Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

neviem co s tym,prosim pomozte

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#31 Příspěvek od ringov »

dobry den avast sa neda nejako odinstalovat?Ked to skusam tak to zamietne.Dakujem :) :( Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-12 11:28:23
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (30%) free of 8 GB
Total RAM: 511 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:29, on 12.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe
E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
E:\avast\AVASTA~1\Setup\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [avast!] E:\avast\AVASTA~1\Setup\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 4686 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avast!"=E:\avast\AVASTA~1\Setup\ashDisp.exe [2009-11-25 81000]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieframe.dll]
regsvr32.exe /s C:\WINDOWS\System32\ieframe.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shell32.dll]
regsvr32.exe /s C:\WINDOWS\system32\shell32.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk]
E:\kasper\VIRUSR~1\SETUP_~1.20~\startup.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-12 09:55:17 ----A---- C:\WINDOWS\system32\drivers\9574816.sys
2011-04-12 09:45:20 ----D---- C:\32788R22FWJFW
2011-04-12 09:44:57 ----D---- C:\Program Files\Windows Media Connect 2
2011-04-12 09:44:57 ----D---- C:\Program Files\Secunia
2011-04-12 09:44:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-12 09:44:57 ----D---- C:\Program Files\ESET
2011-04-12 09:44:57 ----D---- C:\Program Files\Alwil Software
2011-04-12 09:44:57 ----D---- C:\Program Files\7-Zip
2011-04-12 09:41:55 ----A---- C:\WINDOWS\ntbtlog.txt
2011-04-12 09:37:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-12 09:24:28 ----D---- C:\32788R22FWJFW(3)
2011-04-12 08:47:09 ----D---- C:\WINDOWS\CSC
2011-04-12 08:45:34 ----D---- C:\32788R22FWJFW(2)
2011-04-11 21:18:10 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-04-11 21:18:09 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-04-11 21:18:08 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-04-11 21:18:06 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-04-11 21:18:06 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-04-11 21:18:06 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-04-11 21:18:06 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-04-11 21:17:06 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-04-11 16:37:14 ----D---- C:\WINDOWS\MindSoft Utilities 2011
2011-04-11 12:28:37 ----A---- C:\cleanup.bat
2011-04-11 12:28:10 ----A---- C:\WINDOWS\system32\vhxaag.txt
2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 22:37:02 ----SD---- C:\ComboFix
2011-04-10 19:04:58 ----A---- C:\WINDOWS\system32\drivers\rkhdrv40.sys
2011-04-10 16:43:50 ----D---- C:\rsit
2011-04-10 14:15:05 ----A---- C:\WINDOWS\zip.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWSC.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWREG.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\sed.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\PEV.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\NIRCMD.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\MBR.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\grep.exe
2011-04-10 14:14:35 ----D---- C:\Qoobox
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-10 01:10:38 ----A---- C:\WINDOWS\system32\drivers\rootrepeal.sys
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:30:36 ----D---- C:\Program Files\CCleaner
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-04 15:29:15 ----D---- C:\WINDOWS\ERDNT
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-12 11:24:33 ----SD---- C:\WINDOWS\Tasks
2011-04-12 11:03:30 ----D---- C:\WINDOWS\Minidump
2011-04-12 10:45:37 ----D---- C:\WINDOWS
2011-04-12 09:56:10 ----D---- C:\WINDOWS\system32\drivers
2011-04-12 09:56:09 ----HD---- C:\WINDOWS\inf
2011-04-12 09:56:09 ----D---- C:\WINDOWS\system32\CatRoot
2011-04-12 09:56:07 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-12 09:49:32 ----D---- C:\WINDOWS\system32\config
2011-04-12 09:48:53 ----D---- C:\WINDOWS\system32\wbem
2011-04-12 09:48:47 ----D---- C:\WINDOWS\Registration
2011-04-12 09:45:24 ----D---- C:\WINDOWS\system32
2011-04-12 09:45:22 ----SHD---- C:\WINDOWS\Installer
2011-04-12 09:44:57 ----RD---- C:\Program Files
2011-04-12 09:44:57 ----D---- C:\ProgramData
2011-04-12 09:34:45 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-12 08:20:59 ----D---- C:\Config.Msi
2011-04-12 08:20:57 ----D---- C:\WINDOWS\WinSxS
2011-04-12 08:20:55 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-12 07:05:51 ----SHD---- C:\System Volume Information
2011-04-12 07:05:51 ----D---- C:\WINDOWS\system32\Restore
2011-04-12 06:55:29 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-11 20:16:53 ----D---- C:\WINDOWS\Prefetch
2011-04-11 16:38:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 22:46:40 ----D---- C:\Program Files\Common Files
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 10:03:31 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 rkhdrv40;Rootkit Unhooker Driver; C:\WINDOWS\system32\drivers\rkhdrv40.sys [2011-04-10 24448]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-09-15 94160]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S1 setup_9.0.0.722_09.04.2011_10-43drv;setup_9.0.0.722_09.04.2011_10-43drv; C:\WINDOWS\system32\DRIVERS\9574816.sys [2009-10-09 315408]
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashServ.exe [2009-11-25 138680]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 avast! Mail Scanner;avast! Mail Scanner; E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashMaiSv.exe [2009-11-25 254040]
S3 avast! Web Scanner;avast! Web Scanner; E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\ashWebSv.exe [2009-11-25 352920]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#32 Příspěvek od motji »

Odinstalujte Avast tímto http://www.avast.com/cs-cz/uninstall-utility.
Pak nahlaste stav pc, vzhledem k tomu, že si stále děláte, co chcete, tak nemám vůbec přehled, co tam je a co není. Neodpověděl jste mi na otázku, jeslti jste použil nějaký antirootkit.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#33 Příspěvek od ringov »

uz si nespominam aky antirootkit,myslim ze root repeal .Avast uz je odinstalovany . Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-12 13:41:40
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (30%) free of 8 GB
Total RAM: 511 MB (22% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:42, on 12.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 4010 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieframe.dll]
regsvr32.exe /s C:\WINDOWS\System32\ieframe.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shell32.dll]
regsvr32.exe /s C:\WINDOWS\system32\shell32.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk]
E:\kasper\VIRUSR~1\SETUP_~1.20~\startup.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-12 12:26:41 ----D---- C:\32788R22FWJFW
2011-04-12 09:55:17 ----A---- C:\WINDOWS\system32\drivers\9574816.sys
2011-04-12 09:44:57 ----D---- C:\Program Files\Windows Media Connect 2
2011-04-12 09:44:57 ----D---- C:\Program Files\Secunia
2011-04-12 09:44:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-12 09:44:57 ----D---- C:\Program Files\ESET
2011-04-12 09:44:57 ----D---- C:\Program Files\Alwil Software
2011-04-12 09:44:57 ----D---- C:\Program Files\7-Zip
2011-04-12 09:41:55 ----A---- C:\WINDOWS\ntbtlog.txt
2011-04-12 09:37:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-12 09:24:28 ----D---- C:\32788R22FWJFW(3)
2011-04-12 08:47:09 ----D---- C:\WINDOWS\CSC
2011-04-12 08:45:34 ----D---- C:\32788R22FWJFW(2)
2011-04-11 16:37:14 ----D---- C:\WINDOWS\MindSoft Utilities 2011
2011-04-11 12:28:37 ----A---- C:\cleanup.bat
2011-04-11 12:28:10 ----A---- C:\WINDOWS\system32\vhxaag.txt
2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 22:37:02 ----SD---- C:\ComboFix
2011-04-10 19:04:58 ----A---- C:\WINDOWS\system32\drivers\rkhdrv40.sys
2011-04-10 16:43:50 ----D---- C:\rsit
2011-04-10 14:15:05 ----A---- C:\WINDOWS\zip.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWXCACLS.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWSC.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\SWREG.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\sed.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\PEV.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\NIRCMD.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\MBR.exe
2011-04-10 14:15:05 ----A---- C:\WINDOWS\grep.exe
2011-04-10 14:14:35 ----D---- C:\Qoobox
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-10 01:10:38 ----A---- C:\WINDOWS\system32\drivers\rootrepeal.sys
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:30:36 ----D---- C:\Program Files\CCleaner
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-04 15:29:15 ----D---- C:\WINDOWS\ERDNT
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-12 13:28:09 ----D---- C:\WINDOWS\Prefetch
2011-04-12 13:22:27 ----D---- C:\WINDOWS\Minidump
2011-04-12 13:22:27 ----D---- C:\WINDOWS
2011-04-12 13:15:33 ----D---- C:\WINDOWS\system32
2011-04-12 11:24:33 ----SD---- C:\WINDOWS\Tasks
2011-04-12 09:56:10 ----D---- C:\WINDOWS\system32\drivers
2011-04-12 09:56:09 ----HD---- C:\WINDOWS\inf
2011-04-12 09:56:09 ----D---- C:\WINDOWS\system32\CatRoot
2011-04-12 09:56:07 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-12 09:49:32 ----D---- C:\WINDOWS\system32\config
2011-04-12 09:48:53 ----D---- C:\WINDOWS\system32\wbem
2011-04-12 09:48:47 ----D---- C:\WINDOWS\Registration
2011-04-12 09:45:22 ----SHD---- C:\WINDOWS\Installer
2011-04-12 09:44:57 ----RD---- C:\Program Files
2011-04-12 09:44:57 ----D---- C:\ProgramData
2011-04-12 09:34:45 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-12 08:20:59 ----D---- C:\Config.Msi
2011-04-12 08:20:57 ----D---- C:\WINDOWS\WinSxS
2011-04-12 08:20:55 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-12 07:05:51 ----SHD---- C:\System Volume Information
2011-04-12 07:05:51 ----D---- C:\WINDOWS\system32\Restore
2011-04-12 06:55:29 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-11 16:38:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 22:46:40 ----D---- C:\Program Files\Common Files
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 10:03:31 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 rkhdrv40;Rootkit Unhooker Driver; C:\WINDOWS\system32\drivers\rkhdrv40.sys [2011-04-10 24448]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S1 setup_9.0.0.722_09.04.2011_10-43drv;setup_9.0.0.722_09.04.2011_10-43drv; C:\WINDOWS\system32\DRIVERS\9574816.sys [2009-10-09 315408]
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S2 aswUpdSv;avast! iAVS4 Control Service; E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe []
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#34 Příspěvek od motji »

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://tharifas.sweb.cz/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?


Jak to vypadá s počítačem?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#35 Příspěvek od ringov »

Uz je to dobre,len internet trocha seká.T-cleaner mam vymazat? Spyware terminator mi buda stacit na ochranu? Vypisuje mi chybu ze ovladac midi konpatiblny s MPU-401 nefunguje a neda sa stiahnut aktualizacia.Dakujem za pomoc :) ,prajem pekny den.------- --------- Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-12 14:28:58
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (36%) free of 8 GB
Total RAM: 511 MB (13% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:29, on 12.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
E:\rsit\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3931 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieframe.dll]
regsvr32.exe /s C:\WINDOWS\System32\ieframe.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shell32.dll]
regsvr32.exe /s C:\WINDOWS\system32\shell32.dll []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk]
E:\kasper\VIRUSR~1\SETUP_~1.20~\startup.exe []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-12 14:28:58 ----D---- C:\rsit
2011-04-12 14:16:15 ----D---- C:\Program Files\CCleaner
2011-04-12 09:55:17 ----A---- C:\WINDOWS\system32\drivers\9574816.sys
2011-04-12 09:44:57 ----D---- C:\Program Files\Windows Media Connect 2
2011-04-12 09:44:57 ----D---- C:\Program Files\Secunia
2011-04-12 09:44:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-12 09:44:57 ----D---- C:\Program Files\ESET
2011-04-12 09:44:57 ----D---- C:\Program Files\Alwil Software
2011-04-12 09:44:57 ----D---- C:\Program Files\7-Zip
2011-04-12 09:37:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-12 09:24:28 ----D---- C:\32788R22FWJFW(3)
2011-04-12 08:47:09 ----D---- C:\WINDOWS\CSC
2011-04-12 08:45:34 ----D---- C:\32788R22FWJFW(2)
2011-04-11 16:37:14 ----D---- C:\WINDOWS\MindSoft Utilities 2011
2011-04-11 12:28:10 ----A---- C:\WINDOWS\system32\vhxaag.txt
2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 19:04:58 ----A---- C:\WINDOWS\system32\drivers\rkhdrv40.sys
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-12 14:25:04 ----D---- C:\WINDOWS
2011-04-12 14:16:15 ----RD---- C:\Program Files
2011-04-12 14:06:45 ----D---- C:\WINDOWS\Minidump
2011-04-12 14:06:37 ----D---- C:\WINDOWS\Prefetch
2011-04-12 14:06:35 ----D---- C:\WINDOWS\system32\drivers
2011-04-12 14:04:56 ----D---- C:\WINDOWS\system32\Restore
2011-04-12 13:15:33 ----D---- C:\WINDOWS\system32
2011-04-12 11:24:33 ----SD---- C:\WINDOWS\Tasks
2011-04-12 09:56:09 ----HD---- C:\WINDOWS\inf
2011-04-12 09:56:09 ----D---- C:\WINDOWS\system32\CatRoot
2011-04-12 09:56:07 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-12 09:49:32 ----D---- C:\WINDOWS\system32\config
2011-04-12 09:48:53 ----D---- C:\WINDOWS\system32\wbem
2011-04-12 09:48:47 ----D---- C:\WINDOWS\Registration
2011-04-12 09:45:22 ----SHD---- C:\WINDOWS\Installer
2011-04-12 09:44:57 ----D---- C:\ProgramData
2011-04-12 09:34:45 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-12 08:20:59 ----D---- C:\Config.Msi
2011-04-12 08:20:57 ----D---- C:\WINDOWS\WinSxS
2011-04-12 08:20:55 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-12 07:05:51 ----SHD---- C:\System Volume Information
2011-04-12 06:55:29 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-11 16:38:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 22:46:40 ----D---- C:\Program Files\Common Files
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 10:03:31 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 rkhdrv40;Rootkit Unhooker Driver; C:\WINDOWS\system32\drivers\rkhdrv40.sys [2011-04-10 24448]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S1 setup_9.0.0.722_09.04.2011_10-43drv;setup_9.0.0.722_09.04.2011_10-43drv; C:\WINDOWS\system32\DRIVERS\9574816.sys [2009-10-09 315408]
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S2 aswUpdSv;avast! iAVS4 Control Service; E:\avast\Avast Antivirus 2010 Professional With Serials\Setup\aswUpdSv.exe []
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#36 Příspěvek od motji »

:arrow:Stáhněte OTM http://oldtimer.geekstogo.com/OTM.exe
Stáhněte na plochu Otm, 2krát klikněte na Otm,spustí se program,
Do levého okna "Paste Instructions for Items to be Moved" pod žlutou čáru zkopírujete skript

Kód: Vybrat vše

:processes
explorer.exe
 
:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\WINDOWS\system32\drivers\9574816.sys
C:\WINDOWS\system32\drivers\rkhdrv40.sys 
C:\32788R22FWJFW(3)
C:\32788R22FWJFW(2)
C:\32788R22FWJFW
:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieframe.dll]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shell32.dll]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk]

:Services
9574816
aswUpdSv
NTACCESS
SetupNTGLM7X
rkhdrv40

:commands
[resethosts]
[emptytemp]
[EMPTYFLASH]
[clearallrestorepoints]
[Reboot]
-klikněte na červené tlačítko Moveit!
-sem vložte obsah zeleného okénka
-Pokud se bude chtít restartovat pc, dejte YES,log pak najdete C:\_OTM\MovedFiles. Log vložte sem


Zkuste u Terminátora vypnout rezidentní štít. T-cleaner smazat.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#37 Příspěvek od ringov »

Je to spravne?----- All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
C:\WINDOWS\SoftwareDistribution\Download\066ffb90ad17118b5d00aa1a10e09d35\BIT1A.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\1c13a3485c4b9a24bac76c4cc8aa317b\BIT1B.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\25b0b42a79049877c2b9c72177e944ea\BIT1E.tmp moved successfully.
C:\WINDOWS\SoftwareDistribution\Download\a081a150a4f978c1bd667c2a5a110ed7\BIT19.tmp moved successfully.
C:\WINDOWS\system32\drivers\9574816.sys moved successfully.
C:\WINDOWS\system32\drivers\rkhdrv40.sys moved successfully.
C:\32788R22FWJFW(3)\License(2) folder moved successfully.
C:\32788R22FWJFW(3) folder moved successfully.
C:\32788R22FWJFW(2)\License(2) folder moved successfully.
C:\32788R22FWJFW(2) folder moved successfully.
File/Folder C:\32788R22FWJFW not found.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ieframe.dll\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shell32.dll\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^setup_9.0.0.722_09.04.2011_10-43.lnk\ deleted successfully.
========== SERVICES/DRIVERS ==========
Error: No service named 9574816 was found to stop!
Service\Driver key 9574816 not found.
Service aswUpdSv stopped successfully!
Service aswUpdSv deleted successfully!
Service NTACCESS stopped successfully!
Service NTACCESS deleted successfully!
Service SetupNTGLM7X stopped successfully!
Service SetupNTGLM7X deleted successfully!
Service rkhdrv40 stopped successfully!
Service rkhdrv40 deleted successfully!
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 33284 bytes
->Temporary Internet Files folder emptied: 257929 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 53609273 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1176 bytes

User: All Users

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 71373 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 3202297 bytes

Total Files Cleaned = 55,00 mb


Unable to start service SRService!

OTM by OldTimer - Version 3.1.17.2 log created on 04122011_190859

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#38 Příspěvek od motji »

Ano, poprosím o nový log ze rsitu. Co počítač?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#39 Příspěvek od ringov »

Pocitac sa uz cova dobre ale mam na diskoch Recycler a Syst.Vol.Infor.a na USB mam Autorun.inf..Stiahol som Panda vaccine a este stale to tam je,ale comp. je rychlejsi-------Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-13 09:24:38
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 3 GB (35%) free of 8 GB
Total RAM: 511 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 09:24, on 13.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
E:\panda\Panda USB Vaccine\USBVaccine.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\wscntfy.exe
E:\rsit\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3824 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\PandaUSBVaccine.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"=C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-13 06:36:35 ----D---- C:\Program Files\Panda Security
2011-04-13 06:36:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Panda Security
2011-04-12 19:08:59 ----D---- C:\_OTM
2011-04-12 14:28:58 ----D---- C:\rsit
2011-04-12 14:16:15 ----D---- C:\Program Files\CCleaner
2011-04-12 09:44:57 ----D---- C:\Program Files\Windows Media Connect 2
2011-04-12 09:44:57 ----D---- C:\Program Files\Secunia
2011-04-12 09:44:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-04-12 09:44:57 ----D---- C:\Program Files\ESET
2011-04-12 09:44:57 ----D---- C:\Program Files\Alwil Software
2011-04-12 09:44:57 ----D---- C:\Program Files\7-Zip
2011-04-12 09:37:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-04-12 08:47:09 ----D---- C:\WINDOWS\CSC
2011-04-11 16:37:14 ----D---- C:\WINDOWS\MindSoft Utilities 2011
2011-04-11 12:28:10 ----A---- C:\WINDOWS\system32\vhxaag.txt
2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-13 09:14:25 ----D---- C:\WINDOWS\Prefetch
2011-04-13 09:05:12 ----SD---- C:\WINDOWS\Tasks
2011-04-13 08:34:48 ----D---- C:\WINDOWS
2011-04-13 08:34:46 ----D---- C:\WINDOWS\system32
2011-04-13 08:34:45 ----D---- C:\Program Files\Common Files
2011-04-13 07:14:01 ----D---- C:\WINDOWS\system32\drivers
2011-04-13 07:11:23 ----D---- C:\WINDOWS\WinSxS
2011-04-13 07:11:16 ----SHD---- C:\WINDOWS\Installer
2011-04-13 07:11:14 ----D---- C:\Config.Msi
2011-04-13 07:05:36 ----D---- C:\WINDOWS\system32\Restore
2011-04-13 07:05:35 ----SHD---- C:\System Volume Information
2011-04-13 07:02:25 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-13 06:39:12 ----HD---- C:\WINDOWS\inf
2011-04-13 06:36:36 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-13 06:36:35 ----RD---- C:\Program Files
2011-04-12 14:06:45 ----D---- C:\WINDOWS\Minidump
2011-04-12 09:56:09 ----D---- C:\WINDOWS\system32\CatRoot
2011-04-12 09:49:32 ----D---- C:\WINDOWS\system32\config
2011-04-12 09:48:53 ----D---- C:\WINDOWS\system32\wbem
2011-04-12 09:48:47 ----D---- C:\WINDOWS\Registration
2011-04-12 09:44:57 ----D---- C:\ProgramData
2011-04-12 09:34:45 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-12 08:20:55 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-12 06:55:29 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-11 16:38:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S1 setup_9.0.0.722_09.04.2011_10-43drv;setup_9.0.0.722_09.04.2011_10-43drv; C:\WINDOWS\system32\DRIVERS\9574816.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#40 Příspěvek od motji »

To máte jen odkryté skryté a systémové soubory, jinak ty složky jsou v pořádku.
:arrow: Ještě znovu spustte OTL, klikněte na tlačítko vyčisti, uklidí po sobě :)
:arrow: Doinstalujte firewall
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#41 Příspěvek od ringov »

ako mam doinstalovat firewal?Stiahol som comodo internet security-spravil som dobre? zo sofmania sk.dakujem.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#42 Příspěvek od motji »

Comodo můžete, jen nechte zapnutý pouze firewall
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

Re: neviem co s tym,prosim pomozte

#43 Příspěvek od ringov »

neviete ci sa da k comodo stiahnut cestina alebo slovencina?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: neviem co s tym,prosim pomozte

#44 Příspěvek od motji »

Měla by být přímo v instalátoru.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

ringov
Návštěvník
Návštěvník
Příspěvky: 313
Registrován: 04 dub 2011 14:21
Bydliště: Cejkov

problem zo zvukom

#45 Příspěvek od ringov »

mam problem so zvukom na webe.neprehrava zvuk nikde-------------Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2011-04-14 22:39:33
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 2 GB (30%) free of 8 GB
Total RAM: 511 MB (54% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:39, on 14.4.2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Download Image with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download URL in selection with Download Manager - tbr:iemenudownsel
O8 - Extra context menu item: Download URL with Download Manager - tbr:iemenudownload
O8 - Extra context menu item: Download with Star Downloader - E:\My Download Files\ACCELELATOR PLUS\Star Downloader\sdie.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - (no file)
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 3976 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\PandaUSBVaccine.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"=C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-11-17 577536]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe [2011-04-05 2216960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"D:\hry\Nová složka (2)\age2_x1.exe"="D:\hry\Nová složka (2)\age2_x1.exe:*:Enabled:Age of Empires II Expansion"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2011-04-14 22:39:33 ----D---- C:\rsit
2011-04-14 15:36:28 ----D---- C:\WINDOWS\LastGood
2011-04-13 10:29:27 ----D---- C:\Documents and Settings\All Users\Data aplikací\_comodo_
2011-04-13 10:21:38 ----A---- C:\WINDOWS\system32\cssdll32.dll
2011-04-13 06:36:35 ----D---- C:\Program Files\Panda Security
2011-04-13 06:36:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Panda Security
2011-04-12 14:16:15 ----D---- C:\Program Files\CCleaner
2011-04-12 09:44:57 ----D---- C:\Program Files\Windows Media Connect 2
2011-04-12 09:44:57 ----D---- C:\Program Files\Secunia
2011-04-12 09:37:21 ----N---- C:\WINDOWS\SchedLgU.Txt
2011-04-12 08:47:09 ----D---- C:\WINDOWS\CSC
2011-04-11 16:37:14 ----D---- C:\WINDOWS\MindSoft Utilities 2011
2011-04-11 12:28:10 ----A---- C:\WINDOWS\system32\vhxaag.txt
2011-04-11 07:05:07 ----D---- C:\Program Files\Crawler
2011-04-10 23:01:44 ----SHD---- C:\RECYCLER
2011-04-10 22:52:11 ----D---- C:\WINDOWS\temp
2011-04-10 12:36:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2011-04-10 09:33:06 ----D---- C:\Program Files\Defraggler
2011-04-10 07:21:49 ----D---- C:\WINDOWS\system32\PreInstall
2011-04-10 07:21:43 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2011-04-10 07:21:43 ----HD---- C:\WINDOWS\$hf_mig$
2011-04-09 09:21:29 ----D---- C:\WINDOWS\system32\NtmsData
2011-04-09 07:25:29 ----HD---- C:\WINDOWS\system32\GroupPolicy
2011-04-09 06:46:03 ----D---- C:\WINDOWS\SxsCaPendDel
2011-04-08 13:29:03 ----D---- C:\Program Files\Google
2011-04-08 10:04:50 ----A---- C:\WINDOWS\system32\ChCfg.exe
2011-04-08 10:04:25 ----RA---- C:\WINDOWS\system32\drivers\alcxwdm.sys
2011-04-08 10:03:43 ----D---- C:\Program Files\Realtek AC97
2011-04-08 10:03:41 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2011-04-08 10:03:37 ----A---- C:\WINDOWS\soundman.exe
2011-04-08 10:03:36 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2011-04-08 10:03:32 ----A---- C:\WINDOWS\alcupd.exe
2011-04-08 10:03:32 ----A---- C:\WINDOWS\Alcrmv.exe
2011-04-07 11:48:26 ----D---- C:\Program Files\trend micro
2011-04-06 16:53:19 ----N---- C:\WINDOWS\cmaudio.ini
2011-04-06 16:53:19 ----D---- C:\Program Files\C-Media
2011-04-06 15:48:38 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2011-04-06 15:24:35 ----ASH---- C:\pagefile.sys
2011-04-06 08:49:29 ----SHD---- C:\Documents and Settings\All Users\Data aplikací\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
2011-04-06 00:05:19 ----D---- C:\Program Files\WinClamAVShield
2011-04-05 22:59:59 ----A---- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2011-04-05 22:59:57 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2011-04-05 22:59:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2011-04-05 22:59:42 ----D---- C:\Program Files\Spyware Terminator
2011-04-05 21:30:29 ----D---- C:\WINDOWS\WBEM
2011-04-05 21:28:55 ----HDC---- C:\WINDOWS\ie8
2011-04-05 21:28:55 ----D---- C:\WINDOWS\system32\cs-CZ
2011-04-04 17:15:57 ----HD---- C:\Program Files\WindowsUpdate
2011-04-04 15:56:13 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2011-04-04 15:34:35 ----N---- C:\Boot.bak
2011-04-04 15:34:26 ----RASHD---- C:\cmdcons
2011-04-01 10:37:23 ----A---- C:\WINDOWS\WEBTRANS.INI
2011-04-01 10:36:28 ----A---- C:\WINDOWS\WEBWTR.INI
2011-04-01 10:36:15 ----D---- C:\WINDOWS\XXLGS

======List of files/folders modified in the last 1 months======

2011-04-14 22:39:36 ----D---- C:\WINDOWS\Prefetch
2011-04-14 22:35:39 ----D---- C:\WINDOWS
2011-04-14 22:02:15 ----D---- C:\WINDOWS\system32
2011-04-14 17:01:07 ----HD---- C:\WINDOWS\inf
2011-04-14 16:49:03 ----D---- C:\WINDOWS\system32\CatRoot2
2011-04-14 12:49:01 ----D---- C:\WINDOWS\system32\Restore
2011-04-14 12:49:00 ----SHD---- C:\System Volume Information
2011-04-14 10:24:09 ----D---- C:\WINDOWS\system32\drivers
2011-04-14 08:24:20 ----RD---- C:\Program Files
2011-04-13 09:05:12 ----SD---- C:\WINDOWS\Tasks
2011-04-13 08:34:45 ----D---- C:\Program Files\Common Files
2011-04-13 07:11:23 ----D---- C:\WINDOWS\WinSxS
2011-04-13 07:11:16 ----SHD---- C:\WINDOWS\Installer
2011-04-13 07:11:14 ----D---- C:\Config.Msi
2011-04-13 06:36:36 ----HD---- C:\Program Files\InstallShield Installation Information
2011-04-12 14:06:45 ----D---- C:\WINDOWS\Minidump
2011-04-12 09:56:09 ----D---- C:\WINDOWS\system32\CatRoot
2011-04-12 09:49:32 ----D---- C:\WINDOWS\system32\config
2011-04-12 09:48:53 ----D---- C:\WINDOWS\system32\wbem
2011-04-12 09:48:47 ----D---- C:\WINDOWS\Registration
2011-04-12 09:44:57 ----D---- C:\ProgramData
2011-04-12 09:34:45 ----D---- C:\WINDOWS\system32\drivers\etc
2011-04-12 08:20:55 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-04-12 06:55:29 ----D---- C:\WINDOWS\SoftwareDistribution
2011-04-11 16:38:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-04-10 22:46:56 ----D---- C:\WINDOWS\AppPatch
2011-04-10 19:20:57 ----RSH---- C:\boot.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\win.ini
2011-04-10 19:20:57 ----A---- C:\WINDOWS\system.ini
2011-04-10 15:04:41 ----D---- C:\WINDOWS\pss
2011-04-09 22:43:10 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2011-04-09 12:02:00 ----D---- C:\Program Files\WinRAR
2011-04-09 09:26:00 ----D---- C:\WINDOWS\repair
2011-04-09 09:21:27 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-04-08 13:36:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\IDM
2011-04-08 13:36:01 ----D---- C:\WINDOWS\Debug
2011-04-08 10:02:59 ----D---- C:\Program Files\Common Files\InstallShield
2011-04-08 09:48:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-04-06 09:07:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\TuneUp Software
2011-04-06 08:55:12 ----D---- C:\Documents and Settings\Administrator\Data aplikací\TuneUp Software
2011-04-06 08:17:50 ----D---- C:\Documents and Settings
2011-04-05 23:11:04 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-04-05 21:52:02 ----D---- C:\Program Files\Mozilla Firefox
2011-04-05 21:32:51 ----D---- C:\WINDOWS\Help
2011-04-05 21:32:51 ----D---- C:\Program Files\Internet Explorer
2011-04-05 21:30:19 ----D---- C:\WINDOWS\Media
2011-03-28 22:12:08 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2011-03-28 21:13:19 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-08 43528]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-12-29 4026112]
R3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
R3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
R3 PAC207;Trust WB-1400T Webcam; C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 508288]
R3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 S3SAVAGE4M;S3SAVAGE4M; C:\WINDOWS\System32\DRIVERS\s3sav4m.sys [2001-08-17 77824]
S1 SASDIFSV;SASDIFSV; \??\E:\My Download Files\antispywer\SASDIFSV.SYS []
S1 SASKUTIL;SASKUTIL; \??\E:\My Download Files\antispywer\SASKUTIL.sys []
S1 setup_9.0.0.722_09.04.2011_10-43drv;setup_9.0.0.722_09.04.2011_10-43drv; C:\WINDOWS\system32\DRIVERS\9574816.sys []
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS []
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 SASENUM;SASENUM; \??\E:\My Download Files\antispywer\SASENUM.SYS []
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2011-04-05 496128]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-09-26 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe []
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]

-----------------EOF-----------------

Odpovědět