pro Motji

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz


Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 Říj 2010 09:59

pro Motji

#1 Příspěvek od kolariktomas1 »

Logfile of random's system information tool 1.08 (written by random/random)
Run by rodina at 2010-10-22 15:47:03
Systém Microsoft Windows XP Professional Service Pack 3
System drive E: has 18 GB (46%) free of 38 GB
Total RAM: 759 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:58, on 22.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Google\Update\GoogleUpdate.exe
E:\Program Files\CyberLink\Shared Files\RichVideo.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\System32\snmp.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Citrix\ICA Client\ssonsvr.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\System32\igfxtray.exe
E:\WINDOWS\System32\hkcmd.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
E:\Program Files\lg_fwupdate\fwupdate.exe
E:\Program Files\Winamp\winampa.exe
E:\WINDOWS\PixArt\PAC207\Monitor.exe
E:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe
E:\Program Files\Search Settings\SearchSettings.exe
E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
E:\Program Files\Citrix\ICA Client\concentr.exe
E:\Program Files\DynamicUSBTool\DynamicUSB.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
E:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
E:\Program Files\Nikon\NkView6\NkvMon.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
E:\Program Files\Mozilla Firefox\firefox.exe
E:\PROGRA~1\Crawler\CToolbar.exe
E:\Program Files\Mozilla Firefox\plugin-container.exe
E:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\rodina\Dokumenty\Stažené soubory\RSIT.exe
E:\Program Files\trend micro\rodina.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - E:\Program Files\Search Settings\kb128\SearchSettings.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - E:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - E:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - E:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - E:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - E:\Program Files\Search Settings\kb128\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - E:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - E:\Program Files\BS.Player ControlBar\BSToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - E:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - E:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [IgfxTray] E:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] E:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "E:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PAC207_Monitor] E:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] E:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [DC1300 Monitor] E:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SearchSettings] E:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [OM2_Monitor] "E:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [ConnectionCenter] "E:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [DynamicUSB] "E:\Program Files\DynamicUSBTool\DynamicUSB.exe"
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [OM2_Monitor] "E:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = E:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Google Sidewiki... - res://E:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - E:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - E:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - E:\PROGRA~1\Crawler\ctbr.dll
O20 - Winlogon Notify: !SASWinLogon - E:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\PROGRA~1\ALWILS~1\Avast4\ashMaiSv.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - E:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - E:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - E:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11298 bytes

======Scheduled tasks folder======

E:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - E:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - E:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
E:\PROGRA~1\Crawler\ctbr.dll [2010-09-02 1241448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - E:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-12 278192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - E:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-10-16 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - E:\Program Files\Search Settings\kb128\SearchSettings.dll [2009-04-09 1091584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - E:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-10-14 863688]
{2C688203-7EB3-4327-9995-1CB417BA23F9} - BS.Player ControlBar - E:\Program Files\BS.Player ControlBar\BSToolbar.dll [2008-10-08 859592]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - E:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-12 278192]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - E:\PROGRA~1\Crawler\ctbr.dll [2010-09-02 1241448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=E:\WINDOWS\System32\igfxtray.exe [2002-06-19 155648]
"HotKeysCmds"=E:\WINDOWS\System32\hkcmd.exe [2002-06-19 114688]
"HP Software Update"=E:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"RemoteControl"=E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=E:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
"LGODDFU"=E:\Program Files\lg_fwupdate\fwupdate.exe [2010-07-18 557056]
"WinampAgent"=E:\Program Files\Winamp\winampa.exe [2010-01-14 37888]
"PAC207_Monitor"=E:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=E:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"DC1300 Monitor"=E:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe [2009-03-04 45056]
"NeroFilterCheck"=E:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SearchSettings"=E:\Program Files\Search Settings\SearchSettings.exe [2009-04-09 970240]
"Adobe Reader Speed Launcher"=E:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"OM2_Monitor"=E:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe [2009-11-25 54672]
"ConnectionCenter"=E:\Program Files\Citrix\ICA Client\concentr.exe [2009-09-12 103768]
"DynamicUSB"=E:\Program Files\DynamicUSBTool\DynamicUSB.exe [2007-03-02 94208]
"avast!"=E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
"SunJavaUpdateSched"=E:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=E:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-08 39408]
"OM2_Monitor"=E:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]

E:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - E:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
Microsoft Office.lnk - E:\Program Files\Microsoft Office\Office\OSA9.EXE
NkvMon.exe.lnk - E:\Program Files\Nikon\NkView6\NkvMon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
E:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
E:\WINDOWS\system32\igfxsrvc.dll [2002-06-19 307200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
E:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - E:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=E:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\Program Files\ICQ6\ICQ.exe"="E:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"E:\Program Files\uTorrent\uTorrent.exe"="E:\Program Files\uTorrent\uTorrent.exe:*:Disabled:µTorrent"
"E:\WINDOWS\system32\dpvsetup.exe"="E:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"E:\WINDOWS\system32\rundll32.exe"="E:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"E:\WINDOWS\system32\sessmgr.exe"="E:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"E:\Program Files\ICQ6.5\ICQ.exe"="E:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"E:\Program Files\Skype\Plugin Manager\skypePM.exe"="E:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Documents and Settings\tom\Dokumenty\Stažené soubory\BULANCI.EXE"="C:\Documents and Settings\tom\Dokumenty\Stažené soubory\BULANCI.EXE:*:Enabled:BULANCI"
"E:\WINDOWS\system32\dplaysvr.exe"="E:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"E:\Program Files\Skype\Phone\Skype.exe"="E:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

6169-11-24 00:54:03 ----D---- E:\Documents and Settings\All Users\Data aplikací\MSN6
6169-11-24 00:35:36 ----D---- E:\Netgear
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\vxblock.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxwave.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxmas.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxinsa64.exe
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxhpinst.exe
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxdrv.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxcpya64.exe
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\px.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\drivers\PxHelp20.sys
6169-11-23 14:04:33 ----D---- E:\Program Files\Winamp
6169-11-23 13:43:41 ----A---- E:\WINDOWS\system32\igfxres.dll
6169-11-23 13:33:36 ----A---- E:\WINDOWS\system32\drivers\ks.sys
6169-11-23 13:33:36 ----A---- E:\WINDOWS\system32\drivers\drmk.sys
6169-11-23 13:33:35 ----A---- E:\WINDOWS\system32\drivers\stream.sys
6169-11-23 13:33:35 ----A---- E:\WINDOWS\system32\drivers\portcls.sys
6169-11-23 13:33:34 ----A---- E:\WINDOWS\system32\ksuser.dll
2010-10-22 15:47:05 ----D---- E:\Program Files\trend micro
2010-10-22 15:47:03 ----D---- E:\rsit
2010-10-14 20:23:42 ----D---- E:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-10-14 20:23:35 ----D---- E:\Program Files\SUPERAntiSpyware
2010-10-10 18:20:26 ----A---- E:\WINDOWS\mdm.ini
2010-10-10 17:15:27 ----D---- E:\Program Files\Microsoft Visual Studio
2010-09-28 18:10:17 ----A---- E:\WINDOWS\ntbtlog.txt
2010-09-27 13:54:08 ----SHD---- E:\WINDOWS\CSC

======List of files/folders modified in the last 1 months======

2010-10-22 15:47:06 ----D---- E:\WINDOWS\Prefetch
2010-10-22 15:47:05 ----RD---- E:\Program Files
2010-10-22 15:46:17 ----D---- E:\Program Files\Spyware Terminator
2010-10-22 15:46:11 ----D---- E:\Program Files\WinClamAVShield
2010-10-22 15:43:50 ----HDC---- E:\Documents and Settings\All Users\Data aplikací\~0
2010-10-22 15:43:47 ----HD---- E:\Config.Msi
2010-10-22 15:43:41 ----SHD---- E:\WINDOWS\Installer
2010-10-22 15:42:45 ----D---- E:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-10-22 15:42:43 ----DC---- E:\WINDOWS\system32\DRVSTORE
2010-10-22 15:42:32 ----D---- E:\WINDOWS\system32
2010-10-22 15:01:54 ----D---- E:\Program Files\Crawler
2010-10-22 15:01:39 ----D---- E:\Program Files\Mozilla Firefox
2010-10-22 14:12:26 ----A---- E:\WINDOWS\lgfwup.ini
2010-10-22 14:12:17 ----D---- E:\Program Files\lg_fwupdate
2010-10-22 14:09:13 ----D---- E:\WINDOWS\Temp
2010-10-21 23:04:48 ----A---- E:\WINDOWS\SchedLgU.Txt
2010-10-16 10:22:50 ----D---- E:\WINDOWS\system32\CatRoot2
2010-10-15 16:19:45 ----D---- E:\Documents and Settings\rodina\Data aplikací\Skype
2010-10-15 16:14:14 ----D---- E:\Documents and Settings\rodina\Data aplikací\skypePM
2010-10-15 06:45:27 ----A---- E:\WINDOWS\win.ini
2010-10-14 22:53:04 ----D---- E:\WINDOWS
2010-10-14 20:23:15 ----D---- E:\Program Files\Malwarebytes' Anti-Malware
2010-10-14 20:23:12 ----D---- E:\WINDOWS\system32\drivers
2010-10-13 20:41:53 ----D---- E:\WINDOWS\network diagnostic
2010-10-10 17:16:35 ----D---- E:\WINDOWS\Help
2010-10-10 17:15:40 ----D---- E:\Program Files\Common Files\Microsoft Shared
2010-09-30 17:30:24 ----D---- E:\WINDOWS\Microsoft.NET
2010-09-29 19:02:38 ----D---- E:\Documents and Settings\rodina\Data aplikací\IcaClient
2010-09-28 17:41:54 ----D---- E:\Documents and Settings
2010-09-28 17:39:38 ----D---- E:\WINDOWS\Debug
2010-09-28 17:23:13 ----D---- E:\WINDOWS\system32\XPSViewer
2010-09-28 17:23:09 ----RSD---- E:\WINDOWS\Fonts
2010-09-28 17:22:04 ----HD---- E:\WINDOWS\inf
2010-09-28 17:21:30 ----D---- E:\WINDOWS\system32\CatRoot
2010-09-28 17:18:40 ----A---- E:\WINDOWS\system32\PerfStringBackup.INI
2010-09-28 17:18:28 ----RSD---- E:\WINDOWS\assembly
2010-09-28 17:18:13 ----D---- E:\WINDOWS\WinSxS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; E:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; E:\WINDOWS\System32\Drivers\sptd.sys [2008-10-21 717296]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; E:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; E:\WINDOWS\system32\drivers\ialmsbw.sys [2002-06-21 90784]
R1 ctxusbm;Citrix USB Monitor Driver; E:\WINDOWS\system32\DRIVERS\ctxusbm.sys [2009-09-08 65584]
R1 intelppm;Řadič procesoru Intel; E:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SASDIFSV;SASDIFSV; \??\E:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\E:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; E:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-06-20 225856]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; E:\WINDOWS\system32\drivers\ialmkchw.sys [2002-06-21 69792]
R3 aeaudio;aeaudio; E:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 E1000;Intel(R) PRO/1000 Adapter Driver; E:\WINDOWS\System32\DRIVERS\e1000325.sys [2002-05-06 99328]
R3 hidusb;Ovladač třídy standardu HID; E:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; E:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2002-06-21 78877]
R3 mouhid;Ovladač myši standardu HID; E:\WINDOWS\System32\DRIVERS\mouhid.sys [2002-09-23 12160]
R3 pfc;Padus ASPI Shell; E:\WINDOWS\system32\drivers\pfc.sys [2003-08-11 14604]
R3 smwdm;smwdm; E:\WINDOWS\system32\drivers\smwdm.sys [2002-07-08 553800]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; E:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; E:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; E:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R4 sp_rsdrv2;Spyware Terminator Driver 2; \??\E:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
S3 a2q4z5xs;a2q4z5xs; E:\WINDOWS\system32\drivers\a2q4z5xs.sys []
S3 CCDECODE;Dekodér Closed Caption; E:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CrystalSysInfo;CrystalSysInfo; \??\E:\Program Files\MediaCoder\SysInfo.sys []
S3 DC1300;DC 1300 WDM Video Capture; E:\WINDOWS\System32\Drivers\BSC504AV.SYS [2009-03-04 515365]
S3 hamachi;Hamachi Network Interface; E:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; E:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; E:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; E:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
S3 INIDVD;Initio USB DVD Filter Driver; E:\WINDOWS\system32\DRIVERS\inidvd.sys [2007-11-07 7936]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; E:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; E:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PAC207;e-Messenger 112; E:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
S3 SLIP;BDA Slip De-Framer; E:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; E:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBCamera;DC 1300 Still Image Capture; E:\WINDOWS\System32\Drivers\BscBulk.sys [2009-03-04 10986]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; E:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; E:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; E:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; E:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; E:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; E:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; E:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; E:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; E:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); E:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SimpTcp;Jednoduché služby TCP/IP; E:\WINDOWS\System32\tcpsvcs.exe [2002-09-23 19456]
R2 SNMP;SNMP; E:\WINDOWS\System32\snmp.exe [2008-04-14 32768]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); E:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-22 135664]
S3 aspnet_state;ASP.NET State Service; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Mail Scanner;avast! Mail Scanner; E:\PROGRA~1\ALWILS~1\Avast4\ashMaiSv.exe [2009-08-17 254040]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-26 182768]
S3 idsvc;Windows CardSpace; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; E:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 p2pgasvc;Ověřování v síti skupiny rovnocenných počítačů; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Správce identit sítě rovnocenných počítačů; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Síť rovnocenných počítačů; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Protokol PNRP; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 SNMPTRAP;Zachytávání pro službu SNMP; E:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; E:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 Říj 2010 09:59

Re: pro Motji

#2 Příspěvek od kolariktomas1 »

info log:

info.txt logfile of random's system information tool 1.08 2010-10-22 15:48:13

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 E:\WINDOWS\INF\PCHealth.inf
2d3 SteadyMove for Adobe Premiere Pro-->MsiExec.exe /I{94118D5F-2D5D-4BF5-9F84-11FB8A97B566}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Adobe AIR-->E:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->E:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->E:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Premiere Pro-->RunDll32 "E:\Program Files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll",LaunchSetup "E:\Program Files\InstallShield Installation Information\{084709F7-38C5-4609-B55F-2417939315EB}\setup.exe"
Adobe Reader 9.3.4-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A93000000001}
Aktualizace systému Windows XP (KB951072-v2)-->"E:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB951978)-->"E:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB955839)-->"E:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB967715)-->"E:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB968389)-->"E:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB973815)-->"E:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB952069)-->"E:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB968816)-->"E:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB973540)-->"E:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player 11 (KB936782)-->"E:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player 11 (KB954154)-->"E:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Aktualizace zabezpečení produktu Windows XP (KB941569)-->"E:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127)-->"E:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127-v2)-->"E:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB953838)-->"E:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB956390)-->"E:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB969897)-->"E:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB971961)-->"E:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB972260)-->"E:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB923561)-->"E:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB938464)-->"E:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB938464-v2)-->"E:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB946648)-->"E:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB950762)-->"E:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB950974)-->"E:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951066)-->"E:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951376-v2)-->"E:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951698)-->"E:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951748)-->"E:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB952004)-->"E:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB952954)-->"E:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB953839)-->"E:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB954211)-->"E:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB954459)-->"E:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB954600)-->"E:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB955069)-->"E:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956391)-->"E:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956572)-->"E:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956744)-->"E:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956802)-->"E:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956803)-->"E:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956841)-->"E:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956844)-->"E:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB957095)-->"E:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB957097)-->"E:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958644)-->"E:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958687)-->"E:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB959426)-->"E:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960225)-->"E:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960803)-->"E:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960859)-->"E:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961371-v2)-->"E:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961373)-->"E:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961501)-->"E:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB968537)-->"E:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB969898)-->"E:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB970238)-->"E:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971557)-->"E:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971633)-->"E:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971657)-->"E:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973346)-->"E:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973354)-->"E:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973507)-->"E:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973869)-->"E:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
ALZip-->"E:\Program Files\ESTsoft\ALZip\unins000.exe"
Any Weblock 1.0.0-->"E:\Program Files\AnyUtils\Any Weblock\unins000.exe"
ArcSoft Panorama Maker 3.0-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{1CABB679-3958-44AA-BFFF-4E68A2684255}\Setup.exe" -l0x9 -uninst
Audacity 1.3.5 (Unicode)-->"E:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
Auto Gordian Knot 2.45-->E:\Program Files\AutoGK\uninst.exe
avast! Antivirus-->E:\Program Files\Alwil Software\Avast4\aswRunDll.exe "E:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AviSynth 2.5-->"E:\Program Files\AviSynth 2.5\Uninstall.exe"
Booster 1.03-->"E:\Program Files\LG USB Booster\unins000.exe"
BS.Player ControlBar-->E:\Program Files\BS.Player ControlBar\uninst.exe
BS.Player FREE-->"E:\Program Files\Webteh\BSplayer\uninstall.exe"
CCleaner-->"E:\Program Files\CCleaner\uninst.exe"
Citrix online plug-in (HDX)-->MsiExec.exe /I{812424AC-A8B5-44E6-8D48-07E939D1AD9A}
Citrix online plug-in (SSON)-->MsiExec.exe /I{7C84DDDF-DEC9-4E02-8222-D86E73531CEB}
Citrix online plug-in (USB)-->MsiExec.exe /I{55392E52-1AAD-44C4-BE49-258FFE72434F}
Citrix online plug-in (Web)-->MsiExec.exe /I{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}
Citrix online plug-in-->E:\Documents and Settings\All Users\Data aplikací\Citrix\Citrix online plug-in\TrolleyExpress.exe /uninstall /cleanup
Crawler Toolbar with Web Security Guard-->E:\PROGRA~1\Crawler\CToolbar.exe uninst
DAEMON Tools Toolbar-->E:\Program Files\DAEMON Tools Toolbar\uninst.exe
DC1300-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{B68AABF8-591C-4B1F-906E-DCEF6E18958A}\SETUP.EXE" -l0x9
Důležitá aktualizace aplikace Windows Media Player 11 (KB959772)-->"E:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
DVD Suite-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
DynamicUSBTool-->MsiExec.exe /I{85BC6E3A-E8D4-48B7-8EEE-13E46F65BA75}
e-Messenger 112-->"E:\Program Files\InstallShield Installation Information\{730C01C5-CAE4-46FE-BA13-8B3E637F8192}\setup.exe" -runfromtemp -l0x0005 -removeonly
Free The Pharaoh v1.0-->"E:\Program Files\Free The Pharaoh\unins000.exe"
Free WMA to MP3 Converter 1.16-->"E:\Program Files\Free WMA to MP3 Converter\unins000.exe"
FTP Commander-->E:\Program Files\FTP Commander\uninstall.exe
GamingHarbor Toolbar-->"E:\Documents and Settings\All Users\Data aplikací\{F444439B-B473-48E8-8DE5-4CB929C79A9F}\Setup.exe" REMOVE=TRUE MODIFY=FALSE
GamingHarbor Toolbar-->E:\Documents and Settings\All Users\Data aplikací\{F444439B-B473-48E8-8DE5-4CB929C79A9F}\Setup.exe
Google Toolbar for Internet Explorer-->"E:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_223E2B8E7BAD9544.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
GTK+ 2.6.9 runtime environment-->"E:\Program Files\Common Files\GTK\2.0\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->E:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"E:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Customer Participation Program 9.0-->E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet All-In-One Software 9.0-->E:\Program Files\HP\Digital Imaging\{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}\setup\hpzscr01.exe -datfile hposcr14.dat
HP Imaging Device Functions 9.0-->E:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential 2.01-->E:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0-->E:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
ICQ6.5-->"E:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
Intel(R) Extreme Graphics Driver Software-->RUNDLL32.EXE E:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Intel(R) PRO Ethernet Adapter and Software-->Prounstl.exe
IrfanView (remove only)-->E:\Program Files\IrfanView\iv_uninstall.exe
Java(TM) 6 Update 21-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
KaraFun 1.16a-->"E:\Program Files\KaraFun\unins000.exe"
Kodek 0.16 CZ-->"E:\Program Files\Kodek CZ\unins000.exe"
LG ODD Auto Firmware Update-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{6179550A-3E7C-499E-BCC9-9E8113E0A285}\setup.exe"
Malwarebytes' Anti-Malware-->"E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee Security Scan Plus-->"E:\Program Files\McAfee Security Scan\uninstall.exe"
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->E:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"E:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"E:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"E:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Professional-->MsiExec.exe /I{00010405-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"E:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox (3.6.11)-->E:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
My Photo Index-->E:\Program Files\MyPhotoIndex\My Photo Index\Uninstall.exe
Nero Media Player-->E:\WINDOWS\UNNMP.exe /UNINSTALL
Nero OEM-->E:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
NeroVision Express 2-->E:\WINDOWS\UNNeroVision.exe /UNINSTALL
Nikon View 6-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{AAB84E83-C8DF-4752-9DFC-2E2A48EE5E9F}\setup.exe" UNINSTALL
Ogg Vorbis ACM Codec-->E:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_ACM 132 E:\WINDOWS\INF\Vorbis.inf
OLYMPUS Master 2-->MsiExec.exe /X{3A1AB8E6-748E-4B95-AA2D-FE9952EB3106}
Oprava hotfix aplikace Windows Media Player 11 (KB939683)-->"E:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Oprava Hotfix systému Windows XP (KB952287)-->"E:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Oprava Hotfix systému Windows XP (KB970653-v3)-->"E:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
PhotoFiltre-->"E:\Program Files\PhotoFiltre\Uninst.exe"
PowerDVD-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
QuickTime-->E:\WINDOWS\unvise32qt.exe E:\WINDOWS\System32\QuickTime\Uninstall.log
Search Settings 1.2.1-->MsiExec.exe /X{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
SoundMAX-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
SUPERAntiSpyware-->"E:\Program Files\SUPERAntiSpyware\Uninstall.exe"
TELL ME MORE-->"E:\Program Files\Auralog\TELL ME MORE SI PLUS\Bin\unsetup.exe" -file "E:\Program Files\Auralog\TELL ME MORE SI PLUS\unsetup.aui"
Tennis Critters Demo-->"E:\Program Files\TennisCrittersDemo\uninstall.exe"
The GIMP 2.2.8-->"E:\Program Files\GIMP-2.0\unins000.exe"
The Sims 2-->C:\ewa hra the Sims\EAUninstall.exe
visionapp OneTimePass-->MsiExec.exe /I{BFCF1FE9-C3B0-46EC-8DB5-F52447E7B665}
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->E:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 1.0.3-->E:\Program Files\VideoLAN\VLC\uninstall.exe
VobSub v2.23 (Remove Only)-->"E:\Program Files\Gabest\VobSub\uninstall.exe"
WebMate-->"E:\Program Files\InstallShield Installation Information\{40B6D0B4-301A-4020-869F-2E3936E02299}\setup.exe" -runfromtemp -l0x0005 -removeonly
Winamp Toolbar-->"E:\Program Files\Winamp Toolbar\uninstall.exe"
Windows Internet Explorer 8-->"E:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"E:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"E:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"E:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"E:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"E:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR-->E:\Program Files\WinRAR\uninstall.exe
Wise Registry Cleaner Free 5.02-->"E:\Program Files\Wise Registry Cleaner\unins000.exe"
XviD MPEG4 Video Codec (remove only)-->"E:\WINDOWS\system32\xvid-uninstall.exe"

======System event log======

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Správce vzdáleného přístupu byl změněn na: Spuštěno

Record Number: 356
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Správce vzdáleného přístupu úspěšně odeslán.

Record Number: 355
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User: MY-KOL\tom

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Telefonní subsystém byl změněn na: Spuštěno

Record Number: 354
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Načítání obrázků (WIA) byl změněn na: Spuštěno

Record Number: 353
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Služba rozpoznávání pomocí protokolu SSDP byl změněn na: Spuštěno

Record Number: 352
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

=====Application event log=====

Computer Name: MY-KOL
Event Code: 4097
Message: Aplikace E:\Program Files\Windows Media Player\wmplayer.exe vygenerovala aplikační chybu.
K chybě došlo dne 23. 11. 6169 v 12:29:57,734
Vygenerovaná výjimka: c0000005 na adrese 77C34848 (MSVCRT!Gettnames)

Record Number: 42
Source Name: DrWatson
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 1000
Message: Chybující aplikace wmplayer.exe, verze 8.0.0.4487, chybující modul msvcrt.dll, verze 7.0.2600.1106, adresa chyby 0x00034848.

Record Number: 41
Source Name: Application Error
Time Written: 19700513010148.000000+120
Event Type: Chyba
User:

Computer Name: MY-KOL
Event Code: 4097
Message: Aplikace E:\Program Files\Windows Media Player\wmplayer.exe vygenerovala aplikační chybu.
K chybě došlo dne 21. 11. 6169 v 13:43:27,406
Vygenerovaná výjimka: c0000005 na adrese 77C34848 (MSVCRT!Gettnames)

Record Number: 40
Source Name: DrWatson
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 1000
Message: Chybující aplikace wmplayer.exe, verze 8.0.0.4487, chybující modul msvcrt.dll, verze 7.0.2600.1106, adresa chyby 0x00034848.

Record Number: 39
Source Name: Application Error
Time Written: 19700514132620.000000+120
Event Type: Chyba
User:

Computer Name: MY-KOL
Event Code: 4097
Message: Aplikace E:\Program Files\Windows Media Player\wmplayer.exe vygenerovala aplikační chybu.
K chybě došlo dne 21. 11. 6169 v 13:43:17,171
Vygenerovaná výjimka: c0000005 na adrese 77C34848 (MSVCRT!Gettnames)

Record Number: 38
Source Name: DrWatson
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;E:\Program Files\Common Files\GTK\2.0\bin;E:\Program Files\ESTsoft\ALZip\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0207
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO

-----------------EOF-----------------

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: pro Motji

#3 Příspěvek od motji »

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
- přejmenujte ho na cobra.com


A omlouvám se za pozdní odpověď, jste se mi tu ztatil v zodpovězených :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 Říj 2010 09:59

Re: pro Motji

#4 Příspěvek od kolariktomas1 »

Vše proběhlo podle návodu. Věřím, že už je vše OK. Jste super a moc děkuji :) . Kdy byla ještě drobná rada jak nejlépe předejít bez větších nákladů podobné situaci bylo by to fajn. Díky za pomoc.
Obsah Combofix.txt
ComboFix 10-10-22.04 - tatka 23.10.2010 7:17.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.759.541 [GMT 2:00]
Spuštěný z: e:\documents and settings\tatka\Plocha\cobra.com.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
e:\documents and settings\tatka\Data aplikací\Dealio
e:\documents and settings\tatka\Data aplikací\Dealio\res\widgets.xml
e:\documents and settings\tatka\Data aplikací\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
e:\documents and settings\tom\Local Settings\Temporary Internet Files\_tm152.tmp
e:\documents and settings\tom\Local Settings\Temporary Internet Files\stb06759.tmp
e:\program files\Search Settings
e:\program files\Search Settings\kb128\SearchSettings.dll
e:\program files\Search Settings\kb128\SearchSettingsRes409.dll
e:\program files\Search Settings\SearchSettings.exe
e:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-23 do 2010-10-23 )))))))))))))))))))))))))))))))
.

6169-11-24 00:14 . 6169-11-24 00:14 -------- d-----w- e:\documents and settings\tatka\Local Settings\Data aplikací\Identities
6169-11-23 22:54 . 6169-11-23 22:54 -------- d-----w- e:\documents and settings\tatka\Data aplikací\MSN6
6169-11-23 22:54 . 6169-11-23 22:54 -------- d-----w- e:\documents and settings\All Users\Data aplikací\MSN6
6169-11-23 22:35 . 2009-10-04 06:18 -------- d-----w- E:\Netgear
6169-11-23 12:04 . 2009-04-28 20:20 44944 ------w- e:\windows\system32\drivers\PxHelp20.sys
6169-11-23 12:04 . 2010-04-06 16:45 -------- d-----w- e:\program files\Winamp
6169-11-23 11:43 . 2002-06-19 18:15 155648 ----a-w- e:\windows\system32\igfxres.dll
6169-11-23 11:33 . 2008-04-13 19:16 141056 -c--a-w- e:\windows\system32\dllcache\ks.sys
6169-11-23 11:33 . 2008-04-13 19:16 141056 ----a-w- e:\windows\system32\drivers\ks.sys
6169-11-23 11:33 . 2008-04-13 18:45 60160 -c--a-w- e:\windows\system32\dllcache\drmk.sys
6169-11-23 11:33 . 2008-04-13 18:45 60160 ----a-w- e:\windows\system32\drivers\drmk.sys
6169-11-23 11:33 . 2008-04-13 19:19 146048 -c--a-w- e:\windows\system32\dllcache\portcls.sys
6169-11-23 11:33 . 2008-04-13 19:19 146048 ----a-w- e:\windows\system32\drivers\portcls.sys
6169-11-23 11:33 . 2008-04-13 18:45 49408 -c--a-w- e:\windows\system32\dllcache\stream.sys
6169-11-23 11:33 . 2008-04-13 18:45 49408 ----a-w- e:\windows\system32\drivers\stream.sys
6169-11-23 11:33 . 2008-04-14 03:21 4096 -c--a-w- e:\windows\system32\dllcache\ksuser.dll
6169-11-23 11:33 . 2008-04-14 03:21 4096 ----a-w- e:\windows\system32\ksuser.dll
6169-11-23 11:33 . 2008-04-14 03:22 129536 ----a-w- e:\windows\system32\ksproxy.ax
2010-10-22 13:47 . 2010-10-22 13:47 -------- d-----w- e:\program files\trend micro
2010-10-22 13:47 . 2010-10-22 13:48 -------- d-----w- E:\rsit
2010-10-14 18:23 . 2010-10-14 18:23 -------- d-----w- e:\documents and settings\tom\Data aplikací\SUPERAntiSpyware.com
2010-10-14 18:23 . 2010-10-14 18:23 -------- d-----w- e:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-10-14 18:23 . 2010-10-14 18:23 -------- d-----w- e:\program files\SUPERAntiSpyware
2010-10-09 08:24 . 2010-10-22 13:01 16856 ----a-w- e:\program files\Mozilla Firefox\plugin-container.exe
2010-10-09 08:23 . 2010-10-22 13:01 719832 ----a-w- e:\program files\Mozilla Firefox\mozcpp19.dll
2010-09-28 15:41 . 2010-09-28 15:41 -------- d-----w- e:\documents and settings\záloha reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 17:33 . 2010-09-01 17:33 1409 ----a-w- e:\windows\QTFont.for
2009-09-12 21:05 . 2009-09-12 21:05 124240 ----a-w- e:\program files\mozilla firefox\plugins\CCMSDK.dll
2009-09-12 21:06 . 2009-09-12 21:06 13136 ----a-w- e:\program files\mozilla firefox\plugins\cgpcfg.dll
2009-09-12 21:06 . 2009-09-12 21:06 70488 ----a-w- e:\program files\mozilla firefox\plugins\CgpCore.dll
2009-09-12 21:06 . 2009-09-12 21:06 91480 ----a-w- e:\program files\mozilla firefox\plugins\confmgr.dll
2009-09-12 21:06 . 2009-09-12 21:06 22360 ----a-w- e:\program files\mozilla firefox\plugins\ctxlogging.dll
2009-09-12 21:07 . 2009-09-12 21:07 255312 ----a-w- e:\program files\mozilla firefox\plugins\ctxmui.dll
2009-09-12 21:06 . 2009-09-12 21:06 31064 ----a-w- e:\program files\mozilla firefox\plugins\icafile.dll
2009-09-12 21:06 . 2009-09-12 21:06 40280 ----a-w- e:\program files\mozilla firefox\plugins\icalogon.dll
2009-08-14 11:33 . 2009-08-14 11:33 652640 ----a-w- e:\program files\mozilla firefox\plugins\sslsdk_b.dll
2009-09-12 21:06 . 2009-09-12 21:06 23896 ----a-w- e:\program files\mozilla firefox\plugins\TcpPServ.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-08 39408]
"OM2_Monitor"="e:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-11-25 95632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="e:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="e:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"HP Software Update"="e:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"RemoteControl"="e:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="e:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"LGODDFU"="e:\program files\lg_fwupdate\fwupdate.exe" [2010-07-18 557056]
"WinampAgent"="e:\program files\Winamp\winampa.exe" [2010-01-13 37888]
"PAC207_Monitor"="e:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="e:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"DC1300 Monitor"="e:\program files\DC1300\DCMnt1_0\DC1300mi.exe" [2009-03-04 45056]
"NeroFilterCheck"="e:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"OM2_Monitor"="e:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-11-25 54672]
"ConnectionCenter"="e:\program files\Citrix\ICA Client\concentr.exe" [2009-09-12 103768]
"DynamicUSB"="e:\program files\DynamicUSBTool\DynamicUSB.exe" [2007-03-02 94208]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

e:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
McAfee Security Scan Plus.lnk - e:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Microsoft Office.lnk - e:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
NkvMon.exe.lnk - e:\program files\Nikon\NkView6\NkvMon.exe [2002-8-28 233472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- e:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\WINDOWS\\system32\\sessmgr.exe"=
"e:\\Program Files\\ICQ6.5\\ICQ.exe"=
"e:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Documents and Settings\\tom\\Dokumenty\\Stažené soubory\\BULANCI.EXE"=
"e:\\WINDOWS\\system32\\dplaysvr.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Skupiny sítě Peer-to-Peer
"3540:UDP"= 3540:UDP:Protokol PNRP (Peer Name Resolution Protocol)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 ctxusbm;Citrix USB Monitor Driver;e:\windows\system32\drivers\ctxusbm.sys [8.9.2009 18:13 65584]
R1 SASDIFSV;SASDIFSV;e:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;e:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
S2 gupdate;Služba Google Update (gupdate);e:\program files\Google\Update\GoogleUpdate.exe [22.2.2010 22:38 135664]
S3 DC1300;DC 1300 WDM Video Capture;e:\windows\system32\drivers\Bsc504av.sys [4.3.2009 21:54 515365]
S3 INIDVD;Initio USB DVD Filter Driver;e:\windows\system32\drivers\inidvd.sys [11.11.2008 18:41 7936]
S3 McComponentHostService;McAfee Security Scan Component Host Service;e:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 14:49 227232]
S3 PAC207;e-Messenger 112;e:\windows\system32\drivers\PFC027.SYS [17.1.2009 18:34 616064]
S4 sptd;sptd;e:\windows\system32\drivers\sptd.sys [21.10.2008 15:17 717296]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Obsah adresáře 'Naplánované úlohy'

2010-10-23 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-02-22 20:38]

2010-10-23 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-02-22 20:38]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Winamp Search - e:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Crawler Search - tbr:iemenu
Trusted Zone: cpas.cz\czcscisa201
Trusted Zone: cpas.cz\moje
Trusted Zone: mojebanka.cz\www
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - e:\progra~1\Crawler\ctbr.dll
DPF: DirectAnimation Java Classes - file://e:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file:///E:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - e:\documents and settings\tatka\Data aplikací\Mozilla\Firefox\Profiles\9m90hyqr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://www.crawler.com/search/dispatcher.aspx? ... 60076&qkw=
FF - component: e:\documents and settings\tatka\Data aplikací\Mozilla\Firefox\Profiles\9m90hyqr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: e:\program files\Crawler\firefox\components\xcomm.dll
FF - component: e:\program files\Crawler\firefox\components\xshared.dll
FF - component: e:\program files\Crawler\firefox\components\xsupport.dll
FF - component: e:\program files\Crawler\firefox\components\xwsg.dll
FF - plugin: e:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: e:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npwachk.dll

---- NASTAVENÍ FIREFOXU ----
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
e:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Toolbar-Locked - (no file)
HKCU-Run-SpywareTerminatorUpdate - e:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM-Run-SearchSettings - e:\program files\Search Settings\SearchSettings.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-23 07:24
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\INIDVD]
"ImagePath"=multi:"system32\DRIVERS\inidvd.sys\00"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\INIDVD]
"ImagePath"=multi:"system32\DRIVERS\inidvd.sys\00"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(724)
e:\program files\SUPERAntiSpyware\SASWINLO.DLL
e:\program files\Citrix\ICA Client\pnsson.dll
e:\windows\system32\vorbis.dll
e:\windows\system32\ogg.dll

- - - - - - - > 'lsass.exe'(780)
e:\windows\system32\vorbis.dll
e:\windows\system32\ogg.dll
.
Celkový čas: 2010-10-23 07:27:17
ComboFix-quarantined-files.txt 2010-10-23 05:27

Před spuštěním: Volných bajtů: 18 607 779 840
Po spuštění: Volných bajtů: 19 767 238 656

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 4DA0652CB0465AC97E61641D695A7B64

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: pro Motji

#5 Příspěvek od motji »

:o Máte nějaké divné datum, dělal jste s tím něco? Pro jistotu zkontroolijte pc ještě s mbamem. Jinak už je v pořádku? Které pc jste nechal připojené k síti?
6169-11-23 22:54 . 6169-11-23 22:54 -------- d-----w- e:\documents and settings\tatka\Data aplikací\MSN6

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 Říj 2010 09:59

Re: pro Motji

#6 Příspěvek od kolariktomas1 »

ne ne omlouvam se, odpovidal tatka, ktery si myslel, ze uz je vse v poradku, jeste je stim neco v spatne...
posilam log s mbam:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

23.10.2010 9:06:33
mbam-log-2010-10-23 (09-06-33).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 277506
Time elapsed: 1 hour(s), 1 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25b44baa-2a26-414b-9934-2033cdc4e16e}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

detokovalo ty opet tyhle dva trojske kone, ty se vraci opetovne. nekdy jsou tri.

od site mam odpojeny notebook protoze ten mam odvirovany jede vse v poradku ale s timto stolnim pc mam problem. po odpojeni od site bych nemohl komunikovat s vami a pouzivam ho i pracovne .... takze muzu vse zopakovat jeste vecer az uz nebude potreba byt pripojeny na net a nechat ho odpojeny pres nedeli....

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: pro Motji

#7 Příspěvek od motji »

V mbamu vše smažte.
Bylo by potřeba znovu nastavit připojení k internetu - IP adresy. Máte tam právě trojana, který Vám je přepisuje.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 Říj 2010 09:59

Re: pro Motji

#8 Příspěvek od kolariktomas1 »

Toto je ma IP konfigurace ,
Jestli tomu dobře rozumím pak moje IP se generuje přes DHCP, sam umím pouze v připojení sítě spustit tzv. automatickou opravu připojení. Jsem připojen na místního providera, asi je potřeba změnu IP žádat u něho? Je to tak?

Fyzická adresa: 00-30-13-05-2C-47
Adresa IP: 192.168.1.3
Maska podsítě: 255.255.255.0
Výchozí brána: 192.168.1.1
Server DHCP: 192.168.1.1
Datum zapůjčení adresy IP: 25.10.2010 20:20:23
Zapůjčení adresy IP vyprší: 26.10.2010 16:32:56
Servery DNS: 85.255.112.174, 85.255.112.201
Server WINS:

Trojan se objevuje opakovaně v registru viz LOG. níže. Je nutno se odpojit při testování na VIRY vždy od sítě?

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

24.10.2010 12:50:20
mbam-log-2010-10-24 (12-50-20).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 275754
Time elapsed: 1 hour(s), 17 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25b44baa-2a26-414b-9934-2033cdc4e16e}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Děkuji za napovězení dalšího postupu Jirka Tomášův otec

Avatar uživatele
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 Říj 2008 08:02

Re: pro Motji

#9 Příspěvek od motji »

V mbamu vše smažte.

Servery DNS: 85.255.112.174, 85.255.112.201
tohle určitě nejsou Vaše IP adresy, jedině že by jste měl providera na Ukrajině :D .

Ted jsem zapoměla, jak to máte s připojením - tuším přes router? Resetujte router do výchozího nastavení, odpojte kabel od pc a zase připojte. A pak se podívejte, zda se IP adresy změnili. Jestli to dobře chápu, tak by se Vám po vyresetování routeru měli sami automaticky načíst.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět