pro vyosek - PC2
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
pro vyosek - PC2
Logfile of random's system information tool 1.08 (written by random/random)
Run by PEPA NETBOOK at 2010-10-31 13:03:23
Microsoft Windows 7 Professional
System drive C: has 7 GB (33%) free of 20 GB
Total RAM: 2039 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:05:20, on 31.10.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Brownie\BrStsWnd.exe
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Brownie\Brnipmon.exe
C:\Windows\Explorer.exe
C:\Program Files\Opera\opera.exe
C:\Users\PEPA NETBOOK\Desktop\RSIT.exe
C:\Program Files\trend micro\PEPA NETBOOK.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [HotkeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - HKLM\..\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [Norton Ghost 15.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Asus Launcher Service (AsusService) - Unknown owner - C:\Windows\System32\AsusService.exe
O23 - Service: GenericMount Helper Service - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
--
End of file - 5275 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-10-30 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-09-27 1250696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-10-30 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"HotkeyMon"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe []
"HotkeyService"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe []
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 497024]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-09-15 1094224]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"BrStsWnd"=C:\Program Files\Brownie\BrstsWnd.exe [2008-09-18 880640]
"Norton Ghost 15.0"=C:\Program Files\Norton Ghost\Agent\VProTray.exe [2009-10-01 2596712]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-10-11 14940040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-10-31 12:18:32 ----D---- C:\Program Files\trend micro
2010-10-31 12:18:30 ----D---- C:\rsit
2010-10-31 12:13:00 ----D---- C:\Windows\temp
2010-10-31 12:12:56 ----A---- C:\ComboFix.txt
2010-10-31 12:11:31 ----SHD---- C:\$RECYCLE.BIN
2010-10-31 11:18:55 ----A---- C:\Windows\MBR.exe
2010-10-31 11:18:54 ----A---- C:\Windows\zip.exe
2010-10-31 11:18:54 ----A---- C:\Windows\SWREG.exe
2010-10-31 11:18:54 ----A---- C:\Windows\sed.exe
2010-10-31 11:18:54 ----A---- C:\Windows\PEV.exe
2010-10-31 11:18:54 ----A---- C:\Windows\NIRCMD.exe
2010-10-31 11:18:54 ----A---- C:\Windows\grep.exe
2010-10-31 11:18:53 ----A---- C:\Windows\SWSC.exe
2010-10-31 11:17:16 ----A---- C:\Windows\SWXCACLS.exe
2010-10-31 11:14:44 ----D---- C:\Windows\ERDNT
2010-10-31 11:11:36 ----D---- C:\Qoobox
2010-10-31 08:41:49 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Macromedia
2010-10-31 08:41:48 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Adobe
2010-10-31 07:52:30 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Symantec
2010-10-31 07:43:26 ----A---- C:\Windows\system32\drivers\WimFltr.sys
2010-10-31 07:41:52 ----A---- C:\Windows\system32\drivers\symsnap.sys
2010-10-31 07:41:32 ----A---- C:\Windows\system32\drivers\vproeventmonitor.sys
2010-10-31 07:41:08 ----DC---- C:\Windows\system32\DRVSTORE
2010-10-31 07:41:08 ----A---- C:\Windows\system32\GEARAspi.dll
2010-10-31 07:41:08 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2010-10-31 07:38:50 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-10-31 07:37:29 ----D---- C:\ProgramData\Symantec
2010-10-31 07:37:29 ----D---- C:\ProgramData\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-10-31 07:37:29 ----D---- C:\Program Files\Norton Ghost
2010-10-31 06:54:07 ----D---- C:\Program Files\foxitreader
2010-10-30 21:53:26 ----D---- C:\Windows\system32\Wat
2010-10-30 21:52:13 ----D---- C:\Windows\system32\Macromed
2010-10-30 21:48:55 ----A---- C:\Windows\system32\msv1_0.dll
2010-10-30 21:45:29 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-10-30 21:45:28 ----A---- C:\Windows\system32\PresentationHost.exe
2010-10-30 21:45:28 ----A---- C:\Windows\system32\netfxperf.dll
2010-10-30 21:45:28 ----A---- C:\Windows\system32\mscoree.dll
2010-10-30 21:45:28 ----A---- C:\Windows\system32\dfshim.dll
2010-10-30 21:40:29 ----D---- C:\Program Files\Microsoft Silverlight
2010-10-30 21:38:11 ----A---- C:\Windows\BRVIDEO.INI
2010-10-30 21:38:11 ----A---- C:\Windows\brmx2001.ini
2010-10-30 21:38:08 ----A---- C:\Windows\BRWMARK.INI
2010-10-30 21:37:29 ----N---- C:\Windows\system32\brlmw03a.ini
2010-10-30 21:37:28 ----N---- C:\Windows\system32\brlmw03a.dll
2010-10-30 21:37:24 ----D---- C:\Program Files\Brownie
2010-10-30 21:37:24 ----A---- C:\Windows\HL-2150N.INI
2010-10-30 21:37:05 ----A---- C:\Windows\system32\BRRBTOOL.EXE
2010-10-30 21:37:05 ----A---- C:\Windows\system32\BROSNMP.DLL
2010-10-30 21:37:04 ----N---- C:\Windows\system32\Pdrvinst.dll
2010-10-30 21:37:04 ----D---- C:\Program Files\Brother
2010-10-30 21:37:04 ----A---- C:\Windows\system32\BRLM03A.DLL
2010-10-30 21:37:03 ----N---- C:\Windows\system32\BRWEBUP.EXE
2010-10-30 21:37:03 ----N---- C:\Windows\system32\BrWebIns.dll
2010-10-30 21:36:25 ----A---- C:\Windows\Brownie.ini
2010-10-30 21:36:13 ----D---- C:\Program Files\Common Files\InstallShield
2010-10-30 21:35:09 ----A---- C:\Windows\WTRDCTM.INI
2010-10-30 21:30:30 ----D---- C:\Program Files\Translator
2010-10-30 21:30:26 ----A---- C:\Windows\system32\browserchoice.exe
2010-10-30 21:30:07 ----D---- C:\ProgramData\LangSoft
2010-10-30 21:29:51 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\LangSoft
2010-10-30 21:28:14 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Opera
2010-10-30 21:27:50 ----D---- C:\Program Files\Opera
2010-10-30 21:27:18 ----A---- C:\Windows\system32\MRT.exe
2010-10-30 21:26:35 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2010-10-30 21:26:20 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2010-10-30 21:26:20 ----A---- C:\Windows\system32\drivers\ks.sys
2010-10-30 21:26:14 ----D---- C:\Program Files\WinRAR
2010-10-30 21:23:45 ----A---- C:\Windows\system32\ntdll.dll
2010-10-30 21:23:44 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-10-30 21:23:25 ----A---- C:\Windows\system32\drivers\fvevol.sys
2010-10-30 21:23:09 ----A---- C:\Windows\system32\secproc_isv.dll
2010-10-30 21:23:09 ----A---- C:\Windows\system32\secproc.dll
2010-10-30 21:23:08 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-10-30 21:23:08 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-10-30 21:23:08 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-10-30 21:23:08 ----A---- C:\Windows\system32\RMActivate.exe
2010-10-30 21:23:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-10-30 21:23:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-10-30 21:23:02 ----D---- C:\Program Files\Zoner
2010-10-30 21:22:59 ----A---- C:\Windows\system32\CPFilters.dll
2010-10-30 21:22:58 ----A---- C:\Windows\system32\msdri.dll
2010-10-30 21:22:56 ----A---- C:\Windows\system32\psisdecd.dll
2010-10-30 21:15:20 ----D---- C:\Program Files\Microsoft Works
2010-10-30 21:14:37 ----D---- C:\Program Files\Microsoft Visual Studio
2010-10-30 21:14:35 ----D---- C:\Program Files\Common Files\DESIGNER
2010-10-30 21:13:40 ----D---- C:\Windows\PCHEALTH
2010-10-30 21:13:40 ----D---- C:\Program Files\Microsoft.NET
2010-10-30 21:07:47 ----D---- C:\Program Files\Microsoft Office
2010-10-30 21:07:46 ----D---- C:\ProgramData\Microsoft Help
2010-10-30 21:07:10 ----RD---- C:\MSOCache
2010-10-30 20:59:09 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\skypePM
2010-10-30 20:58:53 ----A---- C:\Windows\system32\ole32.dll
2010-10-30 20:58:51 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-10-30 20:58:35 ----A---- C:\Windows\system32\spoolsv.exe
2010-10-30 20:58:32 ----A---- C:\Windows\system32\mshtml.dll
2010-10-30 20:58:29 ----A---- C:\Windows\system32\ieframe.dll
2010-10-30 20:58:28 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-30 20:58:28 ----A---- C:\Windows\system32\iertutil.dll
2010-10-30 20:58:27 ----A---- C:\Windows\system32\mstime.dll
2010-10-30 20:58:26 ----A---- C:\Windows\system32\urlmon.dll
2010-10-30 20:58:25 ----A---- C:\Windows\system32\wininet.dll
2010-10-30 20:58:25 ----A---- C:\Windows\system32\licmgr10.dll
2010-10-30 20:58:25 ----A---- C:\Windows\system32\iedkcs32.dll
2010-10-30 20:58:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-10-30 20:58:24 ----A---- C:\Windows\system32\iepeers.dll
2010-10-30 20:58:23 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-30 20:58:23 ----A---- C:\Windows\system32\jsproxy.dll
2010-10-30 20:58:23 ----A---- C:\Windows\system32\ieui.dll
2010-10-30 20:58:22 ----A---- C:\Windows\system32\msfeedssync.exe
2010-10-30 20:57:59 ----A---- C:\Windows\system32\inetcomm.dll
2010-10-30 20:57:57 ----A---- C:\Windows\system32\winlogon.exe
2010-10-30 20:57:57 ----A---- C:\Windows\explorer.exe
2010-10-30 20:57:52 ----A---- C:\Windows\system32\rtutils.dll
2010-10-30 20:57:48 ----A---- C:\Windows\system32\iccvid.dll
2010-10-30 20:57:47 ----A---- C:\Windows\system32\ir32_32.dll
2010-10-30 20:57:42 ----A---- C:\Windows\system32\lsasrv.dll
2010-10-30 20:57:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2010-10-30 20:57:36 ----A---- C:\Windows\system32\tzres.dll
2010-10-30 20:57:24 ----A---- C:\Windows\system32\t2embed.dll
2010-10-30 20:57:20 ----A---- C:\Windows\system32\schannel.dll
2010-10-30 20:57:19 ----A---- C:\Windows\system32\msasn1.dll
2010-10-30 20:57:18 ----A---- C:\Windows\system32\msxml3.dll
2010-10-30 20:57:12 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2010-10-30 20:57:12 ----A---- C:\Windows\system32\CertEnroll.dll
2010-10-30 20:57:11 ----A---- C:\Windows\system32\winresume.exe
2010-10-30 20:57:11 ----A---- C:\Windows\system32\winload.exe
2010-10-30 20:56:43 ----A---- C:\Windows\system32\asycfilt.dll
2010-10-30 20:56:04 ----D---- C:\Program Files\Common Files\Skype
2010-10-30 20:55:45 ----RD---- C:\Program Files\Skype
2010-10-30 20:55:44 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Skype
2010-10-30 20:55:38 ----D---- C:\ProgramData\Skype
2010-10-30 20:54:17 ----D---- C:\Program Files\Ask.com
2010-10-30 20:53:29 ----A---- C:\Windows\system32\comctl32.dll
2010-10-30 20:53:26 ----A---- C:\Windows\system32\mfc40u.dll
2010-10-30 20:53:26 ----A---- C:\Windows\system32\mfc40.dll
2010-10-30 20:53:20 ----D---- C:\Program Files\The KMPlayer
2010-10-30 20:52:31 ----A---- C:\Windows\system32\wmp.dll
2010-10-30 20:52:27 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-30 20:52:21 ----A---- C:\Windows\system32\jscript.dll
2010-10-30 20:52:16 ----A---- C:\Windows\system32\kernel32.dll
2010-10-30 20:52:15 ----A---- C:\Windows\system32\apphelp.dll
2010-10-30 20:52:12 ----A---- C:\Windows\system32\quartz.dll
2010-10-30 20:52:12 ----A---- C:\Windows\system32\msvidc32.dll
2010-10-30 20:52:12 ----A---- C:\Windows\system32\mciavi32.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\msyuv.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\msrle32.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\iyuv_32.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\avifil32.dll
2010-10-30 20:52:10 ----A---- C:\Windows\system32\tsbyuv.dll
2010-10-30 20:52:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-10-30 20:52:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-10-30 20:52:02 ----A---- C:\Windows\system32\shell32.dll
2010-10-30 20:52:00 ----A---- C:\Windows\system32\win32k.sys
2010-10-30 20:51:23 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-30 20:51:23 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-30 20:51:22 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-30 20:51:22 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-30 20:51:18 ----A---- C:\Windows\system32\wmpmde.dll
2010-10-30 20:51:16 ----A---- C:\Windows\system32\vbscript.dll
2010-10-30 20:51:14 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-10-30 20:51:13 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2010-10-30 20:51:13 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2010-10-30 20:51:13 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2010-10-30 20:50:41 ----SHD---- C:\System Volume Information
2010-10-30 20:49:32 ----D---- C:\Windows\Panther
2010-10-30 20:48:07 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Win7codecs
2010-10-30 20:47:50 ----D---- C:\Program Files\Win7codecs
2010-10-30 20:46:44 ----D---- C:\ProgramData\Win7codecs
2010-10-30 20:41:10 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-10-30 20:40:10 ----D---- C:\Program Files\DAEMON Tools Lite
2010-10-30 20:39:51 ----A---- C:\Windows\system32\fontsub.dll
2010-10-30 20:39:51 ----A---- C:\Windows\system32\atmlib.dll
2010-10-30 20:39:51 ----A---- C:\Windows\system32\atmfd.dll
2010-10-30 20:39:35 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\DAEMON Tools Lite
2010-10-30 20:39:27 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-10-30 20:36:50 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-30 20:35:07 ----D---- C:\Windows\system32\x64
2010-10-30 20:35:07 ----A---- C:\Windows\system32\igxpun.exe
2010-10-30 20:33:28 ----A---- C:\Windows\system32\wintrust.dll
2010-10-30 20:33:18 ----A---- C:\Windows\system32\cabview.dll
2010-10-30 20:31:39 ----D---- C:\Program Files\Microsoft Security Essentials
2010-10-30 20:31:23 ----SHD---- C:\Windows\Installer
2010-10-30 20:27:57 ----D---- C:\Program Files\Elantech
2010-10-30 20:27:41 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\InstallShield
2010-10-30 20:23:44 ----A---- C:\Windows\system32\AsusService.exe
2010-10-30 20:23:44 ----A---- C:\Windows\system32\AsusSender.exe
2010-10-30 20:23:44 ----A---- C:\Windows\AsAcpiSvrLang.ini
2010-10-30 20:22:02 ----D---- C:\Program Files\EeePC
2010-10-30 20:22:01 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-30 20:21:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-10-30 20:17:21 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Identities
2010-10-30 20:16:29 ----SD---- C:\Users\PEPA NETBOOK\AppData\Roaming\Microsoft
2010-10-30 20:16:29 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Media Center Programs
2010-10-30 20:13:35 ----D---- C:\Recovery
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Šablony
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Plocha
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Oblíbené položky
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Nabídka Start
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Dokumenty
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Data aplikací
2010-10-30 20:08:50 ----A---- C:\Windows\system32\drivers\ETD.sys
2010-10-30 20:08:49 ----A---- C:\Windows\system32\drivers\kbfiltr.sys
2010-10-30 20:06:51 ----D---- C:\Windows\SoftwareDistribution
2010-10-30 20:03:53 ----D---- C:\Windows\Prefetch
2010-10-30 20:03:23 ----ASH---- C:\pagefile.sys
2010-10-30 20:03:23 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2010-10-31 12:20:44 ----D---- C:\Windows\system32\config
2010-10-31 12:18:32 ----RD---- C:\Program Files
2010-10-31 12:13:03 ----D---- C:\Windows\system32\drivers
2010-10-31 12:13:00 ----D---- C:\Windows
2010-10-31 12:12:22 ----D---- C:\Windows\System32
2010-10-31 12:12:21 ----D---- C:\Windows\inf
2010-10-31 12:07:25 ----A---- C:\Windows\system.ini
2010-10-31 12:06:47 ----D---- C:\Windows\system32\drivers\etc
2010-10-31 12:02:51 ----D---- C:\Windows\system32\wdi
2010-10-31 11:48:02 ----D---- C:\Windows\AppPatch
2010-10-31 11:47:57 ----D---- C:\Program Files\Common Files
2010-10-31 07:43:15 ----D---- C:\Windows\winsxs
2010-10-31 07:42:41 ----D---- C:\Windows\Registration
2010-10-31 07:41:53 ----D---- C:\Windows\system32\catroot
2010-10-31 07:41:12 ----D---- C:\Windows\system32\DriverStore
2010-10-31 07:37:29 ----D---- C:\ProgramData
2010-10-31 07:23:03 ----D---- C:\Windows\Microsoft.NET
2010-10-31 07:22:31 ----RSD---- C:\Windows\assembly
2010-10-30 21:53:32 ----D---- C:\Windows\system32\migration
2010-10-30 21:53:32 ----D---- C:\Program Files\Internet Explorer
2010-10-30 21:53:31 ----D---- C:\Windows\system32\cs-CZ
2010-10-30 21:53:30 ----D---- C:\Windows\ehome
2010-10-30 21:53:30 ----D---- C:\Program Files\Windows Mail
2010-10-30 21:53:29 ----D---- C:\Windows\system32\Boot
2010-10-30 21:53:28 ----D---- C:\Program Files\Windows Media Player
2010-10-30 21:49:11 ----D---- C:\Windows\system32\catroot2
2010-10-30 21:41:47 ----SD---- C:\ProgramData\Microsoft
2010-10-30 21:27:20 ----D---- C:\Windows\debug
2010-10-30 21:15:13 ----D---- C:\Program Files\Common Files\microsoft shared
2010-10-30 21:14:02 ----RSD---- C:\Windows\Fonts
2010-10-30 21:09:15 ----D---- C:\Windows\ShellNew
2010-10-30 20:58:04 ----D---- C:\Windows\system32\Tasks
2010-10-30 20:48:56 ----D---- C:\Windows\Setup
2010-10-30 20:38:46 ----D---- C:\Windows\system32\CodeIntegrity
2010-10-30 20:32:42 ----D---- C:\Windows\Logs
2010-10-30 20:21:28 ----D---- C:\Windows\system32\restore
2010-10-30 20:20:57 ----D---- C:\Windows\system32\wbem
2010-10-30 20:16:28 ----RD---- C:\Users
2010-10-30 20:13:34 ----D---- C:\Program Files\Windows NT
2010-10-30 20:12:42 ----D---- C:\Windows\rescache
2010-10-30 20:08:58 ----D---- C:\Windows\system32\sysprep
2010-10-30 20:06:48 ----D---- C:\Windows\system32\drivers\UMDF
2010-10-30 20:04:32 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-30 691696]
R0 symsnap;Symantec Volume Snap Shot Driver; C:\Windows\system32\DRIVERS\symsnap.sys [2009-09-21 138592]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
R3 GEARAspiWDM;GearAspiWDM; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 GenericMount;Generic Mount Driver; C:\Windows\system32\DRIVERS\GenericMount.sys [2009-09-21 46192]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-07-13 47104]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 ac33nobg;ac33nobg; C:\Windows\system32\drivers\ac33nobg.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 catchme;catchme; \??\C:\Users\PEPANE~1\AppData\Local\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\Users\PEPANE~1\AppData\Local\Temp\mbr.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 VProEventMonitor;Symantec Event Monitor Driver; C:\Windows\system32\DRIVERS\vproeventmonitor.sys [2009-09-21 15096]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2009-10-01 131000]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AsusService;Asus Launcher Service; C:\Windows\System32\AsusService.exe [2009-08-18 219136]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Norton Ghost;Norton Ghost; C:\Program Files\Norton Ghost\Agent\VProSvc.exe [2009-10-01 4584288]
R3 SymSnapService;SymSnapService; C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2009-09-21 1964528]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 GenericMount Helper Service;GenericMount Helper Service; C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe [2009-09-21 1571336]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider; C:\Windows\system32\dllhost.exe [2009-07-14 7168]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-30 1343400]
-----------------EOF-----------------
Run by PEPA NETBOOK at 2010-10-31 13:03:23
Microsoft Windows 7 Professional
System drive C: has 7 GB (33%) free of 20 GB
Total RAM: 2039 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:05:20, on 31.10.2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Brownie\BrStsWnd.exe
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Brownie\Brnipmon.exe
C:\Windows\Explorer.exe
C:\Program Files\Opera\opera.exe
C:\Users\PEPA NETBOOK\Desktop\RSIT.exe
C:\Program Files\trend micro\PEPA NETBOOK.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\ProgramData\LangSoft\WebIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: PandoraTV Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\ProgramData\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [SuperHybridEngine] AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe
O4 - HKLM\..\Run: [HotkeyMon] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe
O4 - HKLM\..\Run: [HotkeyService] AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [Norton Ghost 15.0] "C:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\ProgramData\LangSoft\WebIE.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Asus Launcher Service (AsusService) - Unknown owner - C:\Windows\System32\AsusService.exe
O23 - Service: GenericMount Helper Service - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
--
End of file - 5275 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\ProgramData\LangSoft\WebIE.dll [2010-10-30 798771]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-09-27 1250696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D4027C7F-154A-4066-A1AD-4243D8127440} - PandoraTV Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2010-02-04 1197448]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\ProgramData\LangSoft\WebIE.dll [2010-10-30 798771]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SuperHybridEngine"=AsusSender.exe C:\Program Files\EeePC\SHE\SuperHybridEngine.exe []
"HotkeyMon"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe []
"HotkeyService"=AsusSender.exe C:\Program Files\EeePC\HotkeyService\HotkeyService.exe []
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-07-30 497024]
"MSSE"=C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-09-15 1094224]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-23 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-23 173592]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-23 150552]
"BrStsWnd"=C:\Program Files\Brownie\BrstsWnd.exe [2008-09-18 880640]
"Norton Ghost 15.0"=C:\Program Files\Norton Ghost\Agent\VProTray.exe [2009-10-01 2596712]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-10-11 14940040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-23 218112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2010-10-31 12:18:32 ----D---- C:\Program Files\trend micro
2010-10-31 12:18:30 ----D---- C:\rsit
2010-10-31 12:13:00 ----D---- C:\Windows\temp
2010-10-31 12:12:56 ----A---- C:\ComboFix.txt
2010-10-31 12:11:31 ----SHD---- C:\$RECYCLE.BIN
2010-10-31 11:18:55 ----A---- C:\Windows\MBR.exe
2010-10-31 11:18:54 ----A---- C:\Windows\zip.exe
2010-10-31 11:18:54 ----A---- C:\Windows\SWREG.exe
2010-10-31 11:18:54 ----A---- C:\Windows\sed.exe
2010-10-31 11:18:54 ----A---- C:\Windows\PEV.exe
2010-10-31 11:18:54 ----A---- C:\Windows\NIRCMD.exe
2010-10-31 11:18:54 ----A---- C:\Windows\grep.exe
2010-10-31 11:18:53 ----A---- C:\Windows\SWSC.exe
2010-10-31 11:17:16 ----A---- C:\Windows\SWXCACLS.exe
2010-10-31 11:14:44 ----D---- C:\Windows\ERDNT
2010-10-31 11:11:36 ----D---- C:\Qoobox
2010-10-31 08:41:49 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Macromedia
2010-10-31 08:41:48 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Adobe
2010-10-31 07:52:30 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Symantec
2010-10-31 07:43:26 ----A---- C:\Windows\system32\drivers\WimFltr.sys
2010-10-31 07:41:52 ----A---- C:\Windows\system32\drivers\symsnap.sys
2010-10-31 07:41:32 ----A---- C:\Windows\system32\drivers\vproeventmonitor.sys
2010-10-31 07:41:08 ----DC---- C:\Windows\system32\DRVSTORE
2010-10-31 07:41:08 ----A---- C:\Windows\system32\GEARAspi.dll
2010-10-31 07:41:08 ----A---- C:\Windows\system32\drivers\GEARAspiWDM.sys
2010-10-31 07:38:50 ----D---- C:\Program Files\Common Files\Symantec Shared
2010-10-31 07:37:29 ----D---- C:\ProgramData\Symantec
2010-10-31 07:37:29 ----D---- C:\ProgramData\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-10-31 07:37:29 ----D---- C:\Program Files\Norton Ghost
2010-10-31 06:54:07 ----D---- C:\Program Files\foxitreader
2010-10-30 21:53:26 ----D---- C:\Windows\system32\Wat
2010-10-30 21:52:13 ----D---- C:\Windows\system32\Macromed
2010-10-30 21:48:55 ----A---- C:\Windows\system32\msv1_0.dll
2010-10-30 21:45:29 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-10-30 21:45:28 ----A---- C:\Windows\system32\PresentationHost.exe
2010-10-30 21:45:28 ----A---- C:\Windows\system32\netfxperf.dll
2010-10-30 21:45:28 ----A---- C:\Windows\system32\mscoree.dll
2010-10-30 21:45:28 ----A---- C:\Windows\system32\dfshim.dll
2010-10-30 21:40:29 ----D---- C:\Program Files\Microsoft Silverlight
2010-10-30 21:38:11 ----A---- C:\Windows\BRVIDEO.INI
2010-10-30 21:38:11 ----A---- C:\Windows\brmx2001.ini
2010-10-30 21:38:08 ----A---- C:\Windows\BRWMARK.INI
2010-10-30 21:37:29 ----N---- C:\Windows\system32\brlmw03a.ini
2010-10-30 21:37:28 ----N---- C:\Windows\system32\brlmw03a.dll
2010-10-30 21:37:24 ----D---- C:\Program Files\Brownie
2010-10-30 21:37:24 ----A---- C:\Windows\HL-2150N.INI
2010-10-30 21:37:05 ----A---- C:\Windows\system32\BRRBTOOL.EXE
2010-10-30 21:37:05 ----A---- C:\Windows\system32\BROSNMP.DLL
2010-10-30 21:37:04 ----N---- C:\Windows\system32\Pdrvinst.dll
2010-10-30 21:37:04 ----D---- C:\Program Files\Brother
2010-10-30 21:37:04 ----A---- C:\Windows\system32\BRLM03A.DLL
2010-10-30 21:37:03 ----N---- C:\Windows\system32\BRWEBUP.EXE
2010-10-30 21:37:03 ----N---- C:\Windows\system32\BrWebIns.dll
2010-10-30 21:36:25 ----A---- C:\Windows\Brownie.ini
2010-10-30 21:36:13 ----D---- C:\Program Files\Common Files\InstallShield
2010-10-30 21:35:09 ----A---- C:\Windows\WTRDCTM.INI
2010-10-30 21:30:30 ----D---- C:\Program Files\Translator
2010-10-30 21:30:26 ----A---- C:\Windows\system32\browserchoice.exe
2010-10-30 21:30:07 ----D---- C:\ProgramData\LangSoft
2010-10-30 21:29:51 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\LangSoft
2010-10-30 21:28:14 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Opera
2010-10-30 21:27:50 ----D---- C:\Program Files\Opera
2010-10-30 21:27:18 ----A---- C:\Windows\system32\MRT.exe
2010-10-30 21:26:35 ----A---- C:\Windows\system32\drivers\sffp_sd.sys
2010-10-30 21:26:20 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2010-10-30 21:26:20 ----A---- C:\Windows\system32\drivers\ks.sys
2010-10-30 21:26:14 ----D---- C:\Program Files\WinRAR
2010-10-30 21:23:45 ----A---- C:\Windows\system32\ntdll.dll
2010-10-30 21:23:44 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2010-10-30 21:23:25 ----A---- C:\Windows\system32\drivers\fvevol.sys
2010-10-30 21:23:09 ----A---- C:\Windows\system32\secproc_isv.dll
2010-10-30 21:23:09 ----A---- C:\Windows\system32\secproc.dll
2010-10-30 21:23:08 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
2010-10-30 21:23:08 ----A---- C:\Windows\system32\secproc_ssp.dll
2010-10-30 21:23:08 ----A---- C:\Windows\system32\RMActivate_isv.exe
2010-10-30 21:23:08 ----A---- C:\Windows\system32\RMActivate.exe
2010-10-30 21:23:07 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
2010-10-30 21:23:07 ----A---- C:\Windows\system32\RMActivate_ssp.exe
2010-10-30 21:23:02 ----D---- C:\Program Files\Zoner
2010-10-30 21:22:59 ----A---- C:\Windows\system32\CPFilters.dll
2010-10-30 21:22:58 ----A---- C:\Windows\system32\msdri.dll
2010-10-30 21:22:56 ----A---- C:\Windows\system32\psisdecd.dll
2010-10-30 21:15:20 ----D---- C:\Program Files\Microsoft Works
2010-10-30 21:14:37 ----D---- C:\Program Files\Microsoft Visual Studio
2010-10-30 21:14:35 ----D---- C:\Program Files\Common Files\DESIGNER
2010-10-30 21:13:40 ----D---- C:\Windows\PCHEALTH
2010-10-30 21:13:40 ----D---- C:\Program Files\Microsoft.NET
2010-10-30 21:07:47 ----D---- C:\Program Files\Microsoft Office
2010-10-30 21:07:46 ----D---- C:\ProgramData\Microsoft Help
2010-10-30 21:07:10 ----RD---- C:\MSOCache
2010-10-30 20:59:09 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\skypePM
2010-10-30 20:58:53 ----A---- C:\Windows\system32\ole32.dll
2010-10-30 20:58:51 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-10-30 20:58:35 ----A---- C:\Windows\system32\spoolsv.exe
2010-10-30 20:58:32 ----A---- C:\Windows\system32\mshtml.dll
2010-10-30 20:58:29 ----A---- C:\Windows\system32\ieframe.dll
2010-10-30 20:58:28 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-30 20:58:28 ----A---- C:\Windows\system32\iertutil.dll
2010-10-30 20:58:27 ----A---- C:\Windows\system32\mstime.dll
2010-10-30 20:58:26 ----A---- C:\Windows\system32\urlmon.dll
2010-10-30 20:58:25 ----A---- C:\Windows\system32\wininet.dll
2010-10-30 20:58:25 ----A---- C:\Windows\system32\licmgr10.dll
2010-10-30 20:58:25 ----A---- C:\Windows\system32\iedkcs32.dll
2010-10-30 20:58:24 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-10-30 20:58:24 ----A---- C:\Windows\system32\iepeers.dll
2010-10-30 20:58:23 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-30 20:58:23 ----A---- C:\Windows\system32\jsproxy.dll
2010-10-30 20:58:23 ----A---- C:\Windows\system32\ieui.dll
2010-10-30 20:58:22 ----A---- C:\Windows\system32\msfeedssync.exe
2010-10-30 20:57:59 ----A---- C:\Windows\system32\inetcomm.dll
2010-10-30 20:57:57 ----A---- C:\Windows\system32\winlogon.exe
2010-10-30 20:57:57 ----A---- C:\Windows\explorer.exe
2010-10-30 20:57:52 ----A---- C:\Windows\system32\rtutils.dll
2010-10-30 20:57:48 ----A---- C:\Windows\system32\iccvid.dll
2010-10-30 20:57:47 ----A---- C:\Windows\system32\ir32_32.dll
2010-10-30 20:57:42 ----A---- C:\Windows\system32\lsasrv.dll
2010-10-30 20:57:42 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2010-10-30 20:57:36 ----A---- C:\Windows\system32\tzres.dll
2010-10-30 20:57:24 ----A---- C:\Windows\system32\t2embed.dll
2010-10-30 20:57:20 ----A---- C:\Windows\system32\schannel.dll
2010-10-30 20:57:19 ----A---- C:\Windows\system32\msasn1.dll
2010-10-30 20:57:18 ----A---- C:\Windows\system32\msxml3.dll
2010-10-30 20:57:12 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2010-10-30 20:57:12 ----A---- C:\Windows\system32\CertEnroll.dll
2010-10-30 20:57:11 ----A---- C:\Windows\system32\winresume.exe
2010-10-30 20:57:11 ----A---- C:\Windows\system32\winload.exe
2010-10-30 20:56:43 ----A---- C:\Windows\system32\asycfilt.dll
2010-10-30 20:56:04 ----D---- C:\Program Files\Common Files\Skype
2010-10-30 20:55:45 ----RD---- C:\Program Files\Skype
2010-10-30 20:55:44 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Skype
2010-10-30 20:55:38 ----D---- C:\ProgramData\Skype
2010-10-30 20:54:17 ----D---- C:\Program Files\Ask.com
2010-10-30 20:53:29 ----A---- C:\Windows\system32\comctl32.dll
2010-10-30 20:53:26 ----A---- C:\Windows\system32\mfc40u.dll
2010-10-30 20:53:26 ----A---- C:\Windows\system32\mfc40.dll
2010-10-30 20:53:20 ----D---- C:\Program Files\The KMPlayer
2010-10-30 20:52:31 ----A---- C:\Windows\system32\wmp.dll
2010-10-30 20:52:27 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-30 20:52:21 ----A---- C:\Windows\system32\jscript.dll
2010-10-30 20:52:16 ----A---- C:\Windows\system32\kernel32.dll
2010-10-30 20:52:15 ----A---- C:\Windows\system32\apphelp.dll
2010-10-30 20:52:12 ----A---- C:\Windows\system32\quartz.dll
2010-10-30 20:52:12 ----A---- C:\Windows\system32\msvidc32.dll
2010-10-30 20:52:12 ----A---- C:\Windows\system32\mciavi32.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\msyuv.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\msrle32.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\iyuv_32.dll
2010-10-30 20:52:11 ----A---- C:\Windows\system32\avifil32.dll
2010-10-30 20:52:10 ----A---- C:\Windows\system32\tsbyuv.dll
2010-10-30 20:52:07 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-10-30 20:52:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-10-30 20:52:02 ----A---- C:\Windows\system32\shell32.dll
2010-10-30 20:52:00 ----A---- C:\Windows\system32\win32k.sys
2010-10-30 20:51:23 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-30 20:51:23 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-30 20:51:22 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-30 20:51:22 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-30 20:51:18 ----A---- C:\Windows\system32\wmpmde.dll
2010-10-30 20:51:16 ----A---- C:\Windows\system32\vbscript.dll
2010-10-30 20:51:14 ----A---- C:\Windows\system32\StructuredQuery.dll
2010-10-30 20:51:13 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2010-10-30 20:51:13 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2010-10-30 20:51:13 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2010-10-30 20:50:41 ----SHD---- C:\System Volume Information
2010-10-30 20:49:32 ----D---- C:\Windows\Panther
2010-10-30 20:48:07 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Win7codecs
2010-10-30 20:47:50 ----D---- C:\Program Files\Win7codecs
2010-10-30 20:46:44 ----D---- C:\ProgramData\Win7codecs
2010-10-30 20:41:10 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-10-30 20:40:10 ----D---- C:\Program Files\DAEMON Tools Lite
2010-10-30 20:39:51 ----A---- C:\Windows\system32\fontsub.dll
2010-10-30 20:39:51 ----A---- C:\Windows\system32\atmlib.dll
2010-10-30 20:39:51 ----A---- C:\Windows\system32\atmfd.dll
2010-10-30 20:39:35 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\DAEMON Tools Lite
2010-10-30 20:39:27 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-10-30 20:36:50 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-30 20:35:07 ----D---- C:\Windows\system32\x64
2010-10-30 20:35:07 ----A---- C:\Windows\system32\igxpun.exe
2010-10-30 20:33:28 ----A---- C:\Windows\system32\wintrust.dll
2010-10-30 20:33:18 ----A---- C:\Windows\system32\cabview.dll
2010-10-30 20:31:39 ----D---- C:\Program Files\Microsoft Security Essentials
2010-10-30 20:31:23 ----SHD---- C:\Windows\Installer
2010-10-30 20:27:57 ----D---- C:\Program Files\Elantech
2010-10-30 20:27:41 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\InstallShield
2010-10-30 20:23:44 ----A---- C:\Windows\system32\AsusService.exe
2010-10-30 20:23:44 ----A---- C:\Windows\system32\AsusSender.exe
2010-10-30 20:23:44 ----A---- C:\Windows\AsAcpiSvrLang.ini
2010-10-30 20:22:02 ----D---- C:\Program Files\EeePC
2010-10-30 20:22:01 ----HD---- C:\Program Files\InstallShield Installation Information
2010-10-30 20:21:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-10-30 20:17:21 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Identities
2010-10-30 20:16:29 ----SD---- C:\Users\PEPA NETBOOK\AppData\Roaming\Microsoft
2010-10-30 20:16:29 ----D---- C:\Users\PEPA NETBOOK\AppData\Roaming\Media Center Programs
2010-10-30 20:13:35 ----D---- C:\Recovery
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Šablony
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Plocha
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Oblíbené položky
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Nabídka Start
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Dokumenty
2010-10-30 20:13:34 ----SHD---- C:\ProgramData\Data aplikací
2010-10-30 20:08:50 ----A---- C:\Windows\system32\drivers\ETD.sys
2010-10-30 20:08:49 ----A---- C:\Windows\system32\drivers\kbfiltr.sys
2010-10-30 20:06:51 ----D---- C:\Windows\SoftwareDistribution
2010-10-30 20:03:53 ----D---- C:\Windows\Prefetch
2010-10-30 20:03:23 ----ASH---- C:\pagefile.sys
2010-10-30 20:03:23 ----ASH---- C:\hiberfil.sys
======List of files/folders modified in the last 1 months======
2010-10-31 12:20:44 ----D---- C:\Windows\system32\config
2010-10-31 12:18:32 ----RD---- C:\Program Files
2010-10-31 12:13:03 ----D---- C:\Windows\system32\drivers
2010-10-31 12:13:00 ----D---- C:\Windows
2010-10-31 12:12:22 ----D---- C:\Windows\System32
2010-10-31 12:12:21 ----D---- C:\Windows\inf
2010-10-31 12:07:25 ----A---- C:\Windows\system.ini
2010-10-31 12:06:47 ----D---- C:\Windows\system32\drivers\etc
2010-10-31 12:02:51 ----D---- C:\Windows\system32\wdi
2010-10-31 11:48:02 ----D---- C:\Windows\AppPatch
2010-10-31 11:47:57 ----D---- C:\Program Files\Common Files
2010-10-31 07:43:15 ----D---- C:\Windows\winsxs
2010-10-31 07:42:41 ----D---- C:\Windows\Registration
2010-10-31 07:41:53 ----D---- C:\Windows\system32\catroot
2010-10-31 07:41:12 ----D---- C:\Windows\system32\DriverStore
2010-10-31 07:37:29 ----D---- C:\ProgramData
2010-10-31 07:23:03 ----D---- C:\Windows\Microsoft.NET
2010-10-31 07:22:31 ----RSD---- C:\Windows\assembly
2010-10-30 21:53:32 ----D---- C:\Windows\system32\migration
2010-10-30 21:53:32 ----D---- C:\Program Files\Internet Explorer
2010-10-30 21:53:31 ----D---- C:\Windows\system32\cs-CZ
2010-10-30 21:53:30 ----D---- C:\Windows\ehome
2010-10-30 21:53:30 ----D---- C:\Program Files\Windows Mail
2010-10-30 21:53:29 ----D---- C:\Windows\system32\Boot
2010-10-30 21:53:28 ----D---- C:\Program Files\Windows Media Player
2010-10-30 21:49:11 ----D---- C:\Windows\system32\catroot2
2010-10-30 21:41:47 ----SD---- C:\ProgramData\Microsoft
2010-10-30 21:27:20 ----D---- C:\Windows\debug
2010-10-30 21:15:13 ----D---- C:\Program Files\Common Files\microsoft shared
2010-10-30 21:14:02 ----RSD---- C:\Windows\Fonts
2010-10-30 21:09:15 ----D---- C:\Windows\ShellNew
2010-10-30 20:58:04 ----D---- C:\Windows\system32\Tasks
2010-10-30 20:48:56 ----D---- C:\Windows\Setup
2010-10-30 20:38:46 ----D---- C:\Windows\system32\CodeIntegrity
2010-10-30 20:32:42 ----D---- C:\Windows\Logs
2010-10-30 20:21:28 ----D---- C:\Windows\system32\restore
2010-10-30 20:20:57 ----D---- C:\Windows\system32\wbem
2010-10-30 20:16:28 ----RD---- C:\Users
2010-10-30 20:13:34 ----D---- C:\Program Files\Windows NT
2010-10-30 20:12:42 ----D---- C:\Windows\rescache
2010-10-30 20:08:58 ----D---- C:\Windows\system32\sysprep
2010-10-30 20:06:48 ----D---- C:\Windows\system32\drivers\UMDF
2010-10-30 20:04:32 ----D---- C:\Windows\CSC
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-10-30 691696]
R0 symsnap;Symantec Volume Snap Shot Driver; C:\Windows\system32\DRIVERS\symsnap.sys [2009-09-21 138592]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 48128]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 34816]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 93696]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 58880]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
R3 GEARAspiWDM;GearAspiWDM; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 GenericMount;Generic Mount Driver; C:\Windows\system32\DRIVERS\GenericMount.sys [2009-09-21 46192]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-09-23 4808192]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 13880]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20); C:\Windows\system32\DRIVERS\L1E62x86.sys [2009-07-13 47104]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista; C:\Windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 129536]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
S3 ac33nobg;ac33nobg; C:\Windows\system32\drivers\ac33nobg.sys []
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 392704]
S3 catchme;catchme; \??\C:\Users\PEPANE~1\AppData\Local\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\Users\PEPANE~1\AppData\Local\Temp\mbr.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S3 VProEventMonitor;Symantec Event Monitor Driver; C:\Windows\system32\DRIVERS\vproeventmonitor.sys [2009-09-21 15096]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2009-10-01 131000]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AsusService;Asus Launcher Service; C:\Windows\System32\AsusService.exe [2009-08-18 219136]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
R2 Norton Ghost;Norton Ghost; C:\Program Files\Norton Ghost\Agent\VProSvc.exe [2009-10-01 4584288]
R3 SymSnapService;SymSnapService; C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2009-09-21 1964528]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 GenericMount Helper Service;GenericMount Helper Service; C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe [2009-09-21 1571336]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider; C:\Windows\system32\dllhost.exe [2009-07-14 7168]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-10-30 1343400]
-----------------EOF-----------------
Re: pro vyosek - PC2
Zdravim
Nepouzivejte ComboFix bez doporuceni radce
Nebezpeci CFka
Vlozte mi sem jeho log, je ulozen v c:\combofix.txt
- Je urcen primarne pro radce - jeho svevolnym pouzitim ztracite narok na podporu
- Maze stopy po haveti, takze v logu z RSIT neni nic videt
- Jeho log je treba dolustit, jelikoz neumi smazat vse - to ovsem tezko zvladnete pokud k tomu nejste vyskolen
- CF muze mit bug = sunda Vam system, pokud nevite kam co uklada, jak co obnovit, mate system v kytkam a ceka Vas reinstal
- CF taky bohuzel prozatim nekontroluje nektere dulezite knihovny (napr. hal.dll) - ty treba mazou nektere typy haveti (napr. angela) - smaze Vam po restartu hal.dll = nenajede Vam system a jste o radek vyse = reinstal
Re: pro vyosek - PC2
OK, jen k předešlému tématu. T-cleaner nejde spustit, ostatní provedeno dle návodu.
Tady le ten log :
ComboFix 10-10-30.05 - PEPA NETBOOK 31.10.2010 11:21:42.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2039.1268 [GMT 1:00]
Spuštěný z: c:\users\PEPA NETBOOK\Documents\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\userinit.exe . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-28 do 2010-10-31 )))))))))))))))))))))))))))))))
.
2010-10-31 10:59 . 2010-10-31 10:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-31 06:43 . 2009-10-01 21:03 131000 ----a-w- c:\windows\system32\drivers\WimFltr.sys
2010-10-31 06:41 . 2009-09-21 19:20 138592 ----a-w- c:\windows\system32\drivers\symsnap.sys
2010-10-31 06:41 . 2009-09-21 19:40 15096 ----a-w- c:\windows\system32\drivers\vproeventmonitor.sys
2010-10-31 06:41 . 2010-10-31 06:43 -------- dc----w- c:\windows\system32\DRVSTORE
2010-10-31 06:41 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-10-31 06:41 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-10-31 06:38 . 2010-10-31 06:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-10-31 06:37 . 2010-10-31 06:46 -------- d-----w- c:\programdata\Symantec
2010-10-31 06:37 . 2010-10-31 06:38 -------- d-----w- c:\program files\Norton Ghost
2010-10-31 06:37 . 2010-10-31 06:37 -------- d-----w- c:\programdata\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-10-31 05:54 . 2010-10-31 05:54 -------- d-----w- c:\program files\foxitreader
2010-10-30 20:53 . 2010-10-30 20:53 -------- d-----w- c:\windows\system32\Wat
2010-10-30 20:52 . 2010-10-30 20:52 -------- d-----w- c:\windows\system32\Macromed
2010-10-30 20:48 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-10-30 20:45 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-10-30 20:45 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-10-30 20:45 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-10-30 20:45 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-10-30 20:45 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-10-30 20:40 . 2010-10-30 20:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-30 20:37 . 2004-08-09 22:42 77824 ------w- c:\windows\system32\brlmw03a.dll
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brownie
2010-10-30 20:37 . 2007-08-19 16:34 94208 ----a-w- c:\windows\system32\BRRBTOOL.EXE
2010-10-30 20:37 . 2006-12-21 02:23 176128 ----a-w- c:\windows\system32\BROSNMP.DLL
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brother
2010-10-30 20:37 . 2007-04-23 23:30 192512 ------w- c:\windows\system32\Pdrvinst.dll
2010-10-30 20:37 . 2004-09-23 15:00 24223 ----a-w- c:\windows\system32\BRLM03A.DLL
2010-10-30 20:37 . 2006-08-04 15:43 73728 ------w- c:\windows\system32\BRWEBUP.EXE
2010-10-30 20:37 . 2006-08-03 11:14 90112 ------w- c:\windows\system32\BrWebIns.dll
2010-10-30 20:36 . 2010-10-30 20:37 -------- d-----w- c:\program files\Common Files\InstallShield
2010-10-30 20:30 . 2010-10-30 20:35 -------- d-----w- c:\program files\Translator
2010-10-30 20:30 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-10-30 20:30 . 2010-10-30 20:33 -------- d-----w- c:\programdata\LangSoft
2010-10-30 20:27 . 2010-10-30 20:28 -------- d-----w- c:\program files\Opera
2010-10-30 20:26 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-10-30 20:26 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-10-30 20:26 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-10-30 20:23 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-10-30 20:23 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-30 20:23 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-10-30 20:23 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-10-30 20:23 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-10-30 20:23 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-10-30 20:23 . 2010-10-30 20:23 -------- d-----w- c:\program files\Zoner
2010-10-30 20:22 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-30 20:22 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-30 20:22 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-30 20:22 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-30 20:22 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-10-30 20:21 . 2010-08-27 05:30 13312 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-10-30 20:15 . 2010-10-30 20:15 -------- d-----w- c:\program files\Microsoft Works
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\windows\PCHEALTH
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\program files\Microsoft.NET
2010-10-30 20:07 . 2010-10-30 20:18 -------- d-----w- c:\programdata\Microsoft Help
2010-10-30 20:07 . 2010-10-30 20:07 -------- d-----r- C:\MSOCache
2010-10-30 19:57 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-30 19:56 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-10-30 19:56 . 2010-10-30 19:56 -------- d-----w- c:\program files\Common Files\Skype
2010-10-30 19:55 . 2010-10-30 19:56 -------- d-----r- c:\program files\Skype
2010-10-30 19:55 . 2010-10-30 19:55 -------- d-----w- c:\programdata\Skype
2010-10-30 19:54 . 2010-10-30 19:54 -------- d-----w- c:\program files\Ask.com
2010-10-30 19:53 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-10-30 19:53 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-10-30 19:53 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-10-30 19:53 . 2010-10-30 19:54 -------- d-----w- c:\program files\The KMPlayer
2010-10-30 19:51 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-30 19:51 . 2010-08-27 03:30 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-30 19:51 . 2010-08-27 05:46 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-30 19:51 . 2010-08-27 03:30 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-30 19:51 . 2010-08-21 05:36 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-30 19:51 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-10-30 19:51 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-30 19:51 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-10-30 19:51 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-10-30 19:51 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-10-30 19:49 . 2010-10-30 19:15 -------- d-----w- c:\windows\Panther
2010-10-30 19:47 . 2010-10-30 19:48 -------- d-----w- c:\program files\Win7codecs
2010-10-30 19:46 . 2010-10-30 19:48 -------- d-----w- c:\programdata\Win7codecs
2010-10-30 19:41 . 2010-10-30 19:41 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-30 19:40 . 2010-10-30 19:41 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-10-30 19:39 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-30 19:39 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-10-30 19:39 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-10-30 19:39 . 2010-10-30 19:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-10-30 19:36 . 2010-10-07 14:21 6146896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52221D85-1211-4A49-AC3A-F9B5CC330E14}\mpengine.dll
2010-10-30 19:36 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-30 19:35 . 2010-10-30 19:35 -------- d-----w- c:\windows\system32\x64
2010-10-30 19:35 . 2009-09-23 17:30 1002008 ----a-w- c:\windows\system32\igxpun.exe
2010-10-30 19:33 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-10-30 19:33 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-10-30 19:31 . 2010-10-30 20:01 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-10-30 19:31 . 2010-10-31 06:44 -------- d-sh--w- c:\windows\Installer
2010-10-30 19:27 . 2010-10-30 19:27 -------- d-----w- c:\program files\Elantech
2010-10-30 19:23 . 2009-09-11 11:25 33768 ----a-w- c:\windows\system32\AsusSender.exe
2010-10-30 19:23 . 2009-08-18 15:35 219136 ----a-w- c:\windows\system32\AsusService.exe
2010-10-30 19:22 . 2010-10-30 19:24 -------- d-----w- c:\program files\EeePC
2010-10-30 19:22 . 2010-10-30 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-30 19:20 . 2010-10-31 06:59 -------- d-----w- c:\windows\system32\wbem\Performance
2010-10-30 19:16 . 2010-10-30 19:17 -------- d-----w- c:\users\PEPA NETBOOK
2010-10-30 19:08 . 2009-07-08 11:43 4512768 ----a-w- c:\windows\system32\ETDUI.cpl
2010-10-30 19:08 . 2009-07-29 13:30 87040 ----a-w- c:\windows\system32\drivers\ETD.sys
2010-10-30 19:08 . 2009-07-20 15:29 13880 ----a-w- c:\windows\system32\drivers\kbfiltr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-21 05:36 . 2010-10-30 19:57 224256 ----a-w- c:\windows\system32\schannel.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 14:50 1197448 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperHybridEngine"="AsusSender.exe" [2009-09-11 33768]
"HotkeyMon"="AsusSender.exe" [2009-09-11 33768]
"HotkeyService"="AsusSender.exe" [2009-09-11 33768]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 497024]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1094224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-09-18 880640]
"Norton Ghost 15.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2009-10-01 2596712]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 14:49 14940040 ----a-r- c:\program files\Skype\Phone\Skype.exe
R3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe [2009-09-21 1571336]
R3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-07-14 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-30 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 691696]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [2009-08-18 219136]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys [2009-09-21 46192]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
S3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2009-09-21 1964528]
.
.
------- Doplňkový sken -------
.
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-PC Translator - c:\users\PEPANE~1\AppData\Local\Temp\UN32.EXE
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\taskhost.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\WUDFHost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\EeePC\HotkeyService\HotKeyMon.exe
c:\program files\EeePC\SHE\SuperHybridEngine.exe
c:\program files\EeePC\HotkeyService\HotkeyService.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Brownie\Brnipmon.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-10-31 12:12:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-31 11:12
Před spuštěním: 6 909 964 288
Po spuštění: 6 856 261 632
- - End Of File - - F2826D80A3036BACA100C1D4C5584E4F
Tady le ten log :
ComboFix 10-10-30.05 - PEPA NETBOOK 31.10.2010 11:21:42.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2039.1268 [GMT 1:00]
Spuštěný z: c:\users\PEPA NETBOOK\Documents\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\userinit.exe . . . je infikován!!
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-28 do 2010-10-31 )))))))))))))))))))))))))))))))
.
2010-10-31 10:59 . 2010-10-31 10:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-31 06:43 . 2009-10-01 21:03 131000 ----a-w- c:\windows\system32\drivers\WimFltr.sys
2010-10-31 06:41 . 2009-09-21 19:20 138592 ----a-w- c:\windows\system32\drivers\symsnap.sys
2010-10-31 06:41 . 2009-09-21 19:40 15096 ----a-w- c:\windows\system32\drivers\vproeventmonitor.sys
2010-10-31 06:41 . 2010-10-31 06:43 -------- dc----w- c:\windows\system32\DRVSTORE
2010-10-31 06:41 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-10-31 06:41 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-10-31 06:38 . 2010-10-31 06:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-10-31 06:37 . 2010-10-31 06:46 -------- d-----w- c:\programdata\Symantec
2010-10-31 06:37 . 2010-10-31 06:38 -------- d-----w- c:\program files\Norton Ghost
2010-10-31 06:37 . 2010-10-31 06:37 -------- d-----w- c:\programdata\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-10-31 05:54 . 2010-10-31 05:54 -------- d-----w- c:\program files\foxitreader
2010-10-30 20:53 . 2010-10-30 20:53 -------- d-----w- c:\windows\system32\Wat
2010-10-30 20:52 . 2010-10-30 20:52 -------- d-----w- c:\windows\system32\Macromed
2010-10-30 20:48 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-10-30 20:45 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-10-30 20:45 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-10-30 20:45 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-10-30 20:45 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-10-30 20:45 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-10-30 20:40 . 2010-10-30 20:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-30 20:37 . 2004-08-09 22:42 77824 ------w- c:\windows\system32\brlmw03a.dll
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brownie
2010-10-30 20:37 . 2007-08-19 16:34 94208 ----a-w- c:\windows\system32\BRRBTOOL.EXE
2010-10-30 20:37 . 2006-12-21 02:23 176128 ----a-w- c:\windows\system32\BROSNMP.DLL
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brother
2010-10-30 20:37 . 2007-04-23 23:30 192512 ------w- c:\windows\system32\Pdrvinst.dll
2010-10-30 20:37 . 2004-09-23 15:00 24223 ----a-w- c:\windows\system32\BRLM03A.DLL
2010-10-30 20:37 . 2006-08-04 15:43 73728 ------w- c:\windows\system32\BRWEBUP.EXE
2010-10-30 20:37 . 2006-08-03 11:14 90112 ------w- c:\windows\system32\BrWebIns.dll
2010-10-30 20:36 . 2010-10-30 20:37 -------- d-----w- c:\program files\Common Files\InstallShield
2010-10-30 20:30 . 2010-10-30 20:35 -------- d-----w- c:\program files\Translator
2010-10-30 20:30 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-10-30 20:30 . 2010-10-30 20:33 -------- d-----w- c:\programdata\LangSoft
2010-10-30 20:27 . 2010-10-30 20:28 -------- d-----w- c:\program files\Opera
2010-10-30 20:26 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-10-30 20:26 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-10-30 20:26 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-10-30 20:23 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-10-30 20:23 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-30 20:23 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-10-30 20:23 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-10-30 20:23 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-10-30 20:23 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-10-30 20:23 . 2010-10-30 20:23 -------- d-----w- c:\program files\Zoner
2010-10-30 20:22 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-30 20:22 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-30 20:22 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-30 20:22 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-30 20:22 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-10-30 20:21 . 2010-08-27 05:30 13312 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-10-30 20:15 . 2010-10-30 20:15 -------- d-----w- c:\program files\Microsoft Works
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\windows\PCHEALTH
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\program files\Microsoft.NET
2010-10-30 20:07 . 2010-10-30 20:18 -------- d-----w- c:\programdata\Microsoft Help
2010-10-30 20:07 . 2010-10-30 20:07 -------- d-----r- C:\MSOCache
2010-10-30 19:57 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-30 19:56 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-10-30 19:56 . 2010-10-30 19:56 -------- d-----w- c:\program files\Common Files\Skype
2010-10-30 19:55 . 2010-10-30 19:56 -------- d-----r- c:\program files\Skype
2010-10-30 19:55 . 2010-10-30 19:55 -------- d-----w- c:\programdata\Skype
2010-10-30 19:54 . 2010-10-30 19:54 -------- d-----w- c:\program files\Ask.com
2010-10-30 19:53 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-10-30 19:53 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-10-30 19:53 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-10-30 19:53 . 2010-10-30 19:54 -------- d-----w- c:\program files\The KMPlayer
2010-10-30 19:51 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-30 19:51 . 2010-08-27 03:30 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-30 19:51 . 2010-08-27 05:46 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-30 19:51 . 2010-08-27 03:30 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-30 19:51 . 2010-08-21 05:36 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-30 19:51 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-10-30 19:51 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-30 19:51 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-10-30 19:51 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-10-30 19:51 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-10-30 19:49 . 2010-10-30 19:15 -------- d-----w- c:\windows\Panther
2010-10-30 19:47 . 2010-10-30 19:48 -------- d-----w- c:\program files\Win7codecs
2010-10-30 19:46 . 2010-10-30 19:48 -------- d-----w- c:\programdata\Win7codecs
2010-10-30 19:41 . 2010-10-30 19:41 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-30 19:40 . 2010-10-30 19:41 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-10-30 19:39 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-30 19:39 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-10-30 19:39 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-10-30 19:39 . 2010-10-30 19:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-10-30 19:36 . 2010-10-07 14:21 6146896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52221D85-1211-4A49-AC3A-F9B5CC330E14}\mpengine.dll
2010-10-30 19:36 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-30 19:35 . 2010-10-30 19:35 -------- d-----w- c:\windows\system32\x64
2010-10-30 19:35 . 2009-09-23 17:30 1002008 ----a-w- c:\windows\system32\igxpun.exe
2010-10-30 19:33 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-10-30 19:33 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-10-30 19:31 . 2010-10-30 20:01 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-10-30 19:31 . 2010-10-31 06:44 -------- d-sh--w- c:\windows\Installer
2010-10-30 19:27 . 2010-10-30 19:27 -------- d-----w- c:\program files\Elantech
2010-10-30 19:23 . 2009-09-11 11:25 33768 ----a-w- c:\windows\system32\AsusSender.exe
2010-10-30 19:23 . 2009-08-18 15:35 219136 ----a-w- c:\windows\system32\AsusService.exe
2010-10-30 19:22 . 2010-10-30 19:24 -------- d-----w- c:\program files\EeePC
2010-10-30 19:22 . 2010-10-30 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-30 19:20 . 2010-10-31 06:59 -------- d-----w- c:\windows\system32\wbem\Performance
2010-10-30 19:16 . 2010-10-30 19:17 -------- d-----w- c:\users\PEPA NETBOOK
2010-10-30 19:08 . 2009-07-08 11:43 4512768 ----a-w- c:\windows\system32\ETDUI.cpl
2010-10-30 19:08 . 2009-07-29 13:30 87040 ----a-w- c:\windows\system32\drivers\ETD.sys
2010-10-30 19:08 . 2009-07-20 15:29 13880 ----a-w- c:\windows\system32\drivers\kbfiltr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-21 05:36 . 2010-10-30 19:57 224256 ----a-w- c:\windows\system32\schannel.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-02-04 14:50 1197448 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperHybridEngine"="AsusSender.exe" [2009-09-11 33768]
"HotkeyMon"="AsusSender.exe" [2009-09-11 33768]
"HotkeyService"="AsusSender.exe" [2009-09-11 33768]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 497024]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1094224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-09-18 880640]
"Norton Ghost 15.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2009-10-01 2596712]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-10-11 14:49 14940040 ----a-r- c:\program files\Skype\Phone\Skype.exe
R3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe [2009-09-21 1571336]
R3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-07-14 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-30 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 691696]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [2009-08-18 219136]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys [2009-09-21 46192]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
S3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2009-09-21 1964528]
.
.
------- Doplňkový sken -------
.
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
AddRemove-PC Translator - c:\users\PEPANE~1\AppData\Local\Temp\UN32.EXE
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\taskhost.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\WUDFHost.exe
c:\windows\System32\rundll32.exe
c:\windows\system32\conhost.exe
c:\program files\EeePC\HotkeyService\HotKeyMon.exe
c:\program files\EeePC\SHE\SuperHybridEngine.exe
c:\program files\EeePC\HotkeyService\HotkeyService.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Brownie\Brnipmon.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-10-31 12:12:54 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-31 11:12
Před spuštěním: 6 909 964 288
Po spuštění: 6 856 261 632
- - End Of File - - F2826D80A3036BACA100C1D4C5584E4F
Re: pro vyosek - PC2
- c:\windows\system32\userinit.exe
- Kliknete na Prochazet
- Soubor nehledejte, jen vlozte cestu souboru, ktery chci otestovat
- Kliknete na Send File
- Pokud na Vas vyskoci obrazovka jako je nize, tak kliknete na ReAnalyse

- Vysledek analyzy sem vlozte (jako odkaz)
- Do okna vlozte skript nize
Kód: Vybrat vše
:filefind userinit.exe- Kliknete na Look
- Tlacitko Look se zmeni na Scanning a zsedne
- Pockejte pokud se tlacitko Scanning opet nezmeni na Look - tak poznate ze SystemLook dokoncil svou praci
- Vyskoci na Vas log s nazvem SystemLook (pripadne bude ulozen na plose), jeho obsah mi sem vlozte
Re: pro vyosek - PC2
Jeste poprosim o SystemLook
Re: pro vyosek - PC2
SystemLook 04.09.10 by jpshortstuff
Log created at 14:19 on 31/10/2010 by PEPA NETBOOK
Administrator - Elevation successful
No Context: filefind
No Context: userinit.exe
-= EOF =-
Log created at 14:19 on 31/10/2010 by PEPA NETBOOK
Administrator - Elevation successful
No Context: filefind
No Context: userinit.exe
-= EOF =-
Re: pro vyosek - PC2
Spatne jste zkopiroval skript pro SL, takze znovu, nesmite zapomenout na tu dvojtecku
Kód: Vybrat vše
:filefind
userinit.exe[code]Re: pro vyosek - PC2
T-cleaner pořád nejde spustit ani na jednom PC 
Re: pro vyosek - PC2
SystemLook 04.09.10 by jpshortstuff
Log created at 14:30 on 31/10/2010 by PEPA NETBOOK
Administrator - Elevation successful
========== filefind ==========
Searching for "userinit.exe"
C:\Windows\ERDNT\cache\userinit.exe --a---- 26112 bytes [11:10 31/10/2010] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
C:\Windows\System32\userinit.exe --a---- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe --a---- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
-= EOF =-
Log created at 14:30 on 31/10/2010 by PEPA NETBOOK
Administrator - Elevation successful
========== filefind ==========
Searching for "userinit.exe"
C:\Windows\ERDNT\cache\userinit.exe --a---- 26112 bytes [11:10 31/10/2010] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
C:\Windows\System32\userinit.exe --a---- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe --a---- 26112 bytes [23:34 13/07/2009] [01:14 14/07/2009] 6DE80F60D7DE9CE6B8C2DDFDF79EF175
-= EOF =-
Re: pro vyosek - PC2
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
SRPeek:: c:\windows\system32\userinit.exe Restore:: c:\windows\system32\userinit.exe Folder:: c:\program files\Ask.com Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{D4027C7F-154A-4066-A1AD-4243D8127440}"=- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{D4027C7F-154A-4066-A1AD-4243D8127440}"=- [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: pro vyosek - PC2
omlouvám se za spoždění ale nějak jsem vytuhl
ComboFix 10-10-30.05 - PEPA NETBOOK 31.10.2010 15:58:41.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2039.1262 [GMT 1:00]
Spuštěný z: c:\users\PEPA NETBOOK\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\PEPA NETBOOK\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ERDNT\cache\userinit.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-28 do 2010-10-31 )))))))))))))))))))))))))))))))
.
2010-10-31 15:10 . 2010-10-31 15:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-31 11:18 . 2010-10-31 12:05 -------- d-----w- c:\program files\trend micro
2010-10-31 11:18 . 2010-10-31 11:19 -------- d-----w- C:\rsit
2010-10-31 06:43 . 2009-10-01 21:03 131000 ----a-w- c:\windows\system32\drivers\WimFltr.sys
2010-10-31 06:41 . 2009-09-21 19:20 138592 ----a-w- c:\windows\system32\drivers\symsnap.sys
2010-10-31 06:41 . 2009-09-21 19:40 15096 ----a-w- c:\windows\system32\drivers\vproeventmonitor.sys
2010-10-31 06:41 . 2010-10-31 06:43 -------- dc----w- c:\windows\system32\DRVSTORE
2010-10-31 06:41 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-10-31 06:41 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-10-31 06:38 . 2010-10-31 06:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-10-31 06:37 . 2010-10-31 06:46 -------- d-----w- c:\programdata\Symantec
2010-10-31 06:37 . 2010-10-31 06:38 -------- d-----w- c:\program files\Norton Ghost
2010-10-31 06:37 . 2010-10-31 06:37 -------- d-----w- c:\programdata\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-10-31 05:54 . 2010-10-31 05:54 -------- d-----w- c:\program files\foxitreader
2010-10-30 20:53 . 2010-10-30 20:53 -------- d-----w- c:\windows\system32\Wat
2010-10-30 20:52 . 2010-10-30 20:52 -------- d-----w- c:\windows\system32\Macromed
2010-10-30 20:48 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-10-30 20:45 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-10-30 20:45 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-10-30 20:45 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-10-30 20:45 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-10-30 20:45 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-10-30 20:40 . 2010-10-30 20:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-30 20:37 . 2004-08-09 22:42 77824 ------w- c:\windows\system32\brlmw03a.dll
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brownie
2010-10-30 20:37 . 2007-08-19 16:34 94208 ----a-w- c:\windows\system32\BRRBTOOL.EXE
2010-10-30 20:37 . 2006-12-21 02:23 176128 ----a-w- c:\windows\system32\BROSNMP.DLL
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brother
2010-10-30 20:37 . 2007-04-23 23:30 192512 ------w- c:\windows\system32\Pdrvinst.dll
2010-10-30 20:37 . 2004-09-23 15:00 24223 ----a-w- c:\windows\system32\BRLM03A.DLL
2010-10-30 20:37 . 2006-08-04 15:43 73728 ------w- c:\windows\system32\BRWEBUP.EXE
2010-10-30 20:37 . 2006-08-03 11:14 90112 ------w- c:\windows\system32\BrWebIns.dll
2010-10-30 20:36 . 2010-10-30 20:37 -------- d-----w- c:\program files\Common Files\InstallShield
2010-10-30 20:30 . 2010-10-30 20:35 -------- d-----w- c:\program files\Translator
2010-10-30 20:30 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-10-30 20:30 . 2010-10-30 20:33 -------- d-----w- c:\programdata\LangSoft
2010-10-30 20:27 . 2010-10-30 20:28 -------- d-----w- c:\program files\Opera
2010-10-30 20:26 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-10-30 20:26 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-10-30 20:26 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-10-30 20:23 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-10-30 20:23 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-30 20:23 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-10-30 20:23 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-10-30 20:23 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-10-30 20:23 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-10-30 20:23 . 2010-10-30 20:23 -------- d-----w- c:\program files\Zoner
2010-10-30 20:22 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-30 20:22 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-30 20:22 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-30 20:22 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-30 20:22 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-10-30 20:21 . 2010-08-27 05:30 13312 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-10-30 20:15 . 2010-10-30 20:15 -------- d-----w- c:\program files\Microsoft Works
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\windows\PCHEALTH
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\program files\Microsoft.NET
2010-10-30 20:07 . 2010-10-30 20:18 -------- d-----w- c:\programdata\Microsoft Help
2010-10-30 20:07 . 2010-10-30 20:07 -------- d-----r- C:\MSOCache
2010-10-30 19:57 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-30 19:56 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-10-30 19:56 . 2010-10-30 19:56 -------- d-----w- c:\program files\Common Files\Skype
2010-10-30 19:55 . 2010-10-30 19:56 -------- d-----r- c:\program files\Skype
2010-10-30 19:55 . 2010-10-30 19:55 -------- d-----w- c:\programdata\Skype
2010-10-30 19:53 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-10-30 19:53 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-10-30 19:53 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-10-30 19:53 . 2010-10-30 19:54 -------- d-----w- c:\program files\The KMPlayer
2010-10-30 19:51 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-30 19:51 . 2010-08-27 03:30 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-30 19:51 . 2010-08-27 05:46 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-30 19:51 . 2010-08-27 03:30 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-30 19:51 . 2010-08-21 05:36 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-30 19:51 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-10-30 19:51 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-30 19:51 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-10-30 19:51 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-10-30 19:51 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-10-30 19:49 . 2010-10-30 19:15 -------- d-----w- c:\windows\Panther
2010-10-30 19:47 . 2010-10-30 19:48 -------- d-----w- c:\program files\Win7codecs
2010-10-30 19:46 . 2010-10-30 19:48 -------- d-----w- c:\programdata\Win7codecs
2010-10-30 19:41 . 2010-10-30 19:41 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-30 19:40 . 2010-10-30 19:41 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-10-30 19:39 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-30 19:39 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-10-30 19:39 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-10-30 19:39 . 2010-10-30 19:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-10-30 19:36 . 2010-10-07 14:21 6146896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52221D85-1211-4A49-AC3A-F9B5CC330E14}\mpengine.dll
2010-10-30 19:36 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-30 19:35 . 2010-10-30 19:35 -------- d-----w- c:\windows\system32\x64
2010-10-30 19:35 . 2009-09-23 17:30 1002008 ----a-w- c:\windows\system32\igxpun.exe
2010-10-30 19:33 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-10-30 19:33 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-10-30 19:31 . 2010-10-30 20:01 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-10-30 19:31 . 2010-10-31 06:44 -------- d-sh--w- c:\windows\Installer
2010-10-30 19:27 . 2010-10-30 19:27 -------- d-----w- c:\program files\Elantech
2010-10-30 19:23 . 2009-09-11 11:25 33768 ----a-w- c:\windows\system32\AsusSender.exe
2010-10-30 19:23 . 2009-08-18 15:35 219136 ----a-w- c:\windows\system32\AsusService.exe
2010-10-30 19:22 . 2010-10-30 19:24 -------- d-----w- c:\program files\EeePC
2010-10-30 19:22 . 2010-10-30 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-30 19:20 . 2010-10-31 11:12 -------- d-----w- c:\windows\system32\wbem\Performance
2010-10-30 19:16 . 2010-10-30 19:17 -------- d-----w- c:\users\PEPA NETBOOK
2010-10-30 19:08 . 2009-07-08 11:43 4512768 ----a-w- c:\windows\system32\ETDUI.cpl
2010-10-30 19:08 . 2009-07-29 13:30 87040 ----a-w- c:\windows\system32\drivers\ETD.sys
2010-10-30 19:08 . 2009-07-20 15:29 13880 ----a-w- c:\windows\system32\drivers\kbfiltr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-21 05:36 . 2010-10-30 19:57 224256 ----a-w- c:\windows\system32\schannel.dll
.
(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperHybridEngine"="AsusSender.exe" [2009-09-11 33768]
"HotkeyMon"="AsusSender.exe" [2009-09-11 33768]
"HotkeyService"="AsusSender.exe" [2009-09-11 33768]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 497024]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1094224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-09-18 880640]
"Norton Ghost 15.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2009-10-01 2596712]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
R3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe [2009-09-21 1571336]
R3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-07-14 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-30 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 691696]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [2009-08-18 219136]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys [2009-09-21 46192]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
S3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2009-09-21 1964528]
.
.
------- Doplňkový sken -------
.
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\taskhost.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\program files\EeePC\HotkeyService\HotKeyMon.exe
c:\program files\EeePC\SHE\SuperHybridEngine.exe
c:\program files\EeePC\HotkeyService\HotkeyService.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Brownie\Brnipmon.exe
c:\windows\system32\sppsvc.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-10-31 16:20:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-31 15:20
ComboFix2.txt 2010-10-31 11:12
Před spuštěním: 6 572 212 224
Po spuštění: 6 517 391 360
- - End Of File - - 056D42085AEFB94E329EBA5E3CC9DB60
ComboFix 10-10-30.05 - PEPA NETBOOK 31.10.2010 15:58:41.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1250.420.1029.18.2039.1262 [GMT 1:00]
Spuštěný z: c:\users\PEPA NETBOOK\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\PEPA NETBOOK\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\ERDNT\cache\userinit.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-28 do 2010-10-31 )))))))))))))))))))))))))))))))
.
2010-10-31 15:10 . 2010-10-31 15:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-31 11:18 . 2010-10-31 12:05 -------- d-----w- c:\program files\trend micro
2010-10-31 11:18 . 2010-10-31 11:19 -------- d-----w- C:\rsit
2010-10-31 06:43 . 2009-10-01 21:03 131000 ----a-w- c:\windows\system32\drivers\WimFltr.sys
2010-10-31 06:41 . 2009-09-21 19:20 138592 ----a-w- c:\windows\system32\drivers\symsnap.sys
2010-10-31 06:41 . 2009-09-21 19:40 15096 ----a-w- c:\windows\system32\drivers\vproeventmonitor.sys
2010-10-31 06:41 . 2010-10-31 06:43 -------- dc----w- c:\windows\system32\DRVSTORE
2010-10-31 06:41 . 2009-05-18 13:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-10-31 06:41 . 2008-04-17 12:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-10-31 06:38 . 2010-10-31 06:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-10-31 06:37 . 2010-10-31 06:46 -------- d-----w- c:\programdata\Symantec
2010-10-31 06:37 . 2010-10-31 06:38 -------- d-----w- c:\program files\Norton Ghost
2010-10-31 06:37 . 2010-10-31 06:37 -------- d-----w- c:\programdata\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3}
2010-10-31 05:54 . 2010-10-31 05:54 -------- d-----w- c:\program files\foxitreader
2010-10-30 20:53 . 2010-10-30 20:53 -------- d-----w- c:\windows\system32\Wat
2010-10-30 20:52 . 2010-10-30 20:52 -------- d-----w- c:\windows\system32\Macromed
2010-10-30 20:48 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-10-30 20:45 . 2009-11-25 10:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-10-30 20:45 . 2009-11-25 10:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-10-30 20:45 . 2009-11-25 10:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-10-30 20:45 . 2009-11-25 10:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-10-30 20:45 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-10-30 20:40 . 2010-10-30 20:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-10-30 20:37 . 2004-08-09 22:42 77824 ------w- c:\windows\system32\brlmw03a.dll
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brownie
2010-10-30 20:37 . 2007-08-19 16:34 94208 ----a-w- c:\windows\system32\BRRBTOOL.EXE
2010-10-30 20:37 . 2006-12-21 02:23 176128 ----a-w- c:\windows\system32\BROSNMP.DLL
2010-10-30 20:37 . 2010-10-30 20:37 -------- d-----w- c:\program files\Brother
2010-10-30 20:37 . 2007-04-23 23:30 192512 ------w- c:\windows\system32\Pdrvinst.dll
2010-10-30 20:37 . 2004-09-23 15:00 24223 ----a-w- c:\windows\system32\BRLM03A.DLL
2010-10-30 20:37 . 2006-08-04 15:43 73728 ------w- c:\windows\system32\BRWEBUP.EXE
2010-10-30 20:37 . 2006-08-03 11:14 90112 ------w- c:\windows\system32\BrWebIns.dll
2010-10-30 20:36 . 2010-10-30 20:37 -------- d-----w- c:\program files\Common Files\InstallShield
2010-10-30 20:30 . 2010-10-30 20:35 -------- d-----w- c:\program files\Translator
2010-10-30 20:30 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-10-30 20:30 . 2010-10-30 20:33 -------- d-----w- c:\programdata\LangSoft
2010-10-30 20:27 . 2010-10-30 20:28 -------- d-----w- c:\program files\Opera
2010-10-30 20:26 . 2009-10-10 02:57 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-10-30 20:26 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-10-30 20:26 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-10-30 20:23 . 2010-03-24 06:37 1286456 ----a-w- c:\windows\system32\ntdll.dll
2010-10-30 20:23 . 2010-07-13 05:22 26504 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2010-10-30 20:23 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-10-30 20:23 . 2010-01-18 23:29 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 369152 ----a-w- c:\windows\system32\secproc.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-10-30 20:23 . 2010-01-18 23:29 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-10-30 20:23 . 2010-01-18 23:28 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-10-30 20:23 . 2010-01-18 23:28 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-10-30 20:23 . 2010-01-18 23:28 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-10-30 20:23 . 2010-10-30 20:23 -------- d-----w- c:\program files\Zoner
2010-10-30 20:22 . 2010-08-04 06:18 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-10-30 20:22 . 2010-08-04 06:17 417792 ----a-w- c:\windows\system32\msdri.dll
2010-10-30 20:22 . 2010-08-04 06:15 204288 ----a-w- c:\windows\system32\MSNP.ax
2010-10-30 20:22 . 2010-08-04 06:15 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2010-10-30 20:22 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-10-30 20:21 . 2010-08-27 05:30 13312 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-10-30 20:15 . 2010-10-30 20:15 -------- d-----w- c:\program files\Microsoft Works
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\windows\PCHEALTH
2010-10-30 20:13 . 2010-10-30 20:13 -------- d-----w- c:\program files\Microsoft.NET
2010-10-30 20:07 . 2010-10-30 20:18 -------- d-----w- c:\programdata\Microsoft Help
2010-10-30 20:07 . 2010-10-30 20:07 -------- d-----r- C:\MSOCache
2010-10-30 19:57 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-10-30 19:56 . 2010-03-05 07:42 67584 ----a-w- c:\windows\system32\asycfilt.dll
2010-10-30 19:56 . 2010-10-30 19:56 -------- d-----w- c:\program files\Common Files\Skype
2010-10-30 19:55 . 2010-10-30 19:56 -------- d-----r- c:\program files\Skype
2010-10-30 19:55 . 2010-10-30 19:55 -------- d-----w- c:\programdata\Skype
2010-10-30 19:53 . 2010-08-21 05:33 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-10-30 19:53 . 2010-08-31 04:32 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-10-30 19:53 . 2010-08-31 04:32 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-10-30 19:53 . 2010-10-30 19:54 -------- d-----w- c:\program files\The KMPlayer
2010-10-30 19:51 . 2010-08-27 03:31 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-30 19:51 . 2010-08-27 03:30 308736 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-30 19:51 . 2010-08-27 05:46 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-30 19:51 . 2010-08-27 03:30 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-30 19:51 . 2010-08-21 05:36 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-10-30 19:51 . 2010-03-08 21:33 427520 ----a-w- c:\windows\system32\vbscript.dll
2010-10-30 19:51 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-30 19:51 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-10-30 19:51 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-10-30 19:51 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-10-30 19:49 . 2010-10-30 19:15 -------- d-----w- c:\windows\Panther
2010-10-30 19:47 . 2010-10-30 19:48 -------- d-----w- c:\program files\Win7codecs
2010-10-30 19:46 . 2010-10-30 19:48 -------- d-----w- c:\programdata\Win7codecs
2010-10-30 19:41 . 2010-10-30 19:41 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-10-30 19:40 . 2010-10-30 19:41 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-10-30 19:39 . 2010-05-27 07:24 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-10-30 19:39 . 2010-05-27 03:49 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-10-30 19:39 . 2009-10-19 14:10 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-10-30 19:39 . 2010-10-30 19:39 -------- d-----w- c:\programdata\DAEMON Tools Lite
2010-10-30 19:36 . 2010-10-07 14:21 6146896 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{52221D85-1211-4A49-AC3A-F9B5CC330E14}\mpengine.dll
2010-10-30 19:36 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-30 19:35 . 2010-10-30 19:35 -------- d-----w- c:\windows\system32\x64
2010-10-30 19:35 . 2009-09-23 17:30 1002008 ----a-w- c:\windows\system32\igxpun.exe
2010-10-30 19:33 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-10-30 19:33 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2010-10-30 19:31 . 2010-10-30 20:01 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-10-30 19:31 . 2010-10-31 06:44 -------- d-sh--w- c:\windows\Installer
2010-10-30 19:27 . 2010-10-30 19:27 -------- d-----w- c:\program files\Elantech
2010-10-30 19:23 . 2009-09-11 11:25 33768 ----a-w- c:\windows\system32\AsusSender.exe
2010-10-30 19:23 . 2009-08-18 15:35 219136 ----a-w- c:\windows\system32\AsusService.exe
2010-10-30 19:22 . 2010-10-30 19:24 -------- d-----w- c:\program files\EeePC
2010-10-30 19:22 . 2010-10-30 20:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-30 19:20 . 2010-10-31 11:12 -------- d-----w- c:\windows\system32\wbem\Performance
2010-10-30 19:16 . 2010-10-30 19:17 -------- d-----w- c:\users\PEPA NETBOOK
2010-10-30 19:08 . 2009-07-08 11:43 4512768 ----a-w- c:\windows\system32\ETDUI.cpl
2010-10-30 19:08 . 2009-07-29 13:30 87040 ----a-w- c:\windows\system32\drivers\ETD.sys
2010-10-30 19:08 . 2009-07-20 15:29 13880 ----a-w- c:\windows\system32\drivers\kbfiltr.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-21 05:36 . 2010-10-30 19:57 224256 ----a-w- c:\windows\system32\schannel.dll
.
(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperHybridEngine"="AsusSender.exe" [2009-09-11 33768]
"HotkeyMon"="AsusSender.exe" [2009-09-11 33768]
"HotkeyService"="AsusSender.exe" [2009-09-11 33768]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-07-30 497024]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-09-15 1094224]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2008-09-18 880640]
"Norton Ghost 15.0"="c:\program files\Norton Ghost\Agent\VProTray.exe" [2009-10-01 2596712]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
R3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\Norton Ghost\Shared\Drivers\GenericMountHelper.exe [2009-09-21 1571336]
R3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2009-07-14 7168]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-30 1343400]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-10-30 691696]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AsusService;Asus Launcher Service;c:\windows\System32\AsusService.exe [2009-08-18 219136]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2009-07-29 87040]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys [2009-09-21 46192]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
S3 netr28;Ralink 802.11n – bezdrátový ovladač pro systém Windows Vista;c:\windows\system32\DRIVERS\netr28.sys [2009-07-13 530944]
S3 SymSnapService;SymSnapService;c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [2009-09-21 1964528]
.
.
------- Doplňkový sken -------
.
IE: {{7E6A20FB-153F-402c-A84B-1A64E1955D3D} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\programdata\LangSoft\WebIE.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\programdata\LangSoft\WebIE.dll
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\windows\system32\taskhost.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\program files\EeePC\HotkeyService\HotKeyMon.exe
c:\program files\EeePC\SHE\SuperHybridEngine.exe
c:\program files\EeePC\HotkeyService\HotkeyService.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Brownie\Brnipmon.exe
c:\windows\system32\sppsvc.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Celkový čas: 2010-10-31 16:20:10 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-31 15:20
ComboFix2.txt 2010-10-31 11:12
Před spuštěním: 6 572 212 224
Po spuštění: 6 517 391 360
- - End Of File - - 056D42085AEFB94E329EBA5E3CC9DB60
Re: pro vyosek - PC2
Jak se chova PC 
Re: pro vyosek - PC2
Nějak nepoznávám změnu. Netbook fungoval obstojně, asi ho ta havěť nezpomalovala. Každopádně jsem rád, že je čistý a můžu udělat zálohu na HDD. Ještě udělám ten postup co jste uvedl u PC1.
Re: pro vyosek - PC2
- Start - Spustit (nebo pouzijte klavesobou zkratku Win+R)
- Napiste ComboFix /Uninstall
- Stisknete Enter
- Tohle smaze Combofix a jeho slozky
- Stahnete a spustte
- Pro potvrzeni volby mackejte A, Enter
- Po pouziti utilitu smazte
- Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
- Stahnete a spustte
- Kliknete na CleanUp a potvrdte YES
- Program uklidi a restartuje PC
- Stahnete a spustte
- Kliknete na Start a potvrdte OK
- Program uklidi a restartuje pc
- Po pouziti utilitu smazte
Panel čistič
- Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
- dejte Hledej problémy
- nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
- postup opakujte dokud nebude bez problemu - vetsinou cca 3x
- Zde muzete odinstalovat nepotrebne programy



Přispějete na provoz fóra?