Stránka 2 z 2

Re: prosím o kontrolu blbne mi notebook

Napsal: 25 lis 2010 15:45
od Loutka
Logfile of random's system information tool 1.08 (written by random/random)
Run by Hana Pojmonová at 2010-11-25 15:44:33
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 6 GB (41%) free of 15 GB
Total RAM: 1012 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:44:47, on 25.11.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\DOCUME~1\HANAPO~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Hana Pojmonová\Plocha\RSIT.exe
C:\Program Files\trend micro\Hana Pojmonová.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACA ... 9&m=aoa110
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{53AA6D19-10CE-49B0-BF55-A09F866BDB1E}: NameServer = 192.168.150.237,194.228.2.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

--
End of file - 4755 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-05-15 16862720]
"AzMixerSel"=C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe [2006-07-17 53248]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-24 1044480]
"LManager"=C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE [2008-05-13 821768]
"M3000Mnt"=M3000Rmv.dll ,WinMainRmv /StartStillMnt []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-11 34672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2008-04-14 208952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2008-04-14 59392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-14 455168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-14 455168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProductReg]
C:\Program Files\Acer\WR_PopUp\ProductReg.exe [2008-09-23 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-09-02 13351304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-04-10 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^0hxd66k.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\0hxd66k.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^0pfl60n.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\0pfl60n.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^0zu0lg0.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\0zu0lg0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^15k7brh.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\15k7brh.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^1yze3a1.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\1yze3a1.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^66k81wh.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\66k81wh.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^6douu5v.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\6douu5v.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^6s86e3a.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\6s86e3a.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^70aaqg0.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\70aaqg0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^bg8703ek5f.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\bg8703ek5f.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^c1yo1klq.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\c1yo1klq.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^fqlgmm3yy.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\fqlgmm3yy.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^g81sdezf66w.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\g81sdezf66w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^grniojf66w.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\grniojf66w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^j5k7brh3.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\j5k7brh3.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^jkf081mx.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\jkf081mx.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^l03c6duk5.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\l03c6duk5.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^mhn66e3a1w.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\mhn66e3a1w.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^n0jo81lghm8.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\n0jo81lghm8.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^q3cxnoz081g.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\q3cxnoz081g.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^qgmm3yy7.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\qgmm3yy7.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^qlr66i86u8.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\qlr66i86u8.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^qmrnddze86g.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\qmrnddze86g.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^qq6m8703u.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\qq6m8703u.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^s0o31gb0m7.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\s0o31gb0m7.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^s1zjfabg.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\s1zjfabg.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^s3o1klq8703.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\s3o1klq8703.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^tu6ag3w5.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\tu6ag3w5.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^ty86k870.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\ty86k870.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^u5vgrsnt60.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\u5vgrsnt60.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^up081whidtu.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\up081whidtu.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^w2xyt03k0lw.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\w2xyt03k0lw.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^wx1oo6u0.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\wx1oo6u0.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^x081epqlr.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\x081epqlr.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^xsjzzffgbr.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\xsjzzffgbr.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^y5k7brh3ez.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\y5k7brh3ez.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^yejuk780c.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\yejuk780c.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Hana Pojmonová^Nabídka Start^Programy^Po spuštění^zuva86m81y.exe]
C:\Documents and Settings\Hana Pojmonová\Nabídka Start\Programy\Po spuštění\zuva86m81y.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSK80Service"=2
"MpfService"=2
"mnmsrvc"=3
"McSysmon"=3
"McShield"=2
"McProxy"=2
"McODS"=3
"McNASvc"=2
"mcmscsvc"=2
"McAfee SiteAdvisor Service"=2
"gusvc"=3
"GoogleDesktopManager-080708-050100"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2008-02-14 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Documents and Settings\Hana Pojmonová\Plocha\P1753577.JPG-www.facebook.exe"="C:\WINDOWS\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-11-25 05:25:44 ----D---- C:\Avenger
2010-11-25 05:25:43 ----A---- C:\avenger.txt
2010-11-23 19:50:57 ----A---- C:\ComboFix.txt
2010-11-22 21:22:38 ----A---- C:\Boot.bak
2010-11-22 21:22:14 ----RASHD---- C:\cmdcons
2010-11-22 21:18:55 ----A---- C:\WINDOWS\zip.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\SWSC.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\SWREG.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\sed.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\PEV.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\NIRCMD.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\MBR.exe
2010-11-22 21:18:55 ----A---- C:\WINDOWS\grep.exe
2010-11-22 21:18:52 ----SHD---- C:\System Volume Information
2010-11-22 21:18:08 ----D---- C:\WINDOWS\ERDNT
2010-11-22 21:17:50 ----D---- C:\Qoobox
2010-11-22 17:13:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-11-22 17:07:51 ----RA---- C:\Documents and Settings\Hana Pojmonová\Data aplikací\BG0Ai.txt
2010-11-22 16:58:01 ----D---- C:\rsit
2010-11-22 16:58:01 ----D---- C:\Program Files\trend micro
2010-11-22 16:47:15 ----D---- C:\Documents and Settings\Hana Pojmonová\Data aplikací\HEXelon
2010-11-22 16:42:31 ----D---- C:\Program Files\TC UP
2010-11-22 15:58:56 ----D---- C:\Program Files\Yahoo!
2010-11-22 15:58:45 ----D---- C:\Program Files\CCleaner
2010-11-21 19:23:41 ----RA---- C:\Documents and Settings\Hana Pojmonová\Data aplikací\k6jLC.txt
2010-11-17 18:22:23 ----D---- C:\Documents and Settings\Hana Pojmonová\Data aplikací\BSplayer
2010-11-17 15:59:32 ----D---- C:\Program Files\Conduit
2010-11-17 15:59:11 ----D---- C:\Documents and Settings\Hana Pojmonová\Data aplikací\BSplayer Pro
2010-11-17 15:59:05 ----D---- C:\Program Files\Webteh
2010-11-13 19:58:42 ----RSH---- C:\Documents and Settings\Hana Pojmonová\Data aplikací\juzjf.exe

======List of files/folders modified in the last 1 months======

2010-11-23 19:47:38 ----A---- C:\WINDOWS\system.ini
2010-11-22 21:22:40 ----RASH---- C:\boot.ini
2010-11-22 21:03:16 ----A---- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Filtr Intel sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 agpCPQ;Filtr Compaq sběrnice AGP; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
R0 alim1541;Filtr ALI sběrnice AGP; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
R0 amdagp;Ovladač filtru AMD portu AGP; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
R0 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2008-04-14 13952]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2008-08-20 44944]
R0 sisagp;Filtr SIS sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
R0 viaagp;Filtr VIA sběrnice AGP ; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 VD_FileDisk;VD_FileDisk; C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 15872]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-05-20 1312576]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\WINDOWS\system32\DRIVERS\DKbFltr.sys [2004-12-07 16896]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2008-02-14 5854752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-20 4800000]
R3 M3000Srv;Acer Crystal Eye webcam Driver; C:\WINDOWS\System32\Drivers\M3000KNT.sys [2008-08-06 151936]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2008-08-07 111360]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2008-04-24 225024]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 int15.sys;int15.sys; \??\c:\acernb\int15.sys []
S3 JMCR;JMCR; C:\WINDOWS\system32\DRIVERS\jmcr.sys [2008-07-07 96856]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-14 268288]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-22 136120]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: prosím o kontrolu blbne mi notebook

Napsal: 25 lis 2010 16:38
od Loutka
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 5188

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

25.11.2010 16:36:53
mbam-log-2010-11-25 (16-36-53).txt

Typ skenu: Úplný sken (C:\|)
Skenované objekty: 193043
Uplynulý čas: 30 minuta(y), 30 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 77

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001308.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001309.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001310.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001311.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001312.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001313.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001314.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001315.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001316.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001317.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001318.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001319.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001320.exe (Trojan.Ddox) -> No action taken.
C:\System Volume Information\_restore{2ED94076-DB0D-418E-9E4D-B4490E2D2A79}\RP1\A0001321.exe (Trojan.Ddox) -> No action taken.
C:\Documents and Settings\Hana Pojmonová\indjjsf.exe (Trojan.Inject) -> No action taken.
C:\Documents and Settings\Hana Pojmonová\Plocha\P1753577.JPG-www.facebook.exe (Worm.Palevo) -> No action taken.
C:\Qoobox\Quarantine\C\nlw.exe.vir (Worm.Autorun) -> No action taken.
C:\Qoobox\Quarantine\C\Documents and Settings\Hana Pojmonová\Data aplikací\Microsoft\dyvoopou.exe.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\Documents and Settings\Hana Pojmonová\Data aplikací\Microsoft\jofebe.exe.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\Documents and Settings\Hana Pojmonová\Data aplikací\Microsoft\roulyke.exe.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\RECYCLER\S-1-5-21-2768641779-7308119087-725856793-5782\yv8g67.exe.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jofebe.exe.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\tvvalvlx.sys.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\0hxd66k.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\0pfl60n.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\0zu0lg0.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\15k7brh.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\1yze3a1.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\66k81wh.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\6douu5v.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\6s86e3a.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\70aaqg0.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\bg8703ek5f.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\c1yo1klq.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\fqlgmm3yy.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\g81sdezf66w.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\grniojf66w.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\j5k7brh3.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\jkf081mx.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\l03c6duk5.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\mhn66e3a1w.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\n0jo81lghm8.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\q3cxnoz081g.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\qgmm3yy7.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\qlr66i86u8.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\qmrnddze86g.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\qq6m8703u.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\s0o31gb0m7.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\s1zjfabg.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\s3o1klq8703.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\tu6ag3w5.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\ty86k870.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\u5vgrsnt60.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\up081whidtu.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\w2xyt03k0lw.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\wx1oo6u0.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\x081epqlr.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\xsjzzffgbr.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\y5k7brh3ez.exeStartup.vir (Trojan.Lethic) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\yejuk780c.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\pss\zuva86m81y.exeStartup.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0002.CHK.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0003.CHK.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0004.CHK.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0005.CHK.vir (Trojan.Agent) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0006.CHK.vir (Trojan.Downloader) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0007.CHK.vir (Trojan.Downloader) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0010.CHK.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0011.CHK.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0012.CHK.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0013.CHK.vir (Trojan.Ddox) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0014.CHK.vir (Trojan.Dropper) -> No action taken.
C:\Qoobox\Quarantine\C\FOUND.000\FILE0015.CHK.vir (Trojan.Dropper) -> No action taken.
C:\Program Files\trend micro\backups\backup-20101123-190247-235-jkf081mx.exe (Trojan.Ddox) -> No action taken.
C:\Documents and Settings\All Users\Data aplikací\common.data (Malware.Trace) -> No action taken.
C:\Documents and Settings\Hana Pojmonová\Data aplikací\juzjf.exe (Worm.Palevo) -> No action taken.
C:\Documents and Settings\Hana Pojmonová\secupdat.dat (Worm.Autorun) -> No action taken.

Re: prosím o kontrolu blbne mi notebook

Napsal: 25 lis 2010 17:36
od Marek-26
Vše co MBAM našel smažte ;-)

Re: prosím o kontrolu blbne mi notebook

Napsal: 25 lis 2010 17:45
od Loutka
smazáno

Re: prosím o kontrolu blbne mi notebook

Napsal: 25 lis 2010 19:32
od Marek-26
Ještě se poradím s kolegy jak odstranit ty zbytkové záznamy v registrech :wink: Jinak už by měl být PC čistý :)
Propříště až Vám přijde na chatu na Facebooku zpráva ve znění "Photo :) a odkaz" tak neklikat, nestahovat a poslat uživatele sem k nám :D

Re: prosím o kontrolu blbne mi notebook

Napsal: 25 lis 2010 19:54
od Loutka
jj díky je to notebook dcery

Re: prosím o kontrolu blbne mi notebook

Napsal: 27 lis 2010 16:24
od Diallix
Dobry den.

:)

Na Marekove poziadanie, tu vstupujem.

Do poznamkoveho bloku skopirujte :
@ECHO OFF

@REG EXPORT "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig" "%systemdrive%\bck.txt"
@REG.exe DELETE "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig" /f

start %systemdrive%\bck.txt
Ulozte trebars na plochu ako vsetky subory >> fix.cmd

fix.cmd spustite.

Po prikazoch Vam naskoci obsah suboru bck.txt, ktory sem prekopirujte.

Re: prosím o kontrolu blbne mi notebook

Napsal: 27 lis 2010 20:20
od Loutka
Děkuji moc ale musel jsem notebook přeinstalovat protože spadnul win......Tak předem děkuji za pomoc.......

Re: prosím o kontrolu blbne mi notebook

Napsal: 29 lis 2010 00:29
od Marek-26
To je divné ... PC by až na ty zbytky v registrech čistý :wink:
Za mě i za všechny kolegy - Nemáte zač :)