
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o kontrolu
- scan combofix nerobil - ponúkol mi dokonca novú verziu
- musela som PC reštartovať - nejak zamrzol
- potom hláška - že sa systém obnovuje po vážnej chybe
- a nakoniec sa cobofix rozbehol:
ComboFix 10-06-13.04 - Admin 14.06.2010 23:48:19.6.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1588 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-06-05 18:31 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-14 23:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-14 23:51:42
ComboFix-quarantined-files.txt 2010-06-14 21:51
ComboFix2.txt 2010-06-14 17:01
Pre-Run: 72 546 258 944 bytes free
Post-Run: 72 536 178 688 bytes free
- - End Of File - - DEC4F7F551974DF41696EF0059C8C39B
- musela som PC reštartovať - nejak zamrzol
- potom hláška - že sa systém obnovuje po vážnej chybe
- a nakoniec sa cobofix rozbehol:
ComboFix 10-06-13.04 - Admin 14.06.2010 23:48:19.6.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1588 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-06-05 18:31 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-14 23:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-14 23:51:42
ComboFix-quarantined-files.txt 2010-06-14 21:51
ComboFix2.txt 2010-06-14 17:01
Pre-Run: 72 546 258 944 bytes free
Post-Run: 72 536 178 688 bytes free
- - End Of File - - DEC4F7F551974DF41696EF0059C8C39B
Re: Prosím o kontrolu


Registry::
[-HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
ComboFix 10-06-13.04 - Admin 15.06.2010 0:07.7.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1501 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-06-05 18:31 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-15 00:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-15 00:09:41
ComboFix-quarantined-files.txt 2010-06-14 22:09
ComboFix2.txt 2010-06-14 21:51
ComboFix3.txt 2010-06-14 17:01
Pre-Run: 72 545 058 816 bytes free
Post-Run: 72 535 207 936 bytes free
- - End Of File - - 643F1ADC60DDB9371EFAE058133FD7E0
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1501 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-14 to 2010-06-14 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-06-05 18:31 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-15 00:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-15 00:09:41
ComboFix-quarantined-files.txt 2010-06-14 22:09
ComboFix2.txt 2010-06-14 21:51
ComboFix3.txt 2010-06-14 17:01
Pre-Run: 72 545 058 816 bytes free
Post-Run: 72 535 207 936 bytes free
- - End Of File - - 643F1ADC60DDB9371EFAE058133FD7E0
Re: Prosím o kontrolu
Nechce se mu od Vás, Uvidíme, co vyštourá mbam
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.


-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
Pekný nový deň ...
MBA som robila prvýkrát a hneď aj zle
- prvý som zvolila rýchly scan a mazala som PRED vaším vyzvaním (asi mám tiež nejaký vírus v hlave
)
1.(rýchly scan) log
Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org
Verzia databázy: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
15.6.2010 7:07:28
mbam-log-2010-06-15 (07-07-28).txt
Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 115162
Uplynulý čas: 2 min, 58 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 1
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
2.(úplný scan) log
Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org
Verzia databázy: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
15.6.2010 7:58:25
mbam-log-2010-06-15 (07-58-25).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 218266
Uplynulý čas: 25 min, 30 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
MBA som robila prvýkrát a hneď aj zle


1.(rýchly scan) log
Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org
Verzia databázy: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
15.6.2010 7:07:28
mbam-log-2010-06-15 (07-07-28).txt
Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 115162
Uplynulý čas: 2 min, 58 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 1
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
2.(úplný scan) log
Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org
Verzia databázy: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
15.6.2010 7:58:25
mbam-log-2010-06-15 (07-58-25).txt
Typ kontroly: Úplná kontrola (C:\|D:\|)
Objektov kontrolovaných: 218266
Uplynulý čas: 25 min, 30 sek
Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registračné kľúče: 0
Infikované registračné hodnoty: 0
Infikované položky registračných dát: 0
Infikované priečinky: 0
Infikované súbory: 0
Infikované služby pamäte:
(Škodlivé položky neboli zistené)
Infikované moduly pamäte:
(Škodlivé položky neboli zistené)
Infikované registračné kľúče:
(Škodlivé položky neboli zistené)
Infikované registračné hodnoty:
(Škodlivé položky neboli zistené)
Infikované položky registračných dát:
(Škodlivé položky neboli zistené)
Infikované priečinky:
(Škodlivé položky neboli zistené)
Infikované súbory:
(Škodlivé položky neboli zistené)
Re: Prosím o kontrolu
Jak to ted vypadá s počítačem?
Zopakujte skript na combofix s tímto textem
Killall::
Registry::
[-HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Zopakujte skript na combofix s tímto textem
Killall::
Registry::
[-HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
- PC sa dnes samočinne nevypína
- po vložení nového skriptu nabehlo
"vyskytol sa problém s aplikáciou CSS ...."
"there´s a newer version of combofix available ... update combofis"
- po vložení nového skriptu nabehlo
"vyskytol sa problém s aplikáciou CSS ...."
"there´s a newer version of combofix available ... update combofis"
Re: Prosím o kontrolu
Stahněte si nový combofix
Ten starý odstraňte
Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.

Ten starý odstraňte

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
Ďakujem za trpezlivosť
neviem, či je v poriadku, že po neúspešných scanoch COMBofixom, jeho odinštalovaní sa mi nedá pripojiť na net - vždy musím PC reštartovať - aj teraz po inštalovaní nového COMB
ComboFix 10-06-14.03 - Admin 15.06.2010 17:10:33.8.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1421 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-15 13:16 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-29 13:39 . 2010-06-15 04:56 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-06-15 04:56 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-15 17:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1976)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-15 17:13:50
ComboFix-quarantined-files.txt 2010-06-15 15:13
Pre-Run: 72 708 997 120 bytes free
Post-Run: 72 698 843 136 bytes free
- - End Of File - - D6BCC7C3063876BB54278DCE13065B21
???
TERAZ mám vložiť ten skript na combofix s tímto textem
Killall::
Registry::
[-HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]

ComboFix 10-06-14.03 - Admin 15.06.2010 17:10:33.8.2 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.2047.1421 [GMT 2:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 )))))))))))))))))))))))))))))))
.
2010-06-11 09:30 . 2010-06-14 13:02 -------- d-----w- c:\program files\trend micro
2010-06-11 09:30 . 2010-06-11 09:30 -------- d-----w- C:\rsit
2010-06-06 17:18 . 2010-06-06 17:18 -------- d-----w- c:\program files\Photo Story 3 for Windows
2010-06-01 12:26 . 2010-06-14 18:46 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Thunderbird
2010-06-01 12:26 . 2010-06-01 12:26 -------- d-----w- c:\documents and settings\Admin\Application Data\Thunderbird
2010-05-28 19:31 . 2010-05-28 19:31 -------- d-----w- c:\documents and settings\Admin\dwhelper
2010-05-25 12:11 . 2010-05-25 12:11 -------- d-----w- c:\program files\MSXML 4.0
2010-05-23 15:01 . 2010-03-29 11:04 81920 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
2010-05-21 06:11 . 2010-05-21 06:11 -------- d-----w- c:\program files\QuickTime
2010-05-21 05:40 . 2010-05-21 05:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Hot_MP3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-15 13:16 . 2009-09-20 15:27 -------- d-----w- c:\documents and settings\Admin\Application Data\AIMP
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 04:56 . 2010-06-15 04:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-06 17:50 . 2009-10-27 15:48 -------- d-----w- c:\program files\Flock
2010-06-05 20:41 . 2009-02-05 19:43 -------- d-----w- c:\documents and settings\Admin\Application Data\Skype
2010-06-05 18:32 . 2009-02-05 19:46 -------- d-----w- c:\documents and settings\Admin\Application Data\skypePM
2010-05-21 06:11 . 2010-03-05 07:15 -------- d-----w- c:\program files\Common Files\Apple
2010-05-13 10:18 . 2009-03-20 21:42 -------- d-----w- c:\program files\Alwil Software
2010-05-13 10:16 . 2010-05-13 10:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-12 09:21 . 2009-10-03 12:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 19:55 . 2009-02-05 14:04 -------- d-----w- c:\program files\ALFA
2010-05-06 20:59 . 2009-03-20 21:42 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2009-03-20 21:42 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-03-20 21:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-03-20 21:42 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-03-20 21:42 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-03-20 21:42 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-03-20 21:42 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-03-20 21:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-03-20 21:42 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 12:22 . 2010-04-11 11:24 -------- d-----w- c:\documents and settings\Admin\Application Data\Leawo
2010-05-06 12:00 . 2009-02-04 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-01 19:18 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-05-01 11:48 -------- d-----w- c:\documents and settings\Admin\Application Data\EasyMP3Downloader
2010-05-01 11:48 . 2010-04-30 21:04 -------- d-----w- c:\program files\Hot_MP3
2010-04-30 21:20 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\documents and settings\Admin\Application Data\SuperMP3Download
2010-04-30 21:04 . 2010-04-30 21:04 -------- d-----w- c:\program files\Conduit
2010-04-29 13:39 . 2010-06-15 04:56 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 13:39 . 2010-06-15 04:56 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 18:55 . 2010-04-23 18:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2010-04-11 09:23 . 2010-04-11 09:23 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-11 09:23 . 2010-04-11 09:23 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-11 09:23 . 2010-04-11 09:23 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-09 15:58 . 2009-02-04 14:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-03-31 15:49 . 2010-03-31 15:49 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-28 19:30 . 2009-02-04 14:26 74416 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-19 06:54 . 2010-03-19 06:54 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2009-03-20 09:29 . 2009-03-20 09:29 8192 --sha-w- c:\windows\o2cLicStore.bin
.
------- Sigcheck -------
[-] 2008-08-25 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-02-22 10:05 2353176 ----a-w- c:\program files\Hot_MP3\tbHot_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot_.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-07 133104]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-30 16864768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"nwiz"="nwiz.exe" [2008-11-12 1630208]
"NvMediaCenter"="NvMCTray.dll" [2008-11-12 86016]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"bgsmsnd.exe"="c:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe" [2006-06-02 106496]
"CardDetectorHUAWEIX70"="c:\program files\CardDetector\HUAWEIX70\CardDetector.exe" [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"="c:\program files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe" [2008-02-01 107248]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"Video Accelerator"="c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe" [2010-04-07 6642688]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
2010-04-07 10:06 6642688 ----a-w- c:\program files\Leawo\Video Accelerator\VideoAccelerator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"d:\\PROGRAMY, HRY, SUBORY\\hry pre miša\\Worms 4 Mayhem\\WORMS 4 MAYHEM.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\OrangeBS\\BEWInternetSK\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20.3.2009 23:42 164048]
R2 Angelnt;Angelnt;c:\windows\system32\drivers\ANGELNT.SYS [5.2.2009 16:04 51072]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20.3.2009 23:42 19024]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [4.12.2007 20:34 946816]
.
Contents of the 'Scheduled Tasks' folder
2010-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
- c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 22:02]
.
.
------- Supplementary Scan -------
.
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\rqxc4w98.default\extensions\xmlfiller@software602.cz\platform\WINNT_x86-msvc\plugins\npfiller.dll
FF - plugin: c:\documents and settings\Admin\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npfiller.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-15 17:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:19,d3,37,96,8c,74,13,9a,b1,ee,91,40,4e,97,51,15,2b,2e,dd,3f,a1,71,f1,
39,79,43,6b,1c,df,bf,4a,9b,34,d8,3a,a1,c7,b1,13,5b,23,7d,4f,84,9a,45,e0,65,\
"??"=hex:db,2e,90,50,8b,d4,b8,be,c5,d6,e7,de,ab,9e,65,1d
[HKEY_USERS\S-1-5-21-1078081533-1682526488-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:c7,88,18,70,d1,6c,b0,03,94,2b,c8,f2,5c,dd,84,66,93,77,ec,43,eb,
ed,d3,c1,3a,f3,7e,6a,8e,0f,87,4a,be,65,d1,d1,c2,28,35,8a,3b,13,4d,f8,e3,c8,\
"rkeysecu"=hex:f7,3a,91,19,0c,02,64,61,2d,ee,ef,12,62,b7,96,52
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1976)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-15 17:13:50
ComboFix-quarantined-files.txt 2010-06-15 15:13
Pre-Run: 72 708 997 120 bytes free
Post-Run: 72 698 843 136 bytes free
- - End Of File - - D6BCC7C3063876BB54278DCE13065B21
???

Killall::
Registry::
[-HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Re: Prosím o kontrolu
Ne, už to nedělejte. Dívala sjem se, klíč patří k jendomu toolbaru.
Takže combofix znovu odinstalujte, a napište jak to s pc vypadá
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Takže combofix znovu odinstalujte, a napište jak to s pc vypadá

ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
Logfile of random's system information tool 1.07 (written by random/random)
Run by Admin at 2010-06-15 18:26:28
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 70 GB (70%) free of 100 GB
Total RAM: 2047 MB (69% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:27:19, on 15.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\Explorer.EXE
C:\windows\RTHDCPL.EXE
C:\windows\system32\RunDLL32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
C:\Program Files\CardDetector\HUAWEIX70\CardDetector.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\OrangeBS\BEWInternetSK\Launcher\Launcher.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\windows\system32\svchost.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\OrangeBS\BEWInternetSK\systray\systrayapp.exe
C:\Program Files\OrangeBS\BEWInternetSK\connectivity\connectivitymanager.exe
C:\Program Files\OrangeBS\BEWInternetSK\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Leawo\Video Accelerator\FLVPlayer.exe
C:\Program Files\OrangeBS\BEWInternetSK\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\4\FTCOMModule.exe
C:\Program Files\OrangeBS\BEWInternetSK\PhoneTools\TextMessaging.exe
C:\Program Files\OrangeBS\BEWInternetSK\Deskboard\deskboard.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\Admin\Desktop\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files\Hot_MP3\tbHot_.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files\Hot_MP3\tbHot_.dll
O3 - Toolbar: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files\Hot_MP3\tbHot_.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [bgsmsnd.exe] C:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
O4 - HKLM\..\Run: [CardDetectorHUAWEIX70] C:\Program Files\CardDetector\HUAWEIX70\CardDetector.exe
O4 - HKLM\..\Run: [BEWINTERNET-SKSessionManager] C:\Program Files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Video Accelerator] "C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe" -auto
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... eqlab3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4B2C923-8E94-4116-B9D9-F48831E7A54A}: NameServer = 213.151.200.30 213.151.208.161
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - Unknown owner - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\windows\system32\sfrem01.exe
--
End of file - 6975 bytes
======Scheduled tasks folder======
C:\windows\tasks\AppleSoftwareUpdate.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
C:\windows\tasks\MP Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Hot MP3 Toolbar - C:\Program Files\Hot_MP3\tbHot_.dll [2010-02-22 2353176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9384bd4c-dd14-4be9-80f7-f6277511e4f5} - Hot MP3 Toolbar - C:\Program Files\Hot_MP3\tbHot_.dll [2010-02-22 2353176]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\windows\RTHDCPL.EXE [2008-09-30 16864768]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-11-12 13672448]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit []
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-05-16 213936]
"bgsmsnd.exe"=C:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe [2006-06-02 106496]
"CardDetectorHUAWEIX70"=C:\Program Files\CardDetector\HUAWEIX70\CardDetector.exe [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"=C:\Program Files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe [2008-02-01 107248]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]
"Video Accelerator"=C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe [2010-04-07 6642688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe [2010-04-07 6642688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
"C:\Program Files\Codemasters\GRID\GRID.exe"="C:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID"
"D:\PROGRAMY, HRY, SUBORY\hry pre miša\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE"="D:\PROGRAMY, HRY, SUBORY\hry pre miša\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE:*:Enabled:Worms 4 Mayhem"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"C:\Program Files\OrangeBS\BEWInternetSK\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeBS\BEWInternetSK\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-06-15 18:26:28 ----D---- C:\rsit
2010-06-15 17:59:59 ----D---- C:\Program Files\CCleaner
2010-06-15 17:41:30 ----SHD---- C:\RECYCLER
2010-06-15 17:13:52 ----D---- C:\windows\temp
2010-06-15 06:56:22 ----D---- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2010-06-15 06:56:07 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-06-15 06:56:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-11 11:30:07 ----D---- C:\Program Files\trend micro
2010-06-11 11:02:31 ----D---- C:\windows\Minidump
2010-06-06 19:18:39 ----D---- C:\Program Files\Photo Story 3 for Windows
2010-06-01 14:26:24 ----D---- C:\Documents and Settings\Admin\Application Data\Thunderbird
2010-05-25 14:12:15 ----HDC---- C:\windows\$NtUninstallKB978262$
2010-05-25 14:12:11 ----HDC---- C:\windows\$NtUninstallKB971468$
2010-05-25 14:12:06 ----HDC---- C:\windows\$NtUninstallKB970430$
2010-05-25 14:12:02 ----HDC---- C:\windows\$NtUninstallKB955759$
2010-05-25 14:11:57 ----HDC---- C:\windows\$NtUninstallKB972270$
2010-05-25 14:11:52 ----HDC---- C:\windows\$NtUninstallKB975560$
2010-05-25 14:11:47 ----D---- C:\Program Files\MSXML 4.0
2010-05-25 14:11:19 ----HDC---- C:\windows\$NtUninstallKB977914$
2010-05-21 08:11:26 ----D---- C:\Program Files\QuickTime
======List of files/folders modified in the last 1 months======
2010-06-15 18:26:36 ----D---- C:\windows\Prefetch
2010-06-15 18:25:44 ----A---- C:\windows\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2010-06-15 18:25:09 ----D---- C:\Program Files\HiJackThis
2010-06-15 18:15:04 ----SD---- C:\windows\Tasks
2010-06-15 18:12:58 ----D---- C:\windows\system32\ias
2010-06-15 18:12:55 ----A---- C:\windows\ModemLog_Communications cable between two computers.txt
2010-06-15 18:12:54 ----A---- C:\windows\ModemLog_Communications cable between two computers #2.txt
2010-06-15 18:12:28 ----SHD---- C:\System Volume Information
2010-06-15 18:12:28 ----D---- C:\windows\system32\Restore
2010-06-15 18:11:56 ----AD---- C:\WINDOWS
2010-06-15 18:10:57 ----A---- C:\windows\SchedLgU.Txt
2010-06-15 17:59:59 ----RD---- C:\Program Files
2010-06-15 17:47:24 ----D---- C:\windows\Internet Logs
2010-06-15 17:15:55 ----D---- C:\windows\system32\CatRoot2
2010-06-15 17:12:30 ----A---- C:\windows\system.ini
2010-06-15 17:11:37 ----D---- C:\windows\system32\drivers
2010-06-15 17:11:37 ----D---- C:\windows\system32
2010-06-15 17:11:37 ----D---- C:\windows\AppPatch
2010-06-15 17:11:34 ----D---- C:\Program Files\Common Files
2010-06-15 15:16:35 ----D---- C:\Documents and Settings\Admin\Application Data\AIMP
2010-06-06 19:50:05 ----D---- C:\Program Files\Flock
2010-06-06 19:47:39 ----SD---- C:\Documents and Settings\Admin\Application Data\Microsoft
2010-06-06 19:18:42 ----SHD---- C:\windows\Installer
2010-06-06 19:18:42 ----D---- C:\Config.Msi
2010-06-06 19:18:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-06-05 22:41:16 ----D---- C:\Documents and Settings\Admin\Application Data\Skype
2010-06-05 20:32:33 ----D---- C:\Documents and Settings\Admin\Application Data\skypePM
2010-06-04 22:55:24 ----A---- C:\windows\NeroDigital.ini
2010-06-01 13:35:33 ----D---- C:\Program Files\Mozilla Firefox
2010-05-30 18:59:30 ----HD---- C:\windows\inf
2010-05-25 14:15:58 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-25 14:12:25 ----D---- C:\windows\system32\CatRoot
2010-05-25 14:12:15 ----HD---- C:\windows\$hf_mig$
2010-05-25 14:12:12 ----RSHDC---- C:\windows\system32\dllcache
2010-05-25 14:11:48 ----D---- C:\windows\WinSxS
2010-05-24 09:34:51 ----D---- C:\windows\pss
2010-05-21 08:11:17 ----D---- C:\Program Files\Common Files\Apple
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 intelppm;Intel Processor Driver; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\windows\System32\drivers\prodrv06.sys [2004-01-26 52224]
R2 Angelnt;Angelnt; C:\windows\System32\Drivers\ANGELNT.SYS [2009-02-05 51072]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2010-05-06 100432]
R2 irda;IrDA Protocol; C:\windows\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 usbhub;Trust 350FT PowerC@m Flash (Controller); C:\windows\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2010-05-06 23376]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\windows\system32\DRIVERS\HPZid412.sys [2006-02-01 49664]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\windows\system32\DRIVERS\HPZipr12.sys [2006-02-01 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\windows\system32\DRIVERS\HPZius12.sys [2006-02-01 21568]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-08-08 101120]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RtkHDAud.sys [2008-10-02 4878336]
R3 mouhid;Mouse HID Driver; C:\windows\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2008-11-12 6188320]
R3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\windows\system32\PCANDIS5.SYS []
R3 Rasirda;WAN Miniport (IrDA); C:\windows\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\windows\System32\Drivers\RootMdm.sys [2006-02-28 5888]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\windows\system32\DRIVERS\Rtenicxp.sys [2008-12-17 119552]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;USB Scanner Driver; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 3xHybrid;3xHybrid service; C:\windows\system32\DRIVERS\3xHybrid.sys [2009-02-04 946816]
S3 CCDECODE;Closed Caption Decoder; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 DCamUSBDXGTech;Trust 350FT PowerC@m Flash (Video Camera); C:\windows\System32\Drivers\GT891x1.SYS [2001-12-11 314792]
S3 GT890x;Trust 350FT PowerC@m Flash (Still Camera); C:\windows\System32\Drivers\GT890x.SYS [2001-07-05 18088]
S3 MPE;BDA MPE Filter; C:\windows\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\windows\system32\DRIVERS\MSIRCOMM.sys [2008-04-14 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\windows\system32\PCAMPR5.SYS []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\windows\system32\DRIVERS\irstusb.sys [2001-08-17 26624]
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2008-02-01 65536]
R2 Irmon;Infrared Monitor; C:\windows\system32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2008-11-12 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-11-22 69632]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\windows\system32\sfrem01.exe [2006-05-10 353912]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
CClaener som mala (analyzujem dosť často, no cez registre som zatiaľ sama nečistila) - ale stiahla som nový podľa pokynov - BEZ yahoo tool.
PC
ide všetko, resp. ne nič zlé som nenatrafila 
Run by Admin at 2010-06-15 18:26:28
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 70 GB (70%) free of 100 GB
Total RAM: 2047 MB (69% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:27:19, on 15.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\windows\Explorer.EXE
C:\windows\RTHDCPL.EXE
C:\windows\system32\RunDLL32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
C:\Program Files\CardDetector\HUAWEIX70\CardDetector.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\OrangeBS\BEWInternetSK\Launcher\Launcher.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\windows\system32\nvsvc32.exe
C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\windows\system32\svchost.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\OrangeBS\BEWInternetSK\systray\systrayapp.exe
C:\Program Files\OrangeBS\BEWInternetSK\connectivity\connectivitymanager.exe
C:\Program Files\OrangeBS\BEWInternetSK\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Leawo\Video Accelerator\FLVPlayer.exe
C:\Program Files\OrangeBS\BEWInternetSK\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\4\FTCOMModule.exe
C:\Program Files\OrangeBS\BEWInternetSK\PhoneTools\TextMessaging.exe
C:\Program Files\OrangeBS\BEWInternetSK\Deskboard\deskboard.exe
C:\windows\system32\wuauclt.exe
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\Admin\Desktop\RSIT.exe
C:\Program Files\trend micro\Admin.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files\Hot_MP3\tbHot_.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files\Hot_MP3\tbHot_.dll
O3 - Toolbar: Hot MP3 Toolbar - {9384bd4c-dd14-4be9-80f7-f6277511e4f5} - C:\Program Files\Hot_MP3\tbHot_.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [bgsmsnd.exe] C:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe
O4 - HKLM\..\Run: [CardDetectorHUAWEIX70] C:\Program Files\CardDetector\HUAWEIX70\CardDetector.exe
O4 - HKLM\..\Run: [BEWINTERNET-SKSessionManager] C:\Program Files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Video Accelerator] "C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe" -auto
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDow ... eqlab3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4B2C923-8E94-4116-B9D9-F48831E7A54A}: NameServer = 213.151.200.30 213.151.208.161
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - Unknown owner - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\windows\system32\sfrem01.exe
--
End of file - 6975 bytes
======Scheduled tasks folder======
C:\windows\tasks\AppleSoftwareUpdate.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004Core.job
C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1682526488-682003330-1004UA.job
C:\windows\tasks\MP Scheduled Scan.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
Hot MP3 Toolbar - C:\Program Files\Hot_MP3\tbHot_.dll [2010-02-22 2353176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9384bd4c-dd14-4be9-80f7-f6277511e4f5} - Hot MP3 Toolbar - C:\Program Files\Hot_MP3\tbHot_.dll [2010-02-22 2353176]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\windows\RTHDCPL.EXE [2008-09-30 16864768]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-11-12 13672448]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit []
"ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe [2006-05-16 213936]
"bgsmsnd.exe"=C:\windows\System32\spool\DRIVERS\W32X86\2\bgsmsnd.exe [2006-06-02 106496]
"CardDetectorHUAWEIX70"=C:\Program Files\CardDetector\HUAWEIX70\CardDetector.exe [2008-02-04 278528]
"BEWINTERNET-SKSessionManager"=C:\Program Files\OrangeBS\BEWInternetSK\SessionManager\SessionManager.exe [2008-02-01 107248]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]
"Video Accelerator"=C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe [2010-04-07 6642688]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Google Update"=C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
"NBJ"=C:\Program Files\Ahead\Nero BackItUp\NBJ.exe [2005-10-11 1961984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Video Accelerator]
C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe [2010-04-07 6642688]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Disabled:Firefox"
"C:\Program Files\Codemasters\GRID\GRID.exe"="C:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID"
"D:\PROGRAMY, HRY, SUBORY\hry pre miša\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE"="D:\PROGRAMY, HRY, SUBORY\hry pre miša\Worms 4 Mayhem\WORMS 4 MAYHEM.EXE:*:Enabled:Worms 4 Mayhem"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Disabled:Microsoft DirectPlay8 Server"
"C:\Program Files\OrangeBS\BEWInternetSK\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeBS\BEWInternetSK\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-06-15 18:26:28 ----D---- C:\rsit
2010-06-15 17:59:59 ----D---- C:\Program Files\CCleaner
2010-06-15 17:41:30 ----SHD---- C:\RECYCLER
2010-06-15 17:13:52 ----D---- C:\windows\temp
2010-06-15 06:56:22 ----D---- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2010-06-15 06:56:07 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-06-15 06:56:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-11 11:30:07 ----D---- C:\Program Files\trend micro
2010-06-11 11:02:31 ----D---- C:\windows\Minidump
2010-06-06 19:18:39 ----D---- C:\Program Files\Photo Story 3 for Windows
2010-06-01 14:26:24 ----D---- C:\Documents and Settings\Admin\Application Data\Thunderbird
2010-05-25 14:12:15 ----HDC---- C:\windows\$NtUninstallKB978262$
2010-05-25 14:12:11 ----HDC---- C:\windows\$NtUninstallKB971468$
2010-05-25 14:12:06 ----HDC---- C:\windows\$NtUninstallKB970430$
2010-05-25 14:12:02 ----HDC---- C:\windows\$NtUninstallKB955759$
2010-05-25 14:11:57 ----HDC---- C:\windows\$NtUninstallKB972270$
2010-05-25 14:11:52 ----HDC---- C:\windows\$NtUninstallKB975560$
2010-05-25 14:11:47 ----D---- C:\Program Files\MSXML 4.0
2010-05-25 14:11:19 ----HDC---- C:\windows\$NtUninstallKB977914$
2010-05-21 08:11:26 ----D---- C:\Program Files\QuickTime
======List of files/folders modified in the last 1 months======
2010-06-15 18:26:36 ----D---- C:\windows\Prefetch
2010-06-15 18:25:44 ----A---- C:\windows\ModemLog_HUAWEI Mobile Connect - 3G Modem #2.txt
2010-06-15 18:25:09 ----D---- C:\Program Files\HiJackThis
2010-06-15 18:15:04 ----SD---- C:\windows\Tasks
2010-06-15 18:12:58 ----D---- C:\windows\system32\ias
2010-06-15 18:12:55 ----A---- C:\windows\ModemLog_Communications cable between two computers.txt
2010-06-15 18:12:54 ----A---- C:\windows\ModemLog_Communications cable between two computers #2.txt
2010-06-15 18:12:28 ----SHD---- C:\System Volume Information
2010-06-15 18:12:28 ----D---- C:\windows\system32\Restore
2010-06-15 18:11:56 ----AD---- C:\WINDOWS
2010-06-15 18:10:57 ----A---- C:\windows\SchedLgU.Txt
2010-06-15 17:59:59 ----RD---- C:\Program Files
2010-06-15 17:47:24 ----D---- C:\windows\Internet Logs
2010-06-15 17:15:55 ----D---- C:\windows\system32\CatRoot2
2010-06-15 17:12:30 ----A---- C:\windows\system.ini
2010-06-15 17:11:37 ----D---- C:\windows\system32\drivers
2010-06-15 17:11:37 ----D---- C:\windows\system32
2010-06-15 17:11:37 ----D---- C:\windows\AppPatch
2010-06-15 17:11:34 ----D---- C:\Program Files\Common Files
2010-06-15 15:16:35 ----D---- C:\Documents and Settings\Admin\Application Data\AIMP
2010-06-06 19:50:05 ----D---- C:\Program Files\Flock
2010-06-06 19:47:39 ----SD---- C:\Documents and Settings\Admin\Application Data\Microsoft
2010-06-06 19:18:42 ----SHD---- C:\windows\Installer
2010-06-06 19:18:42 ----D---- C:\Config.Msi
2010-06-06 19:18:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-06-05 22:41:16 ----D---- C:\Documents and Settings\Admin\Application Data\Skype
2010-06-05 20:32:33 ----D---- C:\Documents and Settings\Admin\Application Data\skypePM
2010-06-04 22:55:24 ----A---- C:\windows\NeroDigital.ini
2010-06-01 13:35:33 ----D---- C:\Program Files\Mozilla Firefox
2010-05-30 18:59:30 ----HD---- C:\windows\inf
2010-05-25 14:15:58 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-25 14:12:25 ----D---- C:\windows\system32\CatRoot
2010-05-25 14:12:15 ----HD---- C:\windows\$hf_mig$
2010-05-25 14:12:12 ----RSHDC---- C:\windows\system32\dllcache
2010-05-25 14:11:48 ----D---- C:\windows\WinSxS
2010-05-24 09:34:51 ----D---- C:\windows\pss
2010-05-21 08:11:17 ----D---- C:\Program Files\Common Files\Apple
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\windows\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 aswSP;aswSP; C:\windows\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\windows\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 intelppm;Intel Processor Driver; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\windows\System32\drivers\prodrv06.sys [2004-01-26 52224]
R2 Angelnt;Angelnt; C:\windows\System32\Drivers\ANGELNT.SYS [2009-02-05 51072]
R2 aswFsBlk;aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;avast! Standard Shield Support; C:\windows\system32\drivers\aswMon2.sys [2010-05-06 100432]
R2 irda;IrDA Protocol; C:\windows\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 usbhub;Trust 350FT PowerC@m Flash (Controller); C:\windows\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 aswRdr;aswRdr; C:\windows\system32\drivers\aswRdr.sys [2010-05-06 23376]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\windows\system32\DRIVERS\HPZid412.sys [2006-02-01 49664]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\windows\system32\DRIVERS\HPZipr12.sys [2006-02-01 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\windows\system32\DRIVERS\HPZius12.sys [2006-02-01 21568]
R3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\windows\system32\DRIVERS\ewusbmdm.sys [2007-08-08 101120]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RtkHDAud.sys [2008-10-02 4878336]
R3 mouhid;Mouse HID Driver; C:\windows\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2008-11-12 6188320]
R3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\windows\system32\PCANDIS5.SYS []
R3 Rasirda;WAN Miniport (IrDA); C:\windows\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\windows\System32\Drivers\RootMdm.sys [2006-02-28 5888]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\windows\system32\DRIVERS\Rtenicxp.sys [2008-12-17 119552]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbprint;Microsoft USB PRINTER Class; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;USB Scanner Driver; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 3xHybrid;3xHybrid service; C:\windows\system32\DRIVERS\3xHybrid.sys [2009-02-04 946816]
S3 CCDECODE;Closed Caption Decoder; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 DCamUSBDXGTech;Trust 350FT PowerC@m Flash (Video Camera); C:\windows\System32\Drivers\GT891x1.SYS [2001-12-11 314792]
S3 GT890x;Trust 350FT PowerC@m Flash (Still Camera); C:\windows\System32\Drivers\GT890x.SYS [2001-07-05 18088]
S3 MPE;BDA MPE Filter; C:\windows\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSIRCOMM;Microsoft IR Communications Driver; C:\windows\system32\DRIVERS\MSIRCOMM.sys [2008-04-14 22016]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\windows\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\windows\system32\PCAMPR5.SYS []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 SLIP;BDA Slip De-Framer; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 STIrUsb;SigmaTel USB-IrDA Dongle; C:\windows\system32\DRIVERS\irstusb.sys [2001-08-17 26624]
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2008-02-01 65536]
R2 Irmon;Infrared Monitor; C:\windows\system32\svchost.exe [2008-04-14 14336]
R2 NVSvc;NVIDIA Display Driver Service; C:\windows\system32\nvsvc32.exe [2008-11-12 163908]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2005-11-22 69632]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\windows\system32\sfrem01.exe [2006-05-10 353912]
S3 aspnet_state;ASP.NET State Service; C:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2009-03-04 621056]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
-----------------EOF-----------------
CClaener som mala (analyzujem dosť často, no cez registre som zatiaľ sama nečistila) - ale stiahla som nový podľa pokynov - BEZ yahoo tool.
PC


Re: Prosím o kontrolu
U registrů si můžete dělat zálohy a když bude vše v pořádku, tak ji smažete. osobně si zálohu nedělám, zatím se mi nestalo, že by CCleaner smazal něco špatného.
Pokud tento toolbar nepoužíváte, smažte ho
Toolbar: Hot MP3 Toolbar
Nevidím firewall, ten ve windows je nedostačující. Za sebe Vám můžu doporučit Zone alarm nebo pc tools firewall, jsou sice v angkličtině, ale jednoduché.
Pokud nejsou problémy, je to vše
.

Toolbar: Hot MP3 Toolbar

Pokud nejsou problémy, je to vše

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
Toolbar: Hot MP3 Toolbar - vymažem ... ale neviem AKO
/kde ho hľadať ?
Ak som to ok pochopila - vírus som chytila cez IE z MP3 ? Deti začali húfne sťahovať pesničky a videá, ináč IE nepoužívam (škoda, že WINDOWS ano). Dá sa PC nastaviť tak, aby bol IE "sprostredkovateľom" len pri nevyhnutných upgrade?
Programy pri spustení - niečo som odkukala z fóra - je to dobre?
Firewall - prosím ešte radu - vyskúšala som ZONE Alarm (Free, CZ, a vraj skromný) - ale strašne spomaľoval až zamŕzal pri prehliadaní webu



Programy pri spustení - niečo som odkukala z fóra - je to dobre?
Firewall - prosím ešte radu - vyskúšala som ZONE Alarm (Free, CZ, a vraj skromný) - ale strašne spomaľoval až zamŕzal pri prehliadaní webu

Re: Prosím o kontrolu
Odkoukala jste to dobře
V ccleaneru klikněte na nástroje - odinstalovat - a ten toolbar tak zkuste najít.
Zone alarm jste měla kterou verzi? Devítková verze v tomto trošku zlobila, ale myslela jsme, že už to opravili
. Pokud chcete, můžeme zkusit osmičkovou verzi.
Používáte firefox?

V ccleaneru klikněte na nástroje - odinstalovat - a ten toolbar tak zkuste najít.
Zone alarm jste měla kterou verzi? Devítková verze v tomto trošku zlobila, ale myslela jsme, že už to opravili

Používáte firefox?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu
toolbar som už zmazala a vypla aj v doplnkoch IE
Zone alarm - verziu som sťahovala hneď, ako mi kázal doplniť firewall RADCA Caroprd111 pri problémoch s PC - 28.brez 2010
Prosím, dajte mi link - kde stiahnuť 8-verziu ZoneA - vyskúšam.
prehliadač - 95 %
a 5 % G.chrome
ZATIAĽ ĎAKUJEM VEĽMI PEKNE
Zone alarm - verziu som sťahovala hneď, ako mi kázal doplniť firewall RADCA Caroprd111 pri problémoch s PC - 28.brez 2010
Prosím, dajte mi link - kde stiahnuť 8-verziu ZoneA - vyskúšam.
prehliadač - 95 %

ZATIAĽ ĎAKUJEM VEĽMI PEKNE
