
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
prosím o kontrolu logu při najetí se restartuje......
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
prosím o kontrolu logu při najetí se restartuje......
Logfile of random's system information tool 1.06 (written by random/random)
Run by Peťa at 2011-02-08 12:11:21
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 1 GB (3%) free of 38 GB
Total RAM: 503 MB (68% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
C:\WINDOWS\tasks\WGASetup.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-09-27 341600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-10-18 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFre2.dll [2010-10-18 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
MyPlayCity Toolbar BHO - C:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-11-30 1536000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2010-10-18 1485112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{D5D47440-0750-463D-BAEF-A47D02414806} - Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-03-28 1017592]
{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFre2.dll [2010-10-18 3908192]
{648ADDE1-369B-4868-A419-0B67EBFD8F73} - MyPlayCity Toolbar - C:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-11-30 1536000]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2010-10-18 1485112]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-13 16857600]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-06-10 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-06-10 13758464]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-02-06 2021400]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-09-27 202256]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-08 305440]
"NVIDIA driver monitor"=c:\windows\nvsvc32.exe [2011-01-02 87552]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2010-12-20 111928]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-07-13 414992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2007-08-02 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"NVIDIA driver monitor"=c:\windows\nvsvc32.exe [2011-01-02 87552]
"ICQ"=~C:\Program Files\ICQ7.2\ICQ.exe silent loginmode=4 []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-01-03 15028104]
"MSConfig"=C:\Documents and Settings\Peťa\gqva.exe [2011-01-31 17920]
"gaquoot"=C:\Documents and Settings\Peťa\Data aplikací\Microsoft\cudof.exe [2011-01-31 229888]
C:\Documents and Settings\Peťa\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe"="C:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe:*:Enabled:Far Cry"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe"="C:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe:*:Enabled:MyPlayCity Toolbar (Helper)"
"C:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe"="C:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe:*:Enabled:MyPlayCity Toolbar (Update)"
"C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe"="C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe:*:Enabled:BF1942"
"C:\Documents and Settings\Peťa\Plocha\facebook-pic00005267.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe"="C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe:*:Enabled:SweetIM Installer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{62cb0c66-a47a-11df-bfb3-000fea522d86}]
shell\AutoRun\command - F:\TranscendService(JF).exe
======List of files/folders created in the last 1 months======
2011-02-08 12:11:23 ----D---- C:\Program Files\trend micro
2011-02-08 12:11:21 ----D---- C:\rsit
2011-02-08 12:10:29 ----A---- C:\WINDOWS\gmer.ini
2011-02-08 12:10:25 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2011-02-08 12:10:25 ----A---- C:\WINDOWS\gmer.dll
2011-02-08 12:10:24 ----A---- C:\WINDOWS\gmer.exe
2011-02-08 12:07:35 ----D---- C:\Documents and Settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 12:07:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-02-08 12:07:20 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-08 12:06:59 ----D---- C:\Program Files\Yahoo!
2011-02-08 12:06:51 ----D---- C:\Program Files\CCleaner
2011-02-08 12:06:36 ----D---- C:\ComboFix
2011-02-08 09:44:44 ----A---- C:\WINDOWS\ntbtlog.txt
2011-01-31 21:03:25 ----AH---- C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt
2011-01-31 21:02:14 ----RSH---- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
2011-01-31 21:02:06 ----A---- C:\ni.exe
2011-01-29 22:13:41 ----D---- C:\Documents and Settings\Peťa\Data aplikací\skypePM
2011-01-29 22:07:18 ----D---- C:\Program Files\Common Files\Skype
2011-01-29 22:07:09 ----RD---- C:\Program Files\Skype
2011-01-29 22:07:07 ----D---- C:\Documents and Settings\Peťa\Data aplikací\Skype
2011-01-29 22:06:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-01-25 18:22:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2011-01-25 18:18:19 ----D---- C:\Program Files\Microsoft WSE
2011-01-25 18:14:13 ----RSD---- C:\WINDOWS\assembly
2011-01-25 18:13:03 ----D---- C:\WINDOWS\Microsoft.NET
2011-01-25 17:48:26 ----D---- C:\Program Files\Electronic Arts
2011-01-18 13:40:30 ----RA---- C:\WINDOWS\system32\vp6vfw.dll
2011-01-16 21:27:11 ----D---- C:\Program Files\SweetIM
2011-01-16 21:27:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\SweetIM
======List of files/folders modified in the last 1 months======
2011-02-08 12:11:23 ----RD---- C:\Program Files
2011-02-08 12:10:29 ----D---- C:\WINDOWS
2011-02-08 12:10:25 ----D---- C:\WINDOWS\system32\drivers
2011-02-08 12:05:51 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-08 10:47:50 ----D---- C:\WINDOWS\Temp
2011-02-08 09:46:31 ----D---- C:\WINDOWS\system32
2011-02-08 09:34:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-01 14:09:38 ----A---- C:\WINDOWS\DUMP53ad.tmp
2011-02-01 14:05:38 ----A---- C:\WINDOWS\DUMP516b.tmp
2011-02-01 12:07:06 ----D---- C:\WINDOWS\Prefetch
2011-02-01 12:05:51 ----SD---- C:\Documents and Settings\Peťa\Data aplikací\Microsoft
2011-02-01 12:05:12 ----SD---- C:\WINDOWS\Tasks
2011-01-30 20:13:51 ----D---- C:\Documents and Settings\Peťa\Data aplikací\ICQ
2011-01-30 10:52:35 ----D---- C:\Program Files\Opera
2011-01-30 10:52:21 ----SHD---- C:\WINDOWS\Installer
2011-01-29 22:07:18 ----D---- C:\Program Files\Common Files
2011-01-25 18:18:14 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-01-25 18:18:13 ----D---- C:\WINDOWS\WinSxS
2011-01-25 18:17:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-25 18:13:21 ----HD---- C:\WINDOWS\inf
2011-01-25 18:13:10 ----D---- C:\Program Files\Internet Explorer
2011-01-25 17:48:13 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-23 23:49:17 ----D---- C:\WINDOWS\Help
2011-01-21 23:47:01 ----A---- C:\WINDOWS\wincmd.ini
2011-01-18 18:34:00 ----D---- C:\Program Files\Magic Solitaire
2011-01-18 13:40:31 ----D---- C:\Program Files\EA GAMES
2011-01-18 13:38:24 ----D---- C:\Program Files\MyPlayCity.com
2011-01-18 13:34:11 ----D---- C:\Documents and Settings\Peťa\Data aplikací\DAEMON Tools Lite
2011-01-18 13:30:09 ----D---- C:\Program Files\Bus Simulator
2011-01-17 14:44:27 ----D---- C:\Documents and Settings\Peťa\Data aplikací\InImages
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2007-08-02 39936]
S2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
S2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2007-08-02 88448]
S2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2007-08-02 63232]
S2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2007-08-02 55936]
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2011-02-08 85969]
S3 GVCplDrv;GVCplDrv; C:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 23040]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-14 4676096]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-06-10 8087712]
S3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2007-08-02 163584]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-11-22 250496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-27 136176]
S2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
S2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-06-10 168004]
S2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2007-08-02 14336]
S2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~1\SMILEY~2\bar\1.bin\1vbarsvc.exe [2010-11-12 28766]
S2 upauylponz29iuac;SigmaTel Audio Service; C:\Documents and Settings\LocalService\Data aplikací\Microsoft\naturyttoof.exe [2011-01-31 229888]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-02-06 20680]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-08 545568]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2007-08-02 14336]
-----------------EOF-----------------
Run by Peťa at 2011-02-08 12:11:21
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 1 GB (3%) free of 38 GB
Total RAM: 503 MB (68% free)
HijackThis download failed
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
C:\WINDOWS\tasks\WGASetup.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-09-27 341600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
Conduit Engine - C:\Program Files\ConduitEngine\ConduitEngine.dll [2010-10-18 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A}]
CentrumczToolbar BHO - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFre2.dll [2010-10-18 3908192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Plug-In - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-11-22 1242504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
MyPlayCity Toolbar BHO - C:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-11-30 1536000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
SweetIM Toolbar Helper - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2010-10-18 1485112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2010-03-25 968000]
{D5D47440-0750-463D-BAEF-A47D02414806} - Centrum.cz Toolbar - C:\Program Files\CentrumczToolbar\IEToolbar.dll [2010-02-12 1274160]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-03-28 1017592]
{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec} - Free Lunch Design Toolbar - C:\Program Files\Free_Lunch_Design\tbFre2.dll [2010-10-18 3908192]
{648ADDE1-369B-4868-A419-0B67EBFD8F73} - MyPlayCity Toolbar - C:\Program Files\MyPlayCity Toolbar\Toolbar.dll [2010-11-30 1536000]
{EEE6C35B-6118-11DC-9C72-001320C79847} - SweetIM Toolbar for Internet Explorer - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [2010-10-18 1485112]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-13 16857600]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-06-10 86016]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-06-10 13758464]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-02-06 2021400]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-09-27 202256]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-08 305440]
"NVIDIA driver monitor"=c:\windows\nvsvc32.exe [2011-01-02 87552]
"SweetIM"=C:\Program Files\SweetIM\Messenger\SweetIM.exe [2010-12-20 111928]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2009-07-13 414992]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2007-08-02 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-08-17 1667584]
"NVIDIA driver monitor"=c:\windows\nvsvc32.exe [2011-01-02 87552]
"ICQ"=~C:\Program Files\ICQ7.2\ICQ.exe silent loginmode=4 []
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-01-03 15028104]
"MSConfig"=C:\Documents and Settings\Peťa\gqva.exe [2011-01-31 17920]
"gaquoot"=C:\Documents and Settings\Peťa\Data aplikací\Microsoft\cudof.exe [2011-01-31 229888]
C:\Documents and Settings\Peťa\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe"="C:\Program Files\Ubisoft\Crytek\Far Cry\Bin32\FarCry.exe:*:Enabled:Far Cry"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe"="C:\Program Files\MyPlayCity Toolbar\TroubleShooter.exe:*:Enabled:MyPlayCity Toolbar (Helper)"
"C:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe"="C:\Program Files\MyPlayCity Toolbar\ToolbarUpdate.exe:*:Enabled:MyPlayCity Toolbar (Update)"
"C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe"="C:\Program Files\EA GAMES\Battlefield 1942\BF1942.exe:*:Enabled:BF1942"
"C:\Documents and Settings\Peťa\Plocha\facebook-pic00005267.exe"="c:\windows\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe"="C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe:*:Enabled:SweetIM Installer"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{62cb0c66-a47a-11df-bfb3-000fea522d86}]
shell\AutoRun\command - F:\TranscendService(JF).exe
======List of files/folders created in the last 1 months======
2011-02-08 12:11:23 ----D---- C:\Program Files\trend micro
2011-02-08 12:11:21 ----D---- C:\rsit
2011-02-08 12:10:29 ----A---- C:\WINDOWS\gmer.ini
2011-02-08 12:10:25 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2011-02-08 12:10:25 ----A---- C:\WINDOWS\gmer.dll
2011-02-08 12:10:24 ----A---- C:\WINDOWS\gmer.exe
2011-02-08 12:07:35 ----D---- C:\Documents and Settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 12:07:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-02-08 12:07:20 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-02-08 12:06:59 ----D---- C:\Program Files\Yahoo!
2011-02-08 12:06:51 ----D---- C:\Program Files\CCleaner
2011-02-08 12:06:36 ----D---- C:\ComboFix
2011-02-08 09:44:44 ----A---- C:\WINDOWS\ntbtlog.txt
2011-01-31 21:03:25 ----AH---- C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt
2011-01-31 21:02:14 ----RSH---- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
2011-01-31 21:02:06 ----A---- C:\ni.exe
2011-01-29 22:13:41 ----D---- C:\Documents and Settings\Peťa\Data aplikací\skypePM
2011-01-29 22:07:18 ----D---- C:\Program Files\Common Files\Skype
2011-01-29 22:07:09 ----RD---- C:\Program Files\Skype
2011-01-29 22:07:07 ----D---- C:\Documents and Settings\Peťa\Data aplikací\Skype
2011-01-29 22:06:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2011-01-25 18:22:01 ----D---- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
2011-01-25 18:18:19 ----D---- C:\Program Files\Microsoft WSE
2011-01-25 18:14:13 ----RSD---- C:\WINDOWS\assembly
2011-01-25 18:13:03 ----D---- C:\WINDOWS\Microsoft.NET
2011-01-25 17:48:26 ----D---- C:\Program Files\Electronic Arts
2011-01-18 13:40:30 ----RA---- C:\WINDOWS\system32\vp6vfw.dll
2011-01-16 21:27:11 ----D---- C:\Program Files\SweetIM
2011-01-16 21:27:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\SweetIM
======List of files/folders modified in the last 1 months======
2011-02-08 12:11:23 ----RD---- C:\Program Files
2011-02-08 12:10:29 ----D---- C:\WINDOWS
2011-02-08 12:10:25 ----D---- C:\WINDOWS\system32\drivers
2011-02-08 12:05:51 ----D---- C:\WINDOWS\system32\CatRoot2
2011-02-08 10:47:50 ----D---- C:\WINDOWS\Temp
2011-02-08 09:46:31 ----D---- C:\WINDOWS\system32
2011-02-08 09:34:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-02-01 14:09:38 ----A---- C:\WINDOWS\DUMP53ad.tmp
2011-02-01 14:05:38 ----A---- C:\WINDOWS\DUMP516b.tmp
2011-02-01 12:07:06 ----D---- C:\WINDOWS\Prefetch
2011-02-01 12:05:51 ----SD---- C:\Documents and Settings\Peťa\Data aplikací\Microsoft
2011-02-01 12:05:12 ----SD---- C:\WINDOWS\Tasks
2011-01-30 20:13:51 ----D---- C:\Documents and Settings\Peťa\Data aplikací\ICQ
2011-01-30 10:52:35 ----D---- C:\Program Files\Opera
2011-01-30 10:52:21 ----SHD---- C:\WINDOWS\Installer
2011-01-29 22:07:18 ----D---- C:\Program Files\Common Files
2011-01-25 18:18:14 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-01-25 18:18:13 ----D---- C:\WINDOWS\WinSxS
2011-01-25 18:17:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-01-25 18:13:21 ----HD---- C:\WINDOWS\inf
2011-01-25 18:13:10 ----D---- C:\Program Files\Internet Explorer
2011-01-25 17:48:13 ----HD---- C:\Program Files\InstallShield Installation Information
2011-01-23 23:49:17 ----D---- C:\WINDOWS\Help
2011-01-21 23:47:01 ----A---- C:\WINDOWS\wincmd.ini
2011-01-18 18:34:00 ----D---- C:\Program Files\Magic Solitaire
2011-01-18 13:40:31 ----D---- C:\Program Files\EA GAMES
2011-01-18 13:38:24 ----D---- C:\Program Files\MyPlayCity.com
2011-01-18 13:34:11 ----D---- C:\Documents and Settings\Peťa\Data aplikací\DAEMON Tools Lite
2011-01-18 13:30:09 ----D---- C:\Program Files\Bus Simulator
2011-01-17 14:44:27 ----D---- C:\Documents and Settings\Peťa\Data aplikací\InImages
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
S1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2007-08-02 39936]
S2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-02-06 113448]
S2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2007-08-02 88448]
S2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2007-08-02 63232]
S2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2007-08-02 55936]
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2011-02-08 85969]
S3 GVCplDrv;GVCplDrv; C:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 23040]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-14 4676096]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-06-10 8087712]
S3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2007-08-02 163584]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-11-22 250496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
S2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-27 136176]
S2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-03-28 246520]
S2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-06-10 168004]
S2 NWCWorkstation;Klient systému NetWare; C:\WINDOWS\system32\svchost.exe [2007-08-02 14336]
S2 SmileyCentral_1vService;SmileyCentral Service; C:\PROGRA~1\SMILEY~2\bar\1.bin\1vbarsvc.exe [2010-11-12 28766]
S2 upauylponz29iuac;SigmaTel Audio Service; C:\Documents and Settings\LocalService\Data aplikací\Microsoft\naturyttoof.exe [2011-01-31 229888]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-02-06 20680]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-08 545568]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2007-08-02 14336]
-----------------EOF-----------------
Re: prosím o kontrolu logu při najetí se restartuje......
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2011-02-08 12:46:19
Windows 5.1.2600 Service Pack 2
---- User code sections - GMER 1.0.14 ----
.text C:\Documents and Settings\Peťa\Plocha\gmer.exe[752] ADVAPI32.dll!RegCreateKeyExW 77DC774C 1 Byte [ E9 ]
.text C:\Documents and Settings\Peťa\Plocha\gmer.exe[752] ADVAPI32.dll!RegCreateKeyExW + 2 77DC774E 3 Bytes [ 3B, 28, FA ]
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0xDE 0x60 0xBD ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3D 0x5C 0xE9 0x4C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF6 0x2F 0xF5 0x53 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0xDE 0x60 0xBD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3D 0x5C 0xE9 0x4C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF6 0x2F 0xF5 0x53 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0xDE 0x60 0xBD ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3D 0x5C 0xE9 0x4C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF6 0x2F 0xF5 0x53 ...
---- EOF - GMER 1.0.14 ----
Rootkit scan 2011-02-08 12:46:19
Windows 5.1.2600 Service Pack 2
---- User code sections - GMER 1.0.14 ----
.text C:\Documents and Settings\Peťa\Plocha\gmer.exe[752] ADVAPI32.dll!RegCreateKeyExW 77DC774C 1 Byte [ E9 ]
.text C:\Documents and Settings\Peťa\Plocha\gmer.exe[752] ADVAPI32.dll!RegCreateKeyExW + 2 77DC774E 3 Bytes [ 3B, 28, FA ]
---- Registry - GMER 1.0.14 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0xDE 0x60 0xBD ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3D 0x5C 0xE9 0x4C ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF6 0x2F 0xF5 0x53 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0xDE 0x60 0xBD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3D 0x5C 0xE9 0x4C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF6 0x2F 0xF5 0x53 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA2 0xDE 0x60 0xBD ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x3D 0x5C 0xE9 0x4C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF6 0x2F 0xF5 0x53 ...
---- EOF - GMER 1.0.14 ----
Re: prosím o kontrolu logu při najetí se restartuje......
Dobrý večer
Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix


http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu při najetí se restartuje......
ComboFix 11-02-08.03 - Peťa 09.02.2011 8:39.1.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.361 [GMT 1:00]
Spuštěný z: c:\documents and settings\Peťa\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Data aplikací\Microsoft\cudof.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\naturyttoof.exe
c:\documents and settings\Peťa\Data aplikací\Microsoft\cudof.exe
c:\documents and settings\Peťa\Data aplikací\Microsoft\naturyttoof.exe
c:\windows\nvsvc32.exe
c:\windows\system32\secupdat.dat
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_upauylponz29iuac
-------\Service_upauylponz29iuac
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-09 do 2011-02-09 )))))))))))))))))))))))))))))))
.
2011-02-09 08:21 . 2011-02-09 08:21 739328 ----a-w- c:\windows\system32\drivers\jpylwawnj.sys
2011-02-09 07:25 . 2011-02-09 07:25 739328 ----a-w- c:\windows\system32\drivers\ybvmafar.sys
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- c:\program files\trend micro
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- C:\rsit
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 11:07 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\Yahoo!
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\CCleaner
2011-02-08 11:02 . 2011-02-08 11:02 739328 ----a-w- c:\windows\system32\drivers\zglssjuip.sys
2011-02-08 10:31 . 2011-02-08 10:31 739328 ----a-w- c:\windows\system32\drivers\ponflyf.sys
2011-02-08 08:31 . 2011-02-08 08:31 739328 ----a-w- c:\windows\system32\drivers\wgieaazid.sys
2011-02-04 18:03 . 2011-02-04 18:03 739328 ----a-w- c:\windows\system32\drivers\vkaoyph.sys
2011-02-04 17:46 . 2011-02-04 17:46 739328 ----a-w- c:\windows\system32\drivers\udabpjno.sys
2011-02-04 17:44 . 2011-02-04 17:44 739328 ----a-w- c:\windows\system32\drivers\ihgthd.sys
2011-02-04 17:43 . 2011-02-04 17:43 739328 ----a-w- c:\windows\system32\drivers\kctkrynn.sys
2011-02-03 14:13 . 2011-02-03 14:13 739328 ----a-w- c:\windows\system32\drivers\gkzwsipxd.sys
2011-02-03 14:12 . 2011-02-03 14:12 739328 ----a-w- c:\windows\system32\drivers\npyys.sys
2011-02-03 14:11 . 2011-02-03 14:11 739328 ----a-w- c:\windows\system32\drivers\twsvwducr.sys
2011-02-03 14:09 . 2011-02-03 14:09 739328 ----a-w- c:\windows\system32\drivers\obarb.sys
2011-02-02 12:46 . 2011-02-02 12:46 739328 ----a-w- c:\windows\system32\drivers\droexbjz.sys
2011-02-02 04:00 . 2011-02-02 04:00 739328 ----a-w- c:\windows\system32\drivers\decnqmxr.sys
2011-02-01 19:14 . 2011-02-01 19:14 739328 ----a-w- c:\windows\system32\drivers\cvlukcdha.sys
2011-02-01 19:12 . 2011-02-01 19:12 739328 ----a-w- c:\windows\system32\drivers\nsbylfang.sys
2011-02-01 17:34 . 2011-02-01 17:34 739328 ----a-w- c:\windows\system32\drivers\bodmarlf.sys
2011-02-01 17:33 . 2011-02-01 17:33 739328 ----a-w- c:\windows\system32\drivers\akgqehfe.sys
2011-02-01 17:31 . 2011-02-01 17:31 739328 ----a-w- c:\windows\system32\drivers\eqfkegryl.sys
2011-02-01 14:20 . 2011-02-01 17:22 739328 ----a-w- c:\windows\system32\drivers\imjmqna.sys
2011-02-01 14:18 . 2011-02-01 14:18 739328 ----a-w- c:\windows\system32\drivers\cyueiaj.sys
2011-02-01 14:17 . 2011-02-01 14:17 739328 ----a-w- c:\windows\system32\drivers\hwtzhtdv.sys
2011-02-01 14:13 . 2011-02-01 14:13 739328 ----a-w- c:\windows\system32\drivers\rwpvlm.sys
2011-02-01 14:12 . 2011-02-01 14:12 739328 ----a-w- c:\windows\system32\drivers\gwubv.sys
2011-02-01 14:11 . 2011-02-01 14:11 739328 ----a-w- c:\windows\system32\drivers\bvodeha.sys
2011-02-01 14:09 . 2011-02-01 14:09 739328 ----a-w- c:\windows\system32\drivers\prlzh.sys
2011-02-01 14:07 . 2011-02-01 14:07 739328 ----a-w- c:\windows\system32\drivers\zguns.sys
2011-02-01 13:14 . 2011-02-01 13:14 739328 ----a-w- c:\windows\system32\drivers\xeacvpulh.sys
2011-02-01 13:13 . 2011-02-01 13:13 739328 ----a-w- c:\windows\system32\drivers\idecctqu.sys
2011-02-01 13:11 . 2011-02-01 13:11 739328 ----a-w- c:\windows\system32\drivers\rafea.sys
2011-02-01 13:08 . 2011-02-01 13:08 739328 ----a-w- c:\windows\system32\drivers\pfwcd.sys
2011-02-01 13:07 . 2011-02-01 13:07 739328 ----a-w- c:\windows\system32\drivers\ugxoiskgx.sys
2011-02-01 13:04 . 2011-02-01 13:04 739328 ----a-w- c:\windows\system32\drivers\avoqebum.sys
2011-02-01 13:03 . 2011-02-01 13:03 739328 ----a-w- c:\windows\system32\drivers\lgawlex.sys
2011-02-01 11:14 . 2011-02-01 11:14 739328 ----a-w- c:\windows\system32\drivers\pmykpd.sys
2011-02-01 11:12 . 2011-02-01 11:12 739328 ----a-w- c:\windows\system32\drivers\dktnzimx.sys
2011-02-01 11:10 . 2011-02-01 11:10 739328 ----a-w- c:\windows\system32\drivers\ylsvj.sys
2011-02-01 11:08 . 2011-02-01 11:08 739328 ----a-w- c:\windows\system32\drivers\zqnzulh.sys
2011-02-01 11:07 . 2011-02-01 11:07 739328 ----a-w- c:\windows\system32\drivers\pslipbbb.sys
2011-01-31 20:03 . 2011-01-31 20:03 17920 ---ha-w- c:\documents and settings\Peťa\gqva.exe
2011-01-31 20:02 . 2011-01-31 20:02 126976 --sh--r- c:\documents and settings\Peťa\Data aplikací\juzjf.exe
2011-01-31 20:02 . 2011-01-31 20:02 126976 ----a-w- C:\ni.exe
2011-01-29 21:13 . 2011-01-31 13:32 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\skypePM
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----w- c:\program files\Common Files\Skype
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----r- c:\program files\Skype
2011-01-29 21:07 . 2011-01-31 20:38 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Skype
2011-01-29 21:06 . 2011-01-29 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-01-25 17:22 . 2011-01-25 17:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-01-25 17:18 . 2011-01-25 17:18 -------- d-----w- c:\program files\Microsoft WSE
2011-01-25 16:48 . 2011-01-25 16:48 -------- d-----w- c:\program files\Electronic Arts
2011-01-18 12:40 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-16 20:27 . 2011-01-16 20:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SweetIM
2011-01-16 20:27 . 2011-01-16 20:27 -------- d-----w- c:\program files\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-01 13:09 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP53ad.tmp
2011-02-01 13:05 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP516b.tmp
2011-02-01 11:07 . 2010-08-10 08:37 739328 ----a-w- c:\windows\system32\drivers\aec.sys
2010-12-26 21:34 . 2007-08-02 12:00 29392 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-11-20 18:27 . 2010-11-20 18:27 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
------- Sigcheck -------
[-] 2011-02-01 11:07 . 569BF3687D4F26FB5E992FE4AD4A5164 . 739328 . . [6.0.6000.16386] . . c:\windows\system32\drivers\aec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys
[7] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\dllcache\aec.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"= "c:\program files\Free_Lunch_Design\tbFre2.dll" [2010-10-18 3908192]
"{3a750e59-9048-456b-a7f9-4d22dcb583f3}"= "c:\program files\MyPlayCity Toolbar\Helper.dll" [2010-11-30 356864]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2010-10-18 138552]
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[HKEY_CLASSES_ROOT\clsid\{3a750e59-9048-456b-a7f9-4d22dcb583f3}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{B4A5B3E8-CF41-4CCD-BEEA-C4445836DC6A}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\Free_Lunch_Design\tbFre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
2010-11-30 17:53 1536000 ----a-w- c:\program files\MyPlayCity Toolbar\Toolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2010-10-18 16:28 1485112 ----a-r- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"= "c:\program files\Free_Lunch_Design\tbFre2.dll" [2010-10-18 3908192]
"{648ADDE1-369B-4868-A419-0B67EBFD8F73}"= "c:\program files\MyPlayCity Toolbar\Toolbar.dll" [2010-11-30 1536000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2010-10-18 1485112]
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[HKEY_CLASSES_ROOT\clsid\{648adde1-369b-4868-a419-0b67ebfd8f73}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{FD06BF24-8C4E-49C7-9ABB-C833F0C87116}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC}"= "c:\program files\Free_Lunch_Design\tbFre2.dll" [2010-10-18 3908192]
"{648ADDE1-369B-4868-A419-0B67EBFD8F73}"= "c:\program files\MyPlayCity Toolbar\Toolbar.dll" [2010-11-30 1536000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2010-10-18 1485112]
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[HKEY_CLASSES_ROOT\clsid\{648adde1-369b-4868-a419-0b67ebfd8f73}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{FD06BF24-8C4E-49C7-9ABB-C833F0C87116}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-08-02 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Peťa^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Peťa\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\Peťa\gqva.exe \u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2009-02-06 12:23 2021400 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 13:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-03 14:44 15028104 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2010-12-20 16:15 111928 ----a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-09-27 16:16 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Documents and Settings\\Peťa\\Plocha\\facebook-pic00005267.exe"= c:\\windows\\nvsvc32.exe
"c:\\Documents and Settings\\Peťa\\Plocha\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.8.2010 13:35 691696]
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 13:23 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 13:24 93336]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 13:23 727720]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.9.2010 17:13 136176]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.8.2010 11:18 246520]
S2 SmileyCentral_1vService;SmileyCentral Service;c:\progra~1\SMILEY~2\bar\1.bin\1vbarsvc.exe [12.11.2010 18:56 28766]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-08 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-30 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://home.sweetim.com
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FDCB521-35A7-4342-A0C7-1194C9EBB954} = 88.103.252.2,194.228.2.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb002YYCZ_ZNzfb014&ptb=7C552DF5-D873-46DD-BDA3-3CC277730C7F&psa=&ind=2010111304&ptnrS=ZNzfb002YYCZ_ZNzfb014&si=&st=kwd&n=77cfdd48&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Centrum.cz Toolbar em:version=1.202.012.001 em:displayname=Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Centrum.cz Toolbar! em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files\SmileyCentral_1v\bar\1.bin
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-gaquoot - c:\documents and settings\Peťa\Data aplikací\Microsoft\cudof.exe
MSConfigStartUp-ICQ - ~c:\program files\ICQ7.2\ICQ.exe
AddRemove-Caesar 3 - c:\sierra\Caesar3\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-09 09:24
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(648)
c:\windows\system32\msi.dll
.
Celkový čas: 2011-02-09 09:31:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-09 08:31
Před spuštěním: 1 338 478 592
Po spuštění: 1 909 305 344
- - End Of File - - 5B2BD41AB04FD25EFD747A82B2C8ACCD
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.361 [GMT 1:00]
Spuštěný z: c:\documents and settings\Peťa\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Data aplikací\Microsoft\cudof.exe
c:\documents and settings\LocalService\Data aplikací\Microsoft\naturyttoof.exe
c:\documents and settings\Peťa\Data aplikací\Microsoft\cudof.exe
c:\documents and settings\Peťa\Data aplikací\Microsoft\naturyttoof.exe
c:\windows\nvsvc32.exe
c:\windows\system32\secupdat.dat
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_upauylponz29iuac
-------\Service_upauylponz29iuac
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-09 do 2011-02-09 )))))))))))))))))))))))))))))))
.
2011-02-09 08:21 . 2011-02-09 08:21 739328 ----a-w- c:\windows\system32\drivers\jpylwawnj.sys
2011-02-09 07:25 . 2011-02-09 07:25 739328 ----a-w- c:\windows\system32\drivers\ybvmafar.sys
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- c:\program files\trend micro
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- C:\rsit
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 11:07 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\Yahoo!
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\CCleaner
2011-02-08 11:02 . 2011-02-08 11:02 739328 ----a-w- c:\windows\system32\drivers\zglssjuip.sys
2011-02-08 10:31 . 2011-02-08 10:31 739328 ----a-w- c:\windows\system32\drivers\ponflyf.sys
2011-02-08 08:31 . 2011-02-08 08:31 739328 ----a-w- c:\windows\system32\drivers\wgieaazid.sys
2011-02-04 18:03 . 2011-02-04 18:03 739328 ----a-w- c:\windows\system32\drivers\vkaoyph.sys
2011-02-04 17:46 . 2011-02-04 17:46 739328 ----a-w- c:\windows\system32\drivers\udabpjno.sys
2011-02-04 17:44 . 2011-02-04 17:44 739328 ----a-w- c:\windows\system32\drivers\ihgthd.sys
2011-02-04 17:43 . 2011-02-04 17:43 739328 ----a-w- c:\windows\system32\drivers\kctkrynn.sys
2011-02-03 14:13 . 2011-02-03 14:13 739328 ----a-w- c:\windows\system32\drivers\gkzwsipxd.sys
2011-02-03 14:12 . 2011-02-03 14:12 739328 ----a-w- c:\windows\system32\drivers\npyys.sys
2011-02-03 14:11 . 2011-02-03 14:11 739328 ----a-w- c:\windows\system32\drivers\twsvwducr.sys
2011-02-03 14:09 . 2011-02-03 14:09 739328 ----a-w- c:\windows\system32\drivers\obarb.sys
2011-02-02 12:46 . 2011-02-02 12:46 739328 ----a-w- c:\windows\system32\drivers\droexbjz.sys
2011-02-02 04:00 . 2011-02-02 04:00 739328 ----a-w- c:\windows\system32\drivers\decnqmxr.sys
2011-02-01 19:14 . 2011-02-01 19:14 739328 ----a-w- c:\windows\system32\drivers\cvlukcdha.sys
2011-02-01 19:12 . 2011-02-01 19:12 739328 ----a-w- c:\windows\system32\drivers\nsbylfang.sys
2011-02-01 17:34 . 2011-02-01 17:34 739328 ----a-w- c:\windows\system32\drivers\bodmarlf.sys
2011-02-01 17:33 . 2011-02-01 17:33 739328 ----a-w- c:\windows\system32\drivers\akgqehfe.sys
2011-02-01 17:31 . 2011-02-01 17:31 739328 ----a-w- c:\windows\system32\drivers\eqfkegryl.sys
2011-02-01 14:20 . 2011-02-01 17:22 739328 ----a-w- c:\windows\system32\drivers\imjmqna.sys
2011-02-01 14:18 . 2011-02-01 14:18 739328 ----a-w- c:\windows\system32\drivers\cyueiaj.sys
2011-02-01 14:17 . 2011-02-01 14:17 739328 ----a-w- c:\windows\system32\drivers\hwtzhtdv.sys
2011-02-01 14:13 . 2011-02-01 14:13 739328 ----a-w- c:\windows\system32\drivers\rwpvlm.sys
2011-02-01 14:12 . 2011-02-01 14:12 739328 ----a-w- c:\windows\system32\drivers\gwubv.sys
2011-02-01 14:11 . 2011-02-01 14:11 739328 ----a-w- c:\windows\system32\drivers\bvodeha.sys
2011-02-01 14:09 . 2011-02-01 14:09 739328 ----a-w- c:\windows\system32\drivers\prlzh.sys
2011-02-01 14:07 . 2011-02-01 14:07 739328 ----a-w- c:\windows\system32\drivers\zguns.sys
2011-02-01 13:14 . 2011-02-01 13:14 739328 ----a-w- c:\windows\system32\drivers\xeacvpulh.sys
2011-02-01 13:13 . 2011-02-01 13:13 739328 ----a-w- c:\windows\system32\drivers\idecctqu.sys
2011-02-01 13:11 . 2011-02-01 13:11 739328 ----a-w- c:\windows\system32\drivers\rafea.sys
2011-02-01 13:08 . 2011-02-01 13:08 739328 ----a-w- c:\windows\system32\drivers\pfwcd.sys
2011-02-01 13:07 . 2011-02-01 13:07 739328 ----a-w- c:\windows\system32\drivers\ugxoiskgx.sys
2011-02-01 13:04 . 2011-02-01 13:04 739328 ----a-w- c:\windows\system32\drivers\avoqebum.sys
2011-02-01 13:03 . 2011-02-01 13:03 739328 ----a-w- c:\windows\system32\drivers\lgawlex.sys
2011-02-01 11:14 . 2011-02-01 11:14 739328 ----a-w- c:\windows\system32\drivers\pmykpd.sys
2011-02-01 11:12 . 2011-02-01 11:12 739328 ----a-w- c:\windows\system32\drivers\dktnzimx.sys
2011-02-01 11:10 . 2011-02-01 11:10 739328 ----a-w- c:\windows\system32\drivers\ylsvj.sys
2011-02-01 11:08 . 2011-02-01 11:08 739328 ----a-w- c:\windows\system32\drivers\zqnzulh.sys
2011-02-01 11:07 . 2011-02-01 11:07 739328 ----a-w- c:\windows\system32\drivers\pslipbbb.sys
2011-01-31 20:03 . 2011-01-31 20:03 17920 ---ha-w- c:\documents and settings\Peťa\gqva.exe
2011-01-31 20:02 . 2011-01-31 20:02 126976 --sh--r- c:\documents and settings\Peťa\Data aplikací\juzjf.exe
2011-01-31 20:02 . 2011-01-31 20:02 126976 ----a-w- C:\ni.exe
2011-01-29 21:13 . 2011-01-31 13:32 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\skypePM
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----w- c:\program files\Common Files\Skype
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----r- c:\program files\Skype
2011-01-29 21:07 . 2011-01-31 20:38 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Skype
2011-01-29 21:06 . 2011-01-29 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-01-25 17:22 . 2011-01-25 17:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-01-25 17:18 . 2011-01-25 17:18 -------- d-----w- c:\program files\Microsoft WSE
2011-01-25 16:48 . 2011-01-25 16:48 -------- d-----w- c:\program files\Electronic Arts
2011-01-18 12:40 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-16 20:27 . 2011-01-16 20:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SweetIM
2011-01-16 20:27 . 2011-01-16 20:27 -------- d-----w- c:\program files\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-01 13:09 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP53ad.tmp
2011-02-01 13:05 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP516b.tmp
2011-02-01 11:07 . 2010-08-10 08:37 739328 ----a-w- c:\windows\system32\drivers\aec.sys
2010-12-26 21:34 . 2007-08-02 12:00 29392 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-11-20 18:27 . 2010-11-20 18:27 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
------- Sigcheck -------
[-] 2011-02-01 11:07 . 569BF3687D4F26FB5E992FE4AD4A5164 . 739328 . . [6.0.6000.16386] . . c:\windows\system32\drivers\aec.sys
[-] 2008-04-13 16:39 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys
[7] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\dllcache\aec.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"= "c:\program files\Free_Lunch_Design\tbFre2.dll" [2010-10-18 3908192]
"{3a750e59-9048-456b-a7f9-4d22dcb583f3}"= "c:\program files\MyPlayCity Toolbar\Helper.dll" [2010-11-30 356864]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2010-10-18 138552]
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[HKEY_CLASSES_ROOT\clsid\{3a750e59-9048-456b-a7f9-4d22dcb583f3}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{B4A5B3E8-CF41-4CCD-BEEA-C4445836DC6A}]
[HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
2010-10-18 10:26 3908192 ----a-w- c:\program files\Free_Lunch_Design\tbFre2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
2010-11-30 17:53 1536000 ----a-w- c:\program files\MyPlayCity Toolbar\Toolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2010-10-18 16:28 1485112 ----a-r- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"= "c:\program files\Free_Lunch_Design\tbFre2.dll" [2010-10-18 3908192]
"{648ADDE1-369B-4868-A419-0B67EBFD8F73}"= "c:\program files\MyPlayCity Toolbar\Toolbar.dll" [2010-11-30 1536000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2010-10-18 1485112]
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[HKEY_CLASSES_ROOT\clsid\{648adde1-369b-4868-a419-0b67ebfd8f73}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{FD06BF24-8C4E-49C7-9ABB-C833F0C87116}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC}"= "c:\program files\Free_Lunch_Design\tbFre2.dll" [2010-10-18 3908192]
"{648ADDE1-369B-4868-A419-0B67EBFD8F73}"= "c:\program files\MyPlayCity Toolbar\Toolbar.dll" [2010-11-30 1536000]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2010-10-18 1485112]
[HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[HKEY_CLASSES_ROOT\clsid\{648adde1-369b-4868-a419-0b67ebfd8f73}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{FD06BF24-8C4E-49C7-9ABB-C833F0C87116}]
[HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-08-02 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Peťa^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Peťa\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\Peťa\gqva.exe \u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2009-02-06 12:23 2021400 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 13:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-03 14:44 15028104 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2010-12-20 16:15 111928 ----a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-09-27 16:16 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Documents and Settings\\Peťa\\Plocha\\facebook-pic00005267.exe"= c:\\windows\\nvsvc32.exe
"c:\\Documents and Settings\\Peťa\\Plocha\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.8.2010 13:35 691696]
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 13:23 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 13:24 93336]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 13:23 727720]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.9.2010 17:13 136176]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.8.2010 11:18 246520]
S2 SmileyCentral_1vService;SmileyCentral Service;c:\progra~1\SMILEY~2\bar\1.bin\1vbarsvc.exe [12.11.2010 18:56 28766]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-08 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-30 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://home.sweetim.com
mStart Page = hxxp://home.sweetim.com
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FDCB521-35A7-4342-A0C7-1194C9EBB954} = 88.103.252.2,194.228.2.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZNzfb002YYCZ_ZNzfb014&ptb=7C552DF5-D873-46DD-BDA3-3CC277730C7F&psa=&ind=2010111304&ptnrS=ZNzfb002YYCZ_ZNzfb014&si=&st=kwd&n=77cfdd48&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Centrum.cz Toolbar em:version=1.202.012.001 em:displayname=Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Centrum.cz Toolbar! em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files\SmileyCentral_1v\bar\1.bin
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
MSConfigStartUp-gaquoot - c:\documents and settings\Peťa\Data aplikací\Microsoft\cudof.exe
MSConfigStartUp-ICQ - ~c:\program files\ICQ7.2\ICQ.exe
AddRemove-Caesar 3 - c:\sierra\Caesar3\Uninst.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-09 09:24
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(648)
c:\windows\system32\msi.dll
.
Celkový čas: 2011-02-09 09:31:21 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-09 08:31
Před spuštěním: 1 338 478 592
Po spuštění: 1 909 305 344
- - End Of File - - 5B2BD41AB04FD25EFD747A82B2C8ACCD
Re: prosím o kontrolu logu při najetí se restartuje......
Nádhera
, proboha kde jste k tomu přišel? Tipla bych že to tqam máte už od konce ledna. Dejte mi tam 20 minut, než napíšu skript na smazání, máte tam chovnou stanici rootkitů




Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu při najetí se restartuje......



-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
Kód: Vybrat vše
KillAll::
Collect::
c:\windows\system32\drivers\zglssjuip.sys
c:\windows\system32\drivers\ponflyf.sys
c:\windows\system32\drivers\wgieaazid.sys
c:\windows\system32\drivers\vkaoyph.sys
c:\windows\system32\drivers\udabpjno.sys
c:\windows\system32\drivers\ihgthd.sys
c:\windows\system32\drivers\kctkrynn.sys
c:\windows\system32\drivers\gkzwsipxd.sys
c:\windows\system32\drivers\npyys.sys
c:\windows\system32\drivers\twsvwducr.sys
c:\windows\system32\drivers\obarb.sys
c:\windows\system32\drivers\droexbjz.sys
c:\windows\system32\drivers\decnqmxr.sys
c:\windows\system32\drivers\cvlukcdha.sys
c:\windows\system32\drivers\nsbylfang.sys
c:\windows\system32\drivers\bodmarlf.sys
c:\windows\system32\drivers\akgqehfe.sys
c:\windows\system32\drivers\eqfkegryl.sys
c:\windows\system32\drivers\imjmqna.sys
c:\windows\system32\drivers\cyueiaj.sys
c:\windows\system32\drivers\hwtzhtdv.sys
c:\windows\system32\drivers\rwpvlm.sys
c:\windows\system32\drivers\gwubv.sys
c:\windows\system32\drivers\bvodeha.sys
c:\windows\system32\drivers\prlzh.sys
c:\windows\system32\drivers\zguns.sys
c:\windows\system32\drivers\xeacvpulh.sys
c:\windows\system32\drivers\idecctqu.sys
c:\windows\system32\drivers\rafea.sys
c:\windows\system32\drivers\pfwcd.sys
c:\windows\system32\drivers\ugxoiskgx.sys
c:\windows\system32\drivers\avoqebum.sys
c:\windows\system32\drivers\lgawlex.sys
c:\windows\system32\drivers\pmykpd.sys
c:\windows\system32\drivers\dktnzimx.sys
c:\windows\system32\drivers\ylsvj.sys
c:\windows\system32\drivers\zqnzulh.sys
c:\windows\system32\drivers\pslipbbb.sys
c:\documents and settings\Peťa\gqva.exe
c:\documents and settings\Peťa\Data aplikací\juzjf.exe
C:\ni.exe
c:\windows\system32\drivers\jpylwawnj.sys
c:\windows\system32\drivers\ybvmafar.sys
c:\documents and settings\Peťa\gqva.exe
DDS::
uStart Page = hxxp://home.sweetim.com
mStart Page = hxxp://home.sweetim.com
Firefox::
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsear ... searchfor=
Registry::
[-HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[-HKEY_CLASSES_ROOT\clsid\{3a750e59-9048-456b-a7f9-4d22dcb583f3}]
[-HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1]
[-HKEY_CLASSES_ROOT\TypeLib\{B4A5B3E8-CF41-4CCD-BEEA-C4445836DC6A}]
[-HKEY_CLASSES_ROOT\FreeCauseURLSearchHook.FCToolbarURLSearchHook]
[-HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D496B221-52BB-4DA7-B5E7-4442022F207D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}"=-
"{648ADDE1-369B-4868-A419-0B67EBFD8F73}"=-
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[-HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[-HKEY_CLASSES_ROOT\clsid\{648adde1-369b-4868-a419-0b67ebfd8f73}]
[-HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar.3]
[-HKEY_CLASSES_ROOT\TypeLib\{FD06BF24-8C4E-49C7-9ABB-C833F0C87116}]
[-HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar]
[-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{57CC715D-37CA-44E4-9EC2-8C2CBDDB25EC}"=-
"{648ADDE1-369B-4868-A419-0B67EBFD8F73}"=-
"{EEE6C35B-6118-11DC-9C72-001320C79847}"=-
[-HKEY_CLASSES_ROOT\clsid\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}]
[-HKEY_CLASSES_ROOT\clsid\{648adde1-369b-4868-a419-0b67ebfd8f73}]
[-HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar.3]
[-HKEY_CLASSES_ROOT\TypeLib\{FD06BF24-8C4E-49C7-9ABB-C833F0C87116}]
[-HKEY_CLASSES_ROOT\FCTB000063009.IEToolbar]
[-HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[-HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[-HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
Restore::
c:\windows\system32\drivers\aec.sys
c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys
Folder::
c:\program files\SweetIM
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu při najetí se restartuje......
ComboFix 11-02-08.03 - Peťa 09.02.2011 12:11:46.2.2 - x86 MINIMAL
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.367 [GMT 1:00]
Spuštěný z: c:\documents and settings\Peťa\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Peťa\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
file zipped: c:\documents and settings\Peťa\Data aplikací\juzjf.exe
file zipped: c:\documents and settings\Peťa\gqva.exe
file zipped: C:\ni.exe
file zipped: c:\windows\system32\drivers\akgqehfe.sys
file zipped: c:\windows\system32\drivers\avoqebum.sys
file zipped: c:\windows\system32\drivers\bodmarlf.sys
file zipped: c:\windows\system32\drivers\bvodeha.sys
file zipped: c:\windows\system32\drivers\cvlukcdha.sys
file zipped: c:\windows\system32\drivers\cyueiaj.sys
file zipped: c:\windows\system32\drivers\decnqmxr.sys
file zipped: c:\windows\system32\drivers\dktnzimx.sys
file zipped: c:\windows\system32\drivers\droexbjz.sys
file zipped: c:\windows\system32\drivers\eqfkegryl.sys
file zipped: c:\windows\system32\drivers\gkzwsipxd.sys
file zipped: c:\windows\system32\drivers\gwubv.sys
file zipped: c:\windows\system32\drivers\hwtzhtdv.sys
file zipped: c:\windows\system32\drivers\idecctqu.sys
file zipped: c:\windows\system32\drivers\ihgthd.sys
file zipped: c:\windows\system32\drivers\imjmqna.sys
file zipped: c:\windows\system32\drivers\jpylwawnj.sys
file zipped: c:\windows\system32\drivers\kctkrynn.sys
file zipped: c:\windows\system32\drivers\lgawlex.sys
file zipped: c:\windows\system32\drivers\npyys.sys
file zipped: c:\windows\system32\drivers\nsbylfang.sys
file zipped: c:\windows\system32\drivers\obarb.sys
file zipped: c:\windows\system32\drivers\pfwcd.sys
file zipped: c:\windows\system32\drivers\pmykpd.sys
file zipped: c:\windows\system32\drivers\ponflyf.sys
file zipped: c:\windows\system32\drivers\prlzh.sys
file zipped: c:\windows\system32\drivers\pslipbbb.sys
file zipped: c:\windows\system32\drivers\rafea.sys
file zipped: c:\windows\system32\drivers\rwpvlm.sys
file zipped: c:\windows\system32\drivers\twsvwducr.sys
file zipped: c:\windows\system32\drivers\udabpjno.sys
file zipped: c:\windows\system32\drivers\ugxoiskgx.sys
file zipped: c:\windows\system32\drivers\vkaoyph.sys
file zipped: c:\windows\system32\drivers\wgieaazid.sys
file zipped: c:\windows\system32\drivers\xeacvpulh.sys
file zipped: c:\windows\system32\drivers\ybvmafar.sys
file zipped: c:\windows\system32\drivers\ylsvj.sys
file zipped: c:\windows\system32\drivers\zglssjuip.sys
file zipped: c:\windows\system32\drivers\zguns.sys
file zipped: c:\windows\system32\drivers\zqnzulh.sys
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ni.exe
c:\program files\SweetIM
c:\program files\SweetIM\Messenger\ContentPackagesActivationHandler.exe
c:\program files\SweetIM\Messenger\default.xml
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\program files\SweetIM\Messenger\mgArchive.dll
c:\program files\SweetIM\Messenger\mgcommon.dll
c:\program files\SweetIM\Messenger\mgcommunication.dll
c:\program files\SweetIM\Messenger\mgconfig.dll
c:\program files\SweetIM\Messenger\mgFlashPlayer.dll
c:\program files\SweetIM\Messenger\mghooking.dll
c:\program files\SweetIM\Messenger\mgICQAuto.dll
c:\program files\SweetIM\Messenger\mgICQMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mglogger.dll
c:\program files\SweetIM\Messenger\mgMediaPlayer.dll
c:\program files\SweetIM\Messenger\mgMsnAuto.dll
c:\program files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgsimcommon.dll
c:\program files\SweetIM\Messenger\mgSweetIM.dll
c:\program files\SweetIM\Messenger\mgUpdateSupport.dll
c:\program files\SweetIM\Messenger\mgxml_wrapper.dll
c:\program files\SweetIM\Messenger\mgYahooAuto.dll
c:\program files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
c:\program files\SweetIM\Messenger\msvcp71.dll
c:\program files\SweetIM\Messenger\msvcr71.dll
c:\program files\SweetIM\Messenger\resources\images\AudibleButton.png
c:\program files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
c:\program files\SweetIM\Messenger\resources\images\EmoticonButton.png
c:\program files\SweetIM\Messenger\resources\images\GamesButton.png
c:\program files\SweetIM\Messenger\resources\images\KeyboardButton.png
c:\program files\SweetIM\Messenger\resources\images\NudgeButton.png
c:\program files\SweetIM\Messenger\resources\images\SoundFxButton.png
c:\program files\SweetIM\Messenger\resources\images\WinksButton.png
c:\program files\SweetIM\Messenger\resources\sqlite\mgSqlite3.dll
c:\program files\SweetIM\Messenger\SweetIM.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\ClearHist.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\conf\logger.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\default.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\mgcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgconfig.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\mghooking.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mglogger.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcm90.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcp90.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcr90.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\about.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\affid.dat
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\basis.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_current.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_hover.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_left.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_photo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_web.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_yahoo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\clear-history.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim-over.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier.js
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dating.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\e_cards.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon_over.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\find.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\free_stuff.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\games.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\glitter.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_current.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_hover.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_left.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_photo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_web.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_yahoo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\help.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\highlight.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\locales.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_16x16.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_21x18.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_32x32.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_about.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\more-search-providers.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\music.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\news.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\options.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_current.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_hover.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_left.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_photo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_web.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_yahoo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\photos.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\search-current-site.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\shopping.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileySmile.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileyWink.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\sweetim_text.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\toolbar.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\version.txt
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\web-search.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\web-toolbar.js
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png
c:\windows\system32\drivers\akgqehfe.sys
c:\windows\system32\drivers\avoqebum.sys
c:\windows\system32\drivers\bodmarlf.sys
c:\windows\system32\drivers\bvodeha.sys
c:\windows\system32\drivers\cvlukcdha.sys
c:\windows\system32\drivers\cyueiaj.sys
c:\windows\system32\drivers\decnqmxr.sys
c:\windows\system32\drivers\dktnzimx.sys
c:\windows\system32\drivers\droexbjz.sys
c:\windows\system32\drivers\eqfkegryl.sys
c:\windows\system32\drivers\gkzwsipxd.sys
c:\windows\system32\drivers\gwubv.sys
c:\windows\system32\drivers\hwtzhtdv.sys
c:\windows\system32\drivers\idecctqu.sys
c:\windows\system32\drivers\ihgthd.sys
c:\windows\system32\drivers\imjmqna.sys
c:\windows\system32\drivers\jpylwawnj.sys
c:\windows\system32\drivers\kctkrynn.sys
c:\windows\system32\drivers\lgawlex.sys
c:\windows\system32\drivers\npyys.sys
c:\windows\system32\drivers\nsbylfang.sys
c:\windows\system32\drivers\obarb.sys
c:\windows\system32\drivers\pfwcd.sys
c:\windows\system32\drivers\pmykpd.sys
c:\windows\system32\drivers\ponflyf.sys
c:\windows\system32\drivers\prlzh.sys
c:\windows\system32\drivers\pslipbbb.sys
c:\windows\system32\drivers\rafea.sys
c:\windows\system32\drivers\rwpvlm.sys
c:\windows\system32\drivers\twsvwducr.sys
c:\windows\system32\drivers\udabpjno.sys
c:\windows\system32\drivers\ugxoiskgx.sys
c:\windows\system32\drivers\vkaoyph.sys
c:\windows\system32\drivers\wgieaazid.sys
c:\windows\system32\drivers\xeacvpulh.sys
c:\windows\system32\drivers\ybvmafar.sys
c:\windows\system32\drivers\ylsvj.sys
c:\windows\system32\drivers\zglssjuip.sys
c:\windows\system32\drivers\zguns.sys
c:\windows\system32\drivers\zqnzulh.sys
Nakažená kopie c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\aec.sys
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-09 do 2011-02-09 )))))))))))))))))))))))))))))))
.
2011-02-09 08:34 . 2011-02-09 08:34 -------- d-----w- c:\program files\XP_Key_Changer
2011-02-09 08:34 . 2008-02-21 00:12 36864 ----a-w- c:\windows\system32\MD5.ocx
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- c:\program files\trend micro
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- C:\rsit
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 11:07 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\Yahoo!
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\CCleaner
2011-01-31 20:03 . 2011-01-31 20:03 17920 ---ha-w- c:\documents and settings\Peťa\gqva.exe
2011-01-31 20:02 . 2011-01-31 20:02 126976 --sha-r- c:\documents and settings\Peťa\Data aplikací\juzjf.exe
2011-01-29 21:13 . 2011-01-31 13:32 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\skypePM
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----w- c:\program files\Common Files\Skype
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----r- c:\program files\Skype
2011-01-29 21:07 . 2011-01-31 20:38 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Skype
2011-01-29 21:06 . 2011-01-29 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-01-25 17:22 . 2011-01-25 17:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-01-25 17:18 . 2011-01-25 17:18 -------- d-----w- c:\program files\Microsoft WSE
2011-01-25 16:48 . 2011-01-25 16:48 -------- d-----w- c:\program files\Electronic Arts
2011-01-18 12:40 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-16 20:27 . 2011-01-16 20:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-01 13:09 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP53ad.tmp
2011-02-01 13:05 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP516b.tmp
2011-02-01 11:07 . 2010-08-10 08:37 739328 ----a-w- c:\windows\system32\drivers\aec.sys
2010-12-26 21:34 . 2007-08-02 12:00 29392 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-11-20 18:27 . 2010-11-20 18:27 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
------- Sigcheck -------
[-] 2011-02-01 11:07 . 569BF3687D4F26FB5E992FE4AD4A5164 . 739328 . . [6.0.6000.16386] . . c:\windows\system32\drivers\aec.sys
[7] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys
[7] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\dllcache\aec.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-08-02 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Peťa^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Peťa\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2009-02-06 12:23 2021400 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 13:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-03 14:44 15028104 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-09-27 16:16 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Documents and Settings\\Peťa\\Plocha\\facebook-pic00005267.exe"= c:\\windows\\nvsvc32.exe
"c:\\Documents and Settings\\Peťa\\Plocha\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.8.2010 13:35 691696]
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 13:23 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 13:24 93336]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 13:23 727720]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.9.2010 17:13 136176]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.8.2010 11:18 246520]
S2 SmileyCentral_1vService;SmileyCentral Service;c:\progra~1\SMILEY~2\bar\1.bin\1vbarsvc.exe [12.11.2010 18:56 28766]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-08 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-30 20:18]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FDCB521-35A7-4342-A0C7-1194C9EBB954} = 88.103.252.2,194.228.2.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Centrum.cz Toolbar em:version=1.202.012.001 em:displayname=Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Centrum.cz Toolbar! em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files\SmileyCentral_1v\bar\1.bin
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{3a750e59-9048-456b-a7f9-4d22dcb583f3} - (no file)
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
MSConfigStartUp-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-09 12:23
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2011-02-09 12:28:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-09 11:28
ComboFix2.txt 2011-02-09 08:31
Před spuštěním: 1 908 690 944
Po spuštění: 1 831 116 800
- - End Of File - - 70ED0EFC1CB9F3807E63143C4E1A116F
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.503.367 [GMT 1:00]
Spuštěný z: c:\documents and settings\Peťa\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Peťa\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
file zipped: c:\documents and settings\Peťa\Data aplikací\juzjf.exe
file zipped: c:\documents and settings\Peťa\gqva.exe
file zipped: C:\ni.exe
file zipped: c:\windows\system32\drivers\akgqehfe.sys
file zipped: c:\windows\system32\drivers\avoqebum.sys
file zipped: c:\windows\system32\drivers\bodmarlf.sys
file zipped: c:\windows\system32\drivers\bvodeha.sys
file zipped: c:\windows\system32\drivers\cvlukcdha.sys
file zipped: c:\windows\system32\drivers\cyueiaj.sys
file zipped: c:\windows\system32\drivers\decnqmxr.sys
file zipped: c:\windows\system32\drivers\dktnzimx.sys
file zipped: c:\windows\system32\drivers\droexbjz.sys
file zipped: c:\windows\system32\drivers\eqfkegryl.sys
file zipped: c:\windows\system32\drivers\gkzwsipxd.sys
file zipped: c:\windows\system32\drivers\gwubv.sys
file zipped: c:\windows\system32\drivers\hwtzhtdv.sys
file zipped: c:\windows\system32\drivers\idecctqu.sys
file zipped: c:\windows\system32\drivers\ihgthd.sys
file zipped: c:\windows\system32\drivers\imjmqna.sys
file zipped: c:\windows\system32\drivers\jpylwawnj.sys
file zipped: c:\windows\system32\drivers\kctkrynn.sys
file zipped: c:\windows\system32\drivers\lgawlex.sys
file zipped: c:\windows\system32\drivers\npyys.sys
file zipped: c:\windows\system32\drivers\nsbylfang.sys
file zipped: c:\windows\system32\drivers\obarb.sys
file zipped: c:\windows\system32\drivers\pfwcd.sys
file zipped: c:\windows\system32\drivers\pmykpd.sys
file zipped: c:\windows\system32\drivers\ponflyf.sys
file zipped: c:\windows\system32\drivers\prlzh.sys
file zipped: c:\windows\system32\drivers\pslipbbb.sys
file zipped: c:\windows\system32\drivers\rafea.sys
file zipped: c:\windows\system32\drivers\rwpvlm.sys
file zipped: c:\windows\system32\drivers\twsvwducr.sys
file zipped: c:\windows\system32\drivers\udabpjno.sys
file zipped: c:\windows\system32\drivers\ugxoiskgx.sys
file zipped: c:\windows\system32\drivers\vkaoyph.sys
file zipped: c:\windows\system32\drivers\wgieaazid.sys
file zipped: c:\windows\system32\drivers\xeacvpulh.sys
file zipped: c:\windows\system32\drivers\ybvmafar.sys
file zipped: c:\windows\system32\drivers\ylsvj.sys
file zipped: c:\windows\system32\drivers\zglssjuip.sys
file zipped: c:\windows\system32\drivers\zguns.sys
file zipped: c:\windows\system32\drivers\zqnzulh.sys
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ni.exe
c:\program files\SweetIM
c:\program files\SweetIM\Messenger\ContentPackagesActivationHandler.exe
c:\program files\SweetIM\Messenger\default.xml
c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
c:\program files\SweetIM\Messenger\mgArchive.dll
c:\program files\SweetIM\Messenger\mgcommon.dll
c:\program files\SweetIM\Messenger\mgcommunication.dll
c:\program files\SweetIM\Messenger\mgconfig.dll
c:\program files\SweetIM\Messenger\mgFlashPlayer.dll
c:\program files\SweetIM\Messenger\mghooking.dll
c:\program files\SweetIM\Messenger\mgICQAuto.dll
c:\program files\SweetIM\Messenger\mgICQMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mglogger.dll
c:\program files\SweetIM\Messenger\mgMediaPlayer.dll
c:\program files\SweetIM\Messenger\mgMsnAuto.dll
c:\program files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
c:\program files\SweetIM\Messenger\mgsimcommon.dll
c:\program files\SweetIM\Messenger\mgSweetIM.dll
c:\program files\SweetIM\Messenger\mgUpdateSupport.dll
c:\program files\SweetIM\Messenger\mgxml_wrapper.dll
c:\program files\SweetIM\Messenger\mgYahooAuto.dll
c:\program files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
c:\program files\SweetIM\Messenger\msvcp71.dll
c:\program files\SweetIM\Messenger\msvcr71.dll
c:\program files\SweetIM\Messenger\resources\images\AudibleButton.png
c:\program files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
c:\program files\SweetIM\Messenger\resources\images\EmoticonButton.png
c:\program files\SweetIM\Messenger\resources\images\GamesButton.png
c:\program files\SweetIM\Messenger\resources\images\KeyboardButton.png
c:\program files\SweetIM\Messenger\resources\images\NudgeButton.png
c:\program files\SweetIM\Messenger\resources\images\SoundFxButton.png
c:\program files\SweetIM\Messenger\resources\images\WinksButton.png
c:\program files\SweetIM\Messenger\resources\sqlite\mgSqlite3.dll
c:\program files\SweetIM\Messenger\SweetIM.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\ClearHist.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\conf\logger.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\default.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\mgcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgconfig.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe
c:\program files\SweetIM\Toolbars\Internet Explorer\mghooking.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mglogger.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcm90.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcp90.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT\msvcr90.dll
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\about.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\affid.dat
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\basis.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_current.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_hover.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_left.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_photo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_web.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\blue\search_button_yahoo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\clear-history.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim-over.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier-anim.gif
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\content-notifier.js
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dating.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\e_cards.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\eye_icon_over.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\find.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\free_stuff.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\games.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\glitter.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_current.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_hover.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_left.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_photo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_web.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\green\search_button_yahoo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\help.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\highlight.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\locales.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_16x16.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_21x18.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_32x32.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\logo_about.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\more-search-providers.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\music.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\news.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\options.html
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_bing.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_current.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_dictionary.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_google.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_hover.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_left.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_photo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_web.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\orange\search_button_yahoo.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\photos.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\search-current-site.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\shopping.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileySmile.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\SmileyWink.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\sweetim_text.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\toolbar.xml
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\version.txt
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\video.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\web-search.png
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\web-toolbar.js
c:\program files\SweetIM\Toolbars\Internet Explorer\resources\yahoo.png
c:\windows\system32\drivers\akgqehfe.sys
c:\windows\system32\drivers\avoqebum.sys
c:\windows\system32\drivers\bodmarlf.sys
c:\windows\system32\drivers\bvodeha.sys
c:\windows\system32\drivers\cvlukcdha.sys
c:\windows\system32\drivers\cyueiaj.sys
c:\windows\system32\drivers\decnqmxr.sys
c:\windows\system32\drivers\dktnzimx.sys
c:\windows\system32\drivers\droexbjz.sys
c:\windows\system32\drivers\eqfkegryl.sys
c:\windows\system32\drivers\gkzwsipxd.sys
c:\windows\system32\drivers\gwubv.sys
c:\windows\system32\drivers\hwtzhtdv.sys
c:\windows\system32\drivers\idecctqu.sys
c:\windows\system32\drivers\ihgthd.sys
c:\windows\system32\drivers\imjmqna.sys
c:\windows\system32\drivers\jpylwawnj.sys
c:\windows\system32\drivers\kctkrynn.sys
c:\windows\system32\drivers\lgawlex.sys
c:\windows\system32\drivers\npyys.sys
c:\windows\system32\drivers\nsbylfang.sys
c:\windows\system32\drivers\obarb.sys
c:\windows\system32\drivers\pfwcd.sys
c:\windows\system32\drivers\pmykpd.sys
c:\windows\system32\drivers\ponflyf.sys
c:\windows\system32\drivers\prlzh.sys
c:\windows\system32\drivers\pslipbbb.sys
c:\windows\system32\drivers\rafea.sys
c:\windows\system32\drivers\rwpvlm.sys
c:\windows\system32\drivers\twsvwducr.sys
c:\windows\system32\drivers\udabpjno.sys
c:\windows\system32\drivers\ugxoiskgx.sys
c:\windows\system32\drivers\vkaoyph.sys
c:\windows\system32\drivers\wgieaazid.sys
c:\windows\system32\drivers\xeacvpulh.sys
c:\windows\system32\drivers\ybvmafar.sys
c:\windows\system32\drivers\ylsvj.sys
c:\windows\system32\drivers\zglssjuip.sys
c:\windows\system32\drivers\zguns.sys
c:\windows\system32\drivers\zqnzulh.sys
Nakažená kopie c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\dllcache\aec.sys
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-01-09 do 2011-02-09 )))))))))))))))))))))))))))))))
.
2011-02-09 08:34 . 2011-02-09 08:34 -------- d-----w- c:\program files\XP_Key_Changer
2011-02-09 08:34 . 2008-02-21 00:12 36864 ----a-w- c:\windows\system32\MD5.ocx
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- c:\program files\trend micro
2011-02-08 11:11 . 2011-02-08 11:11 -------- d-----w- C:\rsit
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2011-02-08 11:07 . 2011-02-08 11:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-08 11:07 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\Yahoo!
2011-02-08 11:06 . 2011-02-08 11:07 -------- d-----w- c:\program files\CCleaner
2011-01-31 20:03 . 2011-01-31 20:03 17920 ---ha-w- c:\documents and settings\Peťa\gqva.exe
2011-01-31 20:02 . 2011-01-31 20:02 126976 --sha-r- c:\documents and settings\Peťa\Data aplikací\juzjf.exe
2011-01-29 21:13 . 2011-01-31 13:32 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\skypePM
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----w- c:\program files\Common Files\Skype
2011-01-29 21:07 . 2011-01-29 21:07 -------- d-----r- c:\program files\Skype
2011-01-29 21:07 . 2011-01-31 20:38 -------- d-----w- c:\documents and settings\Peťa\Data aplikací\Skype
2011-01-29 21:06 . 2011-01-29 21:07 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Skype
2011-01-25 17:22 . 2011-01-25 17:22 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Electronic Arts
2011-01-25 17:18 . 2011-01-25 17:18 -------- d-----w- c:\program files\Microsoft WSE
2011-01-25 16:48 . 2011-01-25 16:48 -------- d-----w- c:\program files\Electronic Arts
2011-01-18 12:40 . 2004-08-18 08:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2011-01-16 20:27 . 2011-01-16 20:28 -------- d-----w- c:\documents and settings\All Users\Data aplikací\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-01 13:09 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP53ad.tmp
2011-02-01 13:05 . 2010-08-10 09:57 98304 ----a-w- c:\windows\DUMP516b.tmp
2011-02-01 11:07 . 2010-08-10 08:37 739328 ----a-w- c:\windows\system32\drivers\aec.sys
2010-12-26 21:34 . 2007-08-02 12:00 29392 ----a-w- c:\windows\system32\drivers\secdrv.sys
2010-11-20 18:27 . 2010-11-20 18:27 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
.
------- Sigcheck -------
[-] 2011-02-01 11:07 . 569BF3687D4F26FB5E992FE4AD4A5164 . 739328 . . [6.0.6000.16386] . . c:\windows\system32\drivers\aec.sys
[7] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\aec.sys
[7] 2004-08-03 20:39 . 841F385C6CFAF66B58FBD898722BB4F0 . 142464 . . [5.1.2601.2078] . . c:\windows\system32\dllcache\aec.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"nwiz"="nwiz.exe" [2009-06-10 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-10 13758464]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-08-02 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^Peťa^Nabídka Start^Programy^Po spuštění^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk]
path=c:\documents and settings\Peťa\Nabídka Start\Programy\Po spuštění\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
backup=c:\windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\egui]
2009-02-06 12:23 2021400 ----a-w- c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-08-17 13:58 1667584 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-01-03 14:44 15028104 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-09-27 16:16 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\MyPlayCity Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Documents and Settings\\Peťa\\Plocha\\facebook-pic00005267.exe"= c:\\windows\\nvsvc32.exe
"c:\\Documents and Settings\\Peťa\\Plocha\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10.8.2010 13:35 691696]
S1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [6.2.2009 13:23 106208]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [6.2.2009 13:24 93336]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [6.2.2009 13:23 727720]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27.9.2010 17:13 136176]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [29.8.2010 11:18 246520]
S2 SmileyCentral_1vService;SmileyCentral Service;c:\progra~1\SMILEY~2\bar\1.bin\1vbarsvc.exe [12.11.2010 18:56 28766]
.
Obsah adresáře 'Naplánované úlohy'
2011-01-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-02-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-27 16:13]
2011-02-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]
2011-02-08 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-08-30 20:18]
.
.
------- Doplňkový sken -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4FDCB521-35A7-4342-A0C7-1194C9EBB954} = 88.103.252.2,194.228.2.1
Handler: centrumcztoolbar - {61A97628-7C82-4315-957A-C74C2CDD85DF} - c:\program files\CentrumczToolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - prefs.js: browser.search.selectedEngine - Centrum.cz Search
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Centrum.cz Toolbar em:version=1.202.012.001 em:displayname=Centrum.cz Toolbar em:iconURL=chrome://cetrumczp/skin/logo.ico em:creator=iGeared LLC em:description=Centrum.cz Toolbar! em:homepageURL=http://www.igeared.com >: Cetrumcz@igeared - c:\program files\CentrumczToolbar\Firefox\Cetrumcz@igeared
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files\SmileyCentral_1v\bar\1.bin
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
URLSearchHooks-{3a750e59-9048-456b-a7f9-4d22dcb583f3} - (no file)
URLSearchHooks-{EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
MSConfigStartUp-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-09 12:23
Windows 5.1.2600 Service Pack 2 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
Celkový čas: 2011-02-09 12:28:38 - počítač byl restartován
ComboFix-quarantined-files.txt 2011-02-09 11:28
ComboFix2.txt 2011-02-09 08:31
Před spuštěním: 1 908 690 944
Po spuštění: 1 831 116 800
- - End Of File - - 70ED0EFC1CB9F3807E63143C4E1A116F
Re: prosím o kontrolu logu při najetí se restartuje......
pořád to jde jen do nouzového režimu po přihlášení se to restartuje.....to je divné.......A není to proto že je tam nelegální systém......to není muj počítač......
Re: prosím o kontrolu logu při najetí se restartuje......
Ještě to není v pořádku
Stahněte OTL http://oldtimer.geekstogo.com/OTL.exe
-uložte ho na plochu a spustte soubor OTL.exe.
-do bílého okna dole skopírujte tento skript:
- zaškrtněte okénko Pro všechny uživatele.
-označte okénka Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví logy OTL.Txt a Extras.txt, vložte je zde
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.

-uložte ho na plochu a spustte soubor OTL.exe.
-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
netsvcs
drivers32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
c:\windows\*.* /U
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
ndis.sys
winlogon.exe
explorer.exe
userinit.exe
lsass.exe
svchost.exe
smss.exe
hal.dll
ws2_32.dll
tcpip.sys
cryptsvc.dll
Changer.sys
JakNDis.sys
isapnp.sys
cdrom.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
CREATERESTOREPOINT
-označte okénka Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
- Klikněte na tlačítko Prohledat
-po dokončení skenu se objeví logy OTL.Txt a Extras.txt, vložte je zde


-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu při najetí se restartuje......
OTL logfile created on: 9.2.2011 20:06:42 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Peťa\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
503,00 Mb Total Physical Memory | 366,00 Mb Available Physical Memory | 73,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 1,73 Gb Free Space | 4,64% Space Free | Partition Type: NTFS
Drive E: | 1,87 Gb Total Space | 1,83 Gb Free Space | 97,66% Space Free | Partition Type: FAT32
Computer Name: PETR | User Name: Peťa | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.02.09 20:03:02 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
PRC - [2007.09.14 06:02:10 | 001,080,264 | ---- | M] (C. Ghisler & Co.) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\savedump.exe
========== Modules (SafeList) ==========
MOD - [2011.02.09 20:03:02 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
MOD - [2007.08.02 13:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2010.11.12 18:56:27 | 000,028,766 | ---- | M] (SmileyCentral) [Auto | Stopped] -- C:\Program Files\SmileyCentral_1v\bar\1.bin\1vbarsvc.exe -- (SmileyCentral_1vService)
SRV - [2010.03.28 15:47:30 | 000,246,520 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.02.06 13:27:06 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009.02.06 13:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
========== Driver Services (SafeList) ==========
DRV - [2011.02.01 12:07:16 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aec.sys -- (aec)
DRV - [2010.08.10 13:35:40 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.08.10 09:37:40 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2009.06.10 17:33:00 | 008,087,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009.02.06 13:24:24 | 000,093,336 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009.02.06 13:23:18 | 000,106,208 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.02.06 13:19:52 | 000,113,448 | ---- | M] (ESET) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008.02.14 10:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.08.02 13:00:00 | 000,088,448 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2007.08.02 13:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2007.08.02 13:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2006.11.22 07:01:00 | 000,250,496 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005.01.07 16:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.05.02 09:47:08 | 000,023,040 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\GVCplDrv.sys -- (GVCplDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..browser.search.selectedEngine: "Centrum.cz Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: Cetrumcz@igeared:1.202.012.001
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.4
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: {6a210611-2f33-4926-bf27-3fd9af8266eb}:1.300.306
FF - prefs.js..extensions.enabledItems: 1vffxtbr@SmileyCentral_1v.com:1.1
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.1.0.2
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Centrum.cz Search"
FF - prefs.js..browser.startup.homepage: "http://home.mywebsearch.com/index.jhtml ... C277730C7F"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.freecause.com/?m=search&t ... 6561197&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\Cetrumcz@igeared: C:\Program Files\CentrumczToolbar\Firefox\Cetrumcz@igeared [2010.08.19 19:12:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.09.27 17:17:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\1vffxtbr@SmileyCentral_1v.com: C:\Program Files\SmileyCentral_1v\bar\1.bin [2010.11.12 18:56:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.01.24 19:51:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.19 01:23:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010.08.21 22:42:58 | 000,000,000 | ---D | M]
[2010.08.19 19:12:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Extensions
[2011.02.08 12:08:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions
[2010.10.25 19:11:19 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2011.02.08 12:07:05 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.10.27 09:45:36 | 000,000,000 | ---D | M] (MyPlayCity Toolbar) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
[2010.08.29 11:18:56 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.01.16 21:27:45 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011.01.31 15:00:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-1.xml
[2010.10.21 14:21:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-2.xml
[2010.10.28 14:40:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-3.xml
[2010.11.13 15:32:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-4.xml
[2011.01.22 01:47:25 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-5.xml
[2010.09.13 17:43:40 | 000,001,056 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin.xml
[2010.10.27 09:59:42 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\search-the-web.xml
[2010.11.13 11:37:35 | 000,010,057 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\SmileyCentral_1v.xml
[2011.01.16 21:27:29 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\sweetim.xml
[2011.02.08 12:08:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.01.29 22:07:49 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\DATA APLIKACĂ\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\PEĹĄA\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\UEKFD37J.DEFAULT\EXTENSIONS\{6A210611-2F33-4926-BF27-3FD9AF8266EB}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\PEĹĄA\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\UEKFD37J.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\PEĹĄA\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\UEKFD37J.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010.08.19 19:12:04 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="Cetrumcz@igeared" em:name="Centrum.cz Toolbar" em:version="1.202.012.001" em:displayname="Centrum.cz Toolbar" em:iconURL="chrome://cetrumczp/skin/logo.ico" em:creator="iGeared LLC" em:description="Centrum.cz Toolbar!" em:homepageURL="http://www.igeared.com" >) -- C:\PROGRAM FILES\CENTRUMCZTOOLBAR\FIREFOX\CETRUMCZ@IGEARED
[2010.11.12 18:56:32 | 000,000,000 | ---D | M] (SmileyCentral) -- C:\PROGRAM FILES\SMILEYCENTRAL_1V\BAR\1.BIN
[2010.02.11 23:11:32 | 000,001,425 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\Cetrumcz_igeared.xml
[2010.08.25 07:02:23 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.08.25 07:02:23 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.08.25 07:02:23 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.08.25 07:02:23 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.08.25 07:02:23 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2011.02.09 12:23:01 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CentrumczToolbar BHO) - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\Toolbar\WebBrowser: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O18 - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Peťa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Peťa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.08.10 09:14:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ==========
[2011.02.09 20:05:10 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
[2011.02.09 12:34:19 | 000,739,328 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\vjttyjapf.sys
[2011.02.09 12:32:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011.02.09 09:34:15 | 000,036,864 | ---- | C] (MoonValleySoft.com) -- C:\WINDOWS\System32\MD5.ocx
[2011.02.09 09:34:15 | 000,000,000 | ---D | C] -- C:\Program Files\XP_Key_Changer
[2011.02.09 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\XP_Key_Changer
[2011.02.09 08:35:22 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.02.09 08:35:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.02.09 08:35:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.02.09 08:35:22 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.02.09 08:35:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.02.09 08:31:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011.02.09 08:31:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.02.08 12:11:23 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.02.08 12:11:21 | 000,000,000 | ---D | C] -- C:\rsit
[2011.02.08 12:10:25 | 000,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2011.02.08 12:07:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Data aplikací\Malwarebytes
[2011.02.08 12:07:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.02.08 12:07:23 | 000,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.02.08 12:07:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.02.08 12:07:20 | 000,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.02.08 12:07:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.02.08 12:06:59 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2011.02.08 12:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Nabídka Start\Programy\CCleaner
[2011.02.08 12:06:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.01.30 17:25:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\Nová složka (4)
[2011.01.29 22:13:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Data aplikací\skypePM
[2011.01.29 22:07:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011.01.29 22:07:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
[2011.01.29 22:07:09 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011.01.29 22:07:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Data aplikací\Skype
[2011.01.29 22:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Skype
[2011.01.29 22:05:50 | 021,164,424 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\Peťa\Plocha\SkypeSetupFull.exe
[2011.01.25 18:22:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2011.01.25 18:19:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Dokumenty\Electronic Arts
[2011.01.25 18:18:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
[2011.01.25 18:14:13 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2011.01.25 18:13:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2011.01.25 18:11:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Electronic Arts
[2011.01.25 17:48:26 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2011.01.20 16:25:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\Nová složka (3)
[2011.01.18 13:40:30 | 000,442,368 | R--- | C] (On2.com) -- C:\WINDOWS\System32\vp6vfw.dll
[2011.01.16 21:27:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2011.01.16 21:25:36 | 000,355,128 | ---- | C] (SweetIM Technologies, Ltd.) -- C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe
[2011.01.16 12:28:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\new2
[2011.01.16 00:11:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\3gp
[2011.01.15 10:21:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\Nová složka (2)
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.02.09 20:04:57 | 000,001,878 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2011.02.09 20:03:02 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
[2011.02.09 20:02:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.02.09 12:34:19 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\vjttyjapf.sys
[2011.02.09 12:23:01 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011.02.09 12:11:35 | 000,001,192 | ---- | M] () -- C:\CF-Submit.htm
[2011.02.09 11:47:20 | 000,036,864 | ---- | M] () -- C:\Documents and Settings\Peťa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.02.09 08:33:34 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011.02.09 08:29:50 | 000,117,448 | ---- | M] () -- C:\Documents and Settings\Peťa\Dokumenty\cc_20110209_082944.reg
[2011.02.09 08:25:02 | 004,265,718 | R--- | M] () -- C:\Documents and Settings\Peťa\Plocha\ComboFix.exe
[2011.02.09 08:24:05 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.02.08 12:18:19 | 000,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini
[2011.02.08 12:10:25 | 000,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll
[2011.02.08 12:10:25 | 000,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2011.02.08 12:10:25 | 000,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd
[2011.02.08 12:07:27 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.08 12:06:52 | 000,001,548 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\CCleaner.lnk
[2011.02.08 11:31:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011.02.08 09:46:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.02.08 09:31:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.02.03 15:13:22 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
[2011.02.01 19:24:00 | 000,000,932 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.02.01 12:07:16 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\aec.sys
[2011.02.01 12:05:16 | 000,235,289 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2011.02.01 12:05:14 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
[2011.01.31 21:03:26 | 000,045,568 | -H-- | M] () -- C:\Documents and Settings\Peťa\secupdat.dat
[2011.01.31 21:03:26 | 000,017,920 | -H-- | M] () -- C:\Documents and Settings\Peťa\gqva.exe
[2011.01.31 21:02:08 | 000,126,976 | RHS- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
[2011.01.31 20:22:55 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2011.01.30 17:22:19 | 000,095,744 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\TP FKJ 2011.xls
[2011.01.30 14:44:22 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\iTunes.lnk
[2011.01.30 14:16:53 | 000,035,552 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\167552_147101802014326_100001435212159_306284_6924789_n.jpg
[2011.01.30 11:09:27 | 005,208,406 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\e156ba77b665f21fcb824cc6f14633de.mp3
[2011.01.30 11:01:27 | 005,979,153 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\efefdd583b929bfbc798ebb49feebd8b.mp3
[2011.01.30 10:52:35 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.01.29 22:13:54 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011.01.29 22:06:17 | 021,164,424 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\Peťa\Plocha\SkypeSetupFull.exe
[2011.01.28 20:07:01 | 000,000,102 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\httpwww.facebook.comphoto.phpfbid=124947984241521&set=t.100001802765502.URL
[2011.01.25 18:17:47 | 000,395,200 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.01.25 18:17:47 | 000,392,918 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.01.25 18:17:47 | 000,069,926 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.01.25 18:17:47 | 000,059,440 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.01.25 18:11:42 | 000,001,723 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 3.lnk
[2011.01.23 21:31:00 | 000,019,086 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Jajky_e1_e1_e1.jpg
[2011.01.22 12:29:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011.01.21 21:31:28 | 000,000,452 | ---- | M] () -- C:\Documents and Settings\Peťa\Dokumenty\spider.sav
[2011.01.21 13:47:47 | 000,001,014 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Continue SweetIM Installation.lnk
[2011.01.17 14:42:50 | 010,351,380 | ---- | M] () -- C:\Documents and Settings\Peťa\__rzi_00.781
[2011.01.16 21:25:47 | 000,355,128 | ---- | M] (SweetIM Technologies, Ltd.) -- C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe
[2011.01.16 17:47:14 | 009,557,922 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Iker Casillas Vs Hugo Lloris.mp3
[2011.01.16 12:40:13 | 005,648,415 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Stay.mp3
[2011.01.15 20:38:10 | 000,003,689 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\is.jpeg
[2011.01.13 18:27:31 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.02.09 12:11:35 | 000,001,192 | ---- | C] () -- C:\CF-Submit.htm
[2011.02.09 08:35:22 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.02.09 08:35:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.02.09 08:35:22 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.02.09 08:35:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.02.09 08:35:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.02.09 08:29:47 | 000,117,448 | ---- | C] () -- C:\Documents and Settings\Peťa\Dokumenty\cc_20110209_082944.reg
[2011.02.09 08:28:55 | 004,265,718 | R--- | C] () -- C:\Documents and Settings\Peťa\Plocha\ComboFix.exe
[2011.02.08 12:18:07 | 000,811,008 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\gmer.exe
[2011.02.08 12:10:29 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2011.02.08 12:10:25 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2011.02.08 12:10:25 | 000,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd
[2011.02.08 12:10:24 | 000,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2011.02.08 12:07:27 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.08 12:06:52 | 000,001,548 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\CCleaner.lnk
[2011.02.08 09:46:23 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.01.31 21:03:26 | 000,045,568 | -H-- | C] () -- C:\Documents and Settings\Peťa\secupdat.dat
[2011.01.31 21:03:26 | 000,017,920 | -H-- | C] () -- C:\Documents and Settings\Peťa\gqva.exe
[2011.01.31 21:03:25 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt
[2011.01.31 21:02:14 | 000,126,976 | RHS- | C] () -- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
[2011.01.31 14:39:07 | 005,648,415 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Stay.mp3
[2011.01.30 17:22:19 | 000,095,744 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\TP FKJ 2011.xls
[2011.01.30 14:16:52 | 000,035,552 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\167552_147101802014326_100001435212159_306284_6924789_n.jpg
[2011.01.30 11:08:57 | 005,208,406 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\e156ba77b665f21fcb824cc6f14633de.mp3
[2011.01.30 11:01:02 | 005,979,153 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\efefdd583b929bfbc798ebb49feebd8b.mp3
[2011.01.30 10:52:35 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2011.01.30 10:52:34 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.01.29 22:13:54 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011.01.29 22:07:19 | 000,002,283 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2011.01.28 20:07:01 | 000,000,102 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\httpwww.facebook.comphoto.phpfbid=124947984241521&set=t.100001802765502.URL
[2011.01.27 20:22:32 | 000,019,086 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Jajky_e1_e1_e1.jpg
[2011.01.25 18:11:42 | 000,001,723 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 3.lnk
[2011.01.22 19:14:01 | 070,514,470 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\MVI_4388.avi
[2011.01.21 13:47:47 | 000,001,014 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Continue SweetIM Installation.lnk
[2011.01.17 14:42:49 | 010,351,380 | ---- | C] () -- C:\Documents and Settings\Peťa\__rzi_00.781
[2011.01.16 17:46:25 | 009,557,922 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Iker Casillas Vs Hugo Lloris.mp3
[2011.01.15 20:38:10 | 000,003,689 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\is.jpeg
[2010.12.05 13:06:45 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2010.09.27 20:24:10 | 000,000,274 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010.08.29 12:19:48 | 000,000,325 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2010.08.27 07:34:58 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.08.27 07:34:57 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.08.15 14:37:44 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2010.08.15 14:37:44 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2010.08.15 13:31:31 | 000,036,864 | ---- | C] () -- C:\Documents and Settings\Peťa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.15 12:57:24 | 000,001,878 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.08.10 11:06:29 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010.08.10 09:55:53 | 000,023,040 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2009.06.10 07:29:34 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009.06.10 07:29:34 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009.06.10 07:29:34 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009.06.10 07:29:32 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.08.02 13:00:00 | 000,029,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
========== LOP Check ==========
[2010.08.21 17:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\CentrumczToolbar
[2010.08.10 13:35:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.10.31 18:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DivoGames
[2011.01.25 18:22:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2010.08.21 22:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.08.29 11:18:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2011.01.16 21:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.10.30 09:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011.01.18 13:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DAEMON Tools Lite
[2010.09.26 12:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepBurner
[2010.10.27 09:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepVoyage
[2010.11.30 18:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009
[2011.01.30 20:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\ICQ
[2011.01.17 14:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\InImages
[2010.09.27 17:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\MMToolz
[2010.08.21 22:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Opera
[2011.02.08 11:31:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
< c:\windows\*.* /U >
[7 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.08.20 05:48:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Adobe
[2010.10.30 10:05:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Apple Computer
[2011.01.18 13:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DAEMON Tools Lite
[2010.09.26 12:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepBurner
[2010.10.27 09:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepVoyage
[2010.11.30 18:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009
[2010.08.15 13:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\GRETECH
[2010.10.06 18:22:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Help
[2011.01.30 20:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\ICQ
[2010.08.10 09:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Identities
[2011.01.17 14:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\InImages
[2010.08.19 19:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Macromedia
[2011.02.08 12:07:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Malwarebytes
[2011.02.09 08:45:05 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Peťa\Data aplikací\Microsoft
[2010.09.27 17:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\MMToolz
[2010.08.19 19:12:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla
[2010.08.21 22:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Opera
[2010.12.26 13:50:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Real
[2011.01.31 21:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Skype
[2011.01.31 14:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\skypePM
< %APPDATA%\*.exe /s >
[2011.01.31 21:02:08 | 000,126,976 | RHS- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
[2010.08.03 19:51:06 | 000,143,496 | ---- | M] (FreeCause Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\ToolbarUpdate.exe
[2010.10.08 23:17:30 | 000,102,296 | ---- | M] (FreeCause Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\TroubleShooter.exe
[2010.11.30 18:53:01 | 000,061,266 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\Uninst.exe
[3 C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\*.tmp files -> C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\*.tmp -> ]
[2007.03.22 11:46:40 | 000,126,976 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\GRETECH\GomPlayer\GrLauncher.exe
[2011.01.25 18:18:20 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2010.12.11 18:01:12 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.13\setup.exe
[2011.01.28 18:25:44 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\setup.exe
[2010.05.13 12:09:52 | 000,220,272 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
[2010.10.22 18:10:16 | 000,190,632 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\gtb_helper\LaunchHelper.exe
[2010.03.25 11:08:26 | 013,407,072 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\chr\ChromeInstaller.exe
[2010.10.22 18:10:16 | 000,190,632 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\chr_helper\LaunchHelper.exe
[2010.12.23 10:35:32 | 025,806,848 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\rp\RealPlayer.exe
< MD5 for: AGP440.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys
< MD5 for: ATAPI.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2007.08.02 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2007.08.02 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2007.08.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2007.08.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2007.08.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2007.08.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2007.08.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2007.08.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2007.08.02 13:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.13 19:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys
< MD5 for: ISAPNP.SYS >
[2001.10.24 10:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2001.10.24 10:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2007.08.02 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys
< MD5 for: LSASS.EXE >
[2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2007.08.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2007.08.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2007.08.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009.02.06 19:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 19:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2007.08.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2007.08.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2007.08.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll
< MD5 for: SCECLI.DLL >
[2007.08.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2007.08.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2007.08.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll
< MD5 for: SMSS.EXE >
[2007.08.02 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2007.08.02 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2007.08.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2007.08.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2007.08.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2007.08.02 13:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2007.08.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2007.08.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2007.08.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2007.08.02 13:00:00 | 000,506,880 | ---- | M] (Microsoft Corporation) MD5=051A52001D625F316CE81A539BD25192 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2007.08.02 13:00:00 | 000,506,880 | ---- | M] (Microsoft Corporation) MD5=051A52001D625F316CE81A539BD25192 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2007.08.02 13:00:00 | 000,506,880 | ---- | M] (Microsoft Corporation) MD5=051A52001D625F316CE81A539BD25192 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe
< MD5 for: WS2_32.DLL >
[2007.08.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2007.08.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2007.08.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.08.10 11:02:42 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.08.10 11:02:42 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.08.10 11:02:42 | 000,462,848 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
No captured output from command...
< %systemroot%\system32\drivers\*.sys /3 >
[2011.02.08 12:10:25 | 000,085,969 | ---- | M] (GMER) -- C:\WINDOWS\system32\drivers\gmer.sys
[2011.02.09 12:34:19 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\system32\drivers\vjttyjapf.sys
< %systemroot%\system32\*.* /3 >
[2011.02.08 09:46:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\system32\d3d9caps.dat
[2011.02.08 09:31:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Peťa\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
503,00 Mb Total Physical Memory | 366,00 Mb Available Physical Memory | 73,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 94,00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,26 Gb Total Space | 1,73 Gb Free Space | 4,64% Space Free | Partition Type: NTFS
Drive E: | 1,87 Gb Total Space | 1,83 Gb Free Space | 97,66% Space Free | Partition Type: FAT32
Computer Name: PETR | User Name: Peťa | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.02.09 20:03:02 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
PRC - [2007.09.14 06:02:10 | 001,080,264 | ---- | M] (C. Ghisler & Co.) -- C:\totalcmd\TOTALCMD.EXE
PRC - [2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\savedump.exe
========== Modules (SafeList) ==========
MOD - [2011.02.09 20:03:02 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
MOD - [2007.08.02 13:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2010.11.12 18:56:27 | 000,028,766 | ---- | M] (SmileyCentral) [Auto | Stopped] -- C:\Program Files\SmileyCentral_1v\bar\1.bin\1vbarsvc.exe -- (SmileyCentral_1vService)
SRV - [2010.03.28 15:47:30 | 000,246,520 | ---- | M] () [Auto | Stopped] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2009.02.06 13:27:06 | 000,020,680 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV - [2009.02.06 13:23:36 | 000,727,720 | ---- | M] (ESET) [Auto | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe -- (ekrn)
========== Driver Services (SafeList) ==========
DRV - [2011.02.01 12:07:16 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\aec.sys -- (aec)
DRV - [2010.08.10 13:35:40 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010.08.10 09:37:40 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2009.06.10 17:33:00 | 008,087,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009.02.06 13:24:24 | 000,093,336 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\epfwtdir.sys -- (epfwtdir)
DRV - [2009.02.06 13:23:18 | 000,106,208 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2009.02.06 13:19:52 | 000,113,448 | ---- | M] (ESET) [File_System | Auto | Stopped] -- C:\WINDOWS\system32\drivers\eamon.sys -- (eamon)
DRV - [2008.02.14 10:04:06 | 004,676,096 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007.08.02 13:00:00 | 000,088,448 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx)
DRV - [2007.08.02 13:00:00 | 000,063,232 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb)
DRV - [2007.08.02 13:00:00 | 000,055,936 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Stopped] -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx)
DRV - [2006.11.22 07:01:00 | 000,250,496 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2005.01.07 16:07:18 | 000,138,752 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004.05.02 09:47:08 | 000,023,040 | R--- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\GVCplDrv.sys -- (GVCplDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-606747145-329068152-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..browser.search.selectedEngine: "Centrum.cz Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: Cetrumcz@igeared:1.202.012.001
FF - prefs.js..extensions.enabledItems: {800b5000-a755-47e1-992b-48a1c1357f07}:2.0.0.4
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.5
FF - prefs.js..extensions.enabledItems: {6a210611-2f33-4926-bf27-3fd9af8266eb}:1.300.306
FF - prefs.js..extensions.enabledItems: 1vffxtbr@SmileyCentral_1v.com:1.1
FF - prefs.js..extensions.enabledItems: {EEE6C361-6118-11DC-9C72-001320C79847}:1.1.0.2
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaultenginename: "Centrum.cz Search"
FF - prefs.js..sweetim.toolbar.previous.browser.search.defaulturl: ""
FF - prefs.js..sweetim.toolbar.previous.browser.search.selectedEngine: "Centrum.cz Search"
FF - prefs.js..browser.startup.homepage: "http://home.mywebsearch.com/index.jhtml ... C277730C7F"
FF - prefs.js..sweetim.toolbar.previous.keyword.URL: "http://search.freecause.com/?m=search&t ... 6561197&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\Cetrumcz@igeared: C:\Program Files\CentrumczToolbar\Firefox\Cetrumcz@igeared [2010.08.19 19:12:04 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010.09.27 17:17:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\1vffxtbr@SmileyCentral_1v.com: C:\Program Files\SmileyCentral_1v\bar\1.bin [2010.11.12 18:56:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.01.24 19:51:57 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.12.19 01:23:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010.08.21 22:42:58 | 000,000,000 | ---D | M]
[2010.08.19 19:12:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Extensions
[2011.02.08 12:08:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions
[2010.10.25 19:11:19 | 000,000,000 | ---D | M] (Free Lunch Design Toolbar) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{57cc715d-37ca-44e4-9ec2-8c2cbddb25ec}
[2011.02.08 12:07:05 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.10.27 09:45:36 | 000,000,000 | ---D | M] (MyPlayCity Toolbar) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
[2010.08.29 11:18:56 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2011.01.16 21:27:45 | 000,000,000 | ---D | M] (SweetIM Toolbar for Firefox) -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
[2011.01.31 15:00:36 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-1.xml
[2010.10.21 14:21:46 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-2.xml
[2010.10.28 14:40:14 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-3.xml
[2010.11.13 15:32:40 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-4.xml
[2011.01.22 01:47:25 | 000,000,950 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin-5.xml
[2010.09.13 17:43:40 | 000,001,056 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\icqplugin.xml
[2010.10.27 09:59:42 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\search-the-web.xml
[2010.11.13 11:37:35 | 000,010,057 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\SmileyCentral_1v.xml
[2011.01.16 21:27:29 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\searchplugins\sweetim.xml
[2011.02.08 12:08:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011.01.29 22:07:49 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\DATA APLIKACĂ\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\PEĹĄA\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\UEKFD37J.DEFAULT\EXTENSIONS\{6A210611-2F33-4926-BF27-3FD9AF8266EB}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\PEĹĄA\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\UEKFD37J.DEFAULT\EXTENSIONS\{800B5000-A755-47E1-992B-48A1C1357F07}
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\PEĹĄA\DATA APLIKACĂ\MOZILLA\FIREFOX\PROFILES\UEKFD37J.DEFAULT\EXTENSIONS\{EEE6C361-6118-11DC-9C72-001320C79847}
[2010.08.19 19:12:04 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="Cetrumcz@igeared" em:name="Centrum.cz Toolbar" em:version="1.202.012.001" em:displayname="Centrum.cz Toolbar" em:iconURL="chrome://cetrumczp/skin/logo.ico" em:creator="iGeared LLC" em:description="Centrum.cz Toolbar!" em:homepageURL="http://www.igeared.com" >) -- C:\PROGRAM FILES\CENTRUMCZTOOLBAR\FIREFOX\CETRUMCZ@IGEARED
[2010.11.12 18:56:32 | 000,000,000 | ---D | M] (SmileyCentral) -- C:\PROGRAM FILES\SMILEYCENTRAL_1V\BAR\1.BIN
[2010.02.11 23:11:32 | 000,001,425 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\Cetrumcz_igeared.xml
[2010.08.25 07:02:23 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2010.08.25 07:02:23 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2010.08.25 07:02:23 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2010.08.25 07:02:23 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2010.08.25 07:02:23 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml
O1 HOSTS File: ([2011.02.09 12:23:01 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (CentrumczToolbar BHO) - {33CD02D0-8C93-4926-A2FE-2CE72CE7DF1A} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\..\Toolbar\WebBrowser: (Centrum.cz Toolbar) - {D5D47440-0750-463D-BAEF-A47D02414806} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-606747145-329068152-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O18 - Protocol\Handler\centrumcztoolbar {61A97628-7C82-4315-957A-C74C2CDD85DF} - C:\Program Files\CentrumczToolbar\IEToolbar.dll ()
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Peťa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Peťa\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.08.10 09:14:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Error starting restore point: The function was called in safe mode.
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ==========
[2011.02.09 20:05:10 | 000,602,624 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
[2011.02.09 12:34:19 | 000,739,328 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\vjttyjapf.sys
[2011.02.09 12:32:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011.02.09 09:34:15 | 000,036,864 | ---- | C] (MoonValleySoft.com) -- C:\WINDOWS\System32\MD5.ocx
[2011.02.09 09:34:15 | 000,000,000 | ---D | C] -- C:\Program Files\XP_Key_Changer
[2011.02.09 09:34:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\XP_Key_Changer
[2011.02.09 08:35:22 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011.02.09 08:35:22 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011.02.09 08:35:22 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011.02.09 08:35:22 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011.02.09 08:35:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011.02.09 08:31:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2011.02.09 08:31:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011.02.08 12:11:23 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2011.02.08 12:11:21 | 000,000,000 | ---D | C] -- C:\rsit
[2011.02.08 12:10:25 | 000,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2011.02.08 12:07:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Data aplikací\Malwarebytes
[2011.02.08 12:07:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2011.02.08 12:07:23 | 000,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011.02.08 12:07:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2011.02.08 12:07:20 | 000,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011.02.08 12:07:20 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011.02.08 12:06:59 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2011.02.08 12:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Nabídka Start\Programy\CCleaner
[2011.02.08 12:06:51 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011.01.30 17:25:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\Nová složka (4)
[2011.01.29 22:13:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Data aplikací\skypePM
[2011.01.29 22:07:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011.01.29 22:07:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Skype
[2011.01.29 22:07:09 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011.01.29 22:07:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Data aplikací\Skype
[2011.01.29 22:06:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Skype
[2011.01.29 22:05:50 | 021,164,424 | ---- | C] (Skype Technologies S.A.) -- C:\Documents and Settings\Peťa\Plocha\SkypeSetupFull.exe
[2011.01.25 18:22:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2011.01.25 18:19:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Dokumenty\Electronic Arts
[2011.01.25 18:18:19 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft WSE
[2011.01.25 18:14:13 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2011.01.25 18:13:03 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2011.01.25 18:11:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Electronic Arts
[2011.01.25 17:48:26 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2011.01.20 16:25:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\Nová složka (3)
[2011.01.18 13:40:30 | 000,442,368 | R--- | C] (On2.com) -- C:\WINDOWS\System32\vp6vfw.dll
[2011.01.16 21:27:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2011.01.16 21:25:36 | 000,355,128 | ---- | C] (SweetIM Technologies, Ltd.) -- C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe
[2011.01.16 12:28:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\new2
[2011.01.16 00:11:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\3gp
[2011.01.15 10:21:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Peťa\Plocha\Nová složka (2)
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.02.09 20:04:57 | 000,001,878 | ---- | M] () -- C:\WINDOWS\wincmd.ini
[2011.02.09 20:03:02 | 000,602,624 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Peťa\Plocha\OTL.exe
[2011.02.09 20:02:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.02.09 12:34:19 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\vjttyjapf.sys
[2011.02.09 12:23:01 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2011.02.09 12:11:35 | 000,001,192 | ---- | M] () -- C:\CF-Submit.htm
[2011.02.09 11:47:20 | 000,036,864 | ---- | M] () -- C:\Documents and Settings\Peťa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011.02.09 08:33:34 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011.02.09 08:29:50 | 000,117,448 | ---- | M] () -- C:\Documents and Settings\Peťa\Dokumenty\cc_20110209_082944.reg
[2011.02.09 08:25:02 | 004,265,718 | R--- | M] () -- C:\Documents and Settings\Peťa\Plocha\ComboFix.exe
[2011.02.09 08:24:05 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.02.08 12:18:19 | 000,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini
[2011.02.08 12:10:25 | 000,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll
[2011.02.08 12:10:25 | 000,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2011.02.08 12:10:25 | 000,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd
[2011.02.08 12:07:27 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.08 12:06:52 | 000,001,548 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\CCleaner.lnk
[2011.02.08 11:31:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011.02.08 09:46:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.02.08 09:31:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.02.03 15:13:22 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-606747145-329068152-1801674531-1003.job
[2011.02.01 19:24:00 | 000,000,932 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.02.01 12:07:16 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\aec.sys
[2011.02.01 12:05:16 | 000,235,289 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2011.02.01 12:05:14 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-606747145-329068152-1801674531-1003.job
[2011.01.31 21:03:26 | 000,045,568 | -H-- | M] () -- C:\Documents and Settings\Peťa\secupdat.dat
[2011.01.31 21:03:26 | 000,017,920 | -H-- | M] () -- C:\Documents and Settings\Peťa\gqva.exe
[2011.01.31 21:02:08 | 000,126,976 | RHS- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
[2011.01.31 20:22:55 | 000,002,283 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2011.01.30 17:22:19 | 000,095,744 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\TP FKJ 2011.xls
[2011.01.30 14:44:22 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\iTunes.lnk
[2011.01.30 14:16:53 | 000,035,552 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\167552_147101802014326_100001435212159_306284_6924789_n.jpg
[2011.01.30 11:09:27 | 005,208,406 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\e156ba77b665f21fcb824cc6f14633de.mp3
[2011.01.30 11:01:27 | 005,979,153 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\efefdd583b929bfbc798ebb49feebd8b.mp3
[2011.01.30 10:52:35 | 000,001,492 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.01.29 22:13:54 | 000,000,056 | -H-- | M] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011.01.29 22:06:17 | 021,164,424 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\Peťa\Plocha\SkypeSetupFull.exe
[2011.01.28 20:07:01 | 000,000,102 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\httpwww.facebook.comphoto.phpfbid=124947984241521&set=t.100001802765502.URL
[2011.01.25 18:17:47 | 000,395,200 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011.01.25 18:17:47 | 000,392,918 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2011.01.25 18:17:47 | 000,069,926 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2011.01.25 18:17:47 | 000,059,440 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011.01.25 18:11:42 | 000,001,723 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 3.lnk
[2011.01.23 21:31:00 | 000,019,086 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Jajky_e1_e1_e1.jpg
[2011.01.22 12:29:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011.01.21 21:31:28 | 000,000,452 | ---- | M] () -- C:\Documents and Settings\Peťa\Dokumenty\spider.sav
[2011.01.21 13:47:47 | 000,001,014 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Continue SweetIM Installation.lnk
[2011.01.17 14:42:50 | 010,351,380 | ---- | M] () -- C:\Documents and Settings\Peťa\__rzi_00.781
[2011.01.16 21:25:47 | 000,355,128 | ---- | M] (SweetIM Technologies, Ltd.) -- C:\Documents and Settings\Peťa\Plocha\SweetImSetup.exe
[2011.01.16 17:47:14 | 009,557,922 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Iker Casillas Vs Hugo Lloris.mp3
[2011.01.16 12:40:13 | 005,648,415 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\Stay.mp3
[2011.01.15 20:38:10 | 000,003,689 | ---- | M] () -- C:\Documents and Settings\Peťa\Plocha\is.jpeg
[2011.01.13 18:27:31 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.02.09 12:11:35 | 000,001,192 | ---- | C] () -- C:\CF-Submit.htm
[2011.02.09 08:35:22 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011.02.09 08:35:22 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011.02.09 08:35:22 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011.02.09 08:35:22 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011.02.09 08:35:22 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011.02.09 08:29:47 | 000,117,448 | ---- | C] () -- C:\Documents and Settings\Peťa\Dokumenty\cc_20110209_082944.reg
[2011.02.09 08:28:55 | 004,265,718 | R--- | C] () -- C:\Documents and Settings\Peťa\Plocha\ComboFix.exe
[2011.02.08 12:18:07 | 000,811,008 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\gmer.exe
[2011.02.08 12:10:29 | 000,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2011.02.08 12:10:25 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2011.02.08 12:10:25 | 000,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd
[2011.02.08 12:10:24 | 000,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2011.02.08 12:07:27 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2011.02.08 12:06:52 | 000,001,548 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\CCleaner.lnk
[2011.02.08 09:46:23 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.01.31 21:03:26 | 000,045,568 | -H-- | C] () -- C:\Documents and Settings\Peťa\secupdat.dat
[2011.01.31 21:03:26 | 000,017,920 | -H-- | C] () -- C:\Documents and Settings\Peťa\gqva.exe
[2011.01.31 21:03:25 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt
[2011.01.31 21:02:14 | 000,126,976 | RHS- | C] () -- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
[2011.01.31 14:39:07 | 005,648,415 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Stay.mp3
[2011.01.30 17:22:19 | 000,095,744 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\TP FKJ 2011.xls
[2011.01.30 14:16:52 | 000,035,552 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\167552_147101802014326_100001435212159_306284_6924789_n.jpg
[2011.01.30 11:08:57 | 005,208,406 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\e156ba77b665f21fcb824cc6f14633de.mp3
[2011.01.30 11:01:02 | 005,979,153 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\efefdd583b929bfbc798ebb49feebd8b.mp3
[2011.01.30 10:52:35 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Nabídka Start\Programy\Opera.lnk
[2011.01.30 10:52:34 | 000,001,492 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Opera.lnk
[2011.01.29 22:13:54 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat
[2011.01.29 22:07:19 | 000,002,283 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Skype.lnk
[2011.01.28 20:07:01 | 000,000,102 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\httpwww.facebook.comphoto.phpfbid=124947984241521&set=t.100001802765502.URL
[2011.01.27 20:22:32 | 000,019,086 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Jajky_e1_e1_e1.jpg
[2011.01.25 18:11:42 | 000,001,723 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\The Sims™ 3.lnk
[2011.01.22 19:14:01 | 070,514,470 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\MVI_4388.avi
[2011.01.21 13:47:47 | 000,001,014 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Continue SweetIM Installation.lnk
[2011.01.17 14:42:49 | 010,351,380 | ---- | C] () -- C:\Documents and Settings\Peťa\__rzi_00.781
[2011.01.16 17:46:25 | 009,557,922 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\Iker Casillas Vs Hugo Lloris.mp3
[2011.01.15 20:38:10 | 000,003,689 | ---- | C] () -- C:\Documents and Settings\Peťa\Plocha\is.jpeg
[2010.12.05 13:06:45 | 000,000,032 | ---- | C] () -- C:\WINDOWS\CD-Start.INI
[2010.09.27 20:24:10 | 000,000,274 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2010.08.29 12:19:48 | 000,000,325 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2010.08.27 07:34:58 | 000,815,104 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010.08.27 07:34:57 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010.08.15 14:37:44 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2010.08.15 14:37:44 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2010.08.15 13:31:31 | 000,036,864 | ---- | C] () -- C:\Documents and Settings\Peťa\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.08.15 12:57:24 | 000,001,878 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2010.08.10 11:06:29 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010.08.10 09:55:53 | 000,023,040 | R--- | C] () -- C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2009.06.10 07:29:34 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009.06.10 07:29:34 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009.06.10 07:29:34 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2009.06.10 07:29:32 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.08.02 13:00:00 | 000,029,392 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
========== LOP Check ==========
[2010.08.21 17:14:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\CentrumczToolbar
[2010.08.10 13:35:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
[2010.10.31 18:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\DivoGames
[2011.01.25 18:22:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Electronic Arts
[2010.08.21 22:42:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ESET
[2010.08.29 11:18:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2011.01.16 21:28:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\SweetIM
[2010.10.30 09:43:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2011.01.18 13:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DAEMON Tools Lite
[2010.09.26 12:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepBurner
[2010.10.27 09:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepVoyage
[2010.11.30 18:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009
[2011.01.30 20:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\ICQ
[2011.01.17 14:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\InImages
[2010.09.27 17:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\MMToolz
[2010.08.21 22:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Opera
[2011.02.08 11:31:21 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job
========== Purity Check ==========
========== Custom Scans ==========
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
< c:\windows\*.* /U >
[7 c:\windows\*.tmp files -> c:\windows\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2010.08.20 05:48:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Adobe
[2010.10.30 10:05:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Apple Computer
[2011.01.18 13:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DAEMON Tools Lite
[2010.09.26 12:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepBurner
[2010.10.27 09:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\DeepVoyage
[2010.11.30 18:53:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009
[2010.08.15 13:36:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\GRETECH
[2010.10.06 18:22:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Help
[2011.01.30 20:13:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\ICQ
[2010.08.10 09:22:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Identities
[2011.01.17 14:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\InImages
[2010.08.19 19:07:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Macromedia
[2011.02.08 12:07:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Malwarebytes
[2011.02.09 08:45:05 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Peťa\Data aplikací\Microsoft
[2010.09.27 17:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\MMToolz
[2010.08.19 19:12:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Mozilla
[2010.08.21 22:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Opera
[2010.12.26 13:50:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Real
[2011.01.31 21:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\Skype
[2011.01.31 14:32:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Peťa\Data aplikací\skypePM
< %APPDATA%\*.exe /s >
[2011.01.31 21:02:08 | 000,126,976 | RHS- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
[2010.08.03 19:51:06 | 000,143,496 | ---- | M] (FreeCause Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\ToolbarUpdate.exe
[2010.10.08 23:17:30 | 000,102,296 | ---- | M] (FreeCause Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\TroubleShooter.exe
[2010.11.30 18:53:01 | 000,061,266 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\Uninst.exe
[3 C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\*.tmp files -> C:\Documents and Settings\Peťa\Data aplikací\FCTB000063009\Toolbar\*.tmp -> ]
[2007.03.22 11:46:40 | 000,126,976 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\GRETECH\GomPlayer\GrLauncher.exe
[2011.01.25 18:18:20 | 000,010,134 | R--- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
[2010.12.11 18:01:12 | 000,506,024 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.13\setup.exe
[2011.01.28 18:25:44 | 000,510,120 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\setup.exe
[2010.05.13 12:09:52 | 000,220,272 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
[2010.10.22 18:10:16 | 000,190,632 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\gtb_helper\LaunchHelper.exe
[2010.03.25 11:08:26 | 013,407,072 | ---- | M] () -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\chr\ChromeInstaller.exe
[2010.10.22 18:10:16 | 000,190,632 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\chr_helper\LaunchHelper.exe
[2010.12.23 10:35:32 | 025,806,848 | ---- | M] (RealNetworks, Inc.) -- C:\Documents and Settings\Peťa\Data aplikací\Real\Update\setup3.14\rp\RealPlayer.exe
< MD5 for: AGP440.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008.04.13 19:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\agp440.sys
< MD5 for: ATAPI.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008.04.13 19:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2007.08.02 13:00:00 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2004.08.03 21:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: CDROM.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2008.04.13 19:40:46 | 000,062,976 | ---- | M] (Microsoft Corporation) MD5=1F4260CC5B42272D71F79E570A27A4FE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cdrom.sys
[2007.08.02 13:00:00 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys
< MD5 for: CRYPTSVC.DLL >
[2007.08.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[2007.08.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2007.08.02 13:00:00 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll
[2008.04.14 04:21:38 | 000,062,464 | ---- | M] (Microsoft Corporation) MD5=F3AB0933CBD166D271992F411C27CCAF -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\cryptsvc.dll
< MD5 for: EVENTLOG.DLL >
[2008.04.14 04:21:41 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=2EE99F67C930931EB404DADCE57E976E -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\eventlog.dll
[2007.08.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2007.08.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2007.08.02 13:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: EXPLORER.EXE >
[2008.04.14 04:22:22 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=27AFD587C462E280EE046B8CCA3C2CD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\explorer.exe
[2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\ERDNT\cache\explorer.exe
[2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2007.08.02 13:00:00 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe
< MD5 for: HAL.DLL >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2008.04.13 19:31:32 | 000,105,344 | ---- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\hal.dll
[2007.08.02 13:00:00 | 000,134,400 | ---- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 -- C:\WINDOWS\system32\hal.dll
< MD5 for: CHANGER.SYS >
[2007.08.02 13:00:00 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys
[2008.04.13 19:40:58 | 000,008,192 | ---- | M] (Microsoft Corporation) MD5=2A5815CA6FFF24B688C01F828B96819C -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\changer.sys
< MD5 for: ISAPNP.SYS >
[2001.10.24 10:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\dllcache\isapnp.sys
[2001.10.24 10:44:12 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys
[2007.08.02 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\isapnp.sys
[2008.04.14 03:27:53 | 000,037,248 | ---- | M] (Microsoft Corporation) MD5=CC9F8A2D60AED1A51A3AC34C59B987AE -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\isapnp.sys
< MD5 for: LSASS.EXE >
[2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\ERDNT\cache\lsass.exe
[2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2007.08.02 13:00:00 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe
[2008.04.14 04:22:29 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=ED0A176354487CEED65B80A7148AB739 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\lsass.exe
< MD5 for: NDIS.SYS >
[2008.04.13 20:20:37 | 000,182,656 | ---- | M] (Microsoft Corporation) MD5=1DF7F42665C94B825322FAE71721130D -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ndis.sys
[2007.08.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\ERDNT\cache\ndis.sys
[2007.08.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2007.08.02 13:00:00 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys
< MD5 for: NETLOGON.DLL >
[2009.02.06 19:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009.02.06 19:47:20 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=1F43B8C0F4C767FBED89711C30E704D9 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2007.08.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2007.08.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2007.08.02 13:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll
[2008.04.14 04:21:50 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=C2ED0E3408F50BBC149D4F0936E67832 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\netlogon.dll
< MD5 for: SCECLI.DLL >
[2007.08.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2007.08.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2007.08.02 13:00:00 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll
[2008.04.14 04:21:54 | 000,185,856 | ---- | M] (Microsoft Corporation) MD5=830CE8951C71F361D7D2F38416CC8BC1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\scecli.dll
< MD5 for: SMSS.EXE >
[2007.08.02 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2007.08.02 13:00:00 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2008.04.14 04:22:47 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=9B08A8C6331C2DA9C30377BCB4262721 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\smss.exe
< MD5 for: SVCHOST.EXE >
[2008.04.14 04:22:48 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=BE4A520E29B6391F49E79CCC52044D93 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\svchost.exe
[2007.08.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\ERDNT\cache\svchost.exe
[2007.08.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2007.08.02 13:00:00 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe
< MD5 for: TCPIP.SYS >
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\ERDNT\cache\tcpip.sys
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2008.06.20 11:45:13 | 000,360,320 | ---- | M] (Microsoft Corporation) MD5=2A5554FC5B1E04E131230E3CE035C3F9 -- C:\WINDOWS\system32\drivers\tcpip.sys
[2008.06.20 11:44:42 | 000,360,960 | ---- | M] (Microsoft Corporation) MD5=744E57C99232201AE98C49168B918F48 -- C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[2008.04.13 20:20:16 | 000,361,344 | ---- | M] (Microsoft Corporation) MD5=93EA8D04EC73A85DB02EB8805988F733 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\tcpip.sys
[2008.06.20 12:51:12 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=9AEFA14BD6B182D61E3119FA5F436D3D -- C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[2007.08.02 13:00:00 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[2008.06.20 12:59:02 | 000,361,600 | ---- | M] (Microsoft Corporation) MD5=AD978A1B783B5719720CFF204B666C8E -- C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
< MD5 for: USERINIT.EXE >
[2008.04.14 04:22:50 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=7DC1830F22E7D275B438127B68030239 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\userinit.exe
[2007.08.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\ERDNT\cache\userinit.exe
[2007.08.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2007.08.02 13:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe
< MD5 for: WINLOGON.EXE >
[2007.08.02 13:00:00 | 000,506,880 | ---- | M] (Microsoft Corporation) MD5=051A52001D625F316CE81A539BD25192 -- C:\WINDOWS\ERDNT\cache\winlogon.exe
[2007.08.02 13:00:00 | 000,506,880 | ---- | M] (Microsoft Corporation) MD5=051A52001D625F316CE81A539BD25192 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2007.08.02 13:00:00 | 000,506,880 | ---- | M] (Microsoft Corporation) MD5=051A52001D625F316CE81A539BD25192 -- C:\WINDOWS\system32\winlogon.exe
[2008.04.14 04:22:53 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=CDDB1F8E1AEA356F3AD106F2CF9B7FEA -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\winlogon.exe
< MD5 for: WS2_32.DLL >
[2007.08.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\ERDNT\cache\ws2_32.dll
[2007.08.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2007.08.02 13:00:00 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll
[2008.04.14 04:22:06 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=951D473917C51F21496D914CF6E5DDD1 -- C:\WINDOWS\SoftwareDistribution\Download\44c8256673ca0542cb198384f8131b68\ws2_32.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2010.08.10 11:02:42 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.08.10 11:02:42 | 000,663,552 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.08.10 11:02:42 | 000,462,848 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.dll /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
No captured output from command...
< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
No captured output from command...
< %systemroot%\system32\drivers\*.sys /3 >
[2011.02.08 12:10:25 | 000,085,969 | ---- | M] (GMER) -- C:\WINDOWS\system32\drivers\gmer.sys
[2011.02.09 12:34:19 | 000,739,328 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\system32\drivers\vjttyjapf.sys
< %systemroot%\system32\*.* /3 >
[2011.02.08 09:46:31 | 000,000,664 | ---- | M] () -- C:\WINDOWS\system32\d3d9caps.dat
[2011.02.08 09:31:08 | 000,013,646 | ---- | M] () -- C:\WINDOWS\system32\wpa.dbl
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< End of report >
Re: prosím o kontrolu logu při najetí se restartuje......

-do bílého okna dole skopírujte tento skript:
Kód: Vybrat vše
:OTL
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe
C:\Documents and Settings\Peťa\gqva.exe
C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt
C:\Documents and Settings\Peťa\secupdat.dat
C:\CF-Submit.htm
C:\WINDOWS\System32\ezsidmv.dat
:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]
-klikněte na tlačítko opravit.
-Následně se pc restartuje.
- Log vložte zde

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu při najetí se restartuje......
All processes killed
========== OTL ==========
No active process named explorer.exe was found!
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\system32\SET2C22.tmp moved successfully.
C:\WINDOWS\system32\SET2C26.tmp moved successfully.
C:\WINDOWS\system32\SET2C2E.tmp moved successfully.
C:\WINDOWS\DUMP516b.tmp moved successfully.
C:\WINDOWS\DUMP53ad.tmp¨ moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\SET25.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\system32\ConduitEngine.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\temp\GUR1.tmp moved successfully.
C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe moved successfully.
C:\Documents and Settings\Peťa\gqva.exe moved successfully.
C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt moved successfully.
C:\Documents and Settings\Peťa\secupdat.dat moved successfully.
C:\CF-Submit.htm moved successfully.
C:\WINDOWS\System32\ezsidmv.dat moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Nikola
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Peťa
->Temp folder emptied: 393216 bytes
->Temporary Internet Files folder emptied: 207117 bytes
->FireFox cache emptied: 43885503 bytes
->Google Chrome cache emptied: 98745974 bytes
->Opera cache emptied: 36911468 bytes
->Flash cache emptied: 139169 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 172,00 mb
[EMPTYFLASH]
User: All Users
User: Default User
User: LocalService
User: NetworkService
User: Nikola
User: Peťa
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.20.6 log created on 02092011_224927
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
========== OTL ==========
No active process named explorer.exe was found!
========== FILES ==========
File\Folder C:\WINDOWS\system32\*.tmp.dll not found.
C:\WINDOWS\system32\SET2C22.tmp moved successfully.
C:\WINDOWS\system32\SET2C26.tmp moved successfully.
C:\WINDOWS\system32\SET2C2E.tmp moved successfully.
C:\WINDOWS\DUMP516b.tmp moved successfully.
C:\WINDOWS\DUMP53ad.tmp¨ moved successfully.
C:\WINDOWS\msdownld.tmp folder moved successfully.
C:\WINDOWS\SET25.tmp moved successfully.
C:\WINDOWS\SET3.tmp moved successfully.
C:\WINDOWS\SET4.tmp moved successfully.
C:\WINDOWS\SET8.tmp moved successfully.
C:\WINDOWS\system32\ConduitEngine.tmp moved successfully.
C:\WINDOWS\system32\CONFIG.TMP moved successfully.
C:\WINDOWS\temp\GUR1.tmp moved successfully.
C:\Documents and Settings\Peťa\Data aplikací\juzjf.exe moved successfully.
C:\Documents and Settings\Peťa\gqva.exe moved successfully.
C:\Documents and Settings\Peťa\Data aplikací\HhdFJl61DD.txt moved successfully.
C:\Documents and Settings\Peťa\secupdat.dat moved successfully.
C:\CF-Submit.htm moved successfully.
C:\WINDOWS\System32\ezsidmv.dat moved successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Nikola
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Peťa
->Temp folder emptied: 393216 bytes
->Temporary Internet Files folder emptied: 207117 bytes
->FireFox cache emptied: 43885503 bytes
->Google Chrome cache emptied: 98745974 bytes
->Opera cache emptied: 36911468 bytes
->Flash cache emptied: 139169 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 172,00 mb
[EMPTYFLASH]
User: All Users
User: Default User
User: LocalService
User: NetworkService
User: Nikola
User: Peťa
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.20.6 log created on 02092011_224927
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Re: prosím o kontrolu logu při najetí se restartuje......
Zbytek doděláme zítra, já už jdu spát.
Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken
NIC NEMAZAT
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.

-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: prosím o kontrolu logu při najetí se restartuje......
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 5727
Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13
10.2.2011 8:36:51
mbam-log-2011-02-10 (08-36-36).txt
Typ kontroly: Úplný test (C:\|)
Testované objekty: 192989
Uplynulý čas: 17 minut, 26 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 49
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\Peťa\Plocha\facebook-pic00005267.exe (Trojan.Yimfoca) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\localservice\data aplikací\microsoft\cudof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\localservice\data aplikací\microsoft\naturyttoof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\Peťa\data aplikací\microsoft\cudof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\Peťa\data aplikací\microsoft\naturyttoof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\nvsvc32.exe.vir (Trojan.Yimfoca) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP138\A0043034.exe (Trojan.Yimfoca) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP138\A0043035.exe (Trojan.Yimfoca) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0055942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0055944.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0056943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0057942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0058942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0059942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0060942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0061942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0062942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0063942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0064942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0065943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0066942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0067943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0068943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0070943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0071942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0071949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0075948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0076949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0077948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0078948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0079949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0080949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0081948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0082948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0083949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0084948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0085948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0085951.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0085955.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0086955.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0087954.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0088954.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP151\A0089954.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0093967.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095015.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095016.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095017.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095018.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095019.exe (Trojan.Yimfoca) -> No action taken.
www.malwarebytes.org
Verze databáze: 5727
Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.13
10.2.2011 8:36:51
mbam-log-2011-02-10 (08-36-36).txt
Typ kontroly: Úplný test (C:\|)
Testované objekty: 192989
Uplynulý čas: 17 minut, 26 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 0
Infikované hodnoty v registru: 0
Infikované datové položky v registru: 0
Infikované složky: 0
Infikované soubory: 49
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované hodnoty v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky v registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\Peťa\Plocha\facebook-pic00005267.exe (Trojan.Yimfoca) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\localservice\data aplikací\microsoft\cudof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\localservice\data aplikací\microsoft\naturyttoof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\Peťa\data aplikací\microsoft\cudof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\Peťa\data aplikací\microsoft\naturyttoof.exe.vir (Trojan.VB) -> No action taken.
c:\Qoobox\quarantine\C\WINDOWS\nvsvc32.exe.vir (Trojan.Yimfoca) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP138\A0043034.exe (Trojan.Yimfoca) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP138\A0043035.exe (Trojan.Yimfoca) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0055942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0055944.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0056943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0057942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0058942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0059942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0060942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0061942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0062942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0063942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0064942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0065943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0066942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0067943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0068943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0070943.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0071942.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0071949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0075948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0076949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0077948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0078948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0079949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0080949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0081948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0082948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0083949.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0084948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0085948.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0085951.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0085955.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0086955.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0087954.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP150\A0088954.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP151\A0089954.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0093967.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095015.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095016.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095017.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095018.exe (Trojan.VB) -> No action taken.
c:\system volume information\_restore{f731efd7-2b19-4590-88df-c8bea0e046ea}\RP152\A0095019.exe (Trojan.Yimfoca) -> No action taken.
Re: prosím o kontrolu logu při najetí se restartuje......
V mbamu vše smažte.
Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
Kód: Vybrat vše
Restore::
c:\windows\system32\drivers\aec.sys
Driver::
SmileyCentral_1vService
Folder::
c:\progra~1\SMILEY~2
FF - ProfilePath - c:\documents and settings\Peťa\Data aplikací\Mozilla\Firefox\Profiles\uekfd37j.default\
FF - Ext: SmileyCentral: 1vffxtbr@SmileyCentral_1v.com - c:\program files\SmileyCentral_1v\bar\1.bin
FF - Ext: ICQ Toolbar: {800b5000-a755-47e1-992b-48a1c1357f07} - %profile%\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
FF - Ext: MyPlayCity Toolbar: {6a210611-2f33-4926-bf27-3fd9af8266eb} - %profile%\extensions\{6a210611-2f33-4926-bf27-3fd9af8266eb}
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.