Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

TR/Crypt.ZPACK.Gen trojan

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Walky
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 102
Registrován: 11 kvě 2009 19:53

TR/Crypt.ZPACK.Gen trojan

#1 Příspěvek od Walky »

Avira mi nasla tento vir a ked ho sa avira ho snazi vymazat alebo zakazat pristup tak sa mi da pc ako do usporneho rezimu a uz ho mozem len vypnut.Este mi vybehuje tabulka a tam ked stlacim close tak sa stane to iste


Logfile of random's system information tool 1.06 (written by random/random)
Run by Joyo at 2010-04-14 16:42:46
Microsoft Windows XP Professional Service Pack 2
System drive C: has 8 GB (42%) free of 20 GB
Total RAM: 1023 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:42:59, on 14. 4. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Programy\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\ntvdm.exe
C:\DOCUME~1\Joyo\LOCALS~1\Temp\081494.exe
C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\RSIT.exe
C:\Program Files\trend micro\Joyo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/ ... ch/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.com
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\RunOnce: [WiseStubReboot] MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I "C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI" TRANSFORMS="C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST" WISE_SETUP_EXE_PATH="c:\nvidia\displaydriver\195.62\winxp\international\PhysX_9.09.0814_SystemSoftware.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Akcelerátor spuštění AutoCADu.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8881 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll [2010-01-08 700416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-26 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
C:\Program Files\pdfforge Toolbar\SearchSettings.dll [2010-01-08 1109504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-26 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]
{B922D405-6D13-4A2B-AE89-08A030DA4402} - pdfforge Toolbar - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll [2010-01-08 700416]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"SearchSettings"=C:\Program Files\pdfforge Toolbar\SearchSettings.exe [2010-01-08 974848]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-03-05 1135912]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-11-20 12669544]
"nwiz"=nwiz.exe /install []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-12-19 15360]
"DAEMON Tools Lite"=D:\Programy\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-04 1667584]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe [2005-11-24 94208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WiseStubReboot"=MSIEXEC /quiet SKIP_PPU_DRIVER_INSTALL=1 /I C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MSI TRANSFORMS=C:\Program Files\Common Files\Wise Installation Wizard\WISC5C1C0F0D62F4DBF81D4D7EF397C228B_9_09_0814.MST WISE_SETUP_EXE_PATH=c:\nvidia\displaydriver\195.62\winxp\international\PhysX_9.09.0814_SystemSoftware.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
C:\WINDOWS\ALCMTR.EXE [2007-07-25 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ7.0\ICQ.exe silent loginmode=4 []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
C:\PROGRA~1\LAUNCH~1\LManager.exe [2007-07-25 752136]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2009-11-20 12669544]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2009-11-20 110184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2007-07-25 16342528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-02-22 26101032]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\Hry\Steam\Steam.exe [2010-03-26 1217872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-07-25 827392]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Akcelerátor spuštění AutoCADu.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Documents and Settings\Joyo\Start Menu\Programs\Startup
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"D:\Hry\Steam\Steam.exe"="D:\Hry\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe"="D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2"
"D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe"="D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.0\ICQ.exe"="C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7"
"C:\Program Files\ICQ7.0\aolload.exe"="C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a37834a-37fe-11df-83e0-001dd968892e}]
shell\AutoRun\command - F:\xmor.exe
shell\open\command - F:\xmor.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34d2103a-29d2-11df-83cf-001dd968892e}]
shell\AutoRun\command - F:\MILEGEJ//kitic.exe
shell\open\command - F:\MILEGEJ//kitic.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4717b7d6-3cbe-11df-83eb-001dd968892e}]
shell\AutoRun\command - F:\MILEGEJ//kitic.exe
shell\open\command - F:\MILEGEJ//kitic.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4717b7fe-3cbe-11df-83eb-001dd968892e}]
shell\AutoRun\command - DODA\JENE\NeST.exe
shell\open\command - DODA\JENE\NeST.exe


======File associations======

.scr - open - "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-04-14 16:42:47 ----D---- C:\Program Files\trend micro
2010-04-14 16:42:46 ----D---- C:\rsit
2010-04-14 13:17:19 ----RSH---- C:\Documents and Settings\Joyo\Application Data\jlwcbb.exe
2010-04-14 10:22:09 ----D---- C:\Program Files\Yahoo!
2010-04-13 17:38:19 ----D---- C:\Documents and Settings\Joyo\Application Data\DivX
2010-04-12 20:40:02 ----D---- C:\Program Files\Common Files\DivX Shared
2010-04-12 20:38:50 ----D---- C:\Program Files\DivX
2010-04-12 20:38:23 ----D---- C:\Documents and Settings\All Users\Application Data\DivX
2010-04-12 09:27:32 ----D---- C:\Documents and Settings\Joyo\Application Data\U3
2010-04-06 14:42:44 ----D---- C:\Program Files\Traction Software
2010-04-06 01:10:31 ----D---- C:\Documents and Settings\Joyo\Application Data\Free Download Manager
2010-04-06 01:10:29 ----D---- C:\Program Files\Free Download Manager
2010-04-06 00:01:27 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-04-05 23:59:08 ----A---- C:\WINDOWS\system32\btw_ci.dll
2010-04-05 23:58:56 ----D---- C:\Program Files\WIDCOMM
2010-03-31 20:59:27 ----A---- C:\WINDOWS\NeroDigital.ini
2010-03-31 19:34:18 ----D---- C:\Documents and Settings\Joyo\Application Data\Ahead
2010-03-31 19:32:58 ----D---- C:\Program Files\Nero
2010-03-31 19:32:58 ----D---- C:\Program Files\Common Files\Ahead
2010-03-28 14:43:04 ----D---- C:\Documents and Settings\Joyo\Application Data\Help
2010-03-28 11:17:22 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-03-28 11:17:21 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2010-03-28 11:17:21 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2010-03-28 11:17:20 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-03-28 11:17:20 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2010-03-28 11:17:19 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-03-28 11:17:19 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-03-28 11:17:18 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-03-28 11:17:16 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-03-28 11:17:16 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-03-28 11:17:16 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-03-28 11:17:13 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-03-28 11:17:13 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-03-28 11:17:12 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-03-28 11:17:10 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-03-28 11:17:10 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-03-28 11:17:09 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-03-28 11:17:07 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2010-03-28 11:17:07 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2010-03-28 11:17:07 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-03-28 11:17:06 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2010-03-28 11:17:06 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2010-03-28 11:17:06 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-03-28 11:17:03 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2010-03-28 11:17:03 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-03-28 11:17:02 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2010-03-28 11:17:01 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-03-28 11:17:01 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-03-28 11:17:01 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-03-28 11:16:59 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-03-28 11:16:59 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-03-28 11:16:57 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-03-28 11:16:55 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-03-28 11:16:43 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-03-28 11:16:42 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-03-27 20:56:49 ----D---- C:\Documents and Settings\Joyo\Application Data\Search Settings
2010-03-27 20:56:42 ----D---- C:\Documents and Settings\Joyo\Application Data\pdfforge
2010-03-27 15:53:08 ----D---- C:\Documents and Settings\Joyo\Application Data\PDFCreator
2010-03-27 15:50:52 ----D---- C:\Program Files\Application Updater
2010-03-27 15:50:51 ----D---- C:\Program Files\pdfforge Toolbar
2010-03-27 15:50:16 ----A---- C:\WINDOWS\system32\pdfcmnnt.dll
2010-03-27 15:50:14 ----A---- C:\WINDOWS\system32\MSMPIDE.DLL
2010-03-27 15:50:13 ----D---- C:\Program Files\PDFCreator
2010-03-27 15:21:51 ----D---- C:\WINDOWS\system32\XPSViewer
2010-03-27 15:21:44 ----D---- C:\WINDOWS\system32\en-us
2010-03-27 15:21:43 ----D---- C:\Program Files\Reference Assemblies
2010-03-27 15:21:13 ----N---- C:\WINDOWS\system32\spmsg2.dll
2010-03-27 15:15:43 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-03-27 15:15:36 ----D---- C:\Program Files\MSXML 6.0
2010-03-27 15:01:52 ----D---- C:\Program Files\ICQ7.1
2010-03-26 18:40:01 ----D---- C:\Program Files\SystemRequirementsLab
2010-03-26 18:39:45 ----D---- C:\Documents and Settings\Joyo\Application Data\SystemRequirementsLab
2010-03-26 18:39:37 ----D---- C:\WINDOWS\Sun
2010-03-26 17:54:11 ----D---- C:\Documents and Settings\All Users\Application Data\Sun
2010-03-26 17:54:10 ----D---- C:\Program Files\Common Files\Java
2010-03-26 17:53:57 ----A---- C:\WINDOWS\system32\javaws.exe
2010-03-26 17:53:57 ----A---- C:\WINDOWS\system32\javaw.exe
2010-03-26 17:53:57 ----A---- C:\WINDOWS\system32\java.exe
2010-03-26 17:53:57 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-03-26 17:53:40 ----D---- C:\Program Files\Java
2010-03-26 17:52:21 ----D---- C:\Documents and Settings\Joyo\Application Data\Sun
2010-03-26 17:41:51 ----D---- C:\Documents and Settings\Joyo\Application Data\skypePM
2010-03-26 08:13:53 ----D---- C:\WINDOWS\system32\LogFiles
2010-03-23 22:14:22 ----D---- C:\Program Files\ICQ6Toolbar
2010-03-23 22:14:17 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-03-23 22:13:00 ----D---- C:\Documents and Settings\Joyo\Application Data\ICQ
2010-03-23 21:22:49 ----A---- C:\WINDOWS\unvise32.exe
2010-03-23 21:09:42 ----A---- C:\WINDOWS\IsUn0405.exe
2010-03-23 21:07:01 ----D---- C:\Program Files\AnswerWorks 4.0
2010-03-23 21:03:53 ----D---- C:\Documents and Settings\Joyo\Application Data\Autodesk
2010-03-23 21:03:53 ----D---- C:\Documents and Settings\All Users\Application Data\Autodesk
2010-03-23 21:01:00 ----D---- C:\Program Files\Common Files\Autodesk Shared
2010-03-23 21:00:51 ----D---- C:\Program Files\Autodesk
2010-03-23 20:53:52 ----D---- C:\Program Files\Microsoft Works
2010-03-23 20:53:17 ----D---- C:\Program Files\Microsoft Visual Studio
2010-03-23 20:53:17 ----D---- C:\Program Files\Common Files\DESIGNER
2010-03-23 20:52:26 ----D---- C:\Program Files\Microsoft.NET
2010-03-23 20:49:21 ----D---- C:\Program Files\Microsoft Office
2010-03-23 20:36:23 ----D---- C:\Program Files\CCleaner
2010-03-23 20:31:04 ----A---- C:\WINDOWS\iun6002.exe
2010-03-18 09:48:01 ----D---- C:\Program Files\CONEXANT
2010-03-18 09:47:17 ----A---- C:\WINDOWS\system32\UCI32M16.dll
2010-03-18 09:47:17 ----A---- C:\WINDOWS\system32\mdmxsdk.dll

======List of files/folders modified in the last 1 months======

2010-04-14 16:42:54 ----D---- C:\WINDOWS\Prefetch
2010-04-14 16:42:47 ----RD---- C:\Program Files
2010-04-14 16:42:03 ----D---- C:\WINDOWS\system32
2010-04-14 16:42:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-14 16:38:04 ----D---- C:\WINDOWS\Temp
2010-04-14 16:38:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-14 16:33:38 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-14 13:45:23 ----ASH---- C:\boot.ini
2010-04-14 13:45:23 ----A---- C:\WINDOWS\win.ini
2010-04-14 13:45:23 ----A---- C:\WINDOWS\system.ini
2010-04-14 13:45:05 ----A---- C:\WINDOWS\ntbtlog.txt
2010-04-14 13:30:49 ----D---- C:\Documents and Settings
2010-04-13 16:55:41 ----D---- C:\Documents and Settings\Joyo\Application Data\vlc
2010-04-13 16:33:58 ----D---- C:\Documents and Settings\Joyo\Application Data\dvdcss
2010-04-12 20:40:16 ----SHD---- C:\WINDOWS\Installer
2010-04-12 20:40:16 ----D---- C:\Config.Msi
2010-04-12 20:40:02 ----D---- C:\Program Files\Common Files
2010-04-06 14:47:20 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-06 14:27:08 ----D---- C:\Program Files\ZipGenius 6
2010-04-06 14:23:06 ----D---- C:\Documents and Settings\Joyo\Application Data\ZipGenius
2010-04-06 10:16:51 ----SD---- C:\Documents and Settings\Joyo\Application Data\Microsoft
2010-04-06 08:12:06 ----D---- C:\WINDOWS
2010-04-06 00:01:33 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-06 00:00:54 ----D---- C:\WINDOWS\system32\drivers
2010-04-06 00:00:03 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-05 23:59:49 ----HD---- C:\WINDOWS\inf
2010-04-05 23:59:08 ----SD---- C:\WINDOWS\system32\Microsoft
2010-04-04 18:25:35 ----D---- C:\Documents and Settings\Joyo\Application Data\Adobe
2010-04-03 13:46:41 ----D---- C:\Program Files\Mozilla Firefox
2010-03-31 07:27:57 ----D---- C:\WINDOWS\system
2010-03-31 07:27:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-28 14:43:04 ----D---- C:\WINDOWS\Help
2010-03-28 11:17:24 ----D---- C:\WINDOWS\system32\DirectX
2010-03-28 11:16:53 ----RSD---- C:\WINDOWS\assembly
2010-03-28 11:16:18 ----D---- C:\WINDOWS\WinSxS
2010-03-28 00:14:19 ----D---- C:\WINDOWS\Microsoft.NET
2010-03-27 15:21:55 ----RSD---- C:\WINDOWS\Fonts
2010-03-27 15:21:24 ----D---- C:\WINDOWS\system32\spool
2010-03-27 15:19:12 ----D---- C:\WINDOWS\system32\mui
2010-03-27 11:19:07 ----D---- C:\Documents and Settings\Joyo\Application Data\Skype
2010-03-27 10:51:49 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-03-26 20:54:28 ----D---- C:\WINDOWS\system32\wbem
2010-03-24 08:32:39 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-03-24 07:54:18 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-03-23 21:45:20 ----D---- C:\Documents and Settings\Joyo\Application Data\GHISLER
2010-03-23 21:11:04 ----D---- C:\Program Files\Common Files\Adobe
2010-03-23 21:10:51 ----D---- C:\Program Files\Adobe
2010-03-23 21:03:07 ----D---- C:\Documents and Settings\All Users\Application Data\Valentin EnergieSoftware
2010-03-23 20:58:59 ----D---- C:\WINDOWS\Crystal
2010-03-23 20:52:27 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-03-23 20:50:21 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-03-23 20:49:56 ----D---- C:\Program Files\Common Files\System
2010-03-23 20:47:09 ----D---- C:\Documents and Settings\Joyo\Application Data\DAEMON Tools Lite
2010-03-23 20:31:23 ----A---- C:\WINDOWS\Codec Pack - All In 1 Setup Log.txt
2010-03-23 20:31:04 ----D---- C:\Program Files\Codec Pack - All In 1
2010-03-16 09:56:08 ----A---- C:\WINDOWS\DUMP3901.tmp

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2007-07-24 12672]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2007-03-21 37376]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-06-21 547072]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2007-07-23 539072]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\system32\DRIVERS\btport.sys [2007-07-23 37424]
R3 BTKRNL;Bluetooth Bus Enumerator; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2007-07-23 876384]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2007-07-25 16896]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-12-19 9600]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2007-07-24 988800]
R3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2007-07-24 209664]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-07-25 4419584]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-12-19 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-11-21 10235968]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2007-07-25 19968]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-07-25 12032]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2004-12-19 67584]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-07-25 201856]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-12-19 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-12-19 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-12-19 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-12-19 17024]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2007-07-24 730112]
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S2 bkunhw;\??\C:\; \??\C:\DOCUME~1\Joyo\LOCALS~1\Temp\xipufjnhvylvtfd.sys []
S2 gnbxmwqgxqmpu;\??\C:\DOCUME~; \??\C:\DOCUME~1\Joyo\LOCALS~1\Temp\xvceg.sys []
S2 mmulfi;\??\C:\; \??\C:\DOCUME~1\Joyo\LOCALS~1\Temp\hrwynfmzvvq.sys []
S2 ocziwofoktwyt;\??\C:\DOCUME~; \??\C:\DOCUME~1\Joyo\LOCALS~1\Temp\hqzlpqgvdotc.sys []
S2 sqmfgq;\??\C:\; \??\C:\DOCUME~1\Joyo\LOCALS~1\Temp\vxdmbsdfek.sys []
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-12-19 60800]
S3 axeu4ogz;axeu4ogz; C:\WINDOWS\system32\drivers\axeu4ogz.sys []
S3 BTWDNDIS;Bluetooth LAN Access Server; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2007-07-23 149123]
S3 btwhid;btwhid; C:\WINDOWS\system32\DRIVERS\btwhid.sys [2007-07-23 55352]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2007-07-23 67960]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-12-19 61824]
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2007-07-25 46720]
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2004-12-19 11136]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2004-12-19 10240]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 Application Updater;Application Updater; C:\Program Files\Application Updater\ApplicationUpdater.exe [2010-01-08 380928]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-04-01 273256]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-26 153376]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-11-20 154216]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-03-23 77944]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------

Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: TR/Crypt.ZPACK.Gen trojan

#2 Příspěvek od Caroprd111 »

Zdravím :)


Obrázek Doporučuji odinstalovat (pokud nepoužíváte) toolbary (lišty) v Přidat nebo odebrat programy.


Obrázek Vložte do PC všechny flash disky, které používáte.

Obrázek Stáhněte na plochu UsbFix http://pagesperso-orange.fr/NosTools/Ch ... UsbFix.exe
  • Spusťte, poté zvolte jazyk E - Enter
  • Zvolte 2 - Enter (je možný restart PC)
  • Po dokončení na Vás vyskočí log, vložte mi ho sem, případně ho najdete v C:\UsbFix.txt


Obrázek Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
  • Spusťte program, poté klikněte na Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Obrázek

Walky
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 102
Registrován: 11 kvě 2009 19:53

Re: TR/Crypt.ZPACK.Gen trojan

#3 Příspěvek od Walky »

USBfix


############################## | UsbFix V6.103 |

User : Joyo (Administrators) # JOYO-135916836A
Update on 12/04/2010 by El Desaparecido , C_XX & Chimay8
Start at: 17:32:28 | 14. 4. 2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

AMD Athlon(tm) 64 X2 Dual-Core Processor TK-55
Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Disabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

C:\ -> Local Fixed Disk # 19,53 Go (8,01 Go free) # NTFS
D:\ -> Local Fixed Disk # 92,25 Go (20,8 Go free) # NTFS
E:\ -> CD-ROM Disc
F:\ -> Removable Disk # 1,86 Go (1,35 Go free) [KINGSTON] # FAT
G:\ -> CD-ROM Disc
H:\ -> Removable Disk # 3,73 Go (3,73 Go free) # FAT32

################## | Files # Infected Folders |

Deleted ! D:\Recycler\S-1-5-21-220523388-920026266-839522115-1003
F:\autorun.inf -> Called file : "F:\MILEGEJ//kitic.exe" ( Found ! )
(!) Not deleted ! F:\MILEGEJ//kitic.exe
F:\autorun.inf -> Called file : "F:\MILEGEJ//kitic.exe" ( Found ! )
(!) Not deleted ! F:\MILEGEJ//kitic.exe
Deleted ! F:\autorun.inf

################## | Registry |

Deleted ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
Deleted ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

################## | Mountpoints2 |


################## | Listing of the present files |

[07. 03. 2010 11:28|--a------|0] C:\AUTOEXEC.BAT
[14. 04. 2010 13:45|--ahs----|315] C:\boot.ini
[24. 03. 2010 11:32|--a------|10] C:\CONFIG.SYS
[?|?|?] C:\hiberfil.sys
[07. 03. 2010 11:28|-rahs----|0] C:\IO.SYS
[07. 03. 2010 11:33|--a------|7] C:\ISACER.id
[07. 03. 2010 11:28|-rahs----|0] C:\MSDOS.SYS
[31. 03. 2003 14:00|-rahs----|47580] C:\NTDETECT.COM
[31. 03. 2003 14:00|-rahs----|233632] C:\ntldr
[?|?|?] C:\pagefile.sys
[13. 04. 2010 22:17|--a------|8186549] C:\Prílohy dopl. práce.zip
[07. 03. 2010 14:46|--a------|3077] C:\textures-used.txt
[14. 04. 2010 17:34|--a------|2074] C:\UsbFix.txt
[28. 03. 2010 14:17|--a------|214942] D:\A 001.jpg
[28. 03. 2010 14:18|--a------|226693] D:\A 002.jpg
[28. 03. 2010 14:19|--a------|208930] D:\A 003.jpg
[28. 03. 2010 14:20|--a------|212328] D:\A 004.jpg
[28. 03. 2010 14:21|--a------|250139] D:\A 005.jpg
[28. 03. 2010 14:22|--a------|224452] D:\A 006.jpg
[28. 03. 2010 14:16|--a------|235596] D:\A.jpg
[15. 03. 2010 15:18|--a------|4047680] D:\beton-norma.pdf
[10. 04. 2010 17:38|--a------|82944] D:\Formular - dvojharok 2.doc
[03. 03. 2010 14:34|--a------|95744] D:\Formular - obalka 2.doc
[13. 04. 2010 22:16|--a------|46358528] D:\Prílohy dopl. práce.doc
[14. 04. 2010 16:42|--a------|781909] D:\RSIT.exe
[26. 03. 2010 17:10|--a------|1588224] D:\SteamInstall.msi
[17. 02. 2010 16:35|--a------|3515] F:\config.cfg
[10. 03. 2010 07:41|--a------|75071] F:\ocel drevo - 1zadanie.epw
[15. 03. 2010 15:18|--a------|4047680] F:\beton-norma.pdf
[04. 04. 2010 19:51|--a------|209715200] F:\universe.01x11.part1.rar
[04. 04. 2010 19:21|--a------|157637545] F:\universe.01x11.part2.rar
[03. 03. 2010 14:34|--a------|95744] F:\Formular - obalka 2.doc
[10. 04. 2010 17:38|--a------|82944] F:\Formular - dvojharok 2.doc
[07. 09. 2009 18:57|--a------|15848344] F:\widgetsus.exe
[14. 04. 2010 07:50|--a------|505428] F:\INTEGRA-Dargov, Hyg. filter.emf
[14. 04. 2010 13:19|--a------|118598] F:\INTEGRA-Dargov, Hyg. filter.jpg

################## | Vaccination |

# C:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).
# D:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).
# F:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).

################## | Upload |

Please send the file : C:\UsbFix_Upload_Me_JOYO-135916836A.zip : http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution .

################## | ! End of report # UsbFix V6.103 ! |

OTL

OTL logfile created on: 14. 4. 2010 17:37:02 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Joyo\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d. M. yyyy

1 023,00 Mb Total Physical Memory | 687,00 Mb Available Physical Memory | 67,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 8,01 Gb Free Space | 41,01% Space Free | Partition Type: NTFS
Drive D: | 92,25 Gb Total Space | 20,80 Gb Free Space | 22,55% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1,86 Gb Total Space | 1,35 Gb Free Space | 72,30% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
Drive H: | 3,73 Gb Total Space | 3,73 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: JOYO-135916836A
Current User Name: Joyo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.04.14 17:36:26 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Joyo\Desktop\OTL.exe
PRC - [2010.01.08 01:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2010.01.03 18:07:48 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2009.07.21 14:34:33 | 000,185,089 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2009.05.13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2004.12.19 17:29:43 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010.04.14 17:36:26 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Joyo\Desktop\OTL.exe
MOD - [2004.12.19 17:27:37 | 001,050,624 | R--- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010.03.23 21:07:53 | 000,077,944 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2010.01.08 01:51:02 | 000,380,928 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2010.01.03 18:07:48 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.07.21 14:34:33 | 000,185,089 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2009.05.13 16:48:22 | 000,108,289 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2007.10.11 10:55:14 | 000,122,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)


========== Driver Services (SafeList) ==========

DRV - [2010.03.23 20:34:24 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009.11.25 12:19:02 | 000,056,816 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2009.11.21 04:34:54 | 010,235,968 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009.05.11 10:12:24 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.03.30 10:33:07 | 000,096,104 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2009.02.13 12:35:05 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2007.07.25 03:45:18 | 000,019,968 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2007.07.25 03:45:16 | 000,046,720 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2007.07.25 03:45:12 | 000,012,032 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2007.07.25 03:43:38 | 004,419,584 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.07.25 03:42:34 | 000,201,856 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2007.07.25 03:41:32 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2007.07.25 03:41:26 | 000,020,112 | ---- | M] (Dritek System Inc.) [Kernel | System | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2007.07.24 00:12:00 | 000,988,800 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2007.07.24 00:12:00 | 000,730,112 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2007.07.24 00:12:00 | 000,209,664 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2007.07.23 23:14:00 | 000,876,384 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2007.07.23 23:14:00 | 000,149,123 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2007.07.23 23:14:00 | 000,067,960 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2007.07.23 23:14:00 | 000,055,352 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwhid.sys -- (btwhid)
DRV - [2007.07.23 23:14:00 | 000,037,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2007.07.23 23:13:00 | 000,539,072 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2007.06.21 23:58:32 | 000,547,072 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2007.03.21 23:02:04 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007.02.24 15:42:22 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007.01.23 17:40:20 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006.07.01 23:39:40 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005.01.07 18:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)

IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=302398"
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.2
FF - prefs.js..extensions.enabledItems: pdfforge@mybrowserbar.com:1.1.2
FF - prefs.js..extensions.enabledItems: searchsettings@spigot.com:1.2.3
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.2
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_result ... 2.0.0.2&q="

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.06 15:48:33 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.14 10:22:18 | 000,000,000 | ---D | M]

[2010.03.07 12:14:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Extensions
[2010.04.13 21:43:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\extensions
[2010.03.27 15:02:48 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2010.04.08 22:14:28 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010.03.08 17:15:33 | 000,002,055 | ---- | M] () -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\searchplugins\daemon-search.xml
[2010.04.11 00:51:35 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\searchplugins\icqplugin-1.xml
[2010.04.03 14:18:08 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\searchplugins\icqplugin-2.xml
[2010.02.03 15:37:50 | 000,000,947 | ---- | M] () -- C:\Documents and Settings\Joyo\Application Data\Mozilla\Firefox\Profiles\s3pewq4p.default\searchplugins\icqplugin.xml
[2010.04.13 21:43:13 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2007.03.10 01:16:44 | 000,189,496 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
[2010.01.16 02:50:40 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.01.16 02:50:40 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.01.16 02:50:40 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.01.16 02:50:40 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.01.16 02:50:40 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2010.04.14 17:21:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (FDMIECookiesBHO Class) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll ()
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Spigot, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [DAEMON Tools Lite] D:\Programy\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Akcelerátor spuštění AutoCADu.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\Joyo\Start Menu\Programs\Startup\Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.254
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.03.07 11:28:42 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 17:34:37 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 17:34:37 | 000,000,000 | RHSD | M] - D:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 17:34:38 | 000,000,000 | RHSD | M] - F:\autorun.inf -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.04.14 17:36:26 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Joyo\Desktop\OTL.exe
[2010.04.14 17:34:37 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2010.04.14 17:27:43 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 17:08:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.04.14 17:08:28 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.04.14 17:08:28 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.04.14 17:08:28 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.04.14 17:08:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.04.14 17:06:44 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010.04.14 17:06:29 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.04.14 16:42:47 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.14 16:42:46 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.14 13:38:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010.04.14 13:17:19 | 000,118,784 | RHS- | C] (bpbekvmm) -- C:\Documents and Settings\Joyo\Application Data\jlwcbb.exe
[2010.04.14 10:22:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\My Documents\My Widgets
[2010.04.14 10:22:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\Yahoo
[2010.04.14 10:22:09 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2010.04.13 17:38:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\DivX
[2010.04.12 20:40:27 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Joyo\My Documents\My Videos
[2010.04.12 20:40:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2010.04.12 20:38:50 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2010.04.12 20:38:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DivX
[2010.04.12 09:27:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\U3
[2010.04.11 20:31:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Desktop\janka
[2010.04.10 23:16:49 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Joyo\UserData
[2010.04.08 22:15:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\dwhelper
[2010.04.06 14:42:44 | 000,000,000 | ---D | C] -- C:\Program Files\Traction Software
[2010.04.06 01:10:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\Free Download Manager
[2010.04.06 01:10:29 | 000,000,000 | ---D | C] -- C:\Program Files\Free Download Manager
[2010.04.06 01:09:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\My Documents\New Folder
[2010.04.06 00:01:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Bluetooth Software
[2010.04.06 00:01:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\My Documents\Bluetooth Exchange Folder
[2010.04.06 00:01:27 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2010.04.05 23:59:08 | 000,149,123 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwdndis.sys
[2010.04.05 23:59:08 | 000,106,557 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\btw_ci.dll
[2010.04.05 23:59:08 | 000,067,960 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwusb.sys
[2010.04.05 23:59:08 | 000,055,352 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwhid.sys
[2010.04.05 23:59:08 | 000,037,424 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btport.sys
[2010.04.05 23:59:07 | 000,876,384 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btkrnl.sys
[2010.04.05 23:59:07 | 000,539,072 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btaudio.sys
[2010.04.05 23:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\WIDCOMM
[2010.04.02 16:20:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\My Documents\NeroVision
[2010.03.31 19:35:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\Ahead
[2010.03.31 19:34:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\Ahead
[2010.03.31 19:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\Nero
[2010.03.31 19:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Ahead
[2010.03.31 03:58:24 | 000,353,592 | ---- | C] (DivX, Inc.) -- C:\WINDOWS\System32\DivXControlPanelApplet.cpl
[2010.03.28 14:43:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\Help
[2010.03.28 14:43:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\Help
[2010.03.28 11:17:22 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_42.dll
[2010.03.28 11:17:21 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dcsx_42.dll
[2010.03.28 11:17:21 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx11_42.dll
[2010.03.28 11:17:20 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_42.dll
[2010.03.28 11:17:20 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_42.dll
[2010.03.28 11:17:19 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_41.dll
[2010.03.28 11:17:19 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_41.dll
[2010.03.28 11:17:18 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_41.dll
[2010.03.28 11:17:16 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_40.dll
[2010.03.28 11:17:16 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_40.dll
[2010.03.28 11:17:16 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_40.dll
[2010.03.28 11:17:13 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_39.dll
[2010.03.28 11:17:13 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_39.dll
[2010.03.28 11:17:12 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_39.dll
[2010.03.28 11:17:10 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_38.dll
[2010.03.28 11:17:10 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_38.dll
[2010.03.28 11:17:09 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_38.dll
[2010.03.28 11:17:07 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_37.dll
[2010.03.28 11:17:07 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_37.dll
[2010.03.28 11:17:07 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_37.dll
[2010.03.28 11:17:06 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_36.dll
[2010.03.28 11:17:06 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_36.dll
[2010.03.28 11:17:06 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_36.dll
[2010.03.28 11:17:03 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_35.dll
[2010.03.28 11:17:03 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_35.dll
[2010.03.28 11:17:02 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_35.dll
[2010.03.28 11:17:01 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_34.dll
[2010.03.28 11:17:01 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_34.dll
[2010.03.28 11:17:01 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_34.dll
[2010.03.28 11:16:59 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_33.dll
[2010.03.28 11:16:59 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_33.dll
[2010.03.28 11:16:57 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_33.dll
[2010.03.28 11:16:55 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll
[2010.03.28 11:16:43 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2010.03.28 11:16:42 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2010.03.27 20:56:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\Search Settings
[2010.03.27 20:56:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\pdfforge
[2010.03.27 15:53:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\PDFCreator
[2010.03.27 15:50:52 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2010.03.27 15:50:51 | 000,000,000 | ---D | C] -- C:\Program Files\pdfforge Toolbar
[2010.03.27 15:50:17 | 000,137,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSMAPI32.OCX
[2010.03.27 15:50:16 | 000,662,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSCOMCT2.OCX
[2010.03.27 15:50:14 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSMPIDE.DLL
[2010.03.27 15:50:13 | 000,000,000 | ---D | C] -- C:\Program Files\PDFCreator
[2010.03.27 15:21:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2010.03.27 15:21:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-us
[2010.03.27 15:21:43 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2010.03.27 15:21:13 | 000,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2010.03.27 15:15:36 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2010.03.27 15:01:52 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ7.1
[2010.03.26 18:40:01 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2010.03.26 18:39:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\SystemRequirementsLab
[2010.03.26 18:39:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2010.03.26 17:54:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010.03.26 17:54:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010.03.26 17:53:57 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010.03.26 17:53:57 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.03.26 17:53:57 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.03.26 17:53:57 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.03.26 17:53:57 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.03.26 17:53:40 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2010.03.26 17:52:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\Sun
[2010.03.26 17:41:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\skypePM
[2010.03.26 08:13:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2010.03.24 11:32:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Desktop\programy
[2010.03.23 22:42:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\My Documents\ICQ
[2010.03.23 22:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\ICQ6Toolbar
[2010.03.23 22:14:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ICQ
[2010.03.23 22:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\ICQ
[2010.03.23 22:12:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\AOL
[2010.03.23 22:08:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\Adobe
[2010.03.23 21:22:49 | 000,090,112 | ---- | C] (MindVision Software) -- C:\WINDOWS\unvise32.exe
[2010.03.23 21:09:42 | 000,307,200 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUn0405.exe
[2010.03.23 21:07:01 | 000,000,000 | ---D | C] -- C:\Program Files\AnswerWorks 4.0
[2010.03.23 21:03:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\Autodesk
[2010.03.23 21:03:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Application Data\Autodesk
[2010.03.23 21:03:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2010.03.23 21:01:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Autodesk Shared
[2010.03.23 21:00:51 | 000,000,000 | ---D | C] -- C:\Program Files\Autodesk
[2010.03.23 20:53:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010.03.23 20:53:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2010.03.23 20:53:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010.03.23 20:52:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010.03.23 20:49:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Joyo\Local Settings\Application Data\Microsoft Help
[2010.03.23 20:49:21 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2010.03.23 20:36:23 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.03.23 20:31:04 | 000,737,280 | ---- | C] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002.exe
[2010.03.18 09:48:01 | 000,000,000 | ---D | C] -- C:\Program Files\CONEXANT
[2010.03.18 09:47:17 | 000,988,800 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\HSF_DPV.sys
[2010.03.18 09:47:17 | 000,730,112 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\HSF_CNXT.sys
[2010.03.18 09:47:17 | 000,209,664 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\drivers\HSFHWAZL.sys
[2010.03.18 09:47:17 | 000,176,128 | ---- | C] (Conexant Systems, Inc.) -- C:\WINDOWS\System32\UCI32M16.dll
[2010.03.18 09:47:17 | 000,094,208 | ---- | C] (Conexant) -- C:\WINDOWS\System32\mdmxsdk.dll
[2010.03.08 17:11:30 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\implode.dll
[2010.03.07 11:32:17 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010.03.07 11:32:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010.03.07 11:32:03 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010.03.07 11:32:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.04.14 17:36:44 | 000,514,160 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.04.14 17:36:44 | 000,436,402 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.14 17:36:44 | 000,068,854 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.14 17:36:26 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Joyo\Desktop\OTL.exe
[2010.04.14 17:34:38 | 000,002,651 | ---- | M] () -- C:\UsbFix_Upload_Me_JOYO-135916836A.zip
[2010.04.14 17:32:04 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 17:32:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 17:31:59 | 1072,611,328 | -HS- | M] () -- C:\hiberfil.sys
[2010.04.14 17:31:10 | 003,932,160 | ---- | M] () -- C:\Documents and Settings\Joyo\ntuser.dat
[2010.04.14 17:27:19 | 001,777,501 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\UsbFix.exe
[2010.04.14 17:21:20 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.14 17:21:19 | 000,272,291 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010.04.14 17:21:04 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.04.14 16:59:12 | 003,915,064 | R--- | M] () -- C:\Documents and Settings\Joyo\Desktop\ComboFix.exe
[2010.04.14 13:45:23 | 000,000,552 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.04.14 13:45:23 | 000,000,315 | -HS- | M] () -- C:\boot.ini
[2010.04.14 13:17:19 | 000,118,784 | RHS- | M] (bpbekvmm) -- C:\Documents and Settings\Joyo\Application Data\jlwcbb.exe
[2010.04.14 10:22:36 | 000,000,734 | ---- | M] () -- C:\Documents and Settings\Joyo\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
[2010.04.14 10:22:15 | 000,000,786 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Widgets.lnk
[2010.04.13 22:17:45 | 008,186,549 | ---- | M] () -- C:\Prílohy dopl. práce.zip
[2010.04.13 17:54:29 | 000,002,083 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2010.04.13 13:36:19 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.12 20:40:27 | 000,001,466 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\DivX Movies.lnk
[2010.04.08 20:11:59 | 000,027,074 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\obalka3.pdf
[2010.04.08 20:06:40 | 000,027,114 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\obalka2.pdf
[2010.04.06 21:55:35 | 000,214,289 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\VYKAZ.pdf
[2010.04.06 21:52:15 | 000,192,704 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\PODORYS.pdf
[2010.04.06 21:51:27 | 000,187,039 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\SITUACIA.pdf
[2010.04.06 14:35:20 | 000,000,166 | ---- | M] () -- C:\Documents and Settings\Joyo\Application Data\mainhst.zgh
[2010.04.05 12:59:38 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\Adobe Photoshop 7.0 CE.lnk
[2010.04.02 16:21:48 | 000,043,062 | ---- | M] () -- C:\Documents and Settings\Joyo\My Documents\UserImages.bmp
[2010.04.01 11:28:13 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.04.01 08:06:31 | 000,215,950 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\1NP.pdf
[2010.03.31 20:59:27 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.03.31 19:34:56 | 000,002,367 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk
[2010.03.31 19:34:56 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Nero Home.lnk
[2010.03.31 03:58:24 | 000,353,592 | ---- | M] (DivX, Inc.) -- C:\WINDOWS\System32\DivXControlPanelApplet.cpl
[2010.03.30 23:17:29 | 004,272,680 | -H-- | M] () -- C:\Documents and Settings\Joyo\Local Settings\Application Data\IconCache.db
[2010.03.28 21:41:54 | 000,396,425 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\garaz.pdf
[2010.03.27 15:42:46 | 000,100,024 | ---- | M] () -- C:\Documents and Settings\Joyo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010.03.27 15:29:59 | 000,347,400 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.03.27 00:23:49 | 000,000,575 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\Counter Strike 1.6.lnk
[2010.03.26 17:53:44 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010.03.26 17:53:44 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010.03.26 17:53:44 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010.03.26 17:53:44 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2010.03.26 17:53:43 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll
[2010.03.26 17:41:51 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.03.26 00:39:45 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Joyo\ntuser.ini
[2010.03.24 11:32:22 | 000,000,010 | ---- | M] () -- C:\CONFIG.SYS
[2010.03.24 11:12:12 | 000,018,944 | ---- | M] () -- C:\Documents and Settings\Joyo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.03.23 21:12:00 | 000,000,986 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2010.03.23 21:07:18 | 000,001,959 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Akcelerátor spuštění AutoCADu.lnk
[2010.03.23 20:40:37 | 000,000,206 | ---- | M] () -- C:\Documents and Settings\Joyo\My Documents\cc_20100323_194035.reg
[2010.03.23 20:38:06 | 000,000,482 | ---- | M] () -- C:\Documents and Settings\Joyo\My Documents\cc_20100323_193803.reg
[2010.03.23 20:36:43 | 000,045,266 | ---- | M] () -- C:\Documents and Settings\Joyo\My Documents\cc_20100323_193639.reg
[2010.03.23 20:36:25 | 000,001,548 | ---- | M] () -- C:\Documents and Settings\Joyo\Desktop\CCleaner.lnk
[2010.03.23 20:34:24 | 000,691,696 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.03.23 20:30:38 | 000,000,424 | ---- | M] () -- C:\WINDOWS\zipgenius.xml
[2010.03.23 20:30:35 | 000,737,280 | ---- | M] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.04.14 17:34:38 | 000,002,651 | ---- | C] () -- C:\UsbFix_Upload_Me_JOYO-135916836A.zip
[2010.04.14 17:27:16 | 001,777,501 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\UsbFix.exe
[2010.04.14 17:08:28 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.04.14 17:08:28 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.04.14 17:08:28 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.04.14 17:08:28 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.04.14 17:08:28 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.04.14 16:58:47 | 003,915,064 | R--- | C] () -- C:\Documents and Settings\Joyo\Desktop\ComboFix.exe
[2010.04.14 13:46:18 | 1072,611,328 | -HS- | C] () -- C:\hiberfil.sys
[2010.04.14 10:22:36 | 000,000,734 | ---- | C] () -- C:\Documents and Settings\Joyo\Start Menu\Programs\Startup\Yahoo! Widgets.lnk
[2010.04.14 10:22:15 | 000,000,786 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Yahoo! Widgets.lnk
[2010.04.13 22:17:35 | 008,186,549 | ---- | C] () -- C:\Prílohy dopl. práce.zip
[2010.04.12 20:40:27 | 000,001,466 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\DivX Movies.lnk
[2010.04.08 20:11:58 | 000,027,074 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\obalka3.pdf
[2010.04.08 20:06:39 | 000,027,114 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\obalka2.pdf
[2010.04.06 21:55:33 | 000,214,289 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\VYKAZ.pdf
[2010.04.06 21:52:13 | 000,192,704 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\PODORYS.pdf
[2010.04.06 21:51:24 | 000,187,039 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\SITUACIA.pdf
[2010.04.06 14:25:10 | 000,044,098 | ---- | C] () -- C:\Documents and Settings\Joyo\usrlgo.bmp
[2010.04.05 23:57:11 | 000,000,166 | ---- | C] () -- C:\Documents and Settings\Joyo\Application Data\mainhst.zgh
[2010.04.05 12:59:38 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\Adobe Photoshop 7.0 CE.lnk
[2010.04.02 16:21:48 | 000,043,062 | ---- | C] () -- C:\Documents and Settings\Joyo\My Documents\UserImages.bmp
[2010.04.01 11:28:13 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010.04.01 08:06:28 | 000,215,950 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\1NP.pdf
[2010.03.31 20:59:27 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.03.31 19:34:56 | 000,002,367 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nero StartSmart.lnk
[2010.03.31 19:34:56 | 000,002,271 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Nero Home.lnk
[2010.03.28 21:41:51 | 000,396,425 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\garaz.pdf
[2010.03.27 15:50:16 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2010.03.27 15:22:29 | 000,201,488 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010.03.27 00:22:47 | 000,000,575 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\Counter Strike 1.6.lnk
[2010.03.26 18:41:31 | 000,010,284 | ---- | C] () -- C:\Documents and Settings\Joyo\hs_err_pid1536.log
[2010.03.26 17:41:51 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2010.03.26 17:11:28 | 000,002,083 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2010.03.23 21:12:00 | 000,000,986 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2010.03.23 21:07:18 | 000,001,959 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Akcelerátor spuštění AutoCADu.lnk
[2010.03.23 20:40:36 | 000,000,206 | ---- | C] () -- C:\Documents and Settings\Joyo\My Documents\cc_20100323_194035.reg
[2010.03.23 20:38:04 | 000,000,482 | ---- | C] () -- C:\Documents and Settings\Joyo\My Documents\cc_20100323_193803.reg
[2010.03.23 20:36:41 | 000,045,266 | ---- | C] () -- C:\Documents and Settings\Joyo\My Documents\cc_20100323_193639.reg
[2010.03.23 20:36:25 | 000,001,548 | ---- | C] () -- C:\Documents and Settings\Joyo\Desktop\CCleaner.lnk
[2010.03.23 20:34:24 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2010.03.18 09:47:17 | 000,144,201 | ---- | C] () -- C:\WINDOWS\System32\drivers\HSFProf.cty
[2010.03.08 17:14:38 | 003,932,160 | ---- | C] () -- C:\Documents and Settings\Joyo\ntuser.dat
[2010.03.07 15:38:15 | 000,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2010.03.07 11:53:54 | 000,018,944 | ---- | C] () -- C:\Documents and Settings\Joyo\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.03.07 11:38:48 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2010.03.07 11:33:06 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\Joyo\ntuser.dat.LOG
[2010.03.07 11:33:06 | 000,000,178 | -HS- | C] () -- C:\Documents and Settings\Joyo\ntuser.ini
[2007.04.01 09:00:28 | 002,842,624 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2007.04.01 08:41:52 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2005.10.14 12:56:50 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2005.10.14 12:56:50 | 000,921,600 | ---- | C] () -- C:\WINDOWS\System32\VorbisEnc.dll
[2005.10.14 12:56:50 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2005.10.14 12:56:50 | 000,344,064 | ---- | C] () -- C:\WINDOWS\System32\xvid.dll
[2005.10.14 12:56:50 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2005.10.14 12:56:50 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2005.10.14 12:56:50 | 000,155,136 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2005.10.14 12:56:50 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2005.02.17 12:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005.02.17 12:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2004.12.19 17:31:09 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2004.12.19 17:29:55 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
< End of report >

Walky
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 102
Registrován: 11 kvě 2009 19:53

Re: TR/Crypt.ZPACK.Gen trojan

#4 Příspěvek od Walky »

Extras

OTL Extras logfile created on: 14. 4. 2010 17:37:02 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\Joyo\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 0000041B | Country: Slovakia | Language: SKY | Date Format: d. M. yyyy

1 023,00 Mb Total Physical Memory | 687,00 Mb Available Physical Memory | 67,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 90,00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,53 Gb Total Space | 8,01 Gb Free Space | 41,01% Space Free | Partition Type: NTFS
Drive D: | 92,25 Gb Total Space | 20,80 Gb Free Space | 22,55% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 1,86 Gb Total Space | 1,35 Gb Free Space | 72,30% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
Drive H: | 3,73 Gb Total Space | 3,73 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded

Computer Name: JOYO-135916836A
Current User Name: Joyo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.0\ICQ.exe" = C:\Program Files\ICQ7.0\ICQ.exe:*:Enabled:ICQ7 -- File not found
"C:\Program Files\ICQ7.0\aolload.exe" = C:\Program Files\ICQ7.0\aolload.exe:*:Enabled:aolload.exe -- File not found
"C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"D:\Hry\Steam\Steam.exe" = D:\Hry\Steam\Steam.exe:*:Enabled:Steam -- (Valve Corporation)
"C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)
"D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe" = D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2 -- ()
"D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe" = D:\Hry\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{242FFF00-5F19-4E5E-97F5-95C3DA9939A7}" = ESS Energie Indikator
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2FC099BD-AC9B-33EB-809C-D332E1B27C40}" = Microsoft .NET Framework 3.5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{368E88DE-E5D2-83E7-11AF-23375B581051}" = Nero 7 Demo
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5783F2D7-5001-0405-0002-0060B0CE6BBA}" = AutoCAD 2007 - Český
"{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5CACC829-8351-4D47-9CC1-2E20EA9FE38F}" = Allplan Holzbau
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{67DAF4C3-58CA-4EDB-B734-D97684FC379E}" = General Runtime Files for Nemetschek Allplan 2009
"{71BFC818-0CED-42D6-9C87-5142918957EE}" = ICQ7.1
"{7262D0C8-41CC-4F75-8383-A6C7C61D7FC6}" = Nemetschek SoftLock 2006
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7F947BFE-C2DF-4779-9909-5BEE746BD0C4}" = Microsoft .NET Framework 2.0 Language Pack - CSY
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{90120000-0010-041B-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Slovak) 12
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0015-041B-0000-0000000FF1CE}" = Microsoft Office Access MUI (Slovak) 2007
"{90120000-0016-041B-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Slovak) 2007
"{90120000-0018-041B-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Slovak) 2007
"{90120000-0019-041B-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Slovak) 2007
"{90120000-001A-041B-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Slovak) 2007
"{90120000-001B-041B-0000-0000000FF1CE}" = Microsoft Office Word MUI (Slovak) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040E-0000-0000000FF1CE}" = Microsoft Office Proof (Hungarian) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-041B-0000-0000000FF1CE}" = Microsoft Office Proofing (Slovak) 2007
"{90120000-0044-041B-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Slovak) 2007
"{90120000-006E-041B-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Slovak) 2007
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{AC76BA86-7AD7-1029-7B44-A93000000001}" = Adobe Reader 9.3.1 - Czech
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BAED3957-C271-4670-A50D-8D7438701917}" = Nemetschek Allplan 2009
"{BB9B18A0-0CB2-11DF-8A39-0800200C9A66}" = Allplan Content 2009
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{E031338C-839D-4EDD-9537-99B653C39D81}" = Autodesk MapGuide(R) Viewer ActiveX Control Release 6.5
"{EC3B598C-1151-4191-B5B4-A9072ADE6259}_is1" = ZipGenius 6 (6.0.3.1150)
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F70D5D8C-C1AF-40B3-9E47-3BB5F19EEA3A}" = Atheros for Acer Driver 5.3.0.56_Foxconn Installation Program
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CCleaner" = CCleaner
"CINEMA 4D Release 10 Architecture Edition" = CINEMA 4D Release 10 Architecture Edition
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"DivX Setup.divx.com" = DivX Setup
"EVEREST Home Edition_is1" = EVEREST Home Edition v2.20
"Free Download Manager_is1" = Free Download Manager 3.0
"HijackThis" = HijackThis 2.0.2
"ICQToolbar" = ICQ Toolbar
"LManager" = Launch Manager
"Microsoft .NET Framework 2.0 Language Pack - CSY" = Microsoft .NET Framework 2.0 Language Pack - CSY
"Microsoft .NET Framework 3.5" = Microsoft .NET Framework 3.5
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NEXIS32 3.40.13" = IDA NEXIS 32 rel. 3.40
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"PROPLUS" = Microsoft Office Professional Plus 2007
"PVexpress 3.0_is1" = PVexpress 3.0
"ShockwaveFlash" = Macromedia Flash Player 8
"Steam App 10180" = Call of Duty: Modern Warfare 2
"Steam App 10190" = Call of Duty: Modern Warfare 2 - Multiplayer
"Steam App 440" = Team Fortress 2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Totalcmd" = Total Commander (Remove or Repair)
"TSOLexpress 1.0_is1" = TSOLexpress 1.0
"Video Card Stability Test" = Video Card Stability Test
"VLC media player" = VLC media player 1.0.5
"WIC" = Windows Imaging Component
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Widget Engine" = Yahoo! Widgets
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 23. 3. 2010 14:25:09 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 23. 3. 2010 14:46:39 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 24. 3. 2010 18:07:01 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 25. 3. 2010 4:25:46 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: The server name or address could not be resolved

Error - 25. 3. 2010 18:43:24 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 25. 3. 2010 19:39:08 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 26. 3. 2010 2:12:30 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 26. 3. 2010 14:54:28 | Computer Name = JOYO-135916836A | Source = LoadPerf | ID = 3006
Description = Unable to read the performance counter strings of the 01b language
ID. The Win32 status returned by the call is the first DWORD in Data section.

Error - 26. 3. 2010 18:22:34 | Computer Name = JOYO-135916836A | Source = Application Error | ID = 1000
Description = Faulting application cstrike.exe, version 1.1.1.1, faulting module
cstrike.exe, version 1.1.1.1, fault address 0x00002783.

Error - 27. 3. 2010 4:52:58 | Computer Name = JOYO-135916836A | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/m ... ootseq.txt>
with error: This operation returned because the timeout period expired.

[ System Events ]
Error - 1. 4. 2010 7:38:58 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 147.232.162.200
on the Network Card with network address 001DD968892E.

Error - 1. 4. 2010 7:41:04 | Computer Name = JOYO-135916836A | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
1240-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{431E69FF-A23A-4718-B. The master browser is stopping or an election
is being forced.

Error - 1. 4. 2010 8:20:59 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 147.232.163.253
on the Network Card with network address 001DD968892E.

Error - 1. 4. 2010 8:24:14 | Computer Name = JOYO-135916836A | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
PICITUO-PC that believes that it is the master browser for the domain on transport
NetBT_Tcpip_{431E69FF-A23A-471. The master browser is stopping or an election is
being forced.

Error - 1. 4. 2010 8:31:10 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 147.232.162.230
on the Network Card with network address 001DD968892E.

Error - 1. 4. 2010 8:50:22 | Computer Name = JOYO-135916836A | Source = MRxSmb | ID = 8003
Description = The master browser has received a server announcement from the computer
DELL that believes that it is the master browser for the domain on transport NetBT_Tcpip_{431E69FF-A23A-4718-BE78.
The
master browser is stopping or an election is being forced.

Error - 1. 4. 2010 17:23:52 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 147.232.162.230
on the Network Card with network address 001DD968892E.

Error - 2. 4. 2010 0:48:40 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.117 on
the Network Card with network address 001DD968892E.

Error - 2. 4. 2010 3:45:25 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.117 on
the Network Card with network address 001DD968892E.

Error - 3. 4. 2010 11:11:00 | Computer Name = JOYO-135916836A | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.117 on
the Network Card with network address 001DD968892E.


< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: TR/Crypt.ZPACK.Gen trojan

#5 Příspěvek od Caroprd111 »

Obrázek Tohle znáte
F:\MILEGEJ//kitic.exe


Obrázek Soubor C:\UsbFix_Upload_Me_JOYO-135916836A.zip prosím uložte na http://chiquitine.changelog.fr/Sample/Upload.php


Obrázek Vložte sem log C:\ComboFix.txt

Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!
Obrázek

Odpovědět