Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

tombirdswithhair.com Problém

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
T1tanus
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 17 srp 2010 16:36

tombirdswithhair.com Problém

#1 Příspěvek od T1tanus »

Zdravim

Mám problém s tombirdswithhair.com--> (178.17.162.242) kterej mě neustále Spamuje, Eset to hlásí každou chvilku.Problém to vyřešil až Ad-aware ale po restartu PC se to oběvuje znova.
Kdyby šel ten Malware odstranit,Nebo permamentně zablokovat tu adresu.
:|

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: tombirdswithhair.com Problém

#2 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

T1tanus
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 17 srp 2010 16:36

Re: tombirdswithhair.com Problém

#3 Příspěvek od T1tanus »

J Sry Tady to je
Running processes:
C:\WINDOWS.2\System32\smss.exe
C:\WINDOWS.2\system32\winlogon.exe
C:\WINDOWS.2\system32\services.exe
C:\WINDOWS.2\system32\lsass.exe
C:\WINDOWS.2\system32\Ati2evxx.exe
C:\WINDOWS.2\system32\svchost.exe
C:\WINDOWS.2\System32\svchost.exe
C:\WINDOWS.2\system32\Ati2evxx.exe
C:\WINDOWS.2\system32\svchost.exe
C:\WINDOWS.2\Explorer.EXE
C:\WINDOWS.2\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
C:\WINDOWS.2\system32\svchost.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS.2\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS.2\system32\PnkBstrA.exe
C:\Program Files\Tunngle\TnglCtrl.exe
C:\WINDOWS.2\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS.2\system32\ctfmon.exe
C:\program files\steam\steam.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Documents and Settings\milan Bezdek\Local Settings\Data aplikací\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\milan Bezdek\Dokumenty\Stažené soubory\RSIT.exe
C:\Program Files\trend micro\milan Bezdek.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = About:Blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer - Microsoft Windows XP 2007 Ultra Edition
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Auto_Del_Temp] C:\WINDOWS.2\system32\TEMP.cmd
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [MPlayerForWindows_UpdateReminder] "C:\Program Files\MPlayer for Windows\AutoUpdate.exe" /L=1033 /TASK
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\milan Bezdek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS.2\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.2\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.2\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.2\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.2\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.2\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS.2\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS.2\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS.2\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS.2\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS.2\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS.2\system32\PnkBstrA.exe
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS.2\system32\sfrem01.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files\Tunngle\TnglCtrl.exe

--
End of file - 9521 bytes

======Scheduled tasks folder======

C:\WINDOWS.2\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS.2\tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1972579041-839522115-1005Core.job
C:\WINDOWS.2\tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1972579041-839522115-1005UA.job
C:\WINDOWS.2\tasks\Updates Manager.exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00011268-E188-40DF-A514-835FCD78B1BF}]
IE7Pro BHO - C:\Program Files\IEPro\iepro.dll [2008-02-29 719976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll [2008-01-25 496952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-11-02 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-11-02 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd []
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-11-02 149280]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2007-12-21 1443072]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048]
"Auto_Del_Temp"=C:\WINDOWS.2\system32\TEMP.cmd [2008-02-24 73]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2006-11-10 90112]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-12-03 2213160]
"MPlayerForWindows_UpdateReminder"=C:\Program Files\MPlayer for Windows\AutoUpdate.exe [2010-04-16 234917]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2007-12-13 1688872]
"Google Update"=C:\Documents and Settings\milan Bezdek\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-01-19 135664]
"ctfmon.exe"=C:\WINDOWS.2\system32\ctfmon.exe [2008-04-14 15360]
"Steam"=c:\program files\steam\steam.exe [2010-05-07 1238352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS.2\system32\Ati2evxx.dll [2008-01-10 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS.2\system32\wpdshserviceobj.dll [2008-03-27 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\IEPro\MiniDM.exe"="C:\Program Files\IEPro\MiniDM.exe:*:Enabled:MiniDM"
"C:\WINDOWS.2\system32\PnkBstrA.exe"="C:\WINDOWS.2\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS.2\system32\PnkBstrB.exe"="C:\WINDOWS.2\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Steam\steamapps\common\sam and max episode 4\sammax104_drm.exe"="C:\Program Files\Steam\steamapps\common\sam and max episode 4\sammax104_drm.exe:*:Enabled:Sam and Max 104: Abe Lincoln Must Die"
"C:\Program Files\Autodesk\3dsMax8\3dsmax.exe"="C:\Program Files\Autodesk\3dsMax8\3dsmax.exe:*:Enabled:Autodesk 3ds Max 8"
"C:\Program Files\Autodesk\backburner\monitor.exe"="C:\Program Files\Autodesk\backburner\monitor.exe:*:Enabled:backburner 2.3 monitor"
"C:\Program Files\Autodesk\backburner\manager.exe"="C:\Program Files\Autodesk\backburner\manager.exe:*:Enabled:backburner 2.3 manager"
"C:\Program Files\Autodesk\backburner\server.exe"="C:\Program Files\Autodesk\backburner\server.exe:*:Enabled:backburner 2.3 server"
"C:\Program Files\Sierra\FEAR\FEAR.exe"="C:\Program Files\Sierra\FEAR\FEAR.exe:*:Enabled:FEAR"
"C:\Program Files\Sierra\FEAR\FEARMP.exe"="C:\Program Files\Sierra\FEAR\FEARMP.exe:*:Enabled:FEAR"
"C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Steam\steamapps\titanus008\zombie panic! source\hl2.exe"="C:\Program Files\Steam\steamapps\titanus008\zombie panic! source\hl2.exe:*:Enabled:Zombie Panic! Source"
"C:\Program Files\Steam\steamapps\titanus008\age of chivalry\hl2.exe"="C:\Program Files\Steam\steamapps\titanus008\age of chivalry\hl2.exe:*:Enabled:Age of Chivalry"
"C:\Program Files\Steam\steamapps\titanus008\diprip warm up\hl2.exe"="C:\Program Files\Steam\steamapps\titanus008\diprip warm up\hl2.exe:*:Enabled:D.I.P.R.I.P. Warm Up"
"C:\Program Files\Steam\steamapps\titanus008\sourcesdk\bin\SDKLauncher.exe"="C:\Program Files\Steam\steamapps\titanus008\sourcesdk\bin\SDKLauncher.exe:*:Enabled:Source SDK"
"C:\Program Files\Steam\steamapps\titanus008\pirates, vikings, and knights ii\hl2.exe"="C:\Program Files\Steam\steamapps\titanus008\pirates, vikings, and knights ii\hl2.exe:*:Enabled:Pirates, Vikings, and Knights II"
"C:\Program Files\Steam\steamapps\common\peggle extreme\PeggleExtreme.exe"="C:\Program Files\Steam\steamapps\common\peggle extreme\PeggleExtreme.exe:*:Enabled:Peggle Extreme"
"C:\Program Files\EA Games\Medal of Honor Pacific Assault(tm)\mohpa.exe"="C:\Program Files\EA Games\Medal of Honor Pacific Assault(tm)\mohpa.exe:*:Enabled:Medal of Honor Pacific Assault(tm)"
"C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD_Demo.exe"="C:\Program Files\Steam\steamapps\common\serious sam hd the first encounter\Bin\SamHD_Demo.exe:*:Enabled:Serious Sam HD: The First Encounter Demo"
"C:\Program Files\Microsoft Games\Halo 2\halo2.exe"="C:\Program Files\Microsoft Games\Halo 2\halo2.exe:*:Enabled:Halo 2"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\EA Games\Battlefield 2\BF2.exe"="C:\Program Files\EA Games\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\games\RedFaction\rf.exe"="C:\games\RedFaction\rf.exe:*:Disabled:Red Faction"
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe"="C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForever.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe"="C:\Program Files\Steam\steamapps\common\trackmania nations forever\TmForeverLauncher.exe:*:Enabled:TrackMania Nations Forever"
"C:\Program Files\Steam\steamapps\titanus008\source sdk base 2007\hl2.exe"="C:\Program Files\Steam\steamapps\titanus008\source sdk base 2007\hl2.exe:*:Enabled:Source SDK Base 2007"
"C:\Program Files\Sierra\FEARCombat\FEARMP.exe"="C:\Program Files\Sierra\FEARCombat\FEARMP.exe:*:Enabled:FEAR Combat"
"C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe"="C:\Program Files\Steam\steamapps\common\left 4 dead\left4dead.exe:*:Enabled:Left 4 Dead"
"C:\Program Files\Ventrilo\Ventrilo.exe"="C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
"C:\Program Files\Nexon\Counter-Strike Online\Bin\cstrike-online.exe"="C:\Program Files\Nexon\Counter-Strike Online\Bin\cstrike-online.exe:*:Enabled:Counter-Strike Online"
"C:\Program Files\Tunngle\TnglCtrl.exe"="C:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service"
"C:\Program Files\Tunngle\Tunngle.exe"="C:\Program Files\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client"
"C:\Program Files\Steam\steamapps\common\alien swarm\srcds.exe"="C:\Program Files\Steam\steamapps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server"
"C:\Program Files\Steam\steamapps\common\alien swarm\swarm.exe"="C:\Program Files\Steam\steamapps\common\alien swarm\swarm.exe:*:Enabled:Alien Swarm"
"C:\Program Files\Steam\steamapps\titanus008\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\titanus008\counter-strike source\hl2.exe:*:Enabled:Counter-Strike: Source"
"C:\Program Files\Steam\steamapps\common\alien swarm\bin\SDKLauncher.exe"="C:\Program Files\Steam\steamapps\common\alien swarm\bin\SDKLauncher.exe:*:Enabled:Alien Swarm - SDK"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======File associations======

.reg - open - "regedit.exe" "%1"

======List of files/folders created in the last 1 months======

2010-08-17 21:22:04 ----D---- C:\Program Files\trend micro
2010-08-17 21:22:03 ----D---- C:\rsit
2010-08-17 21:17:31 ----D---- C:\Program Files\DeepSilver
2010-08-17 21:17:30 ----D---- C:\nfs_uc
2010-08-17 21:17:30 ----D---- C:\Neurohunter
2010-08-17 21:17:30 ----D---- C:\Colin McRae Rally 3
2010-08-17 21:17:30 ----D---- C:\b
2010-08-16 10:19:19 ----D---- C:\Program Files\SuperTux
2010-08-15 18:24:14 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\Blender Foundation
2010-08-15 18:24:08 ----D---- C:\Program Files\Blender Foundation
2010-08-14 23:28:19 ----D---- C:\Program Files\Quake
2010-08-14 20:44:02 ----D---- C:\Program Files\Deep Silver
2010-08-14 19:58:56 ----D---- C:\Stalker - Stín černobylu
2010-08-14 15:33:57 ----D---- C:\Program Files\Duke3D
2010-08-13 10:49:42 ----HDC---- C:\WINDOWS.2\$NtUninstallKB982214$
2010-08-13 10:49:34 ----HDC---- C:\WINDOWS.2\$NtUninstallKB2115168$
2010-08-13 10:46:46 ----HDC---- C:\WINDOWS.2\$NtUninstallKB981852$
2010-08-13 10:46:39 ----HDC---- C:\WINDOWS.2\$NtUninstallKB2079403$
2010-08-13 10:46:33 ----HDC---- C:\WINDOWS.2\$NtUninstallKB2160329$
2010-08-13 10:46:27 ----HDC---- C:\WINDOWS.2\$NtUninstallKB980436$
2010-08-13 10:42:50 ----HDC---- C:\WINDOWS.2\$NtUninstallKB981997$
2010-08-13 10:42:37 ----HDC---- C:\WINDOWS.2\$NtUninstallKB982665$
2010-08-12 20:24:46 ----D---- C:\Hotspot Shield
2010-08-11 18:58:58 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\InstallShield Installation Information
2010-08-11 18:45:15 ----D---- C:\gta-vc
2010-08-11 15:01:30 ----D---- C:\Program Files\Disney Interactive Studios
2010-08-10 19:07:33 ----D---- C:\G-Force
2010-08-10 00:38:37 ----D---- C:\Program Files\Defcon
2010-08-09 18:37:22 ----D---- C:\Program Files\dead mans hand
2010-08-07 20:46:32 ----A---- C:\WINDOWS.2\system32\lsdelete.exe
2010-08-07 19:58:36 ----D---- C:\Documents and Settings\All Users.WINDOWS.2\Data aplikací\id Software
2010-08-07 18:28:34 ----A---- C:\WINDOWS.2\system32\drivers\Lbd.sys
2010-08-07 18:28:25 ----A---- C:\WINDOWS.2\system32\drivers\SBREDrv.sys
2010-08-07 18:12:15 ----HDC---- C:\Documents and Settings\All Users.WINDOWS.2\Data aplikací\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-08-07 18:10:57 ----D---- C:\Program Files\Lavasoft
2010-08-04 12:33:06 ----A---- C:\WINDOWS.2\system32\MRT.exe
2010-08-04 12:09:47 ----A---- C:\WINDOWS.2\imsins.BAK
2010-08-04 12:09:30 ----HDC---- C:\WINDOWS.2\$NtUninstallKB2286198$
2010-08-02 19:58:33 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\FMZilla
2010-08-02 19:52:40 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\ProgSense
2010-08-02 19:52:35 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\GrabPro
2010-08-02 19:52:31 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\Orbit
2010-08-02 13:42:38 ----D---- C:\Program Files\DOSBox-0.72
2010-08-01 23:03:04 ----D---- C:\OldGames
2010-07-31 19:03:54 ----D---- C:\bestgames
2010-07-31 12:44:09 ----D---- C:\Program Files\Tunngle
2010-07-30 10:56:06 ----D---- C:\Program Files\Free Window Registry Repair
2010-07-28 18:20:10 ----D---- C:\Documents and Settings\All Users.WINDOWS.2\Data aplikací\McAfee
2010-07-28 18:19:53 ----D---- C:\Documents and Settings\All Users.WINDOWS.2\Data aplikací\NOS
2010-07-27 12:09:21 ----A---- C:\WINDOWS.2\system32\chtbrkr.dll
2010-07-27 12:09:21 ----A---- C:\WINDOWS.2\system32\chsbrkr.dll
2010-07-27 12:09:20 ----A---- C:\WINDOWS.2\system32\korwbrkr.dll
2010-07-27 12:09:19 ----A---- C:\WINDOWS.2\system32\msir3jp.dll
2010-07-27 12:09:05 ----A---- C:\WINDOWS.2\system32\kbd101a.dll
2010-07-27 12:08:56 ----A---- C:\WINDOWS.2\system32\kbdnecNT.dll
2010-07-27 12:08:56 ----A---- C:\WINDOWS.2\system32\kbdnecAT.dll
2010-07-27 12:08:56 ----A---- C:\WINDOWS.2\system32\kbdnec95.dll
2010-07-27 12:08:36 ----A---- C:\WINDOWS.2\system32\c_is2022.dll
2010-07-27 12:07:03 ----D---- C:\Program Files\Nexon
2010-07-27 11:27:27 ----D---- C:\Program Files\Valve
2010-07-25 16:35:19 ----D---- C:\NeedForspeedundercover
2010-07-24 12:54:55 ----D---- C:\NFSUC
2010-07-24 12:54:03 ----D---- C:\Program Files\Archiving
2010-07-23 11:32:29 ----D---- C:\Program Files\GTASA
2010-07-20 10:14:04 ----RA---- C:\WINDOWS.2\system32\tmp400.tmp

======List of files/folders modified in the last 1 months======

2010-08-17 21:22:12 ----D---- C:\WINDOWS.2\Prefetch
2010-08-17 21:22:05 ----D---- C:\WINDOWS.2\Temp
2010-08-17 21:22:04 ----D---- C:\Program Files
2010-08-17 21:20:14 ----D---- C:\Program Files\Steam
2010-08-17 21:19:30 ----D---- C:\WINDOWS.2\system32\inetsrv
2010-08-17 21:17:58 ----D---- C:\WINDOWS.2\system32\config
2010-08-17 21:17:41 ----D---- C:\WINDOWS.2\system32\wbem
2010-08-17 21:17:40 ----D---- C:\WINDOWS.2\Registration
2010-08-17 21:17:25 ----D---- C:\Program Files\MPlayer for Windows
2010-08-17 21:16:36 ----A---- C:\WINDOWS.2\SchedLgU.Txt
2010-08-17 21:16:28 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\Skype
2010-08-17 21:06:21 ----D---- C:\WINDOWS.2\system32
2010-08-17 21:00:46 ----SD---- C:\WINDOWS.2\Tasks
2010-08-17 16:19:57 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\skypePM
2010-08-17 16:19:46 ----D---- C:\WINDOWS.2\system32\CatRoot2
2010-08-16 15:17:38 ----AD---- C:\Documents and Settings\All Users.WINDOWS.2\Data aplikací\TEMP
2010-08-15 22:41:23 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\Real
2010-08-15 12:54:27 ----D---- C:\WINDOWS.2\Minidump
2010-08-15 12:54:27 ----D---- C:\WINDOWS.2
2010-08-15 10:02:21 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-14 21:03:29 ----D---- C:\WINDOWS.2\system32\drivers
2010-08-14 16:48:17 ----D---- C:\Fear2
2010-08-14 11:44:18 ----D---- C:\Program Files\Mozilla Firefox
2010-08-13 11:15:29 ----D---- C:\WINDOWS.2\Microsoft.NET
2010-08-13 11:15:23 ----RSD---- C:\WINDOWS.2\assembly
2010-08-13 11:07:09 ----D---- C:\Config.Msi
2010-08-13 10:50:17 ----HD---- C:\WINDOWS.2\inf
2010-08-13 10:50:11 ----D---- C:\WINDOWS.2\system32\dllcache
2010-08-13 10:50:08 ----D---- C:\WINDOWS.2\system32\cs-cz
2010-08-13 10:50:07 ----D---- C:\Program Files\Internet Explorer
2010-08-13 10:49:41 ----HD---- C:\WINDOWS.2\$hf_mig$
2010-08-13 10:49:23 ----SHD---- C:\WINDOWS.2\Installer
2010-08-13 10:49:15 ----A---- C:\WINDOWS.2\system32\PerfStringBackup.INI
2010-08-13 10:48:54 ----D---- C:\WINDOWS.2\WinSxS
2010-08-13 10:42:52 ----D---- C:\Program Files\Movie Maker
2010-08-11 18:58:53 ----D---- C:\Program Files\Rockstar Games
2010-08-11 15:06:42 ----D---- C:\WINDOWS.2\system32\DirectX
2010-08-10 19:11:52 ----A---- C:\WINDOWS.2\system32\PnkBstrB.exe
2010-08-09 08:34:27 ----RSD---- C:\WINDOWS.2\Fonts
2010-08-08 23:57:51 ----D---- C:\Program Files\Kamosova hnedka
2010-08-08 22:22:52 ----D---- C:\Program Files\Windows Sidebar
2010-08-07 21:26:35 ----D---- C:\Program Files\Warsow 0.5
2010-08-07 19:58:44 ----A---- C:\WINDOWS.2\system32\PnkBstrA.exe
2010-08-07 19:58:43 ----A---- C:\WINDOWS.2\system32\pbsvc.exe
2010-08-07 18:28:34 ----DC---- C:\WINDOWS.2\system32\DRVSTORE
2010-08-07 18:10:56 ----D---- C:\Documents and Settings\All Users.WINDOWS.2\Data aplikací\Lavasoft
2010-08-07 17:59:18 ----A---- C:\WINDOWS.2\NeroDigital.ini
2010-08-04 12:33:07 ----D---- C:\WINDOWS.2\Debug
2010-08-03 14:14:43 ----D---- C:\Program Files\YouTube Downloader
2010-08-01 18:22:04 ----D---- C:\Program Files\EA Games
2010-07-31 17:09:01 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\Publish Providers
2010-07-31 12:44:35 ----D---- C:\Documents and Settings\milan Bezdek\Data aplikací\Tunngle
2010-07-28 18:27:58 ----D---- C:\Fraps
2010-07-28 17:02:12 ----D---- C:\Program Files\NewBlue
2010-07-28 16:53:50 ----D---- C:\Program Files\Doom2
2010-07-27 12:09:10 ----D---- C:\WINDOWS.2\Help
2010-07-27 08:30:31 ----A---- C:\WINDOWS.2\system32\shell32.dll
2010-07-26 09:12:29 ----A---- C:\WINDOWS.2\system.ini
2010-07-20 10:15:11 ----D---- C:\Program Files\DebugMode
2010-07-20 10:14:40 ----D---- C:\Program Files\Image-Line
2010-07-18 14:28:06 ----A---- C:\WINDOWS.2\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS.2\system32\DRIVERS\agp440.sys [2004-08-04 42368]
R0 giveio;giveio; C:\WINDOWS.2\system32\giveio.sys [1996-04-03 5248 begin_of_the_skype_highlighting              1996-04-03 5248      end_of_the_skype_highlighting begin_of_the_skype_highlighting              1996-04-03 5248      end_of_the_skype_highlighting]
R0 Lbd;Lbd; C:\WINDOWS.2\system32\DRIVERS\Lbd.sys [2010-07-12 64288]
R0 sfdrv01;StarForce Protection Environment Driver (version 1.x); C:\WINDOWS.2\system32\drivers\sfdrv01.sys [2006-05-10 51200]
R0 sfhlp02;StarForce Protection Helper Driver (version 2.x); C:\WINDOWS.2\system32\drivers\sfhlp02.sys [2006-05-10 6656]
R0 sfsync04;StarForce Protection Synchronization Driver (version 4.x); C:\WINDOWS.2\system32\drivers\sfsync04.sys [2006-05-10 52224]
R0 speedfan;speedfan; C:\WINDOWS.2\system32\speedfan.sys [2006-09-24 5248]
R0 sptd;sptd; C:\WINDOWS.2\System32\Drivers\sptd.sys [2009-12-24 691696]
R1 easdrv;easdrv; C:\WINDOWS.2\system32\DRIVERS\easdrv.sys [2007-12-21 30216]
R1 epfwtdi;epfwtdi; C:\WINDOWS.2\system32\DRIVERS\epfwtdi.sys [2007-12-21 53768]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS.2\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R2 eamon;EAMON; C:\WINDOWS.2\system32\DRIVERS\eamon.sys [2007-12-21 39944]
R2 epfw;epfw; C:\WINDOWS.2\system32\DRIVERS\epfw.sys [2007-12-21 71176]
R3 ati2mtag;ati2mtag; C:\WINDOWS.2\system32\DRIVERS\ati2mtag.sys [2008-01-10 2846720]
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS.2\system32\drivers\cmuda.sys [2006-06-26 1372992]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS.2\system32\DRIVERS\Epfwndis.sys [2007-12-21 30728]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS.2\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS.2\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS.2\system32\DRIVERS\Rtnicxp.sys [2007-07-12 96384]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle); C:\WINDOWS.2\system32\DRIVERS\tap0901t.sys [2009-09-16 27136]
R3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS.2\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS.2\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\WINDOWS.2\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S3 aysgy1wf;aysgy1wf; C:\WINDOWS.2\system32\drivers\aysgy1wf.sys []
S3 EagleNT;EagleNT; \??\C:\WINDOWS.2\system32\drivers\EagleNT.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\DOCUME~1\MILANB~2\LOCALS~1\Temp\CZN136.tmp []
S3 Lavasoft Kernexplorer;Lavasoft helper driver; \??\C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys []
S3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\WINDOWS.2\system32\drivers\ScreamingBAudio.sys [2009-12-01 34384]
S3 taphss;Anchorfree HSS Adapter; C:\WINDOWS.2\system32\DRIVERS\taphss.sys [2010-06-23 32768]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS.2\system32\DRIVERS\WudfPf.sys [2008-03-27 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS.2\system32\DRIVERS\wudfrd.sys [2008-03-27 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS.2\system32\Ati2evxx.exe [2008-01-10 512000]
R2 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2010-01-23 72704]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 IISADMIN;Správa služby IIS; C:\WINDOWS.2\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-11-02 153376]
R2 mi-raysat_3dsmax8;RaySat_3dsmax8 Server; C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe [2005-09-21 65536]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS.2\system32\PnkBstrA.exe [2010-08-07 75064]
R2 SMTPSVC;Simple Mail Transport Protocol (SMTP); C:\WINDOWS.2\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
R2 TunngleService;TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [2010-07-06 716024]
R2 W3SVC;Publikování na webu; C:\WINDOWS.2\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
S2 ATI Smart;ATI Smart; C:\WINDOWS.2\system32\ati2sgag.exe [2008-01-09 593920]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2010-08-14 1355416]
S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\WINDOWS.2\system32\sfrem01.exe [2006-05-10 353912]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS.2\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS.2\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2007-12-21 19200]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-11-13 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS.2\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 idsvc;Windows CardSpace; c:\WINDOWS.2\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS.2\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS.2\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------

Edit:Sry Musel jsem udělat Bod obnovy protože mi to blokovalo stahování souborů .exe (Ten tomswithhair mam furt)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: tombirdswithhair.com Problém

#4 Příspěvek od Rudy »

Dejte log z ComboFix.
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode, pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k nezadoucim kolizim s rezidentem antispyware
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět