Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Přístup na internet chodí mimo webu AV firem

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
pmeb
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 dub 2006 12:21

Přístup na internet chodí mimo webu AV firem

#1 Příspěvek od pmeb »

Asus eee, XP home, IE6sp3. Není nainstalován žádný AV program.

Přístup na internet možná trochu pomalejší, ale chodí. Dostanu se všude - na seznam, centrum, diit, ... Jen na weby, odkud bych mohl stáhnout a nainstalovat av program, se nedostanu. Při pokusu o www.avg.cz to nahlásí, že stránka je nedostupná. To stejné Avast, symantec, nod, superantispyware. Do viry.cz se dostanu, do spyware.cz opět ne.

Jedině se mi podařilo stáhnout Spybot, ale našel jen pár cookies.
Pak jsem zjistil, že na flashce mohu přinést instalačku a udělat instalaci.
To jsem udělal se Superantispyware + SAS definice z 13.2. Opět našel jen pár cookies.
Gmer trval dlouho a tak jsem ho stopnul. V době zastavení tam byly všechny řádky černé.

Zkusil jsem Combofix ( nutno přinést na flashce ). Výpis zde:
ComboFix 10-02-20.04 - Pavel 21.02.2010 7:17.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.717 [GMT 1:00]
Spuštěný z: c:\documents and settings\Pavel\Plocha\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-2730011636-557054829-4206810205-1003
c:\recycler\S-1-5-21-746137067-1788223648-515967899-1003
c:\windows\system32\ieuinit.inf
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-21 do 2010-02-21 )))))))))))))))))))))))))))))))
.

V tomto časovém úseku nebyly vytvořeny žádné nové soubory.

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-09 12:21 . 2010-07-09 12:21 -------- d-----w- c:\program files\Skype
2010-07-09 12:21 . 2010-07-09 12:21 -------- d-----w- c:\program files\Common Files\Skype
2010-07-09 12:20 . 2010-07-09 12:20 -------- d-----w- c:\program files\InterVideo
2010-07-09 12:19 . 2010-07-09 12:19 -------- d-----w- c:\program files\Common Files\InterVideo
2010-07-09 12:16 . 2010-07-09 12:16 -------- d-----w- c:\program files\Sun
2010-07-09 12:15 . 2010-07-09 12:15 -------- d-----w- c:\program files\Common Files\Java
2010-07-09 12:02 . 2010-07-09 12:01 -------- d-----w- c:\program files\Asus
2010-07-09 11:59 . 2010-07-09 11:59 -------- d-----w- c:\program files\RALINK
2010-07-09 11:59 . 2010-07-09 11:59 -------- d-----w- c:\program files\EeePC
2010-07-09 11:57 . 2010-07-09 11:57 -------- d-----w- c:\program files\Intel
2010-07-09 11:56 . 2010-07-09 11:56 315392 ----a-w- c:\windows\HideWin.exe
2010-07-09 11:55 . 2010-07-09 11:53 -------- d-----w- c:\program files\Windows Live
2010-07-09 11:53 . 2010-07-09 11:53 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
2010-07-09 11:53 . 2010-07-09 11:52 -------- d-----w- c:\program files\Microsoft Works
2010-07-09 11:51 . 2010-07-09 11:51 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-09 11:50 . 2010-07-09 11:50 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-07-09 11:42 . 2010-07-09 11:21 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-09 11:42 . 2010-07-09 11:21 2378 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-07-09 11:40 . 2010-07-09 11:21 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-07-09 11:22 . 2010-07-09 11:22 -------- d-----w- c:\program files\microsoft frontpage
2010-07-09 11:19 . 2010-07-09 11:19 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-02-20 03:20 . 2010-02-20 03:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-20 03:20 . 2010-02-20 03:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-20 03:18 . 2009-06-20 19:51 -------- d-----w- c:\program files\Google
2010-02-19 16:29 . 2008-07-07 17:20 62336 ----a-w- c:\windows\system32\perfc005.dat
2010-02-19 16:29 . 2008-07-07 17:20 379806 ----a-w- c:\windows\system32\perfh005.dat
2010-02-19 16:25 . 2010-02-19 16:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-11 20:39 . 2010-02-11 20:38 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
2010-02-11 20:38 . 2010-02-11 20:38 -------- d-----w- c:\program files\Logitech
2010-02-11 20:38 . 2010-07-09 11:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-11 20:38 . 2010-02-11 20:38 -------- d-----w- c:\program files\Common Files\Remote Control USB Driver
2008-05-07 14:34 . 2010-07-09 12:21 15523560 ----a-w- c:\program files\U1 Setup.exe
2008-04-14 12:00 . 2008-07-07 17:20 161513 --sha-r- c:\windows\system32\cvokrh.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-20 94208]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 148888]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-20 198160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Pavel\Nabˇdka Start\Programy\Po spuçtŘnˇ\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-1-15 393216]
StarOffice 8.lnk - c:\program files\Sun\StarOffice 8\program\quickstart.exe [2007-8-17 122880]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-7 600680]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2010-7-9 303104]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 09:34 5724184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7778:TCP"= 7778:TCP:sjgnd

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5.1.2010 7:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5.1.2010 7:56 74480]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5.1.2010 7:56 7408]
S2 avodxub;Security Driver;c:\windows\system32\svchost.exe -k netsvcs [7.7.2008 18:20 14336]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5.2.2010 19:24 135664]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [9.7.2010 12:59 625024]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
avodxub
.
Obsah adresáře 'Naplánované úlohy'

2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 18:24]

2010-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 18:24]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-21 07:20
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\avodxub]
"ServiceDll"="c:\windows\system32\cvokrh.dll"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(656)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\igfxdev.dll
.
Celkový čas: 2010-02-21 07:22:24
ComboFix-quarantined-files.txt 2010-02-21 06:22

Před spuštěním: Volných bajtů: 77 413 888 000
Po spuštění: Volných bajtů: 77 388 619 776

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - AEB7513984F2F3D94FC15ED36D2558BA


Je zajímavé, že když jsme nechalal zkontrolovat flashku ve stolním PC s NOD32, našel toto:

D:\autorun.inf - INF/Conficker červ
D:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx - varianta infiltrace Win32/Conficker.AA červ

pmeb
Návštěvník
Návštěvník
Příspěvky: 6
Registrován: 24 dub 2006 12:21

Re: Přístup na internet chodí mimo webu AV firem

#2 Příspěvek od pmeb »

Odnesl jsem vyléčenou flashku do problematického Eee a udělal RSIT.Po příchodu zpět a kontrole flashky pomocí nod je zde opět ten nakažený autorun.inf - viz dříve.

Přikládám soubor RSIT log
Logfile of random's system information tool 1.06 (written by random/random)
Run by Pavel at 2010-02-21 10:30:17
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 74 GB (90%) free of 82 GB
Total RAM: 1015 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:30:25, on 21.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\Pavel\Plocha\RSIT.exe
C:\Program Files\trend micro\Pavel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7626 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-12 1372160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2009-06-20 312928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-19 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-04-19 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-12-19 135168]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-12-19 159744]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-12-19 131072]
"AsusTray"=C:\Program Files\EeePC\ACPI\AsTray.exe [2008-06-03 98304]
"AsusACPIServer"=C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe [2008-06-03 479232]
"AsusEPCMonitor"=C:\Program Files\EeePC\ACPI\AsEPCMon.exe [2008-05-21 94208]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-04-19 148888]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2008-07-23 335872]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-07-16 16806400]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2009-06-20 198160]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
SuperHybridEngine.lnk - C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe

C:\Documents and Settings\Pavel\Nabídka Start\Programy\Po spuštění
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe
StarOffice 8.lnk - C:\Program Files\Sun\StarOffice 8\program\quickstart.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe"="C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe"="C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb2a923c-1dce-11df-8634-00235408aa20}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn


======List of files/folders created in the last 1 months======

2010-07-09 14:17:44 ----A---- C:\WINDOWS\system32\h323log.txt
2010-07-09 14:16:50 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-07-09 14:16:50 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-07-09 14:15:46 ----A---- C:\WINDOWS\system32\usbui.dll
2010-07-09 14:14:25 ----A---- C:\WINDOWS\imsins.BAK
2010-07-09 14:14:22 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-09 14:14:21 ----SHD---- C:\WINDOWS\Installer
2010-07-09 14:14:21 ----A---- C:\WINDOWS\ODBCINST.INI
2010-07-09 14:14:20 ----D---- C:\Program Files\Common Files\ODBC
2010-07-09 14:14:18 ----RD---- C:\Program Files
2010-07-09 14:14:18 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-07-09 14:14:18 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-07-09 14:14:18 ----D---- C:\Program Files\Common Files
2010-07-09 14:14:10 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-07-09 14:14:10 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-07-09 14:14:10 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-07-09 14:14:10 ----A---- C:\WINDOWS\system32\irclass.dll
2010-07-09 14:14:10 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-07-09 14:14:10 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-07-09 14:14:10 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-07-09 14:14:09 ----A---- C:\WINDOWS\system32\batt.dll
2010-07-09 14:14:09 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-07-09 14:14:08 ----A---- C:\WINDOWS\system32\storprop.dll
2010-07-09 14:13:56 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2010-07-09 14:13:44 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-09 14:13:44 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-09 14:13:38 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-07-09 14:13:30 ----A---- C:\WINDOWS\setuplog.txt
2010-07-09 14:13:26 ----D---- C:\Documents and Settings
2010-07-09 14:08:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-09 14:08:11 ----RSD---- C:\WINDOWS\Fonts
2010-07-09 14:08:11 ----RD---- C:\WINDOWS\Web
2010-07-09 14:08:11 ----HD---- C:\WINDOWS\inf
2010-07-09 14:08:11 ----D---- C:\WINDOWS\WinSxS
2010-07-09 14:08:11 ----D---- C:\WINDOWS\twain_32
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Temp
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\wins
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\wbem
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\usmt
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\spool
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\ShellExt
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\Setup
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\ras
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\oobe
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\npp
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\mui
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\inetsrv
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\IME
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\icsxml
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\ias
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\export
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\drivers
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\dhcp
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\cs-cz
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\cs
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\config
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\3com_dmi
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\3076
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\2052
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1054
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1042
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1041
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1037
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1033
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1031
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1029
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1028
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32\1025
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system32
2010-07-09 14:08:11 ----D---- C:\WINDOWS\system
2010-07-09 14:08:11 ----D---- C:\WINDOWS\security
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Resources
2010-07-09 14:08:11 ----D---- C:\WINDOWS\repair
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Provisioning
2010-07-09 14:08:11 ----D---- C:\WINDOWS\pchealth
2010-07-09 14:08:11 ----D---- C:\WINDOWS\PeerNet
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Network Diagnostic
2010-07-09 14:08:11 ----D---- C:\WINDOWS\mui
2010-07-09 14:08:11 ----D---- C:\WINDOWS\msapps
2010-07-09 14:08:11 ----D---- C:\WINDOWS\msagent
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Media
2010-07-09 14:08:11 ----D---- C:\WINDOWS\L2Schemas
2010-07-09 14:08:11 ----D---- C:\WINDOWS\java
2010-07-09 14:08:11 ----D---- C:\WINDOWS\ime
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Help
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Driver Cache
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Debug
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Cursors
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Connection Wizard
2010-07-09 14:08:11 ----D---- C:\WINDOWS\Config
2010-07-09 14:08:11 ----D---- C:\WINDOWS\AppPatch
2010-07-09 14:08:11 ----D---- C:\WINDOWS\addins
2010-07-09 14:08:11 ----D---- C:\WINDOWS
2010-07-09 13:32:21 ----A---- C:\WINDOWS\smscfg.ini
2010-07-09 13:31:08 ----D---- C:\Program Files\Eee Storage
2010-07-09 13:26:27 ----A---- C:\WINDOWS\oemver.txt
2010-07-09 13:21:51 ----A---- C:\Program Files\U1 Setup.exe
2010-07-09 13:21:23 ----D---- C:\Program Files\Skype
2010-07-09 13:21:23 ----D---- C:\Program Files\Common Files\Skype
2010-07-09 13:21:15 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-07-09 13:20:16 ----A---- C:\WINDOWS\system32\IVIresizeW7.dll
2010-07-09 13:20:16 ----A---- C:\WINDOWS\system32\IVIresizePX.dll
2010-07-09 13:20:16 ----A---- C:\WINDOWS\system32\IVIresizeP6.dll
2010-07-09 13:20:16 ----A---- C:\WINDOWS\system32\IVIresizeM6.dll
2010-07-09 13:20:16 ----A---- C:\WINDOWS\system32\IVIresizeA6.dll
2010-07-09 13:20:15 ----A---- C:\WINDOWS\system32\IVIresize.dll
2010-07-09 13:20:09 ----D---- C:\Program Files\InterVideo
2010-07-09 13:19:52 ----D---- C:\Program Files\Common Files\InterVideo
2010-07-09 13:16:37 ----D---- C:\Program Files\Sun
2010-07-09 13:16:14 ----A---- C:\WINDOWS\system32\javaws.exe
2010-07-09 13:16:14 ----A---- C:\WINDOWS\system32\javaw.exe
2010-07-09 13:16:14 ----A---- C:\WINDOWS\system32\java.exe
2010-07-09 13:15:46 ----D---- C:\Program Files\Java
2010-07-09 13:15:45 ----D---- C:\Program Files\Common Files\Java
2010-07-09 13:15:27 ----D---- C:\adabas
2010-07-09 13:10:59 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2010-07-09 13:10:47 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2010-07-09 13:10:36 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-07-09 13:10:27 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-07-09 13:10:14 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2010-07-09 13:09:50 ----A---- C:\WINDOWS\system32\spmsg.dll
2010-07-09 13:09:45 ----HDC---- C:\WINDOWS\$NtUninstallKB942763$
2010-07-09 13:09:44 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-09 13:04:09 ----A---- C:\WINDOWS\system32\igfxres.dll
2010-07-09 13:02:07 ----A---- C:\WINDOWS\sr.VBS
2010-07-09 13:02:07 ----A---- C:\WINDOWS\INSTALLEEE.EXE
2010-07-09 13:02:07 ----A---- C:\WINDOWS\HW.VBS
2010-07-09 13:02:07 ----A---- C:\WINDOWS\AUTO.BAT
2010-07-09 13:01:15 ----D---- C:\Program Files\Asus
2010-07-09 12:59:50 ----D---- C:\Program Files\RALINK
2010-07-09 12:59:23 ----D---- C:\Program Files\EeePC
2010-07-09 12:59:03 ----D---- C:\WINDOWS\system32\Atheros_L1e
2010-07-09 12:58:21 ----A---- C:\WINDOWS\system32\igxprd32.dll
2010-07-09 12:58:21 ----A---- C:\WINDOWS\system32\igfxtray.exe
2010-07-09 12:58:20 ----A---- C:\WINDOWS\system32\igfxpers.exe
2010-07-09 12:58:20 ----A---- C:\WINDOWS\system32\igfxexps.dll
2010-07-09 12:58:19 ----A---- C:\WINDOWS\system32\igxpdv32.dll
2010-07-09 12:58:19 ----A---- C:\WINDOWS\system32\igfxsrvc.dll
2010-07-09 12:58:19 ----A---- C:\WINDOWS\system32\igfxext.exe
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\igxpgd32.dll
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\iglicd32.dll
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\igldev32.dll
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\igfxzoom.exe
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\igfxsrvc.exe
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\igfxcfg.exe
2010-07-09 12:58:18 ----A---- C:\WINDOWS\system32\hccutils.dll
2010-07-09 12:58:17 ----A---- C:\WINDOWS\system32\igfxdev.dll
2010-07-09 12:58:17 ----A---- C:\WINDOWS\system32\igfxCoIn_v4906.dll
2010-07-09 12:58:17 ----A---- C:\WINDOWS\system32\hkcmd.exe
2010-07-09 12:58:16 ----A---- C:\WINDOWS\system32\igxpdx32.dll
2010-07-09 12:58:16 ----A---- C:\WINDOWS\system32\igfxress.dll
2010-07-09 12:58:16 ----A---- C:\WINDOWS\system32\igfxpph.dll
2010-07-09 12:58:16 ----A---- C:\WINDOWS\system32\igfxdo.dll
2010-07-09 12:58:15 ----D---- C:\WINDOWS\system32\Lang
2010-07-09 12:58:15 ----A---- C:\WINDOWS\system32\igxpun.exe
2010-07-09 12:58:15 ----A---- C:\WINDOWS\system32\difxapi.dll
2010-07-09 12:57:25 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-07-09 12:57:22 ----D---- C:\Program Files\Intel
2010-07-09 12:57:22 ----A---- C:\WINDOWS\system32\CSVer.dll
2010-07-09 12:57:14 ----D---- C:\Intel
2010-07-09 12:56:49 ----D---- C:\WINDOWS\system32\RTCOM
2010-07-09 12:56:09 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-09 12:56:05 ----A---- C:\WINDOWS\HideWin.exe
2010-07-09 12:56:01 ----D---- C:\Program Files\Common Files\InstallShield
2010-07-09 12:55:37 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-07-09 12:54:27 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-07-09 12:53:39 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller
2010-07-09 12:53:36 ----D---- C:\Program Files\Windows Live
2010-07-09 12:53:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\WLInstaller
2010-07-09 12:53:12 ----D---- C:\Program Files\Microsoft Office
2010-07-09 12:52:09 ----D---- C:\Program Files\Microsoft Works
2010-07-09 12:51:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-07-09 12:51:17 ----D---- C:\Program Files\Common Files\Adobe
2010-07-09 12:51:17 ----D---- C:\Program Files\Adobe
2010-07-09 12:50:38 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-07-09 12:46:10 ----RSD---- C:\WINDOWS\assembly
2010-07-09 12:46:10 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-09 12:46:08 ----D---- C:\WINDOWS\system32\URTTemp
2010-07-09 12:43:54 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-07-09 12:43:54 ----A---- C:\WINDOWS\system32\wups2.dll
2010-07-09 12:43:54 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-07-09 12:43:53 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-07-09 12:43:53 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-07-09 12:25:27 ----HD---- C:\Program Files\Uninstall Information
2010-07-09 12:25:09 ----D---- C:\WINDOWS\SoftwareDistribution
2010-07-09 12:25:05 ----SD---- C:\WINDOWS\system32\Microsoft
2010-07-09 12:25:05 ----D---- C:\WINDOWS\Prefetch
2010-07-09 12:25:04 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-09 12:22:15 ----D---- C:\WINDOWS\system32\xircom
2010-07-09 12:22:15 ----D---- C:\Program Files\xerox
2010-07-09 12:22:15 ----D---- C:\Program Files\microsoft frontpage
2010-07-09 12:22:07 ----A---- C:\WINDOWS\control.ini
2010-07-09 12:22:07 ----A---- C:\AUTOEXEC.BAT
2010-07-09 12:21:53 ----A---- C:\WINDOWS\OEWABLog.txt
2010-07-09 12:21:49 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-07-09 12:20:47 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-09 12:20:47 ----RD---- C:\WINDOWS\Offline Web Pages
2010-07-09 12:20:47 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-07-09 12:20:38 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-07-09 12:20:33 ----HD---- C:\Program Files\WindowsUpdate
2010-07-09 12:20:29 ----D---- C:\Program Files\Online Services
2010-07-09 12:20:19 ----D---- C:\WINDOWS\system32\DirectX
2010-07-09 12:20:18 ----A---- C:\WINDOWS\system32\atrace.dll
2010-07-09 12:20:17 ----A---- C:\WINDOWS\system32\desktop.ini
2010-07-09 12:20:17 ----A---- C:\WINDOWS\desktop.ini
2010-07-09 12:20:16 ----D---- C:\Program Files\Common Files\Services
2010-07-09 12:20:16 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-07-09 12:20:16 ----A---- C:\WINDOWS\system32\acctres.dll
2010-07-09 12:20:15 ----SD---- C:\WINDOWS\Tasks
2010-07-09 12:20:15 ----D---- C:\Program Files\Common Files\MSSoap
2010-07-09 12:20:15 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-07-09 12:20:13 ----D---- C:\WINDOWS\system32\Macromed
2010-07-09 12:20:13 ----D---- C:\WINDOWS\srchasst
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wups.dll
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-07-09 12:20:13 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-07-09 12:20:12 ----N---- C:\WINDOWS\system32\wuauclt.exe
2010-07-09 12:20:12 ----N---- C:\WINDOWS\system32\qmgr.dll
2010-07-09 12:20:12 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-07-09 12:20:12 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-07-09 12:20:12 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2010-07-09 12:20:12 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-07-09 12:20:12 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-07-09 12:20:10 ----D---- C:\Program Files\Movie Maker
2010-07-09 12:20:05 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-07-09 12:20:05 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-07-09 12:20:05 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-07-09 12:20:05 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-07-09 12:20:04 ----N---- C:\WINDOWS\system32\srsvc.dll
2010-07-09 12:20:04 ----D---- C:\WINDOWS\system32\Restore
2010-07-09 12:20:04 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-07-09 12:20:04 ----A---- C:\WINDOWS\system32\srclient.dll
2010-07-09 12:20:04 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-07-09 12:20:04 ----A---- C:\WINDOWS\system32\ils.dll
2010-07-09 12:20:04 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-07-09 12:20:04 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-07-09 12:20:03 ----D---- C:\Program Files\NetMeeting
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\msconf.dll
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\inetres.dll
2010-07-09 12:20:03 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-07-09 12:20:02 ----N---- C:\WINDOWS\system32\schedsvc.dll
2010-07-09 12:20:02 ----D---- C:\Program Files\Outlook Express
2010-07-09 12:20:02 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-07-09 12:20:02 ----A---- C:\WINDOWS\system32\mstask.dll
2010-07-09 12:20:02 ----A---- C:\WINDOWS\system32\isign32.dll
2010-07-09 12:20:02 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-07-09 12:20:02 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-07-09 12:20:02 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-07-09 12:20:01 ----D---- C:\Program Files\Internet Explorer
2010-07-09 12:20:01 ----D---- C:\Program Files\Common Files\System
2010-07-09 12:19:42 ----D---- C:\Program Files\ComPlus Applications
2010-07-09 12:19:40 ----A---- C:\WINDOWS\vbaddin.ini
2010-07-09 12:19:40 ----A---- C:\WINDOWS\vb.ini
2010-07-09 12:19:34 ----D---- C:\WINDOWS\Registration
2010-07-09 12:18:49 ----D---- C:\Program Files\Windows Media Player
2010-07-09 12:18:42 ----D---- C:\Program Files\Messenger
2010-07-09 12:18:41 ----D---- C:\Program Files\MSN Gaming Zone
2010-07-09 12:18:41 ----A---- C:\WINDOWS\system32\write.exe
2010-07-09 12:18:39 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-07-09 12:18:39 ----A---- C:\WINDOWS\system32\hticons.dll
2010-07-09 12:18:39 ----A---- C:\WINDOWS\system32\avwav.dll
2010-07-09 12:18:39 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-07-09 12:18:39 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-07-09 12:18:38 ----A---- C:\WINDOWS\system32\winchat.exe
2010-07-09 12:18:37 ----A---- C:\WINDOWS\system32\winmine.exe
2010-07-09 12:18:37 ----A---- C:\WINDOWS\system32\sol.exe
2010-07-09 12:18:37 ----A---- C:\WINDOWS\system32\charmap.exe
2010-07-09 12:18:37 ----A---- C:\WINDOWS\system32\getuname.dll
2010-07-09 12:18:37 ----A---- C:\WINDOWS\system32\calc.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\tskill.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\tscon.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\shadow.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\reset.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\regini.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\msg.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\logoff.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\freecell.exe
2010-07-09 12:18:36 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-07-09 12:18:34 ----D---- C:\Program Files\Windows NT
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\spider.exe
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-07-09 12:18:34 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-07-09 12:18:33 ----N---- C:\WINDOWS\system32\termsrv.dll
2010-07-09 12:18:33 ----D---- C:\WINDOWS\system32\MsDtc
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\tsgqec.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-07-09 12:18:33 ----A---- C:\WINDOWS\system32\aaclient.dll
2010-07-09 12:18:32 ----D---- C:\WINDOWS\system32\Com
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\stclient.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\comuid.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\colbact.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-07-09 12:18:32 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-07-09 12:18:30 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-07-09 12:18:30 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-07-09 12:18:30 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-07-09 12:18:30 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-02-21 10:30:17 ----D---- C:\rsit
2010-02-21 10:30:17 ----D---- C:\Program Files\trend micro
2010-02-21 07:22:25 ----A---- C:\ComboFix.txt
2010-02-21 07:16:49 ----A---- C:\Boot.bak
2010-02-21 07:16:45 ----RASHD---- C:\cmdcons
2010-02-21 06:59:21 ----A---- C:\WINDOWS\zip.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\SWSC.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\SWREG.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\sed.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\PEV.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\MBR.exe
2010-02-21 06:59:21 ----A---- C:\WINDOWS\grep.exe
2010-02-21 06:59:14 ----D---- C:\WINDOWS\ERDNT
2010-02-21 06:58:56 ----D---- C:\Qoobox
2010-02-20 04:20:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-02-20 04:20:21 ----D---- C:\Program Files\SUPERAntiSpyware
2010-02-20 04:20:21 ----D---- C:\Documents and Settings\Pavel\Data aplikací\SUPERAntiSpyware.com
2010-02-20 04:20:03 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-02-19 18:19:27 ----RA---- C:\WINDOWS\gmer.exe
2010-02-19 18:19:27 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2010-02-19 18:19:27 ----A---- C:\WINDOWS\gmer.ini
2010-02-19 18:19:27 ----A---- C:\WINDOWS\gmer.dll
2010-02-19 17:32:42 ----D---- C:\WINDOWS\pss
2010-02-19 17:21:07 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-19 17:21:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-11 21:39:31 ----D---- C:\Documents and Settings\Pavel\Data aplikací\Mozilla
2010-02-11 21:38:38 ----D---- C:\Program Files\Common Files\Remote Control Software Common
2010-02-11 21:38:35 ----D---- C:\Program Files\Logitech
2010-02-11 21:38:27 ----D---- C:\Program Files\Common Files\Remote Control USB Driver
2010-02-01 21:13:17 ----D---- C:\Documents and Settings\Pavel\Data aplikací\InterVideo

======List of files/folders modified in the last 1 months======

2010-07-09 14:13:56 ----ASH---- C:\Documents and Settings\Pavel\Data aplikací\desktop.ini
2010-07-09 13:15:33 ----D---- C:\Documents and Settings\Pavel\Data aplikací\Sun
2010-07-09 12:58:42 ----D---- C:\Documents and Settings\Pavel\Data aplikací\InstallShield
2010-07-09 12:25:30 ----D---- C:\Documents and Settings\Pavel\Data aplikací\Identities
2010-07-09 12:22:07 ----A---- C:\WINDOWS\win.ini
2010-02-21 09:56:51 ----D---- C:\Documents and Settings\Pavel\Data aplikací\StarOffice8
2010-02-21 07:21:02 ----A---- C:\WINDOWS\system.ini
2010-02-21 07:16:49 ----RASH---- C:\boot.ini
2010-02-20 04:18:54 ----D---- C:\Program Files\Google
2010-01-29 00:26:00 ----SD---- C:\Documents and Settings\Pavel\Data aplikací\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2007-07-26 11264]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-06-24 991400]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-07-16 4747776]
R3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2008-07-14 25088]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-03-11 36864]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-09-20 156392]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-06-11 47272]
S3 catchme;catchme; \??\C:\DOCUME~1\Pavel\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys [2008-09-26 101376]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2008-03-28 625024]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-07-07 346720]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-04-19 152984]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-05 135664]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

-----------------EOF-----------------

Uživatelský avatar
Roli
VIP
VIP
Příspěvky: 13399
Registrován: 26 lis 2006 13:37
Bydliště: ČR

Re: Přístup na internet chodí mimo webu AV firem

#3 Příspěvek od Roli »

Zdravím, tohle fixni v HJT :

R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe


HJT najdeš zde :

C:\Program Files\trend micro\Pavel

Fix znamená že spustíš HJT Obrázek

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

Čištění registru je třeba několikrát zopakovat !


Stáhni a spusť OTMoveIt

do levého okna aplikace pod Paste Instructions for Items to be Moved zkopíruj tento text:

Kód: Vybrat vše

:processes
explorer.exe       

:files 
C:\*.tmp
C:\WINDOWS\System32\*.tmp
C:\WINDOWS\*.tmp

:reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb2a923c-1dce-11df-8634-00235408aa20}]

:commands
[purity]
[emptytemp]
[start explorer]
klikni na MoveIt! a v pravém zeleném okně aplikace se Ti objeví info o provedene akci, obsah okna zkopíruj sem,

pokud aplikace bude požadovat restart, klikni na YES

v tom případě sem chci zkopírovat obsah logu uloženého na C:\_OTMoveIt\MovedFiles\


Tohle :

c:\windows\system32\cvokrh.dll

otestuj na VIRUSTOTAL

(po načtení stránky klikni na tlačítko Procházet, najdi cestu k výše zmíněnému souboru a klikni na tlačítko Odeslat soubor

trvá to okolo deseti minut pak mi sem zkopíruj link, to je ten řádek nahoře v prohlížeči)
| Rsit | Mbam | AVPTool | Cure It |

O víkendu odpočívám :all_coholic:

Odpovědět