Prosím o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Prosím o kontrolu logu
Prosím o kontrolu logu. Po startu systému naběhne "Windows repair", počítač se tváři jakoby všechny věci v něm byly vymazány, nelze spustit správce úloh. Dík
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-01 16:55:27
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 30 GB (26%) free of 114 GB
Total RAM: 1023 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:55:38, on 1.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\RemoteControlService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\All Users\Application Data\15720244.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.3.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Windows Services] winsd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msdrm] msdrm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 8003 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.3.dll [2010-10-07 1164568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-09-06 7585792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-09-06 86016]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-08-24 110592]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-20 15797248]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2006-05-30 811008]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SMail"=C:\Program Files\Seznam\Postak\Postak.exe []
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 1983816]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"Windows Services"=winsd.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-03-15 15360]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-07 488728]
"YoopehTnCRAPa"=C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe [2011-04-01 546816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD]
C:\Program Files\ASUSTek\ASUSDVD\ASUSDVD.exe [2006-06-19 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~3\Office10\OSA.EXE [2001-02-13 83360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-11 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-03-15 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableTaskMgr"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe"="C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe:*:Enabled:SH2"
"C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe"="C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe:*:Enabled:Microsoft Flight Simulator"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe:*:Enabled:Bluetooth PAN Server"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe:*:Enabled:Bluetooth PAN Client"
"C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe"="C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe:*:Enabled:Speedmanager plus"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe:*:Enabled:WiselinkPro"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe:*:Enabled:http_ss_win_pro"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe:*:Enabled:ldrsoft"
"C:\Documents and Settings\Administrator\Desktop\WideClient.exe"="C:\Documents and Settings\Administrator\Desktop\WideClient.exe:*:Enabled:FS Eliminator for FSUIPC client applications"
"C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe"="C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe:*:Enabled:Microsoft Flight Simulator®"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2011-04-01 16:55:28 ----D---- C:\Program Files\trend micro
2011-04-01 16:55:27 ----D---- C:\rsit
2011-04-01 16:55:11 ----A---- C:\WINDOWS\system32\drivers\fjbenamp.sys
2011-04-01 16:42:28 ----A---- C:\WINDOWS\system32\drivers\1089.sys
2011-04-01 16:42:15 ----D---- C:\Windows Repair
2011-04-01 16:42:03 ----AH---- C:\Documents and Settings\All Users\Application Data\15720244.exe
2011-04-01 16:06:58 ----A---- C:\WINDOWS\system32\drivers\1658.sys
2011-04-01 15:48:52 ----A---- C:\WINDOWS\system32\drivers\1128.sys
2011-04-01 15:38:12 ----SHD---- C:\WINDOWS\CSC
2011-04-01 15:37:59 ----AH---- C:\WINDOWS\ntbtlog.txt
2011-04-01 15:24:51 ----A---- C:\WINDOWS\system32\drivers\12211.sys
2011-04-01 15:11:26 ----A---- C:\WINDOWS\system32\drivers\193E.sys
2011-04-01 14:56:11 ----A---- C:\WINDOWS\system32\drivers\746C.sys
2011-04-01 14:09:40 ----A---- C:\WINDOWS\system32\drivers\854F.sys
2011-04-01 13:49:55 ----A---- C:\WINDOWS\system32\drivers\117D.sys
2011-04-01 13:28:09 ----A---- C:\WINDOWS\system32\drivers\164B.sys
2011-04-01 13:21:04 ----A---- C:\WINDOWS\system32\drivers\515C.sys
2011-04-01 13:05:24 ----A---- C:\WINDOWS\system32\drivers\842B.sys
2011-04-01 12:59:37 ----A---- C:\WINDOWS\system32\drivers\139A.sys
2011-04-01 12:57:44 ----AH---- C:\Documents and Settings\All Users\Application Data\18407220.exe
2011-04-01 12:53:38 ----A---- C:\WINDOWS\system32\drivers\122A9.sys
2011-04-01 12:53:35 ----AH---- C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
2011-04-01 12:53:25 ----A---- C:\WINDOWS\system32\wuaucldt.exe
2011-03-25 11:39:18 ----D---- C:\Program Files\QuickTime
2011-03-23 08:43:02 ----A---- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 08:42:57 ----HD---- C:\Program Files\Common Files\Redemption
2011-03-23 08:42:56 ----HD---- C:\Program Files\Common Files\NKTWAB
2011-03-23 08:42:46 ----D---- C:\Program Files\JABLOCOM
2011-03-20 13:38:25 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-09 14:24:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2502898$
======List of files/folders modified in the last 1 months======
2011-04-01 16:55:28 ----RD---- C:\Program Files
2011-04-01 16:55:11 ----D---- C:\WINDOWS\system32\drivers
2011-04-01 16:44:49 ----HD---- C:\WINDOWS\Temp
2011-04-01 16:43:32 ----D---- C:\WINDOWS\system32\Lang
2011-04-01 16:43:24 ----D---- C:\WINDOWS
2011-04-01 16:41:54 ----D---- C:\WINDOWS\Registration
2011-04-01 16:41:13 ----HD---- C:\WINDOWS\system32\CatRoot2
2011-04-01 16:38:31 ----HD---- C:\WINDOWS\inf
2011-04-01 16:16:31 ----D---- C:\WINDOWS\system32
2011-04-01 16:08:32 ----AH---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 14:27:36 ----D---- C:\Program Files\Mozilla Firefox
2011-03-27 10:08:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-25 11:42:05 ----SHD---- C:\WINDOWS\Installer
2011-03-25 11:39:14 ----HD---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2011-03-24 13:30:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-24 10:28:27 ----RSD---- C:\WINDOWS\assembly
2011-03-24 10:28:14 ----D---- C:\WINDOWS\WinSxS
2011-03-24 10:24:32 ----HD---- C:\WINDOWS\Prefetch
2011-03-23 13:11:56 ----A---- C:\WINDOWS\NeroDigital.ini
2011-03-23 08:42:57 ----D---- C:\Program Files\Common Files
2011-03-20 13:38:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-03-12 21:11:40 ----HD---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-03-12 21:04:19 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2011-03-12 21:04:19 ----HD---- C:\Documents and Settings\Administrator\Application Data\Adobe
2011-03-12 21:03:16 ----HD---- C:\Program Files\Common Files\Adobe
2011-03-12 21:02:44 ----D---- C:\Program Files\Adobe
2011-03-09 14:24:45 ----D---- C:\WINDOWS\Debug
2011-03-09 14:24:39 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-09 14:24:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-02 16:55:15 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2006-03-15 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2006-09-27 36560]
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver; C:\WINDOWS\system32\DRIVERS\sbp2port.sys [2005-06-01 43264]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43008]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsld82de729;MpKsld82de729; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{92F6DC44-35CA-4AF4-951A-52AD1A502F88}\MpKsld82de729.sys []
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2006-03-15 88448]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-03-15 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-03-15 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-07-17 494080]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-03-15 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
R3 AVerM115S;AVerM115S service; C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-08-03 856832]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-20 4127232]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 ITECIR;ITE CIR Driver; C:\WINDOWS\system32\DRIVERS\ITECIR.sys [2004-04-22 7366]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-18 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-03-15 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-09-06 3694208]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-07 11136]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2006-10-13 163584]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-09-17 28672]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-09-14 50560]
R3 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-09-30 310016]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2006-03-15 67584]
R3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
S1 cdfss;cdfss; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdfss []
S1 fjbenamp;fjbenamp; \??\C:\WINDOWS\system32\drivers\fjbenamp.sys []
S1 MpKsl0b61d6a5;MpKsl0b61d6a5; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys []
S1 MpKsl0eb62b3a;MpKsl0eb62b3a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys []
S1 MpKsl169119ca;MpKsl169119ca; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys []
S1 MpKsl24013e21;MpKsl24013e21; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys []
S1 MpKsl309fe936;MpKsl309fe936; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys []
S1 MpKsl34dd635a;MpKsl34dd635a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys []
S1 MpKsl495ad359;MpKsl495ad359; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys []
S1 MpKsl59063335;MpKsl59063335; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys []
S1 MpKsl986bef39;MpKsl986bef39; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys []
S1 MpKslc58b38dd;MpKslc58b38dd; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys []
S1 MpKsleccd34e4;MpKsleccd34e4; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys []
S1 MpKslef5db1fc;MpKslef5db1fc; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys []
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbser65.sys []
S3 Bridge;MAC Bridge; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-08-23 1035008]
S3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-08-23 201600]
S3 jusb;jusb; C:\WINDOWS\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2005-02-15 6300]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2005-02-15 9021]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2005-02-17 140619]
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2006-03-15 11136]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2006-03-15 10240]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2006-02-03 108928]
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-12-14 37632]
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2006-02-08 62848]
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2006-01-31 39808]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 UXDCMN;UXDCMN; \??\d:\Winstress\UXDCMN.SYS []
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-08-23 718464]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-10-11 110080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ehRecvr;Služba přijímače aplikace Media Center; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Služba plánování aplikace Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 ITECIRService;ITE Remote Control Service; C:\WINDOWS\system32\RemoteControlService.exe [2005-12-12 656384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-09-06 143426]
R2 NWCWorkstation;Client Service for NetWare; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2010-09-23 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-01 16:55:27
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 30 GB (26%) free of 114 GB
Total RAM: 1023 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:55:38, on 1.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\RemoteControlService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\All Users\Application Data\15720244.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.3.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Windows Services] winsd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msdrm] msdrm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 8003 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.3.dll [2010-10-07 1164568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-09-06 7585792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-09-06 86016]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-08-24 110592]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-20 15797248]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2006-05-30 811008]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SMail"=C:\Program Files\Seznam\Postak\Postak.exe []
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 1983816]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"Windows Services"=winsd.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-03-15 15360]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-07 488728]
"YoopehTnCRAPa"=C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe [2011-04-01 546816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD]
C:\Program Files\ASUSTek\ASUSDVD\ASUSDVD.exe [2006-06-19 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~3\Office10\OSA.EXE [2001-02-13 83360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-11 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-03-15 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableTaskMgr"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe"="C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe:*:Enabled:SH2"
"C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe"="C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe:*:Enabled:Microsoft Flight Simulator"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe:*:Enabled:Bluetooth PAN Server"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe:*:Enabled:Bluetooth PAN Client"
"C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe"="C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe:*:Enabled:Speedmanager plus"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe:*:Enabled:WiselinkPro"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe:*:Enabled:http_ss_win_pro"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe:*:Enabled:ldrsoft"
"C:\Documents and Settings\Administrator\Desktop\WideClient.exe"="C:\Documents and Settings\Administrator\Desktop\WideClient.exe:*:Enabled:FS Eliminator for FSUIPC client applications"
"C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe"="C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe:*:Enabled:Microsoft Flight Simulator®"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2011-04-01 16:55:28 ----D---- C:\Program Files\trend micro
2011-04-01 16:55:27 ----D---- C:\rsit
2011-04-01 16:55:11 ----A---- C:\WINDOWS\system32\drivers\fjbenamp.sys
2011-04-01 16:42:28 ----A---- C:\WINDOWS\system32\drivers\1089.sys
2011-04-01 16:42:15 ----D---- C:\Windows Repair
2011-04-01 16:42:03 ----AH---- C:\Documents and Settings\All Users\Application Data\15720244.exe
2011-04-01 16:06:58 ----A---- C:\WINDOWS\system32\drivers\1658.sys
2011-04-01 15:48:52 ----A---- C:\WINDOWS\system32\drivers\1128.sys
2011-04-01 15:38:12 ----SHD---- C:\WINDOWS\CSC
2011-04-01 15:37:59 ----AH---- C:\WINDOWS\ntbtlog.txt
2011-04-01 15:24:51 ----A---- C:\WINDOWS\system32\drivers\12211.sys
2011-04-01 15:11:26 ----A---- C:\WINDOWS\system32\drivers\193E.sys
2011-04-01 14:56:11 ----A---- C:\WINDOWS\system32\drivers\746C.sys
2011-04-01 14:09:40 ----A---- C:\WINDOWS\system32\drivers\854F.sys
2011-04-01 13:49:55 ----A---- C:\WINDOWS\system32\drivers\117D.sys
2011-04-01 13:28:09 ----A---- C:\WINDOWS\system32\drivers\164B.sys
2011-04-01 13:21:04 ----A---- C:\WINDOWS\system32\drivers\515C.sys
2011-04-01 13:05:24 ----A---- C:\WINDOWS\system32\drivers\842B.sys
2011-04-01 12:59:37 ----A---- C:\WINDOWS\system32\drivers\139A.sys
2011-04-01 12:57:44 ----AH---- C:\Documents and Settings\All Users\Application Data\18407220.exe
2011-04-01 12:53:38 ----A---- C:\WINDOWS\system32\drivers\122A9.sys
2011-04-01 12:53:35 ----AH---- C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
2011-04-01 12:53:25 ----A---- C:\WINDOWS\system32\wuaucldt.exe
2011-03-25 11:39:18 ----D---- C:\Program Files\QuickTime
2011-03-23 08:43:02 ----A---- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 08:42:57 ----HD---- C:\Program Files\Common Files\Redemption
2011-03-23 08:42:56 ----HD---- C:\Program Files\Common Files\NKTWAB
2011-03-23 08:42:46 ----D---- C:\Program Files\JABLOCOM
2011-03-20 13:38:25 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-09 14:24:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2502898$
======List of files/folders modified in the last 1 months======
2011-04-01 16:55:28 ----RD---- C:\Program Files
2011-04-01 16:55:11 ----D---- C:\WINDOWS\system32\drivers
2011-04-01 16:44:49 ----HD---- C:\WINDOWS\Temp
2011-04-01 16:43:32 ----D---- C:\WINDOWS\system32\Lang
2011-04-01 16:43:24 ----D---- C:\WINDOWS
2011-04-01 16:41:54 ----D---- C:\WINDOWS\Registration
2011-04-01 16:41:13 ----HD---- C:\WINDOWS\system32\CatRoot2
2011-04-01 16:38:31 ----HD---- C:\WINDOWS\inf
2011-04-01 16:16:31 ----D---- C:\WINDOWS\system32
2011-04-01 16:08:32 ----AH---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 14:27:36 ----D---- C:\Program Files\Mozilla Firefox
2011-03-27 10:08:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-25 11:42:05 ----SHD---- C:\WINDOWS\Installer
2011-03-25 11:39:14 ----HD---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2011-03-24 13:30:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-24 10:28:27 ----RSD---- C:\WINDOWS\assembly
2011-03-24 10:28:14 ----D---- C:\WINDOWS\WinSxS
2011-03-24 10:24:32 ----HD---- C:\WINDOWS\Prefetch
2011-03-23 13:11:56 ----A---- C:\WINDOWS\NeroDigital.ini
2011-03-23 08:42:57 ----D---- C:\Program Files\Common Files
2011-03-20 13:38:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-03-12 21:11:40 ----HD---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-03-12 21:04:19 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2011-03-12 21:04:19 ----HD---- C:\Documents and Settings\Administrator\Application Data\Adobe
2011-03-12 21:03:16 ----HD---- C:\Program Files\Common Files\Adobe
2011-03-12 21:02:44 ----D---- C:\Program Files\Adobe
2011-03-09 14:24:45 ----D---- C:\WINDOWS\Debug
2011-03-09 14:24:39 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-09 14:24:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-02 16:55:15 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2006-03-15 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2006-09-27 36560]
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver; C:\WINDOWS\system32\DRIVERS\sbp2port.sys [2005-06-01 43264]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43008]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsld82de729;MpKsld82de729; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{92F6DC44-35CA-4AF4-951A-52AD1A502F88}\MpKsld82de729.sys []
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2006-03-15 88448]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-03-15 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-03-15 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-07-17 494080]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-03-15 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
R3 AVerM115S;AVerM115S service; C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-08-03 856832]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-20 4127232]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 ITECIR;ITE CIR Driver; C:\WINDOWS\system32\DRIVERS\ITECIR.sys [2004-04-22 7366]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-18 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-03-15 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-09-06 3694208]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-07 11136]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2006-10-13 163584]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-09-17 28672]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-09-14 50560]
R3 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-09-30 310016]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2006-03-15 67584]
R3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
S1 cdfss;cdfss; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdfss []
S1 fjbenamp;fjbenamp; \??\C:\WINDOWS\system32\drivers\fjbenamp.sys []
S1 MpKsl0b61d6a5;MpKsl0b61d6a5; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys []
S1 MpKsl0eb62b3a;MpKsl0eb62b3a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys []
S1 MpKsl169119ca;MpKsl169119ca; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys []
S1 MpKsl24013e21;MpKsl24013e21; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys []
S1 MpKsl309fe936;MpKsl309fe936; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys []
S1 MpKsl34dd635a;MpKsl34dd635a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys []
S1 MpKsl495ad359;MpKsl495ad359; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys []
S1 MpKsl59063335;MpKsl59063335; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys []
S1 MpKsl986bef39;MpKsl986bef39; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys []
S1 MpKslc58b38dd;MpKslc58b38dd; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys []
S1 MpKsleccd34e4;MpKsleccd34e4; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys []
S1 MpKslef5db1fc;MpKslef5db1fc; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys []
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbser65.sys []
S3 Bridge;MAC Bridge; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-08-23 1035008]
S3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-08-23 201600]
S3 jusb;jusb; C:\WINDOWS\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2005-02-15 6300]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2005-02-15 9021]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2005-02-17 140619]
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2006-03-15 11136]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2006-03-15 10240]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2006-02-03 108928]
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-12-14 37632]
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2006-02-08 62848]
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2006-01-31 39808]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 UXDCMN;UXDCMN; \??\d:\Winstress\UXDCMN.SYS []
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-08-23 718464]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-10-11 110080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ehRecvr;Služba přijímače aplikace Media Center; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Služba plánování aplikace Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 ITECIRService;ITE Remote Control Service; C:\WINDOWS\system32\RemoteControlService.exe [2005-12-12 656384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-09-06 143426]
R2 NWCWorkstation;Client Service for NetWare; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2010-09-23 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Zdravím,
Stáhni a nainstaluj MBAM zde http://www.download.com/Malwarebytes-An ... tag=button
Spustit > na 3.záložce "Aktualizace" > Kontrola aktualizací
následně na 1.záložce "Kontrolor" -> Rychlá kontrola -> Prohledat
po dokončení scanu vyskočí okno Notepad s výsledkem - obsah zkopíruj do své odpovědi
zatím nic nemazat - počkej na posouzení
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Prosím o kontrolu logu
Děkuji.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 6253
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
3.4.2011 12:43:32
mbam-log-2011-04-03 (12-43-27).txt
Typ kontroly: Rychlý test
Testované objekty: 163357
Uplynulý čas: 34 minut, 7 sekund
Infikované procesy v paměti: 2
Infikované moduly v paměti: 0
Infikované klíče v registru: 2
Infikované hodnoty v registru: 7
Infikované datové položky v registru: 3
Infikované složky: 0
Infikované soubory: 23
Infikované procesy v paměti:
c:\documents and settings\all users\application data\yoopehtncrapa.exe (Trojan.Downloader) -> 612 -> No action taken.
c:\documents and settings\all users\application data\18407220.exe (Rogue.FakeHDD) -> 1440 -> No action taken.
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdfss (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Fci (Rootkit.Agent) -> No action taken.
Infikované hodnoty v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YoopehTnCRAPa (Trojan.Downloader) -> Value: YoopehTnCRAPa -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YoopehTnCRAPa (Trojan.Downloader) -> Value: YoopehTnCRAPa -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AIAkiwgpWK (Trojan.FakeAlert) -> Value: AIAkiwgpWK -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\idln2 (Malware.Trace) -> Value: idln2 -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\bk (Malware.Trace) -> Value: bk -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services (Backdoor.Bot) -> Value: Windows Services -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Value: Regedit32 -> No action taken.
Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\all users\application data\yoopehtncrapa.exe (Trojan.Downloader) -> No action taken.
c:\documents and settings\all users\application data\18407220.exe (Rogue.FakeHDD) -> No action taken.
c:\documents and settings\all users\application data\aiakiwgpwk.exe (Trojan.FakeAlert) -> No action taken.
c:\documents and settings\administrator\local settings\temp\cdfss (Rootkit.Agent) -> No action taken.
c:\documents and settings\all users\application data\15720244.exe (Rogue.FakeHDD) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS2.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS3.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS4.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS5.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS6.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS7.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS8.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS9.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NSA.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NSA5.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NSB.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\tmp8.tmp (Trojan.Downloader) -> No action taken.
c:\WINDOWS\Temp\tmpB.tmp (Trojan.FakeAlert) -> No action taken.
c:\documents and settings\administrator\application data\avdrn.dat (Malware.Trace) -> No action taken.
c:\WINDOWS\system32\wuaucldt.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator\wuaucldt.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator\application data\ssdfsfs.bat (Malware.Trace) -> No action taken.
c:\documents and settings\administrator\local settings\temp\internetexplorerupdate.exe (Trojan.FakeAlert) -> No action taken.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 6253
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
3.4.2011 12:43:32
mbam-log-2011-04-03 (12-43-27).txt
Typ kontroly: Rychlý test
Testované objekty: 163357
Uplynulý čas: 34 minut, 7 sekund
Infikované procesy v paměti: 2
Infikované moduly v paměti: 0
Infikované klíče v registru: 2
Infikované hodnoty v registru: 7
Infikované datové položky v registru: 3
Infikované složky: 0
Infikované soubory: 23
Infikované procesy v paměti:
c:\documents and settings\all users\application data\yoopehtncrapa.exe (Trojan.Downloader) -> 612 -> No action taken.
c:\documents and settings\all users\application data\18407220.exe (Rogue.FakeHDD) -> 1440 -> No action taken.
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdfss (Rootkit.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Fci (Rootkit.Agent) -> No action taken.
Infikované hodnoty v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YoopehTnCRAPa (Trojan.Downloader) -> Value: YoopehTnCRAPa -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YoopehTnCRAPa (Trojan.Downloader) -> Value: YoopehTnCRAPa -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AIAkiwgpWK (Trojan.FakeAlert) -> Value: AIAkiwgpWK -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\idln2 (Malware.Trace) -> Value: idln2 -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\bk (Malware.Trace) -> Value: bk -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services (Backdoor.Bot) -> Value: Windows Services -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Value: Regedit32 -> No action taken.
Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\all users\application data\yoopehtncrapa.exe (Trojan.Downloader) -> No action taken.
c:\documents and settings\all users\application data\18407220.exe (Rogue.FakeHDD) -> No action taken.
c:\documents and settings\all users\application data\aiakiwgpwk.exe (Trojan.FakeAlert) -> No action taken.
c:\documents and settings\administrator\local settings\temp\cdfss (Rootkit.Agent) -> No action taken.
c:\documents and settings\all users\application data\15720244.exe (Rogue.FakeHDD) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS2.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS3.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS4.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS5.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS6.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS7.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS8.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NS9.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NSA.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NSA5.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\NSB.tmp (Rootkit.Agent) -> No action taken.
c:\documents and settings\administrator\local settings\temp\tmp8.tmp (Trojan.Downloader) -> No action taken.
c:\WINDOWS\Temp\tmpB.tmp (Trojan.FakeAlert) -> No action taken.
c:\documents and settings\administrator\application data\avdrn.dat (Malware.Trace) -> No action taken.
c:\WINDOWS\system32\wuaucldt.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator\wuaucldt.exe (Trojan.Agent) -> No action taken.
c:\documents and settings\administrator\application data\ssdfsfs.bat (Malware.Trace) -> No action taken.
c:\documents and settings\administrator\local settings\temp\internetexplorerupdate.exe (Trojan.FakeAlert) -> No action taken.
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
MBAM spustit znovu - dát Úplná kontrola
po ukončení -> Zobrazit výsledky -> zkontrolovat zda je vše označeno -> Odstranit označené
vyběhne log, ve kterém budou záznamy tohoto typu:
Infikované adresáře:
C:\Program Files\xxxxxx -> Quarantined and deleted successfully.
ten bych taky rád viděl
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Prosím o kontrolu logu
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Verze databáze: 6253
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
3.4.2011 17:22:20
mbam-log-2011-04-03 (17-22-20).txt
Typ kontroly: Úplný test (C:\|)
Testované objekty: 380775
Uplynulý čas: 2 hodin, 30 minut, 9 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 1
Infikované hodnoty v registru: 5
Infikované datové položky v registru: 3
Infikované složky: 0
Infikované soubory: 18
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Fci (Rootkit.Agent) -> Quarantined and deleted successfully.
Infikované hodnoty v registru:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AIAkiwgpWK (Trojan.FakeAlert) -> Value: AIAkiwgpWK -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\idln2 (Malware.Trace) -> Value: idln2 -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\bk (Malware.Trace) -> Value: bk -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services (Backdoor.Bot) -> Value: Windows Services -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Value: Regedit32 -> Delete on reboot.
Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\all users\application data\aiakiwgpwk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251890.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251891.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251894.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251919.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251944.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251945.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251988.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251992.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0252057.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0252063.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0252072.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tmpB.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wuaucldt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\wuaucldt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\ssdfsfs.bat (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\local settings\temp\internetexplorerupdate.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
www.malwarebytes.org
Verze databáze: 6253
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
3.4.2011 17:22:20
mbam-log-2011-04-03 (17-22-20).txt
Typ kontroly: Úplný test (C:\|)
Testované objekty: 380775
Uplynulý čas: 2 hodin, 30 minut, 9 sekund
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče v registru: 1
Infikované hodnoty v registru: 5
Infikované datové položky v registru: 3
Infikované složky: 0
Infikované soubory: 18
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče v registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Fci (Rootkit.Agent) -> Quarantined and deleted successfully.
Infikované hodnoty v registru:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AIAkiwgpWK (Trojan.FakeAlert) -> Value: AIAkiwgpWK -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\idln2 (Malware.Trace) -> Value: idln2 -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\bk (Malware.Trace) -> Value: bk -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Services (Backdoor.Bot) -> Value: Windows Services -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Value: Regedit32 -> Delete on reboot.
Infikované datové položky v registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
c:\documents and settings\all users\application data\aiakiwgpwk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251890.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251891.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251894.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP622\A0251919.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251944.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251945.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251988.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0251992.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0252057.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0252063.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{72191393-574b-421e-bda2-990653f9bf42}\RP623\A0252072.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tmpB.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wuaucldt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\wuaucldt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\application data\ssdfsfs.bat (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\local settings\temp\internetexplorerupdate.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
MBAM -> OK
dej mi nový RSIT a napiš jestli jsou ještě nějaké problémy
dej mi nový RSIT a napiš jestli jsou ještě nějaké problémy
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Prosím o kontrolu logu
Veškerá havěť (windows repair, vyskakovací okna ap.) jsou pryč, počítač nabíhá a chová se normálně. Jde spustit i správce úloh (dřív nešel), ovšem veškerá data, ikony, nabídka start jsou pryč. Resp. je zřejmě asi nevidím, protože HDD ukazuje kapacitu z 80% zaplněno..
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-01 16:55:27
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 30 GB (26%) free of 114 GB
Total RAM: 1023 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:55:38, on 1.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\RemoteControlService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\All Users\Application Data\15720244.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.3.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Windows Services] winsd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msdrm] msdrm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 8003 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.3.dll [2010-10-07 1164568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-09-06 7585792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-09-06 86016]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-08-24 110592]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-20 15797248]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2006-05-30 811008]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SMail"=C:\Program Files\Seznam\Postak\Postak.exe []
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 1983816]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"Windows Services"=winsd.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-03-15 15360]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-07 488728]
"YoopehTnCRAPa"=C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe [2011-04-01 546816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD]
C:\Program Files\ASUSTek\ASUSDVD\ASUSDVD.exe [2006-06-19 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~3\Office10\OSA.EXE [2001-02-13 83360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-11 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-03-15 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableTaskMgr"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe"="C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe:*:Enabled:SH2"
"C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe"="C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe:*:Enabled:Microsoft Flight Simulator"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe:*:Enabled:Bluetooth PAN Server"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe:*:Enabled:Bluetooth PAN Client"
"C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe"="C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe:*:Enabled:Speedmanager plus"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe:*:Enabled:WiselinkPro"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe:*:Enabled:http_ss_win_pro"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe:*:Enabled:ldrsoft"
"C:\Documents and Settings\Administrator\Desktop\WideClient.exe"="C:\Documents and Settings\Administrator\Desktop\WideClient.exe:*:Enabled:FS Eliminator for FSUIPC client applications"
"C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe"="C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe:*:Enabled:Microsoft Flight Simulator®"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2011-04-01 16:55:28 ----D---- C:\Program Files\trend micro
2011-04-01 16:55:27 ----D---- C:\rsit
2011-04-01 16:55:11 ----A---- C:\WINDOWS\system32\drivers\fjbenamp.sys
2011-04-01 16:42:28 ----A---- C:\WINDOWS\system32\drivers\1089.sys
2011-04-01 16:42:15 ----D---- C:\Windows Repair
2011-04-01 16:42:03 ----AH---- C:\Documents and Settings\All Users\Application Data\15720244.exe
2011-04-01 16:06:58 ----A---- C:\WINDOWS\system32\drivers\1658.sys
2011-04-01 15:48:52 ----A---- C:\WINDOWS\system32\drivers\1128.sys
2011-04-01 15:38:12 ----SHD---- C:\WINDOWS\CSC
2011-04-01 15:37:59 ----AH---- C:\WINDOWS\ntbtlog.txt
2011-04-01 15:24:51 ----A---- C:\WINDOWS\system32\drivers\12211.sys
2011-04-01 15:11:26 ----A---- C:\WINDOWS\system32\drivers\193E.sys
2011-04-01 14:56:11 ----A---- C:\WINDOWS\system32\drivers\746C.sys
2011-04-01 14:09:40 ----A---- C:\WINDOWS\system32\drivers\854F.sys
2011-04-01 13:49:55 ----A---- C:\WINDOWS\system32\drivers\117D.sys
2011-04-01 13:28:09 ----A---- C:\WINDOWS\system32\drivers\164B.sys
2011-04-01 13:21:04 ----A---- C:\WINDOWS\system32\drivers\515C.sys
2011-04-01 13:05:24 ----A---- C:\WINDOWS\system32\drivers\842B.sys
2011-04-01 12:59:37 ----A---- C:\WINDOWS\system32\drivers\139A.sys
2011-04-01 12:57:44 ----AH---- C:\Documents and Settings\All Users\Application Data\18407220.exe
2011-04-01 12:53:38 ----A---- C:\WINDOWS\system32\drivers\122A9.sys
2011-04-01 12:53:35 ----AH---- C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
2011-04-01 12:53:25 ----A---- C:\WINDOWS\system32\wuaucldt.exe
2011-03-25 11:39:18 ----D---- C:\Program Files\QuickTime
2011-03-23 08:43:02 ----A---- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 08:42:57 ----HD---- C:\Program Files\Common Files\Redemption
2011-03-23 08:42:56 ----HD---- C:\Program Files\Common Files\NKTWAB
2011-03-23 08:42:46 ----D---- C:\Program Files\JABLOCOM
2011-03-20 13:38:25 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-09 14:24:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2502898$
======List of files/folders modified in the last 1 months======
2011-04-01 16:55:28 ----RD---- C:\Program Files
2011-04-01 16:55:11 ----D---- C:\WINDOWS\system32\drivers
2011-04-01 16:44:49 ----HD---- C:\WINDOWS\Temp
2011-04-01 16:43:32 ----D---- C:\WINDOWS\system32\Lang
2011-04-01 16:43:24 ----D---- C:\WINDOWS
2011-04-01 16:41:54 ----D---- C:\WINDOWS\Registration
2011-04-01 16:41:13 ----HD---- C:\WINDOWS\system32\CatRoot2
2011-04-01 16:38:31 ----HD---- C:\WINDOWS\inf
2011-04-01 16:16:31 ----D---- C:\WINDOWS\system32
2011-04-01 16:08:32 ----AH---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 14:27:36 ----D---- C:\Program Files\Mozilla Firefox
2011-03-27 10:08:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-25 11:42:05 ----SHD---- C:\WINDOWS\Installer
2011-03-25 11:39:14 ----HD---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2011-03-24 13:30:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-24 10:28:27 ----RSD---- C:\WINDOWS\assembly
2011-03-24 10:28:14 ----D---- C:\WINDOWS\WinSxS
2011-03-24 10:24:32 ----HD---- C:\WINDOWS\Prefetch
2011-03-23 13:11:56 ----A---- C:\WINDOWS\NeroDigital.ini
2011-03-23 08:42:57 ----D---- C:\Program Files\Common Files
2011-03-20 13:38:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-03-12 21:11:40 ----HD---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-03-12 21:04:19 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2011-03-12 21:04:19 ----HD---- C:\Documents and Settings\Administrator\Application Data\Adobe
2011-03-12 21:03:16 ----HD---- C:\Program Files\Common Files\Adobe
2011-03-12 21:02:44 ----D---- C:\Program Files\Adobe
2011-03-09 14:24:45 ----D---- C:\WINDOWS\Debug
2011-03-09 14:24:39 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-09 14:24:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-02 16:55:15 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2006-03-15 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2006-09-27 36560]
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver; C:\WINDOWS\system32\DRIVERS\sbp2port.sys [2005-06-01 43264]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43008]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsld82de729;MpKsld82de729; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{92F6DC44-35CA-4AF4-951A-52AD1A502F88}\MpKsld82de729.sys []
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2006-03-15 88448]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-03-15 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-03-15 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-07-17 494080]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-03-15 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
R3 AVerM115S;AVerM115S service; C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-08-03 856832]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-20 4127232]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 ITECIR;ITE CIR Driver; C:\WINDOWS\system32\DRIVERS\ITECIR.sys [2004-04-22 7366]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-18 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-03-15 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-09-06 3694208]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-07 11136]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2006-10-13 163584]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-09-17 28672]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-09-14 50560]
R3 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-09-30 310016]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2006-03-15 67584]
R3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
S1 cdfss;cdfss; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdfss []
S1 fjbenamp;fjbenamp; \??\C:\WINDOWS\system32\drivers\fjbenamp.sys []
S1 MpKsl0b61d6a5;MpKsl0b61d6a5; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys []
S1 MpKsl0eb62b3a;MpKsl0eb62b3a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys []
S1 MpKsl169119ca;MpKsl169119ca; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys []
S1 MpKsl24013e21;MpKsl24013e21; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys []
S1 MpKsl309fe936;MpKsl309fe936; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys []
S1 MpKsl34dd635a;MpKsl34dd635a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys []
S1 MpKsl495ad359;MpKsl495ad359; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys []
S1 MpKsl59063335;MpKsl59063335; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys []
S1 MpKsl986bef39;MpKsl986bef39; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys []
S1 MpKslc58b38dd;MpKslc58b38dd; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys []
S1 MpKsleccd34e4;MpKsleccd34e4; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys []
S1 MpKslef5db1fc;MpKslef5db1fc; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys []
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbser65.sys []
S3 Bridge;MAC Bridge; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-08-23 1035008]
S3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-08-23 201600]
S3 jusb;jusb; C:\WINDOWS\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2005-02-15 6300]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2005-02-15 9021]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2005-02-17 140619]
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2006-03-15 11136]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2006-03-15 10240]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2006-02-03 108928]
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-12-14 37632]
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2006-02-08 62848]
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2006-01-31 39808]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 UXDCMN;UXDCMN; \??\d:\Winstress\UXDCMN.SYS []
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-08-23 718464]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-10-11 110080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ehRecvr;Služba přijímače aplikace Media Center; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Služba plánování aplikace Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 ITECIRService;ITE Remote Control Service; C:\WINDOWS\system32\RemoteControlService.exe [2005-12-12 656384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-09-06 143426]
R2 NWCWorkstation;Client Service for NetWare; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2010-09-23 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-01 16:55:27
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 30 GB (26%) free of 114 GB
Total RAM: 1023 MB (34% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:55:38, on 1.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\RemoteControlService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\All Users\Application Data\15720244.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\system32\ACEngSvr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
C:\WINDOWS\system32\attrib.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\WINDOWS\system32\attrib.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.3.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SMail] "C:\Program Files\Seznam\Postak\Postak.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Windows Services] winsd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msdrm] msdrm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [YoopehTnCRAPa] C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O9 - Extra button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: ITE Remote Control Service (ITECIRService) - ITE Tech. Inc. - C:\WINDOWS\system32\RemoteControlService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 8003 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-01-30 62376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2009-11-25 202080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-01-05 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2011-01-05 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.3.dll [2010-10-07 1164568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2009-11-25 1496408]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-09-06 7585792]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-09-06 86016]
"HControl"=C:\WINDOWS\ATK0100\HControl.exe [2006-08-24 110592]
"High Definition Audio Property Page Shortcut"=C:\WINDOWS\system32\HDAShCut.exe [2005-01-07 61952]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-20 15797248]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2006-05-30 811008]
"Wireless Console 2"=C:\Program Files\Wireless Console 2\wcourier.exe [2005-10-17 987136]
"SMail"=C:\Program Files\Seznam\Postak\Postak.exe []
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2009-07-27 1983816]
"CanonSolutionMenu"=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2009-03-18 767312]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2010-11-30 997408]
"Windows Services"=winsd.exe []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe [2011-01-30 35736]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-11-15 932288]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
"Regedit32"=C:\WINDOWS\system32\regedit.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2006-03-15 15360]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-07 488728]
"YoopehTnCRAPa"=C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe [2011-04-01 546816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 133104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD]
C:\Program Files\ASUSTek\ASUSDVD\ASUSDVD.exe [2006-06-19 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2010-11-29 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~3\Office10\OSA.EXE [2001-02-13 83360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-08-11 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2006-03-15 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableTaskMgr"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe"="C:\Program Files\SSI\Silent Hunter II\Shell\SH2.exe:*:Enabled:SH2"
"C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe"="C:\Program Files\Microsoft Games\Flight Simulator 9\fs9.exe:*:Enabled:Microsoft Flight Simulator"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPSS.exe:*:Enabled:Bluetooth PAN Server"
"C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe"="C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe:*:Enabled:Bluetooth PAN Client"
"C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe"="C:\Program Files\T-Mobile\Speedmanager plus\Speedmanager plus.exe:*:Enabled:Speedmanager plus"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe:*:Enabled:WiselinkPro"
"C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe"="C:\Program Files\Samsung\SAMSUNG PC Share Manager\http_ss_win_pro.exe:*:Enabled:http_ss_win_pro"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"="C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe:*:Enabled:ldrsoft"
"C:\Documents and Settings\Administrator\Desktop\WideClient.exe"="C:\Documents and Settings\Administrator\Desktop\WideClient.exe:*:Enabled:FS Eliminator for FSUIPC client applications"
"C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe"="C:\Program Files\Microsoft Games\Microsoft Flight Simulator X\fsx.exe:*:Enabled:Microsoft Flight Simulator®"
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe"="C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth"
"C:\Program Files\Google\Google Earth\client\googleearth.exe"="C:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\ICQ7.2\ICQ.exe"="C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2"
"C:\Program Files\ICQ7.2\aolload.exe"="C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe"
======List of files/folders created in the last 1 months======
2011-04-01 16:55:28 ----D---- C:\Program Files\trend micro
2011-04-01 16:55:27 ----D---- C:\rsit
2011-04-01 16:55:11 ----A---- C:\WINDOWS\system32\drivers\fjbenamp.sys
2011-04-01 16:42:28 ----A---- C:\WINDOWS\system32\drivers\1089.sys
2011-04-01 16:42:15 ----D---- C:\Windows Repair
2011-04-01 16:42:03 ----AH---- C:\Documents and Settings\All Users\Application Data\15720244.exe
2011-04-01 16:06:58 ----A---- C:\WINDOWS\system32\drivers\1658.sys
2011-04-01 15:48:52 ----A---- C:\WINDOWS\system32\drivers\1128.sys
2011-04-01 15:38:12 ----SHD---- C:\WINDOWS\CSC
2011-04-01 15:37:59 ----AH---- C:\WINDOWS\ntbtlog.txt
2011-04-01 15:24:51 ----A---- C:\WINDOWS\system32\drivers\12211.sys
2011-04-01 15:11:26 ----A---- C:\WINDOWS\system32\drivers\193E.sys
2011-04-01 14:56:11 ----A---- C:\WINDOWS\system32\drivers\746C.sys
2011-04-01 14:09:40 ----A---- C:\WINDOWS\system32\drivers\854F.sys
2011-04-01 13:49:55 ----A---- C:\WINDOWS\system32\drivers\117D.sys
2011-04-01 13:28:09 ----A---- C:\WINDOWS\system32\drivers\164B.sys
2011-04-01 13:21:04 ----A---- C:\WINDOWS\system32\drivers\515C.sys
2011-04-01 13:05:24 ----A---- C:\WINDOWS\system32\drivers\842B.sys
2011-04-01 12:59:37 ----A---- C:\WINDOWS\system32\drivers\139A.sys
2011-04-01 12:57:44 ----AH---- C:\Documents and Settings\All Users\Application Data\18407220.exe
2011-04-01 12:53:38 ----A---- C:\WINDOWS\system32\drivers\122A9.sys
2011-04-01 12:53:35 ----AH---- C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe
2011-04-01 12:53:25 ----A---- C:\WINDOWS\system32\wuaucldt.exe
2011-03-25 11:39:18 ----D---- C:\Program Files\QuickTime
2011-03-23 08:43:02 ----A---- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 08:42:57 ----HD---- C:\Program Files\Common Files\Redemption
2011-03-23 08:42:56 ----HD---- C:\Program Files\Common Files\NKTWAB
2011-03-23 08:42:46 ----D---- C:\Program Files\JABLOCOM
2011-03-20 13:38:25 ----D---- C:\Program Files\Microsoft Silverlight
2011-03-09 14:24:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2502898$
======List of files/folders modified in the last 1 months======
2011-04-01 16:55:28 ----RD---- C:\Program Files
2011-04-01 16:55:11 ----D---- C:\WINDOWS\system32\drivers
2011-04-01 16:44:49 ----HD---- C:\WINDOWS\Temp
2011-04-01 16:43:32 ----D---- C:\WINDOWS\system32\Lang
2011-04-01 16:43:24 ----D---- C:\WINDOWS
2011-04-01 16:41:54 ----D---- C:\WINDOWS\Registration
2011-04-01 16:41:13 ----HD---- C:\WINDOWS\system32\CatRoot2
2011-04-01 16:38:31 ----HD---- C:\WINDOWS\inf
2011-04-01 16:16:31 ----D---- C:\WINDOWS\system32
2011-04-01 16:08:32 ----AH---- C:\WINDOWS\SchedLgU.Txt
2011-03-28 14:27:36 ----D---- C:\Program Files\Mozilla Firefox
2011-03-27 10:08:14 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-03-25 11:42:05 ----SHD---- C:\WINDOWS\Installer
2011-03-25 11:39:14 ----HD---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2011-03-24 13:30:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-03-24 10:28:27 ----RSD---- C:\WINDOWS\assembly
2011-03-24 10:28:14 ----D---- C:\WINDOWS\WinSxS
2011-03-24 10:24:32 ----HD---- C:\WINDOWS\Prefetch
2011-03-23 13:11:56 ----A---- C:\WINDOWS\NeroDigital.ini
2011-03-23 08:42:57 ----D---- C:\Program Files\Common Files
2011-03-20 13:38:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2011-03-12 21:11:40 ----HD---- C:\Documents and Settings\All Users\Application Data\Adobe
2011-03-12 21:04:19 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2011-03-12 21:04:19 ----HD---- C:\Documents and Settings\Administrator\Application Data\Adobe
2011-03-12 21:03:16 ----HD---- C:\Program Files\Common Files\Adobe
2011-03-12 21:02:44 ----D---- C:\Program Files\Adobe
2011-03-09 14:24:45 ----D---- C:\WINDOWS\Debug
2011-03-09 14:24:39 ----A---- C:\WINDOWS\system32\MRT.exe
2011-03-09 14:24:21 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-03-02 16:55:15 ----HD---- C:\Documents and Settings\All Users\Application Data\CanonIJPLM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2006-03-15 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2006-09-27 36560]
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver; C:\WINDOWS\system32\DRIVERS\sbp2port.sys [2005-06-01 43264]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 43008]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 MpFilter;Microsoft Malware Protection Driver; C:\WINDOWS\system32\DRIVERS\MpFilter.sys [2010-10-24 165264]
R1 MpKsld82de729;MpKsld82de729; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{92F6DC44-35CA-4AF4-951A-52AD1A502F88}\MpKsld82de729.sys []
R1 Tosrfcom;Bluetooth RFCOMM from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfcom.sys [2005-08-01 64896]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R2 irda;IrDA Protocol; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2006-03-15 88448]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-03-15 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-03-15 55936]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2006-07-17 494080]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2006-03-15 60800]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\WINDOWS\ATK0100\ASNDIS5.SYS []
R3 AVerM115S;AVerM115S service; C:\WINDOWS\system32\DRIVERS\AVerM115S.sys [2006-08-03 856832]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-12-20 4127232]
R3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 ITECIR;ITE CIR Driver; C:\WINDOWS\system32\DRIVERS\ITECIR.sys [2004-04-22 7366]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2005-02-18 5632]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2006-03-15 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-09-06 3694208]
R3 nvsmu;nvsmu; C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-07 11136]
R3 NWRDR;NetWare Rdr; C:\WINDOWS\system32\DRIVERS\nwrdr.sys [2006-10-13 163584]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2005-09-17 28672]
R3 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2005-09-14 50560]
R3 rismxdp;Ricoh xD-Picture Card Driver; C:\WINDOWS\system32\DRIVERS\rixdptsk.sys [2005-09-30 310016]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys [2005-03-04 74496]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2006-03-15 67584]
R3 SynMini;USB2.0 1.3M Web Cam; C:\WINDOWS\System32\Drivers\SynMini.sys [2005-10-03 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image; C:\WINDOWS\System32\Drivers\SynScan.sys [2005-10-03 8278]
R3 tosporte;Bluetooth Port Driver from Toshiba; C:\WINDOWS\system32\DRIVERS\tosporte.sys [2005-11-24 47104]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-04 59264]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-04 31616]
R3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
S1 cdfss;cdfss; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cdfss []
S1 fjbenamp;fjbenamp; \??\C:\WINDOWS\system32\drivers\fjbenamp.sys []
S1 MpKsl0b61d6a5;MpKsl0b61d6a5; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys []
S1 MpKsl0eb62b3a;MpKsl0eb62b3a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys []
S1 MpKsl169119ca;MpKsl169119ca; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys []
S1 MpKsl24013e21;MpKsl24013e21; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys []
S1 MpKsl309fe936;MpKsl309fe936; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys []
S1 MpKsl34dd635a;MpKsl34dd635a; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys []
S1 MpKsl495ad359;MpKsl495ad359; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys []
S1 MpKsl59063335;MpKsl59063335; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys []
S1 MpKsl986bef39;MpKsl986bef39; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys []
S1 MpKslc58b38dd;MpKslc58b38dd; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys []
S1 MpKsleccd34e4;MpKsleccd34e4; \??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys []
S1 MpKslef5db1fc;MpKslef5db1fc; \??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys []
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbser65.sys []
S3 Bridge;MAC Bridge; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\WINDOWS\system32\DRIVERS\bridge.sys [2006-03-15 71552]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 HdAudAddService;Microsoft UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\HdAudio.sys [2005-01-07 145920]
S3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-08-23 1035008]
S3 HSFHWAZL;HSFHWAZL; C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys [2005-08-23 201600]
S3 jusb;jusb; C:\WINDOWS\System32\Drivers\jusb.sys [2007-04-11 29184]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 15360]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 Nokia USB Generic;Nokia USB Generic; C:\WINDOWS\system32\drivers\nmwcdc.sys [2005-02-15 6300]
S3 Nokia USB Modem;Nokia USB Modem; C:\WINDOWS\system32\drivers\nmwcdcm.sys [2005-02-15 9021]
S3 Nokia USB Phone Parent;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\nmwcd.sys [2005-02-17 140619]
S3 sffdisk;SFF Storage Class Driver; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2006-03-15 11136]
S3 sffp_sd;SFF Storage Protocol Driver for SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2006-03-15 10240]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 toshidpt;TOSHIBA Bluetooth HID port driver; C:\WINDOWS\system32\drivers\Toshidpt.sys [2005-07-11 3712]
S3 Tosrfbd;Bluetooth RFBUS from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbd.sys [2006-02-03 108928]
S3 Tosrfbnp;Bluetooth RFBNEP from TOSHIBA; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [2005-12-14 37632]
S3 Tosrfhid;Bluetooth RFHID from TOSHIBA; C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys [2006-02-08 62848]
S3 tosrfnds;Bluetooth Personal Area Network from TOSHIBA; C:\WINDOWS\system32\DRIVERS\tosrfnds.sys [2005-01-06 18612]
S3 TosRfSnd;Bluetooth Audio Device (WDM) from TOSHIBA; C:\WINDOWS\system32\drivers\TosRfSnd.sys [2005-11-11 52864]
S3 Tosrfusb;Bluetooth USB Controller; C:\WINDOWS\System32\Drivers\tosrfusb.sys [2006-01-31 39808]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 UXDCMN;UXDCMN; \??\d:\Winstress\UXDCMN.SYS []
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2008-05-06 11520]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-08-23 718464]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 DNE;Deterministic Network Enhancer Miniport; C:\WINDOWS\system32\DRIVERS\dne2000.sys [2005-10-11 110080]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ehRecvr;Služba přijímače aplikace Media Center; C:\WINDOWS\eHome\ehRecvr.exe [2006-10-09 237568]
R2 ehSched;Služba plánování aplikace Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2009-02-10 116104]
R2 Irmon;Infrared Monitor; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 ITECIRService;ITE Remote Control Service; C:\WINDOWS\system32\RemoteControlService.exe [2005-12-12 656384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-11-12 153376]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-04-24 73728]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-19 322120]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [2010-11-11 11736]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-09-06 143426]
R2 NWCWorkstation;Client Service for NetWare; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2010-09-23 14336]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 136176]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2010-09-23 14336]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Stáhni siComboFix
a ulož ho na plochu.
návod na použití: http://www.bleepingcomputer.com/combofi ... t-combofix
Ukonči všechna aktivní okna,vypni Antispy a Antivir a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna a nic nespouštěj
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Kdyby ti po použití ComboFixu systém nenaběhl - při restartu F8 a poslední známá funkční konfigurace
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Prosím o kontrolu logu
ComboFix 11-04-11.03 - Administrator 12.04.2011 13:11:56.9.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1033.18.1023.737 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_FCI
-------\Legacy_WCSCD
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-12 do 2011-04-12 )))))))))))))))))))))))))))))))
2011-04-06 06:27:12 . 2011-03-15 04:05:43 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\mpengine.dll
2011-04-05 18:17:07 . 2011-04-05 18:19:08 -------- d-----w- C:\32788R22FWJFW.1.tmp
2011-04-03 10:07:16 . 2011-04-03 10:07:16 -------- d--h--w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2011-04-03 10:07:06 . 2010-12-20 16:09:00 38224 ---ha-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-03 10:07:04 . 2011-04-03 10:07:04 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-04-03 10:06:57 . 2011-04-03 10:07:10 -------- d--h--w- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-01 14:55:28 . 2011-04-04 10:02:56 -------- d--h--w- C:\Program Files\trend micro
2011-04-01 14:55:27 . 2011-04-01 14:55:42 -------- d-----w- C:\rsit
2011-04-01 14:42:15 . 2011-04-01 14:42:17 -------- d-----w- C:\Windows Repair
2011-03-25 09:39:29 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
2011-03-25 09:39:20 . 2011-03-18 17:55:52 781272 ---ha-w- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 728024 ---ha-w- C:\Program Files\Mozilla Firefox\libGLESv2.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 1874904 ---ha-w- C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 15832 ---ha-w- C:\Program Files\Mozilla Firefox\mozalloc.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\libEGL.dll
2011-03-25 09:39:18 . 2011-03-25 09:40:27 -------- d--h--w- C:\Program Files\QuickTime
2011-03-25 09:39:18 . 2011-03-18 17:55:52 1893336 ---ha-w- C:\Program Files\Mozilla Firefox\d3dx9_42.dll
2011-03-25 09:39:17 . 2011-03-18 17:55:51 1975768 ---ha-w- C:\Program Files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-23 06:43:12 . 2011-03-23 06:43:12 -------- d--h--w- C:\Documents and Settings\Administrator\Local Settings\Application Data\JABLOCOM
2011-03-23 06:43:02 . 2011-03-23 08:11:15 287229 ---ha-w- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 06:42:57 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\Redemption
2011-03-23 06:42:56 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\NKTWAB
2011-03-23 06:42:46 . 2011-03-23 06:42:58 -------- d--h--w- C:\Program Files\JABLOCOM
2011-03-20 11:38:25 . 2011-03-20 11:38:27 -------- d--h--w- C:\Program Files\Microsoft Silverlight
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-15 04:05:43 . 2010-10-31 14:26:48 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48:32 . 2006-03-15 12:00:00 456192 ---ha-w- C:\WINDOWS\system32\encdec.dll
2011-02-04 16:48:30 . 2006-03-15 12:00:00 291840 ---ha-w- C:\WINDOWS\system32\sbe.dll
2011-01-24 10:20:49 . 2009-08-17 15:42:28 45056 ---ha-w- C:\WINDOWS\system32\acovcnt.exe
2011-01-13 09:41:52 . 2011-01-26 10:25:56 5890896 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-03-18 17:55:52 . 2011-03-25 09:39:29 142296 ---ha-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
------- Sigcheck -------
[7] 2008-06-20 11:59:02 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 10:45:13 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)] . . C:\WINDOWS\system32\dllcache\tcpip.sys
[-] 2008-06-20 10:45:13 . 0B788EE2A876D7B31DF840C13F08CD2B . 360320 . . [5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)] . . C:\WINDOWS\system32\drivers\tcpip.sys
[7] 2008-06-20 10:44:42 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394 (xpsp_sp2_qfe.080620-1259)] . . C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2007-10-30 16:53:32 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244 (xpsp_sp2_qfe.071030-1255)] . . C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2006-04-20 12:18:35 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892 (xpsp.060420-0256)] . . C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2010-01-15 13:33:18 73728 ---ha-w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-10-07 13:55:06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56:34 64512]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-06 11:08:00 7585792]
"nwiz"="nwiz.exe" [2006-09-06 11:08:00 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-06 11:08:00 86016]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 22:22:14 110592]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07:16 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 22:52:52 15797248]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 09:28:20 811008]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [BU]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 02:10:00 1983816]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 01:40:00 767312]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2010-11-30 12:20:36 997408]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 15:45:14 35736]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 20:02:22 932288]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2010-11-29 16:38:18 421888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 12:00:00 15360]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 23:01:00 437160]
"msdrm"="msdrm.exe" [BU]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-10-17 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-08-22 12:21:10 133104 ---hatw- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD]
2006-06-19 15:47:24 528384 ---ha-w- C:\Program Files\ASUSTek\ASUSDVD\ASUSDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38:18 421888 ---ha-w- C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44:46 248552 ---ha-w- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SSI\\Silent Hunter II\\Shell\\SH2.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPSS.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\ICQ7.2\\ICQ.exe"=
"C:\\Program Files\\ICQ7.2\\aolload.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"C:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:msdrm
"45056:TCP"= 45056:TCP:msdrm
"5222:TCP"= 5222:TCP:msdrm
"5225:TCP"= 5225:TCP:msdrm
"2382:TCP"= 2382:TCP:msdrm
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\drivers\ITECIR.sys [14.2.2007 20:22:22 7366]
S1 bmkyuubw;bmkyuubw;\??\C:\WINDOWS\system32\drivers\bmkyuubw.sys --> C:\WINDOWS\system32\drivers\bmkyuubw.sys [?]
S1 MpKsl0b61d6a5;MpKsl0b61d6a5;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys [?]
S1 MpKsl0eb62b3a;MpKsl0eb62b3a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys [?]
S1 MpKsl169119ca;MpKsl169119ca;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys [?]
S1 MpKsl24013e21;MpKsl24013e21;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys [?]
S1 MpKsl309fe936;MpKsl309fe936;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys [?]
S1 MpKsl34dd635a;MpKsl34dd635a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys [?]
S1 MpKsl495ad359;MpKsl495ad359;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys [?]
S1 MpKsl59063335;MpKsl59063335;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys [?]
S1 MpKsl986bef39;MpKsl986bef39;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys [?]
S1 MpKslc58b38dd;MpKslc58b38dd;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys [?]
S1 MpKsleccd34e4;MpKsleccd34e4;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys [?]
S1 MpKslef5db1fc;MpKslef5db1fc;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys [?]
S1 qtysqtwh;qtysqtwh;\??\C:\WINDOWS\system32\drivers\qtysqtwh.sys --> C:\WINDOWS\system32\drivers\qtysqtwh.sys [?]
S1 yuhaiknp;yuhaiknp;\??\C:\WINDOWS\system32\drivers\yuhaiknp.sys --> C:\WINDOWS\system32\drivers\yuhaiknp.sys [?]
S2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\drivers\ethpdrv.sys [29.12.2007 12:07:32 9728]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [28.3.2010 17:05:30 136176]
S2 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [14.2.2007 20:22:22 656384]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);C:\WINDOWS\system32\drivers\adusbmdm65.sys [15.6.2009 13:13:01 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);C:\WINDOWS\system32\DRIVERS\adusbser65.sys --> C:\WINDOWS\system32\DRIVERS\adusbser65.sys [?]
S3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\drivers\AVerM115S.sys [14.2.2007 20:23:12 856832]
S3 jusb;jusb;C:\WINDOWS\system32\drivers\jusb.sys [12.5.2010 15:12:02 29184]
S3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\drivers\SynMini.sys [14.2.2007 20:21:41 720470]
S3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\drivers\SynScan.sys [14.2.2007 20:21:40 8278]
S3 UXDCMN;UXDCMN;\??\d:\Winstress\UXDCMN.SYS --> d:\Winstress\UXDCMN.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [6.5.2008 16:06:00 11520]
Obsah adresáře 'Naplánované úlohy'
2011-03-25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34:12 . 2008-07-30 11:34:12]
2011-04-11 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 15:05:30 . 2010-03-28 15:05:26]
2011-04-11 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 15:05:30 . 2010-03-28 15:05:26]
2011-02-15 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 12:21:19 . 2009-08-22 12:21:10]
2011-04-05 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 12:21:19 . 2009-08-22 12:21:10]
------- Doplňkový sken -------
uStart Page = hxxp://www.seznam.cz/
FF - ProfilePath - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icu18lpp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1033.18.1023.737 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_FCI
-------\Legacy_WCSCD
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-12 do 2011-04-12 )))))))))))))))))))))))))))))))
2011-04-06 06:27:12 . 2011-03-15 04:05:43 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\mpengine.dll
2011-04-05 18:17:07 . 2011-04-05 18:19:08 -------- d-----w- C:\32788R22FWJFW.1.tmp
2011-04-03 10:07:16 . 2011-04-03 10:07:16 -------- d--h--w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2011-04-03 10:07:06 . 2010-12-20 16:09:00 38224 ---ha-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-03 10:07:04 . 2011-04-03 10:07:04 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-04-03 10:06:57 . 2011-04-03 10:07:10 -------- d--h--w- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-01 14:55:28 . 2011-04-04 10:02:56 -------- d--h--w- C:\Program Files\trend micro
2011-04-01 14:55:27 . 2011-04-01 14:55:42 -------- d-----w- C:\rsit
2011-04-01 14:42:15 . 2011-04-01 14:42:17 -------- d-----w- C:\Windows Repair
2011-03-25 09:39:29 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
2011-03-25 09:39:20 . 2011-03-18 17:55:52 781272 ---ha-w- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 728024 ---ha-w- C:\Program Files\Mozilla Firefox\libGLESv2.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 1874904 ---ha-w- C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 15832 ---ha-w- C:\Program Files\Mozilla Firefox\mozalloc.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\libEGL.dll
2011-03-25 09:39:18 . 2011-03-25 09:40:27 -------- d--h--w- C:\Program Files\QuickTime
2011-03-25 09:39:18 . 2011-03-18 17:55:52 1893336 ---ha-w- C:\Program Files\Mozilla Firefox\d3dx9_42.dll
2011-03-25 09:39:17 . 2011-03-18 17:55:51 1975768 ---ha-w- C:\Program Files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-23 06:43:12 . 2011-03-23 06:43:12 -------- d--h--w- C:\Documents and Settings\Administrator\Local Settings\Application Data\JABLOCOM
2011-03-23 06:43:02 . 2011-03-23 08:11:15 287229 ---ha-w- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 06:42:57 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\Redemption
2011-03-23 06:42:56 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\NKTWAB
2011-03-23 06:42:46 . 2011-03-23 06:42:58 -------- d--h--w- C:\Program Files\JABLOCOM
2011-03-20 11:38:25 . 2011-03-20 11:38:27 -------- d--h--w- C:\Program Files\Microsoft Silverlight
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-15 04:05:43 . 2010-10-31 14:26:48 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48:32 . 2006-03-15 12:00:00 456192 ---ha-w- C:\WINDOWS\system32\encdec.dll
2011-02-04 16:48:30 . 2006-03-15 12:00:00 291840 ---ha-w- C:\WINDOWS\system32\sbe.dll
2011-01-24 10:20:49 . 2009-08-17 15:42:28 45056 ---ha-w- C:\WINDOWS\system32\acovcnt.exe
2011-01-13 09:41:52 . 2011-01-26 10:25:56 5890896 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-03-18 17:55:52 . 2011-03-25 09:39:29 142296 ---ha-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
------- Sigcheck -------
[7] 2008-06-20 11:59:02 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 10:45:13 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)] . . C:\WINDOWS\system32\dllcache\tcpip.sys
[-] 2008-06-20 10:45:13 . 0B788EE2A876D7B31DF840C13F08CD2B . 360320 . . [5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)] . . C:\WINDOWS\system32\drivers\tcpip.sys
[7] 2008-06-20 10:44:42 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394 (xpsp_sp2_qfe.080620-1259)] . . C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2007-10-30 16:53:32 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244 (xpsp_sp2_qfe.071030-1255)] . . C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2006-04-20 12:18:35 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892 (xpsp.060420-0256)] . . C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2010-01-15 13:33:18 73728 ---ha-w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-10-07 13:55:06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56:34 64512]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-06 11:08:00 7585792]
"nwiz"="nwiz.exe" [2006-09-06 11:08:00 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-06 11:08:00 86016]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 22:22:14 110592]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07:16 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 22:52:52 15797248]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 09:28:20 811008]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [BU]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 02:10:00 1983816]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 01:40:00 767312]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2010-11-30 12:20:36 997408]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 15:45:14 35736]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 20:02:22 932288]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2010-11-29 16:38:18 421888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 12:00:00 15360]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 23:01:00 437160]
"msdrm"="msdrm.exe" [BU]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-10-17 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-08-22 12:21:10 133104 ---hatw- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD]
2006-06-19 15:47:24 528384 ---ha-w- C:\Program Files\ASUSTek\ASUSDVD\ASUSDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38:18 421888 ---ha-w- C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44:46 248552 ---ha-w- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SSI\\Silent Hunter II\\Shell\\SH2.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPSS.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\ICQ7.2\\ICQ.exe"=
"C:\\Program Files\\ICQ7.2\\aolload.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"C:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:msdrm
"45056:TCP"= 45056:TCP:msdrm
"5222:TCP"= 5222:TCP:msdrm
"5225:TCP"= 5225:TCP:msdrm
"2382:TCP"= 2382:TCP:msdrm
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\drivers\ITECIR.sys [14.2.2007 20:22:22 7366]
S1 bmkyuubw;bmkyuubw;\??\C:\WINDOWS\system32\drivers\bmkyuubw.sys --> C:\WINDOWS\system32\drivers\bmkyuubw.sys [?]
S1 MpKsl0b61d6a5;MpKsl0b61d6a5;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys [?]
S1 MpKsl0eb62b3a;MpKsl0eb62b3a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys [?]
S1 MpKsl169119ca;MpKsl169119ca;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys [?]
S1 MpKsl24013e21;MpKsl24013e21;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys [?]
S1 MpKsl309fe936;MpKsl309fe936;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys [?]
S1 MpKsl34dd635a;MpKsl34dd635a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys [?]
S1 MpKsl495ad359;MpKsl495ad359;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys [?]
S1 MpKsl59063335;MpKsl59063335;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys [?]
S1 MpKsl986bef39;MpKsl986bef39;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys [?]
S1 MpKslc58b38dd;MpKslc58b38dd;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys [?]
S1 MpKsleccd34e4;MpKsleccd34e4;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys [?]
S1 MpKslef5db1fc;MpKslef5db1fc;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys [?]
S1 qtysqtwh;qtysqtwh;\??\C:\WINDOWS\system32\drivers\qtysqtwh.sys --> C:\WINDOWS\system32\drivers\qtysqtwh.sys [?]
S1 yuhaiknp;yuhaiknp;\??\C:\WINDOWS\system32\drivers\yuhaiknp.sys --> C:\WINDOWS\system32\drivers\yuhaiknp.sys [?]
S2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\drivers\ethpdrv.sys [29.12.2007 12:07:32 9728]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [28.3.2010 17:05:30 136176]
S2 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [14.2.2007 20:22:22 656384]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);C:\WINDOWS\system32\drivers\adusbmdm65.sys [15.6.2009 13:13:01 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);C:\WINDOWS\system32\DRIVERS\adusbser65.sys --> C:\WINDOWS\system32\DRIVERS\adusbser65.sys [?]
S3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\drivers\AVerM115S.sys [14.2.2007 20:23:12 856832]
S3 jusb;jusb;C:\WINDOWS\system32\drivers\jusb.sys [12.5.2010 15:12:02 29184]
S3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\drivers\SynMini.sys [14.2.2007 20:21:41 720470]
S3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\drivers\SynScan.sys [14.2.2007 20:21:40 8278]
S3 UXDCMN;UXDCMN;\??\d:\Winstress\UXDCMN.SYS --> d:\Winstress\UXDCMN.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [6.5.2008 16:06:00 11520]
Obsah adresáře 'Naplánované úlohy'
2011-03-25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34:12 . 2008-07-30 11:34:12]
2011-04-11 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 15:05:30 . 2010-03-28 15:05:26]
2011-04-11 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-28 15:05:30 . 2010-03-28 15:05:26]
2011-02-15 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 12:21:19 . 2009-08-22 12:21:10]
2011-04-05 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
- C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-22 12:21:19 . 2009-08-22 12:21:10]
------- Doplňkový sken -------
uStart Page = hxxp://www.seznam.cz/
FF - ProfilePath - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icu18lpp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
Re: Prosím o kontrolu logu
Zdravim a pekny den preji
Zaskocim za kolegu kdyz jste online, at se to pohne, havet tam jeste je a nejak se ji nechce pryc
Pokud nemate, tak presunte Combofix na plochu
Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
KillAll:: Registry:: [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "Windows Services"=- "Adobe Reader Speed Launcher"=- "Adobe ARM"=- "QuickTime Task"=- "Regedit32"=- [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "YoopehTnCRAPa"=- [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerDVD] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"=- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "443:TCP"= "45056:TCP"=- "5222:TCP"=- "5225:TCP"=- "2382:TCP"=- File:: C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe C:\WINDOWS\system32\drivers\fjbenamp.sys C:\WINDOWS\system32\drivers\1089.sys C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job C:\Documents and Settings\All Users\Application Data\15720244.exe C:\WINDOWS\system32\drivers\1658.sys C:\WINDOWS\system32\drivers\1128.sys C:\WINDOWS\system32\drivers\12211.sys C:\WINDOWS\system32\drivers\193E.sys C:\WINDOWS\system32\drivers\746C.sys C:\WINDOWS\system32\drivers\854F.sys C:\WINDOWS\system32\drivers\117D.sys C:\WINDOWS\system32\drivers\164B.sys C:\WINDOWS\system32\drivers\515C.sys C:\WINDOWS\system32\drivers\842B.sys C:\WINDOWS\system32\drivers\139A.sys C:\WINDOWS\system32\drivers\122A9.sys C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe C:\Documents and Settings\All Users\Application Data\18407220.exe C:\32788R22FWJFW.1.tmp C:\WINDOWS\system32\drivers\bmkyuubw.sys C:\WINDOWS\system32\drivers\yuhaiknp.sys C:\WINDOWS\system32\drivers\qtysqtwh.sys Restore:: C:\WINDOWS\system32\drivers\tcpip.sys Driver:: cdfss fjbenamp bmkyuubw qtysqtwh yuhaiknp Folder:: C:\Windows Repair Reboot::- Ulozte vytvoreny TXT jako CFScript.txt
- Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)

- Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
Re: Prosím o kontrolu logu
Hotovo.
ComboFix 11-04-14.03 - Administrator 15.04.2011 17:50:03.10.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1033.18.1023.762 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FILE ::
"C:\32788R22FWJFW.1.tmp"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"
"C:\Documents and Settings\All Users\Application Data\15720244.exe"
"C:\Documents and Settings\All Users\Application Data\18407220.exe"
"C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe"
"C:\WINDOWS\system32\drivers\1089.sys"
"C:\WINDOWS\system32\drivers\1128.sys"
"C:\WINDOWS\system32\drivers\117D.sys"
"C:\WINDOWS\system32\drivers\12211.sys"
"C:\WINDOWS\system32\drivers\122A9.sys"
"C:\WINDOWS\system32\drivers\139A.sys"
"C:\WINDOWS\system32\drivers\164B.sys"
"C:\WINDOWS\system32\drivers\1658.sys"
"C:\WINDOWS\system32\drivers\193E.sys"
"C:\WINDOWS\system32\drivers\515C.sys"
"C:\WINDOWS\system32\drivers\746C.sys"
"C:\WINDOWS\system32\drivers\842B.sys"
"C:\WINDOWS\system32\drivers\854F.sys"
"C:\WINDOWS\system32\drivers\bmkyuubw.sys"
"C:\WINDOWS\system32\drivers\fjbenamp.sys"
"C:\WINDOWS\system32\drivers\qtysqtwh.sys"
"C:\WINDOWS\system32\drivers\yuhaiknp.sys"
"C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job"
"C:\WINDOWS\tasks\AppleSoftwareUpdate.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job"
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Windows Repair
C:\Windows Repair\Uninstall Windows Repair.lnk
C:\Windows Repair\Windows Repair.lnk
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
Nakažená kopie C:\WINDOWS\system32\drivers\tcpip.sys byla nalezena a vyléčena.
Obnovena kopie z - C:\WINDOWS\system32\dllcache\tcpip.sys
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_FCI
-------\Legacy_WCSCD
-------\Service_bmkyuubw
-------\Service_qtysqtwh
-------\Service_yuhaiknp
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-15 do 2011-04-15 )))))))))))))))))))))))))))))))
2011-04-15 16:03:55 . 2011-04-15 16:03:55 28752 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\MpKslc39473ad.sys
2011-04-06 06:27:12 . 2011-03-15 04:05:43 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\mpengine.dll
2011-04-05 18:17:07 . 2011-04-05 18:19:08 -------- d-----w- C:\32788R22FWJFW.1.tmp
2011-04-03 10:07:16 . 2011-04-03 10:07:16 -------- d--h--w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2011-04-03 10:07:06 . 2010-12-20 16:09:00 38224 ---ha-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-03 10:07:04 . 2011-04-03 10:07:04 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-04-03 10:06:57 . 2011-04-03 10:07:10 -------- d--h--w- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-01 14:55:28 . 2011-04-04 10:02:56 -------- d--h--w- C:\Program Files\trend micro
2011-04-01 14:55:27 . 2011-04-01 14:55:42 -------- d-----w- C:\rsit
2011-03-25 09:39:29 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
2011-03-25 09:39:20 . 2011-03-18 17:55:52 781272 ---ha-w- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 728024 ---ha-w- C:\Program Files\Mozilla Firefox\libGLESv2.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 1874904 ---ha-w- C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 15832 ---ha-w- C:\Program Files\Mozilla Firefox\mozalloc.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\libEGL.dll
2011-03-25 09:39:18 . 2011-03-25 09:40:27 -------- d--h--w- C:\Program Files\QuickTime
2011-03-25 09:39:18 . 2011-03-18 17:55:52 1893336 ---ha-w- C:\Program Files\Mozilla Firefox\d3dx9_42.dll
2011-03-25 09:39:17 . 2011-03-18 17:55:51 1975768 ---ha-w- C:\Program Files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-23 06:43:12 . 2011-03-23 06:43:12 -------- d--h--w- C:\Documents and Settings\Administrator\Local Settings\Application Data\JABLOCOM
2011-03-23 06:43:02 . 2011-03-23 08:11:15 287229 ---ha-w- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 06:42:57 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\Redemption
2011-03-23 06:42:56 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\NKTWAB
2011-03-23 06:42:46 . 2011-03-23 06:42:58 -------- d--h--w- C:\Program Files\JABLOCOM
2011-03-20 11:38:25 . 2011-03-20 11:38:27 -------- d--h--w- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-15 04:05:43 . 2010-10-31 14:26:48 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48:32 . 2006-03-15 12:00:00 456192 ---ha-w- C:\WINDOWS\system32\encdec.dll
2011-02-04 16:48:30 . 2006-03-15 12:00:00 291840 ---ha-w- C:\WINDOWS\system32\sbe.dll
2011-01-24 10:20:49 . 2009-08-17 15:42:28 45056 ---ha-w- C:\WINDOWS\system32\acovcnt.exe
2011-03-18 17:55:52 . 2011-03-25 09:39:29 142296 ---ha-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2010-01-15 13:33:18 73728 ---ha-w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-10-07 13:55:06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56:34 64512]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-06 11:08:00 7585792]
"nwiz"="nwiz.exe" [2006-09-06 11:08:00 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-06 11:08:00 86016]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 22:22:14 110592]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07:16 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 22:52:52 15797248]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 09:28:20 811008]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [BU]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 02:10:00 1983816]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 01:40:00 767312]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2010-11-30 12:20:36 997408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 12:00:00 15360]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 23:01:00 437160]
"msdrm"="msdrm.exe" [BU]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-10-17 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SSI\\Silent Hunter II\\Shell\\SH2.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPSS.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\ICQ7.2\\ICQ.exe"=
"C:\\Program Files\\ICQ7.2\\aolload.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"C:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:msdrm
R1 MpKslc39473ad;MpKslc39473ad;C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\MpKslc39473ad.sys [15.4.2011 18:03:55 28752]
R2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\drivers\ethpdrv.sys [29.12.2007 12:07:32 9728]
R2 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [14.2.2007 20:22:22 656384]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\drivers\AVerM115S.sys [14.2.2007 20:23:12 856832]
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\drivers\ITECIR.sys [14.2.2007 20:22:22 7366]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\drivers\SynMini.sys [14.2.2007 20:21:41 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\drivers\SynScan.sys [14.2.2007 20:21:40 8278]
S1 MpKsl0b61d6a5;MpKsl0b61d6a5;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys [?]
S1 MpKsl0eb62b3a;MpKsl0eb62b3a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys [?]
S1 MpKsl169119ca;MpKsl169119ca;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys [?]
S1 MpKsl24013e21;MpKsl24013e21;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys [?]
S1 MpKsl309fe936;MpKsl309fe936;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys [?]
S1 MpKsl34dd635a;MpKsl34dd635a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys [?]
S1 MpKsl495ad359;MpKsl495ad359;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys [?]
S1 MpKsl59063335;MpKsl59063335;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys [?]
S1 MpKsl986bef39;MpKsl986bef39;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys [?]
S1 MpKslc58b38dd;MpKslc58b38dd;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys [?]
S1 MpKsleccd34e4;MpKsleccd34e4;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys [?]
S1 MpKslef5db1fc;MpKslef5db1fc;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [28.3.2010 17:05:30 136176]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);C:\WINDOWS\system32\drivers\adusbmdm65.sys [15.6.2009 13:13:01 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);C:\WINDOWS\system32\DRIVERS\adusbser65.sys --> C:\WINDOWS\system32\DRIVERS\adusbser65.sys [?]
S3 jusb;jusb;C:\WINDOWS\system32\drivers\jusb.sys [12.5.2010 15:12:02 29184]
S3 UXDCMN;UXDCMN;\??\d:\Winstress\UXDCMN.SYS --> d:\Winstress\UXDCMN.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [6.5.2008 16:06:00 11520]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - MPKSLC39473AD
------- Doplňkový sken -------
uStart Page = hxxp://www.seznam.cz/
FF - ProfilePath - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icu18lpp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
ComboFix 11-04-14.03 - Administrator 15.04.2011 17:50:03.10.2 - x86 NETWORK
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1033.18.1023.762 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FILE ::
"C:\32788R22FWJFW.1.tmp"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"
"C:\Documents and Settings\All Users\Application Data\15720244.exe"
"C:\Documents and Settings\All Users\Application Data\18407220.exe"
"C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe"
"C:\WINDOWS\system32\drivers\1089.sys"
"C:\WINDOWS\system32\drivers\1128.sys"
"C:\WINDOWS\system32\drivers\117D.sys"
"C:\WINDOWS\system32\drivers\12211.sys"
"C:\WINDOWS\system32\drivers\122A9.sys"
"C:\WINDOWS\system32\drivers\139A.sys"
"C:\WINDOWS\system32\drivers\164B.sys"
"C:\WINDOWS\system32\drivers\1658.sys"
"C:\WINDOWS\system32\drivers\193E.sys"
"C:\WINDOWS\system32\drivers\515C.sys"
"C:\WINDOWS\system32\drivers\746C.sys"
"C:\WINDOWS\system32\drivers\842B.sys"
"C:\WINDOWS\system32\drivers\854F.sys"
"C:\WINDOWS\system32\drivers\bmkyuubw.sys"
"C:\WINDOWS\system32\drivers\fjbenamp.sys"
"C:\WINDOWS\system32\drivers\qtysqtwh.sys"
"C:\WINDOWS\system32\drivers\yuhaiknp.sys"
"C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job"
"C:\WINDOWS\tasks\AppleSoftwareUpdate.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job"
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Windows Repair
C:\Windows Repair\Uninstall Windows Repair.lnk
C:\Windows Repair\Windows Repair.lnk
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
Nakažená kopie C:\WINDOWS\system32\drivers\tcpip.sys byla nalezena a vyléčena.
Obnovena kopie z - C:\WINDOWS\system32\dllcache\tcpip.sys
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_FCI
-------\Legacy_WCSCD
-------\Service_bmkyuubw
-------\Service_qtysqtwh
-------\Service_yuhaiknp
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-15 do 2011-04-15 )))))))))))))))))))))))))))))))
2011-04-15 16:03:55 . 2011-04-15 16:03:55 28752 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\MpKslc39473ad.sys
2011-04-06 06:27:12 . 2011-03-15 04:05:43 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\mpengine.dll
2011-04-05 18:17:07 . 2011-04-05 18:19:08 -------- d-----w- C:\32788R22FWJFW.1.tmp
2011-04-03 10:07:16 . 2011-04-03 10:07:16 -------- d--h--w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2011-04-03 10:07:06 . 2010-12-20 16:09:00 38224 ---ha-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-03 10:07:04 . 2011-04-03 10:07:04 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-04-03 10:06:57 . 2011-04-03 10:07:10 -------- d--h--w- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-01 14:55:28 . 2011-04-04 10:02:56 -------- d--h--w- C:\Program Files\trend micro
2011-04-01 14:55:27 . 2011-04-01 14:55:42 -------- d-----w- C:\rsit
2011-03-25 09:39:29 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
2011-03-25 09:39:20 . 2011-03-18 17:55:52 781272 ---ha-w- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 728024 ---ha-w- C:\Program Files\Mozilla Firefox\libGLESv2.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 1874904 ---ha-w- C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 15832 ---ha-w- C:\Program Files\Mozilla Firefox\mozalloc.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\libEGL.dll
2011-03-25 09:39:18 . 2011-03-25 09:40:27 -------- d--h--w- C:\Program Files\QuickTime
2011-03-25 09:39:18 . 2011-03-18 17:55:52 1893336 ---ha-w- C:\Program Files\Mozilla Firefox\d3dx9_42.dll
2011-03-25 09:39:17 . 2011-03-18 17:55:51 1975768 ---ha-w- C:\Program Files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-23 06:43:12 . 2011-03-23 06:43:12 -------- d--h--w- C:\Documents and Settings\Administrator\Local Settings\Application Data\JABLOCOM
2011-03-23 06:43:02 . 2011-03-23 08:11:15 287229 ---ha-w- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 06:42:57 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\Redemption
2011-03-23 06:42:56 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\NKTWAB
2011-03-23 06:42:46 . 2011-03-23 06:42:58 -------- d--h--w- C:\Program Files\JABLOCOM
2011-03-20 11:38:25 . 2011-03-20 11:38:27 -------- d--h--w- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-15 04:05:43 . 2010-10-31 14:26:48 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48:32 . 2006-03-15 12:00:00 456192 ---ha-w- C:\WINDOWS\system32\encdec.dll
2011-02-04 16:48:30 . 2006-03-15 12:00:00 291840 ---ha-w- C:\WINDOWS\system32\sbe.dll
2011-01-24 10:20:49 . 2009-08-17 15:42:28 45056 ---ha-w- C:\WINDOWS\system32\acovcnt.exe
2011-03-18 17:55:52 . 2011-03-25 09:39:29 142296 ---ha-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2010-01-15 13:33:18 73728 ---ha-w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-10-07 13:55:06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56:34 64512]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-06 11:08:00 7585792]
"nwiz"="nwiz.exe" [2006-09-06 11:08:00 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-06 11:08:00 86016]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 22:22:14 110592]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07:16 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 22:52:52 15797248]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 09:28:20 811008]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [BU]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 02:10:00 1983816]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 01:40:00 767312]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2010-11-30 12:20:36 997408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 12:00:00 15360]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 23:01:00 437160]
"msdrm"="msdrm.exe" [BU]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-10-17 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SSI\\Silent Hunter II\\Shell\\SH2.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPSS.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\ICQ7.2\\ICQ.exe"=
"C:\\Program Files\\ICQ7.2\\aolload.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"C:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:msdrm
R1 MpKslc39473ad;MpKslc39473ad;C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8028591-21D0-4495-80E1-879A397A4E00}\MpKslc39473ad.sys [15.4.2011 18:03:55 28752]
R2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\drivers\ethpdrv.sys [29.12.2007 12:07:32 9728]
R2 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [14.2.2007 20:22:22 656384]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\drivers\AVerM115S.sys [14.2.2007 20:23:12 856832]
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\drivers\ITECIR.sys [14.2.2007 20:22:22 7366]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\drivers\SynMini.sys [14.2.2007 20:21:41 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\drivers\SynScan.sys [14.2.2007 20:21:40 8278]
S1 MpKsl0b61d6a5;MpKsl0b61d6a5;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys [?]
S1 MpKsl0eb62b3a;MpKsl0eb62b3a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys [?]
S1 MpKsl169119ca;MpKsl169119ca;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys [?]
S1 MpKsl24013e21;MpKsl24013e21;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys [?]
S1 MpKsl309fe936;MpKsl309fe936;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys [?]
S1 MpKsl34dd635a;MpKsl34dd635a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys [?]
S1 MpKsl495ad359;MpKsl495ad359;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys [?]
S1 MpKsl59063335;MpKsl59063335;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys [?]
S1 MpKsl986bef39;MpKsl986bef39;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys [?]
S1 MpKslc58b38dd;MpKslc58b38dd;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys [?]
S1 MpKsleccd34e4;MpKsleccd34e4;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys [?]
S1 MpKslef5db1fc;MpKslef5db1fc;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [28.3.2010 17:05:30 136176]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);C:\WINDOWS\system32\drivers\adusbmdm65.sys [15.6.2009 13:13:01 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);C:\WINDOWS\system32\DRIVERS\adusbser65.sys --> C:\WINDOWS\system32\DRIVERS\adusbser65.sys [?]
S3 jusb;jusb;C:\WINDOWS\system32\drivers\jusb.sys [12.5.2010 15:12:02 29184]
S3 UXDCMN;UXDCMN;\??\d:\Winstress\UXDCMN.SYS --> d:\Winstress\UXDCMN.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [6.5.2008 16:06:00 11520]
--- Ostatní služby/ovladače v paměti ---
*NewlyCreated* - MPKSLC39473AD
------- Doplňkový sken -------
uStart Page = hxxp://www.seznam.cz/
FF - ProfilePath - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icu18lpp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Chybí mi konec logu ComboFixu - můžeš to doplnit?
měl by být zde: C:/Combofix.txt
měl by být zde: C:/Combofix.txt
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Prosím o kontrolu logu
Celou proceduru jsem zopakoval, tady je celý nový log:
CF se řek bych chová lehce nestandartně..krátce po spuštění se zastaví a vyběhne okno typu "program PEV.cfxxe způsobil problém".. a až po odkliknutí "neodesílat" se CF znova rozjede a pokračuje tam kde skončilo. Dále pak při tvorbě logu log nikdy po ukončení CF nevyskočí, ale je nutno ho vždy hledat v C:\atd..
ComboFix 11-04-16.02 - Administrator 17.04.2011 12:11:32.11.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1033.18.1023.578 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FILE ::
"C:\32788R22FWJFW.1.tmp"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"
"C:\Documents and Settings\All Users\Application Data\15720244.exe"
"C:\Documents and Settings\All Users\Application Data\18407220.exe"
"C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe"
"C:\WINDOWS\system32\drivers\1089.sys"
"C:\WINDOWS\system32\drivers\1128.sys"
"C:\WINDOWS\system32\drivers\117D.sys"
"C:\WINDOWS\system32\drivers\12211.sys"
"C:\WINDOWS\system32\drivers\122A9.sys"
"C:\WINDOWS\system32\drivers\139A.sys"
"C:\WINDOWS\system32\drivers\164B.sys"
"C:\WINDOWS\system32\drivers\1658.sys"
"C:\WINDOWS\system32\drivers\193E.sys"
"C:\WINDOWS\system32\drivers\515C.sys"
"C:\WINDOWS\system32\drivers\746C.sys"
"C:\WINDOWS\system32\drivers\842B.sys"
"C:\WINDOWS\system32\drivers\854F.sys"
"C:\WINDOWS\system32\drivers\bmkyuubw.sys"
"C:\WINDOWS\system32\drivers\fjbenamp.sys"
"C:\WINDOWS\system32\drivers\qtysqtwh.sys"
"C:\WINDOWS\system32\drivers\yuhaiknp.sys"
"C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job"
"C:\WINDOWS\tasks\AppleSoftwareUpdate.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job"
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
---- Předchozí spuštění -------
C:\Windows Repair\Uninstall Windows Repair.lnk
C:\Windows Repair\Windows Repair.lnk
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
Nakažená kopie C:\WINDOWS\system32\drivers\tcpip.sys byla nalezena a vyléčena.
Obnovena kopie z - C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_FCI
-------\Legacy_WCSCD
-------\Service_bmkyuubw
-------\Service_qtysqtwh
-------\Service_yuhaiknp
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-17 do 2011-04-17 )))))))))))))))))))))))))))))))
2011-04-17 10:02:22 . 2011-04-17 10:02:22 28752 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BAA06EBB-766F-4C8E-8CA5-ECEF73F439BD}\MpKsl66fc49ef.sys
2011-04-15 16:15:13 . 2011-03-15 04:05:43 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BAA06EBB-766F-4C8E-8CA5-ECEF73F439BD}\mpengine.dll
2011-04-05 18:17:07 . 2011-04-05 18:19:08 -------- d-----w- C:\32788R22FWJFW.1.tmp
2011-04-03 10:07:16 . 2011-04-03 10:07:16 -------- d--h--w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2011-04-03 10:07:06 . 2010-12-20 16:09:00 38224 ---ha-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-03 10:07:04 . 2011-04-03 10:07:04 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-04-03 10:06:57 . 2011-04-03 10:07:10 -------- d--h--w- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-01 14:55:28 . 2011-04-04 10:02:56 -------- d--h--w- C:\Program Files\trend micro
2011-04-01 14:55:27 . 2011-04-01 14:55:42 -------- d-----w- C:\rsit
2011-03-25 09:39:29 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
2011-03-25 09:39:20 . 2011-03-18 17:55:52 781272 ---ha-w- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 728024 ---ha-w- C:\Program Files\Mozilla Firefox\libGLESv2.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 1874904 ---ha-w- C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 15832 ---ha-w- C:\Program Files\Mozilla Firefox\mozalloc.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\libEGL.dll
2011-03-25 09:39:18 . 2011-03-25 09:40:27 -------- d--h--w- C:\Program Files\QuickTime
2011-03-25 09:39:18 . 2011-03-18 17:55:52 1893336 ---ha-w- C:\Program Files\Mozilla Firefox\d3dx9_42.dll
2011-03-25 09:39:17 . 2011-03-18 17:55:51 1975768 ---ha-w- C:\Program Files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-23 06:43:12 . 2011-03-23 06:43:12 -------- d--h--w- C:\Documents and Settings\Administrator\Local Settings\Application Data\JABLOCOM
2011-03-23 06:43:02 . 2011-03-23 08:11:15 287229 ---ha-w- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 06:42:57 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\Redemption
2011-03-23 06:42:56 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\NKTWAB
2011-03-23 06:42:46 . 2011-03-23 06:42:58 -------- d--h--w- C:\Program Files\JABLOCOM
2011-03-20 11:38:25 . 2011-03-20 11:38:27 -------- d--h--w- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-15 04:05:43 . 2010-10-31 14:26:48 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48:32 . 2006-03-15 12:00:00 456192 ---ha-w- C:\WINDOWS\system32\encdec.dll
2011-02-04 16:48:30 . 2006-03-15 12:00:00 291840 ---ha-w- C:\WINDOWS\system32\sbe.dll
2011-01-24 10:20:49 . 2009-08-17 15:42:28 45056 ---ha-w- C:\WINDOWS\system32\acovcnt.exe
2011-03-18 17:55:52 . 2011-03-25 09:39:29 142296 ---ha-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2010-01-15 13:33:18 73728 ---ha-w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-10-07 13:55:06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56:34 64512]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-06 11:08:00 7585792]
"nwiz"="nwiz.exe" [2006-09-06 11:08:00 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-06 11:08:00 86016]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 22:22:14 110592]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07:16 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 22:52:52 15797248]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 09:28:20 811008]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [BU]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 02:10:00 1983816]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 01:40:00 767312]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2010-11-30 12:20:36 997408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 12:00:00 15360]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 23:01:00 437160]
"msdrm"="msdrm.exe" [BU]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-10-17 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SSI\\Silent Hunter II\\Shell\\SH2.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPSS.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\ICQ7.2\\ICQ.exe"=
"C:\\Program Files\\ICQ7.2\\aolload.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"C:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:msdrm
R1 MpKsl66fc49ef;MpKsl66fc49ef;C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BAA06EBB-766F-4C8E-8CA5-ECEF73F439BD}\MpKsl66fc49ef.sys [17.4.2011 12:02:22 28752]
R2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\drivers\ethpdrv.sys [29.12.2007 12:07:32 9728]
R2 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [14.2.2007 20:22:22 656384]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\drivers\AVerM115S.sys [14.2.2007 20:23:12 856832]
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\drivers\ITECIR.sys [14.2.2007 20:22:22 7366]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\drivers\SynMini.sys [14.2.2007 20:21:41 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\drivers\SynScan.sys [14.2.2007 20:21:40 8278]
S1 MpKsl0b61d6a5;MpKsl0b61d6a5;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys [?]
S1 MpKsl0eb62b3a;MpKsl0eb62b3a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys [?]
S1 MpKsl169119ca;MpKsl169119ca;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys [?]
S1 MpKsl24013e21;MpKsl24013e21;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys [?]
S1 MpKsl309fe936;MpKsl309fe936;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys [?]
S1 MpKsl34dd635a;MpKsl34dd635a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys [?]
S1 MpKsl495ad359;MpKsl495ad359;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys [?]
S1 MpKsl59063335;MpKsl59063335;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys [?]
S1 MpKsl986bef39;MpKsl986bef39;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys [?]
S1 MpKslc58b38dd;MpKslc58b38dd;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys [?]
S1 MpKsleccd34e4;MpKsleccd34e4;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys [?]
S1 MpKslef5db1fc;MpKslef5db1fc;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [28.3.2010 17:05:30 136176]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);C:\WINDOWS\system32\drivers\adusbmdm65.sys [15.6.2009 13:13:01 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);C:\WINDOWS\system32\DRIVERS\adusbser65.sys --> C:\WINDOWS\system32\DRIVERS\adusbser65.sys [?]
S3 jusb;jusb;C:\WINDOWS\system32\drivers\jusb.sys [12.5.2010 15:12:02 29184]
S3 UXDCMN;UXDCMN;\??\d:\Winstress\UXDCMN.SYS --> d:\Winstress\UXDCMN.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [6.5.2008 16:06:00 11520]
------- Doplňkový sken -------
uStart Page = hxxp://www.seznam.cz/
FF - ProfilePath - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icu18lpp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
CF se řek bych chová lehce nestandartně..krátce po spuštění se zastaví a vyběhne okno typu "program PEV.cfxxe způsobil problém".. a až po odkliknutí "neodesílat" se CF znova rozjede a pokračuje tam kde skončilo. Dále pak při tvorbě logu log nikdy po ukončení CF nevyskočí, ale je nutno ho vždy hledat v C:\atd..
ComboFix 11-04-16.02 - Administrator 17.04.2011 12:11:32.11.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1033.18.1023.578 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Použité ovládací přepínače :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FILE ::
"C:\32788R22FWJFW.1.tmp"
"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\e.exe"
"C:\Documents and Settings\All Users\Application Data\15720244.exe"
"C:\Documents and Settings\All Users\Application Data\18407220.exe"
"C:\Documents and Settings\All Users\Application Data\YoopehTnCRAPa.exe"
"C:\WINDOWS\system32\drivers\1089.sys"
"C:\WINDOWS\system32\drivers\1128.sys"
"C:\WINDOWS\system32\drivers\117D.sys"
"C:\WINDOWS\system32\drivers\12211.sys"
"C:\WINDOWS\system32\drivers\122A9.sys"
"C:\WINDOWS\system32\drivers\139A.sys"
"C:\WINDOWS\system32\drivers\164B.sys"
"C:\WINDOWS\system32\drivers\1658.sys"
"C:\WINDOWS\system32\drivers\193E.sys"
"C:\WINDOWS\system32\drivers\515C.sys"
"C:\WINDOWS\system32\drivers\746C.sys"
"C:\WINDOWS\system32\drivers\842B.sys"
"C:\WINDOWS\system32\drivers\854F.sys"
"C:\WINDOWS\system32\drivers\bmkyuubw.sys"
"C:\WINDOWS\system32\drivers\fjbenamp.sys"
"C:\WINDOWS\system32\drivers\qtysqtwh.sys"
"C:\WINDOWS\system32\drivers\yuhaiknp.sys"
"C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job"
"C:\WINDOWS\tasks\AppleSoftwareUpdate.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job"
"C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job"
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
---- Předchozí spuštění -------
C:\Windows Repair\Uninstall Windows Repair.lnk
C:\Windows Repair\Windows Repair.lnk
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-725345543-1450960922-1801674531-500UA.job
Nakažená kopie C:\WINDOWS\system32\drivers\tcpip.sys byla nalezena a vyléčena.
Obnovena kopie z - C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CDFSS
-------\Legacy_FCI
-------\Legacy_WCSCD
-------\Service_bmkyuubw
-------\Service_qtysqtwh
-------\Service_yuhaiknp
((((((((((((((((((((((((( Soubory vytvořené od 2011-03-17 do 2011-04-17 )))))))))))))))))))))))))))))))
2011-04-17 10:02:22 . 2011-04-17 10:02:22 28752 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BAA06EBB-766F-4C8E-8CA5-ECEF73F439BD}\MpKsl66fc49ef.sys
2011-04-15 16:15:13 . 2011-03-15 04:05:43 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BAA06EBB-766F-4C8E-8CA5-ECEF73F439BD}\mpengine.dll
2011-04-05 18:17:07 . 2011-04-05 18:19:08 -------- d-----w- C:\32788R22FWJFW.1.tmp
2011-04-03 10:07:16 . 2011-04-03 10:07:16 -------- d--h--w- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2011-04-03 10:07:06 . 2010-12-20 16:09:00 38224 ---ha-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-04-03 10:07:04 . 2011-04-03 10:07:04 -------- d--h--w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2011-04-03 10:06:57 . 2011-04-03 10:07:10 -------- d--h--w- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-01 14:55:28 . 2011-04-04 10:02:56 -------- d--h--w- C:\Program Files\trend micro
2011-04-01 14:55:27 . 2011-04-01 14:55:42 -------- d-----w- C:\rsit
2011-03-25 09:39:29 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
2011-03-25 09:39:20 . 2011-03-18 17:55:52 781272 ---ha-w- C:\Program Files\Mozilla Firefox\mozsqlite3.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 728024 ---ha-w- C:\Program Files\Mozilla Firefox\libGLESv2.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 1874904 ---ha-w- C:\Program Files\Mozilla Firefox\mozjs.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 15832 ---ha-w- C:\Program Files\Mozilla Firefox\mozalloc.dll
2011-03-25 09:39:19 . 2011-03-18 17:55:52 142296 ---ha-w- C:\Program Files\Mozilla Firefox\libEGL.dll
2011-03-25 09:39:18 . 2011-03-25 09:40:27 -------- d--h--w- C:\Program Files\QuickTime
2011-03-25 09:39:18 . 2011-03-18 17:55:52 1893336 ---ha-w- C:\Program Files\Mozilla Firefox\d3dx9_42.dll
2011-03-25 09:39:17 . 2011-03-18 17:55:51 1975768 ---ha-w- C:\Program Files\Mozilla Firefox\D3DCompiler_42.dll
2011-03-23 06:43:12 . 2011-03-23 06:43:12 -------- d--h--w- C:\Documents and Settings\Administrator\Local Settings\Application Data\JABLOCOM
2011-03-23 06:43:02 . 2011-03-23 08:11:15 287229 ---ha-w- C:\WINDOWS\JabloTool Uninstaller.exe
2011-03-23 06:42:57 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\Redemption
2011-03-23 06:42:56 . 2011-03-23 08:11:04 -------- d--h--w- C:\Program Files\Common Files\NKTWAB
2011-03-23 06:42:46 . 2011-03-23 06:42:58 -------- d--h--w- C:\Program Files\JABLOCOM
2011-03-20 11:38:25 . 2011-03-20 11:38:27 -------- d--h--w- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-03-15 04:05:43 . 2010-10-31 14:26:48 6792528 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-04 16:48:32 . 2006-03-15 12:00:00 456192 ---ha-w- C:\WINDOWS\system32\encdec.dll
2011-02-04 16:48:30 . 2006-03-15 12:00:00 291840 ---ha-w- C:\WINDOWS\system32\sbe.dll
2011-01-24 10:20:49 . 2009-08-17 15:42:28 45056 ---ha-w- C:\WINDOWS\system32\acovcnt.exe
2011-03-18 17:55:52 . 2011-03-25 09:39:29 142296 ---ha-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@="{E4000AC4-5E5F-4956-807A-C5854405D64F}"
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2010-01-15 13:33:18 73728 ---ha-w- C:\WINDOWS\system32\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-10-07 13:55:06 488728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56:34 64512]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-06 11:08:00 7585792]
"nwiz"="nwiz.exe" [2006-09-06 11:08:00 1617920]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-06 11:08:00 86016]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-23 22:22:14 110592]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 16:07:16 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 22:52:52 15797248]
"ACMON"="C:\Program Files\ASUS\Splendid\ACMON.exe" [2006-05-30 09:28:20 811008]
"Wireless Console 2"="C:\Program Files\Wireless Console 2\wcourier.exe" [2005-10-17 16:09:34 987136]
"SMail"="C:\Program Files\Seznam\Postak\Postak.exe" [BU]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 02:10:00 1983816]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 01:40:00 767312]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe" [2010-11-30 12:20:36 997408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 12:00:00 15360]
"DWQueuedReporting"="c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 23:01:00 437160]
"msdrm"="msdrm.exe" [BU]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe [2007-10-17 474808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SSI\\Silent Hunter II\\Shell\\SH2.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPSS.exe"=
"C:\\Program Files\\Toshiba\\Bluetooth Toshiba Stack\\TosBtPCS.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"C:\\Program Files\\ICQ7.2\\ICQ.exe"=
"C:\\Program Files\\ICQ7.2\\aolload.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"C:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:msdrm
R1 MpKsl66fc49ef;MpKsl66fc49ef;C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BAA06EBB-766F-4C8E-8CA5-ECEF73F439BD}\MpKsl66fc49ef.sys [17.4.2011 12:02:22 28752]
R2 Ethpdrv;Ethernet Packet Driver;C:\WINDOWS\system32\drivers\ethpdrv.sys [29.12.2007 12:07:32 9728]
R2 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [14.2.2007 20:22:22 656384]
R3 AVerM115S;AVerM115S service;C:\WINDOWS\system32\drivers\AVerM115S.sys [14.2.2007 20:23:12 856832]
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\drivers\ITECIR.sys [14.2.2007 20:22:22 7366]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\drivers\SynMini.sys [14.2.2007 20:21:41 720470]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\drivers\SynScan.sys [14.2.2007 20:21:40 8278]
S1 MpKsl0b61d6a5;MpKsl0b61d6a5;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0b61d6a5.sys [?]
S1 MpKsl0eb62b3a;MpKsl0eb62b3a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2C62ED3B-1C68-44D3-A419-58FCFEDF1DC1}\MpKsl0eb62b3a.sys [?]
S1 MpKsl169119ca;MpKsl169119ca;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E2A2218-9D76-45D0-80F7-BF5C0E9EB8E0}\MpKsl169119ca.sys [?]
S1 MpKsl24013e21;MpKsl24013e21;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4EE6970C-C939-4B02-AF52-C24D16FEC7A5}\MpKsl24013e21.sys [?]
S1 MpKsl309fe936;MpKsl309fe936;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8C46F775-5510-4BBD-89B3-C66099FFBF63}\MpKsl309fe936.sys [?]
S1 MpKsl34dd635a;MpKsl34dd635a;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKsl34dd635a.sys [?]
S1 MpKsl495ad359;MpKsl495ad359;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{932C7E11-85E2-48DB-84AE-DCB3F13AE58D}\MpKsl495ad359.sys [?]
S1 MpKsl59063335;MpKsl59063335;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{472C4D8A-847A-455E-A4E0-ACAD05443EF0}\MpKsl59063335.sys [?]
S1 MpKsl986bef39;MpKsl986bef39;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F2A8E433-228A-4B01-A1D6-2351EDD63540}\MpKsl986bef39.sys [?]
S1 MpKslc58b38dd;MpKslc58b38dd;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E015FB85-7D76-4222-9B1F-3276C08A784F}\MpKslc58b38dd.sys [?]
S1 MpKsleccd34e4;MpKsleccd34e4;\??\c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys --> c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4BA1C05F-2D11-41A4-9C6D-68C8A64ECBEF}\MpKsleccd34e4.sys [?]
S1 MpKslef5db1fc;MpKslef5db1fc;\??\C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys --> C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C8B51A59-C31F-483D-84D8-3F2F8EC35070}\MpKslef5db1fc.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [28.3.2010 17:05:30 136176]
S3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501);C:\WINDOWS\system32\drivers\adusbmdm65.sys [15.6.2009 13:13:01 64896]
S3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501);C:\WINDOWS\system32\DRIVERS\adusbser65.sys --> C:\WINDOWS\system32\DRIVERS\adusbser65.sys [?]
S3 jusb;jusb;C:\WINDOWS\system32\drivers\jusb.sys [12.5.2010 15:12:02 29184]
S3 UXDCMN;UXDCMN;\??\d:\Winstress\UXDCMN.SYS --> d:\Winstress\UXDCMN.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [6.5.2008 16:06:00 11520]
------- Doplňkový sken -------
uStart Page = hxxp://www.seznam.cz/
FF - ProfilePath - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\icu18lpp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: network.proxy.type - 4
- cernohous13
- VIP in memoriam

- Příspěvky: 8720
- Registrován: 09 Pro 2006 06:19
- Místo/Bydliště: Jablonec nad Nisou
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu
Doporučení:
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím
-------------------------------------------------------------------------------------------------
> Podpora fóra <
V průběhu léčení prováděj nové instalace a odinstalace jen na můj pokyn.
Důkladně prostuduj a proveď celou operaci podle mé odpovědi.
V případě nejasností se zeptej - vysvětlím

-------------------------------------------------------------------------------------------------
> Podpora fóra <
Re: Prosím o kontrolu logu
Hotovo. Log z AVPTool:
Automatická kontrola: dokončeno před 11 min. (události: 53, objekty: 370338, čas: 01:54:34)
17.4.2011 19:37:53 Úloha byla dokončena
17.4.2011 19:23:34 Dezinfikováno: Virus.Win32.TDSS.e C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0254317.sys
17.4.2011 19:23:34 Dezinfikováno: Virus.Win32.TDSS.e C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0254317.sys
17.4.2011 19:23:33 Zjištěno: Virus.Win32.TDSS.e C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0254317.sys
17.4.2011 19:23:20 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252099.sys
17.4.2011 19:23:20 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252098.sys
17.4.2011 19:23:20 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252097.sys
17.4.2011 19:23:19 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252096.sys
17.4.2011 19:23:19 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252095.sys
17.4.2011 19:23:19 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252094.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252093.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252092.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252091.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252090.sys
17.4.2011 19:23:17 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252089.sys
17.4.2011 19:23:17 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252088.sys
17.4.2011 19:23:17 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252087.sys
17.4.2011 19:23:16 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252085.sys
17.4.2011 19:23:16 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252084.sys
17.4.2011 19:23:16 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252086.sys
17.4.2011 19:23:13 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251949.exe
17.4.2011 19:23:13 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251896.exe
17.4.2011 19:23:12 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251948.exe
17.4.2011 19:23:12 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251949.exe
17.4.2011 19:23:11 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251895.exe
17.4.2011 19:23:02 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251948.exe
17.4.2011 19:22:58 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251896.exe
17.4.2011 19:22:58 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251895.exe
17.4.2011 19:21:36 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP613\A0250645.exe
17.4.2011 19:21:35 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP613\A0250645.exe/PE-Crypt.XorPE
17.4.2011 19:21:35 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250635.exe
17.4.2011 19:21:34 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250636.exe
17.4.2011 19:21:33 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250635.exe/PE-Crypt.XorPE
17.4.2011 19:21:33 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250636.exe/PE-Crypt.XorPE
17.4.2011 19:21:33 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250617.exe
17.4.2011 19:21:33 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250616.exe
17.4.2011 19:21:32 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250617.exe/PE-Crypt.XorPE
17.4.2011 19:21:32 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250591.exe
17.4.2011 19:21:32 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250616.exe/PE-Crypt.XorPE
17.4.2011 19:21:32 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250572.exe
17.4.2011 19:21:31 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250590.exe
17.4.2011 19:21:31 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250591.exe/PE-Crypt.XorPE
17.4.2011 19:21:31 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250571.exe
17.4.2011 19:21:31 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250590.exe/PE-Crypt.XorPE
17.4.2011 19:21:30 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP611\A0250556.exe
17.4.2011 19:21:30 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250572.exe/PE-Crypt.XorPE
17.4.2011 19:21:30 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP610\A0250490.exe
17.4.2011 19:21:05 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250571.exe/PE-Crypt.XorPE
17.4.2011 19:20:58 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP611\A0250556.exe/PE-Crypt.XorPE
17.4.2011 19:20:52 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP610\A0250490.exe/PE-Crypt.XorPE
17.4.2011 17:52:14 Odstraněno: Exploit.Java.CVE-2010-0840.i C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\39\699f0fe7-175e558b/sapr2/fray3.class
17.4.2011 17:52:13 Zjištěno: Exploit.Java.CVE-2010-0840.i C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\39\699f0fe7-175e558b/sapr2/fray3.class
17.4.2011 17:43:19 Úloha byla spuštěna
Automatická kontrola: dokončeno před 11 min. (události: 53, objekty: 370338, čas: 01:54:34)
17.4.2011 19:37:53 Úloha byla dokončena
17.4.2011 19:23:34 Dezinfikováno: Virus.Win32.TDSS.e C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0254317.sys
17.4.2011 19:23:34 Dezinfikováno: Virus.Win32.TDSS.e C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0254317.sys
17.4.2011 19:23:33 Zjištěno: Virus.Win32.TDSS.e C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0254317.sys
17.4.2011 19:23:20 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252099.sys
17.4.2011 19:23:20 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252098.sys
17.4.2011 19:23:20 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252097.sys
17.4.2011 19:23:19 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252096.sys
17.4.2011 19:23:19 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252095.sys
17.4.2011 19:23:19 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252094.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252093.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252092.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252091.sys
17.4.2011 19:23:18 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252090.sys
17.4.2011 19:23:17 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252089.sys
17.4.2011 19:23:17 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252088.sys
17.4.2011 19:23:17 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252087.sys
17.4.2011 19:23:16 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252085.sys
17.4.2011 19:23:16 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252084.sys
17.4.2011 19:23:16 Zjištěno: HEUR:Trojan.Win32.Generic C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0252086.sys
17.4.2011 19:23:13 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251949.exe
17.4.2011 19:23:13 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251896.exe
17.4.2011 19:23:12 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251948.exe
17.4.2011 19:23:12 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251949.exe
17.4.2011 19:23:11 Odstraněno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251895.exe
17.4.2011 19:23:02 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP623\A0251948.exe
17.4.2011 19:22:58 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251896.exe
17.4.2011 19:22:58 Zjištěno: Trojan.Win32.Wigon.u C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP622\A0251895.exe
17.4.2011 19:21:36 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP613\A0250645.exe
17.4.2011 19:21:35 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP613\A0250645.exe/PE-Crypt.XorPE
17.4.2011 19:21:35 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250635.exe
17.4.2011 19:21:34 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250636.exe
17.4.2011 19:21:33 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250635.exe/PE-Crypt.XorPE
17.4.2011 19:21:33 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250636.exe/PE-Crypt.XorPE
17.4.2011 19:21:33 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250617.exe
17.4.2011 19:21:33 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250616.exe
17.4.2011 19:21:32 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250617.exe/PE-Crypt.XorPE
17.4.2011 19:21:32 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250591.exe
17.4.2011 19:21:32 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250616.exe/PE-Crypt.XorPE
17.4.2011 19:21:32 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250572.exe
17.4.2011 19:21:31 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250590.exe
17.4.2011 19:21:31 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250591.exe/PE-Crypt.XorPE
17.4.2011 19:21:31 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250571.exe
17.4.2011 19:21:31 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250590.exe/PE-Crypt.XorPE
17.4.2011 19:21:30 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP611\A0250556.exe
17.4.2011 19:21:30 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250572.exe/PE-Crypt.XorPE
17.4.2011 19:21:30 Odstraněno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP610\A0250490.exe
17.4.2011 19:21:05 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP612\A0250571.exe/PE-Crypt.XorPE
17.4.2011 19:20:58 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP611\A0250556.exe/PE-Crypt.XorPE
17.4.2011 19:20:52 Zjištěno: Trojan.Win32.Buzus.gyvx C:\System Volume Information\_restore{72191393-574B-421E-BDA2-990653F9BF42}\RP610\A0250490.exe/PE-Crypt.XorPE
17.4.2011 17:52:14 Odstraněno: Exploit.Java.CVE-2010-0840.i C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\39\699f0fe7-175e558b/sapr2/fray3.class
17.4.2011 17:52:13 Zjištěno: Exploit.Java.CVE-2010-0840.i C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\39\699f0fe7-175e558b/sapr2/fray3.class
17.4.2011 17:43:19 Úloha byla spuštěna



Přispějete na provoz fóra?