Stránka 2 z 2

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 14:50
od Domeek
Tady je screenshot z Avastu, jsou to přesně ty soubory, o kterých jsem hovořil. Na usb discích ve složce, která nemá název. Divné. :shock:
avast.rar
(26.39 KiB) Staženo 34 x

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 15:01
od Domeek
Avastem jsem uvedené soubory zavřel po skenu do truhly.
Jeden jsem obnovil a projel na Virustotal, zde je výsledek
https://www.virustotal.com/file/e65c89e ... 360504557/

Screen z Huntera:
hunter.rar
(41.08 KiB) Staženo 39 x
Jinak ta "divna" slozka bez nazvu na usb discich, je jejich obsah pred zavirovanim.

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 15:19
od Domeek
Tady je obsah usb s breberkou.

http://leteckaposta.cz/643943823

Můžu usb disky naformátovat? Abych se podíval, zda když ho odpojím a pak zapojím nedostanu breberku zpátky.

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 15:32
od Domeek
USB disky naformátovány, odpojeny. Provedl jsem reset PC, připojil disky. Zatím se na ně nic nezapsalo. Provádím vakcinaci subfixem.

Po spuštění PC se pokouší nějaký instalátor spustit instalaci PhotoGallery, nevím o co se jedná a jaký proces to vše spouští. Můžeme na to mrknout?

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 15:39
od Domeek
Tady je požadovaný screen
Hunter_procesy.rar
(233.62 KiB) Staženo 27 x

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 15:48
od Domeek
Potíž je v tom, že to chce disk, a já žádný nemám. Zatím to tedy nechám, domluvím se s majitelem na co to používá.
Budeme ještě čistit, nebo už je to všechno? :)

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 16:03
od Domeek

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 16:32
od Domeek
Nový log RSIT:

Logfile of random's system information tool 1.09 (written by random/random)
Run by win-xp at 2013-02-10 16:31:04
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 55 GB (36%) free of 153 GB
Total RAM: 2046 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:31:08, on 10.2.2013
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\win-xp\Plocha\RSIT.exe
C:\Program Files\trend micro\win-xp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [LaunchList] D:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Rychlé spuštění aplikace HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype C2C Service - Skype Technologies S.A. - C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe

--
End of file - 6391 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2012-10-09 449512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2012-10-09 157672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-11-07 8523776]
"nwiz"=nwiz.exe /install []
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RemoteControl"=C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2003-10-31 32768]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-05-10 16342528]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-11-07 81920]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2004-02-12 49152]
"HP Component Manager"=C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [2004-05-12 241664]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2011-09-07 37296]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2012-12-03 946352]
"NPSStartup"= []
"avast"=C:\Program Files\AVAST Software\Avast\avastUI.exe [2012-10-30 4297136]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"LaunchList"=D:\Program Files\Pinnacle\Studio 11\LaunchList2.exe [2007-03-21 145496]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-11-05 68856]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2013-01-08 3674320]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk - D:\Program Files\Microsoft Office\Office\OSA9.EXE
Rychlé spuštění aplikace HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\59426988.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\59426988.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=0
"NoDriveAutoRun"=3

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=3
"NoDriveTypeAutoRun"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"VIDC.MJPG"=Pvmjpg30.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.LEAD"=LCODCCMP.DLL

======List of files/folders created in the last 1 month======

2013-02-10 15:32:15 ----RASHD---- C:\Autorun.inf
2013-02-10 14:09:33 ----A---- C:\TDSSKiller.2.8.15.0_10.02.2013_14.09.33_log.txt
2013-02-10 14:07:33 ----D---- C:\TDSSKiller_Quarantine
2013-02-10 14:05:50 ----A---- C:\TDSSKiller.2.8.15.0_10.02.2013_14.05.50_log.txt
2013-02-10 13:17:39 ----D---- C:\Documents and Settings\win-xp\Data aplikací\WinRAR
2013-02-10 13:17:34 ----D---- C:\Program Files\WinRAR
2013-02-10 10:41:16 ----A---- C:\UsbFix.txt
2013-02-10 10:41:14 ----D---- C:\UsbFix
2013-02-10 10:36:52 ----N---- C:\TDSSKiller.2.8.15.0_10.02.2013_10.36.52_log.txt
2013-02-10 10:17:12 ----D---- C:\_OTL
2013-02-10 10:14:59 ----D---- C:\WINDOWS\pss
2013-02-10 10:09:26 ----N---- C:\AdwCleaner[S1].txt
2013-02-10 10:08:49 ----N---- C:\AdwCleaner[R1].txt
2013-02-09 22:25:34 ----SHD---- C:\RECYCLER
2013-02-09 21:09:54 ----HD---- C:\WINDOWS\PIF
2013-02-09 20:27:35 ----D---- C:\WINDOWS\temp
2013-02-09 20:18:10 ----A---- C:\WINDOWS\zip.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\SWSC.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\SWREG.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\sed.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\PEV.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\NIRCMD.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\MBR.exe
2013-02-09 20:18:10 ----A---- C:\WINDOWS\grep.exe
2013-02-09 20:18:06 ----D---- C:\zmizik.com
2013-02-09 20:16:34 ----D---- C:\Qoobox
2013-02-09 20:16:25 ----D---- C:\WINDOWS\erdnt
2013-02-09 20:13:56 ----A---- C:\WINDOWS\system32\d3d9caps.dat
2013-02-09 20:13:29 ----D---- C:\WINDOWS\CSC
2013-02-09 19:16:19 ----N---- C:\PRIKAZ.TXT
2013-02-09 18:10:18 ----D---- C:\rsit
2013-02-09 18:10:18 ----D---- C:\Program Files\trend micro
2013-02-09 14:27:30 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2013-02-09 14:27:30 ----A---- C:\WINDOWS\system32\drivers\aswFsBlk.sys
2013-02-09 14:27:29 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2013-02-09 14:27:29 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2013-02-09 14:27:28 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2013-02-09 14:27:27 ----A---- C:\WINDOWS\system32\drivers\aswmon2.sys
2013-02-09 14:27:27 ----A---- C:\WINDOWS\system32\drivers\aswmon.sys
2013-02-09 14:27:27 ----A---- C:\WINDOWS\system32\drivers\aavmker4.sys
2013-02-09 14:27:12 ----A---- C:\WINDOWS\system32\aswBoot.exe
2013-02-09 14:27:12 ----A---- C:\WINDOWS\avastSS.scr
2013-02-09 14:26:58 ----D---- C:\Program Files\AVAST Software
2013-02-09 14:26:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\AVAST Software
2013-02-09 13:52:13 ----A---- C:\WINDOWS\SchedLgU.Txt
2013-02-09 12:33:47 ----D---- C:\lan
2013-02-09 12:09:21 ----D---- C:\Program Files\Defraggler
2013-02-09 12:06:58 ----A---- C:\WINDOWS\system32\drivers\HWiNFO32.SYS
2013-02-09 12:06:29 ----D---- C:\Program Files\HWiNFO32
2013-02-09 11:36:51 ----A---- C:\WINDOWS\system32\hidserv.dll
2013-02-09 11:36:48 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2013-02-07 20:33:08 ----D---- C:\WINDOWS\system32\CatRoot_bak
2013-02-07 20:02:17 ----A---- C:\WINDOWS\system32\drivers\dtsoftbus01.sys
2013-02-07 17:49:44 ----D---- C:\WINDOWS\Performance
2013-02-07 17:49:14 ----D---- C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2013-02-06 19:22:22 ----D---- C:\$WINDOWS.~BT
2013-02-06 18:32:53 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
2013-02-06 18:32:48 ----D---- C:\Documents and Settings\win-xp\Data aplikací\DAEMON Tools Lite
2013-02-06 18:32:44 ----D---- C:\Program Files\DAEMON Tools Lite
2013-02-06 18:31:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2013-02-05 16:20:17 ----D---- C:\Documents and Settings\win-xp\Data aplikací\searchresultstb
2013-02-04 14:25:39 ----AH---- C:\Documents and Settings\win-xp\Data aplikací\535gege44f.txt
2013-02-02 14:56:39 ----AH---- C:\Documents and Settings\win-xp\Data aplikací\88r8rrjejeue.txt
2013-02-01 18:52:29 ----AH---- C:\Documents and Settings\win-xp\Data aplikací\87g8gg8g8g8g7g.txt
2013-01-22 17:22:03 ----D---- C:\Program Files\1C
2013-01-19 17:02:05 ----D---- C:\Program Files\Tetris

======List of files/folders modified in the last 1 month======

2013-02-10 16:29:42 ----SHD---- C:\WINDOWS\Installer
2013-02-10 16:29:33 ----D---- C:\Windows
2013-02-10 16:12:00 ----A---- C:\WINDOWS\wincmd.ini
2013-02-10 15:49:21 ----D---- C:\Config.Msi
2013-02-10 15:39:40 ----D---- C:\WINDOWS\system32
2013-02-10 15:39:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2013-02-10 15:25:03 ----D---- C:\WINDOWS\system32\CatRoot2
2013-02-10 14:09:58 ----D---- C:\WINDOWS\Prefetch
2013-02-10 14:09:34 ----D---- C:\WINDOWS\system32\drivers
2013-02-10 13:17:34 ----D---- C:\Program Files
2013-02-09 21:04:23 ----D---- C:\WINDOWS\system32\drivers\etc
2013-02-09 21:03:51 ----SD---- C:\WINDOWS\Tasks
2013-02-09 21:03:08 ----D---- C:\WINDOWS\SoftwareDistribution
2013-02-09 21:02:32 ----A---- C:\WINDOWS\system.ini
2013-02-09 21:00:50 ----D---- C:\WINDOWS\system32\config
2013-02-09 20:25:53 ----D---- C:\WINDOWS\AppPatch
2013-02-09 20:25:52 ----D---- C:\Program Files\Common Files
2013-02-09 14:27:23 ----D---- C:\WINDOWS\WinSxS
2013-02-09 14:27:22 ----D---- C:\Program Files\Common Files\Microsoft Shared
2013-02-09 14:00:32 ----A---- C:\WINDOWS\NeroDigital.ini
2013-02-09 13:31:27 ----D---- C:\WINDOWS\Minidump
2013-02-09 13:31:27 ----D---- C:\WINDOWS\Debug
2013-02-09 12:08:42 ----D---- C:\Program Files\CCleaner
2013-02-09 11:36:57 ----RSHDC---- C:\WINDOWS\system32\dllcache
2013-02-07 21:15:21 ----HD---- C:\WINDOWS\inf
2013-02-07 21:09:18 ----D---- C:\WINDOWS\system32\CatRoot
2013-02-07 19:33:47 ----D---- C:\install
2013-02-07 18:30:08 ----D---- C:\Program Files\Java
2013-02-07 18:30:08 ----D---- C:\Program Files\Internet Explorer
2013-02-07 18:30:08 ----D---- C:\Program Files\HP
2013-02-07 18:30:08 ----D---- C:\Program Files\Hewlett-Packard
2013-02-07 18:30:07 ----D---- C:\Program Files\Google
2013-02-07 18:30:07 ----D---- C:\Program Files\ESET
2013-02-07 18:30:07 ----D---- C:\Program Files\DIFX
2013-02-07 18:30:07 ----D---- C:\Program Files\CyberLink
2013-02-07 18:30:07 ----D---- C:\Program Files\ComPlus Applications
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\System
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Symantec Shared
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\SpeechEngines
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Skype
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Services
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\ODBC
2013-02-07 18:30:07 ----D---- C:\Program Files\Common Files\Nero
2013-02-07 18:30:06 ----D---- C:\Program Files\Realtek
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\MSSoap
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\Java
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\InstallShield
2013-02-07 18:30:06 ----D---- C:\Program Files\Common Files\HP
2013-02-07 18:30:05 ----D---- C:\Program Files\proDAD
2013-02-07 18:30:05 ----D---- C:\Program Files\Pinnacle
2013-02-07 18:30:05 ----D---- C:\Program Files\PC Connectivity Solution
2013-02-07 18:30:05 ----D---- C:\Program Files\Outlook Express
2013-02-07 18:30:05 ----D---- C:\Program Files\Online Services
2013-02-07 18:30:05 ----D---- C:\Program Files\NOS
2013-02-07 18:30:05 ----D---- C:\Program Files\Norton Security Scan
2013-02-07 18:30:05 ----D---- C:\Program Files\NetMeeting
2013-02-07 18:30:05 ----D---- C:\Program Files\MSN Gaming Zone
2013-02-07 18:30:05 ----D---- C:\Program Files\Movie Maker
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Designer
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Ahead
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Adobe AIR
2013-02-07 18:30:05 ----D---- C:\Program Files\Common Files\Adobe
2013-02-07 18:30:05 ----D---- C:\Program Files\CDex_150
2013-02-07 18:30:05 ----D---- C:\Program Files\BIAS
2013-02-07 18:30:05 ----D---- C:\Program Files\Ahead
2013-02-07 18:30:04 ----D---- C:\Program Files\microsoft frontpage
2013-02-07 18:30:04 ----D---- C:\Program Files\Messenger
2013-02-07 18:30:04 ----D---- C:\Program Files\MarkAny
2013-02-07 18:30:04 ----D---- C:\Program Files\Adobe
2013-02-07 18:30:03 ----D---- C:\Program Files\Yahoo!
2013-02-07 18:30:03 ----D---- C:\Program Files\xerox
2013-02-07 18:30:03 ----D---- C:\Program Files\Windows NT
2013-02-07 18:30:03 ----D---- C:\Program Files\Windows Media Player
2013-02-07 18:30:02 ----RD---- C:\Program Files\Skype
2013-02-07 18:30:02 ----D---- C:\Program Files\Video Converter Fox
2013-02-07 18:30:02 ----D---- C:\Program Files\Samsung
2013-02-07 17:58:46 ----RSD---- C:\WINDOWS\assembly
2013-02-07 17:47:33 ----D---- C:\WINDOWS\pchealth
2013-02-06 19:37:03 ----D---- C:\WINDOWS\Microsoft.NET
2013-02-05 16:06:06 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2013-02-01 19:05:38 ----A---- C:\WINDOWS\win.ini
2013-01-27 20:46:24 ----D---- C:\Documents and Settings\win-xp\Data aplikací\Skype
2013-01-26 09:52:34 ----HD---- C:\Program Files\InstallShield Installation Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2013-02-06 466008]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2012-10-30 25256]
R1 AswRdr;aswRdr; C:\WINDOWS\system32\drivers\AswRdr.sys [2012-10-30 35928]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2012-10-30 738504]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2012-10-30 361032]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2012-10-30 54232]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\system32\DRIVERS\dtsoftbus01.sys [2013-02-07 242240]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\WINDOWS\system32\drivers\HWiNFO32.SYS []
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2012-10-30 21256]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2012-10-30 97608]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-05-10 4419584]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2007-01-04 171520]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-11-07 7429088]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-12-14 85120]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 a9qmkbm3;a9qmkbm3; C:\WINDOWS\system32\drivers\a9qmkbm3.sys []
S3 catchme;catchme; \??\C:\DOCUME~1\win-xp\LOCALS~1\Temp\catchme.sys []
S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2004-06-21 51088]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2004-06-21 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2004-06-21 21744]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 RPHook;RPHook; \??\C:\DOCUME~1\win-xp\LOCALS~1\Temp\drv2 []
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-10-30 44808]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre7\bin\jqs.exe [2012-10-09 161768]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-11-07 155716]
R2 Skype C2C Service;Skype C2C Service; C:\Documents and Settings\All Users\Data aplikací\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-12-13 3290896]
R2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2012-11-09 160944]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
S2 PCLEPCI;PCLEPCI; C:\WINDOWS\system32\drivers\pclepci.sys [2005-02-09 14165]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2012-04-17 116648]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-03-18 65536]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]

-----------------EOF-----------------

Re: Zavirovaný PC, Autorun,inf

Napsal: 10 úno 2013 16:57
od Domeek
Děkuji Vám za pomoc, kdyby se ještě něco našlo, dám vědět. :worship: :)