Ad-Aware Update (Daily 3).job
C:\Windows\tasks\Ad-Aware Update (Daily 4).job
C:\Windows\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-08-26 279944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}]
FGCatchUrl - C:\Program Files\FlashGet\jccatch.dll [2007-08-06 94308]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-19 263280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-12-19 764912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2009-01-30 1114112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\WidgiToolbarIE.dll [2009-01-30 650752]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2008-08-26 279944]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-19 263280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-07-06 4669440]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdc.exe [2007-01-24 563080]
"LogMeIn GUI"=C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2008-02-28 63048]
"Flashget"=C:\Program Files\FlashGet\flashget.exe [2007-09-25 2007088]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"UpdatePDRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-01-04 222504]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2009-01-30 992256]
"BVRPLiveUpdate"=C:\Program Files\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\PROGRA~2\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT []
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-10-23 202024]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2006-09-10 218032]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-09-10 86960]
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-10 218032]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\HOMERunner.exe []
"Steam"=C:\Program Files\Steam\Steam.exe [2009-10-24 1217808]
"RGSC"=D:\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent []
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2009-04-13 2387968]
"PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-11 39408]
"igndlm.exe"=C:\Program Files\Download Manager\DLM.exe [2009-10-27 1103216]

C:\Users\Jarda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=0
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 3 months======

2010-02-06 00:27:02 ----D---- C:\rsit
2010-02-06 00:27:02 ----D---- C:\Program Files\trend micro
2010-02-06 00:21:33 ----D---- C:\Program Files\CCleaner
2010-02-05 23:49:37 ----SD---- C:\ComboFix
2010-02-05 23:25:33 ----A---- C:\Windows\NIRCMD.exe
2010-02-05 23:25:33 ----A---- C:\Windows\MBR.exe
2010-02-05 23:18:05 ----A---- C:\Windows\SWXCACLS.exe
2010-02-05 21:09:01 ----A---- C:\Windows\system32\kerberos.dll
2010-02-05 21:09:00 ----A---- C:\Windows\system32\schannel.dll
2010-01-31 21:49:12 ----A---- C:\Windows\GPInstall.exe
2010-01-27 20:41:24 ----D---- C:\ProgramData\PassMark
2010-01-27 20:41:20 ----D---- C:\Program Files\MonitorTest
2010-01-27 20:39:16 ----D---- C:\Program Files\Mihov Blank Screen
2010-01-21 21:12:08 ----A---- C:\Windows\system32\mshtml.dll
2010-01-21 21:12:07 ----A---- C:\Windows\system32\ieframe.dll
2010-01-21 21:12:06 ----A---- C:\Windows\system32\iertutil.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\wininet.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\urlmon.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\occache.dll
2010-01-21 21:12:05 ----A---- C:\Windows\system32\msfeeds.dll
2010-01-21 21:12:04 ----A---- C:\Windows\system32\iedkcs32.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\jsproxy.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\ieUnatt.exe
2010-01-21 21:12:03 ----A---- C:\Windows\system32\ieui.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\iesysprep.dll
2010-01-21 21:12:03 ----A---- C:\Windows\system32\iepeers.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\msfeedssync.exe
2010-01-21 21:12:02 ----A---- C:\Windows\system32\iesetup.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\iernonce.dll
2010-01-21 21:12:02 ----A---- C:\Windows\system32\ie4uinit.exe
2010-01-12 23:54:00 ----A---- C:\Windows\system32\t2embed.dll
2010-01-12 23:53:59 ----A---- C:\Windows\system32\fontsub.dll
2010-01-11 18:18:36 ----D---- C:\Users\Jarda\AppData\Roaming\HypoKalk
2010-01-11 18:00:52 ----D---- C:\Program Files\Komerční Banka
2010-01-10 13:57:45 ----HDC---- C:\ProgramData\{C2AE2ED8-999F-4EF7-AFD4-6772152D0F81}
2010-01-08 18:28:51 ----A---- C:\Windows\system32\ForceBindIP-Uninstaller.exe
2010-01-06 19:17:55 ----D---- C:\BDS
2010-01-04 22:25:53 ----D---- C:\Program Files\GameSpy Arcade
2010-01-04 22:22:48 ----D---- C:\Program Files\Download Manager
2010-01-04 22:21:27 ----D---- C:\Users\Jarda\AppData\Roaming\IGN_DLM
2010-01-03 15:25:36 ----SHD---- C:\ProgramData\SecuROM
2010-01-03 14:52:23 ----D---- C:\Windows\D56B0E274A3E46C9B5C1D93D580C099C.TMP
2009-12-29 13:29:42 ----D---- C:\keygen
2009-12-19 11:53:49 ----D---- C:\Program Files\Winamp
2009-12-14 20:12:45 ----A---- C:\Windows\system32\javaws.exe
2009-12-14 20:12:45 ----A---- C:\Windows\system32\javaw.exe
2009-12-14 20:12:45 ----A---- C:\Windows\system32\java.exe
2009-12-12 11:14:39 ----A---- C:\Windows\system32\nshhttp.dll
2009-12-12 11:14:37 ----A---- C:\Windows\system32\httpapi.dll
2009-12-09 21:16:49 ----A---- C:\Windows\system32\rastls.dll
2009-12-08 20:43:33 ----D---- C:\Users\Jarda\AppData\Roaming\Broad Intelligence
2009-11-30 18:02:40 ----A---- C:\Windows\system32\xliveinstall.dll
2009-11-30 18:02:38 ----A---- C:\Windows\system32\xliveinstallhost.exe
2009-11-29 22:54:58 ----A---- C:\Windows\system32\lsdelete.exe
2009-11-29 21:09:22 ----HDC---- C:\ProgramData\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-29 21:09:12 ----D---- C:\ProgramData\Lavasoft
2009-11-29 21:09:12 ----D---- C:\Program Files\Lavasoft
2009-11-29 19:08:31 ----RA---- C:\Windows\PEV.exe
2009-11-29 19:08:30 ----A---- C:\Windows\zip.exe
2009-11-29 19:08:30 ----A---- C:\Windows\SWSC.exe
2009-11-29 19:08:30 ----A---- C:\Windows\SWREG.exe
2009-11-29 19:08:30 ----A---- C:\Windows\sed.exe
2009-11-29 19:08:30 ----A---- C:\Windows\grep.exe
2009-11-25 03:01:36 ----A---- C:\Windows\system32\tzres.dll
2009-11-25 00:46:26 ----A---- C:\Windows\system32\msxml6.dll
2009-11-25 00:46:24 ----A---- C:\Windows\system32\msxml3.dll
2009-11-23 23:14:59 ----D---- C:\ProgramData\BioWare
2009-11-23 22:29:27 ----D---- C:\Windows\1C4551A64743409391E41477CD655043.TMP
2009-11-23 22:18:12 ----D---- C:\Program Files\Common Files\BioWare
2009-11-23 19:19:00 ----D---- C:\Users\Jarda\AppData\Roaming\Google
2009-11-23 19:00:16 ----D---- C:\Program Files\JDownloader
2009-11-22 11:54:00 ----D---- C:\ProgramData\Apple Computer
2009-11-22 11:54:00 ----D---- C:\Program Files\QuickTime
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvvsvc.exe
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvsvc.dll
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvmctray.dll
2009-11-20 20:33:00 ----A---- C:\Windows\system32\nvcpl.dll
2009-11-20 18:53:04 ----A---- C:\Windows\system32\OpenCL.dll
2009-11-20 18:53:03 ----A---- C:\Windows\system32\nvwgf2um.dll
2009-11-20 18:53:03 ----A---- C:\Windows\system32\nvoglv32.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcuvid.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcuvenc.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcuda.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcompiler.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcod178.dll
2009-11-20 18:53:01 ----A---- C:\Windows\system32\nvcod.dll
2009-11-19 19:35:20 ----A---- C:\Windows\system32\XAudio2_5.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\xactengine3_5.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\D3DX9_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\d3dx11_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\d3dx10_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\d3dcsx_42.dll
2009-11-19 19:35:19 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2009-11-19 19:35:13 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-11-19 19:35:08 ----A---- C:\Windows\system32\XAudio2_3.dll
2009-11-19 19:35:08 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2009-11-19 19:35:07 ----A---- C:\Windows\system32\xactengine3_3.dll
2009-11-19 19:35:07 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2009-11-19 19:35:06 ----A---- C:\Windows\system32\XAudio2_2.dll
2009-11-19 19:35:06 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2009-11-19 19:35:05 ----A---- C:\Windows\system32\xactengine3_2.dll
2009-11-17 15:10:49 ----D---- C:\Program Files\Windows Portable Devices
2009-11-17 02:23:43 ----A---- C:\Windows\system32\UIRibbonRes.dll
2009-11-17 02:23:43 ----A---- C:\Windows\system32\UIRibbon.dll
2009-11-17 02:23:43 ----A---- C:\Windows\system32\UIAnimation.dll
2009-11-17 02:23:23 ----A---- C:\Windows\system32\WMPhoto.dll
2009-11-17 02:23:23 ----A---- C:\Windows\system32\cdd.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\xpsservices.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\XpsRasterService.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\XpsPrint.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\WindowsCodecs.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2009-11-17 02:23:22 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\OpcServices.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\FntCache.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\dxgi.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\dxdiagn.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\dxdiag.exe
2009-11-17 02:23:22 ----A---- C:\Windows\system32\DWrite.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d11.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10warp.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10level9.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10core.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10_1core.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10_1.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d3d10.dll
2009-11-17 02:23:22 ----A---- C:\Windows\system32\d2d1.dll
2009-11-17 02:22:53 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2009-11-17 02:22:53 ----A---- C:\Windows\system32\wpdbusenum.dll
2009-11-17 02:22:53 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2009-11-17 02:22:49 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WPDSp.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\wpdshext.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WpdMtpUS.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WpdMtp.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\WpdConns.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\wpd_ci.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2009-11-17 02:22:48 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2009-11-17 02:21:41 ----A---- C:\Windows\system32\UIAutomationCore.dll
2009-11-17 02:21:41 ----A---- C:\Windows\system32\oleaccrc.dll
2009-11-17 02:21:41 ----A---- C:\Windows\system32\oleacc.dll
2009-11-11 21:29:49 ----A---- C:\Windows\system32\WSDApi.dll
2009-11-11 18:39:03 ----D---- C:\ProgramData\Google
2009-11-11 18:38:46 ----D---- C:\Users\Jarda\AppData\Roaming\IrfanView
2009-11-11 18:38:45 ----D---- C:\Program Files\IrfanView
2009-11-08 23:54:32 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-11-08 23:54:32 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-11-08 23:54:31 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-11-08 23:54:29 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-11-08 23:54:28 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-11-08 23:54:28 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-11-08 23:54:24 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-11-08 23:54:24 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-11-08 23:54:23 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-11-08 10:31:45 ----D---- C:\Program Files\Common Files\Skype
2009-11-08 10:31:44 ----RD---- C:\Program Files\Skype

======List of files/folders modified in the last 3 months======

2010-02-06 00:27:02 ----RD---- C:\Program Files
2010-02-06 00:26:54 ----D---- C:\Windows\Temp
2010-02-06 00:23:44 ----D---- C:\Windows\Minidump
2010-02-06 00:23:44 ----D---- C:\Windows\Debug
2010-02-06 00:23:44 ----D---- C:\Windows
2010-02-06 00:17:19 ----D---- C:\Users\Jarda\AppData\Roaming\Skype
2010-02-06 00:12:11 ----D---- C:\Windows\Tasks
2010-02-06 00:12:11 ----D---- C:\Windows\system32\Tasks
2010-02-06 00:11:43 ----D---- C:\ProgramData\NVIDIA
2010-02-06 00:11:42 ----D---- C:\Windows\System32
2010-02-06 00:11:41 ----D---- C:\Program Files\Steam
2010-02-06 00:07:14 ----D---- C:\Users\Jarda\AppData\Roaming\skypePM
2010-02-06 00:01:03 ----D---- C:\Program Files\LogMeIn
2010-02-05 23:57:40 ----D---- C:\Qoobox
2010-02-05 23:32:27 ----D---- C:\Windows\system32\drivers
2010-02-05 23:32:27 ----D---- C:\Windows\AppPatch
2010-02-05 23:32:26 ----D---- C:\Program Files\Common Files
2010-02-05 23:18:07 ----D---- C:\Windows\Prefetch
2010-02-05 23:16:21 ----A---- C:\Windows\NeroDigital.ini
2010-02-05 23:14:10 ----SHD---- C:\System Volume Information
2010-02-05 23:06:33 ----SHD---- C:\Windows\Installer
2010-02-05 22:50:55 ----D---- C:\Users\Jarda\AppData\Roaming\MxBoost
2010-02-05 22:05:05 ----D---- C:\Windows\winsxs
2010-02-05 21:06:08 ----D---- C:\Windows\system32\catroot
2010-02-05 21:06:06 ----D---- C:\Windows\system32\catroot2
2010-02-05 20:24:11 ----D---- C:\NVIDIA
2010-02-05 19:55:54 ----D---- C:\ipaq 614c
2010-02-05 19:51:11 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-05 19:51:10 ----D---- C:\Windows\inf
2010-02-05 19:44:30 ----D---- C:\install
2010-02-05 19:11:42 ----D---- C:\Program Files\Mozilla Firefox
2010-02-03 20:31:32 ----D---- C:\Downloads
2010-02-01 19:39:06 ----D---- C:\Windows\system32\LogFiles
2010-02-01 00:56:07 ----D---- C:\Program Files\Common Files\Steam
2010-01-31 21:49:17 ----D---- C:\Program Files\ModelH
2010-01-29 08:30:39 ----AD---- C:\ProgramData\TEMP
2010-01-27 23:31:32 ----D---- C:\Program Files\Internet Explorer
2010-01-27 20:41:24 ----HD---- C:\ProgramData
2010-01-26 23:53:07 ----D---- C:\rapid
2010-01-25 19:38:48 ----D---- C:\ProgramData\2DBoy
2010-01-22 18:47:49 ----D---- C:\Windows\system32\migration
2010-01-14 11:12:06 ----N---- C:\Windows\system32\MpSigStub.exe
2010-01-13 03:03:59 ----D---- C:\ProgramData\Microsoft Help
2010-01-13 03:02:58 ----D---- C:\Program Files\Windows Mail
2010-01-10 13:59:19 ----RSD---- C:\Windows\assembly
2010-01-06 19:18:25 ----HD---- C:\Program Files\InstallShield Installation Information
2010-01-05 01:17:46 ----A---- C:\Windows\system32\mrt.exe
2010-01-04 22:21:27 ----SD---- C:\Windows\Downloaded Program Files
2010-01-03 14:52:21 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-12-26 12:48:36 ----DC---- C:\Windows\system32\DRVSTORE
2009-12-26 12:47:59 ----D---- C:\Program Files\Common Files\InstallShield
2009-12-26 12:44:41 ----D---- C:\Program Files\Nokia
2009-12-19 11:57:39 ----A---- C:\Windows\avisplitter.INI
2009-12-19 11:53:51 ----D---- C:\Program Files\Common Files\PX Storage Engine
2009-12-14 20:12:43 ----D---- C:\Program Files\Java
2009-12-13 17:38:01 ----SD---- C:\Users\Jarda\AppData\Roaming\Microsoft
2009-12-08 20:43:27 ----D---- C:\Program Files\MediaCoder
2009-12-02 16:22:50 ----D---- C:\Program Files\Avanquest update
2009-11-25 03:36:22 ----D---- C:\Windows\rescache
2009-11-25 03:18:06 ----D---- C:\Windows\system32\cs-CZ
2009-11-24 16:40:55 ----D---- C:\Program Files\WinRAR
2009-11-23 22:29:13 ----D---- C:\ProgramData\Media Center Programs
2009-11-23 18:46:43 ----D---- C:\Users\Jarda\AppData\Roaming\WinRAR
2009-11-21 19:08:43 ----D---- C:\Manta
2009-11-21 03:34:54 ----A---- C:\Windows\system32\nvudisp.exe
2009-11-21 03:34:54 ----A---- C:\Windows\system32\nvd3dum.dll
2009-11-21 03:34:54 ----A---- C:\Windows\system32\nvapi.dll
2009-11-20 18:56:35 ----D---- C:\Program Files\NVIDIA Corporation
2009-11-20 17:58:26 ----D---- C:\Program Files\DAEMON Tools Pro
2009-11-19 21:42:56 ----A---- C:\Windows\system32\NVUNINST.EXE
2009-11-17 15:10:48 ----D---- C:\Windows\system32\wbem
2009-11-17 15:10:47 ----D---- C:\Windows\system32\zh-HK
2009-11-17 15:10:47 ----D---- C:\Windows\system32\uk-UA
2009-11-17 15:10:47 ----D---- C:\Windows\system32\sl-SI
2009-11-17 15:10:47 ----D---- C:\Windows\system32\pt-PT
2009-11-17 15:10:47 ----D---- C:\Windows\system32\pt-BR
2009-11-17 15:10:47 ----D---- C:\Windows\system32\pl-PL
2009-11-17 15:10:47 ----D---- C:\Windows\system32\ko-KR
2009-11-17 15:10:47 ----D---- C:\Windows\system32\it-IT
2009-11-17 15:10:47 ----D---- C:\Windows\system32\hu-HU
2009-11-17 15:10:47 ----D---- C:\Windows\system32\hr-HR
2009-11-17 15:10:47 ----D---- C:\Windows\system32\he-IL
2009-11-17 15:10:47 ----D---- C:\Windows\system32\bg-BG
2009-11-17 15:10:46 ----D---- C:\Windows\system32\zh-TW
2009-11-17 15:10:46 ----D---- C:\Windows\system32\zh-CN
2009-11-17 15:10:46 ----D---- C:\Windows\system32\tr-TR
2009-11-17 15:10:46 ----D---- C:\Windows\system32\th-TH
2009-11-17 15:10:46 ----D---- C:\Windows\system32\sv-SE
2009-11-17 15:10:46 ----D---- C:\Windows\system32\sr-Latn-CS
2009-11-17 15:10:46 ----D---- C:\Windows\system32\sk-SK
2009-11-17 15:10:46 ----D---- C:\Windows\system32\nl-NL
2009-11-17 15:10:46 ----D---- C:\Windows\system32\lv-LV
2009-11-17 15:10:46 ----D---- C:\Windows\system32\lt-LT
2009-11-17 15:10:46 ----D---- C:\Windows\system32\ja-JP
2009-11-17 15:10:46 ----D---- C:\Windows\system32\fr-FR
2009-11-17 15:10:46 ----D---- C:\Windows\system32\fi-FI
2009-11-17 15:10:46 ----D---- C:\Windows\system32\et-EE
2009-11-17 15:10:46 ----D---- C:\Windows\system32\es-ES
2009-11-17 15:10:46 ----D---- C:\Windows\system32\el-GR
2009-11-17 15:10:46 ----D---- C:\Windows\system32\de-DE
2009-11-17 15:10:46 ----D---- C:\Windows\system32\ar-SA
2009-11-17 15:10:45 ----D---- C:\Windows\system32\ru-RU
2009-11-17 15:10:45 ----D---- C:\Windows\system32\ro-RO
2009-11-17 15:10:45 ----D---- C:\Windows\system32\nb-NO
2009-11-17 15:10:45 ----D---- C:\Windows\system32\en-US
2009-11-17 15:10:45 ----D---- C:\Windows\system32\da-DK
2009-11-16 23:28:07 ----D---- C:\Program Files\Mount&Blade
2009-11-11 18:39:19 ----D---- C:\Program Files\Google
2009-11-10 22:42:13 ----D---- C:\Users\Jarda\AppData\Roaming\Vso
2009-11-08 10:31:44 ----D---- C:\ProgramData\Skype

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATITool;ATITool Overclocking Utility; C:\Windows\system32\DRIVERS\ATITool.sys [2007-08-08 28968]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2009-10-15 281760]
R2 eamon;eamon; C:\Windows\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R2 epfwwfpr;epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [2009-12-18 95896]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2009-10-15 25888]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-10-17 47640]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-04-23 26176]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-07-18 1841312]
R3 lmimirr;lmimirr; C:\Windows\system32\DRIVERS\lmimirr.sys [2008-02-28 10144]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-11-21 11515752]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-10-23 47360]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-03-17 140288]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
R4 EOlmarikFix;EOlmarikFix; \??\C:\Users\Jarda\AppData\Local\Temp\EOlmalikFixer\EOlmarikFix.sys []
S1 EIO;EIO Driver; C:\Windows\system32\DRIVERS\EIO.sys []
S1 HWiNFO32;HWiNFO32 Kernel Driver; \??\C:\Users\Jarda\AppData\Local\Temp\HWiNFO32.SYS []
S3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE; C:\Windows\system32\DRIVERS\3xHybrid.sys [2006-11-22 1121536]
S3 AteksoftAudio;WebCamera Plus Audio; C:\Windows\system32\drivers\ateksoftaudio.sys [2007-12-25 11776]
S3 catchme;catchme; \??\C:\Users\Jarda\AppData\Local\Temp\catchme.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\C:\Program Files\MediaCoder\SysInfo.sys [2007-09-25 15152]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2008-04-22 27672]
S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2007-06-27 53184]
S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2007-06-27 71488]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2009-03-23 15600]
S3 GKUPRO2D;GKUPRO2D; C:\Windows\System32\Drivers\GKUPRO2D.sys [2005-02-18 71168]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MarkFun_NT;MarkFun_NT; \??\C:\Program Files\markfun.w32 [2007-08-21 17912]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys []
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card; C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 1131136]
S3 RivaTuner32;RivaTuner32; \??\C:\Program Files\RivaTuner v2.08\RivaTuner32.sys [2008-03-10 9088]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM); C:\Windows\system32\DRIVERS\s1018bus.sys [2008-11-04 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s1018mdfl.sys [2008-11-04 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s1018mdm.sys [2008-11-04 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s1018mgmt.sys [2008-11-04 108200]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS); C:\Windows\system32\DRIVERS\s1018nd5.sys [2008-11-04 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s1018obex.sys [2008-11-04 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM); C:\Windows\system32\DRIVERS\s1018unic.sys [2008-11-04 109736]
S3 Ser2pl;Prolific2 Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys [2005-11-04 48640]
S3 upperdev;upperdev; C:\Windows\system32\DRIVERS\usbser_lowerflt.sys []
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2009-04-11 15872]
S3 USBCCID;Čtecí zařízení čipových karet USB; C:\Windows\system32\DRIVERS\usbccid.sys [2006-11-02 30208]
S3 winusb;Ovladač WinUsb; C:\Windows\system32\DRIVERS\winusb.sys [2009-04-11 31616]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S4 LMIRfsClientNP;LMIRfsClientNP; C:\Windows\system32\drivers\LMIRfsClientNP.sys []
S4 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2009-12-20 722416]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2008-10-27 759072]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 GoogleUpdateBeta;Google Update Service; C:\Windows\system32\config\system [2010-02-06 22806528]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-04 1181328]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2009-04-13 73728]
R2 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\x86\LogMeIn.exe [2008-02-28 63040]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 71096]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-11-20 122984]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-10-06 241734]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-11-20 240232]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-10-23 382248]
S2 SCardSvrDAUpdaterSvc;Karta Smart Card SCardSvrDAUpdaterSvc; C:\Windows\system32\acluig.exe [2008-01-19 65536]
S2 SPService;SPService; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; D:\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-07-26 25832]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-11 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-01-26 326792]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#8 Příspěvek od motji »

Tohle je log ze Rsitu
Logfile of random's system information tool 1.06

Log z combofixu vypadá uplně jinak :roll: .
pokud ho opravdu nenajdete, spustte combofix znovu a vložte zde log :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#9 Příspěvek od jsykora »

spustit --- notepad "C:\ComboFix.txt" --- chce vytvořit soubor, combofix.txt v rootu není
edit:tahám & spustím

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#10 Příspěvek od motji »

Ok, návod

:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#11 Příspěvek od jsykora »

přiznám se, že Tvou zprávu o vypnutí Firewallu apod. jsem si přečetl až teď, snad nebude ten log k ničemu (běžel Nod32 AV4, Ad-aware, Defender)
ComboFix 10-02-08.02 - Jarda 08.02.2010 23:29:29.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3582.1806 [GMT 1:00]
Spuštěný z: C:\ComboFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\2953887910.dat
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\sdra64.exe
c:\windows\temp\3301729911.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-08 do 2010-02-08 )))))))))))))))))))))))))))))))
.

2010-02-08 22:40 . 2010-02-08 22:40 32 ------w- c:\windows\system32\2953887910.dat
2010-02-08 22:37 . 2010-02-08 22:42 -------- d-----w- c:\users\Jarda\AppData\Local\temp
2010-02-08 22:37 . 2010-02-08 22:37 -------- d-----w- c:\users\Martin\AppData\Local\temp
2010-02-08 22:37 . 2010-02-08 22:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-08 22:25 . 2010-02-08 22:26 3851594 ----a-r- C:\ComboFix.exe
2010-02-06 18:57 . 2010-02-06 18:57 71729122 ----a-w- C:\02-02-100118-19-POP-408-000.zip
2010-02-06 02:19 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-02-06 00:43 . 2010-02-08 19:14 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-06 00:43 . 2010-02-08 19:12 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-06 00:18 . 2010-02-06 00:41 -------- d-----w- C:\SysProt
2010-02-05 23:27 . 2010-02-08 19:38 -------- d-----w- c:\program files\trend micro
2010-02-05 23:27 . 2010-02-05 23:27 -------- d-----w- C:\rsit
2010-02-05 23:21 . 2010-02-05 23:21 -------- d-----w- c:\program files\CCleaner
2010-02-05 20:09 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2010-02-05 20:09 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-01-31 20:49 . 2010-01-31 20:49 796672 ----a-w- c:\windows\GPInstall.exe
2010-01-27 19:41 . 2010-01-27 19:41 -------- d-----w- c:\programdata\PassMark
2010-01-27 19:41 . 2010-01-29 07:27 -------- d-----w- c:\program files\MonitorTest
2010-01-27 19:39 . 2010-01-27 19:39 -------- d-----w- c:\program files\Mihov Blank Screen
2010-01-12 22:54 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-12 22:53 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-11 17:18 . 2010-01-11 17:23 -------- d-----w- c:\users\Jarda\AppData\Roaming\HypoKalk
2010-01-11 17:00 . 2010-01-11 17:00 -------- d-----w- c:\program files\Komerční Banka
2010-01-10 12:57 . 2010-01-10 12:57 -------- dc-h--w- c:\programdata\{C2AE2ED8-999F-4EF7-AFD4-6772152D0F81}
2010-01-10 12:55 . 2010-01-10 12:55 -------- d-----w- c:\users\Jarda\AppData\Local\PackageAware

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 22:42 . 2008-02-06 16:40 -------- d-----w- c:\users\Jarda\AppData\Roaming\Skype
2010-02-08 22:40 . 2009-05-14 22:43 79487 ----a-w- c:\programdata\nvModes.dat
2010-02-08 22:40 . 2008-11-13 16:09 -------- d-----w- c:\program files\Steam
2010-02-08 22:40 . 2008-02-03 16:15 -------- d-----w- c:\programdata\NVIDIA
2010-02-08 22:38 . 2008-03-23 17:10 12 ----a-w- c:\windows\bthservsdp.dat
2010-02-08 22:38 . 2008-02-03 16:21 -------- d-----w- c:\users\Jarda\AppData\Roaming\MxBoost
2010-02-08 22:25 . 2007-01-08 21:09 601848 ----a-w- c:\windows\system32\perfh005.dat
2010-02-08 22:25 . 2007-01-08 21:09 115976 ----a-w- c:\windows\system32\perfc005.dat
2010-02-08 19:08 . 2008-02-06 16:42 -------- d-----w- c:\users\Jarda\AppData\Roaming\skypePM
2010-02-08 19:08 . 2008-06-01 09:01 -------- d-----w- c:\program files\LogMeIn
2010-02-05 23:39 . 2009-04-10 09:08 -------- d-----w- c:\program files\pdfforge Toolbar
2010-02-04 20:13 . 2009-11-29 20:11 389784 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-04 20:13 . 2009-11-29 20:11 3803208 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-04 20:13 . 2009-11-29 20:11 823928 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-04 20:13 . 2009-11-29 20:11 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-01-31 23:56 . 2008-11-13 16:09 -------- d-----w- c:\program files\Common Files\Steam
2010-01-31 20:49 . 2009-04-02 14:19 -------- d-----w- c:\program files\ModelH
2010-01-28 20:07 . 2008-02-03 15:31 105984 ----a-w- c:\users\Jarda\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-27 14:12 . 2009-11-29 20:11 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-27 14:12 . 2009-11-29 21:54 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-01-27 14:12 . 2009-11-29 20:11 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-27 14:12 . 2009-11-29 20:11 15880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-01-27 14:12 . 2009-11-29 20:11 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-27 14:12 . 2009-11-29 20:11 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-27 14:12 . 2009-11-29 20:11 163728 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-01-27 14:12 . 2009-11-29 20:11 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-27 14:12 . 2009-11-29 20:11 87496 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-01-27 14:11 . 2009-11-29 20:11 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-27 14:11 . 2009-11-29 20:11 816784 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-27 14:11 . 2009-11-29 20:11 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-27 14:11 . 2009-11-29 20:11 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-27 08:11 . 2009-11-29 20:11 8 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-27 08:11 . 2009-11-29 20:11 327000 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-01-26 20:30 . 2009-11-23 18:00 -------- d-----w- c:\program files\JDownloader
2010-01-25 18:38 . 2009-01-21 20:23 -------- d-----w- c:\programdata\2DBoy
2010-01-14 10:12 . 2009-10-02 18:18 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 02:03 . 2008-02-03 19:10 -------- d-----w- c:\programdata\Microsoft Help
2010-01-13 02:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-11 17:00 . 2010-01-11 17:00 3638 ----a-r- c:\users\Jarda\AppData\Roaming\Microsoft\Installer\{998C31A1-0FE0-4C33-877C-C6DA1376B24D}\_B868B6B6F4EDFD5E8EBDFB.exe
2010-01-11 17:00 . 2010-01-11 17:00 10134 ----a-r- c:\users\Jarda\AppData\Roaming\Microsoft\Installer\{998C31A1-0FE0-4C33-877C-C6DA1376B24D}\_B641BF25E9A07F9A33B31F.exe
2010-01-11 17:00 . 2010-01-11 17:00 -------- d-----w- c:\program files\Komerční Banka
2010-01-08 20:29 . 2010-01-04 21:25 -------- d-----w- c:\program files\GameSpy Arcade
2010-01-08 20:26 . 2010-01-08 17:28 48471 ----a-w- c:\windows\system32\ForceBindIP-Uninstaller.exe
2010-01-06 18:18 . 2008-02-03 19:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-06 16:31 . 2008-02-03 15:30 1356 ----a-w- c:\users\Jarda\AppData\Local\d3d9caps.dat
2010-01-04 21:25 . 2010-01-04 21:21 -------- d-----w- c:\users\Jarda\AppData\Roaming\IGN_DLM
2010-01-04 21:22 . 2010-01-04 21:22 -------- d-----w- c:\program files\Download Manager
2010-01-03 14:25 . 2010-01-03 14:25 -------- d-sh--w- c:\programdata\SecuROM
2010-01-03 13:52 . 2008-04-03 19:58 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-02 06:38 . 2010-01-21 20:12 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-21 20:12 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-21 20:12 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-21 20:12 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-26 11:47 . 2008-02-03 16:04 -------- d-----w- c:\program files\Common Files\InstallShield
2009-12-26 11:44 . 2009-06-07 11:11 -------- d-----w- c:\program files\Nokia
2009-12-20 16:42 . 2008-02-04 23:30 722416 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-20 16:20 . 2009-12-19 10:53 -------- d-----w- c:\program files\Winamp
2009-12-19 10:53 . 2009-06-21 23:21 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-18 14:02 . 2009-12-18 14:02 95896 ----a-w- c:\windows\system32\drivers\epfwwfpr.sys
2009-12-14 19:12 . 2009-07-04 10:55 -------- d-----w- c:\program files\Java
2009-11-30 17:02 . 2009-11-30 17:02 171144 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-30 17:02 . 2009-11-30 17:02 72840 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-29 20:11 . 2009-11-29 20:11 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-29 20:11 . 2009-11-29 20:11 93360 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-29 20:11 . 2009-11-29 20:11 554280 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-29 20:11 . 2009-11-29 20:11 212480 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-29 20:11 . 2009-11-29 20:11 283944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-29 20:11 . 2009-11-29 20:11 1223976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-29 20:11 . 2009-11-29 20:11 242984 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-20 19:33 . 2009-11-20 19:33 812648 ----a-w- c:\windows\system32\nvsvc.dll
2009-11-20 19:33 . 2009-11-20 19:33 12685928 ----a-w- c:\windows\system32\nvcpl.dll
2009-11-20 19:33 . 2009-11-20 19:33 122984 ----a-w- c:\windows\system32\nvvsvc.exe
2009-11-20 19:33 . 2009-11-20 19:33 110184 ----a-w- c:\windows\system32\nvmctray.dll
2009-11-19 20:42 . 2008-02-03 16:04 592488 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-11-16 08:03 . 2009-11-16 08:03 108792 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-11-16 07:56 . 2009-11-16 07:56 116520 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-03-23 00:05 . 2009-03-23 00:05 29 ----a-w- c:\program files\new_ver.ini
2008-02-14 13:28 . 2008-02-14 13:28 29 ----a-w- c:\program files\version.ini
2008-02-14 13:23 . 2008-02-14 13:23 231944 ----a-w- c:\program files\gwflash.exe
2007-09-21 18:42 . 2007-09-21 18:42 19008 ----a-w- c:\program files\markfun.a64
2007-08-21 18:49 . 2007-08-21 18:49 125504 ----a-w- c:\program files\MarkFunDrv.dll
2007-08-21 18:49 . 2007-08-21 18:49 17912 ----a-w- c:\program files\markfun.w32
2007-04-04 17:35 . 2007-04-04 17:35 207680 ----a-w- c:\program files\updateutility.exe
2007-03-30 03:36 . 2007-03-30 03:36 301 ----a-w- c:\program files\update.ini
2007-03-02 03:48 . 2007-03-02 03:48 240448 ----a-w- c:\program files\gwf32.exe
2006-11-23 22:47 . 2006-11-23 22:47 207680 ----a-w- c:\program files\BIOS_Run.exe
2006-11-23 22:40 . 2006-11-23 22:40 60224 ----a-w- c:\program files\HUADRV.DLL
2006-11-03 17:09 . 2006-11-03 17:09 528 ----a-w- c:\program files\CONFIG.INI
2005-04-27 18:40 . 2005-04-27 18:40 6800 ----a-w- c:\program files\W95_HUA.vxd
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-26 08:32 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
2009-01-30 13:12 650752 ----a-w- c:\program files\pdfforge Toolbar\WidgiToolbarIE.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"= "c:\program files\pdfforge Toolbar\WidgiToolbarIE.dll" [2009-01-30 650752]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]

[HKEY_CLASSES_ROOT\clsid\{b922d405-6d13-4a2b-ae89-08a030da4402}]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-10 218032]
"Steam"="c:\program files\Steam\Steam.exe" [2009-10-24 1217808]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-04-13 2387968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-11 39408]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"Flashget"="c:\program files\FlashGet\flashget.exe" [2007-09-25 2007088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2009-01-30 992256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]

c:\users\Jarda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):16,87,63,38,cb,37,ca,01

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [29.11.2009 21:11 64288]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [16.11.2009 9:03 108792]
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [27.10.2008 17:03 759072]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 9:04 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\System32\drivers\epfwwfpr.sys [18.12.2009 15:02 95896]
R2 GoogleUpdateBeta;Google Update Service;c:\windows\System32\config\systemprofile\AppData\Local\Google\Update\GoogleUpdateBeta.exe [14.12.2009 18:02 53248]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24.9.2009 12:17 1181328]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28.2.2008 14:31 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\System32\drivers\LMIRfsDriver.sys [1.6.2008 10:01 47640]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [20.11.2009 19:17 240232]
S2 SCardSvrDAUpdaterSvc;Karta Smart Card SCardSvrDAUpdaterSvc;c:\windows\system32\acluig.exe srv --> c:\windows\system32\acluig.exe srv [?]
S2 wscsvcBITS;Centrum zabezpečení wscsvcBITS;c:\windows\system32\adtschemah.exe srv --> c:\windows\system32\adtschemah.exe srv [?]
S3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;c:\windows\System32\drivers\3xHybrid.sys [11.7.2009 11:49 1121536]
S3 AteksoftAudio;WebCamera Plus Audio;c:\windows\System32\drivers\ateksoftaudio.sys [30.4.2008 0:22 11776]
S3 BGMYRQ;BGMYRQ;c:\users\Jarda\AppData\Local\Temp\BGMYRQ.exe --> c:\users\Jarda\AppData\Local\Temp\BGMYRQ.exe [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;d:\dragon age\bin_ship\daupdatersvc.service.exe [23.11.2009 22:24 25832]
S3 FKEKD;FKEKD;c:\users\Jarda\AppData\Local\Temp\FKEKD.exe --> c:\users\Jarda\AppData\Local\Temp\FKEKD.exe [?]
S3 FontCache;Mezipaměť písem Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [27.7.2008 17:42 21504]
S3 GKUPRO2D;GKUPRO2D;c:\windows\System32\drivers\GKUPRO2D.sys [18.2.2005 11:57 71168]
S3 JLJORTUI;JLJORTUI;c:\users\Jarda\AppData\Local\Temp\JLJORTUI.exe --> c:\users\Jarda\AppData\Local\Temp\JLJORTUI.exe [?]
S3 JSIOH;JSIOH;c:\users\Jarda\AppData\Local\Temp\JSIOH.exe --> c:\users\Jarda\AppData\Local\Temp\JSIOH.exe [?]
S3 MarkFun_NT;MarkFun_NT;c:\program files\markfun.w32 [21.8.2007 19:49 17912]
S3 Ph3xIB32;Philips 713x Inbox PCI TV Card;c:\windows\System32\drivers\Ph3xIB32.sys [3.4.2007 9:43 1131136]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\System32\drivers\s1018bus.sys [2.8.2009 9:17 86696]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\System32\drivers\s1018mdfl.sys [2.8.2009 9:17 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\System32\drivers\s1018mdm.sys [2.8.2009 9:17 114472]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s1018mgmt.sys [2.8.2009 9:17 108200]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\System32\drivers\s1018nd5.sys [2.8.2009 9:17 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\System32\drivers\s1018obex.sys [2.8.2009 9:17 104616]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\System32\drivers\s1018unic.sys [2.8.2009 9:17 109736]
S4 sptd;sptd;c:\windows\System32\drivers\sptd.sys [5.2.2008 0:30 722416]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-04-13 13:08 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-02-08 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:13]

2010-02-08 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:13]

2010-02-08 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:13]

2010-02-08 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:13]

2010-02-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:13]
.
.
------- Doplňkový sken -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\wpclsp.dll
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/update ... 0.21.0.cab
FF - ProfilePath - c:\users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\odqs0qne.default\
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\users\Jarda\AppData\Roaming\Mozilla\Firefox\Profiles\odqs0qne.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - c:\program files\pdfforge Toolbar\SearchSettings.dll
BHO-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - c:\program files\pdfforge Toolbar\SearchSettings.dll
ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - c:\programdata\2dboy\sp.dll
HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
HKCU-Run-RGSC - d:\rockstar games\Rockstar Games Social Club\RGSCLauncher.exe
HKCU-Run-PMCLoader - c:\program files\Pinnacle\TVCenter Pro\PMCLoader.exe
HKLM-Run-BVRPLiveUpdate - c:\program files\Avanquest update\Engine\Setup.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-Feeding Frenzy 2 - e:\games\FEEDIN~1\UNWISE.EXE
AddRemove-Reflection - e:\detske\Reflection\Uninstal.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-08 23:40
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll atapi.sys >>UNKNOWN [0x877FEF61]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8b9a8d24
\Driver\ACPI -> acpi.sys @ 0x80694d68
\Driver\atapi -> atapi.sys @ 0x807999b0
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MarkFun_NT]
"ImagePath"="\??\c:\program files\markfun.w32"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*o*t*a*p*e*n*i* \Bali]
"Order"=hex:08,00,00,00,02,00,00,00,7a,03,00,00,01,00,00,00,05,00,00,00,88,00,
00,00,00,00,00,00,7a,00,32,00,cd,00,00,00,00,be,88,97,20,00,44,49,56,49,4e,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*o*t*a*p*e*n*i* \Bazary]
"Order"=hex:08,00,00,00,02,00,00,00,7a,07,00,00,01,00,00,00,0b,00,00,00,8c,00,
00,00,00,00,00,00,7e,00,32,00,cd,00,00,00,00,22,be,34,20,00,41,4c,42,45,47,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*o*t*a*p*e*n*i* \DIR]
"Order"=hex:08,00,00,00,02,00,00,00,b2,01,00,00,01,00,00,00,02,00,00,00,d0,00,
00,00,00,00,00,00,c2,00,32,00,cd,00,00,00,00,43,c9,2e,20,00,53,54,52,41,4e,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*o*t*a*p*e*n*i* \LED]
"Order"=hex:08,00,00,00,02,00,00,00,aa,06,00,00,01,00,00,00,08,00,00,00,f4,00,
00,00,00,00,00,00,e6,00,32,00,cd,00,00,00,00,ce,7a,93,20,00,44,45,41,4c,45,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*o*t*a*p*e*n*i* \legend supreme]
"Order"=hex:08,00,00,00,02,00,00,00,a8,00,00,00,01,00,00,00,01,00,00,00,9c,00,
00,00,00,00,00,00,8e,00,32,00,cd,00,00,00,00,70,3e,21,20,00,44,49,56,49,4e,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Z*a*b*a*v*a* \Mount&Blade]
"Order"=hex:08,00,00,00,02,00,00,00,e2,01,00,00,01,00,00,00,02,00,00,00,f4,00,
00,00,00,00,00,00,e6,00,32,00,cd,00,00,00,00,c1,5d,44,20,00,4d,4f,55,4e,54,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Z*a*b*a*v*a* \Pokemon]
"Order"=hex:08,00,00,00,02,00,00,00,88,02,00,00,01,00,00,00,03,00,00,00,ba,00,
00,00,02,00,00,00,ac,00,32,00,cd,00,00,00,00,d5,98,a3,20,00,45,53,4b,50,52,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\ú*
t*y* ]
@Allowed: (Read) (RestrictedCode)
@SACL=(02 0001)
"Order"=hex:08,00,00,00,02,00,00,00,00,01,00,00,01,00,00,00,01,00,00,00,f4,00,
00,00,00,00,00,00,e6,00,32,00,cd,00,00,00,00,bc,90,0b,20,00,50,45,4e,5a,45,\

[HKEY_USERS\S-1-5-21-4241098697-2916585266-1143642914-1000\Software\SecuROM\License information*]
"datasecu"=hex:16,8e,6e,67,6b,e7,18,3a,a5,bf,b1,51,36,e2,8f,00,a8,68,e3,8c,54,
b3,c4,be,9a,b1,ef,da,b8,50,52,ad,db,39,f9,a2,db,83,7f,ff,42,42,4d,1f,5c,16,\
"rkeysecu"=hex:9f,ca,16,75,83,0a,d6,fd,d2,a5,ab,cb,c1,0d,12,f7

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'Explorer.exe'(3100)
c:\program files\FlashGet\fgmgr.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\nvvsvc.exe
c:\windows\system32\conime.exe
c:\windows\RtHDVCpl.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\iashost.exe
c:\windows\system32\WUDFHost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-02-08 23:52:59 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-08 22:52

Před spuštěním: Volných bajtů: 123 560 873 984
Po spuštění: Volných bajtů: 123 503 026 176

- - End Of File - - 6C549CD2D4E90079DEA77D142784EC7D

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#12 Příspěvek od motji »

:arrow: Otestujte na www.virustotal.com
c:\program files\markfun.w32

:arrow: Ještě Nod něco hlásí?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#13 Příspěvek od jsykora »

virustotal http://www.virustotal.com/cs/analisis/0 ... 1259266533
nod32 v paměti hlásí pořád olmarik(a)
mám provézt hloubkovou kontrolu? Před spuštěním combofixu mi stihl ještě lézt na flashku.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: win32/olmarik v operační paměti

#14 Příspěvek od motji »

:o na flešku? Jak Vám tam mohl vlézt?

:arrow: Stáhněte Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, klikněte na Save a tím si uložíte log,který sem vložíte

-Podle návodu v odkazu provedete druhý sken a log sem také vložíte.


:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

jsykora
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 15 lis 2008 22:11

Re: win32/olmarik v operační paměti

#15 Příspěvek od jsykora »

adaware a nod se prali o to, kdo smaže z flešky "autorun"
gmer mám 1. log, druhej scan ukončili windows, po pokusu spustit znovu gmer šlo PC do bluescreenu
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-02-09 00:30:19
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Jarda\AppData\Local\Temp\uglcypob.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Společnost Microsoft)
AttachedDevice \FileSystem\fastfat \Fat eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\tdx \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

---- EOF - GMER 1.0.15 ----
následuje druhý pokus

Odpovědět