Po spuštění systému plno virů

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Zpráva
Autor
GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Po spuštění systému plno virů

#1 Příspěvek od GlaDOS »

Zdravím.
Mám akutní problém. Spustil sem počítač a najednou mě NOD32 hlásí plno virů v system32, které jdou jen ponechat. Tak sem začal klikat na ponechat s vědomím, že jich bude jen pár a najednou se pc restartuje. Po zapnutí to ukazuje viry nanovo. Projel sem složku system32 ale je tam jen 1 vir ve složce drivers soubor asyncmac.sys. Potřeboval bych se té havěti zbavit, ale přeinstalovávat windows XP SP3 nechci (ale stejně sem raději začal zálohovat). Přikládám log z RSIT. Byl bych rád, kdyby se na to prosím někdo podíval. Předem děkuju za pomoc.

Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-08-09 12:23:27
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 895 MB (3%) free of 29 GB
Total RAM: 2047 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:23:34, on 9.8.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WTouch\WTouchService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WTouch\WTouchUser.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\oodtray.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=14597&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - (no file)
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\Msdxm6.ocx
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_SB1.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: updpxe32.exe
O4 - Global Startup: AVer HID Receiver.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: ZoneAlarm Security (2).lnk = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - Global Startup: Zástupce - ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Stáhnout s IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Stáhnout s IDM obsah FLV videa - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Stáhnout s IDM všechny odkazy - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - E:\programy\Infr392\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVerRemote - AVerMedia - C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
O23 - Service: AVerScheduleService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9cab45ac42da0) (gupdate1c9cab45ac42da0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: WTouch Service (WTouchService) - Wacom Technology, Corp. - C:\Program Files\WTouch\WTouchService.exe
O24 - Desktop Component 1: Aqua Real 2 - AD0FABD2-7EAE-40B8-8F44-6FCFE6C883CD

--
End of file - 11287 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-STOLNI-Administrator.job
C:\WINDOWS\tasks\Driver Robot.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-2111687655-839522115-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-2111687655-839522115-500UA.job
C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
C:\WINDOWS\tasks\SmartDefrag.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2009-01-22 161200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
QuickStores-Toolbar - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-26 1385864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]
{8E718888-423F-11D2-876E-00A0C9082467} - &Radio - C:\WINDOWS\system32\Msdxm6.ocx [2000-04-21 844048]
{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - QuickStores-Toolbar - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-05-26 1385864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"PinnacleDriverCheck"=C:\WINDOWS\system32\\PSDrvCheck.exe []
"OODefragTray"=C:\WINDOWS\system32\oodtray.exe [2008-11-03 2540800]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-13 1443072]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-07-21 61440]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-12-09 98304]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"AdobeAAMUpdater-1.0"=C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-06-28 500208]
"AdobeCS5ServiceManager"=C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"Ulead AutoDetector v2"=C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe [2005-05-23 90112]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"PhotoShow Deluxe Media Manager"=C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe [2005-02-26 212992]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2008-10-03 133104]
"EPSON Stylus DX7400 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE [2007-04-12 182272]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2009-04-24 203928]
"AdobeBridge"= []
"SandboxieControl"=C:\Program Files\Sandboxie\SbieCtrl.exe [2010-07-04 398568]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
AVer HID Receiver.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
AVerQuick.lnk - C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
Exif Launcher S.lnk - C:\Program Files\FinePixViewerS\QuickDCF2.exe
ZoneAlarm Security (2).lnk - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
Zástupce - ashDisp.lnk - C:\Program Files\Alwil Software\Avast4\ashDisp.exe

C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění
updpxe32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2009-07-21 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\hry\HL 2\cstrike.exe"="E:\hry\HL 2\cstrike.exe:*:Enabled:cstrike"
"E:\hry\HL 2\hl2.exe"="E:\hry\HL 2\hl2.exe:*:Enabled:hl2"
"E:\Freegames\TrackMania Nations ESWC\TmNationsESWC.exe"="E:\Freegames\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent"
"E:\hry\FPSCORE Metro\fpscore.exe"="E:\hry\FPSCORE Metro\fpscore.exe:*:Enabled:fpscore"
"E:\hry\CS 1.6\hl.exe"="E:\hry\CS 1.6\hl.exe:*:Enabled:Half-Life Launcher"
"C:\WINDOWS\system32\winver.exe"="C:\WINDOWS\system32\winver.exe:*:Enabled:winver"
"E:\programy\Pinacle studio10\programs\RM.exe"="E:\programy\Pinacle studio10\programs\RM.exe:*:Enabled:Render Manager"
"E:\programy\Pinacle studio10\programs\Studio.exe"="E:\programy\Pinacle studio10\programs\Studio.exe:*:Enabled:Studio"
"E:\programy\Pinacle studio10\programs\PMSRegisterFile.exe"="E:\programy\Pinacle studio10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"E:\programy\Pinacle studio10\programs\umi.exe"="E:\programy\Pinacle studio10\programs\umi.exe:*:Enabled:umi"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\hry\The Battle for Middle-earth (tm) II\game.dat"="E:\hry\The Battle for Middle-earth (tm) II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"E:\hry\Unreal Tournament 3\Binaries\UT3.exe"="E:\hry\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:Unreal Tournament 3"
"E:\hry\Demigod\bin\Demigod.exe"="E:\hry\Demigod\bin\Demigod.exe:*:Enabled:Demigod"
"E:\hry\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe"="E:\hry\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)"
"E:\hry\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe"="E:\hry\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"E:\hry\Steam\Steam.exe"="E:\hry\Steam\Steam.exe:*:Enabled:Steam 732897"
"E:\programy\FileZilla FTP Client\filezilla.exe"="E:\programy\FileZilla FTP Client\filezilla.exe:*:Enabled:FileZilla FTP Client"
"E:\hry\left 4 dead 2\Left.4.Dead.2-THEPiRATEGAY\left4dead2.exe"="E:\hry\left 4 dead 2\Left.4.Dead.2-THEPiRATEGAY\left4dead2.exe:*:Enabled:left4dead2"
"E:\hry\Battlefield Bad Company 2\BFBC2Updater.exe"="E:\hry\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"C:\Program Files\Amateur Radio\Ham Radio Deluxe\Digital Master.exe"="C:\Program Files\Amateur Radio\Ham Radio Deluxe\Digital Master.exe:*:Disabled:Digital Master 780"
"E:\hry\Half-Life 2 Ultimate Edition 7\Engine3\hl2.exe"="E:\hry\Half-Life 2 Ultimate Edition 7\Engine3\hl2.exe:*:Enabled:hl2"
"E:\hry\Dawn of War - Soulstorm\Soulstorm.exe"="E:\hry\Dawn of War - Soulstorm\Soulstorm.exe:*:Enabled:Soulstorm"
"E:\hry\Steam\SteamApps\common\osmos demo\OsmosDemo.exe"="E:\hry\Steam\SteamApps\common\osmos demo\OsmosDemo.exe:*:Enabled:Osmos Demo"
"E:\hry\Steam\SteamApps\common\alien swarm\srcds.exe"="E:\hry\Steam\SteamApps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server"
"E:\hry\Steam\SteamApps\common\alien swarm\swarm.exe"="E:\hry\Steam\SteamApps\common\alien swarm\swarm.exe:*:Enabled:Alien Swarm"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\hry\StarCraft II\StarCraft II.exe"="E:\hry\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher"
"E:\hry\StarCraft II\Versions\Base15405\SC2.exe"="E:\hry\StarCraft II\Versions\Base15405\SC2.exe:*:Enabled:StarCraft II"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-08-09 12:23:28 ----D---- C:\Program Files\trend micro
2010-08-09 12:23:27 ----D---- C:\rsit
2010-08-09 12:10:06 ----A---- C:\WINDOWS\system32\drivers\lbrtfdc.sys
2010-08-09 12:01:17 ----A---- C:\WINDOWS\system32\drivers\i2omgmt.sys
2010-08-09 12:01:02 ----A---- C:\WINDOWS\system32\drivers\changer.sys
2010-08-09 11:59:17 ----D---- C:\WINDOWS\LastGood
2010-08-09 11:54:54 ----A---- C:\WINDOWS\system32\drivers\seyoeb.sys
2010-08-07 21:59:13 ----A---- C:\Documents and Settings\Administrator\Data aplikací\myMPQ.ini
2010-08-07 21:53:39 ----D---- C:\Program Files\StarCraft II
2010-08-06 00:21:29 ----RD---- C:\Sandbox
2010-08-06 00:20:00 ----A---- C:\WINDOWS\Sandboxie.ini
2010-08-06 00:19:30 ----D---- C:\Program Files\Sandboxie
2010-08-05 01:02:42 ----A---- C:\protokol o instalaci cestiny do hry starcraft.txt
2010-08-04 23:53:06 ----D---- C:\Documents and Settings\Administrator\Data aplikací\7Wonders
2010-08-04 23:50:58 ----D---- C:\Program Files\ReflexiveArcade
2010-08-04 17:30:40 ----A---- C:\WINDOWS\ScUnin.pif
2010-08-04 17:30:40 ----A---- C:\WINDOWS\ScUnin.exe
2010-08-03 22:51:53 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2010-08-03 22:51:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Blizzard Entertainment
2010-07-30 21:34:00 ----D---- C:\Documents and Settings\Administrator\Data aplikací\dvdcss
2010-07-30 21:27:04 ----D---- C:\Program Files\Easy Video Joiner
2010-07-30 14:00:44 ----D---- C:\Program Files\Easy GIF Animator
2010-07-30 00:08:00 ----ASH---- C:\WINDOWS\CNSYSDLG.SYS
2010-07-30 00:06:39 ----D---- C:\Program Files\Common Files\Canopus Shared
2010-07-29 23:44:31 ----D---- C:\Program Files\Ask.com
2010-07-29 23:43:57 ----D---- C:\Program Files\The KMPlayer
2010-07-26 22:38:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Extreme Picture Finder
2010-07-26 22:25:01 ----D---- C:\Program Files\Mihov Picture Downloader
2010-07-22 23:25:21 ----D---- C:\vcs5BGEffects
2010-07-22 20:29:45 ----D---- C:\Documents and Settings\Administrator\Data aplikací\QuickStoresToolbar
2010-07-22 20:29:39 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-07-11 13:56:57 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-10 22:42:34 ----A---- C:\WINDOWS\system32\drivers\ithsgt.sys
2010-07-10 22:36:56 ----RA---- C:\WINDOWS\system32\tmp996.tmp
2010-07-10 22:36:56 ----RA---- C:\WINDOWS\system32\tmp995.tmp
2010-07-10 16:18:38 ----N---- C:\WINDOWS\readme.txt
2010-07-10 16:16:02 ----N---- C:\WINDOWS\UNNMP.exe
2010-07-10 16:09:25 ----N---- C:\WINDOWS\UNNeroVision.exe
2010-07-10 16:08:32 ----A---- C:\WINDOWS\system32\TwnLib4.dll
2010-07-10 16:08:32 ----A---- C:\WINDOWS\system32\ImagXRA7.dll
2010-07-10 16:08:32 ----A---- C:\WINDOWS\system32\ImagXR7.dll
2010-07-10 16:08:32 ----A---- C:\WINDOWS\system32\ImagXpr7.dll
2010-07-10 16:08:32 ----A---- C:\WINDOWS\system32\ImagX7.dll
2010-07-10 16:08:31 ----A---- C:\WINDOWS\system32\picn20.dll
2010-07-10 00:23:41 ----D---- C:\Documents and Settings\Administrator\Data aplikací\WinAVI
2010-07-10 00:22:48 ----D---- C:\Program Files\WinAVI Video Converter
2010-07-10 00:12:27 ----D---- C:\WINDOWS\XSxS
2010-07-10 00:12:27 ----D---- C:\Program Files\Xenocode

======List of files/folders modified in the last 1 months======

2010-08-09 12:23:28 ----RD---- C:\Program Files
2010-08-09 12:23:28 ----D---- C:\WINDOWS\Temp
2010-08-09 12:14:19 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-09 12:14:14 ----D---- C:\WINDOWS\system32\drivers
2010-08-09 11:59:17 ----D---- C:\WINDOWS
2010-08-09 11:57:05 ----D---- C:\WINDOWS\system32
2010-08-09 11:57:02 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-09 11:56:54 ----D---- C:\Documents and Settings\Administrator\Data aplikací\WTablet
2010-08-09 03:01:59 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-09 02:47:13 ----D---- C:\Documents and Settings\Administrator\Data aplikací\AIMP
2010-08-08 12:58:07 ----D---- C:\Program Files\SpeedFan
2010-08-08 10:26:48 ----D---- C:\Program Files\Common Files\Adobe
2010-08-08 10:23:37 ----D---- C:\Program Files\Adobe
2010-08-08 09:50:59 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Adobe
2010-08-07 20:25:26 ----D---- C:\Program Files\Mozilla Firefox
2010-08-07 16:31:53 ----HD---- C:\WINDOWS\inf
2010-08-06 18:08:34 ----SHD---- C:\WINDOWS\Installer
2010-08-06 18:08:33 ----SD---- C:\WINDOWS\Tasks
2010-08-06 18:01:12 ----D---- C:\Config.Msi
2010-08-06 00:21:31 ----D---- C:\WINDOWS\Prefetch
2010-08-04 18:59:46 ----D---- C:\Documents and Settings\Administrator\Data aplikací\DMCache
2010-08-03 23:12:32 ----D---- C:\Program Files\Common Files
2010-08-03 01:09:07 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-03 00:53:38 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2010-08-03 00:53:38 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2010-08-02 11:05:27 ----D---- C:\Documents and Settings\Administrator\Data aplikací\FileZilla
2010-08-02 00:37:28 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-08-02 00:36:24 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM
2010-07-30 18:34:09 ----A---- C:\WINDOWS\WINTRAN.INI
2010-07-30 00:07:10 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-29 15:40:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2010-07-28 15:47:14 ----SHD---- C:\System Volume Information
2010-07-28 15:47:14 ----D---- C:\WINDOWS\system32\Restore
2010-07-26 22:19:04 ----A---- C:\WINDOWS\level.ini
2010-07-22 20:29:55 ----RSD---- C:\WINDOWS\assembly
2010-07-22 20:29:55 ----D---- C:\WINDOWS\WinSxS
2010-07-12 12:29:37 ----D---- C:\WINDOWS\system32\Lang
2010-07-10 22:37:49 ----D---- C:\WINDOWS\system32\DirectX
2010-07-10 16:18:36 ----D---- C:\Program Files\Common Files\Ulead Systems
2010-07-10 16:18:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ulead Systems
2010-07-10 16:15:38 ----D---- C:\Program Files\Ahead
2010-07-10 14:53:37 ----D---- C:\WINDOWS\system32\config
2010-07-10 14:53:05 ----D---- C:\WINDOWS\system32\wbem
2010-07-10 14:53:05 ----D---- C:\WINDOWS\Registration
2010-07-10 14:36:03 ----RSD---- C:\WINDOWS\Fonts
2010-07-10 14:35:20 ----A---- C:\WINDOWS\VFO.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 giveio;giveio; C:\WINDOWS\system32\giveio.sys [1996-04-03 5248]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-07-09 45200]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS\System32\drivers\sfdrv01.sys [2005-08-10 50688]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a); C:\WINDOWS\System32\drivers\sfdrv01a.sys [2006-07-05 63352]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS\System32\drivers\sfhlp02.sys [2006-06-14 13680]
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x); C:\WINDOWS\System32\drivers\sfsync02.sys [2006-07-10 27032]
R0 sfvfs02;StarForce Protection VFS Driver (version 2.x); C:\WINDOWS\System32\drivers\sfvfs02.sys [2007-01-12 82296]
R0 speedfan;speedfan; C:\WINDOWS\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-05-09 721904]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-13 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-13 54280]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-06-12 56108]
R1 VClone;VClone; C:\WINDOWS\system32\DRIVERS\VClone.sys [2007-06-16 31616]
R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2009-09-23 16512]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-08-04 279712]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-13 40456]
R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2007-08-07 25160]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-13 71176]
R2 ithsgt;ithsgt; C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2010-07-10 162432]
R2 lilsgt;lilsgt; C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2008-12-29 12032]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-08-04 25888]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2009-07-21 3565056]
R3 AVerAF15DMBTH;AVerMedia A850 USB; C:\WINDOWS\System32\Drivers\AVerAF15DMBTH.sys [2008-09-17 293120]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-13 30728]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-04-30 25280]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-19 4127232]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 SbieDrv;SbieDrv; \??\C:\Program Files\Sandboxie\SbieDrv.sys []
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 wacommousefilter;Wacom Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11312]
R3 wacomvhid;Wacom Virtual Hid Driver; C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2009-05-20 13736]
S1 cdrbsvsd;cdrbsvsd; C:\WINDOWS\system32\drivers\cdrbsvsd.sys []
S1 InCDPass;InCDPass; C:\WINDOWS\system32\drivers\InCDPass.sys []
S1 InCDRm;InCD Reader; C:\WINDOWS\system32\drivers\InCDRm.sys []
S3 amcr50wq;amcr50wq; C:\WINDOWS\system32\drivers\amcr50wq.sys []
S3 as0e1skg;as0e1skg; C:\WINDOWS\system32\drivers\as0e1skg.sys []
S3 ASAPIW2K;ASAPIW2K; C:\WINDOWS\System32\Drivers\ASAPIW2K.sys []
S3 ATICDSDr;ATICDSDr; \??\F:\INSTALL\bin\atiicdxx.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys []
S3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2005-05-03 27392]
S3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2007-02-16 11984]
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 Ndisprot;ArcNet NDIS Protocol Driver; \??\C:\WINDOWS\system32\drivers\Ndisprot.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2008-01-30 25216]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 InCDFs;InCD File System; C:\WINDOWS\system32\drivers\InCDFs.sys []
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2009-07-21 602112]
R2 AVerRemote;AVerRemote; C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe [2008-09-10 352256]
R2 AVerScheduleService;AVerScheduleService; C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe [2008-10-16 409600]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2008-03-13 472320]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2008-11-03 1332480]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-11-13 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-01-01 189248]
R2 SbieSvc;Sandboxie Service; C:\Program Files\Sandboxie\SbieSvc.exe [2010-07-04 75496]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TabletServicePen;TabletServicePen; C:\WINDOWS\system32\Pen_Tablet.exe [2009-11-24 4497704]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 1529728]
R2 WTouchService;WTouch Service; C:\Program Files\WTouch\WTouchService.exe [2009-11-24 113448]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-07-21 593920]
S2 gupdate1c9cab45ac42da0;Google Update Service (gupdate1c9cab45ac42da0); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-02 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-13 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-01-24 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
Naposledy upravil(a) GlaDOS dne 09 Srp 2010 19:26, celkem upraveno 1 x.

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Po spuštění plno virů

#2 Příspěvek od JaRon »

1. pouzi Avenger - jeho script:
Files to delete:
C:\Documents and Settings\Administrator\Nabídka Start\Programy\Po spuštění\updpxe32.exe



2.prescanuj PC s MBAM
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění plno virů

#3 Příspěvek od GlaDOS »

Script použit. Po restartu vyskočil log. Ten soubor byl smazán, Rootkity to nenalezlo. Po spuštění už NOD nával infikovaných souborů nehlásí.
Pustil jsem sken MBAM. V průběho skenu NOD konal klasickou skrytou kontrolu a nalezl nějakou infekci, je to ten soubor ve windowsech system32/asyncmac.sys. Šlo ho jen dát do karantény, tak tam je.
V té karánténě jsou ještě soubory z toho návalu infekci, co Nod detekoval. Všechny jsou z windowsů system32/drivers, všechny mají přípony sys, shodnou velikost a stejný typ nákazy. Mají taková jména, any zřejmě vypadali důležitě, ale opravdu si nejsem jist, jestli jsou to důležité soubory, tak se ptám. Přikládám do přílohy screen z karantény, s těmi soubory.
Ještě dodám, že jsem byl odstřihnut od sítě kvůli odesílání (zřejmě) spamu do internetu. Teď jedu na přiděleném proxy serveru.
Tady je log z MBAM:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

9.8.2010 18:13:05
mbam-log-2010-08-09 (18-13-05).txt

Typ skenu: Rychlý sken
Skenované objekty: 122456
Uplynulý čas: 54 minuta(y), 22 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 6
Infikované hodnoty registru: 3
Infikované datové položky registru: 2
Infikované složky: 0
Infikované soubory: 1

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CLASSES_ROOT\homeview (Trojan.DNSChanger) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.

Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\w32id (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\xml2u (Spyware.OnlineGames) -> No action taken.

Infikované datové položky registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\Documents and Settings\Administrator\Data aplikací\avdrn.dat (Malware.Trace) -> No action taken.
Přílohy
karantena.jpg
Obsah karantény
(322.09 KiB) Staženo 414 x

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění plno virů

#4 Příspěvek od GlaDOS »

Poradíte mi někdo co z toho vymazat, dokud mám zaplý MBAM? Nechtěl bych vymazat něco důležitého. A taky, jestli ty jsou ty soubory v karanténě důležité, nebo ne? Děkuji

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Po spuštění systému plno virů

#5 Příspěvek od JaRon »

vymaz vsetko najdene v MBAM - restart - daj uplnu kontrolu
subory v karantene - kedze maju rovnaku velkost na 99% ide o smejdy - ale kludne ich nejaku dobu nechaj v karantene - tam su neskodne :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění systému plno virů

#6 Příspěvek od GlaDOS »

Vymazáno. Teď jede kompletní kontrola, ale to bude trvat několik hodin.
Udělal jsem zběžnou kontrolu přes NOD ve system32/drivers a znovu našel nakažený soubor asyncmac.sys virem Win32/Bubnix.AU trojský kůň. Nejde smazat ani léčit, asi je nějak chráněn. Podle Noda je v karanténě, nicméně ve složce drivers je a stačí na něj jednou kliknout a Nod ho detekuje jako zavirovaný. Dočetl sem se, že ten soubor je důležitý pro funkci Windows.

A chtěl bych se zeptat, je už bezpečné se připojit k internetu? Jestli je ten vir, co odesílal data do internetu vymazán, mělo by to už být bezpečné.

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění systému plno virů

#7 Příspěvek od GlaDOS »

Právě jsem dokončil kompletní sken. Při skenování složky windows/system32/driver si Nod nahlásil vir v tom asyncmac.sys, ale MBAM v něm nic nenašel, takže nevím, co si o tom myslet. Jinak výsledek kompletního skenu byl skoro čistý. Našlo to jen jednoho trojana v portable verzi jednoho programu. Takže ten program ihned letěl, stejně sem ho nepotřeboval, jinak čisto.

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Po spuštění systému plno virů

#8 Příspěvek od JaRon »

uvedeny subor asyncmac.sys otestuj na www.virustotal.com a vysledky vloz sem
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění systému plno virů

#9 Příspěvek od GlaDOS »

Jo a ten asyncmac.sys má naprosto stejnou velikost (585472) jak ty ostatní soubory s příponou sys, co mám v karanténě. Tady je výsledek.

AhnLab-V3 2010.08.11.02/20100811 found [Win-Trojan/Xpack.585472]
AntiVir 8.2.4.34/20100811 found nothing
Antiy-AVL 2.0.3.7/20100811 found nothing
Authentium 5.2.0.5/20100811 found nothing
Avast 4.8.1351.0/20100811 found [Win32:Rootkit-gen]
Avast5 5.0.332.0/20100811 found [Win32:Rootkit-gen]
AVG 9.0.0.851/20100811 found [BackDoor.Generic12.CEFS]
BitDefender 7.2/20100811 found [Trojan.Krap.H]
CAT-QuickHeal 11.00/20100811 found [Trojan.Agent.gen]
ClamAV 0.96.0.3-git/20100811 found nothing
Comodo 5712/20100811 found [EmailWorm.Win32.Joleee.~J1]
DrWeb 5.0.2.03300/20100811 found [Trojan.Packed.20819]
Emsisoft 5.0.0.37/20100811 found [Rootkit.Win32.Agent!IK]
eSafe 7.0.17.0/20100809 found nothing
eTrust-Vet 36.1.7781/20100811 found nothing
F-Prot 4.6.1.107/20100810 found nothing
F-Secure 9.0.15370.0/20100811 found [Trojan.Krap.H]
Fortinet 4.1.143.0/20100811 found nothing
GData 21/20100811 found [Trojan.Krap.H]
Ikarus T3.1.1.87.0/20100811 found [Rootkit.Win32.Agent]
Jiangmin 13.0.900/20100810 found [Rootkit.Agent.inu]
McAfee 5.400.0.1158/20100811 found [Artemis!83AF81FEA495]
McAfee-GW-Edition 2010.1/20100811 found [Artemis!83AF81FEA495]
Microsoft 1.6004/20100811 found nothing
NOD32 5357/20100811 found [Win32/Bubnix.AU]
Norman 6.05.11/20100811 found nothing
nProtect 2010-08-11.02/20100811 found [Trojan.Krap.H]
Panda 10.0.2.7/20100810 found [Suspicious file]
PCTools 7.0.3.5/20100811 found [Trojan.Generic]
Rising 22.60.02.04/20100811 found [Trojan.Win32.Generic.5223EC5A]
Sophos 4.56.0/20100811 found [Mal/Krap-B]
Sunbelt 6717/20100811 found [VirTool.Win32.Obfuscator.FH (v)]
SUPERAntiSpyware 4.40.0.1006/20100811 found nothing
Symantec 20101.1.1.7/20100811 found [Trojan Horse]
TheHacker 6.5.2.1.342/20100811 found [Trojan/Agent.biiu]
TrendMicro-HouseCall 9.120.0.1004/20100811 found nothing
VBA32 3.12.12.8/20100810 found nothing
ViRobot 2010.8.9.3978/20100811 found nothing
VirusBuster 5.0.27.0/20100810 found nothing

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Po spuštění systému plno virů

#10 Příspěvek od JaRon »

je to jasny smejd - ak sa da ZMAZ ho
+
stiahni a uloz na plochu ComboFix

potom spust pod uctom s administratorskym opravnenim


akcia trva cca. 5-10 minut, niekedy i dlhsie -, Pocas scanu nespustaj ziadne ine aplikacie

Nie je dovod na paniku ak stroj bude restartovany
upozornenie: ak pouzivas antispyware s rezidentnim stitem, ten pred scanom vypni.

po restarte aplikacie vytvori log, ulozeny na C:\Combofix.txt (jeho obsah vloz sem)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění systému plno virů

#11 Příspěvek od GlaDOS »

asyncmac.sys sem vymazal ručně Shift+Delete.
Spustil sem CF (jako administrátor), hodilo to prázdnou chybovou hlášku, po odkliknutí se restartoval PC a po restartu naběhl CF a proskenoval PC. Po restartu jak vytvářel log naskočila chybová hláška (je v příloze, má to co dočinění se hrou, kterou už na disku nemám), CF vytvořil log. Konzoli pro zotavení jsem nemohl nainstalovat, protože nemám aktivní připojení k internetu.

ComboFix 10-08-10.06 - Administrator 11.08.2010 15:49:54.3.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1501 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý


VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Plocha\Crack na Flatout 2
c:\documents and settings\Administrator\Plocha\Crack na Flatout 2
c:\program files\INSTALL.LOG
C:\tmp.tmp
c:\windows\Readme.txt
c:\windows\system32\drivers\etc\lmhosts

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-07-11 do 2010-08-11 )))))))))))))))))))))))))))))))
.

2010-08-09 15:12 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-09 15:12 . 2010-08-09 15:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-09 15:12 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-09 10:23 . 2010-08-09 10:23 -------- d-----w- c:\program files\trend micro
2010-08-09 10:23 . 2010-08-09 10:23 -------- d-----w- C:\rsit
2010-08-09 10:10 . 2008-04-13 22:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-08-09 10:10 . 2008-04-13 22:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-08-09 10:01 . 2008-04-13 22:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-08-09 10:01 . 2008-04-13 22:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-08-09 10:01 . 2008-04-13 22:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-08-09 10:01 . 2008-04-13 22:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-08-09 09:54 . 2010-08-11 13:57 755712 ----a-w- c:\windows\system32\drivers\seyoeb.sys
2010-08-07 19:53 . 2010-08-07 19:53 -------- d-----w- c:\program files\StarCraft II
2010-08-06 18:02 . 2010-08-06 18:02 -------- d-----w- c:\documents and settings\All Users\Data aplikaci
2010-08-05 22:21 . 2010-08-05 22:21 -------- d-----r- C:\Sandbox
2010-08-04 21:50 . 2010-08-04 21:50 -------- d-----w- c:\program files\ReflexiveArcade
2010-08-04 15:30 . 2010-08-04 16:02 28369 ----a-w- c:\windows\scunin.dat
2010-08-04 15:30 . 2010-08-04 16:02 967 ----a-w- c:\windows\ScUnin.pif
2010-08-04 15:30 . 2010-08-04 16:02 70656 ----a-w- c:\windows\ScUnin.exe
2010-08-03 20:51 . 2010-08-06 09:48 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-07-30 19:27 . 2010-07-30 19:27 -------- d-----w- c:\program files\Easy Video Joiner
2010-07-30 12:00 . 2010-07-30 12:00 -------- d-----w- c:\program files\Easy GIF Animator
2010-07-29 22:08 . 2010-07-29 22:08 13 --sha-w- c:\windows\CNSYSDLG.SYS
2010-07-29 22:06 . 2010-07-29 22:09 -------- d-----w- c:\program files\Common Files\Canopus Shared
2010-07-29 21:44 . 2010-08-06 16:08 -------- d-----w- c:\program files\Ask.com
2010-07-29 21:43 . 2010-07-29 21:45 -------- d-----w- c:\program files\The KMPlayer
2010-07-26 20:25 . 2010-07-26 20:27 -------- d-----w- c:\program files\Mihov Picture Downloader
2010-07-22 21:25 . 2010-07-22 21:33 -------- d-----w- C:\vcs5BGEffects

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-11 10:09 . 2008-11-22 21:17 -------- d-----w- c:\program files\SpeedFan
2010-08-11 10:05 . 2010-03-05 17:11 380 ----a-w- c:\windows\system32\Pen_Tablet.dat
2010-08-08 08:26 . 2008-04-12 13:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-02 23:09 . 2008-02-19 18:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-02 22:53 . 2008-05-11 18:57 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-08-02 22:53 . 2008-05-11 18:57 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-07-10 20:42 . 2010-07-10 20:42 162432 ----a-w- c:\windows\system32\drivers\ithsgt.sys
2010-07-10 14:18 . 2010-07-08 14:23 -------- d-----w- c:\program files\Common Files\Ulead Systems
2010-07-10 14:15 . 2008-04-19 09:21 -------- d-----w- c:\program files\Ahead
2010-07-09 22:22 . 2010-07-09 22:22 -------- d-----w- c:\program files\WinAVI Video Converter
2010-07-09 22:12 . 2010-07-09 22:12 -------- d-----w- c:\program files\Xenocode
2010-07-09 21:23 . 2008-02-19 18:52 -------- d-----w- c:\program files\CyberLink
2010-07-08 18:47 . 2010-07-08 18:47 -------- d-----w- c:\program files\AnvSoft
2010-07-08 16:57 . 2010-01-24 10:51 -------- d-----w- c:\program files\Opera
2010-07-08 14:22 . 2010-07-08 14:22 -------- d-----w- c:\program files\Ulead Systems
2010-07-06 22:00 . 2010-07-06 22:00 -------- d-----w- c:\program files\QIP 2010
2010-07-06 17:16 . 2010-07-05 22:17 -------- d-----w- c:\program files\AntiTwin
2010-07-03 20:38 . 2010-07-03 20:32 -------- d-----w- c:\program files\Microsoft
2010-07-03 20:36 . 2010-07-03 20:27 -------- d-----w- c:\program files\Farm Helper
2010-07-03 20:32 . 2010-07-03 20:32 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-28 16:05 . 2010-06-28 16:05 -------- d-----w- c:\program files\Adobe Media Player
2010-06-28 16:04 . 2010-06-28 16:04 -------- d-----w- c:\program files\My Company Name
2010-06-28 15:59 . 2010-06-28 15:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-27 07:15 . 2008-05-30 17:47 -------- d-----r- c:\program files\Skype
2010-06-02 02:55 . 2010-07-02 16:07 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 02:55 . 2010-07-02 16:07 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 02:55 . 2010-07-02 16:07 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-05-26 09:41 . 2010-07-02 16:07 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2003-12-18 09:33 . 2010-04-11 16:43 20102 ----a-w- c:\program files\Readme.txt
2003-09-03 05:46 . 2010-04-11 16:43 10960 ----a-w- c:\program files\EULA.txt
2008-03-22 22:47 . 2008-03-22 22:47 0 --sh--w- c:\windows\S520A6F13.tmp
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Nero\data\Xtras\mssysmgr.exe" [2005-02-26 212992]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2008-10-03 133104]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-11-03 2540800]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-13 1443072]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-09 98304]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-06-28 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2005-05-23 90112]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AVer HID Receiver.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2009-12-4 159744]
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2009-12-4 663552]
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2008-8-30 303104]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\winver.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"e:\\hry\\Steam\\Steam.exe"=
"e:\\programy\\FileZilla FTP Client\\filezilla.exe"=
"e:\\hry\\left 4 dead 2\\Left.4.Dead.2-THEPiRATEGAY\\left4dead2.exe"=
"e:\\hry\\Half-Life 2 Ultimate Edition 7\\Engine3\\hl2.exe"=
"e:\\hry\\Steam\\SteamApps\\common\\osmos demo\\OsmosDemo.exe"=
"e:\\hry\\Steam\\SteamApps\\common\\alien swarm\\srcds.exe"=
"e:\\hry\\Steam\\SteamApps\\common\\alien swarm\\swarm.exe"=
"e:\\hry\\StarCraft II\\StarCraft II.exe"=
"e:\\hry\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"WinUpdate.exe"= 6667:TCP
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [4.12.2009 19:32 352256]
R2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [4.12.2009 19:32 409600]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [13.3.2008 16:49 472320]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [5.3.2010 16:13 4497704]
R2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [5.3.2010 16:14 113448]
R3 AVerAF15DMBTH;AVerMedia A850 USB;c:\windows\system32\drivers\AVerAF15DMBTH.sys [9.4.2009 16:27 293120]
S2 gupdate1c9cab45ac42da0;Google Update Service (gupdate1c9cab45ac42da0);c:\program files\Google\Update\GoogleUpdate.exe [2.5.2009 1:27 133104]
S3 ATICDSDr;ATICDSDr;\??\f:\install\bin\atiicdxx.sys --> f:\install\bin\atiicdxx.sys [?]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [30.11.2008 13:04 27904]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.4.2008 14:56 721904]

--- Ostatní služby/ovladače v paměti ---

*Deregistered* - seyoeb
.
Obsah adresáře 'Naplánované úlohy'

2010-08-11 c:\windows\Tasks\AdobeAAMUpdater-1.0-STOLNI-Administrator.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-06-28 14:33]

2010-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 23:27]

2010-08-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 23:27]

2010-08-11 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 13:23]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com/?o=14597&l=dis
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 10.1.9.1:3128
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\Internet Download Manager\IEGetAll.htm
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\gkz7l0pk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=DCF2DF&PC=DCF2&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - component: c:\documents and settings\Administrator\Data aplikací\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\TabletPlugins\npwacom.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKCU-Run-AdobeBridge - (no file)
HKLM-Run-PinnacleDriverCheck - c:\windows\system32\\PSDrvCheck.exe
AddRemove-BFME1->BFME2 Map Pack BETA - c:\documents and settings\Administrator\Data aplikací\My Battle for Middle-earth(tm) II Files\Maps\map_pack_uninstall.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-Half life 2 CZ - c:\documents and settings\Administrator\Plocha\Nová složka\Uninstal.exe
AddRemove-Portal Prelude SK - c:\documents and settings\Administrator\Plocha\Nová složka\Uninstall PP_sK.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-11 15:56
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\seyoeb]

.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1202660629-2111687655-839522115-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:cf,c9,5e,c5,45,e3,b5,59,f3,ad,98,e9,ce,b5,4e,f5,86,59,f9,d1,42,64,98,
35,55,f0,9c,75,fd,39,77,af,04,ce,1b,40,15,f4,f5,8e,5f,d9,ac,5e,ee,15,07,59,\
"??"=hex:34,be,4c,0d,b9,5b,33,60,f0,6b,26,5e,b1,35,e1,23

[HKEY_USERS\S-1-5-21-1202660629-2111687655-839522115-500\Software\SecuROM\License information*]
"datasecu"=hex:f7,bf,31,80,b9,82,f5,8c,6f,ea,e9,95,74,d4,0c,40,76,e7,14,92,be,
cd,72,30,50,0c,84,96,41,04,79,ad,45,c2,40,2f,c3,35,d8,a2,07,71,01,57,1c,e0,\
"rkeysecu"=hex:bf,b6,26,8a,39,ce,99,48,f7,e3,ab,5e,13,bb,dc,dd

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77b861c2-e989-4471-9bc9-991fc2432a98}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fd
"Therad"=dword:0000000f
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,a4,09,8b,91,8a,
32,51,9b,04,a3,b7,bd,5b,11,77,40,c8,29,b7,07,ac,cf,84,17,b4,f5,f8,34,7a,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1c,1f,2d,a2,01,84,36,00,0f,97,f4,4f,b2,ed,6e,9e,1c,23,3e,3e,ef,
72,1f,88,76,11,d9,4b,6b,90,0a,02,c5,3d,07,c2,52,6d,46,1b,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Data aplikací\\ESET\\ESET Smart Security\\"
"DataDir"="ESET\\ESET Smart Security\\"
"EditionName"="TemDono FiX 1.2 (31 days remaining forever up to 2050)"
"InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\"
"LanguageId"=dword:00000405
"PackageTag"=dword:04ff9687
"ProductBase"=dword:00000001
"ProductCode"="{C22F45F8-3BDF-4D0A-99FC-C901E4303E41}"
"ProductName"="ESET Smart Security"
"ProductType"="ess"
"ProductVersion"="4.0.314.0"
"UniqueId"="0007B7964AAB8111"
"ScannerBuild"=dword:00001124
"ScannerVersionId"=dword:00000ef8
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="4AE7356BEF26C3CE622AAB336376BE6717BDC59EE01AF579E3CCB47EA7B74CD17EE0DCA9B9FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14079DB7CE019D40AA5CA6171C11EC38DE3DFBEF608A2DE7FBA2A7FDA8D08FF4D078EB3F3255782DB6718CA4000E185E2118BD9347A87C145F340FBA74775A2E4DB69AEE89652A0F52BD0D26C2FB9A56B21EF8738CFAC1A5B28579185281B50302242A2E933E613D8073E853CB3AB2EACB7CEB6E2BAE187021B8248322EBCB9E8F037510B44FF15AF616368827C883D8D3958ACCF4F20C696933FE499839B44FA9D9090D270C22AD7CEAC004B22C2101C912FCB68BFDA0AA5D9D301C3FEC010897F028FEF7EA30246FFE86EB236C14693DDE9C39E786CA7162668F9372133361B3D6C6A50BE54ACCBD9FB949FD93DAB855AB7C46D5CAF5A073BCA729E23842936EDE8E2614FA96DB6DE140079D32653DC96DDCB2F40C7FBDA097BB3B16ED997EC81F5E059DAF2A29961CB575B1DB1AE8E9593738388C3A7288AFBE8C63C918A65C70C6B0850713B165E869CABCA84FCD94EFB67468166A0EE4025A4378651030D3728C75FD0F529399A75B9E143454283FEDBA68A2764C00FE4E69E956DF4AE86E06AA890B54D91387FCC3EB659CE8D175585579D2FC0C5F331C7E6FD1D880BD7E524E8308E8921A98CC0D152D08C3CD53F85071407E4C67F5335C25937661416CC0D7DC2465D7B14746565D3F9B8C40095927FD81D4A373CCA17CC19863112C34005E77DDE3FA0C25D5F06DC1056072DC4C88AF815B9A08D2370BE0AFCC26586382AA160C823FFA55AEE3D1B0F1D05028E257FB81F2B1493589687E00E3AAC49D7D3ADF5AE3DB789149E9FA5818E2EA58F82BBD947FD701B5F22A7F81DD9E941BEABDDF442FFD1F256070BCDEAD8E78EDA75130A26BF59E2C8F97A88176750E260B9C069D8EC5AEF0721C5038EE41D1FDCF4676E7A264B20240ADA51FE8959C9F5D6F258AB0478CE8C24151301C5DF13496C1957215F1F336AA9D0351F8DACEF8AA04F504C8093F955AEBC066F7B6FA4AE3A775A7B8DF3BDAB7C9355FEA12D7B9FADA925A8D09F21201D9034B4A17B194E215E5BE84658794164E12E608028E7D9C2AF9AEB836F711C87DE0A85EB9FEF684591744F6ABF99FB3F353D71FDDEE74A2DC12750AF4C154047E05170551F06A7C781E970FD059CA48BD18F602D29560638D1FF8431C68B548B68286908336FCC329F46B52668EF4CC5F62DE05FEC799F710CED7AB792921F2B34B39D9E6264F96D678494A7328987EC1187A83F5E90BBFE9AE020D4DE09523B939453C8AB69773A1EA8B027158BD5C01848A59BE89345BD234403749952AB93E881717EF089E1FDC70E20B4EF3022EECD525"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(572)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\WTouch\WTouchUser.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\oodag.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-08-11 16:03:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-08-11 14:03
ComboFix2.txt 2008-08-04 16:26

Před spuštěním: 2 324 910 080
Po spuštění: 3 213 955 072

- - End Of File - - 33A721288F4407C70EF70101AAD624C4
Přílohy
chyba.JPG
(37.66 KiB) Staženo 352 x

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Po spuštění systému plno virů

#12 Příspěvek od JaRon »

fajn, finisujeme :)
Presun ComboFix
na plochu (ak tam este nie je)

otvor si Poznamkovy blok - notepad

do neho zkopiruj skript z nasledujiceho okna:

Kód: Vybrat vše

Driver::
seyoeb

Folder::
c:\program files\Ask.com


uloz vytvoreny textovy soubor ako CFScript.txt na plochu

po ulozeni uchop vytvoreny skript lavym tlacitkom mysi a presun ho nad ikonu Combofixu, nad nim skript upust:

Obrázek

po aplikacii by mal vzniknut dalsi log, ten vloz sem :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění systému plno virů

#13 Příspěvek od GlaDOS »

ComboFix 10-08-10.06 - Administrator 12.08.2010 10:47:58.4.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1545 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\fv_316.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SEYOEB
-------\Service_seyoeb


((((((((((((((((((((((((( Soubory vytvořené od 2010-07-12 do 2010-08-12 )))))))))))))))))))))))))))))))
.

2010-08-09 15:12 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-09 15:12 . 2010-08-09 15:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-09 15:12 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-09 10:23 . 2010-08-09 10:23 -------- d-----w- c:\program files\trend micro
2010-08-09 10:23 . 2010-08-09 10:23 -------- d-----w- C:\rsit
2010-08-09 10:10 . 2008-04-13 22:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-08-09 10:10 . 2008-04-13 22:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-08-09 10:01 . 2008-04-13 22:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-08-09 10:01 . 2008-04-13 22:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-08-09 10:01 . 2008-04-13 22:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-08-09 10:01 . 2008-04-13 22:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-08-09 09:54 . 2010-08-12 08:56 755712 ----a-w- c:\windows\system32\drivers\seyoeb.sys
2010-08-07 19:53 . 2010-08-07 19:53 -------- d-----w- c:\program files\StarCraft II
2010-08-06 18:02 . 2010-08-06 18:02 -------- d-----w- c:\documents and settings\All Users\Data aplikaci
2010-08-05 22:21 . 2010-08-05 22:21 -------- d-----r- C:\Sandbox
2010-08-04 21:50 . 2010-08-04 21:50 -------- d-----w- c:\program files\ReflexiveArcade
2010-08-04 15:30 . 2010-08-04 16:02 28369 ----a-w- c:\windows\scunin.dat
2010-08-04 15:30 . 2010-08-04 16:02 967 ----a-w- c:\windows\ScUnin.pif
2010-08-04 15:30 . 2010-08-04 16:02 70656 ----a-w- c:\windows\ScUnin.exe
2010-08-03 20:51 . 2010-08-06 09:48 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-07-30 19:27 . 2010-07-30 19:27 -------- d-----w- c:\program files\Easy Video Joiner
2010-07-30 12:00 . 2010-07-30 12:00 -------- d-----w- c:\program files\Easy GIF Animator
2010-07-29 22:08 . 2010-07-29 22:08 13 --sha-w- c:\windows\CNSYSDLG.SYS
2010-07-29 22:06 . 2010-07-29 22:09 -------- d-----w- c:\program files\Common Files\Canopus Shared
2010-07-29 21:43 . 2010-07-29 21:45 -------- d-----w- c:\program files\The KMPlayer
2010-07-26 20:25 . 2010-07-26 20:27 -------- d-----w- c:\program files\Mihov Picture Downloader
2010-07-22 21:25 . 2010-07-22 21:33 -------- d-----w- C:\vcs5BGEffects

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-11 14:22 . 2008-11-22 21:17 -------- d-----w- c:\program files\SpeedFan
2010-08-11 10:05 . 2010-03-05 17:11 380 ----a-w- c:\windows\system32\Pen_Tablet.dat
2010-08-08 08:26 . 2008-04-12 13:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-02 23:09 . 2008-02-19 18:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-02 22:53 . 2008-05-11 18:57 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-08-02 22:53 . 2008-05-11 18:57 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-07-10 20:42 . 2010-07-10 20:42 162432 ----a-w- c:\windows\system32\drivers\ithsgt.sys
2010-07-10 14:18 . 2010-07-08 14:23 -------- d-----w- c:\program files\Common Files\Ulead Systems
2010-07-10 14:15 . 2008-04-19 09:21 -------- d-----w- c:\program files\Ahead
2010-07-09 22:22 . 2010-07-09 22:22 -------- d-----w- c:\program files\WinAVI Video Converter
2010-07-09 22:12 . 2010-07-09 22:12 -------- d-----w- c:\program files\Xenocode
2010-07-09 21:23 . 2008-02-19 18:52 -------- d-----w- c:\program files\CyberLink
2010-07-08 18:47 . 2010-07-08 18:47 -------- d-----w- c:\program files\AnvSoft
2010-07-08 16:57 . 2010-01-24 10:51 -------- d-----w- c:\program files\Opera
2010-07-08 14:22 . 2010-07-08 14:22 -------- d-----w- c:\program files\Ulead Systems
2010-07-06 22:00 . 2010-07-06 22:00 -------- d-----w- c:\program files\QIP 2010
2010-07-06 17:16 . 2010-07-05 22:17 -------- d-----w- c:\program files\AntiTwin
2010-07-03 20:38 . 2010-07-03 20:32 -------- d-----w- c:\program files\Microsoft
2010-07-03 20:36 . 2010-07-03 20:27 -------- d-----w- c:\program files\Farm Helper
2010-07-03 20:32 . 2010-07-03 20:32 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-28 16:05 . 2010-06-28 16:05 -------- d-----w- c:\program files\Adobe Media Player
2010-06-28 16:04 . 2010-06-28 16:04 -------- d-----w- c:\program files\My Company Name
2010-06-28 15:59 . 2010-06-28 15:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-27 07:15 . 2008-05-30 17:47 -------- d-----r- c:\program files\Skype
2010-06-02 02:55 . 2010-07-02 16:07 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 02:55 . 2010-07-02 16:07 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 02:55 . 2010-07-02 16:07 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-05-26 09:41 . 2010-07-02 16:07 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 09:41 . 2010-07-02 16:07 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2003-12-18 09:33 . 2010-04-11 16:43 20102 ----a-w- c:\program files\Readme.txt
2003-09-03 05:46 . 2010-04-11 16:43 10960 ----a-w- c:\program files\EULA.txt
2008-03-22 22:47 . 2008-03-22 22:47 0 --sh--w- c:\windows\S520A6F13.tmp
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Nero\data\Xtras\mssysmgr.exe" [2005-02-26 212992]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2008-10-03 133104]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-11-03 2540800]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-13 1443072]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-09 98304]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-06-28 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2005-05-23 90112]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
AVer HID Receiver.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe [2009-12-4 159744]
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2009-12-4 663552]
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2008-8-30 303104]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\winver.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"e:\\hry\\Steam\\Steam.exe"=
"e:\\programy\\FileZilla FTP Client\\filezilla.exe"=
"e:\\hry\\left 4 dead 2\\Left.4.Dead.2-THEPiRATEGAY\\left4dead2.exe"=
"e:\\hry\\Half-Life 2 Ultimate Edition 7\\Engine3\\hl2.exe"=
"e:\\hry\\Steam\\SteamApps\\common\\osmos demo\\OsmosDemo.exe"=
"e:\\hry\\Steam\\SteamApps\\common\\alien swarm\\srcds.exe"=
"e:\\hry\\Steam\\SteamApps\\common\\alien swarm\\swarm.exe"=
"e:\\hry\\StarCraft II\\StarCraft II.exe"=
"e:\\hry\\StarCraft II\\Versions\\Base15405\\SC2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"WinUpdate.exe"= 6667:TCP
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [5.7.2006 14:46 63352]
R2 AVerRemote;AVerRemote;c:\program files\Common Files\AVerMedia\Service\AVerRemote.exe [4.12.2009 19:32 352256]
R2 AVerScheduleService;AVerScheduleService;c:\program files\Common Files\AVerMedia\Service\AVerScheduleService.exe [4.12.2009 19:32 409600]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [13.3.2008 16:49 472320]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [5.3.2010 16:13 4497704]
R2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [5.3.2010 16:14 113448]
R3 AVerAF15DMBTH;AVerMedia A850 USB;c:\windows\system32\drivers\AVerAF15DMBTH.sys [9.4.2009 16:27 293120]
S2 gupdate1c9cab45ac42da0;Google Update Service (gupdate1c9cab45ac42da0);c:\program files\Google\Update\GoogleUpdate.exe [2.5.2009 1:27 133104]
S3 ATICDSDr;ATICDSDr;\??\f:\install\bin\atiicdxx.sys --> f:\install\bin\atiicdxx.sys [?]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [30.11.2008 13:04 27904]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12.4.2008 14:56 721904]
.
Obsah adresáře 'Naplánované úlohy'

2010-08-11 c:\windows\Tasks\AdobeAAMUpdater-1.0-STOLNI-Administrator.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-06-28 14:33]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 23:27]

2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 23:27]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com/?o=14597&l=dis
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 10.1.9.1:3128
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Stáhnout s IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Stáhnout s IDM obsah FLV videa - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Stáhnout s IDM všechny odkazy - c:\program files\Internet Download Manager\IEGetAll.htm
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\gkz7l0pk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=DCF2DF&PC=DCF2&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - component: c:\documents and settings\Administrator\Data aplikací\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\TabletPlugins\npwacom.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll



**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-1202660629-2111687655-839522115-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:cf,c9,5e,c5,45,e3,b5,59,f3,ad,98,e9,ce,b5,4e,f5,86,59,f9,d1,42,64,98,
35,55,f0,9c,75,fd,39,77,af,04,ce,1b,40,15,f4,f5,8e,5f,d9,ac,5e,ee,15,07,59,\
"??"=hex:34,be,4c,0d,b9,5b,33,60,f0,6b,26,5e,b1,35,e1,23

[HKEY_USERS\S-1-5-21-1202660629-2111687655-839522115-500\Software\SecuROM\License information*]
"datasecu"=hex:f7,bf,31,80,b9,82,f5,8c,6f,ea,e9,95,74,d4,0c,40,76,e7,14,92,be,
cd,72,30,50,0c,84,96,41,04,79,ad,45,c2,40,2f,c3,35,d8,a2,07,71,01,57,1c,e0,\
"rkeysecu"=hex:bf,b6,26,8a,39,ce,99,48,f7,e3,ab,5e,13,bb,dc,dd

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77b861c2-e989-4471-9bc9-991fc2432a98}]
@Denied: (Full) (Everyone)
"Model"=dword:000000fd
"Therad"=dword:0000000f
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,a4,09,8b,91,8a,
32,51,9b,04,a3,b7,bd,5b,11,77,40,c8,29,b7,07,ac,cf,84,17,b4,f5,f8,34,7a,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):1c,1f,2d,a2,01,84,36,00,0f,97,f4,4f,b2,ed,6e,9e,1c,23,3e,3e,ef,
72,1f,88,76,11,d9,4b,6b,90,0a,02,c5,3d,07,c2,52,6d,46,1b,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10g_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\Documents and Settings\\All Users\\Data aplikací\\ESET\\ESET Smart Security\\"
"DataDir"="ESET\\ESET Smart Security\\"
"EditionName"="TemDono FiX 1.2 (31 days remaining forever up to 2050)"
"InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\"
"LanguageId"=dword:00000405
"PackageTag"=dword:04ff9687
"ProductBase"=dword:00000001
"ProductCode"="{C22F45F8-3BDF-4D0A-99FC-C901E4303E41}"
"ProductName"="ESET Smart Security"
"ProductType"="ess"
"ProductVersion"="4.0.314.0"
"UniqueId"="0007B7964AAB8111"
"ScannerBuild"=dword:00001124
"ScannerVersionId"=dword:00000ef8
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG11.00.00.01WORKSTATION"="4AE7356BEF26C3CE622AAB336376BE6717BDC59EE01AF579E3CCB47EA7B74CD17EE0DCA9B9FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14079DB7CE019D40AA5CA6171C11EC38DE3DFBEF608A2DE7FBA2A7FDA8D08FF4D078EB3F3255782DB6718CA4000E185E2118BD9347A87C145F340FBA74775A2E4DB69AEE89652A0F52BD0D26C2FB9A56B21EF8738CFAC1A5B28579185281B50302242A2E933E613D8073E853CB3AB2EACB7CEB6E2BAE187021B8248322EBCB9E8F037510B44FF15AF616368827C883D8D3958ACCF4F20C696933FE499839B44FA9D9090D270C22AD7CEAC004B22C2101C912FCB68BFDA0AA5D9D301C3FEC010897F028FEF7EA30246FFE86EB236C14693DDE9C39E786CA7162668F9372133361B3D6C6A50BE54ACCBD9FB949FD93DAB855AB7C46D5CAF5A073BCA729E23842936EDE8E2614FA96DB6DE140079D32653DC96DDCB2F40C7FBDA097BB3B16ED997EC81F5E059DAF2A29961CB575B1DB1AE8E9593738388C3A7288AFBE8C63C918A65C70C6B0850713B165E869CABCA84FCD94EFB67468166A0EE4025A4378651030D3728C75FD0F529399A75B9E143454283FEDBA68A2764C00FE4E69E956DF4AE86E06AA890B54D91387FCC3EB659CE8D175585579D2FC0C5F331C7E6FD1D880BD7E524E8308E8921A98CC0D152D08C3CD53F85071407E4C67F5335C25937661416CC0D7DC2465D7B14746565D3F9B8C40095927FD81D4A373CCA17CC19863112C34005E77DDE3FA0C25D5F06DC1056072DC4C88AF815B9A08D2370BE0AFCC26586382AA160C823FFA55AEE3D1B0F1D05028E257FB81F2B1493589687E00E3AAC49D7D3ADF5AE3DB789149E9FA5818E2EA58F82BBD947FD701B5F22A7F81DD9E941BEABDDF442FFD1F256070BCDEAD8E78EDA75130A26BF59E2C8F97A88176750E260B9C069D8EC5AEF0721C5038EE41D1FDCF4676E7A264B20240ADA51FE8959C9F5D6F258AB0478CE8C24151301C5DF13496C1957215F1F336AA9D0351F8DACEF8AA04F504C8093F955AEBC066F7B6FA4AE3A775A7B8DF3BDAB7C9355FEA12D7B9FADA925A8D09F21201D9034B4A17B194E215E5BE84658794164E12E608028E7D9C2AF9AEB836F711C87DE0A85EB9FEF684591744F6ABF99FB3F353D71FDDEE74A2DC12750AF4C154047E05170551F06A7C781E970FD059CA48BD18F602D29560638D1FF8431C68B548B68286908336FCC329F46B52668EF4CC5F62DE05FEC799F710CED7AB792921F2B34B39D9E6264F96D678494A7328987EC1187A83F5E90BBFE9AE020D4DE09523B939453C8AB69773A1EA8B027158BD5C01848A59BE89345BD234403749952AB93E881717EF089E1FDC70E20B4EF3022EECD525"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(996)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(648)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\oodag.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\program files\WTouch\WTouchUser.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Celkový čas: 2010-08-12 11:02:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-08-12 09:02
ComboFix2.txt 2010-08-11 14:03
ComboFix3.txt 2008-08-04 16:26

Před spuštěním: 3 351 056 384
Po spuštění: 3 260 559 360

- - End Of File - - 61384AD08BB88A0BD8DFE60C8373ECB4

Oukej, co dál?

Avatar uživatele
JaRon
Moderátor
Moderátor
Příspěvky: 15933
Registrován: 29 Bře 2005 13:39
Místo/Bydliště: BB-SK

Re: Po spuštění systému plno virů

#14 Příspěvek od JaRon »

este rucne ZMAZ subor c:\windows\system32\drivers\seyoeb.sys
a ak nie su problemy HOTOVO :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

GlaDOS
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 09 Srp 2010 11:11

Re: Po spuštění systému plno virů

#15 Příspěvek od GlaDOS »

Soubor sem smazal, ComboFix odinstaloval, Pc restartoval a problémy nejsou :)

Děkuji Vám za Váš čas a trpělivost. Do příště si dám lepší pozor kam lezu a co stahuju.
Naposledy upravil(a) GlaDOS dne 12 Srp 2010 10:38, celkem upraveno 1 x.

Odpovědět