Stránka 2 z 2

Re: Facebook vir..PROSIM HELP

Napsal: 23 srp 2011 14:22
od chodnik74
:arrow: Odinstalovat ICQ6Toolbar a všechny nepotřebné toolbary :)


:arrow: Spustíme si HijackThisObrázek

Kód: Vybrat vše

C:\Program Files\trend micro\Owner.exe
(Pokud nenajdeme nebo nemáme,tak stáhneme ZDE )
  • Dále klikneme na tlačítko Do a system scan only
  • Najdeme a označíme následující položky:

    Kód: Vybrat vše

    R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
    R3 - URLSearchHook: (no name) - - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - (no file)
    
    
  • klikneme na položku Fix checked a potvrdíme tlačítkem Ano

:arrow: Otevřeme si Služby Obrázek
  • Stiskněte klávesovou kombinaci WIN+R( nebo start-spustit ),čímž se vám otevře okno pro zadání příkazu pro spuštění. Zkopírujte a vložte sem následujíci text: services.msc a dejte enter
  • Otevře se vám okno se službami vašeho pc,najděte následující služby,dvojklikem rozklikněte,klikneme na Zastavit a dále nastavte Typ spuštění:Zakázano

    Kód: Vybrat vše

    Java Quick Starter
    Služba Google Update (gupdate)
    Služba Google Update (gupdatem)
    Google Software Updater
    

:arrow: Obrázek TFC
  • Stáhneme a spustíme program
  • Klikneme na Start a potvrdíme OK
  • Program začne uklízet,poté restartuje pc
  • po použití program smažte

Poté nový log z RSIT :)

Re: Facebook vir..PROSIM HELP

Napsal: 23 srp 2011 15:30
od impactFBvir
Toolbary odinstalovany.. :)


Logfile of random's system information tool 1.09 (written by random/random)
Run by Owner at 2011-08-23 16:29:10
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 103 GB (67%) free of 153 GB
Total RAM: 2047 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:29:36, on 23.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Program Files\AnyDATA\EasyWirelessNet\EasyWirelessNet.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Dokumenty\Downloads\RSIT.exe
C:\Program Files\AVAST Software\Avast\setup\avast.setup
C:\Program Files\trend micro\Owner.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/#utm_source=icq&u ... um=generic
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Delayer.exe" /LaunchType=Auto /LaunchApps=Common
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-21-1390067357-1614895754-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D629F2F-CFA9-46A0-9491-70DADB320906}: NameServer = 160.218.161.60 160.218.167.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D629F2F-CFA9-46A0-9491-70DADB320906}: NameServer = 160.218.161.60 160.218.167.5
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

--
End of file - 7759 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-08-23 56712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-08-02 577536]
"StartupDelayer"=C:\Program Files\r2 Studios\Startup Delayer\Startup Delayer.exe [2011-06-09 4100096]
"NvMediaCenter"=NvMCTray.dll,NvTaskbarInit -login []
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-07-05 1632360]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=C:\Program Files\ICQ7.6\ICQ.exe [2011-08-23 127040]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2010-04-16 3872080]

C:\Documents and Settings\Owner\Nabídka Start\Programy\Po spuštění
Xfire.lnk - C:\Program Files\Xfire\Xfire.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Metin2\metin2.bin"="C:\Program Files\Metin2\metin2.bin:*:Enabled:metin2"
"C:\Program Files\FlatOut2\FlatOut2.exe"="C:\Program Files\FlatOut2\FlatOut2.exe:*:Enabled:FlatOut2"
"C:\Program Files\Metin2 Kingdom\metinkingdom.exe"="C:\Program Files\Metin2 Kingdom\metinkingdom.exe:*:Enabled:metinkingdom"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\QuadCoreM2\pack\core.bin"="C:\Program Files\QuadCoreM2\pack\core.bin:*:Enabled:core"
"C:\Program Files\Xfire\Xfire.exe"="C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.CFHD"=cfhd.dll
"VIDC.FPS1"=frapsvid.dll
"VIDC.XFR1"=xfcodec.dll
"msacm.siren"=sirenacm.dll

======List of files/folders created in the last 1 month======

2011-08-23 14:05:10 ----D---- C:\rsit
2011-08-23 13:53:08 ----D---- C:\Program Files\Microsoft
2011-08-23 13:52:52 ----D---- C:\Program Files\Windows Live SkyDrive
2011-08-23 13:52:30 ----D---- C:\Program Files\Windows Live
2011-08-23 13:46:33 ----D---- C:\Program Files\Common Files\Windows Live
2011-08-23 13:38:41 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-08-23 13:38:41 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-08-23 13:38:39 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-08-23 13:38:38 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-08-23 13:38:38 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-08-23 13:38:37 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-08-23 13:38:37 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-08-23 13:38:37 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-08-23 13:38:23 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-08-23 13:38:23 ----A---- C:\WINDOWS\avastSS.scr
2011-08-23 13:38:11 ----D---- C:\Program Files\AVAST Software
2011-08-23 13:38:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-08-23 13:27:03 ----D---- C:\Program Files\OpenOffice.org 3
2011-08-23 13:24:37 ----SHD---- C:\Config.Msi
2011-08-23 13:08:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2011-08-23 13:08:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2011-08-23 13:07:25 ----A---- C:\WINDOWS\system32\nvgenco32.dll
2011-08-23 13:07:25 ----A---- C:\WINDOWS\system32\nvdispco32.dll
2011-08-23 13:06:50 ----D---- C:\NVIDIA
2011-08-23 12:58:25 ----D---- C:\Program Files\Common Files\Java
2011-08-23 12:55:10 ----D---- C:\Program Files\ICQ7.6
2011-08-23 12:47:47 ----D---- C:\Program Files\FileHippo.com
2011-08-23 10:47:03 ----D---- C:\Program Files\Defraggler
2011-08-23 10:39:00 ----D---- C:\Program Files\CCleaner
2011-08-23 10:30:25 ----SHD---- C:\RECYCLER
2011-08-22 10:16:26 ----D---- C:\Documents and Settings\Owner\Data aplikací\Malwarebytes
2011-08-22 10:16:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-08-22 10:16:18 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-08-22 10:16:15 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-08-22 10:16:15 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-08-22 09:31:09 ----D---- C:\WINDOWS\temp
2011-08-22 07:27:56 ----A---- C:\Boot.bak
2011-08-22 07:27:52 ----RASHD---- C:\cmdcons
2011-08-22 06:13:57 ----D---- C:\Program Files\trend micro
2011-08-22 04:55:06 ----D---- C:\Documents and Settings\Owner\Data aplikací\Xfire
2011-08-22 04:55:03 ----D---- C:\Program Files\Xfire
2011-08-22 04:22:25 ----D---- C:\WINDOWS\SxsCaPendDel
2011-08-22 02:26:56 ----A---- C:\WINDOWS\system32\javaws.exe
2011-08-22 02:26:56 ----A---- C:\WINDOWS\system32\javaw.exe
2011-08-22 02:26:56 ----A---- C:\WINDOWS\system32\java.exe
2011-08-21 20:13:55 ----D---- C:\Documents and Settings\Owner\Data aplikací\gtk-2.0
2011-08-21 13:26:24 ----D---- C:\Program Files\GIMP-2.0
2011-08-20 21:47:27 ----D---- C:\Documents and Settings\Owner\Data aplikací\Toolbar4
2011-08-20 21:47:21 ----D---- C:\Program Files\HyCam2
2011-08-20 21:40:56 ----D---- C:\Fraps
2011-08-16 17:39:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2011-08-16 17:35:53 ----D---- C:\Program Files\Google
2011-08-12 09:01:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-12 09:01:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-12 09:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-10 22:55:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-10 22:55:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-08-10 20:20:09 ----D---- C:\Documents and Settings\Owner\Data aplikací\vlc
2011-08-10 20:19:04 ----D---- C:\Program Files\VideoLAN
2011-08-05 11:13:33 ----D---- C:\Documents and Settings\Owner\Data aplikací\BabylonToolbar
2011-08-01 21:01:00 ----D---- C:\Program Files\Euro Truck Simulator
2011-08-01 15:29:25 ----D---- C:\Program Files\QuadCoreM2
2011-07-31 21:08:20 ----D---- C:\extensions
2011-07-31 21:08:18 ----D---- C:\Program Files\Conduit
2011-07-31 21:08:15 ----D---- C:\Program Files\ConduitEngine
2011-07-31 21:08:12 ----D---- C:\Program Files\uTorrentBar
2011-07-31 21:07:23 ----D---- C:\Program Files\uTorrent
2011-07-31 21:05:18 ----D---- C:\Documents and Settings\Owner\Data aplikací\uTorrent
2011-07-31 21:00:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\BabylonUpdater
2011-07-31 21:00:12 ----D---- C:\Documents and Settings\Owner\Data aplikací\Babylon
2011-07-31 21:00:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\Babylon
2011-07-31 16:14:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Trymedia
2011-07-31 09:35:46 ----A---- C:\WINDOWS\system32\frapsvid.dll
2011-07-25 09:36:16 ----D---- C:\Program Files\Common Files\Adobe
2011-07-25 09:36:16 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 month======

2011-08-23 16:29:09 ----A---- C:\WINDOWS\ModemLog_AnyDATA CDMA USB Modem (PID 6501).txt
2011-08-23 16:28:35 ----A---- C:\WINDOWS\red_dialer.ini
2011-08-23 16:24:53 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-23 14:14:09 ----SHD---- C:\WINDOWS\Installer
2011-08-23 14:04:33 ----D---- C:\Program Files\WinRAR
2011-08-23 14:04:14 ----SD---- C:\Documents and Settings\Owner\Data aplikací\Microsoft
2011-08-23 13:53:24 ----D---- C:\WINDOWS\system32
2011-08-23 13:53:08 ----RD---- C:\Program Files
2011-08-23 13:52:57 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-08-23 13:52:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-08-23 13:52:17 ----HD---- C:\WINDOWS\inf
2011-08-23 13:46:33 ----D---- C:\Program Files\Common Files
2011-08-23 13:38:41 ----D---- C:\WINDOWS\system32\drivers
2011-08-23 13:38:32 ----D---- C:\WINDOWS\WinSxS
2011-08-23 13:38:23 ----D---- C:\WINDOWS
2011-08-23 13:27:58 ----RSD---- C:\WINDOWS\assembly
2011-08-23 13:27:25 ----RSD---- C:\WINDOWS\Fonts
2011-08-23 13:26:29 ----D---- C:\Program Files\OpenOffice.org 2.3
2011-08-23 13:08:30 ----D---- C:\Documents and Settings
2011-08-23 13:08:28 ----D---- C:\Program Files\NVIDIA Corporation
2011-08-23 13:08:26 ----D---- C:\WINDOWS\Help
2011-08-23 13:07:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-08-23 13:00:10 ----D---- C:\Program Files\The KMPlayer
2011-08-23 12:58:00 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-08-23 12:57:56 ----D---- C:\Program Files\Java
2011-08-23 12:55:57 ----D---- C:\Program Files\ICQ6Toolbar
2011-08-23 12:55:53 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-23 12:55:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2011-08-23 12:52:01 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-23 10:42:38 ----D---- C:\WINDOWS\Logs
2011-08-23 10:42:38 ----D---- C:\WINDOWS\Debug
2011-08-23 10:42:38 ----D---- C:\Documents and Settings\Owner\Data aplikací\DAEMON Tools Lite
2011-08-23 10:38:48 ----SD---- C:\WINDOWS\Tasks
2011-08-23 10:37:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-08-23 10:29:58 ----SHD---- C:\System Volume Information
2011-08-23 10:29:58 ----D---- C:\WINDOWS\system32\Restore
2011-08-22 12:22:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-08-22 09:33:56 ----A---- C:\WINDOWS\system.ini
2011-08-22 09:33:37 ----D---- C:\WINDOWS\system32\drivers\etc
2011-08-22 09:30:03 ----D---- C:\WINDOWS\AppPatch
2011-08-22 09:26:50 ----D---- C:\WINDOWS\system32\drivers\AVG
2011-08-22 09:13:21 ----D---- C:\WINDOWS\system32\config
2011-08-22 09:07:21 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-08-22 07:27:56 ----RASH---- C:\boot.ini
2011-08-21 10:00:58 ----D---- C:\Documents and Settings\Owner\Data aplikací\Sony
2011-08-21 09:59:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony
2011-08-21 09:58:43 ----D---- C:\Program Files\Sony
2011-08-20 21:47:15 ----D---- C:\WINDOWS\Prefetch
2011-08-16 17:40:12 ----D---- C:\WINDOWS\system32\CatRoot
2011-08-12 21:18:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\TrackMania
2011-08-12 19:15:08 ----D---- C:\Documents and Settings\Owner\Data aplikací\ICQ
2011-08-12 14:13:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-12 09:01:26 ----HD---- C:\WINDOWS\$hf_mig$
2011-08-12 08:56:06 ----A---- C:\WINDOWS\system32\MRT.exe
2011-08-12 08:55:31 ----D---- C:\Program Files\Internet Explorer
2011-08-12 08:55:20 ----D---- C:\WINDOWS\ie8updates
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\OpenCL.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\easyUpdatusAPIU.dll
2011-08-01 21:03:08 ----D---- C:\WINDOWS\system32\DirectX
2011-08-01 12:41:43 ----D---- C:\Program Files\Metin2 Kingdom
2011-07-25 17:08:54 ----A---- C:\WINDOWS\system32\mshtml.dll
2011-07-25 09:36:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2011-02-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2011-03-16 32592]
R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-07-04 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2011-01-07 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2011-03-01 34896]
R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2011-04-05 297168]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-07-04 102616]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-01-27 50704]
R3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
R3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-08-18 4017536]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-08-03 12542592]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-09-30 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-09-30 13056]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2011-04-14 134480]
S3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2011-02-10 24144]
S3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2011-02-10 27216]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2011-07-06 25280]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2011-08-03 146024]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2011-02-17 603904]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2010-12-14 1517376]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2011-02-17 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-23 136176]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-23 136176]
S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-08-23 182768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2011-08-23 161664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Facebook vir..PROSIM HELP

Napsal: 23 srp 2011 15:35
od chodnik74
:arrow: Spustíme si HijackThisObrázek

Kód: Vybrat vše

C:\Program Files\trend micro\Owner.exe
(Pokud nenajdeme nebo nemáme,tak stáhneme ZDE )
  • Dále klikneme na tlačítko Do a system scan only
  • Najdeme a označíme následující položky:

    Kód: Vybrat vše

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    
    
  • klikneme na položku Fix checked a potvrdíme tlačítkem Ano

:arrow: Odinstalujte zbytky AVG pomocí nástroje: http://download.avg.com/filedir/util/su ... 1_1322.exe

Poté reset pc a nový log z RSIT :)

Re: Facebook vir..PROSIM HELP

Napsal: 24 srp 2011 09:34
od impactFBvir
Logfile of random's system information tool 1.09 (written by random/random)
Run by Owner at 2011-08-24 10:33:41
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 103 GB (67%) free of 153 GB
Total RAM: 2047 MB (69% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:09, on 24.8.2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AnyDATA\EasyWirelessNet\EasyWirelessNet.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Local Settings\Data aplikací\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Owner\Dokumenty\Downloads\RSIT.exe
C:\Program Files\trend micro\Owner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/#utm_source=icq&u ... um=generic
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [StartupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Delayer.exe" /LaunchType=Auto /LaunchApps=Common
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.6\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-21-1390067357-1614895754-725345543-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files\ICQ7.5\ICQ.exe
O9 - Extra button: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.6 - {7644E42D-B096-457F-8B5B-901238FC81AE} - C:\Program Files\ICQ7.6\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D629F2F-CFA9-46A0-9491-70DADB320906}: NameServer = 160.218.161.60 160.218.167.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D629F2F-CFA9-46A0-9491-70DADB320906}: NameServer = 160.218.161.60 160.218.167.5
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe

--
End of file - 7299 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2011-08-23 56712]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-08-02 577536]
"StartupDelayer"=C:\Program Files\r2 Studios\Startup Delayer\Startup Delayer.exe [2011-06-09 4100096]
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2011-07-05 1632360]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2011-08-03 13892200]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=C:\Program Files\ICQ7.6\ICQ.exe [2011-08-23 127040]

C:\Documents and Settings\Owner\Nabídka Start\Programy\Po spuštění
Xfire.lnk - C:\Program Files\Xfire\Xfire.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableSecureUIAPaths"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Metin2\metin2.bin"="C:\Program Files\Metin2\metin2.bin:*:Enabled:metin2"
"C:\Program Files\FlatOut2\FlatOut2.exe"="C:\Program Files\FlatOut2\FlatOut2.exe:*:Enabled:FlatOut2"
"C:\Program Files\Metin2 Kingdom\metinkingdom.exe"="C:\Program Files\Metin2 Kingdom\metinkingdom.exe:*:Enabled:metinkingdom"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\QuadCoreM2\pack\core.bin"="C:\Program Files\QuadCoreM2\pack\core.bin:*:Enabled:core"
"C:\Program Files\Xfire\Xfire.exe"="C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe"="C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe:*:Enabled:Daemonu.exe"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.5\ICQ.exe"="C:\Program Files\ICQ7.5\ICQ.exe:*:Enabled:ICQ7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.6\ICQ.exe"="C:\Program Files\ICQ7.6\ICQ.exe:*:Enabled:ICQ7.6"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"VIDC.CFHD"=cfhd.dll
"VIDC.FPS1"=frapsvid.dll
"VIDC.XFR1"=xfcodec.dll
"msacm.siren"=sirenacm.dll

======List of files/folders created in the last 1 month======

2011-08-24 08:20:55 ----A---- C:\WINDOWS\system32\muweb.dll
2011-08-24 08:20:54 ----A---- C:\WINDOWS\system32\mucltui.dll
2011-08-23 14:05:10 ----D---- C:\rsit
2011-08-23 13:53:08 ----D---- C:\Program Files\Microsoft
2011-08-23 13:52:52 ----D---- C:\Program Files\Windows Live SkyDrive
2011-08-23 13:52:30 ----D---- C:\Program Files\Windows Live
2011-08-23 13:46:33 ----D---- C:\Program Files\Common Files\Windows Live
2011-08-23 13:38:41 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2011-08-23 13:38:41 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2011-08-23 13:38:39 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2011-08-23 13:38:38 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2011-08-23 13:38:38 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2011-08-23 13:38:37 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2011-08-23 13:38:37 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2011-08-23 13:38:37 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2011-08-23 13:38:23 ----A---- C:\WINDOWS\system32\aswBoot.exe
2011-08-23 13:38:23 ----A---- C:\WINDOWS\avastSS.scr
2011-08-23 13:38:11 ----D---- C:\Program Files\AVAST Software
2011-08-23 13:38:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2011-08-23 13:27:03 ----D---- C:\Program Files\OpenOffice.org 3
2011-08-23 13:24:37 ----SHD---- C:\Config.Msi
2011-08-23 13:08:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA
2011-08-23 13:08:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2011-08-23 13:07:25 ----A---- C:\WINDOWS\system32\nvgenco32.dll
2011-08-23 13:07:25 ----A---- C:\WINDOWS\system32\nvdispco32.dll
2011-08-23 13:06:50 ----D---- C:\NVIDIA
2011-08-23 12:58:25 ----D---- C:\Program Files\Common Files\Java
2011-08-23 12:55:10 ----D---- C:\Program Files\ICQ7.6
2011-08-23 12:47:47 ----D---- C:\Program Files\FileHippo.com
2011-08-23 10:47:03 ----D---- C:\Program Files\Defraggler
2011-08-23 10:39:00 ----D---- C:\Program Files\CCleaner
2011-08-23 10:30:25 ----SHD---- C:\RECYCLER
2011-08-22 10:16:26 ----D---- C:\Documents and Settings\Owner\Data aplikací\Malwarebytes
2011-08-22 10:16:18 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2011-08-22 10:16:18 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2011-08-22 10:16:15 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-08-22 10:16:15 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2011-08-22 09:31:09 ----D---- C:\WINDOWS\temp
2011-08-22 07:27:56 ----A---- C:\Boot.bak
2011-08-22 07:27:52 ----RASHD---- C:\cmdcons
2011-08-22 06:13:57 ----D---- C:\Program Files\trend micro
2011-08-22 04:55:06 ----D---- C:\Documents and Settings\Owner\Data aplikací\Xfire
2011-08-22 04:55:03 ----D---- C:\Program Files\Xfire
2011-08-22 04:22:25 ----D---- C:\WINDOWS\SxsCaPendDel
2011-08-22 02:26:56 ----A---- C:\WINDOWS\system32\javaws.exe
2011-08-22 02:26:56 ----A---- C:\WINDOWS\system32\javaw.exe
2011-08-22 02:26:56 ----A---- C:\WINDOWS\system32\java.exe
2011-08-21 20:13:55 ----D---- C:\Documents and Settings\Owner\Data aplikací\gtk-2.0
2011-08-21 13:26:24 ----D---- C:\Program Files\GIMP-2.0
2011-08-20 21:47:27 ----D---- C:\Documents and Settings\Owner\Data aplikací\Toolbar4
2011-08-20 21:47:21 ----D---- C:\Program Files\HyCam2
2011-08-20 21:40:56 ----D---- C:\Fraps
2011-08-16 17:39:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2011-08-16 17:35:53 ----D---- C:\Program Files\Google
2011-08-12 09:01:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2567680$
2011-08-12 09:01:28 ----HDC---- C:\WINDOWS\$NtUninstallKB2536276-v2$
2011-08-12 09:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB2570222$
2011-08-10 22:55:40 ----HDC---- C:\WINDOWS\$NtUninstallKB2566454$
2011-08-10 22:55:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2562937$
2011-08-10 20:20:09 ----D---- C:\Documents and Settings\Owner\Data aplikací\vlc
2011-08-10 20:19:04 ----D---- C:\Program Files\VideoLAN
2011-08-05 11:13:33 ----D---- C:\Documents and Settings\Owner\Data aplikací\BabylonToolbar
2011-08-01 21:01:00 ----D---- C:\Program Files\Euro Truck Simulator
2011-08-01 15:29:25 ----D---- C:\Program Files\QuadCoreM2
2011-07-31 21:08:20 ----D---- C:\extensions
2011-07-31 21:08:18 ----D---- C:\Program Files\Conduit
2011-07-31 21:08:15 ----D---- C:\Program Files\ConduitEngine
2011-07-31 21:08:12 ----D---- C:\Program Files\uTorrentBar
2011-07-31 21:07:23 ----D---- C:\Program Files\uTorrent
2011-07-31 21:05:18 ----D---- C:\Documents and Settings\Owner\Data aplikací\uTorrent
2011-07-31 21:00:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\BabylonUpdater
2011-07-31 21:00:12 ----D---- C:\Documents and Settings\Owner\Data aplikací\Babylon
2011-07-31 21:00:12 ----D---- C:\Documents and Settings\All Users\Data aplikací\Babylon
2011-07-31 16:14:07 ----D---- C:\Documents and Settings\All Users\Data aplikací\Trymedia
2011-07-31 09:35:46 ----A---- C:\WINDOWS\system32\frapsvid.dll
2011-07-25 09:36:16 ----D---- C:\Program Files\Common Files\Adobe
2011-07-25 09:36:16 ----D---- C:\Program Files\Adobe

======List of files/folders modified in the last 1 month======

2011-08-24 10:33:48 ----D---- C:\WINDOWS\Prefetch
2011-08-24 10:33:06 ----A---- C:\WINDOWS\ModemLog_AnyDATA CDMA USB Modem (PID 6501).txt
2011-08-24 10:26:22 ----A---- C:\WINDOWS\red_dialer.ini
2011-08-24 10:25:52 ----D---- C:\WINDOWS
2011-08-24 10:23:54 ----D---- C:\WINDOWS\system32\CatRoot2
2011-08-24 10:23:54 ----A---- C:\WINDOWS\SchedLgU.Txt
2011-08-24 10:23:37 ----D---- C:\WINDOWS\system32\drivers
2011-08-24 10:23:28 ----SHD---- C:\WINDOWS\Installer
2011-08-24 09:27:02 ----HD---- C:\WINDOWS\inf
2011-08-24 09:20:06 ----HD---- C:\WINDOWS\$hf_mig$
2011-08-24 08:20:55 ----D---- C:\WINDOWS\system32
2011-08-23 14:04:33 ----D---- C:\Program Files\WinRAR
2011-08-23 14:04:14 ----SD---- C:\Documents and Settings\Owner\Data aplikací\Microsoft
2011-08-23 13:53:08 ----RD---- C:\Program Files
2011-08-23 13:52:57 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2011-08-23 13:52:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2011-08-23 13:46:33 ----D---- C:\Program Files\Common Files
2011-08-23 13:38:32 ----D---- C:\WINDOWS\WinSxS
2011-08-23 13:27:58 ----RSD---- C:\WINDOWS\assembly
2011-08-23 13:27:25 ----RSD---- C:\WINDOWS\Fonts
2011-08-23 13:26:29 ----D---- C:\Program Files\OpenOffice.org 2.3
2011-08-23 13:08:30 ----D---- C:\Documents and Settings
2011-08-23 13:08:28 ----D---- C:\Program Files\NVIDIA Corporation
2011-08-23 13:08:26 ----D---- C:\WINDOWS\Help
2011-08-23 13:07:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2011-08-23 13:00:10 ----D---- C:\Program Files\The KMPlayer
2011-08-23 12:58:00 ----A---- C:\WINDOWS\system32\deployJava1.dll
2011-08-23 12:57:56 ----D---- C:\Program Files\Java
2011-08-23 12:55:57 ----D---- C:\Program Files\ICQ6Toolbar
2011-08-23 12:55:53 ----HD---- C:\Program Files\InstallShield Installation Information
2011-08-23 12:55:51 ----D---- C:\Documents and Settings\All Users\Data aplikací\ICQ
2011-08-23 10:42:38 ----D---- C:\WINDOWS\Logs
2011-08-23 10:42:38 ----D---- C:\WINDOWS\Debug
2011-08-23 10:42:38 ----D---- C:\Documents and Settings\Owner\Data aplikací\DAEMON Tools Lite
2011-08-23 10:38:48 ----SD---- C:\WINDOWS\Tasks
2011-08-23 10:37:56 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2011-08-23 10:29:58 ----SHD---- C:\System Volume Information
2011-08-23 10:29:58 ----D---- C:\WINDOWS\system32\Restore
2011-08-22 12:22:00 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2011-08-22 09:33:56 ----A---- C:\WINDOWS\system.ini
2011-08-22 09:33:37 ----D---- C:\WINDOWS\system32\drivers\etc
2011-08-22 09:30:03 ----D---- C:\WINDOWS\AppPatch
2011-08-22 09:13:21 ----D---- C:\WINDOWS\system32\config
2011-08-22 09:07:21 ----D---- C:\Program Files\DAEMON Tools Toolbar
2011-08-22 07:27:56 ----RASH---- C:\boot.ini
2011-08-21 10:00:58 ----D---- C:\Documents and Settings\Owner\Data aplikací\Sony
2011-08-21 09:59:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sony
2011-08-21 09:58:43 ----D---- C:\Program Files\Sony
2011-08-16 17:40:12 ----D---- C:\WINDOWS\system32\CatRoot
2011-08-12 21:18:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\TrackMania
2011-08-12 19:15:08 ----D---- C:\Documents and Settings\Owner\Data aplikací\ICQ
2011-08-12 14:13:04 ----D---- C:\WINDOWS\Microsoft.NET
2011-08-12 08:56:06 ----A---- C:\WINDOWS\system32\MRT.exe
2011-08-12 08:55:31 ----D---- C:\Program Files\Internet Explorer
2011-08-12 08:55:20 ----D---- C:\WINDOWS\ie8updates
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\OpenCL.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2011-08-03 13:49:00 ----A---- C:\WINDOWS\system32\easyUpdatusAPIU.dll
2011-08-01 21:03:08 ----D---- C:\WINDOWS\system32\DirectX
2011-08-01 12:41:43 ----D---- C:\Program Files\Metin2 Kingdom
2011-07-25 17:08:54 ----A---- C:\WINDOWS\system32\mshtml.dll
2011-07-25 09:36:24 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-13 61696]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2011-07-04 30808]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2011-07-04 25432]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2011-07-04 441176]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2011-07-04 309848]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2011-07-04 43608]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2011-07-04 19544]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2011-07-04 102616]
R2 npf;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2010-01-27 50704]
R3 adusbmdm6501;AnyDATA CDMA USB Modem Driver (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbmdm65.sys [2005-05-02 64896]
R3 adusbser6501;AnyDATA CDMA USB Serial Port (PID 6501); C:\WINDOWS\system32\DRIVERS\adusbser65.sys [2005-05-02 64896]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-08-18 4017536]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2011-08-03 12542592]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-09-30 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-09-30 13056]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2011-07-06 25280]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys []
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 NVSvc;NVIDIA Driver Helper Service; C:\WINDOWS\system32\nvsvc32.exe [2011-08-03 146024]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service; C:\WINDOWS\System32\TUProgSt.exe [2011-02-17 603904]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe [2010-12-14 1517376]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 MSSQL$SONY_MEDIAMGR;MSSQL$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe [2002-12-17 7520337]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SQLAgent$SONY_MEDIAMGR;SQLAgent$SONY_MEDIAMGR; C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE [2002-12-17 311872]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2011-02-17 360192]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-23 136176]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2011-08-23 136176]
S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-08-23 182768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2011-08-23 161664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Facebook vir..PROSIM HELP

Napsal: 24 srp 2011 09:47
od chodnik74
Výborně :idea:

Máme hotovo,jak se chová počítač? :)

Re: Facebook vir..PROSIM HELP

Napsal: 24 srp 2011 09:52
od impactFBvir
Vse jiz v poradku ;) Dekuji Vam za ochotu a take za Vas cas.. :) :thumbsup:

Re: Facebook vir..PROSIM HELP

Napsal: 24 srp 2011 10:23
od chodnik74
Rád jsem pomohl :) Náš tým je tu pro Vás i příště :bye:

:closed: