
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu....hlásí vir
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Prosím o kontrolu logu....hlásí vir
Logfile of random's system information tool 1.06 (written by random/random)
Run by pc at 2010-03-11 17:05:50
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (19%) free of 16 GB
Total RAM: 447 MB (15% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
UrlHelper Class - C:\Program Files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\pc\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2008-12-30 131072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-06-29 7626752]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-06-29 86016]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-09-07 716800]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2008-06-29 52168]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-06-28 32768]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"EPSON Stylus SX400 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE [2007-12-17 188928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Disabled:Nero Home"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Documents and Settings\pc\Local Settings\Temporary Internet Files\Content.IE5\CHEBC5UN\incredimail_install[1].exe"="C:\Documents and Settings\pc\Local Settings\Temporary Internet Files\Content.IE5\CHEBC5UN\incredimail_install[1].exe:*:Enabled:IncrediMail Installer"
"C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\Documents and Settings\pc\Plocha\magentic_install(2).exe"="C:\Documents and Settings\pc\Plocha\magentic_install(2).exe:*:Enabled:IncrediMail Installer"
"C:\Program Files\Magentic\bin\MgImp.exe"="C:\Program Files\Magentic\bin\MgImp.exe:*:Enabled:Magentic"
"C:\Program Files\Magentic\bin\Magentic.exe"="C:\Program Files\Magentic\bin\Magentic.exe:*:Enabled:Magentic"
"C:\Program Files\Magentic\bin\MgApp.exe"="C:\Program Files\Magentic\bin\MgApp.exe:*:Enabled:Magentic"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{371e82ec-7a55-11da-bcc4-9a66781f7cd8}]
shell\AutoRun\command - G:\autoverify.exe
======List of files/folders created in the last 1 months======
2010-03-11 17:05:53 ----D---- C:\Program Files\trend micro
2010-03-11 17:05:50 ----D---- C:\rsit
2010-03-11 17:04:43 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-11 17:04:40 ----D---- C:\WINDOWS\LastGood
2010-03-11 16:42:35 ----D---- C:\WINDOWS\PixArt
2010-03-11 16:42:32 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-03-11 16:39:55 ----A---- C:\WINDOWS\system32\SP207.INI
2010-03-11 16:39:55 ----A---- C:\WINDOWS\system32\CoInst_070629.dll
2010-03-11 16:39:53 ----D---- C:\Program Files\Webcam 1200
2010-03-11 16:39:52 ----A---- C:\WINDOWS\AMCap.exe
2010-03-11 16:32:30 ----D---- C:\Program Files\Microsoft Works
2010-03-11 16:32:06 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-11 16:31:24 ----D---- C:\Program Files\Microsoft.NET
2010-03-11 16:28:35 ----D---- C:\WINDOWS\SHELLNEW
2010-03-11 16:27:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-03-11 16:11:57 ----SHD---- C:\Config.Msi
2010-03-11 16:09:02 ----D---- C:\WINDOWS\system32\XPSViewer
2010-03-11 16:08:53 ----D---- C:\Program Files\MSBuild
2010-03-11 16:08:50 ----D---- C:\WINDOWS\system32\en-US
2010-03-11 16:08:18 ----D---- C:\Program Files\Reference Assemblies
2010-03-11 16:07:25 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-03-11 16:07:24 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-03-11 16:07:24 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-03-11 15:22:08 ----D---- C:\Documents and Settings\pc\Data aplikací\IObit
2010-03-11 15:22:06 ----D---- C:\Program Files\IObit
2010-03-11 15:12:41 ----D---- C:\Program Files\Zoner
2010-03-11 15:08:54 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-11 15:08:13 ----D---- C:\WINDOWS\Prefetch
2010-03-11 15:02:25 ----A---- C:\WINDOWS\setuplog.txt
2010-03-11 15:01:41 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-03-11 15:01:41 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-03-11 15:01:40 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-03-11 15:01:40 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-03-11 15:01:40 ----N---- C:\WINDOWS\system32\comsdupd.exe
2010-03-11 15:01:35 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-03-11 15:01:35 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2010-03-11 15:01:35 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-03-11 15:01:34 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2010-03-11 15:01:33 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-03-11 15:01:31 ----N---- C:\WINDOWS\system32\ati3duag.dll
2010-03-11 15:01:30 ----N---- C:\WINDOWS\system32\azroles.dll
2010-03-11 15:01:30 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2010-03-11 15:01:30 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-03-11 15:01:29 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-03-11 15:01:27 ----N---- C:\WINDOWS\system32\credssp.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-03-11 15:01:24 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-03-11 15:01:24 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-03-11 15:01:23 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-03-11 15:01:23 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\mssha.dll
2010-03-11 15:01:19 ----N---- C:\WINDOWS\system32\napstat.exe
2010-03-11 15:01:18 ----N---- C:\WINDOWS\system32\onex.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qutil.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qagent.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slserv.exe
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slgen.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\setupn.exe
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-03-11 15:01:14 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-03-11 15:01:14 ----N---- C:\WINDOWS\slrundll.exe
2010-03-11 15:01:14 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-11 15:01:13 ----D---- C:\WINDOWS\l2schemas
2010-03-11 15:01:12 ----D---- C:\WINDOWS\system32\cs
2010-03-11 15:01:12 ----D---- C:\WINDOWS\system32\bits
2010-03-11 14:59:25 ----D---- C:\WINDOWS\ServicePackFiles
2010-03-11 14:57:48 ----D---- C:\WINDOWS\network diagnostic
2010-03-11 14:56:14 ----A---- C:\WINDOWS\002767_.tmp
2010-03-11 14:53:14 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-03-11 14:26:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-03-11 14:17:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-03-11 14:17:55 ----D---- C:\Program Files\Alwil Software
2010-03-11 14:17:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-03-11 14:13:09 ----A---- C:\WINDOWS\imsins.BAK
2010-03-11 14:13:06 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-03-11 14:13:00 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-03-11 14:09:33 ----A---- C:\WINDOWS\system32\wups2.dll
2010-03-11 14:09:33 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-03-11 14:09:32 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-03-11 14:09:31 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-03-11 14:09:31 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-03-11 14:04:52 ----D---- C:\Program Files\WinASO
======List of files/folders modified in the last 1 months======
2010-03-11 17:05:53 ----RD---- C:\Program Files
2010-03-11 17:05:43 ----HD---- C:\WINDOWS\inf
2010-03-11 17:05:38 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-11 17:05:38 ----D---- C:\WINDOWS
2010-03-11 17:05:02 ----D---- C:\Documents and Settings\pc\Data aplikací\Skype
2010-03-11 17:00:10 ----D---- C:\WINDOWS\Temp
2010-03-11 16:50:45 ----D---- C:\Documents and Settings\pc\Data aplikací\skypePM
2010-03-11 16:50:05 ----D---- C:\WINDOWS\system32
2010-03-11 16:48:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-11 16:43:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-11 16:43:10 ----D---- C:\WINDOWS\system32\drivers
2010-03-11 16:42:44 ----A---- C:\WINDOWS\win.ini
2010-03-11 16:42:35 ----D---- C:\WINDOWS\twain_32
2010-03-11 16:39:48 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-11 16:35:52 ----SD---- C:\Documents and Settings\pc\Data aplikací\Microsoft
2010-03-11 16:34:08 ----SHD---- C:\WINDOWS\Installer
2010-03-11 16:33:50 ----RSD---- C:\WINDOWS\assembly
2010-03-11 16:33:33 ----D---- C:\WINDOWS\system32\config
2010-03-11 16:32:29 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-11 16:32:23 ----D---- C:\WINDOWS\WinSxS
2010-03-11 16:32:06 ----D---- C:\Program Files\Common Files
2010-03-11 16:31:37 ----RSD---- C:\WINDOWS\Fonts
2010-03-11 16:28:48 ----D---- C:\Program Files\Common Files\System
2010-03-11 16:17:48 ----D---- C:\WINDOWS\Microsoft.NET
2010-03-11 16:13:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-11 16:07:45 ----D---- C:\WINDOWS\system32\spool
2010-03-11 16:05:25 ----D---- C:\WINDOWS\system32\mui
2010-03-11 16:05:25 ----D---- C:\Program Files\Internet Explorer
2010-03-11 15:53:03 ----D---- C:\Program Files\ACD Systems
2010-03-11 15:41:35 ----D---- C:\WINDOWS\Help
2010-03-11 15:32:42 ----D---- C:\Program Files\Mozilla Firefox
2010-03-11 15:13:25 ----D---- C:\Documents and Settings\pc\Data aplikací\Zoner
2010-03-11 15:08:58 ----D---- C:\WINDOWS\Debug
2010-03-11 15:07:49 ----D---- C:\WINDOWS\system32\Setup
2010-03-11 15:07:49 ----D---- C:\WINDOWS\AppPatch
2010-03-11 15:07:49 ----D---- C:\Program Files\Messenger
2010-03-11 15:07:48 ----D---- C:\WINDOWS\system32\wbem
2010-03-11 15:06:49 ----D---- C:\Documents and Settings\pc\Data aplikací\ICQ
2010-03-11 15:05:20 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-11 15:05:16 ----D---- C:\WINDOWS\security
2010-03-11 15:01:41 ----D---- C:\WINDOWS\ehome
2010-03-11 15:01:40 ----D---- C:\WINDOWS\system32\inetsrv
2010-03-11 15:01:39 ----D---- C:\WINDOWS\ime
2010-03-11 15:01:14 ----D---- C:\WINDOWS\system32\usmt
2010-03-11 15:01:12 ----D---- C:\WINDOWS\PeerNet
2010-03-11 15:01:12 ----D---- C:\Program Files\Movie Maker
2010-03-11 14:59:18 ----D---- C:\WINDOWS\system32\Restore
2010-03-11 14:59:18 ----D---- C:\WINDOWS\system32\npp
2010-03-11 14:59:17 ----D---- C:\WINDOWS\msagent
2010-03-11 14:59:16 ----D---- C:\WINDOWS\srchasst
2010-03-11 14:59:16 ----D---- C:\Program Files\NetMeeting
2010-03-11 14:59:15 ----D---- C:\WINDOWS\system32\Com
2010-03-11 14:59:13 ----D---- C:\Program Files\Windows NT
2010-03-11 14:59:13 ----D---- C:\Program Files\Windows Media Player
2010-03-11 14:59:13 ----D---- C:\Program Files\Outlook Express
2010-03-11 14:58:57 ----D---- C:\WINDOWS\system32\oobe
2010-03-11 14:58:56 ----D---- C:\WINDOWS\system
2010-03-11 14:56:09 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-11 14:27:18 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-03-11 14:26:38 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-11 13:47:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-11 13:47:23 ----D---- C:\WINDOWS\Minidump
2010-03-11 13:32:25 ----D---- C:\Program Files\CCleaner
2010-03-11 11:18:43 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-28 18:00:26 ----D---- C:\Documents and Settings\pc\Data aplikací\Spyware Terminator
2010-02-18 15:18:40 ----D---- C:\Program Files\CyberLink
2010-02-18 15:17:02 ----D---- C:\Program Files\ASUS
2010-02-18 15:15:58 ----D---- C:\Documents and Settings\pc\Data aplikací\Lavasoft
2010-02-18 15:08:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2010-02-13 12:55:28 ----SD---- C:\WINDOWS\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-03-09 28880]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2005-12-22 5685]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-03-09 100432]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-12-25 278984]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-12-25 25416]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-03-09 23376]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2005-05-03 27392]
R3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-06-29 3929184]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-06-29 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-06-29 20480]
R3 PAC207;Webcam 1200; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-06-29 611584]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2005-10-10 393088]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2008-09-24 29184]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-10-27 223128]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-09-08 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-10 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 IJPLMSVC;Inkjet Printer/Scanner Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2008-01-22 103808]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-06-29 155715]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-06-27 244904]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-09-08 606720]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
R2 UTSCSI;Usbest Service Zero; C:\WINDOWS\system32\UTSCSI.EXE [2006-01-01 45568]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2010-03-11 17:06:04
======Uninstall list======
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A70000000000}
ASUS_Ai_Proactive_Screensaver (E)-->C:\WINDOWS\ASUS_Ai_Proactive_Screensaver (E).scr /u
Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x5
avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{42EDF895-158C-484E-A7F2-42B90759F281}\SETUP.EXE" -l0x9 UNINST
Canon MP Navigator EX 1.2-->"C:\Program Files\Canon\MP Navigator EX 1.2\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.2\uninst.ini
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
Combined Community Codec Pack 2006-12-15-->"C:\Program Files\Combined Community Codec Pack\unins000.exe"
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
DVDFab Decrypter 2.9.8.1-->"C:\Program Files\DVDFab Decrypter\unins000.exe"
EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}\SETUP.EXE" -l0x9 UNINST
EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{46CBBDF8-55B5-40DB-B459-7B848394309C}\Setup.exe" -l0x9 UNINST
EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Stylus SX400 Series Printer Uninstall-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FINSEGE.EXE /R /APD /P:"EPSON Stylus SX400 Series"
EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x9 -anything
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
High Definition Audio Driver Package - KB888111-->C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
ICQ6.5-->"C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
Indeo® software-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Intel\Indeo\Indeo Uninstall.isu" -c"C:\WINDOWS\system32\SavedSystemFiles\indounin.dll"
Inkjet Printer/Scanner Extended Survey Program-->C:\Program Files\Canon\IJPLM\SETUP.EXE -R
Magentic-->C:\PROGRA~1\Magentic\bin\mgsetup.exe /remove /addon:Magentic
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox (3.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Demo-->MsiExec.exe /I{C75DCDD3-16CB-610E-E121-DEB798A61029}
NVIDIA Drivers-->C:\WINDOWS\system32\NVUNINST.EXE UninstallGUI
PowerDirector Express-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDE721EC-870A-11D8-9D75-000129760D75}\setup.exe" -uninstall
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
QIP 2005 8081-->"C:\Program Files\QIP\unins000.exe"
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Defrag 1.10-->"C:\Program Files\IObit\IObit SmartDefrag\unins000.exe"
SoundMAX-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x9 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe"
TrackIR4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE6E6BF7-6A81-4EC2-AD29-4580025149F1}\setup.exe"
VirtualCloneDrive-->"C:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="C:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Webcam 1200-->C:\Program Files\InstallShield Installation Information\{66D475AE-F18B-43A0-8BAF-61AF4403E339}\setup.exe -runfromtemp -l0x0009 -removeonly
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
WinASO Registry Optimizer 4.5.1-->"C:\Program Files\WinASO\Registry Optimizer\unins000.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Zoner Photo Studio 12-->"C:\Program Files\Zoner\Photo Studio 12\unins000.exe" /SILENT
======Hosts File======
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
======Security center information======
AV: avast! Antivirus
======System event log======
Computer Name: PC-8
Event Code: 7036
Message: Stav služby Služba modelu COM pro zápis na disk CD (IMAPI) byl změněn na: Spuštěno
Record Number: 3874
Source Name: Service Control Manager
Time Written: 20091220113316.000000+060
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Služba modelu COM pro zápis na disk CD (IMAPI) úspěšně odeslán.
Record Number: 3873
Source Name: Service Control Manager
Time Written: 20091220113316.000000+060
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: PC-8
Event Code: 7036
Message: Stav služby Služba modelu COM pro zápis na disk CD (IMAPI) byl změněn na: Zastaveno
Record Number: 3872
Source Name: Service Control Manager
Time Written: 20091220111425.000000+060
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 7036
Message: Stav služby Služba modelu COM pro zápis na disk CD (IMAPI) byl změněn na: Spuštěno
Record Number: 3871
Source Name: Service Control Manager
Time Written: 20091220111419.000000+060
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Služba modelu COM pro zápis na disk CD (IMAPI) úspěšně odeslán.
Record Number: 3870
Source Name: Service Control Manager
Time Written: 20091220111419.000000+060
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: PC-8
Event Code: 0
Message:
Record Number: 5802
Source Name: RichVideo
Time Written: 20090526142945.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 1
Message: The service is started.
Record Number: 5801
Source Name: IJPLMSVC
Time Written: 20090526142944.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 0
Message:
Record Number: 5800
Source Name: ICQ Service
Time Written: 20090526142944.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 101
Message: wuauclt (4044) Databázový stroj byl zastaven.
Record Number: 5799
Source Name: ESENT
Time Written: 20090526110205.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 103
Message: wuaueng.dll (4044) SUS20ClientDataStore: Databázový stroj zastavil instanci (0).
Record Number: 5798
Source Name: ESENT
Time Written: 20090526110205.000000+120
Event Type: Informace
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 79 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=4f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Run by pc at 2010-03-11 17:05:50
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 3 GB (19%) free of 16 GB
Total RAM: 447 MB (15% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
UrlHelper Class - C:\Program Files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Documents and Settings\pc\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2008-12-30 131072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-06-29 7626752]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-06-29 86016]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2004-10-27 61952]
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe [2005-05-20 925696]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2005-09-07 716800]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2008-06-29 52168]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2004-06-28 32768]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]
"Monitor"=C:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"EPSON Stylus SX400 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGE.EXE [2007-12-17 188928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" "
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQLite\ICQLite.exe"="C:\Program Files\ICQLite\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe"="C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe:*:Disabled:Nero Home"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Documents and Settings\pc\Local Settings\Temporary Internet Files\Content.IE5\CHEBC5UN\incredimail_install[1].exe"="C:\Documents and Settings\pc\Local Settings\Temporary Internet Files\Content.IE5\CHEBC5UN\incredimail_install[1].exe:*:Enabled:IncrediMail Installer"
"C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\Documents and Settings\pc\Plocha\magentic_install(2).exe"="C:\Documents and Settings\pc\Plocha\magentic_install(2).exe:*:Enabled:IncrediMail Installer"
"C:\Program Files\Magentic\bin\MgImp.exe"="C:\Program Files\Magentic\bin\MgImp.exe:*:Enabled:Magentic"
"C:\Program Files\Magentic\bin\Magentic.exe"="C:\Program Files\Magentic\bin\Magentic.exe:*:Enabled:Magentic"
"C:\Program Files\Magentic\bin\MgApp.exe"="C:\Program Files\Magentic\bin\MgApp.exe:*:Enabled:Magentic"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{371e82ec-7a55-11da-bcc4-9a66781f7cd8}]
shell\AutoRun\command - G:\autoverify.exe
======List of files/folders created in the last 1 months======
2010-03-11 17:05:53 ----D---- C:\Program Files\trend micro
2010-03-11 17:05:50 ----D---- C:\rsit
2010-03-11 17:04:43 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-11 17:04:40 ----D---- C:\WINDOWS\LastGood
2010-03-11 16:42:35 ----D---- C:\WINDOWS\PixArt
2010-03-11 16:42:32 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-03-11 16:39:55 ----A---- C:\WINDOWS\system32\SP207.INI
2010-03-11 16:39:55 ----A---- C:\WINDOWS\system32\CoInst_070629.dll
2010-03-11 16:39:53 ----D---- C:\Program Files\Webcam 1200
2010-03-11 16:39:52 ----A---- C:\WINDOWS\AMCap.exe
2010-03-11 16:32:30 ----D---- C:\Program Files\Microsoft Works
2010-03-11 16:32:06 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-11 16:31:24 ----D---- C:\Program Files\Microsoft.NET
2010-03-11 16:28:35 ----D---- C:\WINDOWS\SHELLNEW
2010-03-11 16:27:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-03-11 16:11:57 ----SHD---- C:\Config.Msi
2010-03-11 16:09:02 ----D---- C:\WINDOWS\system32\XPSViewer
2010-03-11 16:08:53 ----D---- C:\Program Files\MSBuild
2010-03-11 16:08:50 ----D---- C:\WINDOWS\system32\en-US
2010-03-11 16:08:18 ----D---- C:\Program Files\Reference Assemblies
2010-03-11 16:07:25 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-03-11 16:07:24 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-03-11 16:07:24 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-03-11 15:22:08 ----D---- C:\Documents and Settings\pc\Data aplikací\IObit
2010-03-11 15:22:06 ----D---- C:\Program Files\IObit
2010-03-11 15:12:41 ----D---- C:\Program Files\Zoner
2010-03-11 15:08:54 ----A---- C:\WINDOWS\OEWABLog.txt
2010-03-11 15:08:13 ----D---- C:\WINDOWS\Prefetch
2010-03-11 15:02:25 ----A---- C:\WINDOWS\setuplog.txt
2010-03-11 15:01:41 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-03-11 15:01:41 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-03-11 15:01:40 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-03-11 15:01:40 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-03-11 15:01:40 ----N---- C:\WINDOWS\system32\comsdupd.exe
2010-03-11 15:01:35 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-03-11 15:01:35 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2010-03-11 15:01:35 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-03-11 15:01:34 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2010-03-11 15:01:33 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-03-11 15:01:31 ----N---- C:\WINDOWS\system32\ati3duag.dll
2010-03-11 15:01:30 ----N---- C:\WINDOWS\system32\azroles.dll
2010-03-11 15:01:30 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2010-03-11 15:01:30 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-03-11 15:01:29 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-03-11 15:01:27 ----N---- C:\WINDOWS\system32\credssp.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-03-11 15:01:26 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-03-11 15:01:25 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-03-11 15:01:24 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-03-11 15:01:24 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-03-11 15:01:23 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-03-11 15:01:23 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-03-11 15:01:22 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-03-11 15:01:20 ----N---- C:\WINDOWS\system32\mssha.dll
2010-03-11 15:01:19 ----N---- C:\WINDOWS\system32\napstat.exe
2010-03-11 15:01:18 ----N---- C:\WINDOWS\system32\onex.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qutil.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\qagent.dll
2010-03-11 15:01:17 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\tzchange.exe
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slserv.exe
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slgen.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-03-11 15:01:16 ----N---- C:\WINDOWS\system32\setupn.exe
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-03-11 15:01:15 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-03-11 15:01:14 ----N---- C:\WINDOWS\system32\xmllite.dll
2010-03-11 15:01:14 ----N---- C:\WINDOWS\slrundll.exe
2010-03-11 15:01:14 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-11 15:01:13 ----D---- C:\WINDOWS\l2schemas
2010-03-11 15:01:12 ----D---- C:\WINDOWS\system32\cs
2010-03-11 15:01:12 ----D---- C:\WINDOWS\system32\bits
2010-03-11 14:59:25 ----D---- C:\WINDOWS\ServicePackFiles
2010-03-11 14:57:48 ----D---- C:\WINDOWS\network diagnostic
2010-03-11 14:56:14 ----A---- C:\WINDOWS\002767_.tmp
2010-03-11 14:53:14 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-03-11 14:26:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-03-11 14:17:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-03-11 14:17:55 ----D---- C:\Program Files\Alwil Software
2010-03-11 14:17:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-03-11 14:13:09 ----A---- C:\WINDOWS\imsins.BAK
2010-03-11 14:13:06 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-03-11 14:13:00 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-03-11 14:09:33 ----A---- C:\WINDOWS\system32\wups2.dll
2010-03-11 14:09:33 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2010-03-11 14:09:32 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2010-03-11 14:09:31 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-03-11 14:09:31 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2010-03-11 14:04:52 ----D---- C:\Program Files\WinASO
======List of files/folders modified in the last 1 months======
2010-03-11 17:05:53 ----RD---- C:\Program Files
2010-03-11 17:05:43 ----HD---- C:\WINDOWS\inf
2010-03-11 17:05:38 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-11 17:05:38 ----D---- C:\WINDOWS
2010-03-11 17:05:02 ----D---- C:\Documents and Settings\pc\Data aplikací\Skype
2010-03-11 17:00:10 ----D---- C:\WINDOWS\Temp
2010-03-11 16:50:45 ----D---- C:\Documents and Settings\pc\Data aplikací\skypePM
2010-03-11 16:50:05 ----D---- C:\WINDOWS\system32
2010-03-11 16:48:07 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-11 16:43:15 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-11 16:43:10 ----D---- C:\WINDOWS\system32\drivers
2010-03-11 16:42:44 ----A---- C:\WINDOWS\win.ini
2010-03-11 16:42:35 ----D---- C:\WINDOWS\twain_32
2010-03-11 16:39:48 ----HD---- C:\Program Files\InstallShield Installation Information
2010-03-11 16:35:52 ----SD---- C:\Documents and Settings\pc\Data aplikací\Microsoft
2010-03-11 16:34:08 ----SHD---- C:\WINDOWS\Installer
2010-03-11 16:33:50 ----RSD---- C:\WINDOWS\assembly
2010-03-11 16:33:33 ----D---- C:\WINDOWS\system32\config
2010-03-11 16:32:29 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-11 16:32:23 ----D---- C:\WINDOWS\WinSxS
2010-03-11 16:32:06 ----D---- C:\Program Files\Common Files
2010-03-11 16:31:37 ----RSD---- C:\WINDOWS\Fonts
2010-03-11 16:28:48 ----D---- C:\Program Files\Common Files\System
2010-03-11 16:17:48 ----D---- C:\WINDOWS\Microsoft.NET
2010-03-11 16:13:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-11 16:07:45 ----D---- C:\WINDOWS\system32\spool
2010-03-11 16:05:25 ----D---- C:\WINDOWS\system32\mui
2010-03-11 16:05:25 ----D---- C:\Program Files\Internet Explorer
2010-03-11 15:53:03 ----D---- C:\Program Files\ACD Systems
2010-03-11 15:41:35 ----D---- C:\WINDOWS\Help
2010-03-11 15:32:42 ----D---- C:\Program Files\Mozilla Firefox
2010-03-11 15:13:25 ----D---- C:\Documents and Settings\pc\Data aplikací\Zoner
2010-03-11 15:08:58 ----D---- C:\WINDOWS\Debug
2010-03-11 15:07:49 ----D---- C:\WINDOWS\system32\Setup
2010-03-11 15:07:49 ----D---- C:\WINDOWS\AppPatch
2010-03-11 15:07:49 ----D---- C:\Program Files\Messenger
2010-03-11 15:07:48 ----D---- C:\WINDOWS\system32\wbem
2010-03-11 15:06:49 ----D---- C:\Documents and Settings\pc\Data aplikací\ICQ
2010-03-11 15:05:20 ----D---- C:\WINDOWS\system32\CatRoot
2010-03-11 15:05:16 ----D---- C:\WINDOWS\security
2010-03-11 15:01:41 ----D---- C:\WINDOWS\ehome
2010-03-11 15:01:40 ----D---- C:\WINDOWS\system32\inetsrv
2010-03-11 15:01:39 ----D---- C:\WINDOWS\ime
2010-03-11 15:01:14 ----D---- C:\WINDOWS\system32\usmt
2010-03-11 15:01:12 ----D---- C:\WINDOWS\PeerNet
2010-03-11 15:01:12 ----D---- C:\Program Files\Movie Maker
2010-03-11 14:59:18 ----D---- C:\WINDOWS\system32\Restore
2010-03-11 14:59:18 ----D---- C:\WINDOWS\system32\npp
2010-03-11 14:59:17 ----D---- C:\WINDOWS\msagent
2010-03-11 14:59:16 ----D---- C:\WINDOWS\srchasst
2010-03-11 14:59:16 ----D---- C:\Program Files\NetMeeting
2010-03-11 14:59:15 ----D---- C:\WINDOWS\system32\Com
2010-03-11 14:59:13 ----D---- C:\Program Files\Windows NT
2010-03-11 14:59:13 ----D---- C:\Program Files\Windows Media Player
2010-03-11 14:59:13 ----D---- C:\Program Files\Outlook Express
2010-03-11 14:58:57 ----D---- C:\WINDOWS\system32\oobe
2010-03-11 14:58:56 ----D---- C:\WINDOWS\system
2010-03-11 14:56:09 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-03-11 14:27:18 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-03-11 14:26:38 ----D---- C:\WINDOWS\SoftwareDistribution
2010-03-11 13:47:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-11 13:47:23 ----D---- C:\WINDOWS\Minidump
2010-03-11 13:32:25 ----D---- C:\Program Files\CCleaner
2010-03-11 11:18:43 ----A---- C:\WINDOWS\NeroDigital.ini
2010-02-28 18:00:26 ----D---- C:\Documents and Settings\pc\Data aplikací\Spyware Terminator
2010-02-18 15:18:40 ----D---- C:\Program Files\CyberLink
2010-02-18 15:17:02 ----D---- C:\Program Files\ASUS
2010-02-18 15:15:58 ----D---- C:\Documents and Settings\pc\Data aplikací\Lavasoft
2010-02-18 15:08:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\CyberLink
2010-02-13 12:55:28 ----SD---- C:\WINDOWS\Tasks
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-03-09 28880]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2005-12-22 5685]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-03-09 100432]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2008-12-25 278984]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2008-12-25 25416]
R3 ADIHdAudAddService;ADI UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\ADIHdAud.sys [2005-10-05 141312]
R3 AEAudioService;AEAudio Service; C:\WINDOWS\system32\drivers\AEAudio.sys [2005-03-04 127872]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-03-09 23376]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2005-05-03 27392]
R3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2005-04-12 4608]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-06-29 3929184]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-06-29 57856]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-06-29 20480]
R3 PAC207;Webcam 1200; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-06-29 611584]
R3 SenFiltService;SenFilt Service; C:\WINDOWS\system32\drivers\Senfilt.sys [2005-10-10 393088]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2008-09-24 29184]
S3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-10-27 223128]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2004-10-27 145920]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-09-08 47360]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-10 18944]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 IJPLMSVC;Inkjet Printer/Scanner Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2008-01-22 103808]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-06-29 155715]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-06-27 244904]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2008-09-08 606720]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-10 38912]
R2 UTSCSI;Usbest Service Zero; C:\WINDOWS\system32\UTSCSI.EXE [2006-01-01 45568]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.06 2010-03-11 17:06:04
======Uninstall list======
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0 - Czech-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-A70000000000}
ASUS_Ai_Proactive_Screensaver (E)-->C:\WINDOWS\ASUS_Ai_Proactive_Screensaver (E).scr /u
Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x5
avast! Free Antivirus-->C:\Program Files\Alwil Software\Avast5\aswRunDll.exe "C:\Program Files\Alwil Software\Avast5\Setup\setiface.dll" RunSetup
Camera RAW Plug-In for EPSON Creativity Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{42EDF895-158C-484E-A7F2-42B90759F281}\SETUP.EXE" -l0x9 UNINST
Canon MP Navigator EX 1.2-->"C:\Program Files\Canon\MP Navigator EX 1.2\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator EX 1.2\uninst.ini
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd-uninst.exe" /D="C:\Program Files\SlySoft\CloneCD"
CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
Combined Community Codec Pack 2006-12-15-->"C:\Program Files\Combined Community Codec Pack\unins000.exe"
DVD Decrypter (Remove Only)-->"C:\Program Files\DVD Decrypter\uninstall.exe"
DVDFab Decrypter 2.9.8.1-->"C:\Program Files\DVDFab Decrypter\unins000.exe"
EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8A8F8391-4C2C-4BE1-A984-CD4A5A546467}\SETUP.EXE" -l0x9 UNINST
EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{46CBBDF8-55B5-40DB-B459-7B848394309C}\Setup.exe" -l0x9 UNINST
EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
EPSON Stylus SX400 Series Printer Uninstall-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FINSEGE.EXE /R /APD /P:"EPSON Stylus SX400 Series"
EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x9 -anything
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
High Definition Audio Driver Package - KB888111-->C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
ICQ6.5-->"C:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
Indeo® software-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Intel\Indeo\Indeo Uninstall.isu" -c"C:\WINDOWS\system32\SavedSystemFiles\indounin.dll"
Inkjet Printer/Scanner Extended Survey Program-->C:\Program Files\Canon\IJPLM\SETUP.EXE -R
Magentic-->C:\PROGRA~1\Magentic\bin\mgsetup.exe /remove /addon:Magentic
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office Access MUI (Czech) 2007-->MsiExec.exe /X{90120000-0015-0405-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (Czech) 2007-->MsiExec.exe /X{90120000-0016-0405-0000-0000000FF1CE}
Microsoft Office Groove MUI (Czech) 2007-->MsiExec.exe /X{90120000-00BA-0405-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (Czech) 2007-->MsiExec.exe /X{90120000-0044-0405-0000-0000000FF1CE}
Microsoft Office OneNote MUI (Czech) 2007-->MsiExec.exe /X{90120000-00A1-0405-0000-0000000FF1CE}
Microsoft Office Outlook MUI (Czech) 2007-->MsiExec.exe /X{90120000-001A-0405-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (Czech) 2007-->MsiExec.exe /X{90120000-0018-0405-0000-0000000FF1CE}
Microsoft Office Proof (Czech) 2007-->MsiExec.exe /X{90120000-001F-0405-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Slovak) 2007-->MsiExec.exe /X{90120000-001F-041B-0000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2007-->MsiExec.exe /X{90120000-002C-0405-0000-0000000FF1CE}
Microsoft Office Publisher MUI (Czech) 2007-->MsiExec.exe /X{90120000-0019-0405-0000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2007-->MsiExec.exe /X{90120000-006E-0405-0000-0000000FF1CE}
Microsoft Office Word MUI (Czech) 2007-->MsiExec.exe /X{90120000-001B-0405-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox (3.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Demo-->MsiExec.exe /I{C75DCDD3-16CB-610E-E121-DEB798A61029}
NVIDIA Drivers-->C:\WINDOWS\system32\NVUNINST.EXE UninstallGUI
PowerDirector Express-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDE721EC-870A-11D8-9D75-000129760D75}\setup.exe" -uninstall
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
QIP 2005 8081-->"C:\Program Files\QIP\unins000.exe"
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Defrag 1.10-->"C:\Program Files\IObit\IObit SmartDefrag\unins000.exe"
SoundMAX-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\setup.exe" -l0x9 -removeonly
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe"
TrackIR4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE6E6BF7-6A81-4EC2-AD29-4580025149F1}\setup.exe"
VirtualCloneDrive-->"C:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="C:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Webcam 1200-->C:\Program Files\InstallShield Installation Information\{66D475AE-F18B-43A0-8BAF-61AF4403E339}\setup.exe -runfromtemp -l0x0009 -removeonly
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
WinASO Registry Optimizer 4.5.1-->"C:\Program Files\WinASO\Registry Optimizer\unins000.exe"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR-->C:\Program Files\WinRAR\uninstall.exe
Zoner Photo Studio 12-->"C:\Program Files\Zoner\Photo Studio 12\unins000.exe" /SILENT
======Hosts File======
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
======Security center information======
AV: avast! Antivirus
======System event log======
Computer Name: PC-8
Event Code: 7036
Message: Stav služby Služba modelu COM pro zápis na disk CD (IMAPI) byl změněn na: Spuštěno
Record Number: 3874
Source Name: Service Control Manager
Time Written: 20091220113316.000000+060
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Služba modelu COM pro zápis na disk CD (IMAPI) úspěšně odeslán.
Record Number: 3873
Source Name: Service Control Manager
Time Written: 20091220113316.000000+060
Event Type: Informace
User: NT AUTHORITY\SYSTEM
Computer Name: PC-8
Event Code: 7036
Message: Stav služby Služba modelu COM pro zápis na disk CD (IMAPI) byl změněn na: Zastaveno
Record Number: 3872
Source Name: Service Control Manager
Time Written: 20091220111425.000000+060
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 7036
Message: Stav služby Služba modelu COM pro zápis na disk CD (IMAPI) byl změněn na: Spuštěno
Record Number: 3871
Source Name: Service Control Manager
Time Written: 20091220111419.000000+060
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Služba modelu COM pro zápis na disk CD (IMAPI) úspěšně odeslán.
Record Number: 3870
Source Name: Service Control Manager
Time Written: 20091220111419.000000+060
Event Type: Informace
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: PC-8
Event Code: 0
Message:
Record Number: 5802
Source Name: RichVideo
Time Written: 20090526142945.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 1
Message: The service is started.
Record Number: 5801
Source Name: IJPLMSVC
Time Written: 20090526142944.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 0
Message:
Record Number: 5800
Source Name: ICQ Service
Time Written: 20090526142944.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 101
Message: wuauclt (4044) Databázový stroj byl zastaven.
Record Number: 5799
Source Name: ESENT
Time Written: 20090526110205.000000+120
Event Type: Informace
User:
Computer Name: PC-8
Event Code: 103
Message: wuaueng.dll (4044) SUS20ClientDataStore: Databázový stroj zastavil instanci (0).
Record Number: 5798
Source Name: ESENT
Time Written: 20090526110205.000000+120
Event Type: Informace
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 79 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=4f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------
Re: Prosím o kontrolu logu....hlásí vir
Malwarebytes' Anti-Malware 1.44
Verze databáze: 3853
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
11.3.2010 19:02:54
mbam-log-2010-03-11 (19-02-45).txt
Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 133643
Uplynulý čas: 8 minute(s), 57 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 2
Infikované adresáře: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
Verze databáze: 3853
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
11.3.2010 19:02:54
mbam-log-2010-03-11 (19-02-45).txt
Typ kontroly: Rychlá kontrola
Zkontrolované objekty: 133643
Uplynulý čas: 8 minute(s), 57 second(s)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 2
Infikované adresáře: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované moduly v paměti:
(Nebyly nalezeny žádné škodlivé položky)
Infikované klíče registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované hodnoty registru:
(Nebyly nalezeny žádné škodlivé položky)
Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
Infikované adresáře:
(Nebyly nalezeny žádné škodlivé položky)
Infikované soubory:
(Nebyly nalezeny žádné škodlivé položky)
Re: Prosím o kontrolu logu....hlásí vir
Co Mbam našel nech smazat.
Stáhni a ulož na plochu ComboFix,
spusť aplikaci pod účtem s administrátorským oprávněním a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
Stáhni a ulož na plochu ComboFix,
spusť aplikaci pod účtem s administrátorským oprávněním a povol instalaci Konzole pro zotavení - Recovery Console.
Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,
pak ještě jednou klik na ANO a už to jede.
Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.
Při skenovaní může být PC i restartováno nelekat se.
Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,
protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.
Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt
(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.
Re: Prosím o kontrolu logu....hlásí vir
ComboFix 10-03-11.05 - pc 12.03.2010 11:27:06.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.447.207 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-12 do 2010-03-12 )))))))))))))))))))))))))))))))
.
2010-03-11 17:55 . 2010-03-11 17:55 -------- d-sh--w- c:\documents and settings\pc\PrivacIE
2010-03-11 17:51 . 2010-03-11 17:51 -------- d-----w- c:\documents and settings\děti
2010-03-11 17:48 . 2010-03-11 17:48 -------- d-sh--w- c:\documents and settings\pc\IETldCache
2010-03-11 17:42 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-11 17:42 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-11 17:42 . 2010-03-11 17:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-11 17:37 . 2010-03-11 17:37 -------- d-----w- c:\program files\Common Files\Skype
2010-03-11 16:28 . 2010-03-11 16:33 -------- dc-h--w- c:\windows\ie8
2010-03-11 16:15 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-11 16:15 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-11 16:14 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-11 16:13 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-11 16:12 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-11 16:12 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-11 16:12 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-11 16:09 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-11 16:08 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-11 16:05 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-03-11 16:05 . 2010-03-11 16:13 -------- d-----w- c:\program files\trend micro
2010-03-11 16:05 . 2008-10-15 16:38 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-11 16:05 . 2010-03-11 16:06 -------- d-----w- C:\rsit
2010-03-11 16:05 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-03-11 16:05 . 2008-04-11 19:06 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-11 16:04 . 2010-03-11 17:03 -------- d--h--w- c:\windows\$hf_mig$
2010-03-11 16:04 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-11 16:04 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-03-11 15:39 . 2007-06-29 15:32 611584 ----a-w- c:\windows\system32\drivers\PFC027.SYS
2010-03-11 15:39 . 2006-11-20 08:04 6656 ----a-w- c:\windows\system32\CoInst_070629.dll
2010-03-11 15:39 . 2010-03-11 15:39 -------- d-----w- c:\program files\Webcam 1200
2010-03-11 15:39 . 2001-11-05 09:50 69632 ----a-w- c:\windows\AMCap.exe
2010-03-11 15:32 . 2010-03-11 15:32 -------- d-----w- c:\program files\Microsoft Works
2010-03-11 15:31 . 2010-03-11 15:31 -------- d-----w- c:\program files\Microsoft.NET
2010-03-11 15:28 . 2010-03-11 15:32 -------- d-----w- c:\windows\SHELLNEW
2010-03-11 15:09 . 2010-03-11 15:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\MSBuild
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\Reference Assemblies
2010-03-11 15:07 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-11 15:07 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-11 14:22 . 2010-03-11 14:22 -------- d-----w- c:\program files\IObit
2010-03-11 14:12 . 2010-03-11 14:12 -------- d-----w- c:\program files\Zoner
2010-03-11 14:11 . 2010-03-11 14:11 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-03-11 13:57 . 2008-04-14 07:51 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2010-03-11 13:18 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-11 13:18 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-11 13:18 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-11 13:18 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-11 13:18 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-11 13:18 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-11 13:18 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-11 13:17 . 2010-03-09 11:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-11 13:17 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-11 13:17 . 2010-03-11 13:17 -------- d-----w- c:\program files\Alwil Software
2010-03-11 13:09 . 2009-08-06 18:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-03-11 13:04 . 2010-03-11 13:04 -------- d-----w- c:\program files\WinASO
2010-02-11 12:52 . 2003-06-23 00:44 1415680 ----a-w- c:\windows\system32\wmv9vcm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-11 17:53 . 2001-10-25 14:00 79062 ----a-w- c:\windows\system32\perfc005.dat
2010-03-11 17:53 . 2001-10-25 14:00 432004 ----a-w- c:\windows\system32\perfh005.dat
2010-03-11 17:37 . 2007-06-21 17:21 -------- d-----r- c:\program files\Skype
2010-03-11 17:07 . 2006-10-27 11:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-11 15:39 . 2006-10-27 11:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-11 14:53 . 2006-10-27 11:29 -------- d-----w- c:\program files\ACD Systems
2010-03-11 14:07 . 2006-10-27 11:01 96384 ----a-w- c:\windows\system32\drivers\sptd0893.sys
2010-03-11 14:03 . 2005-12-31 23:19 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-11 14:03 . 2005-12-31 23:19 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-11 12:32 . 2008-09-03 11:18 -------- d-----w- c:\program files\CCleaner
2010-02-18 14:18 . 2006-10-27 11:33 -------- d-----w- c:\program files\CyberLink
2010-02-18 14:17 . 2007-05-30 19:18 -------- d-----w- c:\program files\ASUS
2009-12-31 16:50 . 2006-10-20 21:34 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2009-12-22 05:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2005-12-31 23:15 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-29 7626752]
"nwiz"="nwiz.exe" [2006-06-29 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-29 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 32768]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.3.2010 14:18 162640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [8.9.2008 9:58 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.3.2010 14:18 19024]
R3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [11.3.2010 16:39 611584]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.10.2006 12:01 664064]
S2 gupdate;Služba Google Update (gupdate); [x]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 10.2.1.1.:3128
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\pgeafcal.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-12 11:30
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1616)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Celkový čas: 2010-03-12 11:32:16
ComboFix-quarantined-files.txt 2010-03-12 10:32
ComboFix2.txt 2010-03-12 09:46
Před spuštěním: 1 778 311 168
Po spuštění: 1 766 375 424
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - C39CFD7B69EAC91DEDCE87F1B6CF938B
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.447.207 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-12 do 2010-03-12 )))))))))))))))))))))))))))))))
.
2010-03-11 17:55 . 2010-03-11 17:55 -------- d-sh--w- c:\documents and settings\pc\PrivacIE
2010-03-11 17:51 . 2010-03-11 17:51 -------- d-----w- c:\documents and settings\děti
2010-03-11 17:48 . 2010-03-11 17:48 -------- d-sh--w- c:\documents and settings\pc\IETldCache
2010-03-11 17:42 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-11 17:42 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-11 17:42 . 2010-03-11 17:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-11 17:37 . 2010-03-11 17:37 -------- d-----w- c:\program files\Common Files\Skype
2010-03-11 16:28 . 2010-03-11 16:33 -------- dc-h--w- c:\windows\ie8
2010-03-11 16:15 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-11 16:15 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-11 16:14 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-11 16:13 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-11 16:12 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-11 16:12 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-11 16:12 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-11 16:09 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-11 16:08 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-11 16:05 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-03-11 16:05 . 2010-03-11 16:13 -------- d-----w- c:\program files\trend micro
2010-03-11 16:05 . 2008-10-15 16:38 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-11 16:05 . 2010-03-11 16:06 -------- d-----w- C:\rsit
2010-03-11 16:05 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-03-11 16:05 . 2008-04-11 19:06 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-11 16:04 . 2010-03-11 17:03 -------- d--h--w- c:\windows\$hf_mig$
2010-03-11 16:04 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-11 16:04 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-03-11 15:39 . 2007-06-29 15:32 611584 ----a-w- c:\windows\system32\drivers\PFC027.SYS
2010-03-11 15:39 . 2006-11-20 08:04 6656 ----a-w- c:\windows\system32\CoInst_070629.dll
2010-03-11 15:39 . 2010-03-11 15:39 -------- d-----w- c:\program files\Webcam 1200
2010-03-11 15:39 . 2001-11-05 09:50 69632 ----a-w- c:\windows\AMCap.exe
2010-03-11 15:32 . 2010-03-11 15:32 -------- d-----w- c:\program files\Microsoft Works
2010-03-11 15:31 . 2010-03-11 15:31 -------- d-----w- c:\program files\Microsoft.NET
2010-03-11 15:28 . 2010-03-11 15:32 -------- d-----w- c:\windows\SHELLNEW
2010-03-11 15:09 . 2010-03-11 15:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\MSBuild
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\Reference Assemblies
2010-03-11 15:07 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-11 15:07 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-11 14:22 . 2010-03-11 14:22 -------- d-----w- c:\program files\IObit
2010-03-11 14:12 . 2010-03-11 14:12 -------- d-----w- c:\program files\Zoner
2010-03-11 14:11 . 2010-03-11 14:11 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-03-11 13:57 . 2008-04-14 07:51 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2010-03-11 13:18 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-11 13:18 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-11 13:18 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-11 13:18 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-11 13:18 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-11 13:18 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-11 13:18 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-11 13:17 . 2010-03-09 11:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-11 13:17 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-11 13:17 . 2010-03-11 13:17 -------- d-----w- c:\program files\Alwil Software
2010-03-11 13:09 . 2009-08-06 18:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-03-11 13:04 . 2010-03-11 13:04 -------- d-----w- c:\program files\WinASO
2010-02-11 12:52 . 2003-06-23 00:44 1415680 ----a-w- c:\windows\system32\wmv9vcm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-11 17:53 . 2001-10-25 14:00 79062 ----a-w- c:\windows\system32\perfc005.dat
2010-03-11 17:53 . 2001-10-25 14:00 432004 ----a-w- c:\windows\system32\perfh005.dat
2010-03-11 17:37 . 2007-06-21 17:21 -------- d-----r- c:\program files\Skype
2010-03-11 17:07 . 2006-10-27 11:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-11 15:39 . 2006-10-27 11:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-11 14:53 . 2006-10-27 11:29 -------- d-----w- c:\program files\ACD Systems
2010-03-11 14:07 . 2006-10-27 11:01 96384 ----a-w- c:\windows\system32\drivers\sptd0893.sys
2010-03-11 14:03 . 2005-12-31 23:19 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-11 14:03 . 2005-12-31 23:19 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-11 12:32 . 2008-09-03 11:18 -------- d-----w- c:\program files\CCleaner
2010-02-18 14:18 . 2006-10-27 11:33 -------- d-----w- c:\program files\CyberLink
2010-02-18 14:17 . 2007-05-30 19:18 -------- d-----w- c:\program files\ASUS
2009-12-31 16:50 . 2006-10-20 21:34 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2009-12-22 05:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2005-12-31 23:15 343552 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:10 . 2004-08-17 13:49 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-29 7626752]
"nwiz"="nwiz.exe" [2006-06-29 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-29 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 32768]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.3.2010 14:18 162640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [8.9.2008 9:58 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.3.2010 14:18 19024]
R3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [11.3.2010 16:39 611584]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.10.2006 12:01 664064]
S2 gupdate;Služba Google Update (gupdate); [x]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 10.2.1.1.:3128
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\pgeafcal.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&q=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-12 11:30
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(1616)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Celkový čas: 2010-03-12 11:32:16
ComboFix-quarantined-files.txt 2010-03-12 10:32
ComboFix2.txt 2010-03-12 09:46
Před spuštěním: 1 778 311 168
Po spuštění: 1 766 375 424
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - C39CFD7B69EAC91DEDCE87F1B6CF938B
Re: Prosím o kontrolu logu....hlásí vir
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
otevři si Poznámkový blok
do něj zkopíruj skript z následujícího okna:
Kód: Vybrat vše
File::
C:\WINDOWS\002767_.tmp
FireFox::
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\pgeafcal.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... id=afex&q=
po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,
v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci
Re: Prosím o kontrolu logu....hlásí vir
díky za pomoc. Udělám to zítra.Problém je na PC, které je jinde. Abych to dopřesnil, nejzásadnější problém mám s tím, že z počítače jde nějaký spam a poskytovatek blokuje přístup k netu.Zítra vložím log. Díky
Re: Prosím o kontrolu logu....hlásí vir
ComboFix 10-03-11.05 - pc 16.03.2010 12:15:26.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.447.214 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
Použité ovládací přepínače :: E:\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\002767_.tmp"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\002767_.tmp
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-16 do 2010-03-16 )))))))))))))))))))))))))))))))
.
2010-03-12 10:56 . 2010-03-12 10:56 -------- d-----w- c:\windows\system32\LogFiles
2010-03-12 10:56 . 2010-03-12 10:56 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-03-12 10:56 . 2010-03-12 12:30 -------- d-----w- c:\program files\Comodo
2010-03-11 17:55 . 2010-03-11 17:55 -------- d-sh--w- c:\documents and settings\pc\PrivacIE
2010-03-11 17:51 . 2010-03-11 17:51 -------- d-----w- c:\documents and settings\děti
2010-03-11 17:48 . 2010-03-11 17:48 -------- d-sh--w- c:\documents and settings\pc\IETldCache
2010-03-11 17:42 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-11 17:42 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-11 17:42 . 2010-03-11 17:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-11 17:37 . 2010-03-11 17:37 -------- d-----w- c:\program files\Common Files\Skype
2010-03-11 16:28 . 2010-03-11 16:33 -------- dc-h--w- c:\windows\ie8
2010-03-11 16:15 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-11 16:15 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-11 16:14 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-11 16:13 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-11 16:12 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-11 16:12 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-11 16:12 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-11 16:09 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-11 16:08 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-11 16:05 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-03-11 16:05 . 2010-03-11 16:13 -------- d-----w- c:\program files\trend micro
2010-03-11 16:05 . 2008-10-15 16:38 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-11 16:05 . 2010-03-11 16:06 -------- d-----w- C:\rsit
2010-03-11 16:05 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-03-11 16:05 . 2008-04-11 19:06 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-11 16:04 . 2010-03-11 17:03 -------- d--h--w- c:\windows\$hf_mig$
2010-03-11 16:04 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-11 16:04 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-03-11 15:39 . 2007-06-29 15:32 611584 ----a-w- c:\windows\system32\drivers\PFC027.SYS
2010-03-11 15:39 . 2006-11-20 08:04 6656 ----a-w- c:\windows\system32\CoInst_070629.dll
2010-03-11 15:39 . 2010-03-11 15:39 -------- d-----w- c:\program files\Webcam 1200
2010-03-11 15:39 . 2001-11-05 09:50 69632 ----a-w- c:\windows\AMCap.exe
2010-03-11 15:32 . 2010-03-11 15:32 -------- d-----w- c:\program files\Microsoft Works
2010-03-11 15:31 . 2010-03-11 15:31 -------- d-----w- c:\program files\Microsoft.NET
2010-03-11 15:28 . 2010-03-11 15:32 -------- d-----w- c:\windows\SHELLNEW
2010-03-11 15:09 . 2010-03-11 15:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\MSBuild
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\Reference Assemblies
2010-03-11 15:07 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-11 15:07 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-11 14:22 . 2010-03-11 14:22 -------- d-----w- c:\program files\IObit
2010-03-11 14:12 . 2010-03-11 14:12 -------- d-----w- c:\program files\Zoner
2010-03-11 14:11 . 2010-03-11 14:11 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-03-11 13:57 . 2008-04-14 07:51 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2010-03-11 13:18 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-11 13:18 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-11 13:18 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-11 13:18 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-11 13:18 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-11 13:18 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-11 13:18 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-11 13:17 . 2010-03-09 11:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-11 13:17 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-11 13:17 . 2010-03-11 13:17 -------- d-----w- c:\program files\Alwil Software
2010-03-11 13:09 . 2009-08-06 18:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-03-11 13:04 . 2010-03-11 13:04 -------- d-----w- c:\program files\WinASO
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-12 12:26 . 2006-10-27 11:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-11 17:53 . 2001-10-25 14:00 79062 ----a-w- c:\windows\system32\perfc005.dat
2010-03-11 17:53 . 2001-10-25 14:00 432004 ----a-w- c:\windows\system32\perfh005.dat
2010-03-11 17:37 . 2007-06-21 17:21 -------- d-----r- c:\program files\Skype
2010-03-11 15:39 . 2006-10-27 11:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-11 14:53 . 2006-10-27 11:29 -------- d-----w- c:\program files\ACD Systems
2010-03-11 14:07 . 2006-10-27 11:01 96384 ----a-w- c:\windows\system32\drivers\sptd0893.sys
2010-03-11 14:03 . 2005-12-31 23:19 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-11 14:03 . 2005-12-31 23:19 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-11 12:32 . 2008-09-03 11:18 -------- d-----w- c:\program files\CCleaner
2010-02-18 14:18 . 2006-10-27 11:33 -------- d-----w- c:\program files\CyberLink
2010-02-18 14:17 . 2007-05-30 19:18 -------- d-----w- c:\program files\ASUS
2009-12-31 16:50 . 2006-10-20 21:34 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2009-12-22 05:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2005-12-31 23:15 343552 ----a-w- c:\windows\system32\mspaint.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-03-12_09.44.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-12 09:44 . 2010-03-12 12:20 262144 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat
- 2010-03-12 09:44 . 2010-03-12 09:44 262144 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-29 7626752]
"nwiz"="nwiz.exe" [2006-06-29 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-29 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 32768]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.3.2010 14:18 162640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [8.9.2008 9:58 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.3.2010 14:18 19024]
R3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [11.3.2010 16:39 611584]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.10.2006 12:01 664064]
S2 gupdate;Služba Google Update (gupdate); [x]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 10.2.1.1.:3128
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\pgeafcal.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-16 12:19
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2010-03-16 12:21:10
ComboFix-quarantined-files.txt 2010-03-16 11:21
ComboFix2.txt 2010-03-12 10:32
ComboFix3.txt 2010-03-12 09:46
Před spuštěním: 1 666 494 464
Po spuštění: 1 659 113 472
- - End Of File - - 8817ED66090EE8E7A510EF3B9153C9DF
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.447.214 [GMT 1:00]
Spuštěný z: c:\documents and settings\pc\Plocha\ComboFix.exe
Použité ovládací přepínače :: E:\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\002767_.tmp"
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\002767_.tmp
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-16 do 2010-03-16 )))))))))))))))))))))))))))))))
.
2010-03-12 10:56 . 2010-03-12 10:56 -------- d-----w- c:\windows\system32\LogFiles
2010-03-12 10:56 . 2010-03-12 10:56 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-03-12 10:56 . 2010-03-12 12:30 -------- d-----w- c:\program files\Comodo
2010-03-11 17:55 . 2010-03-11 17:55 -------- d-sh--w- c:\documents and settings\pc\PrivacIE
2010-03-11 17:51 . 2010-03-11 17:51 -------- d-----w- c:\documents and settings\děti
2010-03-11 17:48 . 2010-03-11 17:48 -------- d-sh--w- c:\documents and settings\pc\IETldCache
2010-03-11 17:42 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-11 17:42 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-11 17:42 . 2010-03-11 17:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-11 17:37 . 2010-03-11 17:37 -------- d-----w- c:\program files\Common Files\Skype
2010-03-11 16:28 . 2010-03-11 16:33 -------- dc-h--w- c:\windows\ie8
2010-03-11 16:15 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-11 16:15 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-03-11 16:14 . 2009-12-31 16:50 353792 -c----w- c:\windows\system32\dllcache\srv.sys
2010-03-11 16:13 . 2009-12-04 18:22 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-11 16:12 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-03-11 16:12 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-03-11 16:12 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-03-11 16:09 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-03-11 16:08 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-03-11 16:05 . 2009-07-31 04:35 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2010-03-11 16:05 . 2010-03-11 16:13 -------- d-----w- c:\program files\trend micro
2010-03-11 16:05 . 2008-10-15 16:38 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-03-11 16:05 . 2010-03-11 16:06 -------- d-----w- C:\rsit
2010-03-11 16:05 . 2008-05-01 14:37 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-03-11 16:05 . 2008-04-11 19:06 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-03-11 16:04 . 2010-03-11 17:03 -------- d--h--w- c:\windows\$hf_mig$
2010-03-11 16:04 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-03-11 16:04 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2010-03-11 15:43 . 2008-04-13 23:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 -c--a-w- c:\windows\system32\dllcache\ndisip.sys
2010-03-11 15:43 . 2008-04-13 23:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2010-03-11 15:39 . 2007-06-29 15:32 611584 ----a-w- c:\windows\system32\drivers\PFC027.SYS
2010-03-11 15:39 . 2006-11-20 08:04 6656 ----a-w- c:\windows\system32\CoInst_070629.dll
2010-03-11 15:39 . 2010-03-11 15:39 -------- d-----w- c:\program files\Webcam 1200
2010-03-11 15:39 . 2001-11-05 09:50 69632 ----a-w- c:\windows\AMCap.exe
2010-03-11 15:32 . 2010-03-11 15:32 -------- d-----w- c:\program files\Microsoft Works
2010-03-11 15:31 . 2010-03-11 15:31 -------- d-----w- c:\program files\Microsoft.NET
2010-03-11 15:28 . 2010-03-11 15:32 -------- d-----w- c:\windows\SHELLNEW
2010-03-11 15:09 . 2010-03-11 15:09 -------- d-----w- c:\windows\system32\XPSViewer
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\MSBuild
2010-03-11 15:08 . 2010-03-11 15:08 -------- d-----w- c:\program files\Reference Assemblies
2010-03-11 15:07 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-11 15:07 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-03-11 15:07 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-11 15:07 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-03-11 14:22 . 2010-03-11 14:22 -------- d-----w- c:\program files\IObit
2010-03-11 14:12 . 2010-03-11 14:12 -------- d-----w- c:\program files\Zoner
2010-03-11 14:11 . 2010-03-11 14:11 114048 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-03-11 13:57 . 2008-04-14 07:51 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2010-03-11 13:18 . 2010-03-09 11:12 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-11 13:18 . 2010-03-09 11:08 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-11 13:18 . 2010-03-09 11:09 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-11 13:18 . 2010-03-09 11:12 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-11 13:18 . 2010-03-09 11:08 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-11 13:18 . 2010-03-09 11:08 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-11 13:18 . 2010-03-09 11:08 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-11 13:17 . 2010-03-09 11:24 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-11 13:17 . 2010-03-09 11:24 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-11 13:17 . 2010-03-11 13:17 -------- d-----w- c:\program files\Alwil Software
2010-03-11 13:09 . 2009-08-06 18:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-03-11 13:04 . 2010-03-11 13:04 -------- d-----w- c:\program files\WinASO
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-12 12:26 . 2006-10-27 11:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-11 17:53 . 2001-10-25 14:00 79062 ----a-w- c:\windows\system32\perfc005.dat
2010-03-11 17:53 . 2001-10-25 14:00 432004 ----a-w- c:\windows\system32\perfh005.dat
2010-03-11 17:37 . 2007-06-21 17:21 -------- d-----r- c:\program files\Skype
2010-03-11 15:39 . 2006-10-27 11:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-11 14:53 . 2006-10-27 11:29 -------- d-----w- c:\program files\ACD Systems
2010-03-11 14:07 . 2006-10-27 11:01 96384 ----a-w- c:\windows\system32\drivers\sptd0893.sys
2010-03-11 14:03 . 2005-12-31 23:19 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-11 14:03 . 2005-12-31 23:19 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-11 12:32 . 2008-09-03 11:18 -------- d-----w- c:\program files\CCleaner
2010-02-18 14:18 . 2006-10-27 11:33 -------- d-----w- c:\program files\CyberLink
2010-02-18 14:17 . 2007-05-30 19:18 -------- d-----w- c:\program files\ASUS
2009-12-31 16:50 . 2006-10-20 21:34 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2009-12-22 05:09 81920 ------w- c:\windows\system32\ieencode.dll
2009-12-17 07:42 . 2005-12-31 23:15 343552 ----a-w- c:\windows\system32\mspaint.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-03-12_09.44.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-12 09:44 . 2010-03-12 12:20 262144 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat
- 2010-03-12 09:44 . 2010-03-12 09:44 262144 c:\windows\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Windows\UsrClass.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-29 7626752]
"nwiz"="nwiz.exe" [2006-06-29 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-06-29 86016]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 32768]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 13:46 63352]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11.3.2010 14:18 162640]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [8.9.2008 9:58 141312]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11.3.2010 14:18 19024]
R3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [11.3.2010 16:39 611584]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27.10.2006 12:01 664064]
S2 gupdate;Služba Google Update (gupdate); [x]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uDefault_Search_URL = hxxp://search.qip.ru
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = 10.2.1.1.:3128
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\pc\Data aplikací\Mozilla\Firefox\Profiles\pgeafcal.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-16 12:19
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2010-03-16 12:21:10
ComboFix-quarantined-files.txt 2010-03-16 11:21
ComboFix2.txt 2010-03-12 10:32
ComboFix3.txt 2010-03-12 09:46
Před spuštěním: 1 666 494 464
Po spuštění: 1 659 113 472
- - End Of File - - 8817ED66090EE8E7A510EF3B9153C9DF
Re: Prosím o kontrolu logu....hlásí vir
Přes Start >> Spustit zkopíruj do okna:
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Pak dej vědět jaký je stav PC.
ComboFix /Uninstall
a stiskni Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.
Pak dej vědět jaký je stav PC.
Re: Prosím o kontrolu logu....hlásí vir
Combofix jsem ještě neodinstaloval, ale vypadá to, že je vše v pořádku.
Odinstaluju ho a dám vědět.
Díky za pomoc
Odinstaluju ho a dám vědět.
Díky za pomoc