Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

WORM_IRCBOT.BZQ

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
karri84
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 11 kvě 2010 15:44

WORM_IRCBOT.BZQ

#1 Příspěvek od karri84 »

Ahoj,
na přenosných discích se mi začaly objevovat soubory autorun.inf s obsahem:

Kód: Vybrat vše

[autorun]
shell=verb
open=windows.exe
action=Open folder to view files
shell\open=Open
icon=%SystemRoot%\system32\SHELL32.dll,4
a windows.exe. Oba skrytý. Google říká že je to WORM_IRCBOT.BZQ.
Mám NOD32, bohužel nepomáhá. Ad-Aware také ne. Neuměl by prosím někdo poradit?
Po smazání souborů se při práci s diskem objeví znovu.


Logfile of random's system information tool 1.07 (written by random/random)
Run by KARAS at 2010-05-11 16:50:13
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 648 MB (3%) free of 20 GB
Total RAM: 2271 MB (55% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:50:58, on 11.5.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
D:\PROGRAMY\PADSINSTAL\9.1PADS\SDD_HOME\iCDB\win32\bin\iCDBNetLauncher.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Documents and Settings\KARAS\Data aplikací\Microsoft\windows.exe
C:\WINDOWS\system32\wuauclt.exe
D:\PROGRAMY\TOTALCMD\TOTALCMD.EXE
D:\PROGRAMY\_IMAGES\ALTIUM_SUMMER_09\Altium Designer Summer 09.exe
D:\PROGRAMY\Psi\psi.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\KARAS\Plocha\ZÁPLATA\RSIT.exe
C:\Program Files\trend micro\KARAS.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neobux.com/?u=v
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [VSPDXP] C:\Program Files\VSPD XP\vspdconfig.exe /quiet
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [365dni] C:\Program Files\365dníNET\365dniNET.exe
O4 - HKCU\..\Run: [windows.exe] C:\Documents and Settings\KARAS\Data aplikací\Microsoft\windows.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: CyMiniProg3Service - Cypress Semiconductor - C:\Program Files\Cypress\Programmer\3.11\Service\CyMiniProg3Service.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: Remote Server Configuration Manager 2007.8 (MGC.SDD.RSCM.2007.8) - Mentor Graphics Corporation - D:\PROGRAMY\PADSINSTAL\9.1PADS\SDD_HOME\iCDB\win32\bin\iCDBNetLauncher.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe

--
End of file - 7779 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\CypressUpdateManager.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-19 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-02-19 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-10-14 110592]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-10-30 16269312]
"SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-10-24 1451264]
"VSPDXP"=C:\Program Files\VSPD XP\vspdconfig.exe [2003-11-13 974848]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-02-15 417792]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-03-02 15360]
"365dni"=C:\Program Files\365dníNET\365dniNET.exe [2007-01-06 753664]
"windows.exe"=C:\Documents and Settings\KARAS\Data aplikací\Microsoft\windows.exe [2010-01-21 192512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Meebo Notifier]
C:\Documents and Settings\KARAS\Local Settings\Data aplikací\Meebo\Meebo Notifier\MeeboNotifier.exe [2009-06-06 790528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\WINDOWS\system32\oodtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\pdfforge Toolbar\SearchSettings.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-08-07 573440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-04-10 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 2]
C:\Program Files\Wireless Console 2\wcourier.exe [2006-11-29 1011712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Update Scheduler for Proteus Professional 7.lnk]
C:\PROGRA~1\LABCEN~1\PROTEU~1\BIN\UDSCHED.EXE Proteus Professional 7 []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2007-07-04 118784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\PROGRAMY\Psi\psi.exe"="D:\PROGRAMY\Psi\psi.exe:*:Enabled:psi"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"D:\PROGRAMY\TOTALCMD\TOTALCMD.EXE"="D:\PROGRAMY\TOTALCMD\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"D:\PROGRAMY\_IMAGES\ALTIUM_SUMMER_09\Altium Designer Summer 09.exe"="D:\PROGRAMY\_IMAGES\ALTIUM_SUMMER_09\Altium Designer Summer 09.exe:*:Enabled:Altium Designer Summer 09"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{704ff5cd-b307-11de-879e-0015af2f0ad2}]
shell\AutoRun\command - WDSetup.exe


======File associations======

.scr - open - "C:\WINDOWS\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-05-11 16:50:17 ----D---- C:\Program Files\trend micro
2010-05-11 16:50:13 ----D---- C:\rsit
2010-05-11 15:45:10 ----HDC---- C:\Documents and Settings\All Users\Data aplikací\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-11 15:44:42 ----D---- C:\Program Files\Lavasoft
2010-05-11 15:44:42 ----D---- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-05-10 22:47:46 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-05-10 22:46:52 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-05-03 15:37:12 ----A---- C:\WINDOWS\DAINA.INI
2010-05-03 15:37:11 ----D---- C:\CARMS
2010-04-27 15:31:47 ----D---- C:\DO~QTNB9
2010-04-21 22:34:47 ----D---- C:\Program Files\Cherry Dolls
2010-04-17 19:00:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\pads
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\w95inf32.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\w95inf16.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\odbctl32.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\msxbse35.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\mstext35.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\msrepl35.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\msrd2x35.dll
2010-04-17 18:54:15 ----RA---- C:\WINDOWS\system32\mspdox35.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\VBAR332.DLL
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\vb5db.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2l2000.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fxls.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fwordw.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fwks.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2ftext.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fsepv.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2frtf.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2frec.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2frdef.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fhtml.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fdif.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2fcr.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2dvim.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2dpost.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2dnotes.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2dmapi.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2ddisk.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\u2dapp.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\sscsdk32.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\msjter35.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\msjint35.dll
2010-04-17 18:54:14 ----RA---- C:\WINDOWS\system32\dao350.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\pg32.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\p2sodbc.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\p2irdao.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\p2ctdao.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\p2bdao.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\p2bbnd.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\oc30.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\msexcl35.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\implode.dll
2010-04-17 18:54:13 ----RA---- C:\WINDOWS\system32\gswdll32.dll
2010-04-17 18:54:13 ----A---- C:\WINDOWS\system32\msjet35.dll
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\gsw32.exe
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\dzactx.dll
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\duzactx.dll
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\crpe32.dll
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\crpaig32.dll
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\co2c40en.dll
2010-04-17 18:54:12 ----RA---- C:\WINDOWS\system32\ccsdk32.dll
2010-04-17 18:54:10 ----RA---- C:\WINDOWS\system32\Dwspy32.dll
2010-04-17 18:54:10 ----RA---- C:\WINDOWS\system32\CMDLGD6.dll
2010-04-17 18:53:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\mgc
2010-04-17 18:17:29 ----D---- C:\temp
2010-04-17 18:16:49 ----D---- C:\MentorGraphics

======List of files/folders modified in the last 1 months======

2010-05-11 16:50:18 ----D---- C:\WINDOWS\Temp
2010-05-11 16:50:17 ----RD---- C:\Program Files
2010-05-11 16:50:14 ----D---- C:\WINDOWS\Prefetch
2010-05-11 16:21:21 ----D---- C:\Program Files\Mozilla Thunderbird
2010-05-11 16:00:45 ----D---- C:\WINDOWS\system32\CatRoot2
2010-05-11 15:57:48 ----SD---- C:\WINDOWS\Tasks
2010-05-11 15:53:00 ----A---- C:\WINDOWS\WINCMD.INI
2010-05-11 15:51:57 ----D---- C:\Documents and Settings\KARAS\Data aplikací\365dni
2010-05-11 15:51:12 ----D---- C:\WINDOWS
2010-05-11 15:49:41 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-05-11 15:49:00 ----D---- C:\WINDOWS\system32\drivers
2010-05-11 15:48:58 ----HD---- C:\WINDOWS\inf
2010-05-11 15:48:36 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-11 15:45:15 ----SHD---- C:\WINDOWS\Installer
2010-05-11 15:44:35 ----D---- C:\WINDOWS\WinSxS
2010-05-10 22:49:37 ----D---- C:\WINDOWS\system32
2010-05-10 22:48:25 ----D---- C:\Documents and Settings\KARAS\Data aplikací\uTorrent
2010-05-10 22:47:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-10 22:47:43 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-10 22:47:30 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-10 22:47:14 ----A---- C:\WINDOWS\imsins.BAK
2010-05-10 21:19:21 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-10 21:19:17 ----D---- C:\Program Files\ESET
2010-05-10 21:03:55 ----SD---- C:\Documents and Settings\KARAS\Data aplikací\Microsoft
2010-05-09 21:03:03 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-05-06 19:16:30 ----D---- C:\WINDOWS\Minidump
2010-05-06 18:51:43 ----A---- C:\moduleName.txt
2010-05-01 19:40:53 ----A---- C:\WINDOWS\NeroDigital.ini
2010-05-01 19:21:36 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-01 19:13:39 ----D---- C:\Program Files\Cypress
2010-04-19 20:42:51 ----D---- C:\Program Files\Mozilla Firefox
2010-04-17 18:54:10 ----RSD---- C:\WINDOWS\Fonts
2010-04-17 18:54:10 ----D---- C:\Program Files\Mentor Graphics
2010-04-17 18:51:39 ----D---- C:\WINDOWS\Downloaded Installations
2010-04-17 16:23:16 ----RSD---- C:\WINDOWS\assembly
2010-04-17 16:23:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-04-17 16:23:12 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-04-17 16:23:06 ----A---- C:\WINDOWS\vbaddin.ini
2010-04-17 16:22:08 ----A---- C:\WINDOWS\ODBC.INI
2010-04-13 17:39:08 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-10-24 53256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-10-24 34824]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2006-03-02 39936]
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-06-12 56108]
R2 CdaC15BA;CdaC15BA; \??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS []
R2 cvintdrv;cvintdrv; C:\WINDOWS\system32\drivers\cvintdrv.sys [2008-04-07 4096]
R2 DS1410D;DS1410D; C:\WINDOWS\SYSTEM32\drivers\DS1410D.SYS [2004-03-24 6689]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-10-24 39944]
R2 hardlock;hardlock; \??\C:\WINDOWS\system32\drivers\hardlock.sys []
R2 Haspnt;Haspnt; \??\C:\WINDOWS\system32\drivers\Haspnt.sys []
R2 Sentinel;Sentinel; C:\WINDOWS\System32\Drivers\SENTINEL.SYS [2002-12-17 76288]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-12-05 529344]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2007-07-04 2304000]
R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 evserial;Virtual Serial Ports Driver (Eltima Softwate); C:\WINDOWS\System32\DRIVERS\evserial.sys [2007-06-22 51616]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-03 4394496]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-17 5632]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-07-12 51328]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-08-07 980608]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2006-03-02 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2006-03-02 57600]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2006-03-02 17024]
R3 VSBC;Virtual Serial Bus Enumerator (Eltima Software); C:\WINDOWS\system32\DRIVERS\evsbc.sys [2007-06-22 25120]
R3 vsbus;Virtual Serial Bus Enumerator; C:\WINDOWS\system32\DRIVERS\vsb.sys [2003-10-07 18167]
S2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2003-07-29 40448]
S2 IOPort;IOPort; \??\C:\WINDOWS\system32\DRIVERS\IOPORT.SYS []
S2 SSIPDDP;SSIPDDP; \??\C:\WINDOWS\system32\drivers\SSIPDDP.SYS []
S3 AltiumUSBJtag;AltiumUSBJtag; C:\WINDOWS\System32\Drivers\AltiumUSBJtag.sys [2009-08-16 29184]
S3 CSVirtA;Cisco Systems SSL VPN Adapter; C:\WINDOWS\system32\DRIVERS\CSVirtA.sys [2009-05-18 22136]
S3 DKRtWrt;DKRtWrt; C:\WINDOWS\system32\DRIVERS\DKRtWrt.sys [2009-10-21 45232]
S3 FTDIBUS;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2009-10-22 57800]
S3 FTSER2K;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2009-10-22 72520]
S3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2006-03-02 9600]
S3 MCHPUSB;MCHPUSB; C:\WINDOWS\system32\DRIVERS\iqrfusb.sys [2007-12-19 53760]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
S3 PSoCUSB;USB Driver for MiniProg1; C:\WINDOWS\System32\Drivers\Cypress\Mprog1\PSoCUSB.sys [2009-10-16 39480]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2006-03-02 67584]
S3 Ser2pl;Prolific2 Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2009-01-14 50176]
S3 sermouse;Ovladač sériové myši; C:\WINDOWS\system32\DRIVERS\sermouse.sys [2001-10-24 17664]
S3 Sntnlusb;Rainbow USB SuperPro; C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS [2002-12-17 26120]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbser;USB RS-232 Emulation Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2004-08-03 25600]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 VSerial;ELTIMA Virtual Serial Ports Driver; C:\WINDOWS\System32\DRIVERS\vserial.sys [2003-11-12 47104]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2007-07-04 483328]
R2 C-DillaCdaC11BA;C-DillaCdaC11BA; C:\WINDOWS\system32\drivers\CDAC11BA.EXE [2009-05-31 54784]
R2 Diskeeper;Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2009-10-23 1732960]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-10-24 468224]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-02-19 153376]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-11 1291544]
R2 lkClassAds;National Instruments PSP Server Locator; C:\WINDOWS\system32\lkads.exe [2009-06-18 42544]
R2 lkTimeSync;National Instruments Time Synchronization; C:\WINDOWS\system32\lktsrv.exe [2009-06-18 53296]
R2 MGC.SDD.RSCM.2007.8;Remote Server Configuration Manager 2007.8; D:\PROGRAMY\PADSINSTAL\9.1PADS\SDD_HOME\iCDB\win32\bin\iCDBNetLauncher.exe [2009-12-16 1445888]
R2 mxssvr;NI Configuration Manager; C:\Program Files\National Instruments\MAX\nimxs.exe [2009-06-15 12696]
R2 NIDomainService;National Instruments Domain Service; C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe [2009-06-18 356912]
R2 niSvcLoc;NI Service Locator; C:\WINDOWS\system32\nisvcloc.exe [2009-06-04 13896]
R2 NITaggerService;National Instruments Variable Engine; C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe [2009-06-23 740968]
R2 STCAgent;Cisco Systems, Inc. STC Agent; C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe [2009-05-18 259128]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S2 NOD32FiXTemDono;Eset Nod32 Boot; C:\WINDOWS\system32\regedt32.exe [2006-03-02 3584]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CyMiniProg3Service;CyMiniProg3Service; C:\Program Files\Cypress\Programmer\3.11\Service\CyMiniProg3Service.exe [2010-03-19 94208]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-10-24 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 LkCitadelServer;Lookout Citadel Server; C:\WINDOWS\system32\lkcitdl.exe [2008-10-31 695136]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 NILM License Manager;NILM License Manager; C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe [2009-09-18 1007616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 OpcEnum;OpcEnum; C:\WINDOWS\system32\OpcEnum.exe [2009-06-03 98304]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Naposledy upravil(a) karri84 dne 11 kvě 2010 16:08, celkem upraveno 1 x.

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: WORM_IRCBOT.BZQ

#2 Příspěvek od Caroprd111 »

Zdravím :)

Odstraňte prosím log z "Code".
Obrázek

karri84
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 11 kvě 2010 15:44

Re: WORM_IRCBOT.BZQ

#3 Příspěvek od karri84 »

Tak problém možná vyřešen.
Spustil jsem msconfig, našel že v:
C:\Documents and Settings\XXXXXXXX\Data aplikací\
je soubor windows.exe, který se spouští po spuštění.
Ten samý program byl vidět v Task Managerovi.
Ukončil jsem, soubor smazal.
Nyní se již nekopírují na přenosné disky žádně soubory samy od sebe. Uvidíme po restartu.

Problém zřejmě včera vznikl po vložení Flash Disku, který obsahoval autorun a windows.exe. Datum a čas vytvoření by odpovídal. Doporučuji nepotvrzovat "Přehrát automaticky".

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: WORM_IRCBOT.BZQ

#4 Příspěvek od Caroprd111 »

OK :)


Obrázek Vložte do PC všechny flash disky, které používáte.

Obrázek Stáhněte na plochu UsbFix http://pagesperso-orange.fr/NosTools/Ch ... UsbFix.exe
  • Spusťte, poté zvolte jazyk E - Enter
  • Zvolte 1 - Enter (je možný restart PC)
  • Po dokončení na Vás vyskočí log, vložte mi ho sem, případně ho najdete v C:\UsbFix.txt


Obrázek Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
  • Spusťte, poté do spodního políčka vložte následující skript.

Kód: Vybrat vše

 netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys 
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys 
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys 
cdrom.sys 
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav 
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT 
  • Označte položku Pro všechny uživatele.
  • Označte položky Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
  • Klikněte na tlačítko Prohledat
  • Po dokončení, sem vložte logy OTL.Txt a Extras.txt
Obrázek

karri84
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 11 kvě 2010 15:44

Re: WORM_IRCBOT.BZQ

#5 Příspěvek od karri84 »

Po restartu se zdá vše v pohodě, nicméně, spustil jsem oba doporučené SW.

U prvně jmenovaného SW mám problém s tím, že mi to píše že mám nepodporovanou verzi. Že je pouze pro XP, Vista, 7. Nevím co si o tom myslet, protože Mám XP, SP2.

Druhý zdá se pracuje bez problémů, přikládám požadované logy:
OTL logfile created on: 11.5.2010 19:17:31 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\KARAS\Plocha\ZÁPLATA
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 62,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,99 Gb Total Space | 1,15 Gb Free Space | 5,74% Space Free | Partition Type: NTFS
Drive D: | 86,92 Gb Total Space | 1,95 Gb Free Space | 2,25% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 3,76 Gb Total Space | 3,76 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
Drive G: | 970,11 Mb Total Space | 969,23 Mb Free Space | 99,91% Space Free | Partition Type: FAT
Drive H: | 241,73 Mb Total Space | 241,73 Mb Free Space | 100,00% Space Free | Partition Type: FAT
I: Drive not present or media not loaded

Computer Name: KARRI-NOUT
Current User Name: KARAS
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.05.11 18:54:08 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\KARAS\Plocha\ZÁPLATA\OTL.exe
PRC - [2010.05.11 15:47:36 | 000,840,416 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010.05.11 15:47:35 | 001,291,544 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010.04.03 07:19:48 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010.03.31 20:43:27 | 011,957,424 | ---- | M] (Mozilla Messaging) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe
PRC - [2010.01.22 21:36:00 | 000,621,320 | ---- | M] (http://tortoisesvn.net) -- C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
PRC - [2009.12.16 20:07:24 | 001,445,888 | ---- | M] (Mentor Graphics Corporation) -- D:\PROGRAMY\PADSINSTAL\9.1PADS\SDD_HOME\iCDB\win32\bin\iCDBNetLauncher.exe
PRC - [2009.12.02 16:37:06 | 008,456,704 | ---- | M] () -- D:\PROGRAMY\Psi\psi.exe
PRC - [2009.10.23 20:44:36 | 001,732,960 | ---- | M] (Diskeeper Corporation) -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
PRC - [2009.06.23 14:29:48 | 000,740,968 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
PRC - [2009.06.18 08:01:50 | 000,356,912 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
PRC - [2009.06.18 07:57:28 | 000,042,544 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\lkads.exe
PRC - [2009.06.18 07:56:32 | 000,053,296 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\lktsrv.exe
PRC - [2009.06.15 21:44:40 | 000,012,696 | ---- | M] (National Instruments Corporation) -- C:\Program Files\National Instruments\MAX\nimxs.exe
PRC - [2009.06.04 05:14:28 | 000,013,896 | ---- | M] (National Instruments Corporation) -- C:\WINDOWS\system32\nisvcloc.exe
PRC - [2009.05.31 13:56:42 | 000,054,784 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE
PRC - [2009.05.18 21:33:32 | 000,259,128 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\SSL VPN Client\Agent.exe
PRC - [2008.10.24 20:51:16 | 000,468,224 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2008.10.24 20:50:00 | 001,451,264 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2007.09.14 08:02:10 | 001,080,264 | ---- | M] (C. Ghisler & Co.) -- D:\PROGRAMY\TOTALCMD\TOTALCMD.EXE
PRC - [2006.10.14 17:37:40 | 000,110,592 | ---- | M] () -- C:\WINDOWS\ATK0100\HControl.exe
PRC - [2006.08.10 22:08:04 | 002,379,776 | ---- | M] () -- C:\WINDOWS\ATK0100\ATKOSD.exe
PRC - [2006.03.02 14:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010.05.11 18:54:08 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\KARAS\Plocha\ZÁPLATA\OTL.exe
MOD - [2009.07.12 02:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2006.12.01 23:56:00 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
MOD - [2006.10.27 00:48:42 | 002,210,608 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
MOD - [2006.10.27 00:48:34 | 000,955,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveUtil.dll
MOD - [2006.10.27 00:48:02 | 000,222,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
MOD - [2006.10.27 00:47:40 | 000,022,808 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveNew.dll
MOD - [2006.03.02 14:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2006.03.02 14:00:00 | 000,152,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rsaenh.dll
MOD - [2006.03.02 14:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010.05.11 15:47:35 | 001,291,544 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010.03.19 17:26:46 | 000,094,208 | ---- | M] (Cypress Semiconductor) [On_Demand | Stopped] -- C:\Program Files\Cypress\Programmer\3.11\Service\CyMiniProg3Service.exe -- (CyMiniProg3Service)
SRV - [2009.12.16 20:07:24 | 001,445,888 | ---- | M] (Mentor Graphics Corporation) [Auto | Running] -- D:\PROGRAMY\PADSINSTAL\9.1PADS\SDD_HOME\iCDB\win32\bin\iCDBNetLauncher.exe -- (MGC.SDD.RSCM.2007.8)
SRV - [2009.10.23 20:44:36 | 001,732,960 | ---- | M] (Diskeeper Corporation) [Auto | Running] -- C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe -- (Diskeeper)
SRV - [2009.09.18 11:10:28 | 001,007,616 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager)
SRV - [2009.06.23 14:29:48 | 000,740,968 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe -- (NITaggerService)
SRV - [2009.06.18 08:01:50 | 000,356,912 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2009.06.18 07:57:28 | 000,042,544 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\system32\lkads.exe -- (lkClassAds)
SRV - [2009.06.18 07:56:32 | 000,053,296 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\system32\lktsrv.exe -- (lkTimeSync)
SRV - [2009.06.15 21:44:40 | 000,012,696 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\Program Files\National Instruments\MAX\nimxs.exe -- (mxssvr)
SRV - [2009.06.04 05:14:28 | 000,013,896 | ---- | M] (National Instruments Corporation) [Auto | Running] -- C:\WINDOWS\System32\nisvcloc.exe -- (niSvcLoc)
SRV - [2009.06.03 11:26:34 | 000,098,304 | ---- | M] (OPC Foundation) [On_Demand | Stopped] -- C:\WINDOWS\system32\Opcenum.exe -- (OpcEnum)
SRV - [2009.05.31 13:56:42 | 000,054,784 | ---- | M] (Macrovision) [Auto | Running] -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2009.05.18 21:33:32 | 000,259,128 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\SSL VPN Client\Agent.exe -- (STCAgent)
SRV - [2008.10.31 15:52:54 | 000,695,136 | ---- | M] (National Instruments, Inc.) [On_Demand | Stopped] -- C:\WINDOWS\system32\lkcitdl.exe -- (LkCitadelServer)
SRV - [2008.10.24 20:56:30 | 000,019,200 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2008.10.24 20:51:16 | 000,468,224 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
SRV - [2008.07.29 19:16:38 | 000,132,096 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2006.03.02 14:00:00 | 000,003,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\System32\regedt32.exe -- (NOD32FiXTemDono)


========== Driver Services (SafeList) ==========

DRV - [2010.02.04 17:53:02 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2009.10.22 16:11:00 | 000,057,800 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftdibus.sys -- (FTDIBUS)
DRV - [2009.10.22 16:09:00 | 000,072,520 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ftser2k.sys -- (FTSER2K)
DRV - [2009.10.21 02:04:34 | 000,045,232 | ---- | M] (Diskeeper Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DKRtWrt.sys -- (DKRtWrt)
DRV - [2009.10.16 10:15:22 | 000,039,480 | R--- | M] (Cypress Semiconductor) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cypress\mprog1\PSoCUSB.sys -- (PSoCUSB)
DRV - [2009.08.16 13:13:37 | 000,029,184 | ---- | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AltiumUSBJtag.sys -- (AltiumUSBJtag)
DRV - [2009.05.31 13:56:44 | 000,012,464 | ---- | M] (Macrovision Europe Ltd) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2009.05.18 21:33:32 | 000,022,136 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CSVirtA.sys -- (CSVirtA)
DRV - [2009.05.06 14:58:01 | 000,665,600 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (hardlock)
DRV - [2009.05.06 14:58:01 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2009.05.06 14:57:34 | 000,054,272 | ---- | M] () [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\SSIPDDP.SYS -- (SSIPDDP)
DRV - [2009.01.14 16:03:26 | 000,050,176 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2008.10.24 20:53:28 | 000,034,824 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2008.10.24 20:46:24 | 000,053,256 | ---- | M] (ESET) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\easdrv.sys -- (easdrv)
DRV - [2008.10.24 20:45:32 | 000,039,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008.06.12 08:28:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2008.04.07 11:00:00 | 000,004,096 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [2007.12.19 10:40:34 | 000,053,760 | ---- | M] (Microchip Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\iqrfusb.sys -- (MCHPUSB)
DRV - [2007.07.04 22:55:40 | 002,304,000 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007.06.22 16:37:28 | 000,051,616 | ---- | M] (ELTIMA Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\evserial.sys -- (evserial) Virtual Serial Ports Driver (Eltima Softwate)
DRV - [2007.06.22 16:37:22 | 000,025,120 | ---- | M] (ELTIMA Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\evsbc.sys -- (VSBC) Virtual Serial Bus Enumerator (Eltima Software)
DRV - [2006.12.14 16:44:06 | 000,085,120 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2006.12.05 17:36:58 | 000,529,344 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2006.11.03 09:32:30 | 004,394,496 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006.08.07 13:13:50 | 000,980,608 | ---- | M] (Motorola Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smserial.sys -- (smserial)
DRV - [2005.07.14 12:14:34 | 000,027,904 | ---- | M] (REDC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\risdptsk.sys -- (risdptsk)
DRV - [2005.07.12 19:00:30 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005.02.17 23:07:48 | 000,005,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATKACPI.sys -- (MTsensor)
DRV - [2005.01.07 17:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.08.04 00:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004.05.28 10:13:04 | 000,016,269 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Running] -- C:\WINDOWS\ATK0100\ASNDIS5.sys -- (ASNDIS5)
DRV - [2004.03.24 19:21:30 | 000,006,689 | ---- | M] (Dallas Semiconductor MAXIM) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\DS1410D.SYS -- (DS1410D)
DRV - [2003.11.12 13:44:14 | 000,047,104 | ---- | M] (ELTIMA Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vserial.sys -- (VSerial)
DRV - [2003.10.07 11:49:20 | 000,018,167 | ---- | M] (ELTIMA Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\vsb.sys -- (vsbus)
DRV - [2003.07.29 09:57:20 | 000,040,448 | ---- | M] (DeviceGuys, Inc.) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\Dgivecp.Sys -- (DgiVecp)
DRV - [2002.12.17 05:41:10 | 000,076,288 | ---- | M] (Rainbow Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\Drivers\SENTINEL.SYS -- (Sentinel)
DRV - [2002.12.17 05:41:10 | 000,026,120 | R--- | M] (Rainbow Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SNTNLUSB.SYS -- (Sntnlusb)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-507921405-1364589140-682003330-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.neobux.com/?u=v
IE - HKU\S-1-5-21-507921405-1364589140-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7.3
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {de1b245c-de57-11da-ba2d-0050c2490048}:1.0.8
FF - prefs.js..extensions.enabledItems: silvermelxt@pardal.de:1.3.5
FF - prefs.js..extensions.enabledItems: {961408A3-C970-4577-970A-D97C29839A67}:1.3.5
FF - prefs.js..extensions.enabledItems: chromifox@altmusictv.com:3.6.5
FF - prefs.js..extensions.enabledItems: silvermel@pardal.de:1.3.5


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.04.03 07:19:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.04.16 22:46:15 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.03.31 20:43:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins

[2009.12.11 17:34:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Extensions
[2009.12.11 17:34:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010.05.11 06:46:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions
[2009.05.06 19:12:26 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010.04.16 01:18:58 | 000,000,000 | ---D | M] (Charamel) -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2010.04.16 01:19:15 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009.05.06 19:28:15 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2010.02.07 08:26:36 | 000,000,000 | ---D | M] (MinimizeToTray Plus) -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\{de1b245c-de57-11da-ba2d-0050c2490048}
[2010.03.21 00:50:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\chromifox@altmusictv.com
[2010.04.16 01:19:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\silvermel@pardal.de
[2010.04.16 01:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\silvermelxt@pardal.de
[2010.04.16 01:19:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\extensions\staged-xpis
[2009.01.06 00:25:32 | 000,001,447 | ---- | M] () -- C:\Documents and Settings\KARAS\Data aplikací\Mozilla\Firefox\Profiles\73y2futt.default\searchplugins\userlogos.xml
[2010.05.11 06:46:47 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009.07.31 14:06:48 | 001,654,784 | ---- | M] (LizardTech) -- C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll
[2009.10.07 17:11:28 | 000,025,088 | ---- | M] (National Instruments) -- C:\Program Files\Mozilla Firefox\plugins\nplv90win32.dll
[2010.03.19 22:45:32 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.03.19 22:45:32 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.03.19 22:45:32 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.03.19 22:45:32 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.03.19 22:45:32 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2006.03.02 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe ()
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [VSPDXP] C:\Program Files\VSPD XP\vspdconfig.exe ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-507921405-1364589140-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/sh ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.241.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.05.05 23:51:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{549960ff-39c3-11de-8684-0015af2f0ad2}\Shell\AutoRun\command - "" = F:\windows.exe -- File not found
O33 - MountPoints2\{704ff5cd-b307-11de-879e-0015af2f0ad2}\Shell\AutoRun\command - "" = WDSetup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.05.11 16:50:17 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.05.11 15:48:36 | 000,064,288 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2010.05.11 15:48:32 | 000,095,024 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010.05.11 15:45:10 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Data aplikací\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010.05.11 15:44:42 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2010.05.11 15:44:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Lavasoft
[2010.05.10 23:47:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\KARAS\Plocha\CSPROJ
[2010.05.10 22:41:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\KARAS\Plocha\ZÁPLATA
[2010.05.03 15:37:11 | 000,000,000 | ---D | C] -- C:\CARMS
[2010.05.03 15:36:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\KARAS\Plocha\CARMS
[2010.04.21 22:34:47 | 000,000,000 | ---D | C] -- C:\Program Files\Cherry Dolls
[2010.04.17 19:00:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\pads
[2010.04.17 18:54:15 | 000,415,504 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msrepl35.dll
[2010.04.17 18:54:15 | 000,287,504 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxbse35.dll
[2010.04.17 18:54:15 | 000,252,176 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msrd2x35.dll
[2010.04.17 18:54:15 | 000,250,128 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspdox35.dll
[2010.04.17 18:54:15 | 000,166,200 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msmask32.ocx
[2010.04.17 18:54:15 | 000,165,648 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstext35.dll
[2010.04.17 18:54:15 | 000,072,704 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\odbctl32.dll
[2010.04.17 18:54:15 | 000,067,376 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sysinfo.ocx
[2010.04.17 18:54:15 | 000,004,608 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\w95inf32.dll
[2010.04.17 18:54:15 | 000,002,272 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\w95inf16.dll
[2010.04.17 18:54:14 | 000,901,120 | R--- | C] (Three |D| Graphics, Inc.) -- C:\WINDOWS\System32\sscsdk32.dll
[2010.04.17 18:54:14 | 000,570,128 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dao350.dll
[2010.04.17 18:54:14 | 000,525,352 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dbgrid32.ocx
[2010.04.17 18:54:14 | 000,386,800 | R--- | C] (Sheridan Software Systems, Inc.) -- C:\WINDOWS\System32\sstbars.ocx
[2010.04.17 18:54:14 | 000,368,912 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\VBAR332.DLL
[2010.04.17 18:54:14 | 000,221,696 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fhtml.dll
[2010.04.17 18:54:14 | 000,200,496 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dblist32.ocx
[2010.04.17 18:54:14 | 000,194,248 | R--- | C] (Infragistics, Inc.) -- C:\WINDOWS\System32\ssscrl30.ocx
[2010.04.17 18:54:14 | 000,180,736 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fxls.dll
[2010.04.17 18:54:14 | 000,129,024 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2ftext.dll
[2010.04.17 18:54:14 | 000,123,664 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msjint35.dll
[2010.04.17 18:54:14 | 000,120,320 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fwordw.dll
[2010.04.17 18:54:14 | 000,113,664 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2frtf.dll
[2010.04.17 18:54:14 | 000,102,912 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2dnotes.dll
[2010.04.17 18:54:14 | 000,095,232 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2dpost.dll
[2010.04.17 18:54:14 | 000,092,160 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2dvim.dll
[2010.04.17 18:54:14 | 000,089,360 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vb5db.dll
[2010.04.17 18:54:14 | 000,075,264 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fwks.dll
[2010.04.17 18:54:14 | 000,074,240 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2dmapi.dll
[2010.04.17 18:54:14 | 000,073,728 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fsepv.dll
[2010.04.17 18:54:14 | 000,071,680 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fdif.dll
[2010.04.17 18:54:14 | 000,070,144 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2dapp.dll
[2010.04.17 18:54:14 | 000,067,584 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2frdef.dll
[2010.04.17 18:54:14 | 000,064,000 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2frec.dll
[2010.04.17 18:54:14 | 000,064,000 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2fcr.dll
[2010.04.17 18:54:14 | 000,058,880 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2ddisk.dll
[2010.04.17 18:54:14 | 000,056,320 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\u2l2000.dll
[2010.04.17 18:54:14 | 000,030,208 | R--- | C] (APEX Software Corporation) -- C:\WINDOWS\System32\xarray32.ocx
[2010.04.17 18:54:14 | 000,024,848 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msjter35.dll
[2010.04.17 18:54:13 | 001,050,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msjet35.dll
[2010.04.17 18:54:13 | 000,638,464 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\oc30.dll
[2010.04.17 18:54:13 | 000,349,896 | R--- | C] (Infragistics, Inc.) -- C:\WINDOWS\System32\ssa3d30.ocx
[2010.04.17 18:54:13 | 000,250,128 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msexcl35.dll
[2010.04.17 18:54:13 | 000,206,848 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\p2sodbc.dll
[2010.04.17 18:54:13 | 000,152,576 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\p2bdao.dll
[2010.04.17 18:54:13 | 000,112,640 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\p2irdao.dll
[2010.04.17 18:54:13 | 000,081,408 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\p2ctdao.dll
[2010.04.17 18:54:13 | 000,069,632 | R--- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\gswdll32.dll
[2010.04.17 18:54:13 | 000,059,392 | R--- | C] (Seagate Software Information Management Group, Inc.) -- C:\WINDOWS\System32\p2bbnd.dll
[2010.04.17 18:54:12 | 005,350,912 | R--- | C] (Seagate Software, Inc.) -- C:\WINDOWS\System32\crpe32.dll
[2010.04.17 18:54:12 | 000,993,996 | R--- | C] (Seagate Software, Inc.) -- C:\WINDOWS\System32\crystl32.ocx
[2010.04.17 18:54:12 | 000,860,160 | R--- | C] (Three |D| Graphics, Inc.) -- C:\WINDOWS\System32\ccsdk32.dll
[2010.04.17 18:54:12 | 000,290,816 | R--- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\gsw32.exe
[2010.04.17 18:54:12 | 000,249,856 | R--- | C] (Inner Media, Inc.) -- C:\WINDOWS\System32\dzactx.dll
[2010.04.17 18:54:12 | 000,229,888 | R--- | C] (Seagate Software, Information Management Group, Inc.) -- C:\WINDOWS\System32\crpaig32.dll
[2010.04.17 18:54:12 | 000,229,376 | R--- | C] (Inner Media, Inc.) -- C:\WINDOWS\System32\duzactx.dll
[2010.04.17 18:54:12 | 000,210,944 | R--- | C] (Bits Per Second Ltd) -- C:\WINDOWS\System32\graph32.ocx
[2010.04.17 18:54:12 | 000,089,600 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\grid32.ocx
[2010.04.17 18:54:11 | 000,661,504 | R--- | C] (APEX Software Corporation) -- C:\WINDOWS\System32\TDBG5.OCX
[2010.04.17 18:54:11 | 000,557,880 | R--- | C] (Bennet-Tec Information Systems, Inc) -- C:\WINDOWS\System32\TList5.ocx
[2010.04.17 18:54:10 | 001,021,624 | R--- | C] (FarPoint Technologies, Inc.) -- C:\WINDOWS\System32\SPR32X30.OCX
[2010.04.17 18:54:10 | 000,137,216 | R--- | C] (Desaware) -- C:\WINDOWS\System32\Dwspy32.dll
[2010.04.17 18:54:10 | 000,094,208 | R--- | C] (aaa) -- C:\WINDOWS\System32\CMDLGD6.dll
[2010.04.17 18:54:10 | 000,089,088 | R--- | C] (Desaware Inc.) -- C:\WINDOWS\System32\Dwcbk32.ocx
[2010.04.17 18:54:10 | 000,076,288 | R--- | C] (Blue Sky Software Corp.) -- C:\WINDOWS\System32\SMTHLP32.OCX
[2010.04.17 18:53:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\mgc
[2010.04.17 18:17:29 | 000,000,000 | ---D | C] -- C:\temp
[2010.04.17 18:16:49 | 000,000,000 | ---D | C] -- C:\MentorGraphics
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.05.11 19:00:13 | 000,000,388 | ---- | M] () -- C:\WINDOWS\tasks\CypressUpdateManager.job
[2010.05.11 18:24:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010.05.11 18:21:35 | 000,004,649 | ---- | M] () -- C:\WINDOWS\WINCMD.INI
[2010.05.11 18:20:24 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.05.11 18:20:22 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.05.11 18:20:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.05.11 17:36:06 | 006,029,312 | ---- | M] () -- C:\Documents and Settings\KARAS\NTUSER.DAT
[2010.05.11 17:36:06 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\KARAS\ntuser.ini
[2010.05.11 17:24:08 | 000,000,573 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.05.11 17:24:08 | 000,000,234 | ---- | M] () -- C:\boot.ini
[2010.05.11 17:24:07 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.05.11 15:48:20 | 000,095,024 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010.05.11 15:45:09 | 000,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Ad-Aware.lnk
[2010.05.11 01:43:55 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\KARAS\Local Settings\Data aplikací\housecall.guid.cache
[2010.05.10 22:47:14 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010.05.09 21:03:03 | 000,002,378 | ---- | M] () -- C:\WINDOWS\wcx_ftp.ini
[2010.05.04 01:08:26 | 000,066,954 | ---- | M] () -- C:\Documents and Settings\KARAS\Plocha\winscp405.ini
[2010.05.04 01:08:26 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\KARAS\PUTTY.RND
[2010.05.01 19:40:53 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.05.01 19:40:51 | 000,057,344 | ---- | M] () -- C:\Documents and Settings\KARAS\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.04.30 18:04:12 | 005,081,055 | ---- | M] () -- C:\Documents and Settings\KARAS\Plocha\statistika_mgr_studium_zkouska_scan.pdf
[2010.04.22 21:23:08 | 000,000,028 | ---- | M] () -- C:\WINDOWS\PADS Logic
[2010.04.22 20:39:45 | 000,114,826 | ---- | M] () -- C:\Documents and Settings\KARAS\Plocha\slozeniokresu.pdf
[2010.04.22 09:19:15 | 000,288,768 | ---- | M] () -- C:\Documents and Settings\KARAS\Plocha\SMD.doc
[2010.04.19 08:09:12 | 000,050,961 | -H-- | M] () -- C:\treeinfo.wc
[2010.04.19 08:06:43 | 000,100,456 | ---- | M] () -- C:\Documents and Settings\KARAS\Local Settings\Data aplikací\GDIPFONTCACHEV1.DAT
[2010.04.19 08:06:04 | 000,351,384 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.04.17 18:54:28 | 000,000,900 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\PADS Router.lnk
[2010.04.17 18:54:19 | 000,000,893 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\PADS Logic.lnk
[2010.04.17 18:54:19 | 000,000,885 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\PADS Layout.lnk
[2010.04.17 16:23:06 | 000,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini
[2010.04.17 16:22:08 | 000,000,028 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010.04.16 22:46:15 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Adobe Reader 9.lnk
[2010.04.13 17:39:09 | 000,435,594 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.13 17:39:09 | 000,432,516 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.04.13 17:39:09 | 000,079,440 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.04.13 17:39:09 | 000,068,490 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.13 17:39:08 | 001,028,848 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.05.11 15:49:37 | 000,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010.05.11 15:45:09 | 000,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Ad-Aware.lnk
[2010.05.11 01:43:55 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\KARAS\Local Settings\Data aplikací\housecall.guid.cache
[2010.05.03 15:37:12 | 000,000,760 | ---- | C] () -- C:\WINDOWS\DAINA.INI
[2010.05.01 19:01:48 | 000,000,388 | ---- | C] () -- C:\WINDOWS\tasks\CypressUpdateManager.job
[2010.04.30 18:03:56 | 005,081,055 | ---- | C] () -- C:\Documents and Settings\KARAS\Plocha\statistika_mgr_studium_zkouska_scan.pdf
[2010.04.22 21:23:08 | 000,000,028 | ---- | C] () -- C:\WINDOWS\PADS Logic
[2010.04.22 20:39:44 | 000,114,826 | ---- | C] () -- C:\Documents and Settings\KARAS\Plocha\slozeniokresu.pdf
[2010.04.22 09:19:14 | 000,288,768 | ---- | C] () -- C:\Documents and Settings\KARAS\Plocha\SMD.doc
[2010.04.17 18:54:28 | 000,000,900 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\PADS Router.lnk
[2010.04.17 18:54:19 | 000,000,893 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\PADS Logic.lnk
[2010.04.17 18:54:19 | 000,000,885 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\PADS Layout.lnk
[2010.04.17 18:54:14 | 000,073,184 | R--- | C] () -- C:\WINDOWS\System32\DAO2535.TLB
[2010.04.17 18:54:13 | 000,953,344 | R--- | C] () -- C:\WINDOWS\System32\pg32.dll
[2010.04.17 18:54:13 | 000,017,920 | R--- | C] () -- C:\WINDOWS\System32\implode.dll
[2010.04.17 18:54:12 | 000,808,700 | R--- | C] () -- C:\WINDOWS\System32\Win.tlb
[2010.04.17 18:54:12 | 000,193,024 | R--- | C] () -- C:\WINDOWS\System32\co2c40en.dll
[2010.03.28 23:39:54 | 000,000,028 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.01.11 00:03:03 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll
[2009.12.17 10:24:52 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mtstack16.INI
[2009.10.30 19:41:12 | 000,000,051 | ---- | C] () -- C:\WINDOWS\rocksoft.ini
[2009.10.07 08:05:38 | 000,002,705 | ---- | C] () -- C:\WINDOWS\PSPICEEV.INI
[2009.07.06 22:46:49 | 000,000,741 | ---- | C] () -- C:\WINDOWS\tcburner.ini
[2009.06.28 18:25:15 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009.06.14 15:15:52 | 000,000,244 | ---- | C] () -- C:\WINDOWS\System32\nirpc.ini
[2009.06.01 15:32:53 | 000,000,041 | ---- | C] () -- C:\WINDOWS\System32\winchap.dll
[2009.06.01 15:32:53 | 000,000,028 | ---- | C] () -- C:\WINDOWS\System32\wrginst.ini
[2009.05.06 14:58:01 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2009.05.06 14:57:39 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSIPDDP.SYS
[2009.05.06 10:25:02 | 000,002,378 | ---- | C] () -- C:\WINDOWS\wcx_ftp.ini
[2009.05.06 01:41:22 | 000,290,904 | ---- | C] () -- C:\WINDOWS\System32\vc6-re200l.dll
[2009.05.06 00:17:46 | 000,000,621 | ---- | C] () -- C:\WINDOWS\System32\drivers\AW1012d.ini
[2009.05.05 23:58:44 | 000,004,649 | ---- | C] () -- C:\WINDOWS\WINCMD.INI
[2009.05.05 22:36:21 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\drivers\ATKACPI.sys
[2008.10.24 20:53:28 | 000,034,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\epfwtdir.sys
[2008.04.07 11:00:00 | 000,004,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\cvintdrv.sys
[2006.03.02 14:00:00 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2006.03.02 14:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys

========== LOP Check ==========

[2009.05.31 13:54:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Autodesk
[2009.05.07 06:50:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\CanonBJ
[2010.01.13 22:00:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Cypress Semiconductor
[2010.02.15 22:13:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Diskeeper Corporation
[2009.05.07 14:28:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2009.06.01 15:32:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\IsolatedStorage
[2010.01.22 18:23:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\KASTNER software
[2010.04.17 18:53:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\mgc
[2010.03.05 11:26:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\National Instruments
[2010.04.17 19:00:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\pads
[2009.10.30 19:41:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Rockwell Software
[2010.03.25 07:15:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TEMP
[2009.11.04 22:29:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
[2009.11.04 22:29:00 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Data aplikací\{55A29068-F2CE-456C-9148-C869879E2357}
[2010.05.11 15:45:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Data aplikací\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2009.05.31 13:58:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Autodesk
[2009.05.10 12:21:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\CadSoft
[2010.03.14 23:14:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Canon
[2009.05.06 10:07:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Cypress_Semiconductor
[2009.06.01 15:32:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\EasyElectro
[2010.01.22 18:25:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Kastner software
[2009.05.26 20:34:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Meebo
[2009.06.06 08:40:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Opera
[2009.10.30 19:43:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Rockwell Software
[2010.03.20 00:07:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\SmartDraw
[2010.03.11 23:29:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Subversion
[2009.09.06 00:10:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Thinstall
[2009.12.11 17:34:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\Thunderbird
[2009.11.04 22:30:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\TuneUp Software
[2010.05.10 22:48:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\uTorrent
[2010.02.19 23:15:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\KARAS\Data aplikací\VitySoft
[2010.05.11 18:24:01 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010.05.11 19:00:13 | 000,000,388 | ---- | M] () -- C:\WINDOWS\Tasks\CypressUpdateManager.job

========== Purity Check ==========


< End of report >

karri84
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 11 kvě 2010 15:44

Re: WORM_IRCBOT.BZQ

#6 Příspěvek od karri84 »

OTL Extras logfile created on: 11.5.2010 19:17:31 - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\KARAS\Plocha\ZÁPLATA
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 62,00% Memory free
3,00 Gb Paging File | 3,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19,99 Gb Total Space | 1,15 Gb Free Space | 5,74% Space Free | Partition Type: NTFS
Drive D: | 86,92 Gb Total Space | 1,95 Gb Free Space | 2,25% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 3,76 Gb Total Space | 3,76 Gb Free Space | 100,00% Space Free | Partition Type: FAT32
Drive G: | 970,11 Mb Total Space | 969,23 Mb Free Space | 99,91% Space Free | Partition Type: FAT
Drive H: | 241,73 Mb Total Space | 241,73 Mb Free Space | 100,00% Space Free | Partition Type: FAT
I: Drive not present or media not loaded

Computer Name: KARRI-NOUT
Current User Name: KARAS
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_USERS\S-1-5-21-507921405-1364589140-682003330-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DoNotAllowExceptions" = 0
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\PROGRAMY\Psi\psi.exe" = D:\PROGRAMY\Psi\psi.exe:*:Enabled:psi -- ()
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE" = C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE" = C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove -- (Microsoft Corporation)
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE" = C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote -- (Microsoft Corporation)
"C:\Program Files\uTorrent\utorrent.exe" = C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"D:\PROGRAMY\TOTALCMD\TOTALCMD.EXE" = D:\PROGRAMY\TOTALCMD\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows -- (C. Ghisler & Co.)
"D:\PROGRAMY\_IMAGES\ALTIUM_SUMMER_09\Altium Designer Summer 09.exe" = D:\PROGRAMY\_IMAGES\ALTIUM_SUMMER_09\Altium Designer Summer 09.exe:*:Enabled:Altium Designer Summer 09 -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{003C932A-0064-B581-3935-284D2CE76A89}" = Catalyst Control Center Core Implementation
"{00BA866C-F2A2-4BB9-A308-3DFA695B6F7C}" = Java DB 10.5.3.0
"{044F9133-B8D7-4d11-BF39-803FA20F5C8B}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{05046BCC-5E64-4A85-8615-D84DE4C1D865}" = NI VC2005MSMs x86
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{07A99739-82EE-4537-AF2E-1607015D9992}" = NI Service Locator
"{080CBAA8-7B7D-4C83-BCA5-7E07AF32E5BF}" = ESET NOD32 Antivirus
"{08133ED0-B6EB-49CD-B0EF-60502E41D15E}" = NI Xerces Delay Load 2.7.1
"{0AD37499-3D5D-12F0-EBEA-46EE9AD02DBF}" = Catalyst Control Center Localization German
"{0ADC98E8-BDD7-42F7-AC15-093C1B54CDAE}" = Macrovision FLEXid Drivers
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{1742237A-0E60-40A1-9B5C-824450FCBD59}" = FLEXid8 Driver
"{174D7CC5-1117-29D3-8422-2E54ADF7DB5D}" = Catalyst Control Center Localization Norwegian
"{19C120B7-F7A6-4105-9D62-1F6305B2E2CF}" = NI DataSocket 4.7.0
"{1B06E3AF-1CE2-4085-AE4E-DFEC369E86D3}" = NI Logos XT Support
"{1E0E1039-E45D-7EA2-E377-E00C2857E0C2}" = ccc-core-static
"{1FBC283A-8B22-48FA-9DFA-6C65E34455FA}" = NI LabVIEW Real-Time NBFifo
"{21742BF7-C002-40A7-9FF3-49D9A09DC3A8}" = AVRStudio4
"{21A1D4A5-3D9B-9434-4F97-40367BDF4E47}" = Catalyst Control Center Graphics Full New
"{23170F69-40C1-2701-0465-000001000000}" = 7-Zip 4.65
"{23894154-0961-CD0A-BAC0-67E6E96165C3}" = CCC Help Chinese Standard
"{24DFAAD6-E1ED-F588-2AD5-2EA4FE9113AE}" = CCC Help Korean
"{26886987-D038-7438-8DF2-ED3B1888E052}" = CCC Help Hungarian
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java(TM) 6 Update 18
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{291F65CB-4D0E-48F3-8564-014B46C186B8}" = Mentor Graphics CAMCAD Runtime install
"{2A98DB42-3743-4022-ADFA-42AE811484AE}" = NI EULA Depot
"{2C6D0ACD-DD2B-BFE5-A005-53AFD4AA3175}" = Catalyst Control Center Localization Spanish
"{2D50DC1F-FCEC-D970-1DFB-E73CF2404451}" = Catalyst Control Center Localization Hungarian
"{306682DE-BB8E-CD56-9F6B-DE209469418A}" = CCC Help Turkish
"{310477AD-884B-736D-B2C8-7BE9433B243D}" = CCC Help Swedish
"{31814F2E-FA58-AFE8-DC97-3BD97F7191C2}" = CCC Help Greek
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{32A3A4F4-B792-11D6-A78A-00B0D0160180}" = Java(TM) SE Development Kit 6 Update 18
"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook
"{342D4AD7-EC4C-4EC8-AEA6-E70F5905A490}" = SQL Server System CLR Types
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{354F7470-D8E3-95D0-3488-B9E32D5E9636}" = CCC Help German
"{36CDA33B-909B-4719-97D1-C4B99309BDC7}" = ATI Parental Control & Encoder
"{380FAC97-C47F-C5A9-2A51-DFF8DE144B37}" = Catalyst Control Center Localization Italian
"{383AD0A2-FD79-4CF0-B823-C695E32BD08D}" = NI LabVIEW Run-Time Engine Web Services
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{407A5080-4B1C-A43D-9EED-A3B5EDBCF593}" = CCC Help Polish
"{44D4AF75-6870-41F5-9181-662EA05507E1}" = Microsoft Document Explorer 2005
"{45A5461A-7D1D-4A91-B033-0B85E7AB25C2}" = NI MXS 4.6.0f0 for LabVIEW Real-Time
"{46FE06BF-2A08-9D00-ABFD-7F967817E275}" = Catalyst Control Center Localization Swedish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B50D80D-A482-DECD-B584-EB054EBA878A}" = ccc-core-preinstall
"{4B8ACECB-D518-99AA-B1F3-E79F905A83EE}" = Catalyst Control Center Localization Czech
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{50F9A1FC-39D8-46E8-8234-1A1A68A4033E}" = NI Variable Engine 2.3.0
"{52C3DD72-17E5-4E0D-83A8-FB42FCE3A8EF}" = NI-RPC 4.1.1f0 for Phar Lap ETS
"{5783F2D7-0201-0405-0002-0060B0CE6BBA}" = AutoCAD 2004
"{57B77060-04B4-468E-89A9-F68EEE466F57}" = NI USI 1.7.0
"{5A70FCD2-C019-4723-868F-07CD6C7755FF}" = NI Logos 5.1
"{5ABA84ED-D61B-257F-809F-A8C883865854}" = Catalyst Control Center Localization Dutch
"{5B464CAC-76BD-BDBB-8066-318D05D171DF}" = Catalyst Control Center Localization Finnish
"{5BE1E709-30E4-3D6D-A708-96CE8D5E5E8D}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{5C7332EA-BFB9-24A0-BDD9-254F4B113E41}" = Catalyst Control Center Localization Polish
"{5D0C5394-0813-424D-A48C-8986113329C9}" = Cypress Update Manager
"{5DC6B387-DCD5-4B66-B866-434020FF2ECC}" = TortoiseSVN 1.6.7.18415 (32 bit)
"{6426C1E8-ADD6-F91F-C152-2ABB7AB25F9F}" = Catalyst Control Center Graphics Full Existing
"{6447FE3A-8B2C-41DB-9791-322B8445B3E9}" = NI LabVIEW Deployable License 2009
"{66B5F542-952C-F50D-BFF3-BCA582B65860}" = Catalyst Control Center Localization Turkish
"{67213BA8-70C6-458D-9B64-4B93FB35E84B}" = CCC Help Italian
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6AA66ACB-E93C-C7CD-F303-D473AEC8A43E}" = CCC Help Norwegian
"{6D5DC54D-B06E-32A8-A5D9-4978D7A75FA1}" = Catalyst Control Center Localization Japanese
"{6DC712D0-A8AE-70EE-215D-ECE5DB29782C}" = Skins
"{6F7D11DC-DE87-45C8-A37E-A35B724FC771}" = NI Help Assistant
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{782BC438-2C73-77F4-F5B6-7ADC87F611BB}" = CCC Help Spanish
"{791A19F4-E4E5-F4B0-7687-F5D1C4FF799A}" = Catalyst Control Center Graphics Light
"{7ACFB216-29F7-4331-A5ED-2563AEB51F21}" = NI Trace Engine
"{7B8CE908-BF69-4E20-9BFE-681C573879F1}" = NI LabVIEW Run-Time Engine 2009
"{7BBA76B4-CC34-0AAB-6D48-BE0181E20832}" = CCC Help Dutch
"{7E7A035C-9DC5-40B0-B873-002B14CCE3B8}" = NI-RPC 4.1.1f0
"{7F311276-1CD6-1661-8BAE-DD9016FE9B8D}" = Catalyst Control Center Localization Russian
"{7F947BFE-C2DF-4779-9909-5BEE746BD0C4}" = Microsoft .NET Framework 2.0 Language Pack - CSY
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{84C89CF4-F64E-6820-375C-24963DDF99C9}" = Catalyst Control Center Localization Greek
"{8B7917E0-AF55-4E8A-9473-017F0AA03AC8}" = QuickTime
"{8C0D145D-EB41-E1DB-6250-0146B02CBA3A}" = CCC Help Japanese
"{8D015A2F-4D85-419E-8E1D-93B0C246D491}" = Diskeeper 2010 Pro Premier
"{8F5D6849-1A7E-B0B2-F1DE-C0FF21F9E78C}" = CCC Help French
"{90120000-0010-0405-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Czech) 12
"{90120000-0015-0405-0000-0000000FF1CE}" = Microsoft Office Access MUI (Czech) 2007
"{90120000-0016-0405-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Czech) 2007
"{90120000-0018-0405-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Czech) 2007
"{90120000-0019-0405-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Czech) 2007
"{90120000-001A-0405-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Czech) 2007
"{90120000-001B-0405-0000-0000000FF1CE}" = Microsoft Office Word MUI (Czech) 2007
"{90120000-001F-0405-0000-0000000FF1CE}" = Microsoft Office Proof (Czech) 2007
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-041B-0000-0000000FF1CE}" = Microsoft Office Proof (Slovak) 2007
"{90120000-002C-0405-0000-0000000FF1CE}" = Microsoft Office Proofing (Czech) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-0405-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Czech) 2007
"{90120000-006E-0405-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Czech) 2007
"{90120000-00A1-0405-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Czech) 2007
"{90120000-00BA-0405-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Czech) 2007
"{944DA8EF-FD4E-1FD9-D88A-B22D78913BE6}" = Catalyst Control Center Localization Portuguese
"{97F5E039-D2F5-18C0-F0C9-6981F73514CC}" = Catalyst Control Center Localization French
"{9CAE8EA0-EB7E-4039-BDA8-B76ADC4CF710}" = PSoc Programmer 3.11
"{9E684286-287F-AE06-6909-31A0944A9B4F}" = Catalyst Control Center Localization Danish
"{A0CE9CC5-B17D-3FD5-20B9-A2509B475A20}" = ccc-utility
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A35D49A6-F3CF-87AA-6FF1-777D8A06BAB1}" = CCC Help English
"{A4121C0A-438D-426D-986F-4E14BBBAB2A3}" = MGC Visual Studio 7 Runtime
"{A4418082-E601-3954-805B-D56A2B50EC8B}" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"{ABD79E99-F9E3-413B-8D18-11070754355F}" = NI Math Kernel Libraries
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{AC76BA86-7AD7-2448-0000-900000000003}" = Chinese Traditional Fonts Support For Adobe Reader 9
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{AE9AA575-DE74-4711-B3B3-2977D76CC1BB}" = NI TDMS
"{AFEDF70D-8DC3-40CB-93A0-F276E64BDF9C}" = NI VC2008MSMs x86
"{B2CEACB9-7690-30B5-D80A-B138DB4F0E37}" = Catalyst Control Center Localization Chinese Traditional
"{B963C648-249B-4145-BC14-56488262E9A9}" = NI MDF Support
"{BA0C85C1-E5CC-4F58-84FB-8DA29F3412F0}" = NI Uninstaller
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5CF0F7B-312C-45DC-BC45-3F1A2CCD6FDA}" = LM Flash Programmer
"{C9894B05-06D2-4F85-86C8-6B0D011A6BA5}" = NI License Manager
"{CA9A3609-3ECC-4574-8824-A8161A71A603}" = Canon MP150
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D26970AA-C66F-142F-7C66-A73FC3546F57}" = CCC Help Russian
"{D5D88F8F-FDA4-4CF4-9F3E-3F40118C2120}" = AVRStudio4
"{D76162F1-AFAC-47BE-9302-5F35491725E1}" = NI LabVIEW Run-Time Engine Interop 2009
"{D88DB576-0989-879A-38B1-7ED6224B2F52}" = Catalyst Control Center Localization Thai
"{D8B87EBC-12C2-D4FC-F085-A062D4906216}" = CCC Help Danish
"{DA516B86-CA87-42D0-8959-D8CE5D088E8C}" = PSoC Programmer 3.11 Production
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E1BBBAC5-2857-4155-82A6-54492CE88620}" = Opera 9.64
"{E2A05D36-56EF-84FC-E7D7-090D6E5F09BC}" = CCC Help Finnish
"{E4DA4D2C-F57F-782E-752E-9286E5713297}" = Catalyst Control Center Localization Korean
"{E4E118EF-5286-915B-7DBD-D931AB9AF200}" = CCC Help Portuguese
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E5B85BE7-55B5-0A14-7634-FEF92BCB87FB}" = CCC Help Chinese Traditional
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F19E2B0A-2249-45DA-92DB-0CE0DEB8E8A4}" = NI OPC Support
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F384BD83-C317-94DA-A4AB-3E75E43F4F8C}" = Catalyst Control Center Localization Chinese Standard
"{F5E87B12-3C27-452F-8E78-21D42164FD83}" = Microsoft SQL Server 2008 Management Objects
"{F622BE4A-363F-F2B6-1F98-54E5E99B1750}" = CCC Help Thai
"{F6D39840-BB27-A191-BDF2-1841CA805D24}" = CCC Help Czech
"{F827F574-36ED-4D97-820A-AD6F74E02D0D}" = NI MXS 4.6.0
"{FE24BCDF-9231-450D-AA08-D3550B81EE41}" = NI LabVIEW Web Server for Run-Time Engine
"µTorrent CZ_is1" = µTorrent CZ 1.8.4 (build 16442)
"06DBCB3D3DD4D422BAAC9300B7928951376D1ED0" = Balíček ovladače systému Windows - Cypress USB Driver for PSoC3 FirstTouch Kit (06/05/2009 3.4.1.20)
"0B2054297EA51DF25D0963689031FA5711041DDD" = Balíček ovladače systému Windows - Cypress USB Driver for MiniProg1 (06/05/2009 3.4.1.20)
"23C892DBF52DDAF3C9BD2BB6E9805E79FCD09A67" = Windows Driver Package - FTDI CDM Driver Package (05/19/2006 2.00.00)
"50991BD0F3954278F50AF565075F484768B983ED" = Balíček ovladače systému Windows - Cypress USB Driver for FirstTouch Kit (06/05/2009 3.4.1.20)
"57372CC6C7D4040AF30B9B830C6BD8F20B6D72C1" = Balíček ovladače systému Windows - Cypress USB Driver for ICE cube (06/05/2009 3.4.1.20)
"8CEE852E409CB5B6EDAB1888F6BD1FD269A26B33" = Balíček ovladače systému Windows - Cypress USB Driver for FirstTouchRF Kit (06/05/2009 3.4.1.20)
"A2E63BDAC649E514867CB43CE0B4F9DB111206C2" = Windows Driver Package - FTDI CDM Driver Package (05/19/2006 2.00.00)
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Advanced Grapher_is1" = Advanced Grapher 2.2
"Advanced Serial Port Terminal_is1" = Advanced Serial Port Terminal 5.5 (Build 5.5.22.271)
"All ATI Software" = Softarová utilita ATI - Odinstalovat
"ATI Display Driver" = ATI Display Driver
"BC04205E2BE7D324471C260AA412313FE125F88C" = Balíček ovladače systému Windows - Cypress USB Driver for MiniProg3 (06/05/2009 3.4.1.20)
"C38D9B930CD2C4DA4D699D781527D94F5CC30389" = Balíček ovladače systému Windows - Cypress USB Driver for PSoC 5 FirstTouch Kit (06/05/2009 3.4.1.20)
"CdaC13Ba" = SafeCast Shared Components
"Cisco Systems SSL VPN Client" = Cisco SSL VPN Client
"EAGLE 5.2.0" = EAGLE 5.2.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Eset NOD32 v3.0.642 FiX1.2 by TemDono_is1" = NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up
"ESET Online Scanner" = ESET Online Scanner v3
"FSCZ_is1" = FORM studio
"HControl" = ATK0100 ACPI UTILITY
"HTML Compress_is1" = HTML Compress
"HWGUDPCONFIG_is1" = UDP Config 4.9.2
"IQRF IDE_is1" = IQRF IDE 2.04
"IrfanView" = IrfanView (remove only)
"Keil µVision3" = Keil µVision3
"MatlabR2008a" = MATLAB R2008a
"MentorGraphicsJI" = Mentor Graphics Products
"Microsoft .NET Framework 2.0 Language Pack - CSY" = Microsoft .NET Framework 2.0 Language Pack - CSY
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Document Explorer 2005" = Microsoft Document Explorer 2005
"Microsoft Visual C# 2008 Express Edition with SP1 - ENU" = Microsoft Visual C# 2008 Express Edition with SP1 - ENU
"MozBackup" = MozBackup 1.4.9
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Mozilla Thunderbird (3.0.4)" = Mozilla Thunderbird (3.0.4)
"MP Navigator 2.0" = Canon MP Navigator 2.0
"nbi-glassfish-mod-sun-3.0.0.74.2" = Sun GlassFish Enterprise Server v3
"nbi-nb-base-6.8.0.0.0" = NetBeans IDE 6.8
"Nero - Burning Rom!UninstallKey" = Nero 6
"NI Uninstaller" = National Instruments Software
"PowerISO" = PowerISO
"PSPad editor_is1" = PSPad editor
"PSpice Student" = PSpice Student 9.1
"Rainbow Sentinel Driver" = Sentinel System Driver
"RFSim99" = RFSim99
"SMSERIAL" = Motorola SM56 Data Fax Modem
"uTorrent" = µTorrent
"Virtual Serial Ports Driver XP_is1" = Virtual Serial Ports Driver XP
"Virtual Serial Ports Driver_is1" = Virtual Serial Port Driver 6.0 (6.0.1.115)
"VLC media player" = VLC media player 0.9.9
"WIC" = Windows Imaging Component
"Winamp" = Winamp
"WinAVR-20090313" = WinAVR 20090313 (remove only)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Xerox Phaser 3117" = Xerox Phaser 3117

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-507921405-1364589140-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Meebo Notifier" = Meebo Notifier

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10.5.2010 19:23:21 | Computer Name = KARRI-NOUT | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 10.5.2010 21:03:14 | Computer Name = KARRI-NOUT | Source = Ci | ID = 4118
Description = Nebylo možné dokončit prohledávání obsahu d:\.

Error - 10.5.2010 21:03:14 | Computer Name = KARRI-NOUT | Source = Ci | ID = 4118
Description = Nebylo možné dokončit prohledávání obsahu c:\.

Error - 11.5.2010 4:36:23 | Computer Name = KARRI-NOUT | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 11.5.2010 6:46:57 | Computer Name = KARRI-NOUT | Source = Diskeeper | ID = 5
Description = Diskeeper Control Center - ERROR The Diskeeper News and Information
feature was unable to contact the Diskeeper Corporation web server. Ensure this
computer has Internet access. The Error Code is 5.

Error - 11.5.2010 9:05:14 | Computer Name = KARRI-NOUT | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 11.5.2010 9:45:55 | Computer Name = KARRI-NOUT | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 11.5.2010 9:50:46 | Computer Name = KARRI-NOUT | Source = STCAgent | ID = 50331650
Description = Termination reason code 10 [FAST_USER_SWITCH]

Error - 11.5.2010 11:09:38 | Computer Name = KARRI-NOUT | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 11.5.2010 13:15:24 | Computer Name = KARRI-NOUT | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace OTL.exe, verze 3.2.4.1, zablokovaný modul hungapp,
verze 0.0.0.0, adresa bloku 0x00000000.

[ OSession Events ]
Error - 7.3.2010 7:05:45 | Computer Name = KARRI-NOUT | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3937
seconds with 1080 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 11.5.2010 9:05:42 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba Eset Nod32 Boot neuspěla při spuštění v důsledku následující
chyby: %%1053

Error - 11.5.2010 9:51:07 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba SSIPDDP neuspěla při spuštění v důsledku následující chyby:
%%1332

Error - 11.5.2010 9:51:07 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba IOPort neuspěla při spuštění v důsledku následující chyby:
%%2

Error - 11.5.2010 9:51:07 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Eset Nod32 Boot.

Error - 11.5.2010 9:51:07 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba Eset Nod32 Boot neuspěla při spuštění v důsledku následující
chyby: %%1053

Error - 11.5.2010 9:51:49 | Computer Name = KARRI-NOUT | Source = System Error | ID = 1003
Description = Kód chyby 10000050, parametr1 d39040a8, parametr2 00000000, parametr3
805674c7, parametr4 00000000.

Error - 11.5.2010 12:20:49 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba SSIPDDP neuspěla při spuštění v důsledku následující chyby:
%%1332

Error - 11.5.2010 12:20:49 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba IOPort neuspěla při spuštění v důsledku následující chyby:
%%2

Error - 11.5.2010 12:20:49 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7009
Description = Vypršel časový limit (30000 milisekund) čekání na připojení služby
Eset Nod32 Boot.

Error - 11.5.2010 12:20:49 | Computer Name = KARRI-NOUT | Source = Service Control Manager | ID = 7000
Description = Služba Eset Nod32 Boot neuspěla při spuštění v důsledku následující
chyby: %%1053


< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: WORM_IRCBOT.BZQ

#7 Příspěvek od Caroprd111 »

Podle pravidel fóra se zde nelegálním softwarem nezabýváme (nelegální programy představují bezpečnostní hrozbu).
Obstarejte si legální zabezpečení PC (antivir, firewall), poté sem vložte nový log z RSIT a log z CKScanner.

Vyberte si třeba free Aviru nebo Avast + nějaký firewall (doporučuji ZoneAlarm) http://www.viry.cz/forum/viewtopic.php?f=29&t=6152 + http://www.viry.cz/forum/viewtopic.php?f=41&t=6523

Obrázek Stáhněte na plochu CKScanner http://downloads.malwareremoval.com/CKScanner.exe
  • Spusťte a klikněte na "Search For Files", po dokončení skenu klikněte na "Save List to File" -> "OK"
  • Log s názvem ckfiles.txt bude uložený na ploše, obsah tohoto souboru sem vložte.
Obrázek

Odpovědět