Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Rootkit-gen [RtK]

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15691
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Rootkit-gen [RtK]

#31 Příspěvek od JaRon »

ak po vymazani obnovy PC bude fachat dobre, tak vycisti PC s CCleanerom a mozes doinstalovat programy vcetne AVAST-u
CC >> http://www.viry.cz/forum/viewtopic.php?f=46&t=7478
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#32 Příspěvek od lordbrutus »

OK, dekuji za pomoc :worship: Odpoledne napisu vysledek, jak to dopadlo. Doufam, ze to bude v pohode protoze jsem ztratil uz dost casu touto haveti.

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#33 Příspěvek od lordbrutus »

Tak je to v haji :-( udelal sjem presne co s mi napsal. Restartoval jsem PC, pak projela kontrola konzistence disku a pak najel OS, jel jen tak tri minuty a ted je zase tuhej jako pred tim. Jeste pred tim jsem zkusil projet CCleaner (mam ho uz naistalovanej nejakou dobu) ale ten nedojel a vypnul se...no a pak, zase blok . Ach jo :-(

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15691
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Rootkit-gen [RtK]

#34 Příspěvek od JaRon »

konzistencia disku byva spustana pri nejakych problemoch s diskom ,,,
s prikazoveho riadku spust chkdsk/F po restarte by mal opravit chyby (ak su)
+
otestuj HDD programom HDtune <www.hdtune.com> cast Benchmark >> hodnoty vpravo - 6 poloziek odpis
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#35 Příspěvek od lordbrutus »

dam start/spustit a zadam chkdsk/F a nelze najit.... Ta kontrola konzistence se ukalazala vzdy jen po scanovani cure...
To prece neni mozny, ze by mi udelal vir takovou paseku.... ja sjem z toho uz dost spatnej ti reknu :-(

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15691
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Rootkit-gen [RtK]

#36 Příspěvek od JaRon »

start-spustit-cmd<enter> az tam na prikazovom riadku zadas chkdsk/F
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#37 Příspěvek od lordbrutus »

tak jsem udelal tu kontrolu disku - chkdsk v poradku projel bez chyb a HDtune jsou vysledky zde :trans.rate - min. :30,7MB/s max. 115,6 Ave :91,1MB/s
Acces time : 13,3ms Burst rate 154,8MB/s CPU Usage 3,2%

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15691
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Rootkit-gen [RtK]

#38 Příspěvek od JaRon »

disk je OK
pouzi Kaspersky utilitu >> http://support.kaspersky.com/viruses/so ... =208280684
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#39 Příspěvek od lordbrutus »

tak jsem to vyzkusal (TDSSkiller) a nenasel zadne infikovane objekty v pameti, registrech ci souborech. Nevim teda jestli to projel spravne protoze to bylo celkem rychly. Tak si rikam, jestli to zamrzani systemu nedelaji nejake ovladace. Tim, ze mohly byt treba poskozene a nejaky antivirus je mohl misto leceni vymazat...

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Rootkit-gen [RtK]

#40 Příspěvek od stell »

zdravim
zaskok za kolegu,
:arrow: Stahni OTListIt2>> OTL
- spust
-zafajkni
-Scan all users.
-Lop check.
-Purity check.
-v sekciiExtra Registry>zaboduj>Use SafeList
-do okna Custom Scans/Fixes>vloz zeleny text a klik Run SCAN
-scan trva [10-15 min]>.potom vloz sem
-OTL.txt (bude na ploche).
-Extras.txt [bude dole na hlavnom panely]

Kód: Vybrat vše

netsvcs
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\eventlog.dll /s /md5
%SYSTEMDRIVE%\scecli.dll /s /md5
%SYSTEMDRIVE%\netlogon.dll /s /md5
%SYSTEMDRIVE%\cngaudit.dll /s /md5
%SYSTEMDRIVE%\sceclt.dll /s /md5
%SYSTEMDRIVE%\ntelogon.dll /s /md5
%SYSTEMDRIVE%\logevent.dll /s /md5
%SYSTEMDRIVE%\iaStor.sys /s /md5
%SYSTEMDRIVE%\nvstor.sys /s /md5
%SYSTEMDRIVE%\atapi.sys /s /md5
%SYSTEMDRIVE%\IdeChnDr.sys /s /md5
%SYSTEMDRIVE%\viasraid.sys /s /md5
%SYSTEMDRIVE%\AGP440.sys /s /md5
%SYSTEMDRIVE%\vaxscsi.sys /s /md5
%SYSTEMDRIVE%\nvatabus.sys /s /md5
%SYSTEMDRIVE%\viamraid.sys /s /md5
%SYSTEMDRIVE%\nvata.sys /s /md5
%SYSTEMROOT%\*. /mp /s
CREATERESTOREPOINT
%SYSTEMROOT%\system32\*.dll /lockedfiles
%SYSTEMROOT%\Tasks\*.job /lockedfiles
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#41 Příspěvek od lordbrutus »

zde je extras...

OTL Extras logfile created on: 22.2.2010 20:04:11 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = c:\Programy\Antivir
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,65 Gb Total Space | 70,26 Gb Free Space | 71,95% Space Free | Partition Type: NTFS
Drive D: | 200,43 Gb Total Space | 80,59 Gb Free Space | 40,21% Space Free | Partition Type: NTFS
Drive E: | 111,79 Gb Total Space | 12,59 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SPACESTAR
Current User Name: Radim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Computer, Inc.)
"C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger -- (Logitech Inc.)
"C:\Program Files\ICQ6.5\ICQ.exe" = C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6 -- (ICQ, LLC.)
"C:\Program Files\Skype\Phone\Skype.exe" = C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009\WNt500x86\RpcSandraSrv.exe" = C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009\WNt500x86\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{0901FCE8-5415-4499-BBC8-1AA106DD66E2}" = Adobe Setup
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP550_series" = Canon MP550 series MP Drivers
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{18A5DFF2-8A95-49F3-873F-743CB5549F3D}" = Canon ScanGear Starter
"{19E95B87-3DCE-11D7-9B2F-0060B0F769F5}" = AppCAD
"{212748BB-0DA5-46DE-82A1-403736DC9F27}" = MSVC80_x86
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{26E20136-E332-4BC6-903F-ADDCAEE53263}" = ArCon 9 Profesionál
"{28FB7853-A6ED-4F67-8635-9F0E863FC0AD}" = WinFast Codec-TS SDK
"{293D5729-7C01-4FA4-A4DE-BB6A1587BBB9}" = PDF Settings
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{5178C1BB-1EB1-4468-894B-7DE964DDCAA2}" = Adobe Photoshop CS3
"{53480330-E1D1-41CA-B8F8-7F78644F7F50}" = O&O Defrag Professional Edition
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2
"{5869CE1E-BC0B-4648-B1AE-6EF4A985590C}" = Dynamic Energy Saver 1.0 B8.0128.1
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6.5
"{6179A7D2-A668-4F1D-BC9A-DCC6A10C7871}" = Adobe Color NA Extra Settings
"{67A87D78-70B5-4999-85CA-DE4C26100C7A}" = IntelliCAD 2001
"{6A120BD4-6AB8-4BF9-82A8-FC7B0FD61029}" = Nero 7 Ultra Edition
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6D12B99F-EAAA-49D8-8E2F-74FA7459CCB2}" = Adobe Asset Services CS3
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{79D5997E-BF79-48BB-8B41-9BE59C15C2D7}" = OmniPage SE 2.0
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{82427977-8776-4087-90CA-9F65174D3C4D}" = Nokia Connectivity Cable Driver
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}" = Adobe Type Support
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0405-0000-0000000FF1CE}" = Sada Compatibility Pack pro systém Office 2007
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{9A0E0340-C3D7-42D1-96D4-64179FD456AE}" = WinFast De-interlace SDK
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}" = Adobe CMaps
"{A2D81E70-2A98-4A08-A628-94388B063C5E}" = Adobe Color - Photoshop Specific
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1029-7B44-A81200000003}" = Adobe Reader 8 - Czech
"{AF9848E2-5F19-4E49-9E6E-044FBDC28404}" = WinFast TT-SB SDK
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B7CB0BF3-791E-44D3-9F04-786E36D51C9D}" = PC Connectivity Solution
"{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}" = Adobe Default Language CS3
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD087F50-46B2-43E4-BD73-5DB3DC20B47C}" = Adobe Color EU Recommended Settings
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C2ED62F4-4F0B-44DF-B630-DD02FD7E8C60}" = OpenOffice.org 2.4
"{C92C584E-C781-475E-A8E2-C67D993A6B95}" = WinFast PVR2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}" = Adobe PDF Library Files
"{D335AC77-6F59-46D6-9082-F74A9F7E0FC3}" = Canon MP Drivers 7.0
"{D92B72E2-C854-4738-8ED6-4C3661CC17AE}" = Adobe Color JA Extra Settings
"{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}" = Adobe Color Common Settings
"{E91E8912-769D-42F0-8408-0E329443BABC}" = Ralink Wireless LAN Card
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"504244733D18C8F63FF584AEB290E3904E791693" = Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_4977c84bcdc298c444ccfbdcccb660d" = Adobe Photoshop CS3
"ArCon PDF-Export" = ArCon PDF-Export
"EAGLE 5.3.0" = EAGLE 5.3.0
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-WebPrint" = Easy-WebPrint
"FLVPlayer" = FLV Player 1.3.3
"HD Tune_is1" = HD Tune 2.55
"ICQToolbar" = ICQ Toolbar
"InstallShield_{26E20136-E332-4BC6-903F-ADDCAEE53263}" = ArCon 9 Profesionál
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.7 (Full)
"MetaProducts StartUp Organizer" = MetaProducts StartUp Organizer
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Mozilla Firefox (3.5.8)" = Mozilla Firefox (3.5.8)
"Mozilla Thunderbird (2.0.0.23)" = Mozilla Thunderbird (2.0.0.23)
"NVIDIA Drivers" = NVIDIA Drivers
"ProfiCAD_is1" = ProfiCAD
"Syncrosoft's License Control" = Syncrosoft's License Control
"System Explorer_is1" = System Explorer 1.5
"Totalcmd" = Total Commander (Remove or Repair)
"VLC media player" = VideoLAN VLC media player 0.8.6c
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21.2.2010 16:23:20 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 21.2.2010 16:54:10 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 21.2.2010 17:42:05 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 21.2.2010 17:48:09 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 21.2.2010 17:58:51 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 21.2.2010 18:03:46 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 21.2.2010 18:29:11 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 22.2.2010 8:51:21 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 22.2.2010 9:06:54 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 22.2.2010 9:38:48 | Computer Name = SPACESTAR | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

[ System Events ]
Error - 20.2.2010 9:48:32 | Computer Name = SPACESTAR | Source = Service Control Manager | ID = 7026
Description = Zavedení následujícího ovladače pro spouštění počítače nebo systému
se nezdařilo: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss
sptd
Tcpip

Error - 20.2.2010 9:55:26 | Computer Name = SPACESTAR | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby StiSvc
s argumenty za účelem spuštění serveru: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 20.2.2010 9:57:34 | Computer Name = SPACESTAR | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 20.2.2010 9:58:51 | Computer Name = SPACESTAR | Source = sr | ID = 1
Description = Filtr nástroje Obnovení systému zjistil neočekávanou chybu 0xC0000001
při zpracování souboru na svazku HarddiskVolume1. Sledování svazku bylo ukončeno.


Error - 21.2.2010 10:14:04 | Computer Name = SPACESTAR | Source = Ntfs | ID = 262199
Description = Struktura systému souborů disku je poškozena a je nepoužitelná. Je
nutné na svazek D: spustit nástroj chkdsk.

Error - 21.2.2010 10:14:08 | Computer Name = SPACESTAR | Source = Ntfs | ID = 262199
Description = Struktura systému souborů disku je poškozena a je nepoužitelná. Je
nutné na svazek E: spustit nástroj chkdsk.

Error - 21.2.2010 16:40:46 | Computer Name = SPACESTAR | Source = Service Control Manager | ID = 7034
Description = Služba MATLAB Server byla neočekávaně ukončena. Tento stav nastal
již 1krát.

Error - 21.2.2010 19:42:28 | Computer Name = SPACESTAR | Source = Ntfs | ID = 262199
Description = Struktura systému souborů disku je poškozena a je nepoužitelná. Je
nutné na svazek D: spustit nástroj chkdsk.

Error - 22.2.2010 9:12:36 | Computer Name = SPACESTAR | Source = Service Control Manager | ID = 7000
Description = Služba SANDRA neuspěla při spuštění v důsledku následující chyby:
%%2

Error - 22.2.2010 13:32:30 | Computer Name = SPACESTAR | Source = Service Control Manager | ID = 7000
Description = Služba WFIOCTL neuspěla při spuštění v důsledku následující chyby:
%%2


< End of report >

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#42 Příspěvek od lordbrutus »

a zde OTL...

OTL logfile created on: 22.2.2010 20:04:11 - Run 1
OTL by OldTimer - Version 3.1.30.1 Folder = c:\Programy\Antivir
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 64,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 97,65 Gb Total Space | 70,26 Gb Free Space | 71,95% Space Free | Partition Type: NTFS
Drive D: | 200,43 Gb Total Space | 80,59 Gb Free Space | 40,21% Space Free | Partition Type: NTFS
Drive E: | 111,79 Gb Total Space | 12,59 Gb Free Space | 11,26% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: SPACESTAR
Current User Name: Radim
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.02.22 19:57:01 | 000,549,376 | ---- | M] (OldTimer Tools) -- c:\Programy\Antivir\OTL.exe
PRC - [2010.01.08 00:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2009.11.14 18:00:31 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009.06.01 21:20:12 | 000,222,968 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.01.16 17:35:32 | 000,090,112 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
PRC - [2009.01.12 14:04:00 | 002,908,160 | ---- | M] (Leadtek Research Inc.) -- C:\Program Files\WinFast\WFDTV\WFWIZ.exe
PRC - [2008.09.27 17:52:00 | 000,162,304 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2008.09.23 17:59:00 | 000,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2008.04.14 07:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.09.14 06:02:10 | 001,080,264 | ---- | M] (C. Ghisler & Co.) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2006.02.28 11:42:38 | 000,229,376 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2004.12.13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


========== Modules (SafeList) ==========

MOD - [2010.02.22 19:57:01 | 000,549,376 | ---- | M] (OldTimer Tools) -- c:\Programy\Antivir\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - [2010.01.08 00:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2009.11.14 18:00:31 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) [Auto | Running] -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2009.06.01 21:20:12 | 000,222,968 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.03.04 10:25:12 | 000,621,056 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008.09.24 04:49:20 | 000,055,816 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\GIGABYTE\GEST\GSvr.exe -- (GEST Service)
SRV - [2008.09.23 17:59:00 | 000,109,056 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2008.09.19 17:26:12 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008.05.02 01:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007.12.05 00:41:00 | 000,155,716 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc)
SRV - [2007.05.11 01:09:48 | 001,050,120 | ---- | M] (O&O Software GmbH) [Disabled | Stopped] -- C:\WINDOWS\system32\oodag.exe -- (O&O Defrag)
SRV - [2006.10.30 02:34:02 | 000,122,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2006.02.28 11:42:38 | 000,229,376 | ---- | M] (Apple Computer, Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV - [2004.12.13 04:34:32 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
SRV - [2003.07.28 19:28:22 | 000,089,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - [2010.02.20 14:45:45 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2010.02.07 19:19:56 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008.12.25 01:56:42 | 000,433,792 | R--- | M] (Leadtek Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wfeaglxt.sys -- (WFLR6654) WinFast DTV1800 H (XC4000)
DRV - [2008.09.24 04:47:38 | 000,030,008 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2008.09.19 02:09:17 | 000,020,747 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP) AEGIS Protocol (IEEE 802.1x)
DRV - [2008.05.15 11:07:00 | 000,061,424 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- c:\Program Files\CyberLink\PowerDVD8\000.fcl -- ({FE4C91E7-22C2-4D0C-9F6B-82F1B7742054})
DRV - [2008.04.14 00:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mpe.sys -- (MPE)
DRV - [2008.04.14 00:15:38 | 000,026,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser.sys -- (usbser)
DRV - [2008.04.13 23:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) Ovladač zvukové karty USB (WDM)
DRV - [2008.04.13 21:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008.02.29 02:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.02.29 02:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008.02.29 02:12:48 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2008.02.14 10:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008.01.03 15:10:16 | 000,105,856 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007.12.05 00:41:00 | 007,435,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006.09.01 11:32:50 | 000,003,712 | ---- | M] (Logitech Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LBeepKE.sys -- (LBeepKE)
DRV - [2004.12.23 17:27:56 | 000,027,392 | ---- | M] (Ulead Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ULCDRHlp.sys -- (ULCDRHlp)
DRV - [2004.12.20 19:37:14 | 000,020,016 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\PxHelp20.sys -- (PxHelp20)
DRV - [2001.10.25 15:00:00 | 000,017,792 | ---- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie


IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aukro.cz/
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\S-1-5-21-1645522239-2139871995-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\S-1-5-21-1645522239-2139871995-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://novinky.cz/"
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.1.0014
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.1.13
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:1.1.4.1
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... id=afex&q="


FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.02.19 16:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.02.19 16:36:58 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009.08.22 12:41:25 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.23\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2008.09.19 01:53:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Extensions
[2010.02.21 23:22:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\extensions
[2010.02.10 12:42:02 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010.02.07 19:20:18 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\daemon-search.xml
[2010.02.19 08:31:10 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-1.xml
[2009.08.09 07:38:38 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-10.xml
[2009.09.16 17:43:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-11.xml
[2009.10.28 19:16:23 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-12.xml
[2009.12.16 13:04:05 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-13.xml
[2010.01.06 16:03:53 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-14.xml
[2010.01.15 22:02:48 | 000,000,961 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-15.xml
[2008.12.20 09:04:20 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-2.xml
[2009.02.04 20:38:43 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-3.xml
[2009.03.05 17:58:52 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-4.xml
[2009.03.28 11:19:21 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-5.xml
[2009.04.23 22:44:01 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-6.xml
[2009.04.28 21:18:57 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-7.xml
[2009.06.13 11:48:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-8.xml
[2009.07.23 21:34:10 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin-9.xml
[2008.03.31 08:52:00 | 000,000,168 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin.gif
[2008.03.31 08:52:00 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin.src
[2009.06.07 13:21:06 | 000,000,944 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\icqplugin.xml
[2010.02.21 13:26:22 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.06.20 08:01:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.02.19 16:36:54 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.02.19 16:36:54 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.02.19 16:36:54 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.02.19 16:36:54 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.02.19 16:36:54 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.02.19 08:44:33 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Podpora odkazu pro Adobe PDF Reader) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe (Leadtek Research Inc.)
O4 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe (Leadtek Research Inc.)
O4 - Startup: C:\Documents and Settings\Radim\Nabídka Start\Programy\Po spuštění\SystemExplorerDisabled [2008.12.04 17:21:41 | 000,000,000 | -H-D | M]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = [binary data]
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra Button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (ICQ, LLC.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} https://download.macromedia.com/pub/sho ... tor/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/ ... mvadvd.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/fl ... rashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://icq.oberon-media.com/Gameshell/G ... meHost.cab (Oberon Flash Game Host)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\ORCAD_~1.0_D\tools\Capture\itss.dll File not found
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\ORCAD_~1.0_D\tools\Capture\itss.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Nebe.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.09.19 01:41:48 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (OODBS) - C:\WINDOWS\System32\OODBS.exe (O&O Software GmbH)
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008.09.19 03:26:42 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (55172488459452416)

========== Files/Folders - Created Within 30 Days ==========

[2010.02.22 14:44:44 | 000,000,000 | ---D | C] -- C:\Program Files\HD Tune
[2010.02.22 14:33:01 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Radim\Recent
[2010.02.21 23:42:39 | 000,433,792 | R--- | C] (Leadtek Research Inc.) -- C:\WINDOWS\System32\drivers\wfeaglxt.sys
[2010.02.21 14:56:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\DoctorWeb
[2010.02.19 21:18:04 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010.02.19 16:56:40 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010.02.19 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Local Settings\Data aplikací\FreeFixer
[2010.02.19 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\FreeFixer
[2010.02.19 08:39:53 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.02.18 14:44:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\Malwarebytes
[2010.02.18 14:43:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.02.18 14:43:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.02.17 23:21:37 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.02.17 23:18:38 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.02.17 23:18:37 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.02.17 23:18:37 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.02.17 23:18:37 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.02.17 23:18:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.02.17 23:14:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.02.07 19:20:18 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2010.02.07 19:19:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\DAEMON Tools Lite
[2010.02.07 19:18:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.01.30 13:24:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Radim\Data aplikací\Mikrotik
[2008.09.19 01:44:29 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2008.09.19 01:44:16 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2008.09.19 01:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2008.09.18 21:08:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[13 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.02.22 19:22:45 | 000,003,396 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2010.02.22 18:32:28 | 005,767,168 | ---- | M] () -- C:\Documents and Settings\Radim\ntuser.dat
[2010.02.22 18:32:28 | 000,000,002 | ---- | M] () -- C:\WINDOWS\System32\Dvbpws.dll
[2010.02.22 18:01:08 | 000,000,192 | ---- | M] () -- C:\WINDOWS\winamp.ini
[2010.02.22 17:59:08 | 000,051,472 | ---- | M] () -- C:\Documents and Settings\Radim\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.02.22 17:00:33 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.02.22 14:44:44 | 000,000,622 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\HD Tune.lnk
[2010.02.22 14:38:37 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.02.22 14:38:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.02.22 14:38:28 | 001,135,253 | ---- | M] () -- C:\WINDOWS\System32\oodbs.lor
[2010.02.22 14:33:01 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\Radim\ntuser.ini
[2010.02.22 13:51:25 | 001,518,360 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.02.22 13:47:37 | 000,000,143 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\DrWeb.csv
[2010.02.22 05:21:58 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.xls
[2010.02.22 05:20:52 | 000,000,284 | ---- | M] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.csv
[2010.02.22 00:01:07 | 000,001,433 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\WinFast PVR2.lnk
[2010.02.21 21:40:45 | 000,000,158 | ---- | M] () -- C:\WINDOWS\matlab.ini
[2010.02.21 14:48:36 | 000,002,504 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.02.21 12:49:03 | 000,002,275 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2010.02.20 14:45:45 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\gdrv.sys
[2010.02.19 22:48:10 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.02.19 18:09:35 | 000,000,390 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2010.02.19 08:44:33 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.02.18 14:58:19 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\cqfyto.dat
[2010.02.18 13:56:11 | 003,861,435 | R--- | M] () -- C:\Documents and Settings\Radim\Plocha\ComboFix.exe
[2010.02.17 23:21:40 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010.02.09 15:46:45 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.02.07 19:19:56 | 000,691,696 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[13 C:\Documents and Settings\All Users\Data aplikací\*.tmp files -> C:\Documents and Settings\All Users\Data aplikací\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.02.22 14:44:44 | 000,000,622 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\HD Tune.lnk
[2010.02.22 05:21:58 | 000,018,432 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.xls
[2010.02.22 05:20:52 | 000,000,284 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\DrWeb1.csv
[2010.02.22 00:01:07 | 000,001,433 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\WinFast PVR2.lnk
[2010.02.21 20:53:04 | 000,000,143 | ---- | C] () -- C:\Documents and Settings\Radim\Plocha\DrWeb.csv
[2010.02.19 22:47:46 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\Dvbpws.dll
[2010.02.18 14:58:19 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Radim\Data aplikací\cqfyto.dat
[2010.02.17 23:21:40 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.02.17 23:21:38 | 000,261,312 | ---- | C] () -- C:\cmldr
[2010.02.17 23:18:38 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.02.17 23:18:38 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.02.17 23:18:37 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.02.17 23:18:37 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.02.17 23:18:37 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.02.17 23:14:19 | 003,861,435 | R--- | C] () -- C:\Documents and Settings\Radim\Plocha\ComboFix.exe
[2010.02.17 19:04:12 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\NetworkService\Data aplikací\cqfyto.dat
[2009.12.21 17:49:32 | 000,000,030 | ---- | C] () -- C:\WINDOWS\pslabeler3.ini
[2009.12.21 16:00:32 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2009.08.22 13:09:36 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\SYNSOACC.dll
[2009.08.22 13:09:30 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\bgspmnt.dll
[2009.08.22 13:09:20 | 000,000,571 | ---- | C] () -- C:\WINDOWS\System32\FeMakro.ini
[2009.08.22 13:09:20 | 000,000,497 | ---- | C] () -- C:\WINDOWS\System32\FeAnim.ini
[2009.04.01 13:54:23 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2009.02.27 15:12:23 | 000,000,158 | ---- | C] () -- C:\WINDOWS\matlab.ini
[2008.12.02 23:01:27 | 000,000,192 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2008.10.13 18:11:56 | 000,000,146 | ---- | C] () -- C:\WINDOWS\capture.INI
[2008.10.13 17:45:42 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfpct60n.dll
[2008.10.13 17:45:41 | 000,903,168 | ---- | C] () -- C:\WINDOWS\System32\mitmdl30.dll
[2008.10.13 17:45:41 | 000,251,904 | ---- | C] () -- C:\WINDOWS\System32\orant71.dll
[2008.10.13 17:45:41 | 000,176,128 | ---- | C] () -- C:\WINDOWS\System32\lffax60n.dll
[2008.10.13 17:45:41 | 000,141,824 | ---- | C] () -- C:\WINDOWS\System32\lfcmp60n.dll
[2008.10.13 17:45:41 | 000,110,080 | ---- | C] () -- C:\WINDOWS\System32\lfpng60n.dll
[2008.10.13 17:45:41 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\lftif60n.dll
[2008.10.13 17:45:41 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\lfpcx60n.dll
[2008.10.13 17:45:41 | 000,022,528 | ---- | C] () -- C:\WINDOWS\System32\lfeps60n.dll
[2008.10.13 17:45:41 | 000,022,016 | ---- | C] () -- C:\WINDOWS\System32\lfbmp60n.dll
[2008.10.13 17:45:41 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\lfpsd60n.dll
[2008.10.13 17:45:41 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\lftga60n.dll
[2008.10.13 17:45:41 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwpg60n.dll
[2008.10.13 17:45:41 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\lfwmf60n.dll
[2008.10.13 17:45:41 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\lfmsp60n.dll
[2008.10.13 17:45:41 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\lfmac60n.dll
[2008.10.13 17:43:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SPLASH.INI
[2008.09.21 18:20:30 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS6s.DLL
[2008.09.21 18:18:05 | 000,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008.09.19 22:28:27 | 000,000,293 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2008.09.19 17:52:15 | 000,003,396 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2008.09.19 17:18:40 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.09.19 02:09:33 | 000,290,918 | ---- | C] () -- C:\WINDOWS\System32\Install7x.dll
[2008.09.19 01:58:49 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.09.19 01:58:48 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2008.09.19 01:58:25 | 000,000,000 | ---- | C] () -- C:\WINDOWS\oodcnt.INI
[2008.09.19 01:56:20 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2008.09.18 22:52:31 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2008.09.18 22:01:12 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008.09.18 21:26:35 | 000,009,728 | ---- | C] () -- C:\Documents and Settings\Radim\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008.09.18 20:55:12 | 000,000,510 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007.12.05 00:41:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.12.05 00:41:00 | 001,474,560 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.12.05 00:41:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.12.05 00:41:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.12.05 00:41:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2003.04.09 14:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002.03.21 14:39:02 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\UNACEV2.DLL

========== LOP Check ==========

[2008.09.21 13:32:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ACD Systems
[2009.12.21 15:18:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2009.12.24 09:25:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonIJScan
[2010.02.07 19:19:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2009.06.20 08:01:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2009.04.29 15:04:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Installations
[2009.03.11 14:43:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\PC Suite
[2009.05.26 18:26:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ScanSoft
[2008.09.21 18:18:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanAppDataDir
[2008.09.21 18:18:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SSScanWizard
[2010.02.20 14:43:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SystemExplorer
[2009.11.27 15:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2008.12.04 17:24:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2008.09.21 11:12:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ACD Systems
[2008.11.12 21:49:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\CadSoft
[2009.12.24 09:25:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Canon
[2010.02.07 19:31:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\DAEMON Tools Lite
[2010.02.02 16:16:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\FileZilla
[2010.02.19 09:34:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\FreeFixer
[2010.02.21 12:55:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ICQ
[2009.11.27 15:07:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\langmaster.sz
[2008.09.18 20:20:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\MetaProducts
[2010.01.30 13:24:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Mikrotik
[2009.06.29 16:07:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Nokia
[2009.09.12 09:04:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\PC Suite
[2010.01.15 20:57:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\pdfforge
[2009.08.22 13:09:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\pdfMachine
[2008.11.17 17:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ProfiCAD
[2008.09.21 18:18:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\ScanSoft
[2010.01.15 20:57:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Search Settings
[2008.09.25 20:24:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\Thunderbird
[2008.12.04 17:24:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Radim\Data aplikací\TuneUp Software
[2010.02.19 18:09:35 | 000,000,390 | ---- | M] () -- C:\WINDOWS\Tasks\1-Click Maintenance.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >

< %SYSTEMDRIVE%\eventlog.dll /s /md5 >
[2004.08.17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008.04.14 07:51:42 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\system32\eventlog.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\scecli.dll /s /md5 >
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008.04.14 07:51:56 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\system32\scecli.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\netlogon.dll /s /md5 >
[2004.08.17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008.04.14 07:51:52 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\system32\netlogon.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\cngaudit.dll /s /md5 >

< %SYSTEMDRIVE%\sceclt.dll /s /md5 >

< %SYSTEMDRIVE%\ntelogon.dll /s /md5 >

< %SYSTEMDRIVE%\logevent.dll /s /md5 >

< %SYSTEMDRIVE%\iaStor.sys /s /md5 >

< %SYSTEMDRIVE%\nvstor.sys /s /md5 >

< %SYSTEMDRIVE%\atapi.sys /s /md5 >
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008.04.13 23:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

< %SYSTEMDRIVE%\IdeChnDr.sys /s /md5 >

< %SYSTEMDRIVE%\viasraid.sys /s /md5 >

< %SYSTEMDRIVE%\AGP440.sys /s /md5 >
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008.04.13 23:06:40 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys

< %SYSTEMDRIVE%\vaxscsi.sys /s /md5 >

< %SYSTEMDRIVE%\nvatabus.sys /s /md5 >

< %SYSTEMDRIVE%\viamraid.sys /s /md5 >

< %SYSTEMDRIVE%\nvata.sys /s /md5 >

< %SYSTEMROOT%\*. /mp /s >

< %SYSTEMROOT%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMROOT%\Tasks\*.job /lockedfiles >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0230417D
< End of report >

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Rootkit-gen [RtK]

#43 Příspěvek od stell »

:arrow:
Odinstaluj progrm C:\Program Files\DAEMON Tools Lite i pokud mas jine emulatory mechanik, alcohol aspol.
http://www.duplexsecure.com/en/downloads
:arrow: Stahni dle ze stranek SPTD http://www.duplexsecure.com/en/downloads verzi dle sveho operacniho systemu. SPTD for Windows (32 bit) nebo (64b) na plochu
- spust
- zvol moznost Uninstall
- restart PC
:arrow:
odinstaluj Sandru.
spust OTL>do okna customscan/fixes vloz zeleny text a klik RUNFIX>>log po restarte vloz sem.

Kód: Vybrat vše

:OTL
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
FF - prefs.js..extensions.enabledItems: DTToolbar@toolbarnet.com:1.1.1.0014
[2010.02.07 19:20:18 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\Mozilla\Firefox\Profiles\2tmh8x2b.default\searchplugins\daemon-search.xml
O3 - HKU\S-1-5-21-1645522239-2139871995-725345543-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\OrCAD\ORCAD_~1.0_D\tools\Capture\itss.dll File not found
[2010.02.07 19:20:18 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar
[2010.02.18 14:58:19 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Radim\Data aplikací\cqfyto.dat
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Data aplikací\TEMP:0230417D
:commands
[emptytemp]
[start explorer]
[Reboot]
:arrow:
stiahnes specialnu verziu G-Mer
Special
uloz na plochu >>
Odpojiť sa od internetu a zatvor všetky otvorené programy,
Dočasne zakázať akékoľvek real-time aktívnej ochrany,
a spust>.prebehne kratky skan,,,
ak dostanes hlasku rootkit activity and asks if you want to run scan>>kliknes NO<<
a nastavis to takto
Obrázek

>> kliknes scan,<<
na konci skanu >>SAVE<< nazov das mojlog.txt>>uloz na plochu a log vloz sem,,


Ak nedostanes ziadnu hlasku,,,nechas vsetko zafajknute a kliknes SCAN->>>>po skane >>SAVE<<log vloz sem,
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

lordbrutus
Návštěvník
Návštěvník
Příspěvky: 26
Registrován: 17 úno 2010 23:37

Re: Rootkit-gen [RtK]

#44 Příspěvek od lordbrutus »

Ahoj, omlouvam se ale uz jsem to vyresil raznym krokem. format c: a nova instalace OS. Nyni pouzivam jako antivir AVAST 5. Kazdopadne dekuji Vam za pomoc a preji mnoho uspechu v odstranovani viru a jine haveti. :)

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15691
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Rootkit-gen [RtK]

#45 Příspěvek od JaRon »

aj za kolegu: radi sme poradili :)
ad format: niekedy je system tak nahryznuty, ze aj toto riesenie sa rata :wink:
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět