Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

cidrive32.exe -log HJT

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

cidrive32.exe -log HJT

#1 Příspěvek od xaron »

Zdravím :oops:
Mam problém s cidrive32.exe neviem čo to je našiel som to v správcovi úloh/procesy
cidrive32.exe spôsobuje to že keď zapnem prehliadač(firefox) tak vôbec nenačítava stránky, úplne ignoruje to keď klikám na odkazy a podobne aby som mohol normálne surfovať po web stránkach musím cidrive32.exe ukončiť v procesoch ale za par minút sa to zas pusti...

Chcel by som Vás poprosiť o pomoc ako sa toho zbaviť

tu je log s HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:55, on 2. 4. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Search Guard PlusU\sgpUpdaters.exe
D:\WINDOWS\cidrive32.exe
D:\Program Files\Search Guard Plus\SearchGuardPlus.exe
D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\PROGRA~1\MANGOS~1\EasyPHP\MySql\bin\mysqld.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Mozilla Firefox\firefox.exe
G:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zaparit.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe,skp66.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - D:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - D:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - D:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [OrderReminder] D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] "D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
O4 - HKLM\..\Run: [Windows Network Data Management System Service] "skp66.exe" *
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SGPUpdater] D:\Program Files\Search Guard PlusU\sgpUpdaters.exe
O4 - HKLM\..\Run: [FBSearch] D:\Program Files\Search Guard Plus\SearchGuardPlus.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UVS10 Preload] D:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [avast5] D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CurseClient] D:\Program Files\Curse\CurseClient.exe
O4 - HKCU\..\Run: [Windows Network Data Management System Service] "skp66.exe" *
O4 - HKCU\..\Run: [13CFG914-K641-26SF-N31P] C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0950\vsse33.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [psysnew] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] D:\WINDOWS\cidrive32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ATI CATALYST System Tray.lnk = D:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = D:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: MyVitalAgent.lnk = D:\Program Files\INS\VitalAgent\Program\VtlAgent.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apache2 - Apache Software Foundation - D:\PROGRA~1\MANGOS~1\EasyPHP\Apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Windows Network Data Management System Service (BNDMSS) - Unknown owner - C:\WINDOWS\system32\bndmss.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9afd1e0e7928) (gupdate1c9afd1e0e7928) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MySQL - Unknown owner - D:\PROGRA~1\MANGOS~1\EasyPHP\MySql\bin\mysqld.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Ventrilo - Unknown owner - D:\Program Files\VentSrv\ventrilo_svc.exe (file missing)

--
End of file - 8743 bytes
Naposledy upravil(a) xaron dne 02 dub 2010 15:57, celkem upraveno 2 x.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#2 Příspěvek od Caroprd111 »

Zdravím :)

Přečtěte si pravidla fóra a dejte log z RSIT.
Obrázek

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#3 Příspěvek od xaron »

Pravidla prečítane a tu je log

Logfile of random's system information tool 1.06 (written by random/random)
Run by Macko at 2010-04-02 13:07:15
Systém Microsoft Windows XP Professional Service Pack 2
System drive D: has 9 GB (7%) free of 131 GB
Total RAM: 1023 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:07:28, on 2. 4. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Search Guard PlusU\sgpUpdaters.exe
D:\WINDOWS\cidrive32.exe
D:\Program Files\Search Guard Plus\SearchGuardPlus.exe
D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\PROGRA~1\MANGOS~1\EasyPHP\MySql\bin\mysqld.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\WINDOWS\system32\wuauclt.exe
G:\RSIT\RSIT.exe
G:\HJT\Macko.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zaparit.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=D:\WINDOWS\system32\userinit.exe,skp66.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Search Assistant - {F0626A63-410B-45E2-99A1-3F2475B2D695} - D:\Program Files\SGPSA\BHO.dll
O2 - BHO: XBTBPos00 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - D:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O3 - Toolbar: Fast Browser Search Toolbar - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - D:\Program Files\Fast Browser Search\IE\FBStoolbar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [ATICCC] "D:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [OrderReminder] D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [pdfFactory Dispatcher v3] "D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" /source=HKLM
O4 - HKLM\..\Run: [Windows Network Data Management System Service] "skp66.exe" *
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SGPUpdater] D:\Program Files\Search Guard PlusU\sgpUpdaters.exe
O4 - HKLM\..\Run: [FBSearch] D:\Program Files\Search Guard Plus\SearchGuardPlus.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UVS10 Preload] D:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [avast5] D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CurseClient] D:\Program Files\Curse\CurseClient.exe
O4 - HKCU\..\Run: [Windows Network Data Management System Service] "skp66.exe" *
O4 - HKCU\..\Run: [13CFG914-K641-26SF-N31P] C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0950\vsse33.exe
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [psysnew] C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] D:\WINDOWS\cidrive32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: ATI CATALYST System Tray.lnk = D:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = D:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: MyVitalAgent.lnk = D:\Program Files\INS\VitalAgent\Program\VtlAgent.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apache2 - Apache Software Foundation - D:\PROGRA~1\MANGOS~1\EasyPHP\Apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Windows Network Data Management System Service (BNDMSS) - Unknown owner - C:\WINDOWS\system32\bndmss.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9afd1e0e7928) (gupdate1c9afd1e0e7928) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MySQL - Unknown owner - D:\PROGRA~1\MANGOS~1\EasyPHP\MySql\bin\mysqld.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Ventrilo - Unknown owner - D:\Program Files\VentSrv\ventrilo_svc.exe (file missing)

--
End of file - 8750 bytes

======Scheduled tasks folder======

D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-05-15 50376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - D:\Program Files\Java\jre6\bin\ssv.dll [2009-04-19 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - D:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-04-19 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-04-19 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0626A63-410B-45E2-99A1-3F2475B2D695}]
Search Assistant - D:\Program Files\SGPSA\BHO.dll [2009-11-06 293376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}]
Fast Browser Search Toolbar Helper - D:\Program Files\Fast Browser Search\IE\FBStoolbar.dll [2009-08-13 2602368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1BB22D38-A411-4B13-A746-C2A4F4EC7344} - Fast Browser Search Toolbar - D:\Program Files\Fast Browser Search\IE\FBStoolbar.dll [2009-08-13 2602368]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=D:\WINDOWS\SOUNDMAN.EXE [2005-04-15 77824]
"ATIPTA"=D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2005-06-28 344064]
"ATICCC"=D:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-06-29 32768]
"HP Software Update"=D:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-11 49152]
"OrderReminder"=D:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe [2005-03-18 98304]
"SunJavaUpdateSched"=D:\Program Files\Java\jre6\bin\jusched.exe [2009-04-19 136600]
"pdfFactory Dispatcher v3"=D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe [2008-03-05 516096]
"Windows Network Data Management System Service"=skp66.exe * []
"NeroFilterCheck"=D:\WINDOWS\system32\NeroCheck.exe [2006-01-12 155648]
"SGPUpdater"=D:\Program Files\Search Guard PlusU\sgpUpdaters.exe [2009-05-15 67456]
"FBSearch"=D:\Program Files\Search Guard Plus\SearchGuardPlus.exe [2009-05-04 194432]
"QuickTime Task"=D:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"KernelFaultCheck"=D:\WINDOWS\system32\dumprep 0 -k []
"UVS10 Preload"=D:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe [2006-03-07 36864]
"AdobeCS4ServiceManager"=D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"LogMeIn Hamachi Ui"=D:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"avast5"=D:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-03-09 2769336]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Microsoft Driver Setup"=D:\WINDOWS\cidrive32.exe [2010-04-02 155648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=D:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"MSMSGS"=D:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"CurseClient"=D:\Program Files\Curse\CurseClient.exe [2008-05-19 1400832]
"Windows Network Data Management System Service"=skp66.exe * []
"13CFG914-K641-26SF-N31P"=C:\RECYCLER\S-1-5-21-0243336031-4052116379-881863308-0950\vsse33.exe []
"Skype"=D:\Program Files\Skype\Phone\Skype.exe [2009-06-02 24264488]
"psysnew"=C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\psysnew.exe [2010-04-02 118784]
"SUPERAntiSpyware"=D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-04-01 2010864]

D:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
ATI CATALYST System Tray.lnk - D:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
AutoCAD Startup Accelerator.lnk - D:\Program Files\Common Files\Autodesk Shared\acstart16.exe
HP Image Zone Fast Start.lnk - D:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
MyVitalAgent.lnk - D:\Program Files\INS\VitalAgent\Program\VtlAgent.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
D:\WINDOWS\system32\Ati2evxx.dll [2005-06-29 46080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoRun"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\Program Files\MaNGOS 5770\realmd.exe"="D:\Program Files\MaNGOS 5770\realmd.exe:*:Enabled:realmd"
"D:\Program Files\MaNGOS 5770\mangosd.exe"="D:\Program Files\MaNGOS 5770\mangosd.exe:*:Enabled:mangosd"
"D:\Program Files\Mozilla Firefox\firefox.exe"="D:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"D:\Program Files\MaNGOS 5770\EasyPHP\mysql\bin\mysqld.exe"="D:\Program Files\MaNGOS 5770\EasyPHP\mysql\bin\mysqld.exe:*:Enabled:mysqld"
"D:\Program Files\MaNGOS 5770\EasyPHP\apache\bin\Apache.exe"="D:\Program Files\MaNGOS 5770\EasyPHP\apache\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"D:\Program Files\Counter-Strike\hl.exe"="D:\Program Files\Counter-Strike\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Program Files\Counter-Strike\hltv.exe"="D:\Program Files\Counter-Strike\hltv.exe:*:Enabled:HLTV Launcher"
"G:\Program Files\Counter-Strike\hl.exe"="G:\Program Files\Counter-Strike\hl.exe:*:Enabled:Half-Life Launcher"
"D:\Documents and Settings\Macko\Plocha\utorrent.exe"="D:\Documents and Settings\Macko\Plocha\utorrent.exe:*:Enabled:µTorrent"
"D:\MaNGOS 5770\realmd.exe"="D:\MaNGOS 5770\realmd.exe:*:Enabled:realmd"
"D:\Documents and Settings\Macko\Plocha\MaNGOS_Rev._6354_SD2_Rev._507\MaNGOS Rev. 6354 SD2 Rev. 507\realmd.exe"="D:\Documents and Settings\Macko\Plocha\MaNGOS_Rev._6354_SD2_Rev._507\MaNGOS Rev. 6354 SD2 Rev. 507\realmd.exe:*:Enabled:realmd"
"D:\Documents and Settings\Macko\Plocha\utorrent(2).exe"="D:\Documents and Settings\Macko\Plocha\utorrent(2).exe:*:Enabled:µTorrent"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"D:\Documents and Settings\Macko\skp66.exe"="D:\Documents and Settings\Macko\skp66.exeskp66.exe:*:Enabled:BNDMSS"
"skp66.exe"="skp66.exe:*:Enabled:BNDMSS"
"C:\WINDOWS\system32\bndmss.exe"="C:\WINDOWS\system32\bndmss.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\024.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\024.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\070.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\070.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\257.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\257.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\337.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\337.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\668.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\668.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\461.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\461.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\476.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\476.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\730.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\730.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\649.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\649.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\888.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\888.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\563.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\563.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\453.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\453.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\588.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\588.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\635.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\635.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\614.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\614.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\216.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\216.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\426.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\426.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\099.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\099.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\851.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\851.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\694.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\694.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\374.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\374.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\931.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\931.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\095.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\095.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\448.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\448.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\805.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\805.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\913.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\913.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\889.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\889.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\486.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\486.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\859.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\859.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\135.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\135.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\361.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\361.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\389.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\389.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\256.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\256.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\526.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\526.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\129.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\129.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\108.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\108.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\749.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\749.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\123.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\123.exe:*:D:\WINDOWS\cidrive32.exe"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\184.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\184.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\864.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\864.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\082.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\082.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\344.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\344.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\372.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\372.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\887.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\887.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\742.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\742.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\510.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\510.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\901.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\901.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\342.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\342.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\412.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\412.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\142.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\142.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\956.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\956.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\413.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\413.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\284.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\284.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\784.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\784.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\132.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\132.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\235.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\235.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\092.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\092.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\236.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\236.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\474.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\474.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\540.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\540.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\697.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\697.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\030.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\030.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\000.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\000.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\251.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\251.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\857.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\857.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\494.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\494.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\753.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\753.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\929.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\929.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\537.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\537.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\519.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\519.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\077.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\077.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\022.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\022.exe:*:D:\WINDOWS\cidrive32.exe"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\739.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\739.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\608.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\608.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\421.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\421.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\274.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\274.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\515.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\515.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\275.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\275.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\958.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\958.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\802.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\802.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\803.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\803.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\467.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\467.exe:*:Enabled:BNDMSS"
"D:\DOCUME~1\Macko\LOCALS~1\Temp\202.exe"="D:\DOCUME~1\Macko\LOCALS~1\Temp\202.exe:*:Enabled:BNDMSS"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0eea2d2e-c90d-11dd-8826-0013d360f2a3}]
shell\AutoRun\command - I:\RECYCLER32\dmgr.exe
shell\open\command - I:\RECYCLER32\dmgr.exe


======File associations======

.scr - open - "D:\WINDOWS\system32\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-04-02 13:07:15 ----D---- D:\rsit
2010-04-02 12:11:12 ----A---- D:\WINDOWS\system32\aswBoot.exe
2010-04-02 12:11:06 ----D---- D:\Program Files\Alwil Software
2010-04-02 12:11:06 ----D---- D:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-04-02 11:45:58 ----D---- D:\Documents and Settings\All Users\Data aplikací\PrevxCSI
2010-04-02 11:45:58 ----A---- D:\WINDOWS\wininit.ini
2010-04-02 10:16:52 ----D---- D:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-04-02 10:16:46 ----D---- D:\Program Files\SUPERAntiSpyware
2010-04-02 10:16:46 ----D---- D:\Documents and Settings\Macko\Data aplikací\SUPERAntiSpyware.com
2010-04-01 10:44:23 ----RSH---- D:\WINDOWS\cidrive32.exe
2010-03-30 13:57:25 ----D---- D:\Program Files\LogMeIn Hamachi
2010-03-22 17:47:11 ----D---- D:\Documents and Settings\All Users\Data aplikací\MSScanAppDataDir
2010-03-20 14:17:24 ----D---- D:\Documents and Settings\All Users\Data aplikací\FLEXnet
2010-03-20 14:02:30 ----D---- D:\Program Files\Adobe Media Player
2010-03-20 14:00:31 ----D---- D:\Program Files\Common Files\Adobe AIR
2010-03-20 13:56:32 ----D---- D:\Program Files\Common Files\Macrovision Shared
2010-03-16 19:26:12 ----D---- D:\server c
2010-03-04 17:43:39 ----D---- D:\Half-Life
2010-03-03 00:46:10 ----D---- D:\Program Files\Vypinac

======List of files/folders modified in the last 1 months======

2010-04-02 13:07:22 ----D---- D:\WINDOWS\Prefetch
2010-04-02 13:06:49 ----D---- D:\WINDOWS\system32\CatRoot2
2010-04-02 13:06:48 ----D---- D:\WINDOWS\Temp
2010-04-02 13:06:39 ----D---- D:\WINDOWS
2010-04-02 13:06:00 ----D---- D:\Documents and Settings\Macko\Data aplikací\Skype
2010-04-02 13:04:14 ----A---- D:\WINDOWS\SchedLgU.Txt
2010-04-02 12:47:16 ----A---- D:\WINDOWS\NeroDigital.ini
2010-04-02 12:34:17 ----D---- D:\Program Files\Mozilla Firefox
2010-04-02 12:31:53 ----D---- D:\WINDOWS\system32
2010-04-02 12:13:25 ----D---- D:\Program Files\Google
2010-04-02 12:11:24 ----D---- D:\WINDOWS\system32\drivers
2010-04-02 12:11:20 ----SHD---- D:\WINDOWS\Installer
2010-04-02 12:11:20 ----HD---- D:\Config.Msi
2010-04-02 12:11:19 ----D---- D:\WINDOWS\WinSxS
2010-04-02 12:11:06 ----RD---- D:\Program Files
2010-04-02 11:31:20 ----D---- D:\Documents and Settings\Macko\Data aplikací\skypePM
2010-04-02 11:29:28 ----D---- D:\Program Files\DAEMON Tools
2010-04-02 10:16:28 ----D---- D:\Program Files\Common Files\Wise Installation Wizard
2010-04-01 00:12:00 ----D---- D:\Program Files\Wowcko
2010-03-31 19:50:11 ----D---- D:\WOW 243
2010-03-29 15:31:18 ----A---- D:\WINDOWS\system32\PerfStringBackup.INI
2010-03-28 13:05:23 ----D---- D:\Program Files\Optimik
2010-03-27 13:55:09 ----D---- D:\Documents and Settings\Macko\Data aplikací\SQLyog
2010-03-27 13:45:34 ----D---- D:\wow old
2010-03-25 11:50:19 ----SHD---- D:\RECYCLER
2010-03-20 15:49:01 ----D---- D:\Documents and Settings\Macko\Data aplikací\Adobe
2010-03-20 14:45:34 ----D---- D:\Documents and Settings\All Users\Data aplikací\Adobe
2010-03-20 14:04:46 ----D---- D:\Program Files\Adobe
2010-03-20 14:03:28 ----D---- D:\Program Files\Common Files\Adobe
2010-03-20 14:01:58 ----RSD---- D:\WINDOWS\Fonts
2010-03-20 14:00:31 ----D---- D:\Program Files\Common Files
2010-03-18 19:53:53 ----SD---- D:\Documents and Settings\Macko\Data aplikací\Microsoft
2010-03-17 18:17:16 ----D---- D:\Documents and Settings\Macko\Data aplikací\Mp3 Audio Editor
2010-03-16 18:03:04 ----D---- D:\DATA
2010-03-10 22:36:09 ----A---- D:\WINDOWS\LuminancesDlg.ini
2010-03-08 18:24:58 ----D---- D:\Documents and Settings\Macko\Data aplikací\AdobeUM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; D:\WINDOWS\system32\drivers\Aavmker4.sys [2010-03-09 28880]
R1 AmdK8;AMD Processor Driver; D:\WINDOWS\System32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 aswSP;aswSP; D:\WINDOWS\system32\drivers\aswSP.sys [2010-03-09 162640]
R1 aswTdi;avast! Network Shield Support; D:\WINDOWS\system32\drivers\aswTdi.sys [2010-03-09 46672]
R1 SASDIFSV;SASDIFSV; \??\D:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\D:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R2 0VsNdis08;VitalAgent Network Driver 8.1; \??\D:\Program Files\INS\VitalAgent\Program\VsNdis08.sys []
R2 adfs;adfs; D:\WINDOWS\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; D:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-03-09 19024]
R2 aswMon2;avast! Standard Shield Support; D:\WINDOWS\system32\drivers\aswMon2.sys [2010-03-09 100432]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service; D:\WINDOWS\System32\Drivers\ousbehci.sys [2004-06-15 44928]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); D:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-19 2317504]
R3 aswRdr;aswRdr; D:\WINDOWS\system32\drivers\aswRdr.sys [2010-03-09 23376]
R3 ati2mtag;ati2mtag; D:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-06-29 1241088]
R3 atinrvxx;ATI WDM Rage Theater Video; D:\WINDOWS\System32\DRIVERS\atinrvxx.sys [2004-08-04 105984]
R3 dtscsi;dtscsi; D:\WINDOWS\System32\Drivers\dtscsi.sys [2008-06-07 223128]
R3 hamachi;Hamachi Network Interface; D:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 MVDCODEC;ATI WDM Specialized MVD Codec; D:\WINDOWS\System32\DRIVERS\atinmdxx.sys [2004-08-04 13824]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support; D:\WINDOWS\System32\DRIVERS\ousb2hub.sys [2004-06-15 55808]
R3 RTL8023xp;Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver; D:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [2004-04-13 70144]
R3 SASENUM;SASENUM; \??\D:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 teamviewervpn;TeamViewer VPN Adapter; D:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2009-11-09 25088]
R3 usbhub;Rozbočovač umožnující USB2; D:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; D:\WINDOWS\System32\DRIVERS\usbohci.sys [2004-08-03 17024]
S1 kbdhid;Ovladač klávesnice standardu HID; D:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
S3 0VsComm12;VitalAgent Serial Port Driver 12.4; \??\D:\Program Files\INS\VitalAgent\Program\VsComm12.sys []
S3 CCDECODE;Closed Caption Decoder; D:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HidUsb;Ovladač třídy standardu HID; D:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 mouhid;Ovladač myši standardu HID; D:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; D:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; D:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; D:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; D:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 se45bus;Sony Ericsson Device 069 driver (WDM); D:\WINDOWS\system32\DRIVERS\se45bus.sys [2006-11-30 61536]
S3 SLIP;BDA Slip De-Framer; D:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; D:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; D:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; D:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; D:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;World Standard Teletext Codec; D:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; D:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; D:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; D:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; D:\WINDOWS\System32\Ati2evxx.exe [2005-06-29 376832]
R2 avast! Antivirus;avast! Antivirus; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; D:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 JavaQuickStarterService;Java Quick Starter; D:\Program Files\Java\jre6\bin\jqs.exe [2009-04-19 152984]
R2 MDM;Machine Debug Manager; D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 MySQL;MySQL; D:\PROGRA~1\MANGOS~1\EasyPHP\MySql\bin\mysqld.exe [2006-10-22 4493312]
R2 PnkBstrA;PnkBstrA; D:\WINDOWS\system32\PnkBstrA.exe [2009-07-22 75064]
R2 UleadBurningHelper;Ulead Burning Helper; D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2005-01-31 49152]
R3 avast! Mail Scanner;avast! Mail Scanner; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
R3 avast! Web Scanner;avast! Web Scanner; D:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-03-09 40384]
S2 Apache2;Apache2; D:\PROGRA~1\MANGOS~1\EasyPHP\Apache\bin\apache.exe [2006-07-27 20539]
S2 ATI Smart;ATI Smart; D:\WINDOWS\system32\ati2sgag.exe [2005-06-28 516096]
S2 BNDMSS;Windows Network Data Management System Service; C:\WINDOWS\system32\bndmss.exe []
S2 gupdate1c9afd1e0e7928;Google Update Service (gupdate1c9afd1e0e7928); D:\Program Files\Google\Update\GoogleUpdate.exe [2009-03-28 133104]
S2 Ventrilo;Ventrilo; D:\Program Files\VentSrv\ventrilo_svc.exe []
S3 aspnet_state;ASP.NET State Service; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 Autodesk Licensing Service;Autodesk Licensing Service; D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2008-09-05 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-20 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; d:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 IDriverT;InstallDriver Table Manager; D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 ose;Office Source Engine; D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; D:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#4 Příspěvek od Caroprd111 »

Obrázek Doporučuji odinstalovat:
D:\Program Files\uTorrent\uTorrent.exe

P2P sítě a jejich klienti jsou potenciálním bezpečnostním rizikem, prakticky neustále jsou zdrojem virů, zbytečně se vystavujete riziku.



Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary
  • Vložte do PC všechny flash disky, které používáte.
  • Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrazí stránka s licenčními podmínkami, pokračujte stisknutím tlačítka "Ano"
  • Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:
  • Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.
  • Během skenování může být počítač restartován.
Obrázek

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#5 Příspěvek od xaron »

ComboFix 10-04-01.02 - Macko . 04. 2010 14:00:56.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1029.18.1023.679 [GMT 2:00]
Running from: d:\documents and settings\Macko\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\program files\Fast Browser Search
d:\program files\Fast Browser Search\IE\1.bat
d:\program files\Fast Browser Search\IE\about.html
d:\program files\Fast Browser Search\IE\affid.dat
d:\program files\Fast Browser Search\IE\basis.xml
d:\program files\Fast Browser Search\IE\basis_br.xml
d:\program files\Fast Browser Search\IE\basis_de.xml
d:\program files\Fast Browser Search\IE\basis_en.xml
d:\program files\Fast Browser Search\IE\basis_es.xml
d:\program files\Fast Browser Search\IE\basis_fr.xml
d:\program files\Fast Browser Search\IE\basis_it.xml
d:\program files\Fast Browser Search\IE\basis_nr.xml
d:\program files\Fast Browser Search\IE\basis_pt.xml
d:\program files\Fast Browser Search\IE\basis_ru.xml
d:\program files\Fast Browser Search\IE\basis_tr.xml
d:\program files\Fast Browser Search\IE\BHO.dll
d:\program files\Fast Browser Search\IE\ClearRecycleBin.exe
d:\program files\Fast Browser Search\IE\error.html
d:\program files\Fast Browser Search\IE\FBSPlugin.dll
d:\program files\Fast Browser Search\IE\fbsProtection.xml
d:\program files\Fast Browser Search\IE\FbsSearchProvider.xml
d:\program files\Fast Browser Search\IE\FbsSearchProviderIE8.exe
d:\program files\Fast Browser Search\IE\FBStoolbar.dll
d:\program files\Fast Browser Search\IE\fbstoolbar.jar
d:\program files\Fast Browser Search\IE\fbstoolbar.manifest
d:\program files\Fast Browser Search\IE\icons.bmp
d:\program files\Fast Browser Search\IE\info.txt
d:\program files\Fast Browser Search\IE\local.xml
d:\program files\Fast Browser Search\IE\logobg.bmp
d:\program files\Fast Browser Search\IE\MTWBtoolbar.html
d:\program files\Fast Browser Search\IE\search.bmp
d:\program files\Fast Browser Search\IE\search_br.bmp
d:\program files\Fast Browser Search\IE\search_de.bmp
d:\program files\Fast Browser Search\IE\search_es.bmp
d:\program files\Fast Browser Search\IE\search_fr.bmp
d:\program files\Fast Browser Search\IE\search_it.bmp
d:\program files\Fast Browser Search\IE\search_pt.bmp
d:\program files\Fast Browser Search\IE\search_ru.bmp
d:\program files\Fast Browser Search\IE\SearchAssistant.dll
d:\program files\Fast Browser Search\IE\SearchGuardPlus.exe
d:\program files\Fast Browser Search\IE\SearchGuardPlus.ico
d:\program files\Fast Browser Search\IE\SGPU.ico
d:\program files\Fast Browser Search\IE\sgpUpdater.exe
d:\program files\Fast Browser Search\IE\sgpUpdater.xml
d:\program files\Fast Browser Search\IE\SGPUpdaterS.exe
d:\program files\Fast Browser Search\IE\tbs_include_script_003175.js
d:\program files\Fast Browser Search\IE\tbs_include_script_005064.js
d:\program files\Fast Browser Search\IE\tbs_include_script_012817.js
d:\program files\Fast Browser Search\IE\Toolbar Help.htm
d:\program files\Fast Browser Search\IE\ToolBarBHO.dll
d:\program files\Fast Browser Search\IE\uninstall.exe
d:\program files\Fast Browser Search\IE\uninstalSGP.exe
d:\program files\Fast Browser Search\IE\uninstalSGPU.exe
d:\program files\Fast Browser Search\IE\update.exe
d:\program files\Fast Browser Search\IE\version.txt
d:\program files\Search Guard Plus
d:\program files\Search Guard Plus\fbsProtection.xml
d:\program files\Search Guard Plus\fbsSearchProvider.xml
d:\program files\Search Guard Plus\FbsSearchProviderIE8.exe
d:\program files\Search Guard Plus\SearchGuardPlus.exe
d:\program files\Search Guard Plus\SearchGuardPlus.ico
d:\program files\Search Guard Plus\uninstalSGP.exe
d:\program files\Search Guard PlusU
d:\program files\Search Guard PlusU\SGPU.ico
d:\program files\Search Guard PlusU\sgpUpdater.exe
d:\program files\Search Guard PlusU\sgpUpdater.xml
d:\program files\Search Guard PlusU\sgpUpdaters.exe
d:\program files\Search Guard PlusU\uninstalSGPU.exe
d:\program files\SGPSA
d:\program files\SGPSA\BHO.dll
d:\recycler\S-1-5-21-1229272821-573735546-1417001333-1003
d:\recycler\S-1-5-21-2767732418-3748049100-674260828-1892
d:\recycler\S-1-5-21-3187058480-1475561317-757922405-6332
d:\recycler\S-1-5-21-6942734339-7545922255-445744229-0648
d:\recycler\S-1-5-21-7571174801-8384361941-479227755-3056
d:\recycler\S-1-5-21-7571174801-8384361941-479227755-3056\winmap32.exe
d:\recycler\S-1-5-21-7867821975-0616227894-177983958-0640
d:\windows\AppPatch\AcAdProc.dll
d:\windows\cidrive32.exe
d:\windows\eSellerateEngine.dll
d:\windows\system32\ieuinit.inf
d:\windows\wpe pro.INI

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BNDMSS
-------\Service_BNDMSS


((((((((((((((((((((((((( Files Created from 2010-03-02 to 2010-04-02 )))))))))))))))))))))))))))))))
.

2010-04-02 11:07 . 2010-04-02 11:07 -------- d-----w- D:\rsit
2010-04-02 10:11 . 2010-03-09 10:12 162640 ----a-w- d:\windows\system32\drivers\aswSP.sys
2010-04-02 10:11 . 2010-03-09 10:09 23376 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2010-04-02 10:11 . 2010-03-09 10:08 19024 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2010-04-02 10:11 . 2010-03-09 10:12 46672 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2010-04-02 10:11 . 2010-03-09 10:08 100432 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2010-04-02 10:11 . 2010-03-09 10:08 94800 ----a-w- d:\windows\system32\drivers\aswmon.sys
2010-04-02 10:11 . 2010-03-09 10:08 28880 ----a-w- d:\windows\system32\drivers\aavmker4.sys
2010-04-02 10:11 . 2010-03-09 10:24 153184 ----a-w- d:\windows\system32\aswBoot.exe
2010-04-02 10:11 . 2010-02-11 17:53 38848 ----a-w- d:\windows\system32\avastSS.scr
2010-04-02 10:11 . 2010-04-02 10:11 -------- d-----w- d:\program files\Alwil Software
2010-04-02 09:46 . 2010-04-02 09:46 53088 ----a-w- d:\windows\system32\drivers\pxrts.sys
2010-04-02 09:46 . 2010-04-02 09:46 30280 ----a-w- d:\windows\system32\drivers\pxscan.sys
2010-04-02 09:46 . 2010-04-02 09:46 24368 ----a-w- d:\windows\system32\drivers\pxkbf.sys
2010-04-02 08:16 . 2010-04-02 08:16 -------- d-----w- d:\program files\SUPERAntiSpyware
2010-03-30 11:57 . 2010-03-30 11:57 -------- d-----w- d:\program files\LogMeIn Hamachi
2010-03-29 13:30 . 2010-02-03 13:56 26176 ---ha-w- d:\windows\system32\hamachi.sys
2010-03-20 12:02 . 2010-03-20 12:02 -------- d-----w- d:\program files\Adobe Media Player
2010-03-20 12:00 . 2010-03-20 12:00 -------- d-----w- d:\program files\Common Files\Adobe AIR
2010-03-20 11:56 . 2010-03-20 11:56 -------- d-----w- d:\program files\Common Files\Macrovision Shared
2010-03-16 17:26 . 2010-03-16 18:01 -------- d-----w- D:\server c
2010-03-04 15:43 . 2010-03-04 15:45 -------- d-----w- D:\Half-Life

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 10:13 . 2009-03-28 18:14 -------- d-----w- d:\program files\Google
2010-04-02 09:29 . 2008-06-07 07:58 -------- d-----w- d:\program files\DAEMON Tools
2010-04-02 08:16 . 2008-10-19 10:16 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2010-03-31 22:12 . 2009-02-21 22:56 -------- d-----w- d:\program files\Wowcko
2010-03-29 13:31 . 2001-10-25 12:00 75062 ----a-w- d:\windows\system32\perfc005.dat
2010-03-29 13:31 . 2001-10-25 12:00 382780 ----a-w- d:\windows\system32\perfh005.dat
2010-03-28 11:05 . 2009-12-13 11:19 -------- d-----w- d:\program files\Optimik
2010-03-20 12:03 . 2008-09-03 12:46 -------- d-----w- d:\program files\Common Files\Adobe
2010-03-02 22:46 . 2010-03-02 22:46 -------- d-----w- d:\program files\Vypinac
2010-02-26 09:42 . 2010-02-20 01:36 20480 ----a-w- d:\windows\system32\H@tKeysH@@k.DLL
2010-02-24 12:20 . 2010-02-24 12:20 -------- d-----w- d:\program files\TeamSpeak 3 Client
2010-02-21 12:03 . 2008-06-02 12:29 -------- d--h--w- d:\program files\InstallShield Installation Information
2010-02-21 12:03 . 2010-02-21 12:03 -------- d-----w- d:\program files\SmartSound Software
2010-02-21 12:02 . 2010-02-21 12:02 -------- d-----w- d:\program files\Windows Media Components
2010-02-21 12:01 . 2010-02-21 12:01 -------- d-----w- d:\program files\Common Files\Ulead Systems
2010-02-21 12:01 . 2010-02-21 12:01 -------- d-----w- d:\program files\Ulead Systems
2010-02-21 12:01 . 2008-06-02 12:23 -------- d-----w- d:\program files\Common Files\InstallShield
2010-02-21 10:29 . 2010-02-21 10:01 -------- d-----w- d:\program files\Banner Maker Pro 6
2010-02-20 01:04 . 2010-02-20 01:04 -------- d-----w- d:\program files\TeamViewer
2010-02-20 00:50 . 2010-02-19 20:49 -------- d-----w- d:\program files\Hamachi
2010-02-20 00:16 . 2010-02-20 00:16 -------- d-----w- d:\program files\Microsoft Games
2010-02-16 16:02 . 2010-02-16 15:52 -------- d-----w- d:\program files\Euro Truck Simulator
2010-02-08 14:29 . 2010-02-08 14:29 -------- d-----w- d:\program files\Rockstar Games
2010-02-06 15:05 . 2010-02-22 18:06 685725 ----a-w- D:\XPerl-3.0.8_Release.zip
2008-08-10 06:56 . 2008-08-10 06:56 10752 ----a-w- d:\program files\Nový objekt - Dokument programu Microsoft Word.doc
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Network Data Management System Service"="skp66.exe *" [X]
"CurseClient"="d:\program files\Curse\CurseClient.exe" [2008-05-19 1400832]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2010864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Network Data Management System Service"="skp66.exe *" [X]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"ATIPTA"="d:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 344064]
"ATICCC"="d:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-06-28 32768]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"OrderReminder"="d:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 136600]
"pdfFactory Dispatcher v3"="d:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2008-03-05 516096]
"NeroFilterCheck"="d:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"UVS10 Preload"="d:\program files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe" [2006-03-06 36864]
"AdobeCS4ServiceManager"="d:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"LogMeIn Hamachi Ui"="d:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\System32\CTFMON.EXE" [2004-08-17 15360]

d:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATI CATALYST System Tray.lnk - d:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-6-29 32768]
AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-5 10872]
HP Image Zone Fast Start.lnk - d:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-12 73728]
MyVitalAgent.lnk - d:\program files\INS\VitalAgent\Program\VtlAgent.exe [2008-9-4 30208]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\MaNGOS 5770\\realmd.exe"=
"d:\\Program Files\\MaNGOS 5770\\mangosd.exe"=
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Program Files\\MaNGOS 5770\\EasyPHP\\mysql\\bin\\mysqld.exe"=
"d:\\Program Files\\MaNGOS 5770\\EasyPHP\\apache\\bin\\Apache.exe"=
"d:\\Documents and Settings\\Macko\\Plocha\\utorrent.exe"=
"skp66.exe"= skp66.exe:BNDMSS
"d:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sptd;sptd;d:\windows\system32\drivers\sptd.sys [7. 6. 2008 9:57 642560]
R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [2. 4. 2010 12:11 162640]
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [17. 2. 2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17. 2. 2010 11:15 66632]
R2 0VsNdis08;VitalAgent Network Driver 8.1;d:\program files\INS\VitalAgent\Program\VsNdis08.sys [4. 9. 2008 13:48 31671]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2. 4. 2010 12:11 19024]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\LogMeIn Hamachi\hamachi-2.exe [30. 3. 2010 11:16 1107336]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;d:\windows\system32\drivers\ousbehci.sys [2. 6. 2008 14:27 44928]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;d:\windows\system32\drivers\ousb2hub.sys [2. 6. 2008 14:27 55808]
R3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [17. 2. 2010 11:15 12872]
R3 teamviewervpn;TeamViewer VPN Adapter;d:\windows\system32\drivers\teamviewervpn.sys [9. 11. 2009 19:12 25088]
S2 gupdate1c9afd1e0e7928;Google Update Service (gupdate1c9afd1e0e7928);d:\program files\Google\Update\GoogleUpdate.exe [28. 3. 2009 20:14 133104]
S3 0VsComm12;VitalAgent Serial Port Driver 12.4;d:\program files\INS\VitalAgent\Program\VsComm12.sys [4. 9. 2008 13:48 15443]
.
Contents of the 'Scheduled Tasks' folder

2010-03-22 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-04-02 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 18:14]

2010-04-02 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 18:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zaparit.cz/
IE: E&xportovať do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\Macko\Data aplikací\Mozilla\Firefox\Profiles\toovjh0w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/resul ... EF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://wowhead.com/
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/resul ... 98C0B1}&q=
FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
d:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SGPUpdater - d:\program files\Search Guard PlusU\sgpUpdaters.exe
HKLM-Run-FBSearch - d:\program files\Search Guard Plus\SearchGuardPlus.exe
ActiveSetup-{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} - c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\sic32.exe
AddRemove-Counter-Strike - g:\program files\Counter-Strike\uninstall.exe
AddRemove-Counter-strike 1.6 CZ - g:\program files\Counter-Strike\Odinstalovat CZ.exe
AddRemove-HijackThis - G:\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-02 14:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SGPUpdater = d:\program files\Search Guard PlusU\sgpUpdaters.exe??o? Web Tattoo. End-User License Agreement and
FBSearch = d:\program files\Search Guard Plus\SearchGuardPlus.exe? Web Tattoo. End-User License Agreement and

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe >>UNKNOWN [0x8638C398]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x8638c398
\Driver\ACPI -> ACPI.sys @ 0xf76fecb8
\Driver\atapi -> atapi.sys @ 0xf76952f0
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x8059aafe
ParseProcedure -> ntoskrnl.exe @ 0x80569a6e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x8059aafe
ParseProcedure -> ntoskrnl.exe @ 0x80569a6e
NDIS: Realtek RTL8169/8110 Family Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7589ba0
PacketIndicateHandler -> NDIS.sys @ 0xf7578a0b
SendHandler -> NDIS.sys @ 0xf758cb31
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1076)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
d:\windows\system32\Ati2evxx.dll
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(1864)
d:\windows\system32\msi.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
d:\program files\SUPERAntiSpyware\SASSEH.DLL
d:\windows\system32\browselc.dll
d:\program files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
d:\program files\Microsoft Office\OFFICE11\msohev.dll
d:\progra~1\MICROS~2\OFFICE11\MCPS.DLL
.
------------------------ Other Running Processes ------------------------
.
d:\windows\System32\Ati2evxx.exe
d:\program files\Alwil Software\Avast5\AvastSvc.exe
d:\windows\system32\Ati2evxx.exe
d:\progra~1\MANGOS~1\EasyPHP\Apache\bin\apache.exe
d:\progra~1\MANGOS~1\EasyPHP\Apache\bin\apache.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\program files\HP\Digital Imaging\bin\hpqimzone.exe
d:\progra~1\MANGOS~1\EasyPHP\MySql\bin\mysqld.exe
d:\windows\system32\PnkBstrA.exe
d:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
d:\windows\system32\wscntfy.exe
d:\windows\system32\NOTEPAD.EXE
d:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Completion time: 2010-04-02 14:28:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-02 12:28

Pre-Run: 9 649 950 720
Post-Run: Volných bajtů: 14 032 093 184

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 69954278B303AB7D3793C83405EF92CD

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#6 Příspěvek od xaron »

to je vsetko? :D ci este treba nieco spravit?

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#7 Příspěvek od Caroprd111 »

Vydržte, musím se na to podívat.
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#8 Příspěvek od Caroprd111 »

Obrázek Pokud nemáte, přesuňte Combofix na plochu
  • Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.

Kód: Vybrat vše

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Network Data Management System Service"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Network Data Management System Service"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"skp66.exe"=-

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
  • Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
  • Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:

    Obrázek
  • Po aplikaci na Vás vypadne další log,vložte ho sem
Může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci


Obrázek Stáhněte a uložte na plochu SystemLook http://jpshortstuff.247fixes.com/SystemLook.exe
  • Spusťte, do okénka zkopírujte text z bílého okna.

Kód: Vybrat vše

:filefind
skp66.exe.*
skp66.exe
  • klikněte na Look, po dokončení skenu na Vás vyskočí log, zkopírujte ho sem.

Obrázek Tohle otestujte na http://www.virustotal.com/cs/
d:\windows\system32\drivers\pxkbf.sys

(Soubor nehledejte, jenom vložíte tučně označenou cestu, v případě hlášky "Soubor již byl testován" dejte otestovat znovu. Výsledek analýzy sem v podobě odkazu vložte.)
Obrázek

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#9 Příspěvek od xaron »

ComboFix 10-04-01.02 - Macko . 04. 2010 15:48:11.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.421.1029.18.1023.683 [GMT 2:00]
Running from: d:\documents and settings\Macko\Plocha\ComboFix.exe
Command switches used :: d:\documents and settings\Macko\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2010-03-02 to 2010-04-02 )))))))))))))))))))))))))))))))
.

2010-04-02 11:07 . 2010-04-02 11:07 -------- d-----w- D:\rsit
2010-04-02 10:11 . 2010-03-09 10:12 162640 ----a-w- d:\windows\system32\drivers\aswSP.sys
2010-04-02 10:11 . 2010-03-09 10:09 23376 ----a-w- d:\windows\system32\drivers\aswRdr.sys
2010-04-02 10:11 . 2010-03-09 10:08 19024 ----a-w- d:\windows\system32\drivers\aswFsBlk.sys
2010-04-02 10:11 . 2010-03-09 10:12 46672 ----a-w- d:\windows\system32\drivers\aswTdi.sys
2010-04-02 10:11 . 2010-03-09 10:08 100432 ----a-w- d:\windows\system32\drivers\aswmon2.sys
2010-04-02 10:11 . 2010-03-09 10:08 94800 ----a-w- d:\windows\system32\drivers\aswmon.sys
2010-04-02 10:11 . 2010-03-09 10:08 28880 ----a-w- d:\windows\system32\drivers\aavmker4.sys
2010-04-02 10:11 . 2010-03-09 10:24 153184 ----a-w- d:\windows\system32\aswBoot.exe
2010-04-02 10:11 . 2010-02-11 17:53 38848 ----a-w- d:\windows\system32\avastSS.scr
2010-04-02 10:11 . 2010-04-02 10:11 -------- d-----w- d:\program files\Alwil Software
2010-04-02 09:46 . 2010-04-02 09:46 53088 ----a-w- d:\windows\system32\drivers\pxrts.sys
2010-04-02 09:46 . 2010-04-02 09:46 30280 ----a-w- d:\windows\system32\drivers\pxscan.sys
2010-04-02 09:46 . 2010-04-02 09:46 24368 ----a-w- d:\windows\system32\drivers\pxkbf.sys
2010-04-02 08:16 . 2010-04-02 08:16 -------- d-----w- d:\program files\SUPERAntiSpyware
2010-03-30 11:57 . 2010-03-30 11:57 -------- d-----w- d:\program files\LogMeIn Hamachi
2010-03-29 13:30 . 2010-02-03 13:56 26176 ---ha-w- d:\windows\system32\hamachi.sys
2010-03-20 12:02 . 2010-03-20 12:02 -------- d-----w- d:\program files\Adobe Media Player
2010-03-20 12:00 . 2010-03-20 12:00 -------- d-----w- d:\program files\Common Files\Adobe AIR
2010-03-20 11:56 . 2010-03-20 11:56 -------- d-----w- d:\program files\Common Files\Macrovision Shared
2010-03-16 17:26 . 2010-03-16 18:01 -------- d-----w- D:\server c
2010-03-04 15:43 . 2010-03-04 15:45 -------- d-----w- D:\Half-Life

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 10:13 . 2009-03-28 18:14 -------- d-----w- d:\program files\Google
2010-04-02 09:29 . 2008-06-07 07:58 -------- d-----w- d:\program files\DAEMON Tools
2010-04-02 08:16 . 2008-10-19 10:16 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard
2010-03-31 22:12 . 2009-02-21 22:56 -------- d-----w- d:\program files\Wowcko
2010-03-29 13:31 . 2001-10-25 12:00 75062 ----a-w- d:\windows\system32\perfc005.dat
2010-03-29 13:31 . 2001-10-25 12:00 382780 ----a-w- d:\windows\system32\perfh005.dat
2010-03-28 11:05 . 2009-12-13 11:19 -------- d-----w- d:\program files\Optimik
2010-03-20 12:03 . 2008-09-03 12:46 -------- d-----w- d:\program files\Common Files\Adobe
2010-03-02 22:46 . 2010-03-02 22:46 -------- d-----w- d:\program files\Vypinac
2010-02-26 09:42 . 2010-02-20 01:36 20480 ----a-w- d:\windows\system32\H@tKeysH@@k.DLL
2010-02-24 12:20 . 2010-02-24 12:20 -------- d-----w- d:\program files\TeamSpeak 3 Client
2010-02-21 12:03 . 2008-06-02 12:29 -------- d--h--w- d:\program files\InstallShield Installation Information
2010-02-21 12:03 . 2010-02-21 12:03 -------- d-----w- d:\program files\SmartSound Software
2010-02-21 12:02 . 2010-02-21 12:02 -------- d-----w- d:\program files\Windows Media Components
2010-02-21 12:01 . 2010-02-21 12:01 -------- d-----w- d:\program files\Common Files\Ulead Systems
2010-02-21 12:01 . 2010-02-21 12:01 -------- d-----w- d:\program files\Ulead Systems
2010-02-21 12:01 . 2008-06-02 12:23 -------- d-----w- d:\program files\Common Files\InstallShield
2010-02-21 10:29 . 2010-02-21 10:01 -------- d-----w- d:\program files\Banner Maker Pro 6
2010-02-20 01:04 . 2010-02-20 01:04 -------- d-----w- d:\program files\TeamViewer
2010-02-20 00:50 . 2010-02-19 20:49 -------- d-----w- d:\program files\Hamachi
2010-02-20 00:16 . 2010-02-20 00:16 -------- d-----w- d:\program files\Microsoft Games
2010-02-16 16:02 . 2010-02-16 15:52 -------- d-----w- d:\program files\Euro Truck Simulator
2010-02-08 14:29 . 2010-02-08 14:29 -------- d-----w- d:\program files\Rockstar Games
2010-02-06 15:05 . 2010-02-22 18:06 685725 ----a-w- D:\XPerl-3.0.8_Release.zip
2008-08-10 06:56 . 2008-08-10 06:56 10752 ----a-w- d:\program files\Nový objekt - Dokument programu Microsoft Word.doc
.

((((((((((((((((((((((((((((( SnapShot@2010-04-02_12.20.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-02 13:47 . 2010-04-02 13:47 16384 d:\windows\Temp\Perflib_Perfdata_3e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CurseClient"="d:\program files\Curse\CurseClient.exe" [2008-05-19 1400832]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]
"SUPERAntiSpyware"="d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2010864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"ATIPTA"="d:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-28 344064]
"ATICCC"="d:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-06-28 32768]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"OrderReminder"="d:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-19 136600]
"pdfFactory Dispatcher v3"="d:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2008-03-05 516096]
"NeroFilterCheck"="d:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"UVS10 Preload"="d:\program files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe" [2006-03-06 36864]
"AdobeCS4ServiceManager"="d:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"LogMeIn Hamachi Ui"="d:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"avast5"="d:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\System32\CTFMON.EXE" [2004-08-17 15360]

d:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ATI CATALYST System Tray.lnk - d:\program files\ATI Technologies\ATI.ACE\CLI.exe [2005-6-29 32768]
AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-5 10872]
HP Image Zone Fast Start.lnk - d:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-12 73728]
MyVitalAgent.lnk - d:\program files\INS\VitalAgent\Program\VtlAgent.exe [2008-9-4 30208]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\MaNGOS 5770\\realmd.exe"=
"d:\\Program Files\\MaNGOS 5770\\mangosd.exe"=
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\Program Files\\MaNGOS 5770\\EasyPHP\\mysql\\bin\\mysqld.exe"=
"d:\\Program Files\\MaNGOS 5770\\EasyPHP\\apache\\bin\\Apache.exe"=
"d:\\Documents and Settings\\Macko\\Plocha\\utorrent.exe"=
"d:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"d:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 aswSP;aswSP;d:\windows\system32\drivers\aswSP.sys [2. 4. 2010 12:11 162640]
R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [17. 2. 2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17. 2. 2010 11:15 66632]
R2 0VsNdis08;VitalAgent Network Driver 8.1;d:\program files\INS\VitalAgent\Program\VsNdis08.sys [4. 9. 2008 13:48 31671]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2. 4. 2010 12:11 19024]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;d:\program files\LogMeIn Hamachi\hamachi-2.exe [30. 3. 2010 11:16 1107336]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;d:\windows\system32\drivers\ousbehci.sys [2. 6. 2008 14:27 44928]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;d:\windows\system32\drivers\ousb2hub.sys [2. 6. 2008 14:27 55808]
R3 teamviewervpn;TeamViewer VPN Adapter;d:\windows\system32\drivers\teamviewervpn.sys [9. 11. 2009 19:12 25088]
S0 sptd;sptd;d:\windows\system32\drivers\sptd.sys [7. 6. 2008 9:57 642560]
S2 gupdate1c9afd1e0e7928;Google Update Service (gupdate1c9afd1e0e7928);d:\program files\Google\Update\GoogleUpdate.exe [28. 3. 2009 20:14 133104]
S3 0VsComm12;VitalAgent Serial Port Driver 12.4;d:\program files\INS\VitalAgent\Program\VsComm12.sys [4. 9. 2008 13:48 15443]
S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [17. 2. 2010 11:15 12872]
.
Contents of the 'Scheduled Tasks' folder

2010-03-22 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-04-02 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 18:14]

2010-04-02 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-03-28 18:14]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.zaparit.cz/
IE: E&xportovať do programu Microsoft Excel - d:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\Macko\Data aplikací\Mozilla\Firefox\Profiles\toovjh0w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/resul ... EF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://wowhead.com/
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/resul ... 98C0B1}&q=
FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll

---- FIREFOX POLICIES ----
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
d:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-02 15:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1020)
d:\program files\SUPERAntiSpyware\SASWINLO.dll
d:\windows\system32\Ati2evxx.dll
d:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2010-04-02 15:58:14
ComboFix-quarantined-files.txt 2010-04-02 13:58
ComboFix2.txt 2010-04-02 12:28

Pre-Run: Volných bajtů: 14 046 941 184
Post-Run: Volných bajtů: 14 013 394 944

- - End Of File - - 716ED2ABFB213AE9B9C315FBD89B9147

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#10 Příspěvek od xaron »

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 16:02 on 02/04/2010 by Macko (Administrator - Elevation successful)

========== filefind ==========

Searching for "skp66.exe.*"
No files found.

Searching for "skp66.exe"
No files found.

-=End Of File=-

http://www.virustotal.com/cs/analisis/c ... 1270217676

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#11 Příspěvek od Caroprd111 »

Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\plocha\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.


Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Obrázek

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#12 Příspěvek od xaron »

Caroprd111 píše: Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
Ako zistim ci mam 64 alebo 32b?

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#13 Příspěvek od Caroprd111 »

Máte 32b
Obrázek

xaron
Návštěvník
Návštěvník
Příspěvky: 28
Registrován: 02 dub 2010 10:56

Re: cidrive32.exe -log HJT

#14 Příspěvek od xaron »

uniinstal tam nemam
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: cidrive32.exe -log HJT

#15 Příspěvek od Caroprd111 »

SPTD vynechte.
Obrázek

Odpovědět