Stránka 2 z 2

Re: Policejni vir

Napsal: 25 pro 2013 08:54
od Márty84
:!: Pokud nemate, zazalohujte si radeji dulezita data (fotky, dokumenty, atd.) :!:

:!: Nepouzivejte ComboFix bez predchozi domluvy! Je to poruseni pravidel fora a ztratite tim narok na pomoc!

:arrow: Stahnete ComboFix http://download.bleepingcomputer.com/sUBs/ComboFix.exe a ulozte ho na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte ComboFix.
Odsouhlaste licencni podminky a nechte program pracovat. Jestli vam nabidne instalaci Konzoly pro zotaveni, souhlaste.
Po dobu skenu nic nespoustejte, nikam neklikejte.
Po dokonceni skenovani (muze dojit i k restartu pc) by se mel vytvorit log, ktery bude umisteny zde C:\ComboFix.txt
Jeho obsah sem zkopirujte

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku

Re: Policejni vir

Napsal: 25 pro 2013 10:21
od jaroslav.24
tady je ale trvalo to strašně dlouho

ComboFix 13-12-24.02 - Kryton 25.12.2013 10:10:30.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.446.218 [GMT 1:00]
Spuštěný z: c:\documents and settings\Kryton\Plocha\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Kryton\WINDOWS
c:\windows\iun6002.exe
c:\windows\system32\Drivers\afd.sys.bak
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-25 do 2013-12-25 )))))))))))))))))))))))))))))))
.
.
2013-12-24 11:56 . 2013-12-24 14:51 -------- d-----w- C:\AdwCleaner
2013-12-24 08:01 . 2013-12-24 08:01 -------- d-----w- c:\documents and settings\Kryton\Data aplikací\Malwarebytes
2013-12-24 08:00 . 2013-12-24 08:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2013-12-24 08:00 . 2013-12-24 08:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-12-24 08:00 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-24 07:47 . 2013-12-24 07:47 -------- d-----w- c:\program files\trend micro
2013-12-24 07:31 . 2013-12-24 07:31 -------- d-----w- C:\rsit
2013-12-22 05:55 . 2013-12-22 05:55 -------- d-----w- c:\documents and settings\Kryton\Data aplikací\AVAST Software
2013-12-22 05:54 . 2013-12-22 13:14 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-22 05:54 . 2013-12-22 13:14 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-22 05:54 . 2013-12-22 13:14 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-22 05:54 . 2013-12-22 05:54 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-12-22 05:54 . 2013-12-22 13:14 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-22 05:54 . 2013-12-22 13:14 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-22 05:54 . 2013-12-22 13:14 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-12-22 05:54 . 2013-12-22 13:14 270240 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-22 05:54 . 2013-12-22 13:14 43152 ----a-w- c:\windows\avastSS.scr
2013-12-22 05:53 . 2013-12-22 05:53 -------- d-----w- c:\program files\AVAST Software
2013-12-21 17:25 . 2013-12-21 17:25 45089 ----a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\1387646732.bdinstall.bin
2013-12-21 15:19 . 2013-12-21 15:19 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Common Files
2013-12-21 15:18 . 2013-12-21 15:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\MFAData
2013-12-21 15:18 . 2013-12-21 15:18 -------- d-----w- c:\documents and settings\Kryton\Local Settings\Data aplikací\MFAData
2013-12-21 15:18 . 2013-12-21 15:18 -------- d-----w- c:\documents and settings\Kryton\Local Settings\Data aplikací\Avg2014
2013-12-21 10:05 . 2013-12-21 10:05 -------- d-----w- c:\program files\VS Revo Group
2013-12-20 17:18 . 2013-12-20 17:18 -------- d-----w- C:\sh4ldr
2013-12-20 17:17 . 2013-12-20 17:18 -------- d-----w- c:\windows\A358F2F62500420C989C25C4F22DF51E.TMP
2013-12-20 17:17 . 2013-12-20 17:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2013-12-20 16:10 . 2013-12-20 16:11 -------- d-----w- c:\documents and settings\Kryton\Local Settings\Data aplikací\CRE
2013-12-20 13:00 . 2013-12-20 13:02 -------- d-----w- c:\program files\Google
2013-12-08 15:15 . 2013-12-08 15:23 -------- d-----w- c:\program files\Simutrans
2013-12-06 16:01 . 2013-12-06 16:01 -------- d-----w- C:\Games
2013-12-06 06:00 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-25 07:21 . 2013-12-24 14:58 82944 ----a-w- c:\windows\system32\drivers\wdmaud.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4352 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 79744 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 52480 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 34560 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 20992 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 58112 ----a-w- c:\windows\system32\drivers\vdmindvd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 26496 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2013-12-25 07:21 . 2013-12-24 14:58 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 17024 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 142976 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 57600 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 26624 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 16000 ----a-w- c:\windows\system32\drivers\usbintel.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4736 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 23936 ----a-w- c:\windows\system32\drivers\usbcamd2.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 66176 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 23808 ----a-w- c:\windows\system32\drivers\usbcamd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 209408 ----a-w- c:\windows\system32\drivers\update.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12672 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12416 ----a-w- c:\windows\system32\drivers\tunmp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 21376 ----a-w- c:\windows\system32\drivers\tsbvcap.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 51712 ----a-w- c:\windows\system32\drivers\tosdvd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 40840 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 21896 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 18560 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12040 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 359040 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 223616 ----a-w- c:\windows\system32\drivers\tcpip6.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 185824 ----a-w- c:\windows\system32\drivers\SynTP.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 14976 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 48640 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4352 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 336256 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 13312 ----a-w- c:\windows\system32\drivers\srvkp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 96256 ----a-w- c:\windows\system32\drivers\sptd7533.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 73344 ----a-w- c:\windows\system32\drivers\sr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 664064 ----a-w- c:\windows\system32\drivers\sptd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 6400 ----a-w- c:\windows\system32\drivers\splitter.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 25472 ----a-w- c:\windows\system32\drivers\sonydcam.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 32768 ----a-w- c:\windows\system32\drivers\sisnicxp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 32768 ----a-w- c:\windows\system32\drivers\sisnic.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 14592 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 36992 ----a-w- c:\windows\system32\drivers\SISAGPX.SYS.bak
2013-12-25 07:21 . 2013-12-24 14:58 240640 ----a-w- c:\windows\system32\drivers\sisgrp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 11392 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 64640 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 11136 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 10240 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 15488 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 96256 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 67584 ----a-w- c:\windows\system32\drivers\sdbus.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 11973 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 344064 ----a-w- c:\windows\system32\drivers\rt73.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 5888 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 30080 ----a-w- c:\windows\system32\drivers\rndismp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 200064 ----a-w- c:\windows\system32\drivers\RMCast.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 58240 ----a-w- c:\windows\system32\drivers\redbook.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\riodrv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\rio8drv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4224 ----a-w- c:\windows\system32\drivers\rdpcdd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 196864 ----a-w- c:\windows\system32\drivers\rdpdr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 176512 ----a-w- c:\windows\system32\drivers\rdbss.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 139400 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 34432 ----a-w- c:\windows\system32\drivers\rawwan.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 16512 ----a-w- c:\windows\system32\drivers\raspti.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 48384 ----a-w- c:\windows\system32\drivers\raspptp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 8832 ----a-w- c:\windows\system32\drivers\rasacd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 51328 ----a-w- c:\windows\system32\drivers\rasl2tp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 69120 ----a-w- c:\windows\system32\drivers\psched.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 17792 ----a-w- c:\windows\system32\drivers\ptilink.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 39168 ----a-w- c:\windows\system32\drivers\processr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 145792 ----a-w- c:\windows\system32\drivers\portcls.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 119808 ----a-w- c:\windows\system32\drivers\pcmcia.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 68736 ----a-w- c:\windows\system32\drivers\pci.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 6784 ----a-w- c:\windows\system32\drivers\parvdm.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 3328 ----a-w- c:\windows\system32\drivers\pciide.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 25088 ----a-w- c:\windows\system32\drivers\pciidex.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 18688 ----a-w- c:\windows\system32\drivers\partmgr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 80000 ----a-w- c:\windows\system32\drivers\parport.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 46336 ----a-w- c:\windows\system32\drivers\p3.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 3456 ----a-w- c:\windows\system32\drivers\oprghdlr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 163584 ----a-w- c:\windows\system32\drivers\nwrdr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 88448 ----a-w- c:\windows\system32\drivers\nwlnkipx.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 63232 ----a-w- c:\windows\system32\drivers\nwlnknb.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 55936 ----a-w- c:\windows\system32\drivers\nwlnkspx.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 32512 ----a-w- c:\windows\system32\drivers\nwlnkfwd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 2944 ----a-w- c:\windows\system32\drivers\null.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12416 ----a-w- c:\windows\system32\drivers\nwlnkflt.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 574592 ----a-w- c:\windows\system32\drivers\ntfs.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 40320 ----a-w- c:\windows\system32\drivers\nmnt.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 30848 ----a-w- c:\windows\system32\drivers\npfs.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 61824 ----a-w- c:\windows\system32\drivers\nic1394.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\nikedrv.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-22 13:14 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSPower"="SiSPower.dll" [2013-08-19 49152]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
"SoundMan"="SOUNDMAN.EXE" [2013-08-19 77824]
"AGRSMMSG"="AGRSMMSG.exe" [2013-08-20 88363]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2013-08-20 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2013-08-20 688218]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-11-08 128920]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-22 3764024]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Kryton\\Plocha\\DOTA\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\ICQ7.7\\ICQ.exe"=
"c:\\Program Files\\Black Isle\\Lionheart\\Lionheart.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [22.12.2013 6:54 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [22.12.2013 6:54 180248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.8.2013 11:17 664064]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [22.12.2013 6:54 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [22.12.2013 6:54 410528]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [22.12.2013 6:54 67824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-20 13:02 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-22 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-22 13:14]
.
2013-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-20 13:00]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Kryton\Nabídka Start\Programy\IMVU\Run IMVU.lnk
TCP: DhcpNameServer = 109.238.32.52 8.8.8.8
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-Cool's_Codec_pack_4.12 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-12-25 10:17
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrueSight]
"ImagePath"="\??\"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Celkový čas: 2013-12-25 10:19:28
ComboFix-quarantined-files.txt 2013-12-25 09:19
.
Před spuštěním: Volných bajtů: 44 123 635 712
Po spuštění: Volných bajtů: 44 100 714 496
.
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - B449173C98F3EA15EEB980862512C36F
413FC2A0C716421B3158746D63736515

Re: Policejni vir

Napsal: 25 pro 2013 12:09
od Márty84
:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

KillAll::

File::
c:\windows\A358F2F62500420C989C25C4F22DF51E.TMP
c:\windows\Tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job

Folder::
c:\documents and settings\Kryton\Local Settings\Data aplikací\Avg2014

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=-
"Adobe ARM"=-

RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

Driver::
gupdate
gupdatem

Reboot::
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev CFScript a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Pretahntete mysi tento vytvoreny textovy dokument nad ikonu ComboFix a pustte.
ComboFix by se mel spustit a vykonat prikazy.
Az skonci (muze dojit k restartu pc), mel by se objevit novy log, ten mi sem zase zkopirujte.

:!: Kdyby po restartu nenabehl windows, restartujte znovu, mackejte klavesu F8 a zvolte - Posledni znama funkcni konfigurace
:!: Kdyz windows nabehne, ale pri spousteni ruznych programu bude hlasena chyba, staci restartovat pc a bude to v poradku

Re: Policejni vir

Napsal: 25 pro 2013 16:26
od jaroslav.24
Vůbec si nejsem jist že to fungovalo. normálně to prohledalo počítač, jako před tím

ComboFix 13-12-24.02 - Kryton 25.12.2013 16:10:12.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.446.279 [GMT 1:00]
Spuštěný z: c:\documents and settings\Kryton\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Kryton\Plocha\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\windows\A358F2F62500420C989C25C4F22DF51E.TMP"
"c:\windows\Tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job"
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2013-11-25 do 2013-12-25 )))))))))))))))))))))))))))))))
.
.
2013-12-24 11:56 . 2013-12-24 14:51 -------- d-----w- C:\AdwCleaner
2013-12-24 08:01 . 2013-12-24 08:01 -------- d-----w- c:\documents and settings\Kryton\Data aplikací\Malwarebytes
2013-12-24 08:00 . 2013-12-24 08:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2013-12-24 08:00 . 2013-12-24 08:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-12-24 08:00 . 2013-04-04 13:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-12-24 07:47 . 2013-12-24 07:47 -------- d-----w- c:\program files\trend micro
2013-12-24 07:31 . 2013-12-24 07:31 -------- d-----w- C:\rsit
2013-12-22 05:55 . 2013-12-22 05:55 -------- d-----w- c:\documents and settings\Kryton\Data aplikací\AVAST Software
2013-12-22 05:54 . 2013-12-22 13:14 57672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-12-22 05:54 . 2013-12-22 13:14 410528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-12-22 05:54 . 2013-12-22 13:14 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-12-22 05:54 . 2013-12-22 05:54 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-12-22 05:54 . 2013-12-22 13:14 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-12-22 05:54 . 2013-12-22 13:14 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-12-22 05:54 . 2013-12-22 13:14 54832 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-12-22 05:54 . 2013-12-22 13:14 270240 ----a-w- c:\windows\system32\aswBoot.exe
2013-12-22 05:54 . 2013-12-22 13:14 43152 ----a-w- c:\windows\avastSS.scr
2013-12-22 05:53 . 2013-12-22 05:53 -------- d-----w- c:\program files\AVAST Software
2013-12-21 17:25 . 2013-12-21 17:25 45089 ----a-w- c:\documents and settings\All Users.WINDOWS\Data aplikací\1387646732.bdinstall.bin
2013-12-21 15:19 . 2013-12-21 15:19 -------- d--h--w- c:\documents and settings\All Users.WINDOWS\Data aplikací\Common Files
2013-12-21 15:18 . 2013-12-21 15:20 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Data aplikací\MFAData
2013-12-21 15:18 . 2013-12-21 15:18 -------- d-----w- c:\documents and settings\Kryton\Local Settings\Data aplikací\MFAData
2013-12-21 15:18 . 2013-12-21 15:18 -------- d-----w- c:\documents and settings\Kryton\Local Settings\Data aplikací\Avg2014
2013-12-21 10:05 . 2013-12-21 10:05 -------- d-----w- c:\program files\VS Revo Group
2013-12-20 17:18 . 2013-12-20 17:18 -------- d-----w- C:\sh4ldr
2013-12-20 17:17 . 2013-12-20 17:18 -------- d-----w- c:\windows\A358F2F62500420C989C25C4F22DF51E.TMP
2013-12-20 17:17 . 2013-12-20 17:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2013-12-20 16:10 . 2013-12-20 16:11 -------- d-----w- c:\documents and settings\Kryton\Local Settings\Data aplikací\CRE
2013-12-20 13:00 . 2013-12-20 13:02 -------- d-----w- c:\program files\Google
2013-12-08 15:15 . 2013-12-08 15:23 -------- d-----w- c:\program files\Simutrans
2013-12-06 16:01 . 2013-12-06 16:01 -------- d-----w- C:\Games
2013-12-06 06:00 . 1998-10-29 15:45 306688 ----a-w- c:\windows\IsUninst.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-12-25 07:21 . 2013-12-24 14:58 82944 ----a-w- c:\windows\system32\drivers\wdmaud.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4352 ----a-w- c:\windows\system32\drivers\wmilib.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\ws2ifsl.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 79744 ----a-w- c:\windows\system32\drivers\videoprt.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 52480 ----a-w- c:\windows\system32\drivers\volsnap.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 34560 ----a-w- c:\windows\system32\drivers\wanarp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 20992 ----a-w- c:\windows\system32\drivers\vga.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 58112 ----a-w- c:\windows\system32\drivers\vdmindvd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 26496 ----a-w- c:\windows\system32\drivers\USBSTOR.SYS.bak
2013-12-25 07:21 . 2013-12-24 14:58 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 17024 ----a-w- c:\windows\system32\drivers\usbohci.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 142976 ----a-w- c:\windows\system32\drivers\usbport.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 57600 ----a-w- c:\windows\system32\drivers\usbhub.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 26624 ----a-w- c:\windows\system32\drivers\usbehci.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 16000 ----a-w- c:\windows\system32\drivers\usbintel.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4736 ----a-w- c:\windows\system32\drivers\usbd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 23936 ----a-w- c:\windows\system32\drivers\usbcamd2.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 66176 ----a-w- c:\windows\system32\drivers\udfs.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 23808 ----a-w- c:\windows\system32\drivers\usbcamd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 209408 ----a-w- c:\windows\system32\drivers\update.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12672 ----a-w- c:\windows\system32\drivers\usb8023.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12416 ----a-w- c:\windows\system32\drivers\tunmp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 21376 ----a-w- c:\windows\system32\drivers\tsbvcap.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 51712 ----a-w- c:\windows\system32\drivers\tosdvd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 40840 ----a-w- c:\windows\system32\drivers\termdd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 21896 ----a-w- c:\windows\system32\drivers\tdtcp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 18560 ----a-w- c:\windows\system32\drivers\tdi.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12040 ----a-w- c:\windows\system32\drivers\tdpipe.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 359040 ----a-w- c:\windows\system32\drivers\tcpip.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 223616 ----a-w- c:\windows\system32\drivers\tcpip6.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 185824 ----a-w- c:\windows\system32\drivers\SynTP.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 14976 ----a-w- c:\windows\system32\drivers\tape.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 48640 ----a-w- c:\windows\system32\drivers\stream.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4352 ----a-w- c:\windows\system32\drivers\swenum.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 336256 ----a-w- c:\windows\system32\drivers\srv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 13312 ----a-w- c:\windows\system32\drivers\srvkp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 96256 ----a-w- c:\windows\system32\drivers\sptd7533.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 73344 ----a-w- c:\windows\system32\drivers\sr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 664064 ----a-w- c:\windows\system32\drivers\sptd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 6400 ----a-w- c:\windows\system32\drivers\splitter.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 25472 ----a-w- c:\windows\system32\drivers\sonydcam.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 32768 ----a-w- c:\windows\system32\drivers\sisnicxp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 32768 ----a-w- c:\windows\system32\drivers\sisnic.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 14592 ----a-w- c:\windows\system32\drivers\smclib.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 36992 ----a-w- c:\windows\system32\drivers\SISAGPX.SYS.bak
2013-12-25 07:21 . 2013-12-24 14:58 240640 ----a-w- c:\windows\system32\drivers\sisgrp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 11392 ----a-w- c:\windows\system32\drivers\sfloppy.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 64640 ----a-w- c:\windows\system32\drivers\serial.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 11136 ----a-w- c:\windows\system32\drivers\sffdisk.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 10240 ----a-w- c:\windows\system32\drivers\sffp_sd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 15488 ----a-w- c:\windows\system32\drivers\serenum.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 96256 ----a-w- c:\windows\system32\drivers\scsiport.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 67584 ----a-w- c:\windows\system32\drivers\sdbus.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 11973 ----a-w- c:\windows\system32\drivers\secdrv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 344064 ----a-w- c:\windows\system32\drivers\rt73.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 5888 ----a-w- c:\windows\system32\drivers\rootmdm.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 30080 ----a-w- c:\windows\system32\drivers\rndismp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 200064 ----a-w- c:\windows\system32\drivers\RMCast.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 58240 ----a-w- c:\windows\system32\drivers\redbook.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\riodrv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\rio8drv.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 4224 ----a-w- c:\windows\system32\drivers\rdpcdd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 196864 ----a-w- c:\windows\system32\drivers\rdpdr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 176512 ----a-w- c:\windows\system32\drivers\rdbss.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 139400 ----a-w- c:\windows\system32\drivers\rdpwd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 34432 ----a-w- c:\windows\system32\drivers\rawwan.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 16512 ----a-w- c:\windows\system32\drivers\raspti.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 48384 ----a-w- c:\windows\system32\drivers\raspptp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 8832 ----a-w- c:\windows\system32\drivers\rasacd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 51328 ----a-w- c:\windows\system32\drivers\rasl2tp.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 41472 ----a-w- c:\windows\system32\drivers\raspppoe.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 69120 ----a-w- c:\windows\system32\drivers\psched.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 17792 ----a-w- c:\windows\system32\drivers\ptilink.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 39168 ----a-w- c:\windows\system32\drivers\processr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 145792 ----a-w- c:\windows\system32\drivers\portcls.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 119808 ----a-w- c:\windows\system32\drivers\pcmcia.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 68736 ----a-w- c:\windows\system32\drivers\pci.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 6784 ----a-w- c:\windows\system32\drivers\parvdm.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 3328 ----a-w- c:\windows\system32\drivers\pciide.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 25088 ----a-w- c:\windows\system32\drivers\pciidex.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 18688 ----a-w- c:\windows\system32\drivers\partmgr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 80000 ----a-w- c:\windows\system32\drivers\parport.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 46336 ----a-w- c:\windows\system32\drivers\p3.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 3456 ----a-w- c:\windows\system32\drivers\oprghdlr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 163584 ----a-w- c:\windows\system32\drivers\nwrdr.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 88448 ----a-w- c:\windows\system32\drivers\nwlnkipx.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 63232 ----a-w- c:\windows\system32\drivers\nwlnknb.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 55936 ----a-w- c:\windows\system32\drivers\nwlnkspx.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 32512 ----a-w- c:\windows\system32\drivers\nwlnkfwd.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 2944 ----a-w- c:\windows\system32\drivers\null.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12416 ----a-w- c:\windows\system32\drivers\nwlnkflt.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 574592 ----a-w- c:\windows\system32\drivers\ntfs.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 40320 ----a-w- c:\windows\system32\drivers\nmnt.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 30848 ----a-w- c:\windows\system32\drivers\npfs.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 61824 ----a-w- c:\windows\system32\drivers\nic1394.sys.bak
2013-12-25 07:21 . 2013-12-24 14:58 12032 ----a-w- c:\windows\system32\drivers\nikedrv.sys.bak
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-12-22 13:14 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSPower"="SiSPower.dll" [2013-08-19 49152]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
"SoundMan"="SOUNDMAN.EXE" [2013-08-19 77824]
"AGRSMMSG"="AGRSMMSG.exe" [2013-08-20 88363]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2013-08-20 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2013-08-20 688218]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
"CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2013-12-22 3764024]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Kryton\\Plocha\\DOTA\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\ICQ7.7\\ICQ.exe"=
"c:\\Program Files\\Black Isle\\Lionheart\\Lionheart.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
.
R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [22.12.2013 6:54 49944]
R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [22.12.2013 6:54 180248]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.8.2013 11:17 664064]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [22.12.2013 6:54 775952]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [22.12.2013 6:54 410528]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [22.12.2013 6:54 67824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-12-20 13:02 1210320 ----a-w- c:\program files\Google\Chrome\Application\31.0.1650.63\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2013-12-22 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-22 13:14]
.
2013-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-20 13:00]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\ICQ7.7\ICQ.exe
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Kryton\Nabídka Start\Programy\IMVU\Run IMVU.lnk
TCP: DhcpNameServer = 109.238.32.52 8.8.8.8
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-12-25 16:18
Windows 5.1.2600 Service Pack 2 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TrueSight]
"ImagePath"="\??\"
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\Rundll32.exe
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2013-12-25 16:21:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2013-12-25 15:21
ComboFix2.txt 2013-12-25 09:19
.
Před spuštěním: Volných bajtů: 44 016 332 800
Po spuštění: Volných bajtů: 44 090 290 176
.
- - End Of File - - AF008FE43EE75274A287DD5F404ACF88
413FC2A0C716421B3158746D63736515

Re: Policejni vir

Napsal: 25 pro 2013 16:33
od Márty84
Fungovalo to :) Pri tom prohledani to zaroven vykonalo prikazy, ktere jsem mu zadal.

:arrow: Dejte novy log z RSIT

Re: Policejni vir

Napsal: 25 pro 2013 16:58
od jaroslav.24
LOG z RSIT

Logfile of random's system information tool 1.09 (written by random/random)
Run by Kryton at 2013-12-25 16:57:05
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 42 GB (73%) free of 57 GB
Total RAM: 446 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:57:18, on 25.12.2013
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kryton\Plocha\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Kryton.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Kryton\Nabídka Start\Programy\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

--
End of file - 4210 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\avast! Emergency Update.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23 60568]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSPower"=SiSPower.dll,ModeAgent []
"SiS Windows KeyHook"=C:\WINDOWS\system32\keyhook.exe [2005-03-04 32768]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2013-08-19 77824]
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2013-08-20 88363]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2013-08-20 98394]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-20 688218]
"CanonMyPrinter"=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2010-03-25 2516296]
"CanonSolutionMenuEx"=C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [2010-04-02 1185112]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2013-12-22 3764024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-17 239616]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\Kryton\Plocha\DOTA\Warcraft III\Warcraft III.exe"="C:\Documents and Settings\Kryton\Plocha\DOTA\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Program Files\ICQ7.7\ICQ.exe"="C:\Program Files\ICQ7.7\ICQ.exe:*:Enabled:ICQ7.7"
"C:\Program Files\Black Isle\Lionheart\Lionheart.exe"="C:\Program Files\Black Isle\Lionheart\Lionheart.exe:*:Enabled:Lionheart"
"C:\WINDOWS\system32\dpnsvr.exe"="C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\ICQ7.7\ICQ.exe"="C:\Program Files\ICQ7.7\ICQ.exe:*:Enabled:ICQ7.7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.trspch"=tssoft32.acm
"vidc.cvid"=iccvid.dll
"vidc.I420"=msh263.drv
"vidc.iv31"=ir32_32.dll
"vidc.iv32"=ir32_32.dll
"vidc.iv41"=ir41_32.ax
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"msacm.msg723"=msg723.acm
"vidc.M263"=msh263.drv
"vidc.M261"=msh261.drv
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"msacm.iac2"=C:\WINDOWS\system32\iac25_32.ax
"vidc.iv50"=ir50_32.dll
"msacm.l3acm"=C:\WINDOWS\system32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"vidc.XVID"=xvid.dll
"vidc.VP60"=C:\WINDOWS\system32\vp6vfw.dll
"vidc.VP61"=C:\WINDOWS\system32\vp6vfw.dll

======List of files/folders created in the last 1 month======

2013-12-25 16:32:37 ----SHD---- C:\RECYCLER
2013-12-25 16:31:09 ----SD---- C:\ComboFix
2013-12-25 16:21:18 ----D---- C:\WINDOWS\temp
2013-12-25 09:45:41 ----A---- C:\Boot.bak
2013-12-25 09:45:33 ----RASHD---- C:\cmdcons
2013-12-25 09:39:10 ----A---- C:\WINDOWS\zip.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\SWXCACLS.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\SWSC.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\SWREG.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\sed.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\PEV.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\NIRCMD.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\MBR.exe
2013-12-25 09:39:10 ----A---- C:\WINDOWS\grep.exe
2013-12-25 09:38:59 ----D---- C:\Qoobox
2013-12-25 09:38:29 ----D---- C:\WINDOWS\erdnt
2013-12-24 15:58:31 ----A---- C:\WINDOWS\system32\drivers\ws2ifsl.sys.bak
2013-12-24 15:58:31 ----A---- C:\WINDOWS\system32\drivers\wmilib.sys.bak
2013-12-24 15:58:31 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys.bak
2013-12-24 15:58:30 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys.bak
2013-12-24 15:58:30 ----A---- C:\WINDOWS\system32\drivers\volsnap.sys.bak
2013-12-24 15:58:30 ----A---- C:\WINDOWS\system32\drivers\videoprt.sys.bak
2013-12-24 15:58:30 ----A---- C:\WINDOWS\system32\drivers\vga.sys.bak
2013-12-24 15:58:30 ----A---- C:\WINDOWS\system32\drivers\vdmindvd.sys.bak
2013-12-24 15:58:29 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS.bak
2013-12-24 15:58:29 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys.bak
2013-12-24 15:58:29 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys.bak
2013-12-24 15:58:29 ----A---- C:\WINDOWS\system32\drivers\usbport.sys.bak
2013-12-24 15:58:29 ----A---- C:\WINDOWS\system32\drivers\usbohci.sys.bak
2013-12-24 15:58:28 ----A---- C:\WINDOWS\system32\drivers\usbintel.sys.bak
2013-12-24 15:58:28 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys.bak
2013-12-24 15:58:28 ----A---- C:\WINDOWS\system32\drivers\usbehci.sys.bak
2013-12-24 15:58:28 ----A---- C:\WINDOWS\system32\drivers\usbd.sys.bak
2013-12-24 15:58:28 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys.bak
2013-12-24 15:58:28 ----A---- C:\WINDOWS\system32\drivers\usbcamd2.sys.bak
2013-12-24 15:58:27 ----A---- C:\WINDOWS\system32\drivers\usbcamd.sys.bak
2013-12-24 15:58:27 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys.bak
2013-12-24 15:58:27 ----A---- C:\WINDOWS\system32\drivers\update.sys.bak
2013-12-24 15:58:27 ----A---- C:\WINDOWS\system32\drivers\udfs.sys.bak
2013-12-24 15:58:27 ----A---- C:\WINDOWS\system32\drivers\tunmp.sys.bak
2013-12-24 15:58:27 ----A---- C:\WINDOWS\system32\drivers\tsbvcap.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\tosdvd.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\termdd.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\tdi.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\tcpip6.sys.bak
2013-12-24 15:58:26 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys.bak
2013-12-24 15:58:25 ----A---- C:\WINDOWS\system32\drivers\tape.sys.bak
2013-12-24 15:58:25 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys.bak
2013-12-24 15:58:25 ----A---- C:\WINDOWS\system32\drivers\SynTP.sys.bak
2013-12-24 15:58:25 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys.bak
2013-12-24 15:58:24 ----A---- C:\WINDOWS\system32\drivers\swenum.sys.bak
2013-12-24 15:58:24 ----A---- C:\WINDOWS\system32\drivers\stream.sys.bak
2013-12-24 15:58:24 ----A---- C:\WINDOWS\system32\drivers\srvkp.sys.bak
2013-12-24 15:58:24 ----A---- C:\WINDOWS\system32\drivers\srv.sys.bak
2013-12-24 15:58:24 ----A---- C:\WINDOWS\system32\drivers\sr.sys.bak
2013-12-24 15:58:24 ----A---- C:\WINDOWS\system32\drivers\sptd7533.sys.bak
2013-12-24 15:58:23 ----A---- C:\WINDOWS\system32\drivers\sptd.sys.bak
2013-12-24 15:58:23 ----A---- C:\WINDOWS\system32\drivers\splitter.sys.bak
2013-12-24 15:58:23 ----A---- C:\WINDOWS\system32\drivers\sonydcam.sys.bak
2013-12-24 15:58:23 ----A---- C:\WINDOWS\system32\drivers\smclib.sys.bak
2013-12-24 15:58:23 ----A---- C:\WINDOWS\system32\drivers\sisnicxp.sys.bak
2013-12-24 15:58:23 ----A---- C:\WINDOWS\system32\drivers\sisnic.sys.bak
2013-12-24 15:58:22 ----A---- C:\WINDOWS\system32\drivers\sisgrp.sys.bak
2013-12-24 15:58:22 ----A---- C:\WINDOWS\system32\drivers\SISAGPX.SYS.bak
2013-12-24 15:58:22 ----A---- C:\WINDOWS\system32\drivers\sfloppy.sys.bak
2013-12-24 15:58:22 ----A---- C:\WINDOWS\system32\drivers\sffp_sd.sys.bak
2013-12-24 15:58:22 ----A---- C:\WINDOWS\system32\drivers\sffdisk.sys.bak
2013-12-24 15:58:22 ----A---- C:\WINDOWS\system32\drivers\serial.sys.bak
2013-12-24 15:58:21 ----A---- C:\WINDOWS\system32\drivers\serenum.sys.bak
2013-12-24 15:58:21 ----A---- C:\WINDOWS\system32\drivers\secdrv.sys.bak
2013-12-24 15:58:21 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys.bak
2013-12-24 15:58:21 ----A---- C:\WINDOWS\system32\drivers\scsiport.sys.bak
2013-12-24 15:58:21 ----A---- C:\WINDOWS\system32\drivers\rt73.sys.bak
2013-12-24 15:58:20 ----A---- C:\WINDOWS\system32\drivers\rootmdm.sys.bak
2013-12-24 15:58:20 ----A---- C:\WINDOWS\system32\drivers\rndismp.sys.bak
2013-12-24 15:58:20 ----A---- C:\WINDOWS\system32\drivers\RMCast.sys.bak
2013-12-24 15:58:20 ----A---- C:\WINDOWS\system32\drivers\riodrv.sys.bak
2013-12-24 15:58:20 ----A---- C:\WINDOWS\system32\drivers\rio8drv.sys.bak
2013-12-24 15:58:20 ----A---- C:\WINDOWS\system32\drivers\redbook.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\rdpcdd.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\rawwan.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\raspti.sys.bak
2013-12-24 15:58:19 ----A---- C:\WINDOWS\system32\drivers\raspptp.sys.bak
2013-12-24 15:58:18 ----A---- C:\WINDOWS\system32\drivers\raspppoe.sys.bak
2013-12-24 15:58:18 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys.bak
2013-12-24 15:58:18 ----A---- C:\WINDOWS\system32\drivers\rasacd.sys.bak
2013-12-24 15:58:18 ----A---- C:\WINDOWS\system32\drivers\ptilink.sys.bak
2013-12-24 15:58:18 ----A---- C:\WINDOWS\system32\drivers\psched.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\processr.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\portcls.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\pcmcia.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\pciidex.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\pciide.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\pci.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\parvdm.sys.bak
2013-12-24 15:58:17 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys.bak
2013-12-24 15:58:16 ----A---- C:\WINDOWS\system32\drivers\parport.sys.bak
2013-12-24 15:58:16 ----A---- C:\WINDOWS\system32\drivers\p3.sys.bak
2013-12-24 15:58:16 ----A---- C:\WINDOWS\system32\drivers\oprghdlr.sys.bak
2013-12-24 15:58:16 ----A---- C:\WINDOWS\system32\drivers\nwrdr.sys.bak
2013-12-24 15:58:15 ----A---- C:\WINDOWS\system32\drivers\nwlnkspx.sys.bak
2013-12-24 15:58:15 ----A---- C:\WINDOWS\system32\drivers\nwlnknb.sys.bak
2013-12-24 15:58:15 ----A---- C:\WINDOWS\system32\drivers\nwlnkipx.sys.bak
2013-12-24 15:58:15 ----A---- C:\WINDOWS\system32\drivers\nwlnkfwd.sys.bak
2013-12-24 15:58:15 ----A---- C:\WINDOWS\system32\drivers\nwlnkflt.sys.bak
2013-12-24 15:58:15 ----A---- C:\WINDOWS\system32\drivers\null.sys.bak
2013-12-24 15:58:14 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys.bak
2013-12-24 15:58:14 ----A---- C:\WINDOWS\system32\drivers\npfs.sys.bak
2013-12-24 15:58:14 ----A---- C:\WINDOWS\system32\drivers\nmnt.sys.bak
2013-12-24 15:58:14 ----A---- C:\WINDOWS\system32\drivers\nikedrv.sys.bak
2013-12-24 15:58:14 ----A---- C:\WINDOWS\system32\drivers\nic1394.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\netbt.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\netbios.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\ndiswan.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\ndisuio.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys.bak
2013-12-24 15:58:13 ----A---- C:\WINDOWS\system32\drivers\ndis.sys.bak
2013-12-24 15:58:12 ----A---- C:\WINDOWS\system32\drivers\mup.sys.bak
2013-12-24 15:58:12 ----A---- C:\WINDOWS\system32\drivers\mssmbios.sys.bak
2013-12-24 15:58:12 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys.bak
2013-12-24 15:58:12 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys.bak
2013-12-24 15:58:12 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys.bak
2013-12-24 15:58:12 ----A---- C:\WINDOWS\system32\drivers\msgpc.sys.bak
2013-12-24 15:58:11 ----A---- C:\WINDOWS\system32\drivers\msfs.sys.bak
2013-12-24 15:58:11 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys.bak
2013-12-24 15:58:11 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys.bak
2013-12-24 15:58:11 ----A---- C:\WINDOWS\system32\drivers\mqac.sys.bak
2013-12-24 15:58:10 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys.bak
2013-12-24 15:58:10 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys.bak
2013-12-24 15:58:10 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys.bak
2013-12-24 15:58:10 ----A---- C:\WINDOWS\system32\drivers\modem.sys.bak
2013-12-24 15:58:10 ----A---- C:\WINDOWS\system32\drivers\mnmdd.sys.bak
2013-12-24 15:58:09 ----A---- C:\WINDOWS\system32\drivers\mf.sys.bak
2013-12-24 15:58:09 ----A---- C:\WINDOWS\system32\drivers\mcd.sys.bak
2013-12-24 15:58:09 ----A---- C:\WINDOWS\system32\drivers\mbam.sys.bak
2013-12-24 15:58:09 ----A---- C:\WINDOWS\system32\drivers\ksecdd.sys.bak
2013-12-24 15:58:09 ----A---- C:\WINDOWS\system32\drivers\ks.sys.bak
2013-12-24 15:58:09 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys.bak
2013-12-24 15:58:08 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys.bak
2013-12-24 15:58:08 ----A---- C:\WINDOWS\system32\drivers\isapnp.sys.bak
2013-12-24 15:58:08 ----A---- C:\WINDOWS\system32\drivers\irenum.sys.bak
2013-12-24 15:58:08 ----A---- C:\WINDOWS\system32\drivers\ipsec.sys.bak
2013-12-24 15:58:08 ----A---- C:\WINDOWS\system32\drivers\ipnat.sys.bak
2013-12-24 15:58:07 ----A---- C:\WINDOWS\system32\drivers\ipinip.sys.bak
2013-12-24 15:58:07 ----A---- C:\WINDOWS\system32\drivers\ipfltdrv.sys.bak
2013-12-24 15:58:07 ----A---- C:\WINDOWS\system32\drivers\ip6fw.sys.bak
2013-12-24 15:58:07 ----A---- C:\WINDOWS\system32\drivers\intelppm.sys.bak
2013-12-24 15:58:07 ----A---- C:\WINDOWS\system32\drivers\imapi.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\http.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\hidusb.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\hidparse.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\GAGP30KX.SYS.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\ftdisk.sys.bak
2013-12-24 15:58:06 ----A---- C:\WINDOWS\system32\drivers\fs_rec.sys.bak
2013-12-24 15:58:05 ----A---- C:\WINDOWS\system32\drivers\fsvga.sys.bak
2013-12-24 15:58:05 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys.bak
2013-12-24 15:58:05 ----A---- C:\WINDOWS\system32\drivers\flpydisk.sys.bak
2013-12-24 15:58:05 ----A---- C:\WINDOWS\system32\drivers\fips.sys.bak
2013-12-24 15:58:05 ----A---- C:\WINDOWS\system32\drivers\fdc.sys.bak
2013-12-24 15:58:04 ----A---- C:\WINDOWS\system32\drivers\fastfat.sys.bak
2013-12-24 15:58:04 ----A---- C:\WINDOWS\system32\drivers\dxgthk.sys.bak
2013-12-24 15:58:04 ----A---- C:\WINDOWS\system32\drivers\dxg.sys.bak
2013-12-24 15:58:04 ----A---- C:\WINDOWS\system32\drivers\dxapi.sys.bak
2013-12-24 15:58:04 ----A---- C:\WINDOWS\system32\drivers\dtscsi.sys.bak
2013-12-24 15:58:03 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys.bak
2013-12-24 15:58:03 ----A---- C:\WINDOWS\system32\drivers\drmk.sys.bak
2013-12-24 15:58:03 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys.bak
2013-12-24 15:58:03 ----A---- C:\WINDOWS\system32\drivers\dmload.sys.bak
2013-12-24 15:58:03 ----A---- C:\WINDOWS\system32\drivers\dmio.sys.bak
2013-12-24 15:58:02 ----A---- C:\WINDOWS\system32\drivers\dmboot.sys.bak
2013-12-24 15:58:02 ----A---- C:\WINDOWS\system32\drivers\diskdump.sys.bak
2013-12-24 15:58:02 ----A---- C:\WINDOWS\system32\drivers\disk.sys.bak
2013-12-24 15:58:02 ----A---- C:\WINDOWS\system32\drivers\crusoe.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\cpqdap01.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\compbatt.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\CmBatt.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\classpnp.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\cinemst2.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\cdrom.sys.bak
2013-12-24 15:58:01 ----A---- C:\WINDOWS\system32\drivers\cdfs.sys.bak
2013-12-24 15:58:00 ----A---- C:\WINDOWS\system32\drivers\cdaudio.sys.bak
2013-12-24 15:58:00 ----A---- C:\WINDOWS\system32\drivers\cbidf2k.sys.bak
2013-12-24 15:58:00 ----A---- C:\WINDOWS\system32\drivers\bridge.sys.bak
2013-12-24 15:58:00 ----A---- C:\WINDOWS\system32\drivers\beep.sys.bak
2013-12-24 15:58:00 ----A---- C:\WINDOWS\system32\drivers\battc.sys.bak
2013-12-24 15:57:59 ----A---- C:\WINDOWS\system32\drivers\audstub.sys.bak
2013-12-24 15:57:59 ----A---- C:\WINDOWS\system32\drivers\atmuni.sys.bak
2013-12-24 15:57:59 ----A---- C:\WINDOWS\system32\drivers\atmlane.sys.bak
2013-12-24 15:57:59 ----A---- C:\WINDOWS\system32\drivers\atmepvc.sys.bak
2013-12-24 15:57:58 ----A---- C:\WINDOWS\system32\drivers\atmarpc.sys.bak
2013-12-24 15:57:58 ----A---- C:\WINDOWS\system32\drivers\atapi.sys.bak
2013-12-24 15:57:58 ----A---- C:\WINDOWS\system32\drivers\asyncmac.sys.bak
2013-12-24 15:57:58 ----A---- C:\WINDOWS\system32\drivers\arp1394.sys.bak
2013-12-24 15:57:58 ----A---- C:\WINDOWS\system32\drivers\amdk7.sys.bak
2013-12-24 15:57:57 ----A---- C:\WINDOWS\system32\drivers\amdk6.sys.bak
2013-12-24 15:57:56 ----A---- C:\WINDOWS\system32\drivers\ALCXWDM.SYS.bak
2013-12-24 15:57:55 ----A---- C:\WINDOWS\system32\drivers\AGRSM.sys.bak
2013-12-24 15:57:55 ----A---- C:\WINDOWS\system32\drivers\AegisP.sys.bak
2013-12-24 15:57:54 ----A---- C:\WINDOWS\system32\drivers\aec.sys.bak
2013-12-24 15:57:54 ----A---- C:\WINDOWS\system32\drivers\acpiec.sys.bak
2013-12-24 15:57:54 ----A---- C:\WINDOWS\system32\drivers\acpi.sys.bak
2013-12-24 12:56:24 ----D---- C:\AdwCleaner
2013-12-24 09:01:12 ----D---- C:\Documents and Settings\Kryton\Data aplikací\Malwarebytes
2013-12-24 09:00:45 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Malwarebytes
2013-12-24 09:00:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2013-12-24 09:00:42 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2013-12-24 08:47:14 ----D---- C:\Program Files\trend micro
2013-12-24 08:31:13 ----D---- C:\rsit
2013-12-22 06:55:17 ----D---- C:\Documents and Settings\Kryton\Data aplikací\AVAST Software
2013-12-22 06:54:21 ----A---- C:\WINDOWS\system32\drivers\aswTdi.sys
2013-12-22 06:54:20 ----A---- C:\WINDOWS\system32\drivers\aswVmm.sys
2013-12-22 06:54:20 ----A---- C:\WINDOWS\system32\drivers\aswSP.sys
2013-12-22 06:54:20 ----A---- C:\WINDOWS\system32\drivers\aswRvrt.sys
2013-12-22 06:54:19 ----A---- C:\WINDOWS\system32\drivers\aswSnx.sys
2013-12-22 06:54:19 ----A---- C:\WINDOWS\system32\drivers\aswMonFlt.sys
2013-12-22 06:54:18 ----A---- C:\WINDOWS\system32\drivers\aswRdr.sys
2013-12-22 06:54:15 ----A---- C:\WINDOWS\system32\aswBoot.exe
2013-12-22 06:54:11 ----A---- C:\WINDOWS\avastSS.scr
2013-12-22 06:53:23 ----D---- C:\Program Files\AVAST Software
2013-12-21 16:19:00 ----HD---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
2013-12-21 16:18:59 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
2013-12-21 11:05:02 ----D---- C:\Program Files\VS Revo Group
2013-12-20 18:18:16 ----D---- C:\sh4ldr
2013-12-20 18:17:39 ----D---- C:\WINDOWS\A358F2F62500420C989C25C4F22DF51E.TMP
2013-12-20 18:17:30 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2013-12-20 14:00:40 ----D---- C:\Program Files\Google
2013-12-08 16:15:05 ----D---- C:\Program Files\Simutrans
2013-12-06 17:01:47 ----D---- C:\Games
2013-12-06 07:00:27 ----A---- C:\WINDOWS\IsUninst.exe

======List of files/folders modified in the last 1 month======

2013-12-25 16:21:19 ----D---- C:\WINDOWS\system32\drivers
2013-12-25 16:21:18 ----D---- C:\WINDOWS
2013-12-25 16:18:43 ----A---- C:\WINDOWS\system.ini
2013-12-25 16:18:31 ----D---- C:\WINDOWS\system32\drivers\etc
2013-12-25 16:14:15 ----D---- C:\WINDOWS\system32
2013-12-25 16:14:15 ----D---- C:\WINDOWS\AppPatch
2013-12-25 16:14:13 ----D---- C:\Program Files\Common Files
2013-12-25 15:40:51 ----D---- C:\WINDOWS\system32\CatRoot2
2013-12-25 15:31:23 ----D---- C:\WINDOWS\SoftwareDistribution
2013-12-25 09:45:41 ----RASH---- C:\boot.ini
2013-12-24 23:59:54 ----D---- C:\Documents and Settings\Kryton\Data aplikací\vlc
2013-12-24 15:51:31 ----RD---- C:\Program Files
2013-12-24 11:03:06 ----D---- C:\WINDOWS\Registration
2013-12-22 14:14:44 ----SD---- C:\WINDOWS\Tasks
2013-12-22 06:51:55 ----D---- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVAST Software
2013-12-20 19:46:11 ----SHD---- C:\WINDOWS\Installer
2013-12-20 18:52:13 ----D---- C:\WINDOWS\Minidump
2013-12-14 20:27:16 ----D---- C:\Documents and Settings\Kryton\Data aplikací\dvdcss

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\WINDOWS\system32\drivers\aswRvrt.sys [2013-12-22 49944]
R0 aswVmm;avast! VM Monitor; C:\WINDOWS\system32\drivers\aswVmm.sys [2013-12-22 180248]
R0 gagp30kx;Filtr Microsoft Generic AGPv3.0 pro procesorovou platformu K8; C:\WINDOWS\system32\DRIVERS\gagp30kx.sys [2004-08-04 46464]
R0 SISAGP;SiS AGP Filter; C:\WINDOWS\system32\DRIVERS\SISAGPX.sys [2013-08-19 36992]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2013-08-20 664064]
R1 aswRdr;aswRdr; \??\C:\WINDOWS\system32\drivers\aswRdr.sys []
R1 aswSnx;aswSnx; \??\C:\WINDOWS\system32\drivers\aswSnx.sys []
R1 aswSP;aswSP; \??\C:\WINDOWS\system32\drivers\aswSP.sys []
R1 aswTdi;aswTdi; \??\C:\WINDOWS\system32\drivers\aswTdi.sys []
R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2013-08-19 13312]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.10.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2013-08-19 21275]
R2 aswMonFlt;aswMonFlt; \??\C:\WINDOWS\system32\drivers\aswMonFlt.sys []
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2013-08-20 1270540]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2013-08-19 2311680]
R3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
R3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2013-08-20 223128]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 RT73;RT73 USB Wireless LAN Card Driver; C:\WINDOWS\system32\DRIVERS\rt73.sys [2006-06-08 344064]
R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2013-08-19 240640]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51; C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2013-08-19 32768]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2013-08-20 185824]
S3 mbr;mbr; \??\C:\DOCUME~1\Kryton\LOCALS~1\Temp\mbr.sys []
S3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2004-08-03 32768]
S3 TrueSight;TrueSight; \??\ []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-12-22 50344]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-20 116648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2013-12-20 116648]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

-----------------EOF-----------------

Re: Policejni vir

Napsal: 25 pro 2013 17:30
od Márty84
Snad posledni sken a pak budem mazat.


:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Stahnete OTL http://oldtimer.geekstogo.com/OTL.exe , ulozte na plochu a spustte.
Oznacte polozky (dejte tam zatrzitka) Pro všechny uživatele, Kontrola na havěť "LOP" a Kontrola na havěť "Purity"
Do spodniho okna vlozte nasledujici text

Kód: Vybrat vše

CREATERESTOREPOINT

netsvcs
drivers32
savembr:0

/md5start
adp3132.sys
AGP440.sys
ahcix86.sys
ahcix86s.sys
atapi.sys
autochk.exe
cdrom.sys
cngaudit.dll
cryptsvc.dll
eNetHook.dll
eventlog.dll
explorer.exe
hal.dll
Changer.sys
iaStor.sys
iastorv.sys
IdeChnDr.sys
isapnp.sys
JakNDis.sys
KR10N.sys
logevent.dll
lsass.exe
mv61xx.sys
ndis.sys
netlogon.dll
ntelogon.dll
nvata.sys
nvatabus.sys
nvgts.sys
nvraid.sys
nvrd32.sys
nvstor.sys
nvstor32.sys
scecli.dll
sceclt.dll
smss.exe
svchost.exe
symmpi.sys
tcpip.sys
userinit.exe
vaxscsi.sys
viamraid.sys
viasraid.sys
ViPrt.sys
winlogon.exe
ws2_32.dll
/md5stop

%systemroot%*.* /U /s
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\drivers\*.sys /3
%systemroot%\system32\*.* /3
%SYSTEMDRIVE%\*.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s
reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c

type c:\boot.ini >> test.txt /c
%SystemDrive%\PhysicalMBR.bin /md5

*crack* /s
*keygen* /s
*AntiWPA* /s
*loader* /s
*minodlogin* /s
*tnod* /s
*AutoKMS* /s
*activator* /s
*serial* /s
*w7lxe* /s
Kliknete na Prohledat
Po skenu se vytvori dva logy (OTL.Txt a Extras.txt), oba sem vlozte (kdyz budou dlouhe, rozdelte je do vice prispevku).

Re: Policejni vir

Napsal: 25 pro 2013 17:58
od jaroslav.24
otl txt

OTL logfile created on: 25.12.2013 17:41:01 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Kryton\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

446,48 Mb Total Physical Memory | 159,72 Mb Available Physical Memory | 35,77% Memory free
1,03 Gb Paging File | 0,63 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55,88 Gb Total Space | 41,06 Gb Free Space | 73,48% Space Free | Partition Type: NTFS

Computer Name: KRYTON | User Name: Kryton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013.12.25 17:37:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kryton\Plocha\OTL.exe
PRC - [2013.12.22 14:14:33 | 003,764,024 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013.12.22 14:14:32 | 000,050,344 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013.12.04 03:48:06 | 000,863,184 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2013.08.20 10:44:25 | 000,098,394 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2010.03.25 03:50:00 | 002,516,296 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2005.03.04 12:13:04 | 000,032,768 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\Keyhook.exe
PRC - [2004.08.17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2013.12.25 10:43:14 | 002,153,984 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\13122500\algo.dll
MOD - [2013.12.22 06:54:11 | 019,336,120 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2013.12.04 03:48:04 | 000,399,312 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppgooglenaclpluginchrome.dll
MOD - [2013.12.04 03:48:02 | 004,055,504 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll
MOD - [2013.12.04 03:47:08 | 001,619,408 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll


========== Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2013.12.22 14:14:32 | 000,050,344 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (TrueSight)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\Kryton\LOCALS~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2013.12.22 14:14:39 | 000,775,952 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013.12.22 14:14:39 | 000,410,528 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\aswSP.sys -- (aswSP)
DRV - [2013.12.22 14:14:39 | 000,180,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013.12.22 14:14:39 | 000,067,824 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013.12.22 14:14:39 | 000,057,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013.12.22 14:14:39 | 000,054,832 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2013.12.22 06:54:14 | 000,049,944 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013.08.20 11:24:38 | 000,223,128 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dtscsi.sys -- (dtscsi)
DRV - [2013.08.20 11:17:21 | 000,664,064 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2013.08.20 10:37:51 | 001,270,540 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2013.08.19 23:56:44 | 002,311,680 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2013.08.19 23:56:04 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisnicxp.sys -- (SISNICXP)
DRV - [2013.08.19 23:48:20 | 000,240,640 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)
DRV - [2013.08.19 23:48:20 | 000,013,312 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)
DRV - [2013.08.19 23:48:14 | 000,036,992 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SISAGPX.SYS -- (SISAGP)
DRV - [2006.06.08 10:49:50 | 000,344,064 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2004.08.03 23:31:36 | 000,032,768 | ---- | M] (SiS Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_152.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.seznam.cz/
CHR - Extension: Dokumenty Google = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Disk Google = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Vyhled\u00E1v\u00E1n\u00ED Google = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: avast! Online Security = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\9.0.2011.70_0\
CHR - Extension: Pen\u011B\u017Eenka Google = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2013.12.25 16:18:31 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\Keyhook.exe (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SiSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.7 - {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - C:\Program Files\ICQ7.7\ICQ.exe (ICQ, LLC.)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Kryton\Nabídka Start\Programy\IMVU\Run IMVU.lnk File not found
O15 - HKLM\..Trusted Domains: localhost ([]http in Internet)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 109.238.32.52 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{48A87BAB-88F8-43AE-A2ED-07E9BEE29DD1}: DhcpNameServer = 109.238.32.52 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F7557FF-D2DF-42BA-877C-33C6F4329948}: DhcpNameServer = 109.238.32.52 8.8.8.8
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013.01.01 16:42:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvid.dll ()
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin

========== Files/Folders - Created Within 30 Days ==========

[2013.12.25 17:37:41 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kryton\Plocha\OTL.exe
[2013.12.25 16:32:37 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013.12.25 16:31:09 | 000,000,000 | --SD | C] -- C:\ComboFix
[2013.12.25 16:21:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013.12.25 09:45:33 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013.12.25 09:39:10 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013.12.25 09:39:10 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013.12.25 09:39:10 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013.12.25 09:39:10 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013.12.25 09:38:59 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.12.25 09:38:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Kryton\Dokumenty\Filmy
[2013.12.25 09:38:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013.12.25 09:36:23 | 005,158,070 | R--- | C] (Swearware) -- C:\Documents and Settings\Kryton\Plocha\ComboFix.exe
[2013.12.24 15:58:31 | 000,004,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wmilib.sys.bak
[2013.12.24 15:58:30 | 000,079,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\videoprt.sys.bak
[2013.12.24 15:58:30 | 000,058,112 | ---- | C] (RAVISENT Technologies Inc.) -- C:\WINDOWS\System32\drivers\vdmindvd.sys.bak
[2013.12.24 15:58:29 | 000,142,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbport.sys.bak
[2013.12.24 15:58:28 | 000,023,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbcamd2.sys.bak
[2013.12.24 15:58:28 | 000,016,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbintel.sys.bak
[2013.12.24 15:58:28 | 000,004,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbd.sys.bak
[2013.12.24 15:58:27 | 000,023,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbcamd.sys.bak
[2013.12.24 15:58:27 | 000,021,376 | ---- | C] (Toshiba Corporation) -- C:\WINDOWS\System32\drivers\tsbvcap.sys.bak
[2013.12.24 15:58:27 | 000,012,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023.sys.bak
[2013.12.24 15:58:26 | 000,223,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tcpip6.sys.bak
[2013.12.24 15:58:26 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tosdvd.sys.bak
[2013.12.24 15:58:26 | 000,018,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdi.sys.bak
[2013.12.24 15:58:25 | 000,014,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tape.sys.bak
[2013.12.24 15:58:24 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sptd7533.sys.bak
[2013.12.24 15:58:24 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\stream.sys.bak
[2013.12.24 15:58:24 | 000,013,312 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\srvkp.sys.bak
[2013.12.24 15:58:23 | 000,664,064 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys.bak
[2013.12.24 15:58:23 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\drivers\sisnicxp.sys.bak
[2013.12.24 15:58:23 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\drivers\sisnic.sys.bak
[2013.12.24 15:58:23 | 000,025,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sonydcam.sys.bak
[2013.12.24 15:58:23 | 000,014,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smclib.sys.bak
[2013.12.24 15:58:22 | 000,240,640 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\sisgrp.sys.bak
[2013.12.24 15:58:22 | 000,036,992 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\SISAGPX.SYS.bak
[2013.12.24 15:58:21 | 000,344,064 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\drivers\rt73.sys.bak
[2013.12.24 15:58:21 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\scsiport.sys.bak
[2013.12.24 15:58:20 | 000,200,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RMCast.sys.bak
[2013.12.24 15:58:20 | 000,030,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismp.sys.bak
[2013.12.24 15:58:20 | 000,012,032 | ---- | C] (S3/Diamond Multimedia Systems) -- C:\WINDOWS\System32\drivers\riodrv.sys.bak
[2013.12.24 15:58:20 | 000,012,032 | ---- | C] (S3/Diamond Multimedia Systems) -- C:\WINDOWS\System32\drivers\rio8drv.sys.bak
[2013.12.24 15:58:19 | 000,034,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rawwan.sys.bak
[2013.12.24 15:58:17 | 000,145,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys.bak
[2013.12.24 15:58:17 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\pciidex.sys.bak
[2013.12.24 15:58:16 | 000,003,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\oprghdlr.sys.bak
[2013.12.24 15:58:15 | 000,088,448 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnkipx.sys.bak
[2013.12.24 15:58:15 | 000,063,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnknb.sys.bak
[2013.12.24 15:58:15 | 000,055,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnkspx.sys.bak
[2013.12.24 15:58:14 | 000,040,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nmnt.sys.bak
[2013.12.24 15:58:14 | 000,012,032 | ---- | C] (S3/Diamond Multimedia Systems) -- C:\WINDOWS\System32\drivers\nikedrv.sys.bak
[2013.12.24 15:58:11 | 000,072,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mqac.sys.bak
[2013.12.24 15:58:09 | 000,140,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ks.sys.bak
[2013.12.24 15:58:09 | 000,063,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mf.sys.bak
[2013.12.24 15:58:09 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys.bak
[2013.12.24 15:58:09 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mcd.sys.bak
[2013.12.24 15:58:06 | 000,036,224 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidclass.sys.bak
[2013.12.24 15:58:06 | 000,024,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidparse.sys.bak
[2013.12.24 15:58:05 | 000,012,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fsvga.sys.bak
[2013.12.24 15:58:04 | 000,223,128 | ---- | C] (DT Soft Ltd.) -- C:\WINDOWS\System32\drivers\dtscsi.sys.bak
[2013.12.24 15:58:04 | 000,071,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxg.sys.bak
[2013.12.24 15:58:04 | 000,010,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxapi.sys.bak
[2013.12.24 15:58:04 | 000,003,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxgthk.sys.bak
[2013.12.24 15:58:03 | 000,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys.bak
[2013.12.24 15:58:02 | 000,014,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\diskdump.sys.bak
[2013.12.24 15:58:01 | 000,262,528 | ---- | C] (RAVISENT Technologies Inc.) -- C:\WINDOWS\System32\drivers\cinemst2.sys.bak
[2013.12.24 15:58:01 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\classpnp.sys.bak
[2013.12.24 15:58:01 | 000,011,776 | ---- | C] (Compaq Computer Corporation) -- C:\WINDOWS\System32\drivers\cpqdap01.sys.bak
[2013.12.24 15:58:00 | 000,014,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\battc.sys.bak
[2013.12.24 15:57:59 | 000,352,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmuni.sys.bak
[2013.12.24 15:57:59 | 000,055,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmlane.sys.bak
[2013.12.24 15:57:59 | 000,031,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmepvc.sys.bak
[2013.12.24 15:57:57 | 000,040,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\amdk6.sys.bak
[2013.12.24 15:57:56 | 002,311,680 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS.bak
[2013.12.24 15:57:55 | 001,270,540 | ---- | C] (Agere Systems) -- C:\WINDOWS\System32\drivers\AGRSM.sys.bak
[2013.12.24 15:56:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Plocha\RK_Quarantine
[2013.12.24 12:56:24 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013.12.24 11:05:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Kryton\Recent
[2013.12.24 09:01:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Data aplikací\Malwarebytes
[2013.12.24 09:00:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Malwarebytes' Anti-Malware
[2013.12.24 09:00:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Malwarebytes
[2013.12.24 09:00:42 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013.12.24 09:00:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.12.24 08:59:09 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300 (1).exe
[2013.12.24 08:58:47 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300.exe
[2013.12.24 08:47:14 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2013.12.24 08:31:13 | 000,000,000 | ---D | C] -- C:\rsit
[2013.12.22 06:55:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Data aplikací\AVAST Software
[2013.12.22 06:54:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Avast
[2013.12.22 06:54:21 | 000,057,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2013.12.22 06:54:20 | 000,410,528 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.12.22 06:54:19 | 000,775,952 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.12.22 06:54:19 | 000,067,824 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2013.12.22 06:54:18 | 000,054,832 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2013.12.22 06:54:15 | 000,270,240 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2013.12.22 06:54:11 | 000,043,152 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013.12.22 06:53:23 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2013.12.21 16:19:00 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
[2013.12.21 16:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Local Settings\Data aplikací\MFAData
[2013.12.21 16:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
[2013.12.21 16:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Avg2014
[2013.12.21 11:05:02 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2013.12.20 18:18:16 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2013.12.20 18:17:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2013.12.20 17:10:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Local Settings\Data aplikací\CRE
[2013.12.20 14:02:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Nabídka Start\Programy\Google Chrome
[2013.12.20 14:00:40 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2013.12.08 16:24:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Dokumenty\Simutrans
[2013.12.08 16:15:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Nabídka Start\Programy\Simutrans
[2013.12.08 16:15:05 | 000,000,000 | ---D | C] -- C:\Program Files\Simutrans
[2013.12.06 17:01:47 | 000,000,000 | ---D | C] -- C:\Games
[2013.12.06 07:00:27 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013.12.25 17:42:53 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2013.12.25 17:37:50 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kryton\Plocha\OTL.exe
[2013.12.25 16:18:31 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013.12.25 16:18:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013.12.25 16:18:20 | 468,242,432 | -HS- | M] () -- C:\hiberfil.sys
[2013.12.25 09:45:41 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013.12.25 09:37:22 | 005,158,070 | R--- | M] (Swearware) -- C:\Documents and Settings\Kryton\Plocha\ComboFix.exe
[2013.12.25 08:21:59 | 000,004,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wmilib.sys.bak
[2013.12.25 08:21:58 | 000,079,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\videoprt.sys.bak
[2013.12.25 08:21:57 | 000,058,112 | ---- | M] (RAVISENT Technologies Inc.) -- C:\WINDOWS\System32\drivers\vdmindvd.sys.bak
[2013.12.25 08:21:56 | 000,142,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbport.sys.bak
[2013.12.25 08:21:56 | 000,016,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbintel.sys.bak
[2013.12.25 08:21:55 | 000,023,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbcamd2.sys.bak
[2013.12.25 08:21:55 | 000,004,736 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbd.sys.bak
[2013.12.25 08:21:54 | 000,023,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbcamd.sys.bak
[2013.12.25 08:21:54 | 000,012,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usb8023.sys.bak
[2013.12.25 08:21:53 | 000,051,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tosdvd.sys.bak
[2013.12.25 08:21:53 | 000,021,376 | ---- | M] (Toshiba Corporation) -- C:\WINDOWS\System32\drivers\tsbvcap.sys.bak
[2013.12.25 08:21:52 | 000,018,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tdi.sys.bak
[2013.12.25 08:21:51 | 000,223,616 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tcpip6.sys.bak
[2013.12.25 08:21:50 | 000,014,976 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\tape.sys.bak
[2013.12.25 08:21:49 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\stream.sys.bak
[2013.12.25 08:21:48 | 000,013,312 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\srvkp.sys.bak
[2013.12.25 08:21:47 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sptd7533.sys.bak
[2013.12.25 08:21:46 | 000,025,472 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sonydcam.sys.bak
[2013.12.25 08:21:45 | 000,032,768 | ---- | M] (SiS Corporation) -- C:\WINDOWS\System32\drivers\sisnicxp.sys.bak
[2013.12.25 08:21:45 | 000,032,768 | ---- | M] (SiS Corporation) -- C:\WINDOWS\System32\drivers\sisnic.sys.bak
[2013.12.25 08:21:45 | 000,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\smclib.sys.bak
[2013.12.25 08:21:44 | 000,240,640 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\sisgrp.sys.bak
[2013.12.25 08:21:44 | 000,036,992 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\SISAGPX.SYS.bak
[2013.12.25 08:21:42 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\scsiport.sys.bak
[2013.12.25 08:21:41 | 000,344,064 | ---- | M] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\drivers\rt73.sys.bak
[2013.12.25 08:21:41 | 000,200,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\RMCast.sys.bak
[2013.12.25 08:21:41 | 000,030,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rndismp.sys.bak
[2013.12.25 08:21:40 | 000,012,032 | ---- | M] (S3/Diamond Multimedia Systems) -- C:\WINDOWS\System32\drivers\riodrv.sys.bak
[2013.12.25 08:21:40 | 000,012,032 | ---- | M] (S3/Diamond Multimedia Systems) -- C:\WINDOWS\System32\drivers\rio8drv.sys.bak
[2013.12.25 08:21:38 | 000,034,432 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\rawwan.sys.bak
[2013.12.25 08:21:36 | 000,145,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys.bak
[2013.12.25 08:21:35 | 000,025,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\pciidex.sys.bak
[2013.12.25 08:21:34 | 000,003,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\oprghdlr.sys.bak
[2013.12.25 08:21:33 | 000,088,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnkipx.sys.bak
[2013.12.25 08:21:33 | 000,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnknb.sys.bak
[2013.12.25 08:21:33 | 000,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nwlnkspx.sys.bak
[2013.12.25 08:21:31 | 000,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\nmnt.sys.bak
[2013.12.25 08:21:30 | 000,012,032 | ---- | M] (S3/Diamond Multimedia Systems) -- C:\WINDOWS\System32\drivers\nikedrv.sys.bak
[2013.12.25 08:21:25 | 000,072,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mqac.sys.bak
[2013.12.25 08:21:24 | 000,063,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mf.sys.bak
[2013.12.25 08:21:23 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys.bak
[2013.12.25 08:21:23 | 000,007,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mcd.sys.bak
[2013.12.25 08:21:22 | 000,140,928 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ks.sys.bak
[2013.12.25 08:21:16 | 000,036,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidclass.sys.bak
[2013.12.25 08:21:16 | 000,024,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidparse.sys.bak
[2013.12.25 08:21:15 | 000,012,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\fsvga.sys.bak
[2013.12.25 08:21:12 | 000,071,040 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxg.sys.bak
[2013.12.25 08:21:12 | 000,010,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxapi.sys.bak
[2013.12.25 08:21:12 | 000,003,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\dxgthk.sys.bak
[2013.12.25 08:21:11 | 000,223,128 | ---- | M] (DT Soft Ltd.) -- C:\WINDOWS\System32\drivers\dtscsi.sys.bak
[2013.12.25 08:21:11 | 000,060,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys.bak
[2013.12.25 08:21:08 | 000,014,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\diskdump.sys.bak
[2013.12.25 08:21:07 | 000,011,776 | ---- | M] (Compaq Computer Corporation) -- C:\WINDOWS\System32\drivers\cpqdap01.sys.bak
[2013.12.25 08:21:06 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\classpnp.sys.bak
[2013.12.25 08:21:05 | 000,262,528 | ---- | M] (RAVISENT Technologies Inc.) -- C:\WINDOWS\System32\drivers\cinemst2.sys.bak
[2013.12.25 08:21:02 | 000,352,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmuni.sys.bak
[2013.12.25 08:21:02 | 000,014,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\battc.sys.bak
[2013.12.25 08:21:01 | 000,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmlane.sys.bak
[2013.12.25 08:21:01 | 000,031,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\atmepvc.sys.bak
[2013.12.25 08:20:58 | 000,040,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\amdk6.sys.bak
[2013.12.25 08:20:56 | 002,311,680 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS.bak
[2013.12.25 08:20:54 | 001,270,540 | ---- | M] (Agere Systems) -- C:\WINDOWS\System32\drivers\AGRSM.sys.bak
[2013.12.24 18:45:14 | 320,664,172 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x12-Vortex-CZdab-DVD.avi
[2013.12.24 18:25:04 | 407,294,304 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x10-Postupujte-k-domovu-CZdab-DVD.avi
[2013.12.24 17:56:13 | 325,329,174 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x09-Pasažér-CZdab-DVD.avi
[2013.12.24 17:06:44 | 301,951,944 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x08-Daxová-CZdab-DVD (1).avi
[2013.12.24 15:49:57 | 003,770,368 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\RogueKiller.exe
[2013.12.24 12:56:02 | 001,233,962 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\adwcleaner.exe
[2013.12.24 09:00:48 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Plocha\Malwarebytes Anti-Malware.lnk
[2013.12.24 08:59:30 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300 (1).exe
[2013.12.24 08:59:10 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300.exe
[2013.12.24 08:46:57 | 000,781,383 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\RSIT.exe
[2013.12.23 16:58:05 | 233,382,137 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x08-Daxová-CZdab-DVD.avi
[2013.12.23 15:45:58 | 330,378,292 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x07-Bez-Q-CZdab-DVD.avi
[2013.12.23 15:17:00 | 000,000,012 | ---- | M] () -- C:\Documents and Settings\Kryton\intlname.ols
[2013.12.23 14:07:47 | 000,013,824 | ---- | M] () -- C:\Documents and Settings\Kryton\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.12.22 14:14:44 | 000,000,316 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.12.22 14:14:39 | 000,775,952 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2013.12.22 14:14:39 | 000,410,528 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2013.12.22 14:14:39 | 000,180,248 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.12.22 14:14:39 | 000,067,824 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswMonFlt.sys
[2013.12.22 14:14:39 | 000,057,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2013.12.22 14:14:39 | 000,054,832 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2013.12.22 14:14:38 | 000,270,240 | ---- | M] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2013.12.22 14:14:38 | 000,043,152 | ---- | M] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2013.12.22 07:07:44 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Plocha\VLC media player.lnk
[2013.12.22 06:54:14 | 000,049,944 | ---- | M] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013.12.21 18:25:46 | 000,045,089 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\1387646732.bdinstall.bin
[2013.12.20 19:46:03 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job
[2013.12.20 14:02:58 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Plocha\Google Chrome.lnk
[2013.12.18 08:26:34 | 000,064,346 | ---- | M] () -- C:\Documents and Settings\Kryton\Plocha\34063181_720.jpg
[2013.12.09 15:47:51 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.12.25 17:42:53 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2013.12.25 09:45:41 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013.12.25 09:45:34 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2013.12.25 09:39:10 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013.12.25 09:39:10 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013.12.25 09:39:10 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013.12.25 09:39:10 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013.12.25 09:39:10 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013.12.24 18:27:10 | 320,664,172 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x12-Vortex-CZdab-DVD.avi
[2013.12.24 18:00:45 | 407,294,304 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x10-Postupujte-k-domovu-CZdab-DVD.avi
[2013.12.24 17:37:53 | 325,329,174 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x09-Pasažér-CZdab-DVD.avi
[2013.12.24 16:49:36 | 301,951,944 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x08-Daxová-CZdab-DVD (1).avi
[2013.12.24 15:49:50 | 003,770,368 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\RogueKiller.exe
[2013.12.24 12:55:55 | 001,233,962 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\adwcleaner.exe
[2013.12.24 09:00:48 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Plocha\Malwarebytes Anti-Malware.lnk
[2013.12.24 08:46:54 | 000,781,383 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\RSIT.exe
[2013.12.23 16:21:20 | 233,382,137 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x08-Daxová-CZdab-DVD.avi
[2013.12.23 15:27:24 | 330,378,292 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\Star-Trek-Hluboký-vesmír-9-01x07-Bez-Q-CZdab-DVD.avi
[2013.12.22 06:54:41 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013.12.22 06:54:20 | 000,180,248 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013.12.22 06:54:20 | 000,049,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013.12.21 18:25:46 | 000,045,089 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\1387646732.bdinstall.bin
[2013.12.20 19:46:03 | 000,000,936 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job
[2013.12.20 14:02:57 | 000,001,813 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Plocha\Google Chrome.lnk
[2013.12.18 08:26:22 | 000,064,346 | ---- | C] () -- C:\Documents and Settings\Kryton\Plocha\34063181_720.jpg
[2013.08.26 07:30:49 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\Kryton\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.08.21 15:53:46 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\Kryton\intlname.ols
[2013.08.20 16:01:45 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys.sum
[2013.08.20 16:01:45 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSP.sys.sum
[2013.08.20 16:01:45 | 000,000,175 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswSnx.sys.sum
[2013.08.20 13:38:13 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2013.08.20 11:28:20 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2013.08.20 11:24:38 | 000,223,128 | ---- | C] () -- C:\WINDOWS\System32\drivers\dtscsi.sys
[2013.08.20 11:17:21 | 000,096,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd7533.sys
[2013.08.19 23:57:10 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2013.08.19 23:57:06 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2013.08.19 23:57:06 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2013.08.19 23:57:04 | 000,001,240 | ---- | C] () -- C:\WINDOWS\System32\drivers\alcxinit.dat
[2013.08.19 23:48:43 | 000,083,997 | ---- | C] () -- C:\WINDOWS\VGAsetup.ini
[2013.08.19 23:48:40 | 000,032,768 | ---- | C] () -- C:\WINDOWS\InstFunc.exe
[2013.08.19 23:48:30 | 000,100,839 | ---- | C] () -- C:\WINDOWS\System32\VGAunistlog.ini
[2013.08.19 17:26:07 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2013.08.19 17:24:54 | 000,116,560 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013.08.19 15:55:24 | 000,315,392 | ---- | C] () -- C:\WINDOWS\System32\AegisI5.exe
[2013.08.19 15:55:24 | 000,295,018 | ---- | C] () -- C:\WINDOWS\System32\Install7x.dll
[2013.08.19 15:55:24 | 000,002,048 | ---- | C] () -- C:\WINDOWS\System32\drivers\rt73.bin
[2013.08.19 15:46:26 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2013.08.19 15:38:30 | 000,021,812 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2013.08.19 15:00:25 | 000,313,208 | ---- | C] () -- C:\WINDOWS\System32\perfh005.dat
[2013.08.19 15:00:25 | 000,269,162 | ---- | C] () -- C:\WINDOWS\System32\perfi005.dat
[2013.08.19 15:00:25 | 000,047,404 | ---- | C] () -- C:\WINDOWS\System32\perfc005.dat
[2013.08.19 15:00:25 | 000,032,072 | ---- | C] () -- C:\WINDOWS\System32\perfd005.dat
[2013.08.19 14:41:29 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2013.08.19 14:40:12 | 000,314,706 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2013.08.19 14:40:12 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2013.08.19 14:40:12 | 000,041,034 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2013.08.19 14:40:12 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2013.08.19 14:38:37 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2013.08.19 14:36:01 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2013.08.19 14:35:19 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2013.08.19 14:32:49 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2013.08.19 14:32:47 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2013.08.19 14:32:05 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2013.08.19 14:31:36 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2013.08.19 14:30:58 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2013.06.09 07:02:06 | 000,410,504 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\FontCache3.0.0.0.dat
[2012.06.22 11:01:32 | 000,019,984 | ---- | C] () -- C:\WINDOWS\System32\ESGScanner.sys

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2004.08.17 14:49:18 | 001,483,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2004.08.17 14:49:08 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2004.08.17 14:49:20 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013.12.22 06:51:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\AVAST Software
[2013.09.05 12:24:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CanonBJ
[2013.09.05 12:24:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CanonIJMSetup
[2013.09.05 12:24:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\CanonIJWSpt
[2013.12.21 16:19:00 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Common Files
[2013.12.21 16:20:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\MFAData
[2013.09.13 07:29:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Panda Security
[2013.12.22 06:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\AVAST Software
[2013.10.19 11:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\ICQ
[2013.09.19 15:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\ICQ-Profile
[2013.09.13 07:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Panda Security

========== Purity Check ==========



========== Custom Scans ==========

< >
[2013.08.19 15:39:19 | 000,000,065 | RH-- | C] () -- C:\WINDOWS\Tasks\desktop.ini
[2013.08.19 15:47:49 | 000,000,006 | -H-- | C] () -- C:\WINDOWS\Tasks\SA.DAT
[2013.12.20 19:46:03 | 000,000,936 | ---- | C] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job
[2013.12.22 06:54:41 | 000,000,316 | -H-- | C] () -- C:\WINDOWS\Tasks\avast! Emergency Update.job

< >

< MD5 for: AGP440.SYS >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004.08.17 14:57:28 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\erdnt\cache\atapi.sys
[2004.08.17 14:57:28 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: AUTOCHK.EXE >
[2004.08.17 14:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\cmdcons\autochk.exe
[2004.08.17 14:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\autochk.exe
[2004.08.17 14:49:22 | 000,601,088 | ---- | M] (Microsoft Corporation) MD5=CEA8636EC12F062C1ED8A7CB4E75324F -- C:\WINDOWS\system32\dllcache\autochk.exe

< MD5 for: CDROM.SYS >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:cdrom.sys
[2004.08.17 14:57:28 | 000,049,536 | ---- | M] (Microsoft Corporation) MD5=AF9C19B3100FE010496B1A27181FBF72 -- C:\WINDOWS\system32\drivers\cdrom.sys

< MD5 for: CRYPTSVC.DLL >
[2004.08.17 14:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\erdnt\cache\cryptsvc.dll
[2004.08.17 14:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\cryptsvc.dll
[2004.08.17 14:49:04 | 000,060,416 | ---- | M] (Microsoft Corporation) MD5=70D2A1756F4B2067658A186C963FCABD -- C:\WINDOWS\system32\dllcache\cryptsvc.dll

< MD5 for: EVENTLOG.DLL >
[2004.08.17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\erdnt\cache\eventlog.dll
[2004.08.17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004.08.17 14:49:08 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=6EB66066D5C0175320CFEA0A4C74C88F -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: EXPLORER.EXE >
[2004.08.17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\erdnt\cache\explorer.exe
[2004.08.17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\explorer.exe
[2004.08.17 14:49:24 | 001,032,704 | ---- | M] (Microsoft Corporation) MD5=53114D57AB73A406AC7F602227781A99 -- C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: HAL.DLL >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:hal.dll
[2004.08.17 14:57:28 | 000,131,968 | ---- | M] (Microsoft Corporation) MD5=F9A0F579FC18036FFDD9E26E0D268CCD -- C:\WINDOWS\system32\hal.dll

< MD5 for: CHANGER.SYS >
[2004.08.17 14:57:28 | 018,786,869 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:Changer.sys

< MD5 for: ISAPNP.SYS >
[2001.10.25 13:00:00 | 000,035,840 | ---- | M] (Microsoft Corporation) MD5=1091528512E4DD7ED5FDDCC4DF1C53D7 -- C:\WINDOWS\system32\drivers\isapnp.sys

< MD5 for: LSASS.EXE >
[2004.08.17 14:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\erdnt\cache\lsass.exe
[2004.08.17 14:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\dllcache\lsass.exe
[2004.08.17 14:49:24 | 000,013,312 | ---- | M] (Microsoft Corporation) MD5=82A362FE1D4980B71B588D9C10748511 -- C:\WINDOWS\system32\lsass.exe

< MD5 for: NDIS.SYS >
[2004.08.03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\erdnt\cache\ndis.sys
[2004.08.03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\dllcache\ndis.sys
[2004.08.03 22:14:30 | 000,182,912 | ---- | M] (Microsoft Corporation) MD5=558635D3AF1C7546D26067D5D9B6959E -- C:\WINDOWS\system32\drivers\ndis.sys

< MD5 for: NETLOGON.DLL >
[2004.08.17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\erdnt\cache\netlogon.dll
[2004.08.17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004.08.17 14:49:14 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=2591CADAEF7D2242039255028E577688 -- C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\erdnt\cache\scecli.dll
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004.08.17 14:49:18 | 000,184,832 | ---- | M] (Microsoft Corporation) MD5=07119058D451CB7EA4317BCFDA8599A6 -- C:\WINDOWS\system32\scecli.dll

< MD5 for: SMSS.EXE >
[2004.08.17 14:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\dllcache\smss.exe
[2004.08.17 14:49:28 | 000,050,688 | ---- | M] (Microsoft Corporation) MD5=04B69D49D7FC3358A372E97DB6D39447 -- C:\WINDOWS\system32\smss.exe
[2004.08.17 15:49:28 | 000,164,864 | ---- | M] (Microsoft Corporation) MD5=3C100B7FDB179B63829103DF6541337F -- C:\cmdcons\SYSTEM32\SMSS.EXE

< MD5 for: SVCHOST.EXE >
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2004.08.17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\erdnt\cache\svchost.exe
[2004.08.17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\dllcache\svchost.exe
[2004.08.17 14:49:28 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=DFBA2915B0BF58ABB288CD4C9318CB3F -- C:\WINDOWS\system32\svchost.exe

< MD5 for: TCPIP.SYS >
[2004.08.03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\erdnt\cache\tcpip.sys
[2004.08.03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\dllcache\tcpip.sys
[2004.08.03 22:14:42 | 000,359,040 | ---- | M] (Microsoft Corporation) MD5=9F4B36614A0FC234525BA224957DE55C -- C:\WINDOWS\system32\drivers\tcpip.sys

< MD5 for: USERINIT.EXE >
[2004.08.17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\erdnt\cache\userinit.exe
[2004.08.17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\dllcache\userinit.exe
[2004.08.17 14:49:28 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=836F7960362FF95C5D49E40B891F2CFC -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004.08.17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\erdnt\cache\winlogon.exe
[2004.08.17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2004.08.17 14:49:28 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=221C29AE1B4CC61D11D8B27DE78B2307 -- C:\WINDOWS\system32\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WS2_32.DLL >
[2004.08.17 14:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\erdnt\cache\ws2_32.dll
[2004.08.17 14:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\dllcache\ws2_32.dll
[2004.08.17 14:49:22 | 000,082,944 | ---- | M] (Microsoft Corporation) MD5=382E9B87F1282E697C67AF84E34E35E2 -- C:\WINDOWS\system32\ws2_32.dll

< >

< %systemroot%*.* /U /s >
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*. >

< %ALLUSERSPROFILE%\Application Data\*.exe /s >

< %APPDATA%\*. >
[2013.08.21 16:10:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Adobe
[2013.12.22 06:55:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\AVAST Software
[2013.12.14 20:27:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\dvdcss
[2013.10.19 11:06:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\ICQ
[2013.09.19 15:33:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\ICQ-Profile
[2013.08.19 15:50:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Identities
[2013.09.19 15:40:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\InstallShield
[2013.08.20 13:09:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Macromedia
[2013.12.24 09:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Malwarebytes
[2013.10.29 11:21:14 | 000,000,000 | --SD | M] -- C:\Documents and Settings\Kryton\Data aplikací\Microsoft
[2013.09.13 07:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Panda Security
[2013.11.02 17:07:19 | 000,000,000 | RH-D | M] -- C:\Documents and Settings\Kryton\Data aplikací\SecuROM
[2013.10.29 07:18:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Sun
[2013.12.24 23:59:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\vlc

< %APPDATA%\*.exe /s >
[2013.12.20 18:18:31 | 000,110,080 | R--- | M] () -- C:\Documents and Settings\Kryton\Data aplikací\Microsoft\Installer\{A358F2F6-2500-420C-989C-25C4F22DF51E}\IconCF33A0CE.exe
[2013.12.20 18:18:31 | 000,110,080 | R--- | M] () -- C:\Documents and Settings\Kryton\Data aplikací\Microsoft\Installer\{A358F2F6-2500-420C-989C-25C4F22DF51E}\IconD7F16134.exe
[2013.12.20 18:18:31 | 000,110,080 | R--- | M] () -- C:\Documents and Settings\Kryton\Data aplikací\Microsoft\Installer\{A358F2F6-2500-420C-989C-25C4F22DF51E}\IconF7A21AF7.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2013.08.20 11:24:38 | 000,223,128 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\dtscsi.sys
[2013.08.20 11:17:21 | 000,664,064 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd.sys
[2013.08.20 11:17:21 | 000,096,256 | ---- | M] () Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\sptd7533.sys

< %systemroot%\System32\config\*.sav >
[2013.08.19 17:24:05 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav
[2013.08.19 17:24:05 | 000,663,552 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2013.08.19 17:24:05 | 000,458,752 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\drivers\*.sys /3 >

< %systemroot%\system32\*.* /3 >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %SYSTEMDRIVE%\*.exe >

< >

< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >

< reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\winlogon" /v GinaDLL /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WUAUSERV
IMAGEPATH REG_EXPAND_SZ %systemroot%\system32\svchost.exe -k netsvcs

< reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS" /v ImagePath /c >
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BITS
IMAGEPATH REG_EXPAND_SZ %SystemRoot%\system32\svchost.exe -k netsvcs

< >

< type c:\boot.ini >> test.txt /c >
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

< %SystemDrive%\PhysicalMBR.bin /md5 >
[2013.12.25 17:42:53 | 000,000,512 | ---- | M] () MD5=C45483383152F42413AA72ACCA1BF429 -- C:\PhysicalMBR.bin

< >

< *crack* /s >
[2007.05.26 09:16:59 | 003,074,346 | ---- | M] () -- \Documents and Settings\Kryton\Plocha\DOTA\plus_crack.zip

< *keygen* /s >

< *AntiWPA* /s >

< *loader* /s >
[2013.09.19 15:53:27 | 000,005,795 | ---- | M] () -- \Program Files\ICQ7.7\imApp\theme\IMAGES\XtraPreloader\loader.jpg
[2013.09.19 15:53:28 | 000,004,180 | ---- | M] () -- \Program Files\ICQ7.7\imApp\theme\IMAGES\XtraPreloader\zlango-preloader.png
[2013.09.19 15:53:26 | 000,005,520 | ---- | M] () -- \Program Files\ICQ7.7\imApp\theme\MUICoreLib\xtraLoader.swf
[2012.04.20 10:29:39 | 000,002,886 | ---- | M] () -- \Program Files\ICQ7.7\Xtraz\icq\content\babylon_feed\preloader01_b.swf
[2012.04.20 10:29:39 | 000,000,402 | ---- | M] () -- \Program Files\ICQ7.7\Xtraz\icq\content\profile_lightboxs\preloader.html
[2004.08.17 14:49:06 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dmloader.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2004.08.17 14:49:06 | 000,035,840 | ---- | M] () -- \WINDOWS\system32\dllcache\dmloader.dll

< *minodlogin* /s >

< *tnod* /s >

< *AutoKMS* /s >

< *activator* /s >

< *serial* /s >
[2004.08.17 15:44:16 | 000,030,301 | ---- | M] () -- \cmdcons\SERIAL.SY_
[2006.02.06 11:13:24 | 000,000,037 | ---- | M] () -- \Documents and Settings\Kryton\Plocha\program\Microsoft-Office-2003-CZ\Microsoft Office 2003 CZ\SERIAL.txt
[2008.07.29 18:16:38 | 000,966,656 | ---- | M] () -- \Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Runtime.Serialization.dll
[2001.10.25 13:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dpserial.dll
[2001.10.25 13:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\serialui.dll
[1 \WINDOWS\system32\*.tmp files -> \WINDOWS\system32\*.tmp -> ]
[2001.10.25 13:00:00 | 000,053,520 | ---- | M] () -- \WINDOWS\system32\dllcache\dpserial.dll
[2001.10.25 13:00:00 | 000,014,336 | ---- | M] () -- \WINDOWS\system32\dllcache\serialui.dll
[2004.08.17 14:57:28 | 000,064,640 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys
[2013.12.25 08:21:43 | 000,064,640 | ---- | M] () -- \WINDOWS\system32\drivers\serial.sys.bak

< *w7lxe* /s >

< End of report >

Re: Policejni vir

Napsal: 25 pro 2013 18:00
od jaroslav.24
extras txt

OTL Extras logfile created on: 25.12.2013 17:41:01 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Kryton\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

446,48 Mb Total Physical Memory | 159,72 Mb Available Physical Memory | 35,77% Memory free
1,03 Gb Paging File | 0,63 Gb Available in Paging File | 61,00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55,88 Gb Total Space | 41,06 Gb Free Space | 73,48% Space Free | Partition Type: NTFS

Computer Name: KRYTON | User Name: Kryton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
htafile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
https [open] -- Reg Error: Value error.
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 1
"FirewallDisableNotify" = 1
"AntiVirusDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\ICQ7.7\ICQ.exe" = C:\Program Files\ICQ7.7\ICQ.exe:*:Enabled:ICQ7.7 -- (ICQ, LLC.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Documents and Settings\Kryton\Plocha\DOTA\Warcraft III\Warcraft III.exe" = C:\Documents and Settings\Kryton\Plocha\DOTA\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III -- (Blizzard Entertainment)
"C:\Program Files\ICQ7.7\ICQ.exe" = C:\Program Files\ICQ7.7\ICQ.exe:*:Enabled:ICQ7.7 -- (ICQ, LLC.)
"C:\Program Files\Black Isle\Lionheart\Lionheart.exe" = C:\Program Files\Black Isle\Lionheart\Lionheart.exe:*:Enabled:Lionheart -- (Reflexive Entertainment, Inc.)
"C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server -- (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series" = Canon MP280 series MP Drivers
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3513FF2C-BDF9-42E7-A3D9-BDC388E0F790}" = Lionheart Bonus Disk
"{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}" = ICQ7.7
"{90110405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-AB0000000001}" = Adobe Reader XI - Czech
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1
"{D71DF8CD-34E5-43E9-93A6-379BA92C1B9A}" = Lionheart
"{DC226AC9-0314-496C-BE6A-B6A132628466}" = SiSAGP driver
"{E91E8912-769D-42F0-8408-0E329443BABC}" = Ralink Wireless LAN Card
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"Avast" = avast! Free Antivirus
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"CCleaner" = CCleaner
"ESET Online Scanner" = ESET Online Scanner v3
"Freelancer 1.0" = Freelancer
"Google Chrome" = Google Chrome
"InstallShield_{3513FF2C-BDF9-42E7-A3D9-BDC388E0F790}" = Lionheart Bonus Disk
"InstallShield_{D71DF8CD-34E5-43E9-93A6-379BA92C1B9A}" = Lionheart
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware verze 1.75.0.1300
"SiS VGA Driver" = SiS VGA Utilities
"SiSLan" = SiS 900 PCI Fast Ethernet Adapter Driver
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 2.1.2
"WinRAR archiver" = WinRAR
"XviD" = XviD MPEG-4 Codec
"XviD_is1" = XviD 1.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 19.10.2013 8:45:28 | Computer Name = KRYTON | Source = Application Error | ID = 1000
Description = Chybující aplikace explorer.exe, verze 6.0.2900.2180, chybující modul
xvid.dll, verze 0.0.0.0, adresa chyby 0x0000eb92.

Error - 8.11.2013 9:07:12 | Computer Name = KRYTON | Source = Application Error | ID = 1000
Description = Chybující aplikace c2e5mfgxy.exe, verze 0.0.0.0, chybující modul mshtml.dll,
verze 6.0.2900.2180, adresa chyby 0x0007911f.

Error - 9.11.2013 14:42:06 | Computer Name = KRYTON | Source = Application Error | ID = 1000
Description = Chybující aplikace plugin-container.exe, verze 25.0.0.5046, chybující
modul mozalloc.dll, verze 25.0.0.5046, adresa chyby 0x0000119c.

Error - 15.11.2013 5:15:27 | Computer Name = KRYTON | Source = MsiInstaller | ID = 1013
Description = Produkt: Lionheart Bonus Disk - 1: Tuto instalaci nelze spustit přímým
spuštěním balíku MSI. Je nutné spustit program setup.exe.

Error - 19.11.2013 11:11:19 | Computer Name = KRYTON | Source = Application Error | ID = 1000
Description = Chybující aplikace lionheart.exe, verze 1.0.0.0, chybující modul lionheart.exe,
verze 1.0.0.0, adresa chyby 0x000c6a0f.

Error - 6.12.2013 12:15:28 | Computer Name = KRYTON | Source = Application Error | ID = 1000
Description = Chybující aplikace fs2.exe, verze 1.0.0.1, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x00000000.

Error - 6.12.2013 12:16:23 | Computer Name = KRYTON | Source = Application Error | ID = 1000
Description = Chybující aplikace fs2.exe, verze 1.0.0.1, chybující modul unknown,
verze 0.0.0.0, adresa chyby 0x00000000.

[ System Events ]
Error - 25.12.2013 10:31:26 | Computer Name = KRYTON | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly pro Microsoft.VC80.MFCLOC se nezdařila. Referenční
chybová zpráva: Sestavení určené odkazem není v systému nainstalováno. .

Error - 25.12.2013 10:31:26 | Computer Name = KRYTON | Source = SideBySide | ID = 16842811
Description = Generate Activation Context pro C:\Program Files\Canon\Solution Menu
EX\MFC80U.DLL se nezdařila. Referenční chybová zpráva: Operace byla dokončena úspěšně.
.


Error - 25.12.2013 11:10:07 | Computer Name = KRYTON | Source = Service Control Manager | ID = 7034
Description = Služba Služba brány aplikačního rozhraní byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 25.12.2013 11:10:07 | Computer Name = KRYTON | Source = Service Control Manager | ID = 7034
Description = Služba Zařazování tisku byla neočekávaně ukončena. Tento stav nastal
již 1krát.

Error - 25.12.2013 11:18:38 | Computer Name = KRYTON | Source = SideBySide | ID = 16842784
Description = Závislá symbolická adresa Microsoft.VC80.MFCLOC nebyla nalezena a
poslední chyba byla Sestavení určené odkazem není v systému nainstalováno. .

Error - 25.12.2013 11:18:38 | Computer Name = KRYTON | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly pro Microsoft.VC80.MFCLOC se nezdařila. Referenční
chybová zpráva: Sestavení určené odkazem není v systému nainstalováno. .

Error - 25.12.2013 11:18:38 | Computer Name = KRYTON | Source = SideBySide | ID = 16842811
Description = Generate Activation Context pro C:\Program Files\Canon\Solution Menu
EX\MFC80U.DLL se nezdařila. Referenční chybová zpráva: Operace byla dokončena úspěšně.
.


Error - 25.12.2013 11:18:38 | Computer Name = KRYTON | Source = SideBySide | ID = 16842784
Description = Závislá symbolická adresa Microsoft.VC80.MFCLOC nebyla nalezena a
poslední chyba byla Sestavení určené odkazem není v systému nainstalováno. .

Error - 25.12.2013 11:18:38 | Computer Name = KRYTON | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly pro Microsoft.VC80.MFCLOC se nezdařila. Referenční
chybová zpráva: Sestavení určené odkazem není v systému nainstalováno. .

Error - 25.12.2013 11:18:38 | Computer Name = KRYTON | Source = SideBySide | ID = 16842811
Description = Generate Activation Context pro C:\Program Files\Canon\Solution Menu
EX\MFC80U.DLL se nezdařila. Referenční chybová zpráva: Operace byla dokončena úspěšně.
.



< End of report >

Re: Policejni vir

Napsal: 25 pro 2013 19:57
od Márty84
:!: Jestli bude Avast rvat, ze to chce otevrit v sandboxu, nedovolte to! Vyberte moznost Otevrit normalne
:arrow: Znovu spustte OTL
Do spodniho okna vlozte nasledujici text (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[CreateRestorePoint]

:services
gupdate
gupdatem

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job
c:\documents and settings\Kryton\Local Settings\Data aplikací\Avg2014

:otl
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Kryton\Nabídka Start\Programy\IMVU\Run IMVU.lnk File not found
O15 - HKLM\..Trusted Domains: localhost ([]http in Internet)
[2013.12.24 08:59:09 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300 (1).exe
[2013.12.24 08:58:47 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300.exe
[2013.12.21 16:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Avg2014
[2013.09.13 07:35:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kryton\Data aplikací\Panda Security
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[2 C:\WINDOWS\Installer\*.tmp files -> C:\WINDOWS\Installer\*.tmp -> ]
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
Kliknete na Opravit a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu se objevi novy log, ten sem dejte.

Re: Policejni vir

Napsal: 26 pro 2013 06:19
od jaroslav.24
Tady je

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: All Users.WINDOWS

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Kryton
->Temp folder emptied: 856 bytes
->Temporary Internet Files folder emptied: 1414925 bytes
->Google Chrome cache emptied: 127866649 bytes
->Flash cache emptied: 523 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33186 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1279656 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 125,00 mb


[EMPTYFLASH]

User: All Users

User: All Users.WINDOWS

User: Default User

User: Default User.WINDOWS

User: Kryton
->Flash cache emptied: 0 bytes

User: LocalService

User: LocalService.NT AUTHORITY

User: NetworkService

User: NetworkService.NT AUTHORITY

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTL Restore Point
========== SERVICES/DRIVERS ==========
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1cefdb3bc249d14.job moved successfully.
c:\documents and settings\Kryton\Local Settings\Data aplikací\Avg2014\log folder moved successfully.
c:\documents and settings\Kryton\Local Settings\Data aplikací\Avg2014 folder moved successfully.
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{d9288080-1baa-4bc4-9cf8-a92d743db949}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d9288080-1baa-4bc4-9cf8-a92d743db949}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\localhost\ deleted successfully.
C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300 (1).exe moved successfully.
C:\Documents and Settings\Kryton\Plocha\mbam-setup-1.75.0.1300.exe moved successfully.
Folder C:\Documents and Settings\Kryton\Local Settings\Data aplikací\Avg2014\ not found.
C:\Documents and Settings\Kryton\Data aplikací\Panda Security\Panda Cloud Antivirus folder moved successfully.
C:\Documents and Settings\Kryton\Data aplikací\Panda Security folder moved successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP13B.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP216.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP945C.tmp folder deleted successfully.
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAPEBBD.tmp folder deleted successfully.
C:\WINDOWS\Installer\MSI42A.tmp deleted successfully.
C:\WINDOWS\Installer\MSI42C.tmp deleted successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 12262013_061605

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Re: Policejni vir

Napsal: 26 pro 2013 09:22
od Márty84
:arrow: Prejmenujte ComboFix na Uninstall a spustte ho. CF by se mel odinstalovat.

:arrow:
vyosek píše: :arrow: T-Cleaner http://tharifas.sweb.cz/T-Cleaner.exe
  • Stahnete a spustte
  • Pro potvrzeni volby mackejte A, Enter
  • Po pouziti utilitu smazte
  • Antiviry mohou utilitu chybne oznacit jako vir - jedna se o falesny poplach - takze v pohode stahnete (pripadne vypnete pri stahovani antivir)
:arrow: Stahnete OTC http://oldtimer.geekstogo.com/OTC.exe , ulozte a spustte.
Kliknete na napis CleanUp a pote OK - Po uklidu dojde k restartu pc.

:arrow: Stahnete TFC http://oldtimer.geekstogo.com/TFC.exe , ulozte a spustte
Kliknete na START a pote OK - Po uklidu dojde k restartu pc.
Po pouziti muzete programek smazat

:arrow: Stahnete Ccleaner http://www.stahuj.centrum.cz/utility_a_ ... /ccleaner/ a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!

:arrow: Defragmentujte disk(y)
Stahnete program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak je na tom pc.

Re: Policejni vir

Napsal: 26 pro 2013 12:19
od jaroslav.24
Provedeno, vykonáno.
Mockrát vám děkuji.
Notes spokojeně vrní a funguje na 100 procent.
Opravdu moc díky.

Re: Policejni vir

Napsal: 26 pro 2013 12:39
od Márty84
To jsem rad, nemate zac! :)

Mejte se a treba zase nekdy :bye:

:closed: