
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Trojan-Downloader.Murlo
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- paj
- Vzorný návštěvník
- Příspěvky: 52
- Registrován: 21 zář 2006 18:02
- Bydliště: Havířov
- Kontaktovat uživatele:
Trojan-Downloader.Murlo
PC Tools Spyware Doctor 7.0 mi identifikoval Trojan-Downloader.Murlo, o čemž vydal hlášení (viz příloha). Jelikož mám jen Free verzi, nedovede nákazu odstranit. Prosím, jak mám postupovat? Děkuji.
- Přílohy
-
- Murlo.jpg (85.02 KiB) Zobrazeno 916 x
Spam nechodí po horách, ale po lidech
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo
Zdravím,
Přidej log RSIT http://www.viry.cz/forum/viewtopic.php?f=24&t=81939Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Skener" > Provést rychlý sken > Skenovat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo
Vkládám kopii z SZ
OK, log z MBAM:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Verze databáze: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6.5.2010 19:18:20
mbam-log-2010-05-06 (19-18-20).txt
Typ skenu: Rychlý sken
Skenované objekty: 115911
Uplynulý čas: 10 minuta(y), 49 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Log z RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by paj at 2010-05-06 19:23:46
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (72%) free of 46 GB
Total RAM: 1023 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:23:55, on 6.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program files\Antiviry\AVG9\avgchsvx.exe
E:\Program files\Antiviry\AVG9\avgrsx.exe
E:\Program files\Antiviry\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
E:\Program files\Antiviry\AVG9\avgwdsvc.exe
E:\Program files\Antiviry\AVG9\avgfws9.exe
E:\Program Files\Antiviry\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
E:\Program files\Antihavěť\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
E:\Program files\Antiviry\AVG9\avgemc.exe
E:\Program files\Antiviry\AVG9\avgam.exe
E:\Program files\Antiviry\AVG9\avgnsx.exe
E:\Program files\Antiviry\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\Antiviry\AVG9\avgtray.exe
E:\Program files\Utility\MyClipboard_Exe_3.0.0.0\MyClipboard.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
E:\Program files\Antiviry\AVG9\avgcsrvx.exe
E:\Program files\Internet\Prohlížeče\Opera\Opera.exe
E:\Program files\Explorery\totalcmd\TOTALCMD.EXE
E:\Program files\Antihavěť\RSIT\RSIT.exe
C:\Program Files\trend micro\paj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program files\Antiviry\AVG9\avgssie.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [AVG9_TRAY] E:\PROGRA~1\Antiviry\AVG9\avgtray.exe
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: MyClipboard.lnk = E:\Program files\Utility\MyClipboard_Exe_3.0.0.0\MyClipboard.exe
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přeložit - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - E:\Program Files\Překladače\Verdict Free\etnxp.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - E:\Program Files\Překladače\Verdict Free\etnxp.dll
O9 - Extra 'Tools' menuitem: Internetový překladač... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - E:\Program Files\Překladače\Verdict Free\etnxp.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 9157182156
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program files\Antiviry\AVG9\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - E:\Program files\Antiviry\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - E:\Program files\Antiviry\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - E:\Program files\Antiviry\AVG9\avgfws9.exe
O23 - Service: Browser Defender Update Service - Unknown owner - E:\Program Files\Antiviry\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - E:\Program Files\Antiviry\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - E:\Program Files\Antiviry\Spyware Doctor\pctsSvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - E:\Program files\Antihavěť\Spyware Terminator\sp_rsser.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
--
End of file - 8658 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\ConfigExec.job
C:\WINDOWS\tasks\DataUpload.job
C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\ParetoLogic Registration3.job
C:\WINDOWS\tasks\ParetoLogic Update Version3.job
C:\WINDOWS\tasks\XoftSpySE 2.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - E:\Program files\Antiviry\AVG9\avgssie.dll [2010-05-01 1615200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-07 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-07 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"=E:\PROGRA~1\Antiviry\AVG9\avgtray.exe [2010-05-01 2064736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"=C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
MyClipboard.lnk - E:\Program files\Utility\MyClipboard_Exe_3.0.0.0\MyClipboard.exe
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-30 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-03-03 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=E:\Program Files\Antihavet\SUPERAntiSpyware\SASSEH.DLL []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EditLevel"=0
"NoRun"=0
"NoClose"=0
"NoCommonGroups"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoResolveSearch"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\Program files\Antiviry\AVG9\avgdiagex.exe"="E:\Program files\Antiviry\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"E:\Program files\Antiviry\AVG9\avgam.exe"="E:\Program files\Antiviry\AVG9\avgam.exe:*:Enabled:avgam.exe"
"E:\Program files\Antiviry\AVG9\avgupd.exe"="E:\Program files\Antiviry\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"E:\Program files\Antiviry\AVG9\avgnsx.exe"="E:\Program files\Antiviry\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"E:\Program files\Antiviry\AVG9\avgemc.exe"="E:\Program files\Antiviry\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Konzola Microsoft Management Console"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"E:\Program files\Internet\Prohlížeče\Opera\opera.exe"="E:\Program files\Internet\Prohlížeče\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"E:\Program files\Komunikace\X-lite\x-lite.exe"="E:\Program files\Komunikace\X-lite\x-lite.exe:*:Enabled:X-Lite"
"E:\Program files\Explorery\totalcmd\TOTALCMD.EXE"="E:\Program files\Explorery\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-05-06 19:21:17 ----D---- C:\Program Files\trend micro
2010-05-06 19:21:15 ----D---- C:\rsit
2010-05-06 19:05:08 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-06 13:50:45 ----A---- C:\WINDOWS\BDTSupport.dll
2010-05-06 13:50:44 ----A---- C:\WINDOWS\SGDetectionTool.dll
2010-05-06 13:50:44 ----A---- C:\WINDOWS\PCTBDRes.dll
2010-05-06 13:50:44 ----A---- C:\WINDOWS\PCTBDCore.dll
2010-05-06 13:45:47 ----D---- C:\Program Files\Common Files\PC Tools
2010-05-06 13:45:46 ----D---- C:\Documents and Settings\paj\Data aplikací\PC Tools
2010-05-06 13:45:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Tools
2010-05-05 21:20:18 ----A---- C:\WINDOWS\system32\lsdelete.exe
2010-05-05 18:17:53 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-05 18:17:08 ----D---- C:\Program Files\Lavasoft
2010-05-05 18:17:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-05-05 16:04:23 ----D---- C:\Program Files\Common Files\ParetoLogic
2010-05-05 16:04:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
2010-05-05 15:34:24 ----D---- C:\Documents and Settings\paj\Data aplikací\Spyware Terminator
2010-05-05 15:34:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-05-05 14:52:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-05-05 14:52:29 ----D---- C:\Documents and Settings\paj\Data aplikací\SUPERAntiSpyware.com
2010-05-05 14:50:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-05-05 14:45:01 ----D---- C:\Documents and Settings\paj\Data aplikací\VitySoft
2010-05-05 14:12:09 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-05-02 18:53:34 ----D---- C:\Program Files\Google
2010-05-01 16:44:13 ----D---- C:\Documents and Settings\paj\Data aplikací\InfraRecorder
2010-05-01 16:28:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\M-Photo
2010-05-01 16:14:24 ----A---- C:\WINDOWS\system32\TiskProRadost_AlbumMaker_uninstaller.exe
2010-05-01 15:17:51 ----D---- C:\ReFox
2010-04-28 08:51:16 ----D---- C:\Documents and Settings\paj\Data aplikací\Resource Tuner
2010-04-22 13:18:31 ----D---- C:\WINDOWS\Prefetch
2010-04-22 09:01:00 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-04-22 09:00:58 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-04-22 09:00:38 ----D---- C:\Documents and Settings\paj\Data aplikací\TuneUp Software
2010-04-22 08:58:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2010-04-22 08:58:24 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-04-22 07:34:12 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-04-21 16:38:23 ----D---- C:\WINDOWS\pss
2010-04-21 14:20:19 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-04-21 13:44:16 ----A---- C:\Answer.txt
2010-04-21 13:05:27 ----A---- C:\mbam-error.txt
2010-04-21 13:04:18 ----D---- C:\Documents and Settings\paj\Data aplikací\Malwarebytes
2010-04-21 13:04:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-04-21 10:53:31 ----D---- C:\WINDOWS\MATS
2010-04-21 10:53:29 ----D---- C:\Program Files\Microsoft Fix it Center
2010-04-21 10:52:25 ----D---- C:\WINDOWS\system32\windowspowershell
2010-04-21 10:52:16 ----HDC---- C:\WINDOWS\$NtUninstallKB926139-v2$
2010-04-21 10:47:25 ----A---- C:\WINDOWS\system32\pwNative.exe
2010-04-14 06:48:48 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-14 06:48:36 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-14 06:45:01 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-14 06:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 06:44:19 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 06:43:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
======List of files/folders modified in the last 1 months======
2010-05-06 19:21:17 ----RD---- C:\Program Files
2010-05-06 19:20:21 ----D---- C:\WINDOWS\Temp
2010-05-06 19:14:12 ----A---- C:\WINDOWS\WINCMD.INI
2010-05-06 19:05:10 ----D---- C:\WINDOWS\system32\drivers
2010-05-06 18:45:46 ----D---- C:\Documents and Settings\paj\Data aplikací\Skype
2010-05-06 18:44:16 ----D---- C:\Documents and Settings\paj\Data aplikací\skypePM
2010-05-06 18:37:33 ----D---- C:\WINDOWS\system32
2010-05-06 18:37:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-06 18:36:01 ----SD---- C:\WINDOWS\Tasks
2010-05-06 18:35:58 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-06 16:30:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-06 13:52:32 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-06 13:50:45 ----D---- C:\WINDOWS
2010-05-06 13:46:41 ----SHD---- C:\WINDOWS\Installer
2010-05-06 13:46:38 ----D---- C:\WINDOWS\WinSxS
2010-05-06 13:45:47 ----D---- C:\Program Files\Common Files
2010-05-05 18:19:51 ----HD---- C:\WINDOWS\inf
2010-05-05 18:19:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-05 14:51:39 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-05-03 07:59:40 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-02 11:52:53 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-04-28 19:04:12 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-28 19:04:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-28 19:04:10 ----D---- C:\WINDOWS\twain_32
2010-04-27 16:43:35 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-23 09:11:02 ----D---- C:\Documents and Settings\paj\Data aplikací\Audacity
2010-04-22 15:40:44 ----D---- C:\Documents and Settings\paj\Data aplikací\Macromedia
2010-04-22 14:42:52 ----D---- C:\Documents and Settings\paj\Data aplikací\IObit
2010-04-22 14:36:13 ----D---- C:\WINDOWS\system32\MsDtc
2010-04-22 14:36:13 ----D---- C:\WINDOWS\system32\config
2010-04-22 14:36:13 ----D---- C:\WINDOWS\repair
2010-04-22 14:36:13 ----D---- C:\WINDOWS\Logs
2010-04-22 14:36:13 ----D---- C:\WINDOWS\Internet Logs
2010-04-22 14:36:13 ----D---- C:\WINDOWS\Debug
2010-04-22 14:36:13 ----D---- C:\Documents and Settings\paj\Data aplikací\Any Video Converter
2010-04-22 13:21:15 ----SH---- C:\boot.ini
2010-04-22 10:26:50 ----D---- C:\Documents and Settings\paj\Data aplikací\GlarySoft
2010-04-21 15:37:30 ----SD---- C:\Documents and Settings\paj\Data aplikací\Microsoft
2010-04-21 15:19:07 ----A---- C:\WINDOWS\win.ini
2010-04-21 14:57:26 ----A---- C:\WINDOWS\system.ini
2010-04-21 10:53:35 ----RSD---- C:\WINDOWS\assembly
2010-04-21 10:53:35 ----D---- C:\WINDOWS\AppPatch
2010-04-17 09:33:25 ----D---- C:\Documents and Settings\paj\Data aplikací\Ancestry
2010-04-14 06:48:54 ----A---- C:\WINDOWS\imsins.BAK
2010-04-14 06:48:42 ----HD---- C:\WINDOWS\$hf_mig$
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2010-04-28 82380]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-03-03 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-03-03 29512]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-05-01 242896]
R1 FldSafe;FldSafe; C:\WINDOWS\system32\DRIVERS\FldSafe.sys [2010-04-19 10240]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R3 ASAPIW2k;ASAPIW2K; C:\WINDOWS\system32\drivers\ASAPIW2k.sys [2003-12-04 11264]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-30 1333760]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-03-09 30104]
R3 bcm4sbxp;MSI/Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-05-15 43136]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2003-05-01 743367]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MarvinBus;MarvinBus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 PAC207;Trust 100K Series Webcam; C:\WINDOWS\system32\DRIVERS\pfc027.sys [2008-02-13 618112]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S1 SASDIFSV;SASDIFSV; \??\E:\Program files\Antihavet\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\Program Files\Antihavet\SUPERAntiSpyware\SASKUTIL.SYS []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-03-09 30104]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\paj\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\E:\Program files\Multimedia\Konvertory\MediaCoder\SysInfo.sys []
S3 esihdrv;esihdrv; \??\C:\DOCUME~1\paj\LOCALS~1\Temp\esihdrv.sys []
S3 GMSIPCI;GMSIPCI; \??\L:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pwdrvio;pwdrvio; \??\C:\WINDOWS\system32\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\WINDOWS\system32\pwdspio.sys []
S3 SASENUM;SASENUM; \??\E:\Program Files\Antihavet\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-30 376832]
R2 avg9emc;AVG E-mail Scanner; E:\Program files\Antiviry\AVG9\avgemc.exe [2010-03-03 916760]
R2 avg9wd;AVG WatchDog; E:\Program files\Antiviry\AVG9\avgwdsvc.exe [2010-03-05 308064]
R2 avgfws9;AVG Firewall; E:\Program files\Antiviry\AVG9\avgfws9.exe [2010-03-09 2325816]
R2 Browser Defender Update Service;Browser Defender Update Service; E:\Program Files\Antiviry\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-07 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; E:\Program files\Antihavěť\Spyware Terminator\sp_rsser.exe [2010-05-05 488960]
R2 STI Simulator;STI Simulator; C:\WINDOWS\System32\PAStiSvc.exe [2010-03-07 53248]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WDDMService;WD SmartWare Drive Manager; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-10-14 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service; C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
R3 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-08-30 516096]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-05 1285864]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 sdAuxService;PC Tools Auxiliary Service; E:\Program Files\Antiviry\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
S3 sdCoreService;PC Tools Security Service; E:\Program Files\Antiviry\Spyware Doctor\pctsSvc.exe [2010-03-15 1142224]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
OK, log z MBAM:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Verze databáze: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6.5.2010 19:18:20
mbam-log-2010-05-06 (19-18-20).txt
Typ skenu: Rychlý sken
Skenované objekty: 115911
Uplynulý čas: 10 minuta(y), 49 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)
Log z RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by paj at 2010-05-06 19:23:46
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 33 GB (72%) free of 46 GB
Total RAM: 1023 MB (33% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:23:55, on 6.5.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program files\Antiviry\AVG9\avgchsvx.exe
E:\Program files\Antiviry\AVG9\avgrsx.exe
E:\Program files\Antiviry\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
E:\Program files\Antiviry\AVG9\avgwdsvc.exe
E:\Program files\Antiviry\AVG9\avgfws9.exe
E:\Program Files\Antiviry\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PSIService.exe
E:\Program files\Antihavěť\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
E:\Program files\Antiviry\AVG9\avgemc.exe
E:\Program files\Antiviry\AVG9\avgam.exe
E:\Program files\Antiviry\AVG9\avgnsx.exe
E:\Program files\Antiviry\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\Antiviry\AVG9\avgtray.exe
E:\Program files\Utility\MyClipboard_Exe_3.0.0.0\MyClipboard.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
E:\Program files\Antiviry\AVG9\avgcsrvx.exe
E:\Program files\Internet\Prohlížeče\Opera\Opera.exe
E:\Program files\Explorery\totalcmd\TOTALCMD.EXE
E:\Program files\Antihavěť\RSIT\RSIT.exe
C:\Program Files\trend micro\paj.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - E:\Program files\Antiviry\AVG9\avgssie.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [AVG9_TRAY] E:\PROGRA~1\Antiviry\AVG9\avgtray.exe
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: MyClipboard.lnk = E:\Program files\Utility\MyClipboard_Exe_3.0.0.0\MyClipboard.exe
O4 - Global Startup: WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přeložit - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - E:\Program Files\Překladače\Verdict Free\etnxp.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - E:\Program Files\Překladače\Verdict Free\etnxp.dll
O9 - Extra 'Tools' menuitem: Internetový překladač... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - E:\Program Files\Překladače\Verdict Free\etnxp.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 9157182156
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - E:\Program files\Antiviry\AVG9\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - E:\Program files\Antiviry\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - E:\Program files\Antiviry\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - E:\Program files\Antiviry\AVG9\avgfws9.exe
O23 - Service: Browser Defender Update Service - Unknown owner - E:\Program Files\Antiviry\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - E:\Program Files\Antiviry\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - E:\Program Files\Antiviry\Spyware Doctor\pctsSvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - E:\Program files\Antihavěť\Spyware Terminator\sp_rsser.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: WD SmartWare Drive Manager (WDDMService) - WDC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
O23 - Service: WD SmartWare Background Service (WDSmartWareBackgroundService) - Memeo - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
--
End of file - 8658 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\ConfigExec.job
C:\WINDOWS\tasks\DataUpload.job
C:\WINDOWS\tasks\GlaryInitialize.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\ParetoLogic Registration3.job
C:\WINDOWS\tasks\ParetoLogic Update Version3.job
C:\WINDOWS\tasks\XoftSpySE 2.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - E:\Program files\Antiviry\AVG9\avgssie.dll [2010-05-01 1615200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-07 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-07 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - E:\Program Files\Antiviry\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"=E:\PROGRA~1\Antiviry\AVG9\avgtray.exe [2010-05-01 2064736]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"=C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
MyClipboard.lnk - E:\Program files\Utility\MyClipboard_Exe_3.0.0.0\MyClipboard.exe
WDDMStatus.lnk - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-08-30 46080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-03-03 12464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=E:\Program Files\Antihavet\SUPERAntiSpyware\SASSEH.DLL []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"EditLevel"=0
"NoRun"=0
"NoClose"=0
"NoCommonGroups"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDrives"=
"NoResolveSearch"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\Program files\Antiviry\AVG9\avgdiagex.exe"="E:\Program files\Antiviry\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"E:\Program files\Antiviry\AVG9\avgam.exe"="E:\Program files\Antiviry\AVG9\avgam.exe:*:Enabled:avgam.exe"
"E:\Program files\Antiviry\AVG9\avgupd.exe"="E:\Program files\Antiviry\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"E:\Program files\Antiviry\AVG9\avgnsx.exe"="E:\Program files\Antiviry\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"E:\Program files\Antiviry\AVG9\avgemc.exe"="E:\Program files\Antiviry\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Konzola Microsoft Management Console"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"E:\Program files\Internet\Prohlížeče\Opera\opera.exe"="E:\Program files\Internet\Prohlížeče\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"E:\Program files\Komunikace\X-lite\x-lite.exe"="E:\Program files\Komunikace\X-lite\x-lite.exe:*:Enabled:X-Lite"
"E:\Program files\Explorery\totalcmd\TOTALCMD.EXE"="E:\Program files\Explorery\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-05-06 19:21:17 ----D---- C:\Program Files\trend micro
2010-05-06 19:21:15 ----D---- C:\rsit
2010-05-06 19:05:08 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-06 13:50:45 ----A---- C:\WINDOWS\BDTSupport.dll
2010-05-06 13:50:44 ----A---- C:\WINDOWS\SGDetectionTool.dll
2010-05-06 13:50:44 ----A---- C:\WINDOWS\PCTBDRes.dll
2010-05-06 13:50:44 ----A---- C:\WINDOWS\PCTBDCore.dll
2010-05-06 13:45:47 ----D---- C:\Program Files\Common Files\PC Tools
2010-05-06 13:45:46 ----D---- C:\Documents and Settings\paj\Data aplikací\PC Tools
2010-05-06 13:45:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\PC Tools
2010-05-05 21:20:18 ----A---- C:\WINDOWS\system32\lsdelete.exe
2010-05-05 18:17:53 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-05 18:17:08 ----D---- C:\Program Files\Lavasoft
2010-05-05 18:17:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-05-05 16:04:23 ----D---- C:\Program Files\Common Files\ParetoLogic
2010-05-05 16:04:23 ----D---- C:\Documents and Settings\All Users\Data aplikací\ParetoLogic
2010-05-05 15:34:24 ----D---- C:\Documents and Settings\paj\Data aplikací\Spyware Terminator
2010-05-05 15:34:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-05-05 14:52:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-05-05 14:52:29 ----D---- C:\Documents and Settings\paj\Data aplikací\SUPERAntiSpyware.com
2010-05-05 14:50:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-05-05 14:45:01 ----D---- C:\Documents and Settings\paj\Data aplikací\VitySoft
2010-05-05 14:12:09 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-05-02 18:53:34 ----D---- C:\Program Files\Google
2010-05-01 16:44:13 ----D---- C:\Documents and Settings\paj\Data aplikací\InfraRecorder
2010-05-01 16:28:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\M-Photo
2010-05-01 16:14:24 ----A---- C:\WINDOWS\system32\TiskProRadost_AlbumMaker_uninstaller.exe
2010-05-01 15:17:51 ----D---- C:\ReFox
2010-04-28 08:51:16 ----D---- C:\Documents and Settings\paj\Data aplikací\Resource Tuner
2010-04-22 13:18:31 ----D---- C:\WINDOWS\Prefetch
2010-04-22 09:01:00 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-04-22 09:00:58 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-04-22 09:00:38 ----D---- C:\Documents and Settings\paj\Data aplikací\TuneUp Software
2010-04-22 08:58:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2010-04-22 08:58:24 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-04-22 07:34:12 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2010-04-21 16:38:23 ----D---- C:\WINDOWS\pss
2010-04-21 14:20:19 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-04-21 13:44:16 ----A---- C:\Answer.txt
2010-04-21 13:05:27 ----A---- C:\mbam-error.txt
2010-04-21 13:04:18 ----D---- C:\Documents and Settings\paj\Data aplikací\Malwarebytes
2010-04-21 13:04:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-04-21 10:53:31 ----D---- C:\WINDOWS\MATS
2010-04-21 10:53:29 ----D---- C:\Program Files\Microsoft Fix it Center
2010-04-21 10:52:25 ----D---- C:\WINDOWS\system32\windowspowershell
2010-04-21 10:52:16 ----HDC---- C:\WINDOWS\$NtUninstallKB926139-v2$
2010-04-21 10:47:25 ----A---- C:\WINDOWS\system32\pwNative.exe
2010-04-14 06:48:48 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-14 06:48:36 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-14 06:45:01 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-14 06:44:55 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-14 06:44:19 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 06:43:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
======List of files/folders modified in the last 1 months======
2010-05-06 19:21:17 ----RD---- C:\Program Files
2010-05-06 19:20:21 ----D---- C:\WINDOWS\Temp
2010-05-06 19:14:12 ----A---- C:\WINDOWS\WINCMD.INI
2010-05-06 19:05:10 ----D---- C:\WINDOWS\system32\drivers
2010-05-06 18:45:46 ----D---- C:\Documents and Settings\paj\Data aplikací\Skype
2010-05-06 18:44:16 ----D---- C:\Documents and Settings\paj\Data aplikací\skypePM
2010-05-06 18:37:33 ----D---- C:\WINDOWS\system32
2010-05-06 18:37:33 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-05-06 18:36:01 ----SD---- C:\WINDOWS\Tasks
2010-05-06 18:35:58 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-06 16:30:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-06 13:52:32 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-06 13:50:45 ----D---- C:\WINDOWS
2010-05-06 13:46:41 ----SHD---- C:\WINDOWS\Installer
2010-05-06 13:46:38 ----D---- C:\WINDOWS\WinSxS
2010-05-06 13:45:47 ----D---- C:\Program Files\Common Files
2010-05-05 18:19:51 ----HD---- C:\WINDOWS\inf
2010-05-05 18:19:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-05 14:51:39 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-05-03 07:59:40 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-02 11:52:53 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-04-28 19:04:12 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-04-28 19:04:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-28 19:04:10 ----D---- C:\WINDOWS\twain_32
2010-04-27 16:43:35 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-23 09:11:02 ----D---- C:\Documents and Settings\paj\Data aplikací\Audacity
2010-04-22 15:40:44 ----D---- C:\Documents and Settings\paj\Data aplikací\Macromedia
2010-04-22 14:42:52 ----D---- C:\Documents and Settings\paj\Data aplikací\IObit
2010-04-22 14:36:13 ----D---- C:\WINDOWS\system32\MsDtc
2010-04-22 14:36:13 ----D---- C:\WINDOWS\system32\config
2010-04-22 14:36:13 ----D---- C:\WINDOWS\repair
2010-04-22 14:36:13 ----D---- C:\WINDOWS\Logs
2010-04-22 14:36:13 ----D---- C:\WINDOWS\Internet Logs
2010-04-22 14:36:13 ----D---- C:\WINDOWS\Debug
2010-04-22 14:36:13 ----D---- C:\Documents and Settings\paj\Data aplikací\Any Video Converter
2010-04-22 13:21:15 ----SH---- C:\boot.ini
2010-04-22 10:26:50 ----D---- C:\Documents and Settings\paj\Data aplikací\GlarySoft
2010-04-21 15:37:30 ----SD---- C:\Documents and Settings\paj\Data aplikací\Microsoft
2010-04-21 15:19:07 ----A---- C:\WINDOWS\win.ini
2010-04-21 14:57:26 ----A---- C:\WINDOWS\system.ini
2010-04-21 10:53:35 ----RSD---- C:\WINDOWS\assembly
2010-04-21 10:53:35 ----D---- C:\WINDOWS\AppPatch
2010-04-17 09:33:25 ----D---- C:\Documents and Settings\paj\Data aplikací\Ancestry
2010-04-14 06:48:54 ----A---- C:\WINDOWS\imsins.BAK
2010-04-14 06:48:42 ----HD---- C:\WINDOWS\$hf_mig$
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AFS2K;AFS2k; C:\WINDOWS\system32\drivers\AFS2K.sys [2010-04-28 82380]
R1 AmdK7;Ovladač procesoru AMD K7; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2008-04-14 41600]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-03-03 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-03-03 29512]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-05-01 242896]
R1 FldSafe;FldSafe; C:\WINDOWS\system32\DRIVERS\FldSafe.sys [2010-04-19 10240]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-18 12032]
R3 ASAPIW2k;ASAPIW2K; C:\WINDOWS\system32\drivers\ASAPIW2k.sys [2003-12-04 11264]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-08-30 1333760]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-03-09 30104]
R3 bcm4sbxp;MSI/Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2003-05-15 43136]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2003-05-01 743367]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MarvinBus;MarvinBus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-18 12160]
R3 PAC207;Trust 100K Series Webcam; C:\WINDOWS\system32\DRIVERS\pfc027.sys [2008-02-13 618112]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 21248]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S1 SASDIFSV;SASDIFSV; \??\E:\Program files\Antihavet\SUPERAntiSpyware\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\Program Files\Antihavet\SUPERAntiSpyware\SASKUTIL.SYS []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-03-09 30104]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 cpuz132;cpuz132; \??\C:\DOCUME~1\paj\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys []
S3 CrystalSysInfo;CrystalSysInfo; \??\E:\Program files\Multimedia\Konvertory\MediaCoder\SysInfo.sys []
S3 esihdrv;esihdrv; \??\C:\DOCUME~1\paj\LOCALS~1\Temp\esihdrv.sys []
S3 GMSIPCI;GMSIPCI; \??\L:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 pwdrvio;pwdrvio; \??\C:\WINDOWS\system32\pwdrvio.sys []
S3 pwdspio;pwdspio; \??\C:\WINDOWS\system32\pwdspio.sys []
S3 SASENUM;SASENUM; \??\E:\Program Files\Antihavet\SUPERAntiSpyware\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-08-30 376832]
R2 avg9emc;AVG E-mail Scanner; E:\Program files\Antiviry\AVG9\avgemc.exe [2010-03-03 916760]
R2 avg9wd;AVG WatchDog; E:\Program files\Antiviry\AVG9\avgwdsvc.exe [2010-03-05 308064]
R2 avgfws9;AVG Firewall; E:\Program files\Antiviry\AVG9\avgfws9.exe [2010-03-09 2325816]
R2 Browser Defender Update Service;Browser Defender Update Service; E:\Program Files\Antiviry\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
R2 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-07 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; E:\Program files\Antihavěť\Spyware Terminator\sp_rsser.exe [2010-05-05 488960]
R2 STI Simulator;STI Simulator; C:\WINDOWS\System32\PAStiSvc.exe [2010-03-07 53248]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WDDMService;WD SmartWare Drive Manager; C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-10-14 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service; C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]
R3 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-08-30 516096]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe /svc []
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-05 1285864]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe []
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 sdAuxService;PC Tools Auxiliary Service; E:\Program Files\Antiviry\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
S3 sdCoreService;PC Tools Security Service; E:\Program Files\Antiviry\Spyware Doctor\pctsSvc.exe [2010-03-15 1142224]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo
OTM scriptStáhni OTM z odkazu a rozbal nejlépe na plochu.
http://oldtimer.geekstogo.com/OTM.exe
Spusť program „OTM.exe“.
Do okna pod žlutou čáru vlož celý text zeleným písmem ze „Scriptu“
Klikni na červené „Moveit!“
Do své odpovědi vlož obsah zeleného okna
Při nabídce restartu „YES“
a log potom najdeš v C:\_OTM\MovedFiles\
Kód: Vybrat vše
:Processes
explorer.exe
:Reg
[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel]
"Homepage"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME]
:Services
gupdate
gusvc
cpuz132
CrystalSysInfo
esihdrv
GMSIPCI
pwdrvio
pwdspio
:Files
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
:Commands
[emptytemp]
[purity]
[clearallrestorepoints]
[start explorer]
[reboot]

Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
- paj
- Vzorný návštěvník
- Příspěvky: 52
- Registrován: 21 zář 2006 18:02
- Bydliště: Havířov
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo
Zdravím, vše jsem udělal dle návodu, jen OTM po dokončení práce neprovedl reboot, z obrazovky zmizelo vše, musel jsem OTM ukončit pomocí Task Manageru a restartovat systém ručně. OTM uložil složku nikoliv na C:, ale na D:. Vše je vyčištěno dle pokynů ze skriptu. Rychlá kontrola Spyware Doctoru je OK, rovněž i následná úplná kontrola. Děkuji moc za SOS.
Připojuji log z OTM:
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\\Homepage deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Malwarebytes' Anti-Malware not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\ deleted successfully.
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!
Service cpuz132 stopped successfully!
Service cpuz132 deleted successfully!
Service CrystalSysInfo stopped successfully!
Service CrystalSysInfo deleted successfully!
Service esihdrv stopped successfully!
Service esihdrv deleted successfully!
Service GMSIPCI stopped successfully!
Service GMSIPCI deleted successfully!
Service pwdrvio stopped successfully!
Service pwdrvio deleted successfully!
Service pwdspio stopped successfully!
Service pwdspio deleted successfully!
========== FILES ==========
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33597 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes
User: paj
->Temp folder emptied: 1003158 bytes
->Temporary Internet Files folder emptied: 46869130 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 82493537 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 5093 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3110591 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23908466 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 296707011 bytes
Total Files Cleaned = 433,00 mb
Restore points cleared and new OTM Restore Point set!
OTM by OldTimer - Version 3.1.12.0 log created on 05072010_084434
Připojuji log z OTM:
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\\Homepage deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Malwarebytes' Anti-Malware not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\ deleted successfully.
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!
Service cpuz132 stopped successfully!
Service cpuz132 deleted successfully!
Service CrystalSysInfo stopped successfully!
Service CrystalSysInfo deleted successfully!
Service esihdrv stopped successfully!
Service esihdrv deleted successfully!
Service GMSIPCI stopped successfully!
Service GMSIPCI deleted successfully!
Service pwdrvio stopped successfully!
Service pwdrvio deleted successfully!
Service pwdspio stopped successfully!
Service pwdspio deleted successfully!
========== FILES ==========
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33597 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33237 bytes
User: paj
->Temp folder emptied: 1003158 bytes
->Temporary Internet Files folder emptied: 46869130 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 82493537 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 5093 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3110591 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23908466 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 296707011 bytes
Total Files Cleaned = 433,00 mb
Restore points cleared and new OTM Restore Point set!
OTM by OldTimer - Version 3.1.12.0 log created on 05072010_084434
Spam nechodí po horách, ale po lidech
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo


Ten si můžeš nechat i na budoucí občasné čištění.Stáhni Ccleaner - http://www.slunecnice.cz/sw/ccleaner/
Při instalaci vyhodit fajfku u "Instalovat Yahoo! Toolbar"
zavřít Internetový prohlížeč a
spustit "Čistič" > "Spustit Ccleaner" - odstraní nepotřebné
spustit "Registry" > "Hledej problémy" > "Opravit vybrané problémy"
souhlas se zálohou registrů - opakovat dokud nebudou registry čisté.
Návod:http://jnp.zive.cz/Clanky/Prirucka-do-k ... fault.aspx

doporučuji http://www.slunecnice.cz/sw/defraggler/ + čeština
Nemáš zač - rádo se stalo a jsme tady i příště

Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
- paj
- Vzorný návštěvník
- Příspěvky: 52
- Registrován: 21 zář 2006 18:02
- Bydliště: Havířov
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo
Super, to jsem již udělal a je vše v pořádku. Ccleaner používám pravidelně pro každotýdenní údržbu. Ještě jednou děkuji za pomoc. 

Spam nechodí po horách, ale po lidech
- cernohous13
- VIP in memoriam
- Příspěvky: 8721
- Registrován: 09 pro 2006 06:19
- Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Trojan-Downloader.Murlo
Jsem rád, že se podařilo, při problémech se zase ukaž (a nemusí to být moc brzo) 

Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <