Ještě přidávám zprávu z RogueKiller:
RogueKiller V8.4.3 [Jan 24 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Podpora :
http://www.geekstogo.com/forum/files/fi ... guekiller/
Webové stránky :
http://tigzy.geekstogo.com/roguekiller.php
:
http://tigzyrk.blogspot.com/
Operační systém : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Spuštěno v : Normální režim
Uživatel : janl [Práva správce]
Mód : Kontrola -- Datum : 01/25/2013 12:50:30
| ARK || MBR |
¤¤¤ Škodlivé procesy: : 0 ¤¤¤
¤¤¤ ¤¤¤ Záznamy Registrů: : 8 ¤¤¤
[RUN][BLACKLISTDLL] HKLM\[...]\Run : NVHotkey (rundll32.exe C:\Windows\system32\nvHotkey.dll,Start) -> NALEZENO
[PROXY FF] h9gibfmw.default\ 192.168.1.20:8080 -> NALEZENO
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> NALEZENO
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> NALEZENO
[HJ] HKLM\[...]\System : EnableLUA (0) -> NALEZENO
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> NALEZENO
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> NALEZENO
¤¤¤ Zvláštní soubory / Složky: ¤¤¤
¤¤¤ Ovladač : [NAHRÁNO] ¤¤¤
SSDT[13] : NtAlertResumeThread @ 0x834F1C99 -> HOOKED (Unknown @ 0x87799A90)
SSDT[14] : NtAlertThread @ 0x83444BE0 -> HOOKED (Unknown @ 0x87826710)
SSDT[19] : NtAllocateVirtualMemory @ 0x8343DBEC -> HOOKED (Unknown @ 0x87555B78)
SSDT[59] : ExpInterlockedPopEntrySListResume @ 0x8348BF59 -> HOOKED (Unknown @ 0x876F6588)
SSDT[74] : NtCreateMutant @ 0x834242B2 -> HOOKED (Unknown @ 0x878DC340)
SSDT[87] : NtCreateThread @ 0x834EFECA -> HOOKED (Unknown @ 0x8758FC28)
SSDT[131] : NtFreeVirtualMemory @ 0x832CBAEC -> HOOKED (Unknown @ 0x878DD5D8)
SSDT[145] : NtImpersonateAnonymousToken @ 0x834098E0 -> HOOKED (Unknown @ 0x87833198)
SSDT[147] : NtImpersonateThread @ 0x8348D84C -> HOOKED (Unknown @ 0x878645C0)
SSDT[168] : NtMapViewOfSection @ 0x8345A532 -> HOOKED (Unknown @ 0x878DCC18)
SSDT[177] : NtOpenEvent @ 0x83423CAE -> HOOKED (Unknown @ 0x87804BE0)
SSDT[191] : NtOpenProcessToken @ 0x8347823F -> HOOKED (Unknown @ 0x87804668)
SSDT[199] : NtOpenThreadToken @ 0x8348C534 -> HOOKED (Unknown @ 0x878DCF38)
SSDT[304] : NtResumeThread @ 0x83484592 -> HOOKED (Unknown @ 0x87785B38)
SSDT[316] : NtSetContextThread @ 0x834F1745 -> HOOKED (Unknown @ 0x87785668)
SSDT[333] : NtSetInformationProcess @ 0x8344C78D -> HOOKED (Unknown @ 0x878B8440)
SSDT[335] : NtSetInformationThread @ 0x8347DCF6 -> HOOKED (Unknown @ 0x878DD270)
SSDT[366] : NtSuspendProcess @ 0x834F1BD3 -> HOOKED (Unknown @ 0x878177B8)
SSDT[367] : NtSuspendThread @ 0x834A9085 -> HOOKED (Unknown @ 0x877BEBE0)
SSDT[370] : NtTerminateProcess @ 0x8346EBFB -> HOOKED (Unknown @ 0x877D1BE0)
SSDT[371] : NtTerminateThread @ 0x8348C584 -> HOOKED (Unknown @ 0x8778EB38)
SSDT[385] : NtUnmapViewOfSection @ 0x8347887A -> HOOKED (Unknown @ 0x8782E710)
SSDT[399] : NtWriteVirtualMemory @ 0x83473958 -> HOOKED (Unknown @ 0x874DC5D8)
¤¤¤ Soubor HOSTS: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ Kontrola MBR: ¤¤¤
+++++ PhysicalDrive0: ST9160823ASG +++++
--- User ---
[MBR] 340324534f7b63acbd8cf92a4eab84ac
[BSP] 4258a8f73dc6a0bf5c3166438fd3bb07 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 133 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 273105 | Size: 152491 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Dokončeno : << RKreport[1]_S_01252013_02d1250.txt >>
RKreport[1]_S_01252013_02d1250.txt