Stránka 2 z 2

Re: FB vir

Napsal: 29 srp 2011 10:39
od vyosek
Jeste jeden skript - postup je stejny

Kód: Vybrat vše

Folder::
av_ico

SkipFix::

Re: FB vir

Napsal: 29 srp 2011 10:45
od Kopecz
ComboFix 11-08-28.01 - admin 29.08.2011 11:42:27.4.6 - x64
Spuštěný z: c:\users\admin\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\admin\Desktop\CFScript.txt
.
- REŽIM S OMEZENOU FUNKČNOSTÍ -
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2011-07-28 do 2011-08-29 )))))))))))))))))))))))))))))))
.
.
2011-08-29 09:43 . 2011-08-29 09:43 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-29 08:24 . 2011-08-12 04:10 8862544 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F5E77159-442E-4FDF-A4BB-9F1D8FC36297}\mpengine.dll
2011-08-29 08:23 . 2011-08-29 08:23 -------- d-----w- c:\programdata\McAfee
2011-08-29 07:39 . 2011-08-29 08:18 -------- d-----w- c:\program files\trend micro
2011-08-29 07:39 . 2011-08-29 07:42 -------- dc----w- C:\rsit
2011-08-24 06:34 . 2011-08-24 06:34 -------- d-----w- c:\windows\SysWow64\xlive
2011-08-24 06:34 . 2011-07-09 05:26 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-24 06:34 . 2011-07-09 04:29 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-08-22 07:21 . 2011-08-22 07:21 -------- dc----w- C:\$UPGRADE.~OS
2011-08-21 16:43 . 2011-08-21 16:43 -------- d-----w- c:\program files (x86)\SiteAdvisor
2011-08-21 16:42 . 2011-04-14 12:08 24376 ----a-w- c:\program files (x86)\Mozilla Firefox\components\Scriptff.dll
2011-08-21 16:42 . 2011-04-14 12:08 9984 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-08-21 16:42 . 2011-04-14 12:08 149032 ----a-w- c:\windows\system32\mfevtps.exe
2011-08-21 16:42 . 2011-04-14 12:08 94992 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-08-21 16:42 . 2011-04-14 12:08 75160 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2011-08-21 16:42 . 2011-04-14 12:08 63056 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-08-21 16:42 . 2011-04-14 12:08 530304 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-08-21 16:42 . 2011-04-14 12:08 441840 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-08-21 16:42 . 2011-04-14 12:08 283744 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2011-08-21 16:42 . 2011-04-14 12:08 190520 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-08-21 16:42 . 2011-08-21 16:42 -------- d-----w- c:\program files\McAfee.com
2011-08-21 16:07 . 2011-08-21 16:08 53248 ------w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\msihook.dll
2011-08-21 16:07 . 2011-08-21 16:08 32768 ------w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2011-08-21 16:07 . 2011-08-21 16:08 221184 ------w- c:\program files (x86)\Common Files\InstallShield\IScript\iscript.dll
2011-08-21 16:07 . 2011-08-21 16:08 598016 ------w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\ikernel.exe
2011-08-21 16:07 . 2011-08-21 16:08 217088 ------w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2011-08-21 16:07 . 2011-08-21 16:08 114688 ------w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\scpthdlr.dll
2011-08-21 16:07 . 2011-08-21 16:07 126976 ------w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\knlwrap.exe
2011-08-21 15:37 . 2011-08-21 15:37 -------- d-----w- c:\windows\av_ico
2011-08-18 10:32 . 2011-08-18 10:32 -------- d-----w- c:\program files (x86)\Atari
2011-08-17 05:12 . 2011-08-21 16:03 -------- d-----w- c:\programdata\Electronic Arts
2011-08-16 20:53 . 2003-02-11 04:02 32768 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\np32dsw.dll
2011-08-15 18:10 . 2011-08-15 18:10 -------- d-----w- c:\program files (x86)\AVI to 3GP
2011-08-12 13:28 . 2011-08-12 13:28 -------- d-----w- c:\program files (x86)\Download Master
2011-08-12 13:26 . 2011-08-12 13:26 -------- d-----w- c:\program files (x86)\REDEMAX
2011-08-10 09:55 . 2011-07-09 02:46 288768 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-07 20:47 . 2011-08-07 20:47 -------- d-----w- c:\users\admin\AppData\Local\Abelssoft
2011-08-07 20:47 . 2011-08-07 20:49 -------- d-----w- c:\program files (x86)\K-Lite Codec Pack
2011-08-07 20:47 . 2011-08-07 20:49 -------- d-----w- c:\program files (x86)\YouTube Song Downloader
2011-08-07 20:39 . 2011-08-07 20:39 -------- d-----w- c:\programdata\TheManWithNoLife
2011-08-07 20:39 . 2011-08-07 20:43 -------- d-----w- c:\program files\TheManWithNoLife
2011-08-07 20:02 . 2011-08-07 20:02 -------- d-----w- c:\users\admin\AppData\Roaming\DVDVideoSoftIEHelpers
2011-08-07 20:02 . 2011-08-07 20:15 -------- d-----w- c:\program files (x86)\DVDVideoSoft
2011-08-07 20:02 . 2011-08-07 20:03 -------- d-----w- c:\program files (x86)\Common Files\DVDVideoSoft
2011-08-01 05:02 . 2011-08-01 05:02 -------- d-----w- c:\users\admin\AppData\Roaming\Ventrilo
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-29 09:18 . 2010-12-05 18:39 25640 ----a-w- c:\windows\gdrv.sys
2011-08-17 07:34 . 2011-06-13 19:22 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-20 15:14 . 2011-06-15 19:06 18960 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-07-20 08:41 . 2011-07-20 17:06 34624 ----a-w- c:\windows\system32\TURegOpt.exe
2011-07-20 08:35 . 2011-07-20 17:05 25920 ----a-w- c:\windows\system32\authuitu.dll
2011-07-20 08:35 . 2011-07-20 17:05 21312 ----a-w- c:\windows\SysWow64\authuitu.dll
2011-07-20 08:35 . 2011-07-20 17:05 36160 ----a-w- c:\windows\system32\uxtuneup.dll
2011-07-20 08:35 . 2011-07-20 17:05 29504 ----a-w- c:\windows\SysWow64\uxtuneup.dll
2011-07-16 04:26 . 2011-08-10 09:55 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-07-15 19:58 . 2011-07-15 19:58 53248 ----a-r- c:\users\admin\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2011-07-03 15:24 . 2011-07-03 15:24 20480 ----a-w- c:\windows\SysWow64\H@tKeysH@@k.DLL
2011-07-03 14:36 . 2011-07-01 14:20 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-07-03 14:36 . 2011-07-01 14:20 249856 ------w- c:\windows\Setup1.exe
2011-06-17 13:55 . 2011-06-01 10:02 466456 ----a-w- c:\windows\system32\wrap_oal.dll
2011-06-17 13:55 . 2011-06-01 10:02 122904 ----a-w- c:\windows\system32\OpenAL32.dll
2011-06-17 13:55 . 2010-12-23 19:58 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll
2011-06-17 13:55 . 2010-12-23 19:58 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll
2011-06-12 13:05 . 2011-06-12 14:33 80256 ----a-w- c:\windows\SysWow64\ezGOSvc.dll
2011-06-12 13:05 . 2011-06-12 14:33 663424 ----a-w- c:\windows\SysWow64\ezGOSvcApp.exe
2011-06-11 03:07 . 2011-07-13 06:19 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-06-10 23:58 . 2011-06-10 23:58 81744 ----a-w- c:\windows\SysWow64\mfcm100u.dll
2011-06-10 23:58 . 2011-06-10 23:58 81744 ----a-w- c:\windows\SysWow64\mfcm100.dll
2011-06-10 23:58 . 2011-06-10 23:58 773968 ----a-w- c:\windows\SysWow64\msvcr100.dll
2011-06-10 23:58 . 2011-06-10 23:58 64336 ----a-w- c:\windows\SysWow64\mfc100fra.dll
2011-06-10 23:58 . 2011-06-10 23:58 64336 ----a-w- c:\windows\SysWow64\mfc100deu.dll
2011-06-10 23:58 . 2011-06-10 23:58 63824 ----a-w- c:\windows\SysWow64\mfc100esn.dll
2011-06-10 23:58 . 2011-06-10 23:58 62288 ----a-w- c:\windows\SysWow64\mfc100ita.dll
2011-06-10 23:58 . 2011-06-10 23:58 60752 ----a-w- c:\windows\SysWow64\mfc100rus.dll
2011-06-10 23:58 . 2011-06-10 23:58 55120 ----a-w- c:\windows\SysWow64\mfc100enu.dll
2011-06-10 23:58 . 2011-06-10 23:58 51024 ----a-w- c:\windows\SysWow64\vcomp100.dll
2011-06-10 23:58 . 2011-06-10 23:58 4422992 ----a-w- c:\windows\SysWow64\mfc100u.dll
2011-06-10 23:58 . 2011-06-10 23:58 4397384 ----a-w- c:\windows\SysWow64\mfc100.dll
2011-06-10 23:58 . 2011-06-10 23:58 43856 ----a-w- c:\windows\SysWow64\mfc100jpn.dll
2011-06-10 23:58 . 2011-06-10 23:58 43344 ----a-w- c:\windows\SysWow64\mfc100kor.dll
2011-06-10 23:58 . 2011-06-10 23:58 421200 ----a-w- c:\windows\SysWow64\msvcp100.dll
2011-06-10 23:58 . 2011-06-10 23:58 36176 ----a-w- c:\windows\SysWow64\mfc100cht.dll
2011-06-10 23:58 . 2011-06-10 23:58 36176 ----a-w- c:\windows\SysWow64\mfc100chs.dll
2011-06-10 23:58 . 2011-06-10 23:58 138056 ----a-w- c:\windows\SysWow64\atl100.dll
2011-06-03 14:02 . 2011-06-03 14:02 62496 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2011-06-03 14:01 . 2011-06-03 14:01 38288 ----a-w- c:\windows\system32\drivers\EpfwLWF.sys
2011-06-03 14:01 . 2011-06-03 14:01 187632 ----a-w- c:\windows\system32\drivers\epfw.sys
2011-06-03 14:01 . 2011-06-03 14:01 146432 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-06-03 14:00 . 2011-06-03 14:00 202064 ----a-w- c:\windows\system32\drivers\eamonm.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-29_08.42.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-14 04:54 . 2011-08-29 08:26 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-29 09:23 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2011-08-29 09:23 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2011-08-29 08:26 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-12-05 18:31 . 2011-08-29 09:20 62148 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2011-08-29 09:20 24708 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2009-07-14 05:10 . 2011-08-29 08:23 24708 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-12-05 18:24 . 2011-08-29 09:20 3362 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1071306001-177135528-4153119601-1001_UserData.bin
- 2011-08-29 08:42 . 2011-08-29 08:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-29 09:18 . 2011-08-29 09:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-08-29 08:42 . 2011-08-29 08:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-08-29 09:18 . 2011-08-29 09:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-14 04:54 . 2011-08-29 08:26 131072 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2011-08-29 09:23 131072 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"ISUSPM Startup"="c:\progra~2\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-17 221184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-26 336384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
R2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [x]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [x]
R3 AODDriver;AODDriver;c:\program files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
R3 AppleChargerSrv;AppleChargerSrv;c:\windows\system32\AppleChargerSrv.exe [x]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [x]
R3 etdrv;etdrv;c:\windows\etdrv.sys [2010-12-06 25640]
R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys [2010-12-23 30528]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [x]
R3 PAC207;SoC PC-Camera;c:\windows\system32\DRIVERS\PFC027.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [x]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 AppleCharger;AppleCharger;c:\windows\system32\DRIVERS\AppleCharger.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [x]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-01-26 354304]
S2 AMD Reservation Manager;AMD Reservation Manager;c:\program files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 ezGOSvc;Easybits GO Services for Windows;c:\windows\system32\svchost.exe [2009-07-14 27136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-07-20 2027840]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [x]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys [x]
S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys [x]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-06 10144288]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-10-28 1680976]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [BU]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
ezGOSvc
.
------- Doplňkový sken -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.seznam.cz/
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - c:\users\admin\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Translate this web page with Babylon - c:\program files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
IE: {{7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - c:\program files (x86)\ICQ7.5\ICQ.exe
TCP: DhcpNameServer = 192.168.1.2
FF - ProfilePath - c:\users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\rwe7uvgb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
BHO-{ce18769b-c7fa-42d2-860d-17c4662c70ad} - (no file)
Toolbar-{ce18769b-c7fa-42d2-860d-17c4662c70ad} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Celkový čas: 2011-08-29 11:44:47
ComboFix-quarantined-files.txt 2011-08-29 09:44
ComboFix2.txt 2011-08-29 09:16
ComboFix3.txt 2011-08-29 08:44
.
Před spuštěním: Volných bajtů: 283 015 065 600
Po spuštění: Volných bajtů: 282 991 538 176
.
- - End Of File - - CDD11D3B3EE189C725CC88581DD17191

Re: FB vir

Napsal: 29 srp 2011 10:47
od vyosek
Nejak se mu nechce, takze jinak

:arrow: Stahnete OTM (viz muj podpis)
  • Pokud pouzivate Win Vista ci W7, kliknete na OTM pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do leveho okna Paste Instructions for Items to be Moved (pod zlutou caru) vlozte obsah, ktery mate nize
  • Kód: Vybrat vše

    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "egui"=-
    
    :files
    c:\windows\av_ico
    %windir%\system32\*.tmp.dll /s
    %windir%\system32\SET*.tmp /s
    %windir%\*.tmp
    
    :commands
    [RESETHOSTS]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Kliknete na cervene tlacitko MoveIt!
  • Budete vyzvani na restart, dejte Yes, log pote najdete C:\_OTM\MovedFiles, obsah sem vlozte

Re: FB vir

Napsal: 29 srp 2011 10:53
od Kopecz
All processes killed
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\egui not found.
========== FILES ==========
c:\windows\av_ico folder moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: admin
->Temp folder emptied: 34308 bytes
->Temporary Internet Files folder emptied: 395893231 bytes
->Java cache emptied: 683646 bytes
->FireFox cache emptied: 226043555 bytes
->Google Chrome cache emptied: 14455915 bytes
->Flash cache emptied: 137758 bytes

User: All Users

User: AppData
->Temp folder emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 4856976 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50507 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 612,00 mb


OTM by OldTimer - Version 3.1.18.0 log created on 08292011_114955

Files moved on Reboot...

Registry entries deleted on Reboot...

Re: FB vir

Napsal: 29 srp 2011 11:09
od vyosek
:arrow: Odinstalujte Combofix
  • Prejmenujte ComboFix na Uninstall
  • Spustte jej
  • Tohle smaze Combofix a jeho slozky
:arrow: T-Cleaner http://vyosek.ic.cz/pro_usery/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry touhou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: OTC http://oldtimer.geekstogo.com/OTC.exe
  • Stahnete a spustte
  • Kliknete na CleanUp a potvrdte YES
  • Program uklidi a restartuje PC

:arrow: TFC http://oldtimer.geekstogo.com/TFC.exe
  • Stahnete a spustte
  • Kliknete na Start a potvrdte OK
  • Program uklidi a restartuje pc
  • Po pouziti utilitu smazte
:arrow: v nouzovem rezimu (restart PC, mackat F8, zvolit Stav nouze s praci v siti) projedte PC temito utilitami, at se zbavime zbytku antiviru co tam mate :arrow: Stahnete Ccleaner (viz muj podpis)
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: Nainstalujte Avast Free http://www.avast.com/cs-cz/free-antivirus-download

:arrow: Dejte novy log z RSIT a napiste jak se chova PC

Re: FB vir

Napsal: 29 srp 2011 12:01
od Kopecz
Logfile of random's system information tool 1.09 (written by random/random)
Run by admin at 2011-08-29 13:00:55
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 271 GB (90%) free of 300 GB
Total RAM: 3580 MB (52% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:00:58, on 29.8.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\trend micro\admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ˙ţ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {95289393-33EA-4F8D-B952-483415B9C955} - C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: Babylon-English Toolbar - {ce18769b-c7fa-42d2-860d-17c4662c70ad} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Babylon-English Toolbar - {ce18769b-c7fa-42d2-860d-17c4662c70ad} - (no file)
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\admin\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - (no file)
O9 - Extra button: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.5 - {7578ADEA-D65F-4C89-A249-B1C88B6FFC20} - C:\Program Files (x86)\ICQ7.5\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ES lite Service for program management. (ES lite Service) - Unknown owner - C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9684 bytes

======Listing Processes======

\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
atieclxx
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe"
"C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE"
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\PixArt\Pac207\Monitor.exe"
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe"
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe"
WLIDSvcM.exe 2340
KHALMNPR.EXE /API
"C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesApp64.exe" /TUStart /pid:2264
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel=3732.4ab77a0.1803570445 "C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll" Mozilla.Firefox.6.0 -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.jar" 3732 "\\.\pipe\gecko-crash-server-pipe.3732" plugin
C:\Windows\system32\msiexec.exe /V
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /welcome
"C:\Program Files\Windows Sidebar\sidebar.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\admin\Desktop\RSITx64.exe"

=========Mozilla firefox=========

ProfilePath - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\rwe7uvgb.default

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://www.seznam.cz/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=8]
"Description"=Google Update
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

C:\Program Files (x86)\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
flashplayer.xpt
nsIQTScriptablePlugin.xpt
Scriptff.dll

C:\Program Files (x86)\Mozilla Firefox\plugins\
np-mswmp.dll
np32dsw.dll
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
ShockwavePlugin.class
WMP Firefox Plugin License.rtf
WMP Firefox Plugin RelNotes.txt

C:\Program Files (x86)\Mozilla Firefox\searchplugins\
babylon.xml
fcmdSrchvsl.xml
google.xml
heureka-cz.xml
jyxo-cz.xml
seznam-cz.xml
slunecnice-cz.xml
wikipedia-cz.xml

C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\rwe7uvgb.default\extensions\
engine@conduit.com
{32a1fd71-835e-4b11-8e54-886fda0b4c89}
{7b13ec3e-999a-4b70-b9cb-2617b8323822}
{ACAA314B-EEBA-48e4-AD47-84E31C44796C}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
QIPBHO Class - C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-12-13 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
Babylon IE plugin

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2010-11-10 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\qipsearchbar.dll [2010-12-13 141184]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ce18769b-c7fa-42d2-860d-17c4662c70ad}]
Babylon-English Toolbar

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} -
{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2011-07-04 978496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{ce18769b-c7fa-42d2-860d-17c4662c70ad} -
{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - avast! WebRep - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2011-07-04 820864]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-06 10144288]
"Monitor"=C:\Windows\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2010-10-29 1680976]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2011-01-26 336384]
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2011-07-04 3493720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-03-29 249344]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorUser"=3
"EnableSecureUIAPaths"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2011-08-29 12:55:33 ----DC---- C:\rsit
2011-08-29 12:51:32 ----A---- C:\Windows\ntbtlog.txt
2011-08-29 12:51:30 ----A---- C:\Windows\system32\drivers\aswSP.sys
2011-08-29 12:51:30 ----A---- C:\Windows\system32\drivers\aswFsBlk.sys
2011-08-29 12:51:29 ----A---- C:\Windows\system32\drivers\aswTdi.sys
2011-08-29 12:51:29 ----A---- C:\Windows\system32\drivers\aswSnx.sys
2011-08-29 12:51:29 ----A---- C:\Windows\system32\drivers\aswRdr.sys
2011-08-29 12:51:28 ----A---- C:\Windows\system32\drivers\aswMonFlt.sys
2011-08-29 12:51:28 ----A---- C:\Windows\system32\aswBoot.exe
2011-08-29 12:51:24 ----A---- C:\Windows\SYSWOW64\aswBoot.exe
2011-08-29 12:51:24 ----A---- C:\Windows\avastSS.scr
2011-08-29 12:51:20 ----D---- C:\ProgramData\AVAST Software
2011-08-29 12:51:20 ----D---- C:\Program Files\AVAST Software
2011-08-29 12:45:42 ----D---- C:\Program Files\CCleaner
2011-08-29 12:26:43 ----D---- C:\Windows\LastGood
2011-08-29 12:20:47 ----SD---- C:\Windows\SYSWOW64\Microsoft
2011-08-29 12:11:55 ----SDC---- C:\Uninstall
2011-08-29 11:52:31 ----SHDC---- C:\$RECYCLE.BIN
2011-08-29 11:16:09 ----D---- C:\Windows\temp
2011-08-29 10:33:09 ----D---- C:\Windows\ERDNT
2011-08-29 09:39:07 ----D---- C:\Program Files\trend micro
2011-08-24 08:34:32 ----D---- C:\Windows\SYSWOW64\xlive
2011-08-24 08:34:15 ----A---- C:\Windows\SYSWOW64\tzres.dll
2011-08-24 08:34:15 ----A---- C:\Windows\system32\tzres.dll
2011-08-22 09:21:03 ----DC---- C:\$UPGRADE.~OS
2011-08-18 12:32:49 ----D---- C:\Program Files (x86)\Atari
2011-08-17 07:12:11 ----D---- C:\ProgramData\Electronic Arts
2011-08-15 20:10:51 ----D---- C:\Program Files (x86)\AVI to 3GP
2011-08-12 15:28:00 ----D---- C:\Program Files (x86)\Download Master
2011-08-12 15:26:35 ----D---- C:\Program Files (x86)\REDEMAX
2011-08-10 11:56:13 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2011-08-10 11:56:13 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2011-08-10 11:56:13 ----A---- C:\Windows\system32\mshtmled.dll
2011-08-10 11:56:13 ----A---- C:\Windows\system32\iertutil.dll
2011-08-10 11:56:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2011-08-10 11:56:12 ----A---- C:\Windows\SYSWOW64\url.dll
2011-08-10 11:56:12 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2011-08-10 11:56:12 ----A---- C:\Windows\SYSWOW64\jscript.dll
2011-08-10 11:56:12 ----A---- C:\Windows\SYSWOW64\ieui.dll
2011-08-10 11:56:12 ----A---- C:\Windows\system32\urlmon.dll
2011-08-10 11:56:12 ----A---- C:\Windows\system32\url.dll
2011-08-10 11:56:12 ----A---- C:\Windows\system32\jscript9.dll
2011-08-10 11:56:12 ----A---- C:\Windows\system32\jscript.dll
2011-08-10 11:56:12 ----A---- C:\Windows\system32\ieui.dll
2011-08-10 11:56:11 ----A---- C:\Windows\SYSWOW64\wininet.dll
2011-08-10 11:56:11 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2011-08-10 11:56:11 ----A---- C:\Windows\system32\wininet.dll
2011-08-10 11:56:11 ----A---- C:\Windows\system32\jsproxy.dll
2011-08-10 11:56:10 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2011-08-10 11:56:09 ----A---- C:\Windows\system32\mshtml.dll
2011-08-10 11:56:08 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2011-08-10 11:56:08 ----A---- C:\Windows\system32\ieframe.dll
2011-08-10 11:55:24 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2011-08-10 11:55:23 ----A---- C:\Windows\SYSWOW64\xmllite.dll
2011-08-10 11:55:23 ----A---- C:\Windows\system32\xmllite.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-10 11:55:22 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2011-08-10 11:55:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2011-08-10 11:55:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2011-08-10 11:55:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2011-08-10 11:55:22 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2011-08-10 11:55:22 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\wow64win.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\wow64cpu.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\wow64.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\winsrv.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\ntvdm64.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\KernelBase.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\kernel32.dll
2011-08-10 11:55:22 ----A---- C:\Windows\system32\conhost.exe
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2011-08-10 11:55:21 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2011-08-10 11:55:21 ----A---- C:\Windows\SYSWOW64\user.exe
2011-08-10 11:55:21 ----A---- C:\Windows\SYSWOW64\instnm.exe
2011-08-10 11:55:17 ----A---- C:\Windows\SYSWOW64\odbcjt32.dll
2011-08-10 11:55:17 ----A---- C:\Windows\SYSWOW64\odbccu32.dll
2011-08-10 11:55:17 ----A---- C:\Windows\SYSWOW64\odbccr32.dll
2011-08-10 11:55:17 ----A---- C:\Windows\system32\odbctrac.dll
2011-08-10 11:55:17 ----A---- C:\Windows\system32\odbccu32.dll
2011-08-10 11:55:17 ----A---- C:\Windows\system32\odbccr32.dll
2011-08-10 11:55:17 ----A---- C:\Windows\system32\odbccp32.dll
2011-08-10 11:55:16 ----A---- C:\Windows\SYSWOW64\odbctrac.dll
2011-08-10 11:55:16 ----A---- C:\Windows\SYSWOW64\odbccp32.dll
2011-08-10 11:55:15 ----A---- C:\Windows\system32\drivers\tcpip.sys
2011-08-10 11:55:14 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2011-08-10 11:55:13 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2011-08-10 11:55:13 ----A---- C:\Windows\system32\ntoskrnl.exe
2011-08-07 22:47:11 ----D---- C:\Program Files (x86)\K-Lite Codec Pack
2011-08-07 22:47:08 ----D---- C:\Program Files (x86)\YouTube Song Downloader
2011-08-07 22:39:54 ----D---- C:\ProgramData\TheManWithNoLife
2011-08-07 22:39:49 ----D---- C:\Program Files\TheManWithNoLife
2011-08-07 22:02:09 ----D---- C:\Users\admin\AppData\Roaming\DVDVideoSoftIEHelpers
2011-08-07 22:02:02 ----D---- C:\Program Files (x86)\DVDVideoSoft
2011-08-01 07:02:15 ----D---- C:\Users\admin\AppData\Roaming\Ventrilo

======List of files/folders modified in the last 1 month======

2011-08-29 12:52:46 ----D---- C:\Windows\system32\Tasks
2011-08-29 12:51:32 ----D---- C:\Windows
2011-08-29 12:51:30 ----D---- C:\Windows\system32\drivers
2011-08-29 12:51:28 ----SHD---- C:\Windows\Installer
2011-08-29 12:51:28 ----D---- C:\Windows\System32
2011-08-29 12:51:28 ----D---- C:\Config.Msi
2011-08-29 12:51:24 ----D---- C:\Windows\SysWOW64
2011-08-29 12:51:20 ----RD---- C:\Program Files
2011-08-29 12:51:20 ----D---- C:\ProgramData
2011-08-29 12:46:38 ----D---- C:\Users\admin\AppData\Roaming\uTorrent
2011-08-29 12:46:38 ----D---- C:\Users\admin\AppData\Roaming\Skype
2011-08-29 12:46:36 ----D---- C:\Windows\Logs
2011-08-29 12:46:36 ----D---- C:\Windows\debug
2011-08-29 12:39:41 ----D---- C:\Windows\system32\config
2011-08-29 12:24:48 ----RD---- C:\Program Files (x86)
2011-08-29 12:06:24 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2011-08-29 11:49:58 ----D---- C:\Windows\system32\drivers\etc
2011-08-29 11:43:13 ----AC---- C:\Windows\system.ini
2011-08-29 11:12:00 ----D---- C:\Windows\Tasks
2011-08-29 11:11:26 ----D---- C:\Program Files (x86)\Hot_MP3
2011-08-29 11:11:26 ----D---- C:\Program Files (x86)\HiGames
2011-08-29 11:11:26 ----D---- C:\Program Files (x86)\ConduitEngine
2011-08-29 11:10:05 ----D---- C:\Windows\SYSWOW64\drivers
2011-08-29 11:10:05 ----D---- C:\Windows\AppPatch
2011-08-29 11:10:02 ----D---- C:\Program Files\Common Files
2011-08-29 11:10:02 ----D---- C:\Program Files (x86)\Common Files
2011-08-29 10:40:26 ----D---- C:\Program Files (x86)\Digsby Donates
2011-08-29 10:24:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-08-29 09:11:36 ----D---- C:\Windows\Prefetch
2011-08-24 19:43:00 ----D---- C:\Windows\system32\catroot2
2011-08-24 08:54:26 ----D---- C:\Windows\Minidump
2011-08-24 08:45:56 ----D---- C:\Users\admin\AppData\Roaming\ICQ
2011-08-24 08:34:41 ----D---- C:\Windows\winsxs
2011-08-24 08:34:40 ----D---- C:\Windows\SYSWOW64\cs-CZ
2011-08-24 08:34:40 ----D---- C:\Windows\system32\cs-CZ
2011-08-24 08:34:32 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-08-24 08:33:54 ----D---- C:\Windows\system32\catroot
2011-08-21 18:42:33 ----D---- C:\Windows\system32\DriverStore
2011-08-21 18:42:33 ----D---- C:\Windows\inf
2011-08-21 18:42:32 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-08-21 18:07:19 ----D---- C:\Users\admin\AppData\Roaming\GetRightToGo
2011-08-18 14:15:02 ----D---- C:\Windows\SYSWOW64\directx
2011-08-18 13:20:37 ----RSD---- C:\Windows\assembly
2011-08-16 09:46:32 ----D---- C:\Program Files (x86)\Mp3 Knife
2011-08-15 07:14:20 ----D---- C:\Windows\system32\NDF
2011-08-12 13:38:17 ----D---- C:\Program Files (x86)\Farming Simulator 2011
2011-08-11 21:12:25 ----D---- C:\Users\admin\AppData\Roaming\Youtube to MP3 Converter
2011-08-11 08:14:53 ----D---- C:\Windows\Microsoft.NET
2011-08-10 18:27:32 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2011-08-10 12:02:20 ----D---- C:\Windows\SYSWOW64\migration
2011-08-10 12:02:20 ----D---- C:\Windows\system32\migration
2011-08-10 12:02:20 ----D---- C:\Program Files\Internet Explorer
2011-08-10 12:02:20 ----D---- C:\Program Files (x86)\Internet Explorer
2011-08-10 12:01:09 ----D---- C:\ProgramData\Microsoft Help
2011-08-10 11:59:26 ----A---- C:\Windows\system32\MRT.exe
2011-08-09 11:23:04 ----D---- C:\Program Files (x86)\TuneUp Utilities 2011
2011-08-03 21:01:02 ----D---- C:\Program Files (x86)\ICQ7.5
2011-08-01 08:34:41 ----D---- C:\ProgramData\Codemasters

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 16440]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-12-23 503352]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2010-04-27 21544]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2011-07-04 31064]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2011-07-04 288088]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2011-07-04 45400]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\drivers\aswFsBlk.sys [2011-07-04 22360]
R2 aswMonFlt;aswMonFlt; \??\C:\Windows\system32\drivers\aswMonFlt.sys [2011-07-04 64856]
R2 RMCAST;@%SystemRoot%\system32\wshrm.dll,-102; C:\Windows\system32\DRIVERS\RMCAST.sys [2010-11-20 146432]
R3 amdiox64;AMD IO Driver; C:\Windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2011-01-27 9085952]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2011-01-27 299520]
R3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2011-08-29 25640]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-04-06 2337440]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2011-04-30 76056]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2011-04-30 15128]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2011-04-30 66840]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2011-04-30 60184]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2011-02-23 82816]
R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2010-01-27 231328]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-22 347680]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [2011-02-10 11856]
S1 acedrv07;acedrv07; \??\C:\Windows\system32\drivers\acedrv07.sys [2011-01-22 125440]
S1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2011-07-04 600920]
S3 a0rlz59u;a0rlz59u; C:\Windows\system32\drivers\a0rlz59u.sys []
S3 AODDriver;AODDriver; \??\C:\Program Files (x86)\Gigabyte\ET6\amd64\AODDriver.sys [2010-03-12 52280]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2010-12-06 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2010-12-23 30528]
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2011-05-10 33344]
S3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2011-04-30 42776]
S3 PAC207;SoC PC-Camera; C:\Windows\system32\DRIVERS\PFC027.SYS [2006-12-05 572416]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2011-01-27 203776]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-01-26 354304]
R2 AMD Reservation Manager;AMD Reservation Manager; C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe [2010-06-17 194496]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2011-07-04 42184]
R2 ES lite Service;ES lite Service for program management.; C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
R2 ezGOSvc;Easybits GO Services for Windows; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files (x86)\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2011-07-20 2027840]
R2 UxTuneUp;@%SystemRoot%\System32\uxtuneup.dll,-4096; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-12-06 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------
PC běží naprosto v pohodě...děkuju moc!

Re: FB vir

Napsal: 29 srp 2011 17:28
od vyosek
:arrow: Jeste drobnosti, tam mame :)

:arrow: Otevrete si poznamkovy blok
  • Start->spustit->notepad
  • Vlozte text nize
  • Kód: Vybrat vše

    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
    "{ce18769b-c7fa-42d2-860d-17c4662c70ad}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{32099AAC-C132-4136-9E9A-4E364A424E17}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ce18769b-c7fa-42d2-860d-17c4662c70ad}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-
    4EA2-BC77-DFAAB78832CE}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95289393-33EA-4F8D-B952-483415B9C955}]
  • Soubor ulozte jako oprava.reg
  • Pri ukladani dejte ulozit jako typ Vsechny soubory (nastevni je uvedeno na obrazku nize)
  • Obrázek
  • Zavrit notepad a spustit dvojklikem oprava.reg
  • Pripadny dotaz na zmenu registru potvrdte
  • Okno jen problikne a opravi regsitry - soubor muzete smazat

Re: FB vir

Napsal: 29 srp 2011 17:36
od Kopecz
provedeno...diky moc za pomoc!

Re: FB vir

Napsal: 29 srp 2011 17:37
od vyosek
Nemate zac, rad jsem pomohl :worship: Zase nekdy Obrázek


A na rozloucenou Vam zahraje nase kapela :guitar: :150: :151: :152: :153: :154: :196: