Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosim o kontrolu logu a popis odstraneni problemu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#16 Příspěvek od server123 »

Avanger:
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "C:\atapi.sys|C:\WINDOWS\system32\drivers\atapi.sys" completed successfully.

Completed script processing.

*******************

Finished! Terminate.

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#17 Příspěvek od server123 »

OTL:

Kód: Vybrat vše

All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-1060284298-1425521274-725345543-1006\Software\Microsoft\Windows\CurrentVersion\Run\\SpybotSD TeaTimer deleted successfully.
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy\Recovery folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy\Logs folder moved successfully.
C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy folder moved successfully.
C:\Program Files\Spybot - Search & Destroy\Help folder moved successfully.
C:\Program Files\Spybot - Search & Destroy folder moved successfully.
ADS C:\Documents and Settings\All Users\Dokumenty\otazky - rozhovor Pixel.doc:AFP_AfpInfo deleted successfully.
ADS C:\Documents and Settings\All Users\Data aplikací\TEMP:D282699C deleted successfully.
C:\WINDOWS\system32\CONFIG.TMP deleted successfully.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 3837872 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: Leionek
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1204571 bytes
->FireFox cache emptied: 27820217 bytes
->Flash cache emptied: 837 bytes
 
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: Miriamka
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 177496116 bytes
->FireFox cache emptied: 75080213 bytes
->Flash cache emptied: 11694 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
User: restore
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->FireFox cache emptied: 48616449 bytes
->Flash cache emptied: 593 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1139202 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 118272 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 269595 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 320,00 mb
 
 
[EMPTYFLASH]
 
User: Administrator
 
User: All Users
 
User: Default User
 
User: Leionek
->Flash cache emptied: 0 bytes
 
User: LocalService
 
User: Miriamka
->Flash cache emptied: 0 bytes
 
User: NetworkService
 
User: restore
->Flash cache emptied: 0 bytes
 
Total Flash Files Cleaned = 0,00 mb
 
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
 
OTL by OldTimer - Version 3.2.4.1 log created on 05032010_211939

Files\Folders moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#18 Příspěvek od server123 »

oba dva chteli restart, po restartu a spusteni user profilu se to cca 5 minut zasekne, nefunguje lista se start, nefunguji okna, nescroluje text, firefox nenacita ...

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Prosim o kontrolu logu a popis odstraneni problemu

#19 Příspěvek od stell »

ok
vloz prikaz do start-spustit a log vloz sem
cmd /c mbr.exe -t >log.txt&start log.txt
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#20 Příspěvek od server123 »

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll nvatabus.sys
kernel: MBR read successfully
user & kernel MBR OK

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Prosim o kontrolu logu a popis odstraneni problemu

#21 Příspěvek od stell »

oba dva chteli restart, po restartu a spusteni user profilu se to cca 5 minut zasekne, nefunguje lista se start, nefunguji okna, nescroluje text, firefox nenacita ...
ako teda parcujes ak nic nefunguje??Firefox uz ti blbol dlhsie
Error - 3.5.2010 12:02:07 | Computer Name = MAXIM | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace firefox.exe, verze 1.9.2.3743, zablokovaný modul
hungapp, verze 0.0.0.0, adresa bloku 0x00000000.
Aj AVAST ma poskodeny driver-
1:Odinstalujes FireFox aj AVAST-a preinstalujes,
Vycisti pc poriadne CCleanerom
a potom spravis skan s G_MER
http://www.viry.cz/forum/viewtopic.php?f=29&t=62878
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#22 Příspěvek od server123 »

stell píše: ako teda parcujes ak nic nefunguje??Firefox uz ti blbol dlhsie
po tech peti minutach problikne vse na co jsem kliknul a pak to jede v pohode.

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Prosim o kontrolu logu a popis odstraneni problemu

#23 Příspěvek od stell »

no dobre sprav co som napisal,
G-Mer bude trvat dlhsie,takze az zajtra sa na to pozriem,takze po G-Mer este spustis Malwarebytes-komplet skan co najde zmaz a log vloz sem
Stiahnes>>Malwarebytes' Anti-Malware stiahnut-nainstalovat -aktualizovat-
sprav komplet skan,co najde zmazat-,log vloz sem,
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#24 Příspěvek od server123 »

uninstal Avast
uninstal FireFox
CCleaner (smudlilo to neco pres hodinu)

Gmer:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-03 23:03:14
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\restore\LOCALS~1\Temp\axtdypod.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xF6160360, 0x24BB1D, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\internet explorer\iexplore.exe[1252] ole32.dll!OleLoadFromStream 77519C85 5 Bytes JMP 7E2A524C C:\WINDOWS\system32\SHDOCVW.dll (Shell Doc Object and Control Library/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x8F 0x88 0xA0 0xA9 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x1D 0xC5 0x2A ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x84 0xD6 0x6D 0x41 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6C 0x1D 0xAD 0x54 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x1D 0xC5 0x2A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@d0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x84 0xD6 0x6D 0x41 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6C 0x1D 0xAD 0x54 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x68 0x1D 0xC5 0x2A ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@d0 1
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x84 0xD6 0x6D 0x41 ...

---- Files - GMER 1.0.15 ----

File C:\Documents and Settings\restore\Cookies\restore@cnet[1].txt 1151 bytes
File C:\Documents and Settings\restore\Cookies\restore@scorecardresearch[1].txt 107 bytes
File C:\Documents and Settings\restore\Cookies\restore@tase[2].txt 231 bytes
File C:\Documents and Settings\restore\Cookies\restore@teracent[1].txt 123 bytes
File C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\2J45KLIP\3001-8022_4-10804572[1].html 12109 bytes
File C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\Q9IL4JU3\ad[1].11&esc=0&rcu=[clicktracking] 3733 bytes
File C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\Q9IL4JU3\search[1].htm 6439 bytes

---- EOF - GMER 1.0.15 ----

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#25 Příspěvek od server123 »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4063

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

3.5.2010 23:28:00
mbam-log-2010-05-03 (23-28-00).txt

Typ skenu: Úplný sken (C:\|)
Skenované objekty: 182296
Uplynulý čas: 22 minuta(y), 33 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 2

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\System Volume Information\_restore{BCEB004B-6C5E-4525-886C-BDD7AE16CC28}\RP197\A0034814.exe (Adware.WhenU) -> No action taken.
C:\Documents and Settings\Miriamka\Data aplikací\avdrn.dat (Malware.Trace) -> No action taken.

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Prosim o kontrolu logu a popis odstraneni problemu

#26 Příspěvek od stell »

co nasiel Malwarebytes trebalo dat zmazat,tak ako som napisal
Spust OTL
do okna vlastni skenovani/opravy vloz scipt-klik RunFix.log po restarte vloz sem

Kód: Vybrat vše

:files
C:\Documents and Settings\restore\Cookies\restore@cnet[1].txt 
C:\Documents and Settings\restore\Cookies\restore@scorecardresearch[1].txt
C:\Documents and Settings\restore\Cookies\restore@tase[2].txt 231
C:\Documents and Settings\restore\Cookies\restore@teracent[1].txt
C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\2J45KLIP
C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\Q9IL4JU3
C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\Q9IL4JU3
C:\Documents and Settings\Miriamka\Data aplikací\avdrn.dat
C:\System Volume Information\_restore{BCEB004B-6C5E-4525-886C-BDD7AE16CC28}\RP197\A0034814.exe 
:commands
[EmptyTemp]
:arrow: odinstaluj combofix-start-spustit-vloz prikaz combofix /uninstall
:arrow: aplikujes T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
stale A-enter
:arrow: Stiahnes na plochu TFC
zatvor vsetko co mas otvorene a spust-po skane restart

a napis ako sa chova pc.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#27 Příspěvek od server123 »

OTL:
All processes killed
========== FILES ==========
File\Folder C:\Documents and Settings\restore\Cookies\restore@cnet[1].txt not found.
File\Folder C:\Documents and Settings\restore\Cookies\restore@scorecardresearch[1].txt not found.
File\Folder C:\Documents and Settings\restore\Cookies\restore@tase[2].txt 231 not found.
File\Folder C:\Documents and Settings\restore\Cookies\restore@teracent[1].txt not found.
File\Folder C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\2J45KLIP not found.
C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\Q9IL4JU3 folder moved successfully.
File\Folder C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\Q9IL4JU3 not found.
File\Folder C:\Documents and Settings\Miriamka\Data aplikací\avdrn.dat not found.
File\Folder C:\System Volume Information\_restore{BCEB004B-6C5E-4525-886C-BDD7AE16CC28}\RP197\A0034814.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Leionek
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Miriamka
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: restore
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 3964663 bytes
->FireFox cache emptied: 13343596 bytes
->Flash cache emptied: 593 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 17,00 mb


OTL by OldTimer - Version 3.2.4.1 log created on 05042010_185139

Files\Folders moved on Reboot...
C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\8TENS1AR\afr[1].htm moved successfully.
C:\Documents and Settings\restore\Local Settings\Temporary Internet Files\Content.IE5\8TENS1AR\viewtopic[1].htm moved successfully.

Registry entries deleted on Reboot...

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#28 Příspěvek od server123 »

vypada to ok, jen to petiminutove zatuhnuti pri kazdem startu, restartu nebo loginu usera zustalo. Nabehnou okna, lognu se, pak stihnu jednou dvakrat na neco kliknout a zasekne se to na 5 minut. Pak se to rozjede a zatim to vypada ze to jede ok. Kazdopadne i tak diky, uz se na tom da delat, predtim to neslo vubec :)

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: Prosim o kontrolu logu a popis odstraneni problemu

#29 Příspěvek od stell »

no to znamena ze este to nie je ok,
odinstaluj program
C:\Program Files\Cobian Backup 9
precisti CCleanerom a vloz sem log z RSIT.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

server123
Návštěvník
Návštěvník
Příspěvky: 25
Registrován: 03 kvě 2010 17:32

Re: Prosim o kontrolu logu a popis odstraneni problemu

#30 Příspěvek od server123 »

RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by restore at 2010-05-06 21:25:11
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 85 GB (75%) free of 114 GB
Total RAM: 1023 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:25:18, on 6.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Vista Drive Icon\DrvIcon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\restore\Plocha\RSIT.exe
C:\Program Files\trend micro\restore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1060284298-1425521274-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Miriamka')
O4 - HKUS\S-1-5-21-1060284298-1425521274-725345543-1004\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 (User 'Miriamka')
O4 - HKUS\S-1-5-21-1060284298-1425521274-725345543-1004\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'Miriamka')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/L ... nstall.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 5878 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll [2003-05-12 50376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F156768E-81EF-470C-9057-481BA8380DBA}]
FlashGet GetFlash Class - C:\Program Files\FlashGet\getflash.dll [2007-05-18 163840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - StylerToolBar - C:\Program Files\Styler\TB\StylerTB.dll [2006-05-02 102400]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2006-10-22 7700480]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2006-10-22 86016]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2004-12-20 33792]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-11 417792]
"DrvIcon"=C:\Program Files\Vista Drive Icon\DrvIcon.exe [2008-04-13 49152]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-04-14 2790472]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FlashGet\flashget.exe"="C:\Program Files\FlashGet\flashget.exe:*:Enabled:Flashget"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\The Tale of Despereaux\TalesLauncher.exe"="C:\Program Files\The Tale of Despereaux\TalesLauncher.exe:*:Enabled:TalesLauncher"
"C:\Program Files\The Tale of Despereaux\TalesD.exe"="C:\Program Files\The Tale of Despereaux\TalesD.exe:*:Enabled:Tales"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Konzola Microsoft Management Console"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-05-06 21:25:12 ----D---- C:\Program Files\trend micro
2010-05-06 21:25:11 ----D---- C:\rsit
2010-05-04 21:51:11 ----D---- C:\Program Files\VideoLAN
2010-05-04 21:50:26 ----A---- C:\vlc-1.0.5-win32.exe
2010-05-04 19:10:02 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-05-03 23:03:54 ----D---- C:\Documents and Settings\restore\Data aplikací\Malwarebytes
2010-05-03 23:03:48 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-03 23:03:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-05-03 21:52:42 ----D---- C:\Documents and Settings\restore\Data aplikací\DivX
2010-05-03 21:19:50 ----SHD---- C:\RECYCLER
2010-05-02 21:21:07 ----D---- C:\Program Files\CCleaner
2010-05-02 21:11:52 ----A---- C:\Boot.bak
2010-05-02 21:11:47 ----RASHD---- C:\cmdcons
2010-05-02 21:06:45 ----D---- C:\Documents and Settings\restore\Data aplikací\Macromedia
2010-05-02 21:06:45 ----D---- C:\Documents and Settings\restore\Data aplikací\Adobe
2010-05-02 21:06:34 ----D---- C:\Documents and Settings\restore\Data aplikací\Mozilla
2010-05-02 21:01:35 ----D---- C:\Documents and Settings\restore\Data aplikací\Identities
2010-05-02 20:51:49 ----SD---- C:\Documents and Settings\restore\Data aplikací\Microsoft
2010-05-02 20:51:49 ----ASH---- C:\Documents and Settings\restore\Data aplikací\desktop.ini
2010-05-02 19:29:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Windows Genuine Advantage
2010-05-02 19:27:26 ----D---- C:\WINDOWS\SxsCaPendDel
2010-04-22 21:10:14 ----D---- C:\Program Files\MSXML 4.0
2010-04-21 18:07:58 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-04-21 18:07:57 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-04-21 18:07:57 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-04-21 18:07:57 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-04-21 18:07:57 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-04-21 18:07:57 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-04-21 18:07:56 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-04-21 18:07:56 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-04-21 18:07:56 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-04-21 18:07:56 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-04-21 18:07:56 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-04-21 18:07:56 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-04-21 18:07:55 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2010-04-21 18:07:55 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2010-04-21 18:07:55 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-04-21 18:07:55 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-04-21 18:07:55 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2010-04-21 18:07:55 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-04-21 18:07:54 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2010-04-21 18:07:54 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2010-04-21 18:07:54 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2010-04-21 18:07:54 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-04-21 18:07:53 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2010-04-21 18:07:53 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2010-04-21 18:07:53 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2010-04-21 18:07:53 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2010-04-21 18:07:53 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-04-21 18:07:52 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-04-21 18:07:52 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-04-21 18:07:52 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-04-21 18:07:52 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-04-21 18:07:52 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-04-21 18:07:52 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-04-21 18:07:51 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-04-21 18:07:50 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-04-21 18:07:49 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-04-21 18:07:48 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-04-21 18:07:48 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-04-21 18:07:47 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2010-04-21 18:07:47 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2010-04-21 18:07:47 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-04-21 18:07:47 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-04-21 18:07:45 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2010-04-21 18:07:45 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2010-04-21 18:07:45 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2010-04-21 18:07:45 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-04-21 18:07:44 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2010-04-21 18:07:42 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2010-04-21 18:07:41 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-04-21 18:07:40 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2010-04-21 18:07:40 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-04-21 18:07:40 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-04-21 18:07:39 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-04-21 18:07:39 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-04-21 18:07:38 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-04-21 18:07:38 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2010-04-21 18:07:37 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-04-21 18:07:35 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-04-21 18:07:31 ----D---- C:\WINDOWS\Logs
2010-04-21 18:03:01 ----D---- C:\Program Files\The Tale of Despereaux
2010-04-21 17:13:05 ----A---- C:\WINDOWS\system32\GIF89.DLL
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\WMAFile.dll
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\VB6STKIT.DLL
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\VB6FR.DLL
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\SSubTmr6.dll
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\inetfr.DLL
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\AudioInfos.dll
2010-04-21 17:13:04 ----A---- C:\WINDOWS\system32\AudFile.dll
2010-04-21 17:13:03 ----D---- C:\Program Files\Free Easy Burner
2010-04-21 17:13:03 ----A---- C:\WINDOWS\system32\msxml4r.dll
2010-04-21 17:13:03 ----A---- C:\WINDOWS\system32\msxml4a.dll
2010-04-21 17:13:03 ----A---- C:\WINDOWS\system32\MSCMCFR.DLL
2010-04-21 17:13:03 ----A---- C:\WINDOWS\system32\MFC71.dll
2010-04-21 17:13:03 ----A---- C:\WINDOWS\system32\lame_enc.dll
2010-04-21 17:13:03 ----A---- C:\WINDOWS\system32\CMDLGFR.DLL
2010-04-13 07:08:51 ----N---- C:\WINDOWS\system32\browserchoice.exe

======List of files/folders modified in the last 1 months======

2010-05-06 21:25:15 ----D---- C:\WINDOWS\Prefetch
2010-05-06 21:25:12 ----RD---- C:\Program Files
2010-05-06 20:40:16 ----D---- C:\WINDOWS
2010-05-06 20:39:36 ----D---- C:\Program Files\Cobian Backup 9
2010-05-06 20:38:00 ----D---- C:\WINDOWS\Temp
2010-05-06 16:35:38 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-05-06 09:16:39 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-05-05 22:40:37 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-05 11:19:03 ----A---- C:\WINDOWS\wincmd.ini
2010-05-04 19:10:11 ----D---- C:\WINDOWS\system32\drivers
2010-05-04 19:10:08 ----SHD---- C:\WINDOWS\Installer
2010-05-04 19:10:07 ----D---- C:\WINDOWS\WinSxS
2010-05-04 19:10:02 ----D---- C:\WINDOWS\system32
2010-05-04 19:07:03 ----D---- C:\Program Files\Mozilla Firefox
2010-05-03 19:16:56 ----A---- C:\WINDOWS\system.ini
2010-05-03 19:14:16 ----D---- C:\WINDOWS\AppPatch
2010-05-03 19:14:14 ----D---- C:\Program Files\Common Files
2010-05-02 22:15:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-02 21:21:23 ----D---- C:\WINDOWS\Debug
2010-05-02 21:11:52 ----RASH---- C:\boot.ini
2010-05-02 20:51:48 ----D---- C:\Documents and Settings
2010-05-02 19:43:53 ----D---- C:\WINDOWS\Registration
2010-05-02 19:29:29 ----HD---- C:\WINDOWS\inf
2010-05-02 19:28:12 ----D---- C:\WINDOWS\SoftwareDistribution
2010-05-02 19:17:16 ----SD---- C:\WINDOWS\Tasks
2010-05-02 19:16:24 ----D---- C:\Program Files\smartmontools
2010-04-27 20:16:31 ----A---- C:\WINDOWS\winamp.ini
2010-04-21 18:07:59 ----D---- C:\WINDOWS\system32\DirectX
2010-04-21 18:07:28 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-04-14 08:15:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-04-14 08:15:07 ----HD---- C:\WINDOWS\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-04-14 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-04-14 162768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-04-14 46672]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-04-14 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-04-14 100432]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2007-03-08 4027840]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-04-14 23376]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2007-07-12 96384]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2004-05-17 12928]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2006-10-22 159810]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-04-14 40384]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Odpovědět