
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Virus
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Virus
Dobrý den
Dostal jse mi do PC asi trojsky kuň New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost) . CHtěl jsem vymazat jeden .exe soubor ale nešel .no tak jsem ho radči otestoval AvG 2011 a on našel nějaky velmi zavažny nový virus . Už jsem viry mazal tak jsem ten vir nechal AvGéčkem smazat . Sputil ComboFix. Uložil log. Zapnul RSIT . Uložil log . Udělal rychlá sken MBAM (nic nenašel) . Problem je že ten soubot pořád nejde vymazat ...
ComboFix:
ComboFix 10-10-12.03 - Uživatel 14.10.2010 20:16:21.8.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1464 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\SET5D.tmp
c:\program files\Internet Explorer\SET5E.tmp
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-14 do 2010-10-14 )))))))))))))))))))))))))))))))
.
2010-10-14 17:00 . 2010-10-14 17:00 -------- d-----w- c:\windows\LastGood
2010-10-14 14:12 . 2010-09-10 05:52 184320 ----a-w- c:\windows\system32\SET59.tmp
2010-10-14 14:12 . 2010-09-10 05:52 602112 ----a-w- c:\windows\system32\SET54.tmp
2010-10-14 14:12 . 2010-09-10 05:52 55296 ----a-w- c:\windows\system32\SET53.tmp
2010-10-14 14:12 . 2010-09-10 05:52 1986560 ----a-w- c:\windows\system32\SET58.tmp
2010-10-14 14:12 . 2010-09-10 05:52 5957120 ----a-w- c:\windows\system32\SET52.tmp
2010-10-14 14:12 . 2010-09-10 05:52 916480 ----a-w- c:\windows\system32\SET4D.tmp
2010-10-14 14:12 . 2010-09-10 05:52 1210880 ----a-w- c:\windows\system32\SET4E.tmp
2010-10-14 14:12 . 2010-09-10 05:52 11080192 ----a-w- c:\windows\system32\SET5A.tmp
2010-10-14 14:12 . 2010-08-16 08:45 590848 ----a-w- c:\windows\system32\SET43.tmp
2010-10-06 17:10 . 2010-10-06 17:10 -------- d-----w- C:\$AVG
2010-10-06 13:17 . 2010-10-06 13:17 -------- d-----w- c:\documents and settings\Uživatel\Data aplikací\AVG10
2010-10-06 13:16 . 2010-10-06 13:16 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-10-06 13:16 . 2010-10-06 13:16 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2010-10-06 13:16 . 2010-10-06 13:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG Security Toolbar
2010-10-06 13:15 . 2010-10-14 12:55 -------- d-----w- c:\windows\system32\drivers\AVG
2010-10-06 13:15 . 2010-10-06 13:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG10
2010-10-06 13:09 . 2010-10-06 13:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2010-09-22 16:10 . 2010-09-22 16:10 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-09-18 10:23 . 2010-09-18 10:23 974848 ----a-w- c:\windows\system32\SET9D.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
------- Sigcheck -------
[-] 2009-08-10 18:22 . C3A2915C71AE6F225EB906C25CCD29B5 . 24064 . . [1.0.0.5] . . c:\windows\system32\dllcache\ctfmon.exe
[-] 2009-08-10 18:22 . C3A2915C71AE6F225EB906C25CCD29B5 . 24064 . . [1.0.0.5] . . c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-10-11_12.52.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 12:00 . 2010-09-10 05:52 66560 c:\windows\system32\mshtmled.dll
- 2008-04-14 12:00 . 2009-03-08 02:31 66560 c:\windows\system32\mshtmled.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 43520 c:\windows\system32\licmgr10.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 25600 c:\windows\system32\jsproxy.dll
- 2009-06-25 11:59 . 2010-06-24 12:27 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-06-25 11:59 . 2010-09-10 05:52 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2008-04-14 12:00 . 2009-03-08 02:31 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-07-29 06:57 . 2010-09-10 05:52 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2009-07-29 06:57 . 2010-06-24 12:27 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 12800 c:\windows\ie8updates\KB2360131-IE8\xpshims.dll
+ 2010-10-14 17:07 . 2009-03-08 02:31 66560 c:\windows\ie8updates\KB2360131-IE8\mshtmled.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 55296 c:\windows\ie8updates\KB2360131-IE8\msfeedsbs.dll
+ 2010-10-14 17:07 . 2009-03-08 02:34 43008 c:\windows\ie8updates\KB2360131-IE8\licmgr10.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 25600 c:\windows\ie8updates\KB2360131-IE8\jsproxy.dll
- 2008-04-14 12:00 . 2009-10-15 16:32 119808 c:\windows\system32\t2embed.dll
+ 2008-04-14 12:00 . 2010-08-27 08:03 119808 c:\windows\system32\t2embed.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 206848 c:\windows\system32\occache.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\mfc42.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\mfc40u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\mfc40.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 387584 c:\windows\system32\iedkcs32.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 387584 c:\windows\system32\iedkcs32.dll
+ 2008-04-14 12:00 . 2010-08-26 12:22 173056 c:\windows\system32\ie4uinit.exe
- 2008-04-14 12:00 . 2010-06-23 12:08 173056 c:\windows\system32\ie4uinit.exe
+ 2009-06-25 09:51 . 2010-07-16 11:58 219136 c:\windows\system32\dllcache\wordpad.exe
+ 2008-04-14 12:00 . 2010-09-10 05:52 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 12:00 . 2009-10-15 16:32 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2010-08-27 08:03 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2010-08-16 08:45 590848 c:\windows\system32\dllcache\rpcrt4.dll
- 2008-04-14 12:00 . 2010-07-22 15:46 590848 c:\windows\system32\dllcache\rpcrt4.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 611840 c:\windows\system32\dllcache\mstime.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-07-29 06:57 . 2010-09-10 05:52 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-04-14 12:00 . 2010-09-18 10:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\dllcache\mfc42.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\dllcache\mfc40.dll
+ 2009-06-25 11:59 . 2010-09-10 05:52 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-06-25 11:59 . 2010-06-24 12:27 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 184320 c:\windows\system32\dllcache\iepeers.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-11 06:00 . 2010-09-10 05:52 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2010-06-11 06:00 . 2010-06-24 12:27 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 12:00 . 2010-08-26 12:22 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 12:00 . 2010-06-23 12:08 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 12:00 . 2010-09-01 11:52 285824 c:\windows\system32\dllcache\atmfd.dll
+ 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\comctl32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\comctl32.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 916480 c:\windows\ie8updates\KB2360131-IE8\wininet.dll
+ 2010-10-14 17:07 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2360131-IE8\spuninst\updspapi.dll
+ 2010-10-14 17:07 . 2010-02-22 14:20 233848 c:\windows\ie8updates\KB2360131-IE8\spuninst\spuninst.exe
+ 2010-10-14 17:07 . 2010-06-24 12:27 206848 c:\windows\ie8updates\KB2360131-IE8\occache.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 611840 c:\windows\ie8updates\KB2360131-IE8\mstime.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 599040 c:\windows\ie8updates\KB2360131-IE8\msfeeds.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 247808 c:\windows\ie8updates\KB2360131-IE8\ieproxy.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 184320 c:\windows\ie8updates\KB2360131-IE8\iepeers.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 743424 c:\windows\ie8updates\KB2360131-IE8\iedvtool.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 387584 c:\windows\ie8updates\KB2360131-IE8\iedkcs32.dll
+ 2010-10-14 17:07 . 2010-06-23 12:08 173056 c:\windows\ie8updates\KB2360131-IE8\ie4uinit.exe
+ 2010-10-14 14:13 . 2010-08-23 16:12 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
+ 2008-04-14 12:00 . 2010-08-26 15:16 4886528 c:\windows\system32\wmp.dll
+ 2008-04-14 12:00 . 2010-09-01 07:57 1852800 c:\windows\system32\win32k.sys
+ 2008-04-14 12:00 . 2010-08-26 15:16 4886528 c:\windows\system32\dllcache\wmp.dll
+ 2008-04-14 12:00 . 2010-09-01 07:57 1852800 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 12:00 . 2010-09-10 05:52 1210880 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2010-07-16 12:00 1287680 c:\windows\system32\dllcache\ole32.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 5957120 c:\windows\system32\dllcache\mshtml.dll
- 2009-06-25 11:59 . 2010-06-24 12:27 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2009-06-25 11:59 . 2010-09-10 05:52 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 1210368 c:\windows\ie8updates\KB2360131-IE8\urlmon.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 5951488 c:\windows\ie8updates\KB2360131-IE8\mshtml.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 1986560 c:\windows\ie8updates\KB2360131-IE8\iertutil.dll
+ 2009-06-25 11:58 . 2010-10-14 17:02 35385288 c:\windows\system32\MRT.exe
+ 2009-06-25 11:59 . 2010-09-10 05:52 11080192 c:\windows\system32\dllcache\ieframe.dll
+ 2010-10-14 17:07 . 2010-06-24 15:57 11077120 c:\windows\ie8updates\KB2360131-IE8\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-08-27 13:25 2565448 ----a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2010-08-27 2565448]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2010-08-27 2565448]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2010-09-15 2745696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-08-10 24064]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2009-08-10 18:22 24064 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 20:17 52256 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
2007-02-26 08:40 249856 ----a-w- c:\program files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-01-24 10:32 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-02-27 11:03 570664 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-14 19:01 71216 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-01-21 10:17 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-07-02 10:26 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate1c9faffc1c539a5"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"\\\\macek\\storage\\Instalace\\!predinstalace\\Nero CZ a Power DVD\\CDS\\Nero\\Installation\\SetupX.exe"=
"c:\\Program Files\\SEGA\\SEGA Rally\\SEGA Rally.exe"=
"c:\\Program Files\\SEGA\\SEGA Rally\\SEGA Rally_SSE1.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\ProgramData\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Counter-Strike Source\\hl2.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13.9.2010 16:27 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7.9.2010 3:48 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7.9.2010 3:48 249424]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7.9.2010 3:49 298448]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [10.9.2010 1:45 265400]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [19.8.2010 21:42 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [19.8.2010 21:42 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [19.8.2010 21:42 26192]
S2 gupdate1c9faffc1c539a5;Služba Google Update (gupdate1c9faffc1c539a5);c:\program files\Google\Update\GoogleUpdate.exe [2.7.2009 12:27 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [6.10.2010 15:16 488776]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [3.9.2010 10:35 6104144]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\plugins\UI\safedrv.sys --> c:\program files\Garena\plugins\UI\safedrv.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24.8.2009 14:19 721904]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 10:30 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 10:27]
2010-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 10:27]
2010-10-13 c:\windows\Tasks\User_Feed_Synchronization-{A2061C48-FAE3-4493-BA3C-D293A9690810}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://puvodni.centrum.cz/
IE: &Download All by FlashGet - c:\program files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
IE: &Download by FlashGet - c:\program files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
IE: Crawler Search - tbr:iemenu
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\bmnurbgq.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.crawler.com/homepage.aspx?tbid=60347
FF - prefs.js: keyword.URL - hxxp://www.crawler.com/search/dispatcher.aspx? ... 60347&qkw=
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-10-14 20:21:33
ComboFix-quarantined-files.txt 2010-10-14 18:21
ComboFix2.txt 2010-10-11 12:53
ComboFix3.txt 2010-10-09 09:40
Před spuštěním: Volných bajtů: 47 842 742 272
Po spuštění: Volných bajtů: 47 965 372 416
- - End Of File - - AEEC6BEAEDFC4FC092B607FCD912E866
RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Uživatel at 2010-10-14 20:24:25
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 46 GB (31%) free of 150 GB
Total RAM: 2047 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:24:33, on 14.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Documents and Settings\Uživatel\Plocha\pv\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://puvodni.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download All by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
O8 - Extra context menu item: &Download by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Služba Google Update (gupdate1c9faffc1c539a5) (gupdate1c9faffc1c539a5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 7801 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A2061C48-FAE3-4493-BA3C-D293A9690810}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-09-02 1241448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG10\avgssie.dll [2010-09-16 2890592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-08-27 2565448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-09-13 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-07-02 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-09-13 2403392]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-09-02 1241448]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-08-27 2565448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"=C:\Program Files\AVG\AVG10\avgtray.exe [2010-09-15 2745696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2009-08-10 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe [2007-02-26 249856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-01-24 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2008-02-27 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-07-02 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3
"IDriverT"=3
"gusvc"=2
"gupdate1c9faffc1c539a5"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-07-08 143360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"\\macek\storage\Instalace\!predinstalace\Nero CZ a Power DVD\CDS\Nero\Installation\SetupX.exe"="\\macek\storage\Instalace\!predinstalace\Nero CZ a Power DVD\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\SEGA\SEGA Rally\SEGA Rally.exe"="C:\Program Files\SEGA\SEGA Rally\SEGA Rally.exe:*:Enabled:SEGA Rally"
"C:\Program Files\SEGA\SEGA Rally\SEGA Rally_SSE1.exe"="C:\Program Files\SEGA\SEGA Rally\SEGA Rally_SSE1.exe:*:Enabled:SEGA Rally"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\ProgramData\World of Warcraft\Repair.exe"="C:\ProgramData\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Counter-Strike Source\hl2.exe"="C:\Program Files\Counter-Strike Source\hl2.exe:*:Disabled:hl2"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Disabled:Garena"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG10\avgdiagex.exe"="C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostika 2011"
"C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Obecná kontrola pošty"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-10-14 20:23:06 ----SHD---- C:\RECYCLER
2010-10-14 20:21:35 ----D---- C:\WINDOWS\temp
2010-10-14 20:21:34 ----A---- C:\ComboFix.txt
2010-10-14 20:14:54 ----D---- C:\ComboFix
2010-10-14 19:11:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-10-14 19:10:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-10-14 19:10:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-10-14 19:09:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-10-14 19:09:17 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-10-14 19:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-10-14 19:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-10-14 19:00:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-10-14 19:00:32 ----D---- C:\WINDOWS\LastGood
2010-10-14 16:12:37 ----A---- C:\WINDOWS\system32\SET59.tmp
2010-10-14 16:12:36 ----A---- C:\WINDOWS\system32\SET58.tmp
2010-10-14 16:12:36 ----A---- C:\WINDOWS\system32\SET54.tmp
2010-10-14 16:12:36 ----A---- C:\WINDOWS\system32\SET53.tmp
2010-10-14 16:12:35 ----A---- C:\WINDOWS\system32\SET52.tmp
2010-10-14 16:12:33 ----A---- C:\WINDOWS\system32\SET4E.tmp
2010-10-14 16:12:33 ----A---- C:\WINDOWS\system32\SET4D.tmp
2010-10-14 16:12:31 ----A---- C:\WINDOWS\system32\SET5A.tmp
2010-10-14 16:12:05 ----A---- C:\WINDOWS\system32\SET43.tmp
2010-10-11 14:47:06 ----A---- C:\WINDOWS\zip.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\SWSC.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\SWREG.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\sed.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\PEV.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\NIRCMD.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\MBR.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\grep.exe
2010-10-11 14:45:25 ----D---- C:\Qoobox
2010-10-10 16:45:21 ----D---- C:\Config.Msi
2010-10-06 19:10:32 ----D---- C:\$AVG
2010-10-06 15:17:23 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\AVG10
2010-10-06 15:16:25 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-10-06 15:16:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG Security Toolbar
2010-10-06 15:15:41 ----D---- C:\WINDOWS\system32\drivers\AVG
2010-10-06 15:15:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG10
2010-10-06 15:09:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2010-09-29 08:48:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-09-18 12:23:38 ----A---- C:\WINDOWS\system32\SET9D.tmp
2010-09-15 23:33:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-15 23:33:32 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-15 23:33:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-15 23:33:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-15 23:33:19 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-15 23:33:14 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-15 23:31:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
======List of files/folders modified in the last 1 months======
2010-10-14 20:24:33 ----D---- C:\Program Files\trend micro
2010-10-14 20:22:36 ----D---- C:\WINDOWS\system32
2010-10-14 20:21:35 ----D---- C:\WINDOWS
2010-10-14 20:19:55 ----A---- C:\WINDOWS\system.ini
2010-10-14 20:19:48 ----D---- C:\WINDOWS\system32\drivers\etc
2010-10-14 20:19:33 ----D---- C:\Program Files\Internet Explorer
2010-10-14 20:18:23 ----D---- C:\WINDOWS\system32\drivers
2010-10-14 20:18:23 ----D---- C:\WINDOWS\AppPatch
2010-10-14 20:18:22 ----D---- C:\Program Files\Common Files
2010-10-14 20:16:04 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-14 20:15:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-14 20:10:02 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Skype
2010-10-14 20:05:18 ----D---- C:\Program Files\Valve
2010-10-14 19:45:59 ----RD---- C:\Program Files
2010-10-14 19:11:40 ----HD---- C:\WINDOWS\inf
2010-10-14 19:11:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-10-14 19:10:59 ----HD---- C:\WINDOWS\$hf_mig$
2010-10-14 19:10:56 ----A---- C:\WINDOWS\imsins.BAK
2010-10-14 19:10:20 ----D---- C:\WINDOWS\Prefetch
2010-10-14 19:10:11 ----D---- C:\WINDOWS\WinSxS
2010-10-14 19:07:46 ----D---- C:\WINDOWS\ie8updates
2010-10-14 19:02:28 ----A---- C:\WINDOWS\system32\MRT.exe
2010-10-14 17:56:35 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\skypePM
2010-10-11 14:46:52 ----D---- C:\WINDOWS\ERDNT
2010-10-11 14:38:37 ----SHD---- C:\WINDOWS\Installer
2010-10-10 16:46:08 ----D---- C:\Program Files\Common Files\Adobe
2010-10-10 16:46:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-10-09 14:43:15 ----SHD---- C:\System Volume Information
2010-10-09 14:43:15 ----D---- C:\WINDOWS\system32\Restore
2010-10-08 12:08:54 ----RSD---- C:\WINDOWS\assembly
2010-10-08 12:08:13 ----D---- C:\WINDOWS\Microsoft.NET
2010-10-07 08:34:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-10-06 15:15:24 ----D---- C:\Program Files\AVG
2010-10-06 14:43:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-10-04 02:10:55 ----D---- C:\Program Files\Mozilla Firefox
2010-10-02 14:34:02 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\gtk-2.0
2010-09-30 19:12:15 ----D---- C:\Program Files\Warcraft III
2010-09-30 18:20:05 ----D---- C:\Program Files\Garena
2010-09-26 11:56:45 ----D---- C:\Program Files\Counter-Strike Source
2010-09-25 20:49:45 ----D---- C:\Program Files\Google
2010-09-24 19:53:37 ----A---- C:\WINDOWS\NeroDigital.ini
2010-09-22 19:54:32 ----D---- C:\WINDOWS\Network Diagnostic
2010-09-18 08:53:37 ----A---- C:\WINDOWS\system32\mfc42.dll
2010-09-18 08:53:37 ----A---- C:\WINDOWS\system32\mfc40u.dll
2010-09-18 08:53:37 ----A---- C:\WINDOWS\system32\mfc40.dll
2010-09-17 21:02:10 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\ICQ
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 viamraid;viamraid; C:\WINDOWS\system32\drivers\viamraid.sys [2009-06-25 104064]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2009-06-25 9216]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-09-07 298448]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-07-08 3257344]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-05-20 93696]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192]
R3 catchme;catchme; \??\C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\catchme.sys []
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-04-23 818496]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ctljystk;Game port pro zařízení Creative SB Live!; C:\WINDOWS\system32\DRIVERS\ctljystk.sys [2001-08-17 3712]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\plugins\UI\safedrv.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\mbr.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-08-24 721904]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-07-08 573440]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-09-03 6104144]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe [2010-09-10 265400]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-01-24 73728]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 gupdate1c9faffc1c539a5;Služba Google Update (gupdate1c9faffc1c539a5); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-07-02 133104]
S2 spupdsvc;Windows Service Pack Installer update service; C:\WINDOWS\system32\spupdsvc.exe [2009-01-07 26144]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-08-27 488776]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-02 190448]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-09-17 800040]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
-----------------EOF-----------------
Dostal jse mi do PC asi trojsky kuň New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost) . CHtěl jsem vymazat jeden .exe soubor ale nešel .no tak jsem ho radči otestoval AvG 2011 a on našel nějaky velmi zavažny nový virus . Už jsem viry mazal tak jsem ten vir nechal AvGéčkem smazat . Sputil ComboFix. Uložil log. Zapnul RSIT . Uložil log . Udělal rychlá sken MBAM (nic nenašel) . Problem je že ten soubot pořád nejde vymazat ...
ComboFix:
ComboFix 10-10-12.03 - Uživatel 14.10.2010 20:16:21.8.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.2047.1464 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\SET5D.tmp
c:\program files\Internet Explorer\SET5E.tmp
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-14 do 2010-10-14 )))))))))))))))))))))))))))))))
.
2010-10-14 17:00 . 2010-10-14 17:00 -------- d-----w- c:\windows\LastGood
2010-10-14 14:12 . 2010-09-10 05:52 184320 ----a-w- c:\windows\system32\SET59.tmp
2010-10-14 14:12 . 2010-09-10 05:52 602112 ----a-w- c:\windows\system32\SET54.tmp
2010-10-14 14:12 . 2010-09-10 05:52 55296 ----a-w- c:\windows\system32\SET53.tmp
2010-10-14 14:12 . 2010-09-10 05:52 1986560 ----a-w- c:\windows\system32\SET58.tmp
2010-10-14 14:12 . 2010-09-10 05:52 5957120 ----a-w- c:\windows\system32\SET52.tmp
2010-10-14 14:12 . 2010-09-10 05:52 916480 ----a-w- c:\windows\system32\SET4D.tmp
2010-10-14 14:12 . 2010-09-10 05:52 1210880 ----a-w- c:\windows\system32\SET4E.tmp
2010-10-14 14:12 . 2010-09-10 05:52 11080192 ----a-w- c:\windows\system32\SET5A.tmp
2010-10-14 14:12 . 2010-08-16 08:45 590848 ----a-w- c:\windows\system32\SET43.tmp
2010-10-06 17:10 . 2010-10-06 17:10 -------- d-----w- C:\$AVG
2010-10-06 13:17 . 2010-10-06 13:17 -------- d-----w- c:\documents and settings\Uživatel\Data aplikací\AVG10
2010-10-06 13:16 . 2010-10-06 13:16 -------- d-----w- c:\documents and settings\LocalService\Plocha
2010-10-06 13:16 . 2010-10-06 13:16 -------- d--h--w- c:\documents and settings\All Users\Data aplikací\Common Files
2010-10-06 13:16 . 2010-10-06 13:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG Security Toolbar
2010-10-06 13:15 . 2010-10-14 12:55 -------- d-----w- c:\windows\system32\drivers\AVG
2010-10-06 13:15 . 2010-10-06 13:16 -------- d-----w- c:\documents and settings\All Users\Data aplikací\AVG10
2010-10-06 13:09 . 2010-10-06 13:15 -------- d-----w- c:\documents and settings\All Users\Data aplikací\MFAData
2010-09-22 16:10 . 2010-09-22 16:10 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-09-18 10:23 . 2010-09-18 10:23 974848 ----a-w- c:\windows\system32\SET9D.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
------- Sigcheck -------
[-] 2009-08-10 18:22 . C3A2915C71AE6F225EB906C25CCD29B5 . 24064 . . [1.0.0.5] . . c:\windows\system32\dllcache\ctfmon.exe
[-] 2009-08-10 18:22 . C3A2915C71AE6F225EB906C25CCD29B5 . 24064 . . [1.0.0.5] . . c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-10-11_12.52.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 12:00 . 2010-09-10 05:52 66560 c:\windows\system32\mshtmled.dll
- 2008-04-14 12:00 . 2009-03-08 02:31 66560 c:\windows\system32\mshtmled.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 43520 c:\windows\system32\licmgr10.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 25600 c:\windows\system32\jsproxy.dll
- 2009-06-25 11:59 . 2010-06-24 12:27 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-06-25 11:59 . 2010-09-10 05:52 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2008-04-14 12:00 . 2009-03-08 02:31 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-07-29 06:57 . 2010-09-10 05:52 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2009-07-29 06:57 . 2010-06-24 12:27 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 12800 c:\windows\ie8updates\KB2360131-IE8\xpshims.dll
+ 2010-10-14 17:07 . 2009-03-08 02:31 66560 c:\windows\ie8updates\KB2360131-IE8\mshtmled.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 55296 c:\windows\ie8updates\KB2360131-IE8\msfeedsbs.dll
+ 2010-10-14 17:07 . 2009-03-08 02:34 43008 c:\windows\ie8updates\KB2360131-IE8\licmgr10.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 25600 c:\windows\ie8updates\KB2360131-IE8\jsproxy.dll
- 2008-04-14 12:00 . 2009-10-15 16:32 119808 c:\windows\system32\t2embed.dll
+ 2008-04-14 12:00 . 2010-08-27 08:03 119808 c:\windows\system32\t2embed.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 206848 c:\windows\system32\occache.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\mfc42.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\mfc40u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\mfc40.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 387584 c:\windows\system32\iedkcs32.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 387584 c:\windows\system32\iedkcs32.dll
+ 2008-04-14 12:00 . 2010-08-26 12:22 173056 c:\windows\system32\ie4uinit.exe
- 2008-04-14 12:00 . 2010-06-23 12:08 173056 c:\windows\system32\ie4uinit.exe
+ 2009-06-25 09:51 . 2010-07-16 11:58 219136 c:\windows\system32\dllcache\wordpad.exe
+ 2008-04-14 12:00 . 2010-09-10 05:52 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 916480 c:\windows\system32\dllcache\wininet.dll
- 2008-04-14 12:00 . 2009-10-15 16:32 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2010-08-27 08:03 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-04-14 12:00 . 2010-08-16 08:45 590848 c:\windows\system32\dllcache\rpcrt4.dll
- 2008-04-14 12:00 . 2010-07-22 15:46 590848 c:\windows\system32\dllcache\rpcrt4.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 611840 c:\windows\system32\dllcache\mstime.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-07-29 06:57 . 2010-09-10 05:52 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-04-14 12:00 . 2010-09-18 10:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 974848 c:\windows\system32\dllcache\mfc42.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 953856 c:\windows\system32\dllcache\mfc40u.dll
+ 2008-04-14 12:00 . 2010-09-18 06:53 954368 c:\windows\system32\dllcache\mfc40.dll
+ 2009-06-25 11:59 . 2010-09-10 05:52 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-06-25 11:59 . 2010-06-24 12:27 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 184320 c:\windows\system32\dllcache\iepeers.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-11 06:00 . 2010-09-10 05:52 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2010-06-11 06:00 . 2010-06-24 12:27 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-04-14 12:00 . 2010-06-24 12:27 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 12:00 . 2010-08-26 12:22 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 12:00 . 2010-06-23 12:08 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\dllcache\comctl32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 12:00 . 2010-09-01 11:52 285824 c:\windows\system32\dllcache\atmfd.dll
+ 2008-04-14 12:00 . 2010-08-23 16:12 617472 c:\windows\system32\comctl32.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 617472 c:\windows\system32\comctl32.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 916480 c:\windows\ie8updates\KB2360131-IE8\wininet.dll
+ 2010-10-14 17:07 . 2010-07-05 13:13 391032 c:\windows\ie8updates\KB2360131-IE8\spuninst\updspapi.dll
+ 2010-10-14 17:07 . 2010-02-22 14:20 233848 c:\windows\ie8updates\KB2360131-IE8\spuninst\spuninst.exe
+ 2010-10-14 17:07 . 2010-06-24 12:27 206848 c:\windows\ie8updates\KB2360131-IE8\occache.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 611840 c:\windows\ie8updates\KB2360131-IE8\mstime.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 599040 c:\windows\ie8updates\KB2360131-IE8\msfeeds.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 247808 c:\windows\ie8updates\KB2360131-IE8\ieproxy.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 184320 c:\windows\ie8updates\KB2360131-IE8\iepeers.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 743424 c:\windows\ie8updates\KB2360131-IE8\iedvtool.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 387584 c:\windows\ie8updates\KB2360131-IE8\iedkcs32.dll
+ 2010-10-14 17:07 . 2010-06-23 12:08 173056 c:\windows\ie8updates\KB2360131-IE8\ie4uinit.exe
+ 2010-10-14 14:13 . 2010-08-23 16:12 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
+ 2008-04-14 12:00 . 2010-08-26 15:16 4886528 c:\windows\system32\wmp.dll
+ 2008-04-14 12:00 . 2010-09-01 07:57 1852800 c:\windows\system32\win32k.sys
+ 2008-04-14 12:00 . 2010-08-26 15:16 4886528 c:\windows\system32\dllcache\wmp.dll
+ 2008-04-14 12:00 . 2010-09-01 07:57 1852800 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 12:00 . 2010-09-10 05:52 1210880 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2010-07-16 12:00 1287680 c:\windows\system32\dllcache\ole32.dll
+ 2008-04-14 12:00 . 2010-09-10 05:52 5957120 c:\windows\system32\dllcache\mshtml.dll
- 2009-06-25 11:59 . 2010-06-24 12:27 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2009-06-25 11:59 . 2010-09-10 05:52 1986560 c:\windows\system32\dllcache\iertutil.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 1210368 c:\windows\ie8updates\KB2360131-IE8\urlmon.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 5951488 c:\windows\ie8updates\KB2360131-IE8\mshtml.dll
+ 2010-10-14 17:07 . 2010-06-24 12:27 1986560 c:\windows\ie8updates\KB2360131-IE8\iertutil.dll
+ 2009-06-25 11:58 . 2010-10-14 17:02 35385288 c:\windows\system32\MRT.exe
+ 2009-06-25 11:59 . 2010-09-10 05:52 11080192 c:\windows\system32\dllcache\ieframe.dll
+ 2010-10-14 17:07 . 2010-06-24 15:57 11077120 c:\windows\ie8updates\KB2360131-IE8\ieframe.dll
.
-- Snímek resetován k současnému datu --
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-08-27 13:25 2565448 ----a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2010-08-27 2565448]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2010-08-27 2565448]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2010-09-15 2745696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2009-08-10 24064]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 02:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2009-08-10 18:22 24064 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
2007-01-08 20:17 52256 ----a-w- c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
2007-02-26 08:40 249856 ----a-w- c:\program files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-01-24 10:32 2289664 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-02-27 11:03 570664 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2007-03-14 19:01 71216 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-01-21 10:17 61440 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-07-02 10:26 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=2 (0x2)
"gupdate1c9faffc1c539a5"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"\\\\macek\\storage\\Instalace\\!predinstalace\\Nero CZ a Power DVD\\CDS\\Nero\\Installation\\SetupX.exe"=
"c:\\Program Files\\SEGA\\SEGA Rally\\SEGA Rally.exe"=
"c:\\Program Files\\SEGA\\SEGA Rally\\SEGA Rally_SSE1.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\ProgramData\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Counter-Strike Source\\hl2.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [13.9.2010 16:27 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [7.9.2010 3:48 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [7.9.2010 3:48 249424]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7.9.2010 3:49 298448]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [10.9.2010 1:45 265400]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [19.8.2010 21:42 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [19.8.2010 21:42 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [19.8.2010 21:42 26192]
S2 gupdate1c9faffc1c539a5;Služba Google Update (gupdate1c9faffc1c539a5);c:\program files\Google\Update\GoogleUpdate.exe [2.7.2009 12:27 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [6.10.2010 15:16 488776]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [3.9.2010 10:35 6104144]
S3 GGSAFERDriver;GGSAFER Driver;\??\c:\program files\Garena\plugins\UI\safedrv.sys --> c:\program files\Garena\plugins\UI\safedrv.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24.8.2009 14:19 721904]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 10:30 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'
2010-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 10:27]
2010-10-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 10:27]
2010-10-13 c:\windows\Tasks\User_Feed_Synchronization-{A2061C48-FAE3-4493-BA3C-D293A9690810}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://puvodni.centrum.cz/
IE: &Download All by FlashGet - c:\program files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
IE: &Download by FlashGet - c:\program files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
IE: Crawler Search - tbr:iemenu
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\documents and settings\Uživatel\Data aplikací\Mozilla\Firefox\Profiles\bmnurbgq.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.crawler.com/homepage.aspx?tbid=60347
FF - prefs.js: keyword.URL - hxxp://www.crawler.com/search/dispatcher.aspx? ... 60347&qkw=
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\program files\Crawler\Toolbar\firefox\components\xwsg.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(780)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-10-14 20:21:33
ComboFix-quarantined-files.txt 2010-10-14 18:21
ComboFix2.txt 2010-10-11 12:53
ComboFix3.txt 2010-10-09 09:40
Před spuštěním: Volných bajtů: 47 842 742 272
Po spuštění: Volných bajtů: 47 965 372 416
- - End Of File - - AEEC6BEAEDFC4FC092B607FCD912E866
RSIT:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Uživatel at 2010-10-14 20:24:25
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 46 GB (31%) free of 150 GB
Total RAM: 2047 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:24:33, on 14.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.29\GoogleCrashHandler.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
C:\Documents and Settings\Uživatel\Plocha\pv\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://puvodni.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60347
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download All by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bhoall.htm
O8 - Extra context menu item: &Download by FlashGet - C:\Program Files\FlashGet Network\FlashGet universal\ComDlls\Bholink.htm
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Služba Google Update (gupdate1c9faffc1c539a5) (gupdate1c9faffc1c539a5) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 7801 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A2061C48-FAE3-4493-BA3C-D293A9690810}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-09-02 1241448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG10\avgssie.dll [2010-09-16 2890592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-08-27 2565448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2009-09-13 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-07-02 668656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2009-09-13 2403392]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-09-02 1241448]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-08-27 2565448]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"=C:\Program Files\AVG\AVG10\avgtray.exe [2010-09-15 2745696]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-20 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-09-23 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2009-08-10 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
C:\Program Files\lg_fwupdate\fwupdate.exe [2007-02-26 249856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-01-24 2289664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2008-02-27 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-01-21 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-07-02 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3
"IDriverT"=3
"gusvc"=2
"gupdate1c9faffc1c539a5"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-07-08 143360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"\\macek\storage\Instalace\!predinstalace\Nero CZ a Power DVD\CDS\Nero\Installation\SetupX.exe"="\\macek\storage\Instalace\!predinstalace\Nero CZ a Power DVD\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup"
"C:\Program Files\SEGA\SEGA Rally\SEGA Rally.exe"="C:\Program Files\SEGA\SEGA Rally\SEGA Rally.exe:*:Enabled:SEGA Rally"
"C:\Program Files\SEGA\SEGA Rally\SEGA Rally_SSE1.exe"="C:\Program Files\SEGA\SEGA Rally\SEGA Rally_SSE1.exe:*:Enabled:SEGA Rally"
"C:\Program Files\Electronic Arts\EADM\Core.exe"="C:\Program Files\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\ProgramData\World of Warcraft\Repair.exe"="C:\ProgramData\World of Warcraft\Repair.exe:*:Enabled:Blizzard Repair Utility"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Counter-Strike Source\hl2.exe"="C:\Program Files\Counter-Strike Source\hl2.exe:*:Disabled:hl2"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Garena\Garena.exe"="C:\Program Files\Garena\Garena.exe:*:Disabled:Garena"
"C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:Instalátor AVG"
"C:\Program Files\AVG\AVG10\avgdiagex.exe"="C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostika 2011"
"C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Webový štít"
"C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Obecná kontrola pošty"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-10-14 20:23:06 ----SHD---- C:\RECYCLER
2010-10-14 20:21:35 ----D---- C:\WINDOWS\temp
2010-10-14 20:21:34 ----A---- C:\ComboFix.txt
2010-10-14 20:14:54 ----D---- C:\ComboFix
2010-10-14 19:11:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$
2010-10-14 19:10:36 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$
2010-10-14 19:10:10 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$
2010-10-14 19:09:45 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$
2010-10-14 19:09:17 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$
2010-10-14 19:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$
2010-10-14 19:01:44 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$
2010-10-14 19:00:52 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$
2010-10-14 19:00:32 ----D---- C:\WINDOWS\LastGood
2010-10-14 16:12:37 ----A---- C:\WINDOWS\system32\SET59.tmp
2010-10-14 16:12:36 ----A---- C:\WINDOWS\system32\SET58.tmp
2010-10-14 16:12:36 ----A---- C:\WINDOWS\system32\SET54.tmp
2010-10-14 16:12:36 ----A---- C:\WINDOWS\system32\SET53.tmp
2010-10-14 16:12:35 ----A---- C:\WINDOWS\system32\SET52.tmp
2010-10-14 16:12:33 ----A---- C:\WINDOWS\system32\SET4E.tmp
2010-10-14 16:12:33 ----A---- C:\WINDOWS\system32\SET4D.tmp
2010-10-14 16:12:31 ----A---- C:\WINDOWS\system32\SET5A.tmp
2010-10-14 16:12:05 ----A---- C:\WINDOWS\system32\SET43.tmp
2010-10-11 14:47:06 ----A---- C:\WINDOWS\zip.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\SWSC.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\SWREG.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\sed.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\PEV.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\NIRCMD.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\MBR.exe
2010-10-11 14:47:06 ----A---- C:\WINDOWS\grep.exe
2010-10-11 14:45:25 ----D---- C:\Qoobox
2010-10-10 16:45:21 ----D---- C:\Config.Msi
2010-10-06 19:10:32 ----D---- C:\$AVG
2010-10-06 15:17:23 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\AVG10
2010-10-06 15:16:25 ----HD---- C:\Documents and Settings\All Users\Data aplikací\Common Files
2010-10-06 15:16:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG Security Toolbar
2010-10-06 15:15:41 ----D---- C:\WINDOWS\system32\drivers\AVG
2010-10-06 15:15:41 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVG10
2010-10-06 15:09:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\MFAData
2010-09-29 08:48:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$
2010-09-18 12:23:38 ----A---- C:\WINDOWS\system32\SET9D.tmp
2010-09-15 23:33:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2259922$
2010-09-15 23:33:32 ----HDC---- C:\WINDOWS\$NtUninstallKB975558_WM8$
2010-09-15 23:33:29 ----HDC---- C:\WINDOWS\$NtUninstallKB2347290$
2010-09-15 23:33:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2121546$
2010-09-15 23:33:19 ----HDC---- C:\WINDOWS\$NtUninstallKB982802$
2010-09-15 23:33:14 ----HDC---- C:\WINDOWS\$NtUninstallKB981322$
2010-09-15 23:31:09 ----HDC---- C:\WINDOWS\$NtUninstallKB2141007$
======List of files/folders modified in the last 1 months======
2010-10-14 20:24:33 ----D---- C:\Program Files\trend micro
2010-10-14 20:22:36 ----D---- C:\WINDOWS\system32
2010-10-14 20:21:35 ----D---- C:\WINDOWS
2010-10-14 20:19:55 ----A---- C:\WINDOWS\system.ini
2010-10-14 20:19:48 ----D---- C:\WINDOWS\system32\drivers\etc
2010-10-14 20:19:33 ----D---- C:\Program Files\Internet Explorer
2010-10-14 20:18:23 ----D---- C:\WINDOWS\system32\drivers
2010-10-14 20:18:23 ----D---- C:\WINDOWS\AppPatch
2010-10-14 20:18:22 ----D---- C:\Program Files\Common Files
2010-10-14 20:16:04 ----D---- C:\WINDOWS\system32\CatRoot2
2010-10-14 20:15:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-10-14 20:10:02 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Skype
2010-10-14 20:05:18 ----D---- C:\Program Files\Valve
2010-10-14 19:45:59 ----RD---- C:\Program Files
2010-10-14 19:11:40 ----HD---- C:\WINDOWS\inf
2010-10-14 19:11:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-10-14 19:10:59 ----HD---- C:\WINDOWS\$hf_mig$
2010-10-14 19:10:56 ----A---- C:\WINDOWS\imsins.BAK
2010-10-14 19:10:20 ----D---- C:\WINDOWS\Prefetch
2010-10-14 19:10:11 ----D---- C:\WINDOWS\WinSxS
2010-10-14 19:07:46 ----D---- C:\WINDOWS\ie8updates
2010-10-14 19:02:28 ----A---- C:\WINDOWS\system32\MRT.exe
2010-10-14 17:56:35 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\skypePM
2010-10-11 14:46:52 ----D---- C:\WINDOWS\ERDNT
2010-10-11 14:38:37 ----SHD---- C:\WINDOWS\Installer
2010-10-10 16:46:08 ----D---- C:\Program Files\Common Files\Adobe
2010-10-10 16:46:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-10-09 14:43:15 ----SHD---- C:\System Volume Information
2010-10-09 14:43:15 ----D---- C:\WINDOWS\system32\Restore
2010-10-08 12:08:54 ----RSD---- C:\WINDOWS\assembly
2010-10-08 12:08:13 ----D---- C:\WINDOWS\Microsoft.NET
2010-10-07 08:34:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-10-06 15:15:24 ----D---- C:\Program Files\AVG
2010-10-06 14:43:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-10-04 02:10:55 ----D---- C:\Program Files\Mozilla Firefox
2010-10-02 14:34:02 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\gtk-2.0
2010-09-30 19:12:15 ----D---- C:\Program Files\Warcraft III
2010-09-30 18:20:05 ----D---- C:\Program Files\Garena
2010-09-26 11:56:45 ----D---- C:\Program Files\Counter-Strike Source
2010-09-25 20:49:45 ----D---- C:\Program Files\Google
2010-09-24 19:53:37 ----A---- C:\WINDOWS\NeroDigital.ini
2010-09-22 19:54:32 ----D---- C:\WINDOWS\Network Diagnostic
2010-09-18 08:53:37 ----A---- C:\WINDOWS\system32\mfc42.dll
2010-09-18 08:53:37 ----A---- C:\WINDOWS\system32\mfc40u.dll
2010-09-18 08:53:37 ----A---- C:\WINDOWS\system32\mfc40.dll
2010-09-17 21:02:10 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\ICQ
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064]
R0 uagp35;Filtr Microsoft AGPv3.5; C:\WINDOWS\system32\DRIVERS\uagp35.sys [2008-04-14 44672]
R0 viamraid;viamraid; C:\WINDOWS\system32\drivers\viamraid.sys [2009-06-25 104064]
R0 videX32;videX32; C:\WINDOWS\system32\DRIVERS\videX32.sys [2009-06-25 9216]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-09-07 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-09-07 298448]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-07-08 3257344]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2008-05-20 93696]
R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472]
R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288]
R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192]
R3 catchme;catchme; \??\C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\catchme.sys []
R3 cmuda;C-Media WDM Audio Interface; C:\WINDOWS\system32\drivers\cmuda.sys [2004-04-23 818496]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ctljystk;Game port pro zařízení Creative SB Live!; C:\WINDOWS\system32\DRIVERS\ctljystk.sys [2001-08-17 3712]
S3 GGSAFERDriver;GGSAFER Driver; \??\C:\Program Files\Garena\plugins\UI\safedrv.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\mbr.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-08-24 721904]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-07-08 573440]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-09-03 6104144]
R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe [2010-09-10 265400]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-01-24 73728]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 gupdate1c9faffc1c539a5;Služba Google Update (gupdate1c9faffc1c539a5); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-07-02 133104]
S2 spupdsvc;Windows Service Pack Installer update service; C:\WINDOWS\system32\spupdsvc.exe [2009-01-07 26144]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-08-27 488776]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-02 190448]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-09-17 800040]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
-----------------EOF-----------------
Naposledy upravil(a) Thrall dne 14 říj 2010 21:38, celkem upraveno 1 x.
Re: New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost)
Nakonec jsme zjistil že AvG testovalo a byla to nahoda a paranoidne oznacilo IceSword jako vir. Ale stejně by mě zajimalo co to ten ComboFix vymazal .Jestli to byl fakt nejaky vir a jak ten soubor ktery nejde vymazat vymažu.
Re: New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost)
Ale taky mi AvG chytlo nejaky Dropper.Generic.AITJ .Thrall píše:Nakonec jsme zjistil že AvG testovalo a byla to nahoda a paranoidne oznacilo IceSword jako vir. Ale stejně by mě zajimalo co to ten ComboFix vymazal .Jestli to byl fakt nejaky vir a jak ten soubor ktery nejde vymazat vymažu.
Re: New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost)
Thrall píše:Ale stejně by mě zajimalo co to ten ComboFix vymazal .Jestli to byl fakt nejaky vir a jak ten soubor ktery nejde vymazat vymažu.
Re: New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost)
Dobrý večer
Když si sám takto odpovídáte, tak Vás už rádce nevidí, nebot s ekoukáme na ty s 0 odpovědmi
.
Mějte chvilku trpělivost, kouknu na ty logy.
To jste měl stahnutý program Icesword na rootkity? V tom případě je to falešná detekce AVG.

Když si sám takto odpovídáte, tak Vás už rádce nevidí, nebot s ekoukáme na ty s 0 odpovědmi

Mějte chvilku trpělivost, kouknu na ty logy.
To jste měl stahnutý program Icesword na rootkity? V tom případě je to falešná detekce AVG.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost)
:arrow:Stáhněte OTM http://oldtimer.geekstogo.com/OTM.exe
Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,
Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript
-klikněte na červené tlačítko Moveit!
-sem vložte obsah zeleného okénka
-Pokud se bude chtít restartovat pc, dejte YES,log pak najdete C:\_OTM\MovedFiles. Log vložte sem
Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,
Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript
Kód: Vybrat vše
:processes
explorer.exe
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
:commands
[emptytemp]
[EMPTYFLASH]
-sem vložte obsah zeleného okénka
-Pokud se bude chtít restartovat pc, dejte YES,log pak najdete C:\_OTM\MovedFiles. Log vložte sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: New Malware.z-ICESWORD.EXE (AvG 2011:velká zavažnost)
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP158.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1FE.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP212.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP22B.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP306.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP338.tmp folder moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Uživatel
->Temp folder emptied: 32768 bytes
->Temporary Internet Files folder emptied: 1787786 bytes
->FireFox cache emptied: 36983003 bytes
->Flash cache emptied: 64542 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 37,00 mb
OTM by OldTimer - Version 3.1.16.1 log created on 10142010_221416
Files moved on Reboot...
File C:\Documents and Settings\Uživatel\Local Settings\Temp\~DF1D56.tmp not found!
File C:\Documents and Settings\Uživatel\Local Settings\Temp\~DFE6AB.tmp not found!
C:\Documents and Settings\Uživatel\Local Settings\Temporary Internet Files\Content.IE5\X13AZEXV\afr[1].htm moved successfully.
C:\Documents and Settings\Uživatel\Local Settings\Temporary Internet Files\Content.IE5\X13AZEXV\search[2].htm moved successfully.
C:\Documents and Settings\Uživatel\Local Settings\Temporary Internet Files\Content.IE5\VX8OVPIW\afr[1].htm moved successfully.
Registry entries deleted on Reboot...
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP158.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1FE.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP212.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP22B.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP306.tmp folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP338.tmp folder moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Uživatel
->Temp folder emptied: 32768 bytes
->Temporary Internet Files folder emptied: 1787786 bytes
->FireFox cache emptied: 36983003 bytes
->Flash cache emptied: 64542 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 37,00 mb
OTM by OldTimer - Version 3.1.16.1 log created on 10142010_221416
Files moved on Reboot...
File C:\Documents and Settings\Uživatel\Local Settings\Temp\~DF1D56.tmp not found!
File C:\Documents and Settings\Uživatel\Local Settings\Temp\~DFE6AB.tmp not found!
C:\Documents and Settings\Uživatel\Local Settings\Temporary Internet Files\Content.IE5\X13AZEXV\afr[1].htm moved successfully.
C:\Documents and Settings\Uživatel\Local Settings\Temporary Internet Files\Content.IE5\X13AZEXV\search[2].htm moved successfully.
C:\Documents and Settings\Uživatel\Local Settings\Temporary Internet Files\Content.IE5\VX8OVPIW\afr[1].htm moved successfully.
Registry entries deleted on Reboot...
- Rudy
- Site Admin
- Příspěvky: 119426
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Virus
Omlouvám se za vstup, píši na žádost uživatele. Vše bylo smazáno. Nejste pod FUPem?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Virus
http://www.zkratky.cz/FUP/13299Thrall píše:Pod čím?Rudy píše:Omlouvám se za vstup, píši na žádost uživatele. Vše bylo smazáno. Nejste pod FUPem?
Pardon
Nn,mám normální modem od O2
- Rudy
- Site Admin
- Příspěvky: 119426
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Virus
FUP=fair user policy. Omezení rychlosti připojení po stažení předem dohodnuté kvóty dat providerem.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Virus
Asi ne. Jak říkám normalní internet od 02 .Rudy píše:FUP=fair user policy. Omezení rychlosti připojení po stažení předem dohodnuté kvóty dat providerem.
Mám pár dotazů:



Re: Virus
Teď se zase za vstup omlouvám já
, snad to nebude vadit.
Combofix smazal nějaké dočasné soubory, mohli i nemuseli být infikované.
Jaký soubor Vám nejde smazat?
start-spustit - napište chkdsk /f/r
-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.




-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat

-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Virus
Na co je to "chkdsk /f/r " ja jsme ohledně disku hodně opatrnej . Mám tam zalohu ,fotky atd..motji píše:Teď se zase za vstup omlouvám já, snad to nebude vadit.
Combofix smazal nějaké dočasné soubory, mohli i nemuseli být infikované.
Jaký soubor Vám nejde smazat?
start-spustit - napište chkdsk /f/r
-[enter]
souhlas - restartuje se pc a nechá se disk zkontrolovat
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT![]()
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.