
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Total XP Security - Jak ho zničit!??
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
Mě je to jedno, hlavně aby Vám to nevadilo. Hlavně když ntb bude šlapat. On je průser, že modrou "smrt" vyfotit nelze, neb se ukáže cca ani ne na 1 vteřinu a hned reset, je to mžik. Ty soubory ndis atd - ano, byly ve složce, ndis nešel extrahovat.
Re: Total XP Security - Jak ho zničit!??
Přečtěte si prosím tu sz
Jak nešel extrahovat?
, mám Vám přepsat příkazy, aby to bylo na soubory uložené v té složce ndis?

Jak nešel extrahovat?

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Total XP Security - Jak ho zničit!??
V příloze máte nový ndis.sys a pak použijte ten skript
Start - ovládací panely - systém
-klikněte na kartu upřesnit - uplně dole na tlačítko Nastavení
-vyškrtněte políčko automaticky restartovat
-po naběhnutí systému by se měla objevit místo restartu modrá obrazovka. Opište si tam chyby, jako např STOP: 00000X565 atd a vložte je sem.
- pak restartujte a jděte do nouzového režimu , podívejte se, jestli se ve složce C:\WINDOWS\Minidump
nejsou nějaké soubory, pokud ano, dejte je do zipu a pošlete na http://www.leteckaposta.cz, link vložte zde.


-klikněte na kartu upřesnit - uplně dole na tlačítko Nastavení
-vyškrtněte políčko automaticky restartovat
-po naběhnutí systému by se měla objevit místo restartu modrá obrazovka. Opište si tam chyby, jako např STOP: 00000X565 atd a vložte je sem.
- pak restartujte a jděte do nouzového režimu , podívejte se, jestli se ve složce C:\WINDOWS\Minidump
nejsou nějaké soubory, pokud ano, dejte je do zipu a pošlete na http://www.leteckaposta.cz, link vložte zde.
- Přílohy
-
- ndis.rar
- (88.98 KiB) Staženo 103 x
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
ComboFix 10-03-21.05 - Administrator 23.03.2010 2:45.4.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.729 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\Anubides.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\KGootkit.sys
.
--------------- FCopy ---------------
c:\ndis.sys --> c:\windows\system32\drivers\ndis.sys
c:\ndis.sys --> c:\windows\system32\dllcache\ndis.sys
c:\cdrom.sys --> c:\windows\system32\drivers\cdrom.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KGOOTKIT
-------\Service_KGootkit
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-23 do 2010-03-23 )))))))))))))))))))))))))))))))
.
2013-08-25 22:27 . 2008-08-06 13:51 1200128 ----a-w- c:\windows\RtlUpd.exe
2013-08-25 22:27 . 2008-06-18 16:01 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2013-08-25 22:27 . 2007-11-20 16:15 1826816 ----a-w- c:\windows\SkyTel.exe
2013-08-25 22:27 . 2008-08-12 14:10 4751360 ----a-w- c:\windows\system32\drivers\rtkhdaud.sys
2013-08-25 22:27 . 2008-06-19 14:27 9715200 ----a-w- c:\windows\RTLCPL.EXE
2013-08-25 22:27 . 2008-07-31 13:05 16806912 ----a-w- c:\windows\RTHDCPL.EXE
2013-08-25 22:27 . 2007-06-28 14:44 2165760 ----a-w- c:\windows\MicCal.exe
2013-08-25 22:27 . 2013-08-25 22:27 -------- d-----w- c:\program files\Realtek
2013-08-25 22:27 . 2008-06-19 14:42 2808832 ----a-w- c:\windows\ALCWZRD.EXE
2013-08-25 22:27 . 2008-06-19 14:20 57344 ----a-w- c:\windows\ALCMTR.EXE
2013-08-25 22:27 . 2008-07-29 13:42 528384 ----a-w- c:\windows\RtlExUpd.dll
2013-08-11 22:14 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-08-11 22:13 . 2008-04-13 22:09 5504 ----a-w- c:\windows\system32\drivers\mstee.sys
2013-08-11 22:13 . 2008-04-13 22:16 10880 ----a-w- c:\windows\system32\drivers\ndisip.sys
2013-08-11 22:13 . 2008-04-13 22:16 15232 ----a-w- c:\windows\system32\drivers\streamip.sys
2013-08-11 22:12 . 2008-04-13 22:16 11136 ----a-w- c:\windows\system32\drivers\slip.sys
2013-08-11 22:12 . 2008-04-13 22:16 19200 ----a-w- c:\windows\system32\drivers\wstcodec.sys
2013-08-11 22:12 . 2008-04-13 22:16 85248 ----a-w- c:\windows\system32\drivers\nabtsfec.sys
2013-08-11 22:12 . 2008-04-13 22:16 17024 ----a-w- c:\windows\system32\drivers\ccdecode.sys
2013-08-11 22:12 . 2008-04-14 06:52 54272 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2013-08-11 22:12 . 2008-04-14 06:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2013-08-11 22:12 . 2008-04-13 22:16 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-08-11 22:12 . 2008-04-13 22:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-18 08:11 . 2008-08-19 20:16 47272 ----a-w- c:\windows\system32\drivers\btwusb.sys
2012-09-18 08:11 . 2008-07-24 15:37 156816 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2012-09-18 08:11 . 2007-09-20 09:59 106557 ----a-w- c:\windows\system32\btw_ci.dll
2012-09-18 08:10 . 2008-08-19 20:16 991656 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2012-09-18 08:10 . 2008-05-30 09:46 534568 ----a-w- c:\windows\system32\drivers\btaudio.sys
2012-09-18 08:10 . 2008-02-04 15:57 37160 ----a-w- c:\windows\system32\drivers\btport.sys
2012-09-18 08:10 . 2012-09-18 08:10 -------- d-----w- c:\program files\WIDCOMM
2011-09-11 15:59 . 2011-09-11 15:59 -------- d-----w- c:\program files\EeePC
2011-09-11 15:59 . 2008-04-08 13:59 10752 ----a-w- c:\windows\system32\drivers\ASUSACPI.SYS
2011-09-11 15:17 . 2011-09-11 15:17 -------- d-----w- c:\program files\Elantech
2010-03-23 01:38 . 2008-04-13 19:20 182656 ------w- C:\ndis.sys
2010-03-23 00:28 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 00:28 . 2010-03-23 00:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-23 00:28 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-23 00:10 . 2010-03-23 00:10 -------- d-----w- C:\bb
2010-03-23 00:10 . 2010-03-23 00:49 -------- d-----w- C:\ndis
2010-03-23 00:10 . 2008-04-13 18:40 62976 ------w- C:\cdrom.sys
2010-03-22 23:00 . 2010-03-22 23:00 -------- d-----w- C:\_OTM
2010-03-22 21:23 . 2010-03-22 21:23 -------- d-----w- C:\rsit
2010-03-22 20:52 . 2010-03-22 23:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-22 20:25 . 2010-03-22 20:25 0 ----a-w- c:\windows\nsreg.dat
2010-03-22 20:19 . 2010-03-22 20:19 -------- d-----w- c:\program files\Trend Micro
2010-03-22 19:58 . 2010-03-22 19:58 -------- d-----w- c:\program files\CCleaner
2010-03-22 18:44 . 2010-03-22 20:44 -------- d-----w- c:\program files\a-squared Free
2010-03-21 00:15 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-25 22:27 . 2008-08-07 21:52 319488 ----a-w- c:\windows\HideWin.exe
2010-03-23 00:59 . 2008-08-07 03:50 62448 ----a-w- c:\windows\system32\perfc005.dat
2010-03-23 00:59 . 2008-08-07 03:50 380134 ----a-w- c:\windows\system32\perfh005.dat
2010-03-22 21:27 . 2008-08-07 02:07 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-22 21:27 . 2008-08-07 02:07 2378 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-22 20:12 . 2009-05-26 21:00 -------- d-----w- c:\program files\KaM - The Peasants Rebellion
2009-12-31 16:50 . 2008-08-07 03:50 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2008-05-07 14:34 . 2008-08-07 22:20 15523560 ----a-w- c:\program files\U1 Setup.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-03-22_23.34.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 03:50 . 2010-03-23 00:59 53214 c:\windows\system32\perfc009.dat
- 2008-08-07 03:50 . 2010-03-22 23:26 53214 c:\windows\system32\perfc009.dat
+ 2008-08-07 03:50 . 2008-04-14 12:00 15360 c:\windows\system32\ctfmon.exe
- 2010-03-22 23:26 . 2010-03-22 23:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-03-22 23:26 . 2010-03-23 01:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2013-08-11 22:13 . 2010-03-23 01:44 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2013-08-11 22:13 . 2010-03-22 23:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-03-23 01:05 . 2010-03-23 01:44 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-07 03:50 . 2010-03-23 00:59 380992 c:\windows\system32\perfh009.dat
- 2008-08-07 03:50 . 2010-03-22 23:26 380992 c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2011-9-11 311296]
TMMonitor.lnk - c:\program files\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2009-4-13 258048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 09:34 5724184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [22.3.2010 19:44 1858144]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.5.2009 21:36 721904]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [7.8.2008 22:54 625024]
S3 uxkx1;ASUS My Cinema U3100 Mini DVBT;c:\windows\system32\drivers\uxkx1.sys [12.4.2009 16:08 459264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}]
\Shell\AutoRun\command - F:\jedna/stvar.exe
\Shell\explore\command - F:\jedna/stvar.exe
\Shell\open\command - F:\jedna/stvar.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}]
\Shell\AutoRun\command - F:\ime/moje.exe
\Shell\explore\command - F:\ime/moje.exe
\Shell\open\command - F:\ime/moje.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}]
\Shell\AutoRun\command - f:\opop\severina.exe
\Shell\explore\command - f:\.////opop/\\\\severina.exe
\Shell\open\command - f:\opop/////\\\\severina.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath -
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-23 02:51
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(3596)
c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
c:\program files\eee storage\xpclient.dll
c:\program files\eee storage\logicnp.eznamespaceextensions.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Celkový čas: 2010-03-23 02:55:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-23 01:54
ComboFix2.txt 2010-03-23 01:04
ComboFix3.txt 2010-03-23 00:26
ComboFix4.txt 2010-03-22 23:37
Před spuštěním: Volných bajtů: 75 501 887 488
Po spuštění: Volných bajtů: 75 460 792 320
- - End Of File - - 072C1E2DD342FC31D143955987442F15
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.729 [GMT 1:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\Anubides.exe
Použité ovládací přepínače :: c:\documents and settings\Administrator\Plocha\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\KGootkit.sys
.
--------------- FCopy ---------------
c:\ndis.sys --> c:\windows\system32\drivers\ndis.sys
c:\ndis.sys --> c:\windows\system32\dllcache\ndis.sys
c:\cdrom.sys --> c:\windows\system32\drivers\cdrom.sys
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_KGOOTKIT
-------\Service_KGootkit
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-23 do 2010-03-23 )))))))))))))))))))))))))))))))
.
2013-08-25 22:27 . 2008-08-06 13:51 1200128 ----a-w- c:\windows\RtlUpd.exe
2013-08-25 22:27 . 2008-06-18 16:01 77824 ----a-w- c:\windows\SOUNDMAN.EXE
2013-08-25 22:27 . 2007-11-20 16:15 1826816 ----a-w- c:\windows\SkyTel.exe
2013-08-25 22:27 . 2008-08-12 14:10 4751360 ----a-w- c:\windows\system32\drivers\rtkhdaud.sys
2013-08-25 22:27 . 2008-06-19 14:27 9715200 ----a-w- c:\windows\RTLCPL.EXE
2013-08-25 22:27 . 2008-07-31 13:05 16806912 ----a-w- c:\windows\RTHDCPL.EXE
2013-08-25 22:27 . 2007-06-28 14:44 2165760 ----a-w- c:\windows\MicCal.exe
2013-08-25 22:27 . 2013-08-25 22:27 -------- d-----w- c:\program files\Realtek
2013-08-25 22:27 . 2008-06-19 14:42 2808832 ----a-w- c:\windows\ALCWZRD.EXE
2013-08-25 22:27 . 2008-06-19 14:20 57344 ----a-w- c:\windows\ALCMTR.EXE
2013-08-25 22:27 . 2008-07-29 13:42 528384 ----a-w- c:\windows\RtlExUpd.dll
2013-08-11 22:14 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2013-08-11 22:13 . 2008-04-13 22:09 5504 ----a-w- c:\windows\system32\drivers\mstee.sys
2013-08-11 22:13 . 2008-04-13 22:16 10880 ----a-w- c:\windows\system32\drivers\ndisip.sys
2013-08-11 22:13 . 2008-04-13 22:16 15232 ----a-w- c:\windows\system32\drivers\streamip.sys
2013-08-11 22:12 . 2008-04-13 22:16 11136 ----a-w- c:\windows\system32\drivers\slip.sys
2013-08-11 22:12 . 2008-04-13 22:16 19200 ----a-w- c:\windows\system32\drivers\wstcodec.sys
2013-08-11 22:12 . 2008-04-13 22:16 85248 ----a-w- c:\windows\system32\drivers\nabtsfec.sys
2013-08-11 22:12 . 2008-04-13 22:16 17024 ----a-w- c:\windows\system32\drivers\ccdecode.sys
2013-08-11 22:12 . 2008-04-14 06:52 54272 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2013-08-11 22:12 . 2008-04-14 06:52 54272 ----a-w- c:\windows\system32\vfwwdm32.dll
2013-08-11 22:12 . 2008-04-13 22:16 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2013-08-11 22:12 . 2008-04-13 22:15 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-09-18 08:11 . 2008-08-19 20:16 47272 ----a-w- c:\windows\system32\drivers\btwusb.sys
2012-09-18 08:11 . 2008-07-24 15:37 156816 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2012-09-18 08:11 . 2007-09-20 09:59 106557 ----a-w- c:\windows\system32\btw_ci.dll
2012-09-18 08:10 . 2008-08-19 20:16 991656 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2012-09-18 08:10 . 2008-05-30 09:46 534568 ----a-w- c:\windows\system32\drivers\btaudio.sys
2012-09-18 08:10 . 2008-02-04 15:57 37160 ----a-w- c:\windows\system32\drivers\btport.sys
2012-09-18 08:10 . 2012-09-18 08:10 -------- d-----w- c:\program files\WIDCOMM
2011-09-11 15:59 . 2011-09-11 15:59 -------- d-----w- c:\program files\EeePC
2011-09-11 15:59 . 2008-04-08 13:59 10752 ----a-w- c:\windows\system32\drivers\ASUSACPI.SYS
2011-09-11 15:17 . 2011-09-11 15:17 -------- d-----w- c:\program files\Elantech
2010-03-23 01:38 . 2008-04-13 19:20 182656 ------w- C:\ndis.sys
2010-03-23 00:28 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-23 00:28 . 2010-03-23 00:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-23 00:28 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-23 00:10 . 2010-03-23 00:10 -------- d-----w- C:\bb
2010-03-23 00:10 . 2010-03-23 00:49 -------- d-----w- C:\ndis
2010-03-23 00:10 . 2008-04-13 18:40 62976 ------w- C:\cdrom.sys
2010-03-22 23:00 . 2010-03-22 23:00 -------- d-----w- C:\_OTM
2010-03-22 21:23 . 2010-03-22 21:23 -------- d-----w- C:\rsit
2010-03-22 20:52 . 2010-03-22 23:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-03-22 20:25 . 2010-03-22 20:25 0 ----a-w- c:\windows\nsreg.dat
2010-03-22 20:19 . 2010-03-22 20:19 -------- d-----w- c:\program files\Trend Micro
2010-03-22 19:58 . 2010-03-22 19:58 -------- d-----w- c:\program files\CCleaner
2010-03-22 18:44 . 2010-03-22 20:44 -------- d-----w- c:\program files\a-squared Free
2010-03-21 00:15 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-25 22:27 . 2008-08-07 21:52 319488 ----a-w- c:\windows\HideWin.exe
2010-03-23 00:59 . 2008-08-07 03:50 62448 ----a-w- c:\windows\system32\perfc005.dat
2010-03-23 00:59 . 2008-08-07 03:50 380134 ----a-w- c:\windows\system32\perfh005.dat
2010-03-22 21:27 . 2008-08-07 02:07 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-22 21:27 . 2008-08-07 02:07 2378 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-03-22 20:12 . 2009-05-26 21:00 -------- d-----w- c:\program files\KaM - The Peasants Rebellion
2009-12-31 16:50 . 2008-08-07 03:50 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2008-05-07 14:34 . 2008-08-07 22:20 15523560 ----a-w- c:\program files\U1 Setup.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-03-22_23.34.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 03:50 . 2010-03-23 00:59 53214 c:\windows\system32\perfc009.dat
- 2008-08-07 03:50 . 2010-03-22 23:26 53214 c:\windows\system32\perfc009.dat
+ 2008-08-07 03:50 . 2008-04-14 12:00 15360 c:\windows\system32\ctfmon.exe
- 2010-03-22 23:26 . 2010-03-22 23:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-03-22 23:26 . 2010-03-23 01:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2013-08-11 22:13 . 2010-03-23 01:44 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2013-08-11 22:13 . 2010-03-22 23:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-03-23 01:05 . 2010-03-23 01:44 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-07 03:50 . 2010-03-23 00:59 380992 c:\windows\system32\perfh009.dat
- 2008-08-07 03:50 . 2010-03-22 23:26 380992 c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2011-9-11 311296]
TMMonitor.lnk - c:\program files\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2009-4-13 258048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 09:34 5724184 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [22.3.2010 19:44 1858144]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.5.2009 21:36 721904]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [7.8.2008 22:54 625024]
S3 uxkx1;ASUS My Cinema U3100 Mini DVBT;c:\windows\system32\drivers\uxkx1.sys [12.4.2009 16:08 459264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}]
\Shell\AutoRun\command - F:\jedna/stvar.exe
\Shell\explore\command - F:\jedna/stvar.exe
\Shell\open\command - F:\jedna/stvar.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}]
\Shell\AutoRun\command - F:\ime/moje.exe
\Shell\explore\command - F:\ime/moje.exe
\Shell\open\command - F:\ime/moje.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}]
\Shell\AutoRun\command - f:\opop\severina.exe
\Shell\explore\command - f:\.////opop/\\\\severina.exe
\Shell\open\command - f:\opop/////\\\\severina.exe
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Odeslat do zařízení &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Odeslat do zařízení Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath -
---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-23 02:51
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(3596)
c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
c:\program files\eee storage\xpclient.dll
c:\program files\eee storage\logicnp.eznamespaceextensions.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
.
**************************************************************************
.
Celkový čas: 2010-03-23 02:55:00 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-03-23 01:54
ComboFix2.txt 2010-03-23 01:04
ComboFix3.txt 2010-03-23 00:26
ComboFix4.txt 2010-03-22 23:37
Před spuštěním: Volných bajtů: 75 501 887 488
Po spuštění: Volných bajtů: 75 460 792 320
- - End Of File - - 072C1E2DD342FC31D143955987442F15
Re: Total XP Security - Jak ho zničit!??


Připojte ji

-spusťte, zvolte jazyk E - potvrdťe enter
-klikněte na volbu 1 - enter
- po skenu sem vložte log , pokud na Vás nevyskočí, najdete ho C:\UsbFix.txt
Pro jistotu uděláme sken Gmerem, měl jste tam kupu potvůrek, tak at máme jistotu, že je to ok


- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, klikněte na Save a tím si uložíte log,který sem vložíte
-Podle návodu v odkazu provedete druhý sken a log sem také vložíte.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
############################## | UsbFix V6.100 |
User : Kacka (Administrators) # N-WP7F7O85PI341
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 3:36:39 | 23.3.2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Microsoft Windows XP Home Edition (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 6.0.2900.5512
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Místní pevný disk # 79,99 Go (70,01 Go free) # NTFS
D:\ -> Místní pevný disk # 61,2 Go (10,64 Go free) # NTFS
################## | Files # Infected Folders |
################## | Registry |
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
################## | Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}
Shell\AutoRun\command =F:\jedna/stvar.exe
Shell\explore\command =F:\jedna/stvar.exe
Shell\open\command =F:\jedna/stvar.exe
HKCU\..\..\Explorer\MountPoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}
Shell\AutoRun\command =F:\ime/moje.exe
Shell\explore\command =F:\ime/moje.exe
Shell\open\command =F:\ime/moje.exe
HKCU\..\..\Explorer\MountPoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}
Shell\AutoRun\command =F:\OPOP\severina.exe
Shell\explore\command =F:\.////OPOP/\\\\severina.exe
Shell\open\command =F:\OPOP/////\\\\severina.exe
################## | Vaccin |
(!) This computer is not vaccinated!
################## | ! End of report # UsbFix V6.100 ! |
User : Kacka (Administrators) # N-WP7F7O85PI341
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 3:36:39 | 23.3.2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Atom(TM) CPU N270 @ 1.60GHz
Microsoft Windows XP Home Edition (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 6.0.2900.5512
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Místní pevný disk # 79,99 Go (70,01 Go free) # NTFS
D:\ -> Místní pevný disk # 61,2 Go (10,64 Go free) # NTFS
################## | Files # Infected Folders |
################## | Registry |
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
################## | Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}
Shell\AutoRun\command =F:\jedna/stvar.exe
Shell\explore\command =F:\jedna/stvar.exe
Shell\open\command =F:\jedna/stvar.exe
HKCU\..\..\Explorer\MountPoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}
Shell\AutoRun\command =F:\ime/moje.exe
Shell\explore\command =F:\ime/moje.exe
Shell\open\command =F:\ime/moje.exe
HKCU\..\..\Explorer\MountPoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}
Shell\AutoRun\command =F:\OPOP\severina.exe
Shell\explore\command =F:\.////OPOP/\\\\severina.exe
Shell\open\command =F:\OPOP/////\\\\severina.exe
################## | Vaccin |
(!) This computer is not vaccinated!
################## | ! End of report # UsbFix V6.100 ! |
Re: Total XP Security - Jak ho zničit!??


***********
Nechám Vám tu ještě pár návoodů, co máte dělat, já tu budu nejspíš až večer, nebo přes den nakouknu

1.

- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.

http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech

***********
2.

- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, klikněte na Save a tím si uložíte log,který sem vložíte
-Podle návodu v odkazu provedete druhý sken a log sem také vložíte.
***********
3.

-Podle návodu nainstalujte a proveďte sken
-co najde nechejte léčit, mazat
-sken může trvat několik hodin
-vložte zde log z výsledky
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
PC se chová zatím bezproblémově, nabíhá rychle, žádná chybová hlášení, zatím to vypadá dobře...jinak celý bod 1 proveden, jdu na bod 2...
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kacka at 2010-03-23 14:17:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 72 GB (88%) free of 82 GB
Total RAM: 1015 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:40, on 23.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kacka\Plocha\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Kacka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://eeepc.asus.com/global
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
--
End of file - 6261 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-12 1372160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
TMMonitor.lnk - C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3.5"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}]
shell\AutoRun\command - F:\jedna/stvar.exe
shell\explore\command - F:\jedna/stvar.exe
shell\open\command - F:\jedna/stvar.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}]
shell\AutoRun\command - F:\ime/moje.exe
shell\explore\command - F:\ime/moje.exe
shell\open\command - F:\ime/moje.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}]
shell\AutoRun\command - F:\OPOP\severina.exe
shell\explore\command - F:\.////OPOP/\\\\severina.exe
shell\open\command - F:\OPOP/////\\\\severina.exe
======List of files/folders created in the last 1 months======
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SkyTel.exe
2013-08-25 23:27:58 ----A---- C:\WINDOWS\RtlUpd.exe
2013-08-25 23:27:57 ----A---- C:\WINDOWS\RTLCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\RTHDCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\MicCal.exe
2013-08-25 23:27:54 ----D---- C:\Program Files\Realtek
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCWZRD.EXE
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCMTR.EXE
2013-08-25 23:27:39 ----A---- C:\WINDOWS\RtlExUpd.dll
2013-08-17 21:22:50 ----A---- C:\WINDOWS\system32\DetectDevice.txt
2013-08-11 23:14:29 ----A---- C:\WINDOWS\system32\wmpns.dll
2013-08-11 23:12:48 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2012-09-18 09:11:00 ----A---- C:\WINDOWS\system32\btw_ci.dll
2012-09-18 09:10:54 ----D---- C:\Program Files\WIDCOMM
2011-09-11 16:59:53 ----D---- C:\Program Files\EeePC
2011-09-11 16:17:29 ----D---- C:\Program Files\Elantech
2010-03-23 14:17:32 ----D---- C:\rsit
2010-03-23 13:54:36 ----SD---- C:\Anubides
2010-03-23 03:21:15 ----SHD---- C:\RECYCLER
2010-03-23 03:16:05 ----D---- C:\Program Files\Avira
2010-03-23 03:16:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-03-23 02:58:35 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Mozilla
2010-03-23 02:55:04 ----D---- C:\WINDOWS\temp
2010-03-23 02:51:30 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Malwarebytes
2010-03-23 02:50:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-23 01:28:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-23 01:28:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-23 01:10:59 ----D---- C:\bb
2010-03-23 01:10:20 ----D---- C:\ndis
2010-03-23 00:26:27 ----A---- C:\Boot.bak
2010-03-23 00:26:21 ----RASHD---- C:\cmdcons
2010-03-22 21:52:32 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-03-22 21:52:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-22 21:47:39 ----A---- C:\WINDOWS\fn0oxom410fpdatx5xx447ni.ini
2010-03-22 21:20:57 ----D---- C:\Program Files\Mozilla Firefox
2010-03-22 21:19:17 ----D---- C:\Program Files\Trend Micro
2010-03-22 20:58:56 ----D---- C:\Program Files\CCleaner
2010-03-22 20:01:18 ----A---- C:\WINDOWS\system32\MRT.INI
2010-03-22 19:51:16 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-22 19:44:06 ----D---- C:\Program Files\a-squared Free
2010-03-21 01:15:53 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-11 03:01:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-02-25 11:08:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
======List of files/folders modified in the last 1 months======
2013-08-25 23:28:10 ----D---- C:\WINDOWS\system32\RTCOM
2013-08-25 23:27:39 ----A---- C:\WINDOWS\HideWin.exe
2013-08-13 03:29:47 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-09-18 10:32:30 ----D---- C:\WINDOWS\repair
2012-09-18 09:18:16 ----A---- C:\WINDOWS\oemver.txt
2011-09-11 16:59:53 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-23 14:17:40 ----D---- C:\WINDOWS\Prefetch
2010-03-23 14:14:39 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-23 14:14:34 ----D---- C:\WINDOWS
2010-03-23 14:14:02 ----D---- C:\WINDOWS\system32\Restore
2010-03-23 14:14:01 ----SHD---- C:\System Volume Information
2010-03-23 13:46:27 ----D---- C:\WINDOWS\system32
2010-03-23 13:46:27 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-23 03:16:14 ----D---- C:\WINDOWS\system32\drivers
2010-03-23 03:16:13 ----HD---- C:\WINDOWS\inf
2010-03-23 03:16:05 ----RD---- C:\Program Files
2010-03-23 03:15:02 ----SHD---- C:\WINDOWS\Installer
2010-03-23 03:15:01 ----D---- C:\WINDOWS\WinSxS
2010-03-23 03:15:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-23 02:51:09 ----A---- C:\WINDOWS\system.ini
2010-03-23 02:49:51 ----D---- C:\WINDOWS\system32\config
2010-03-23 02:47:47 ----D---- C:\WINDOWS\AppPatch
2010-03-23 02:47:46 ----D---- C:\Program Files\Common Files
2010-03-23 02:45:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-23 00:31:57 ----D---- C:\Program Files\Internet Explorer
2010-03-23 00:31:50 ----D---- C:\Program Files\Adobe
2010-03-23 00:26:27 ----RASH---- C:\boot.ini
2010-03-23 00:01:12 ----SD---- C:\WINDOWS\Tasks
2010-03-22 21:12:28 ----D---- C:\Program Files\KaM - The Peasants Rebellion
2010-03-22 21:01:31 ----D---- C:\WINDOWS\Debug
2010-03-22 18:38:21 ----D---- C:\Documents and Settings
2010-03-20 05:34:20 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Skype
2010-03-20 00:04:26 ----D---- C:\Documents and Settings\Kacka\Data aplikací\skypePM
2010-03-19 20:05:57 ----D---- C:\WINDOWS\system
2010-03-11 03:02:45 ----A---- C:\WINDOWS\win.ini
2010-03-11 03:01:04 ----D---- C:\Program Files\Movie Maker
2010-03-11 03:00:43 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-06 11:56:39 ----D---- C:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-08-19 991656]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-08-19 47272]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-08-12 4751360]
R3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2008-08-25 26112]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-03-11 36864]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2006-11-10 18688]
S3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-03 546976]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-22 21568]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2008-03-28 625024]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 uxkx1;ASUS My Cinema U3100 Mini DVBT; C:\WINDOWS\system32\DRIVERS\uxkx1.sys [2008-02-15 459264]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe [2009-10-01 1858144]
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-02 346720]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kacka at 2010-03-23 14:17:32
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 72 GB (88%) free of 82 GB
Total RAM: 1015 MB (60% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:40, on 23.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kacka\Plocha\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Kacka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://eeepc.asus.com/global
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Podpora odkazu pro Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
--
End of file - 6261 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Podpora odkazu pro Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-12 1372160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2009-04-23 937416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
TMMonitor.lnk - C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3.5"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}]
shell\AutoRun\command - F:\jedna/stvar.exe
shell\explore\command - F:\jedna/stvar.exe
shell\open\command - F:\jedna/stvar.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}]
shell\AutoRun\command - F:\ime/moje.exe
shell\explore\command - F:\ime/moje.exe
shell\open\command - F:\ime/moje.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}]
shell\AutoRun\command - F:\OPOP\severina.exe
shell\explore\command - F:\.////OPOP/\\\\severina.exe
shell\open\command - F:\OPOP/////\\\\severina.exe
======List of files/folders created in the last 1 months======
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SkyTel.exe
2013-08-25 23:27:58 ----A---- C:\WINDOWS\RtlUpd.exe
2013-08-25 23:27:57 ----A---- C:\WINDOWS\RTLCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\RTHDCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\MicCal.exe
2013-08-25 23:27:54 ----D---- C:\Program Files\Realtek
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCWZRD.EXE
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCMTR.EXE
2013-08-25 23:27:39 ----A---- C:\WINDOWS\RtlExUpd.dll
2013-08-17 21:22:50 ----A---- C:\WINDOWS\system32\DetectDevice.txt
2013-08-11 23:14:29 ----A---- C:\WINDOWS\system32\wmpns.dll
2013-08-11 23:12:48 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2012-09-18 09:11:00 ----A---- C:\WINDOWS\system32\btw_ci.dll
2012-09-18 09:10:54 ----D---- C:\Program Files\WIDCOMM
2011-09-11 16:59:53 ----D---- C:\Program Files\EeePC
2011-09-11 16:17:29 ----D---- C:\Program Files\Elantech
2010-03-23 14:17:32 ----D---- C:\rsit
2010-03-23 13:54:36 ----SD---- C:\Anubides
2010-03-23 03:21:15 ----SHD---- C:\RECYCLER
2010-03-23 03:16:05 ----D---- C:\Program Files\Avira
2010-03-23 03:16:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-03-23 02:58:35 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Mozilla
2010-03-23 02:55:04 ----D---- C:\WINDOWS\temp
2010-03-23 02:51:30 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Malwarebytes
2010-03-23 02:50:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-23 01:28:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-23 01:28:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-23 01:10:59 ----D---- C:\bb
2010-03-23 01:10:20 ----D---- C:\ndis
2010-03-23 00:26:27 ----A---- C:\Boot.bak
2010-03-23 00:26:21 ----RASHD---- C:\cmdcons
2010-03-22 21:52:32 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-03-22 21:52:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-22 21:47:39 ----A---- C:\WINDOWS\fn0oxom410fpdatx5xx447ni.ini
2010-03-22 21:20:57 ----D---- C:\Program Files\Mozilla Firefox
2010-03-22 21:19:17 ----D---- C:\Program Files\Trend Micro
2010-03-22 20:58:56 ----D---- C:\Program Files\CCleaner
2010-03-22 20:01:18 ----A---- C:\WINDOWS\system32\MRT.INI
2010-03-22 19:51:16 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-22 19:44:06 ----D---- C:\Program Files\a-squared Free
2010-03-21 01:15:53 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-11 03:01:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-02-25 11:08:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
======List of files/folders modified in the last 1 months======
2013-08-25 23:28:10 ----D---- C:\WINDOWS\system32\RTCOM
2013-08-25 23:27:39 ----A---- C:\WINDOWS\HideWin.exe
2013-08-13 03:29:47 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-09-18 10:32:30 ----D---- C:\WINDOWS\repair
2012-09-18 09:18:16 ----A---- C:\WINDOWS\oemver.txt
2011-09-11 16:59:53 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-23 14:17:40 ----D---- C:\WINDOWS\Prefetch
2010-03-23 14:14:39 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-23 14:14:34 ----D---- C:\WINDOWS
2010-03-23 14:14:02 ----D---- C:\WINDOWS\system32\Restore
2010-03-23 14:14:01 ----SHD---- C:\System Volume Information
2010-03-23 13:46:27 ----D---- C:\WINDOWS\system32
2010-03-23 13:46:27 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-23 03:16:14 ----D---- C:\WINDOWS\system32\drivers
2010-03-23 03:16:13 ----HD---- C:\WINDOWS\inf
2010-03-23 03:16:05 ----RD---- C:\Program Files
2010-03-23 03:15:02 ----SHD---- C:\WINDOWS\Installer
2010-03-23 03:15:01 ----D---- C:\WINDOWS\WinSxS
2010-03-23 03:15:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-23 02:51:09 ----A---- C:\WINDOWS\system.ini
2010-03-23 02:49:51 ----D---- C:\WINDOWS\system32\config
2010-03-23 02:47:47 ----D---- C:\WINDOWS\AppPatch
2010-03-23 02:47:46 ----D---- C:\Program Files\Common Files
2010-03-23 02:45:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-23 00:31:57 ----D---- C:\Program Files\Internet Explorer
2010-03-23 00:31:50 ----D---- C:\Program Files\Adobe
2010-03-23 00:26:27 ----RASH---- C:\boot.ini
2010-03-23 00:01:12 ----SD---- C:\WINDOWS\Tasks
2010-03-22 21:12:28 ----D---- C:\Program Files\KaM - The Peasants Rebellion
2010-03-22 21:01:31 ----D---- C:\WINDOWS\Debug
2010-03-22 18:38:21 ----D---- C:\Documents and Settings
2010-03-20 05:34:20 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Skype
2010-03-20 00:04:26 ----D---- C:\Documents and Settings\Kacka\Data aplikací\skypePM
2010-03-19 20:05:57 ----D---- C:\WINDOWS\system
2010-03-11 03:02:45 ----A---- C:\WINDOWS\win.ini
2010-03-11 03:01:04 ----D---- C:\Program Files\Movie Maker
2010-03-11 03:00:43 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-06 11:56:39 ----D---- C:\WINDOWS\Help
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-08-19 991656]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-08-19 47272]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-08-12 4751360]
R3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2008-08-25 26112]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-03-11 36864]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2006-11-10 18688]
S3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-03 546976]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-22 21568]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2008-03-28 625024]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 uxkx1;ASUS My Cinema U3100 Mini DVBT; C:\WINDOWS\system32\DRIVERS\uxkx1.sys [2008-02-15 459264]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe [2009-10-01 1858144]
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-02 346720]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Re: Total XP Security - Jak ho zničit!??



Můžete prosím připojit flešku a otestovat na www.virustotal.com
F:\ime/moje.exe
F:\OPOP\severina.exe
F:\jedna/stvar.exe
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
Daemon Tools Toolbar je pryč.
A nic z uvedených položek jsem na flashce ani v jednom PC nenašel...?
Gmer pokaždé zamrzne, nevím proč. A Ntb po delší nečinnosti zamrzá rovněž. Jen myš se hýbe naplno. Ale koukal jsem do Správce úloh a výkon CPU je na 100%, mi je divný teda...odvětrávání je na max, přehřátý není...Ten OS bude asi dobře v loji...
A nic z uvedených položek jsem na flashce ani v jednom PC nenašel...?
Gmer pokaždé zamrzne, nevím proč. A Ntb po delší nečinnosti zamrzá rovněž. Jen myš se hýbe naplno. Ale koukal jsem do Správce úloh a výkon CPU je na 100%, mi je divný teda...odvětrávání je na max, přehřátý není...Ten OS bude asi dobře v loji...
Re: Total XP Security - Jak ho zničit!??
Zkuste, jestli bude Gmer zamrzat i v nouzovém režimu
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
Jen bych rád řekl, že mi Avira hlásila předtím Trojany na flashce a ted nic, tak to vypadá dobře.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kacka at 2010-03-23 22:00:56
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 71 GB (86%) free of 82 GB
Total RAM: 1015 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:01:05, on 23.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Kacka\Plocha\Testovací programy\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Kacka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://eeepc.asus.com/global
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7363 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3086602011-2446779318-483012309-1006.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3086602011-2446779318-483012309-1006.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-12 1372160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-03-23 341600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-23 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-23 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-11-22 1037192]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-03-23 202256]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-02-15 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
TMMonitor.lnk - C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3.5"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}]
shell\AutoRun\command - F:\jedna/stvar.exe
shell\explore\command - F:\jedna/stvar.exe
shell\open\command - F:\jedna/stvar.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}]
shell\AutoRun\command - F:\ime/moje.exe
shell\explore\command - F:\ime/moje.exe
shell\open\command - F:\ime/moje.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}]
shell\AutoRun\command - F:\OPOP\severina.exe
shell\explore\command - F:\.////OPOP/\\\\severina.exe
shell\open\command - F:\OPOP/////\\\\severina.exe
======List of files/folders created in the last 1 months======
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SkyTel.exe
2013-08-25 23:27:58 ----A---- C:\WINDOWS\RtlUpd.exe
2013-08-25 23:27:57 ----A---- C:\WINDOWS\RTLCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\RTHDCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\MicCal.exe
2013-08-25 23:27:54 ----D---- C:\Program Files\Realtek
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCWZRD.EXE
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCMTR.EXE
2013-08-25 23:27:39 ----A---- C:\WINDOWS\RtlExUpd.dll
2013-08-17 21:22:50 ----A---- C:\WINDOWS\system32\DetectDevice.txt
2013-08-11 23:14:29 ----A---- C:\WINDOWS\system32\wmpns.dll
2013-08-11 23:12:48 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2012-09-18 09:11:00 ----A---- C:\WINDOWS\system32\btw_ci.dll
2012-09-18 09:10:54 ----D---- C:\Program Files\WIDCOMM
2011-09-11 16:59:53 ----D---- C:\Program Files\EeePC
2011-09-11 16:17:29 ----D---- C:\Program Files\Elantech
2010-03-23 21:12:27 ----D---- C:\Program Files\IrfanView
2010-03-23 21:10:10 ----D---- C:\Program Files\QuickTime
2010-03-23 21:10:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-03-23 21:09:31 ----D---- C:\Program Files\Common Files\Apple
2010-03-23 21:09:04 ----D---- C:\Program Files\Apple Software Update
2010-03-23 21:09:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2010-03-23 21:03:34 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-03-23 21:03:22 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-03-23 21:03:22 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-03-23 21:03:07 ----D---- C:\Program Files\Common Files\xing shared
2010-03-23 21:01:49 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-03-23 21:01:45 ----D---- C:\Program Files\Common Files\Real
2010-03-23 21:01:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-03-23 21:01:43 ----D---- C:\Program Files\Real
2010-03-23 21:00:59 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Real
2010-03-23 20:58:23 ----D---- C:\WINDOWS\system32\Adobe
2010-03-23 20:51:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-03-23 20:51:26 ----A---- C:\WINDOWS\system32\javaws.exe
2010-03-23 20:51:26 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-03-23 20:51:25 ----A---- C:\WINDOWS\system32\javaw.exe
2010-03-23 20:51:25 ----A---- C:\WINDOWS\system32\java.exe
2010-03-23 20:47:55 ----D---- C:\Program Files\Common Files\Adobe
2010-03-23 20:45:45 ----SHD---- C:\Config.Msi
2010-03-23 20:43:32 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-03-23 20:42:32 ----D---- C:\Program Files\NOS
2010-03-23 20:42:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\NOS
2010-03-23 16:33:38 ----D---- C:\Program Files\Defraggler
2010-03-23 16:07:55 ----A---- C:\WINDOWS\system32\vsregexp.dll
2010-03-23 16:07:51 ----A---- C:\WINDOWS\system32\zlcommdb.dll
2010-03-23 16:07:51 ----A---- C:\WINDOWS\system32\zlcomm.dll
2010-03-23 16:07:44 ----A---- C:\WINDOWS\system32\vswmi.dll
2010-03-23 16:07:42 ----A---- C:\WINDOWS\system32\zpeng25.dll
2010-03-23 16:07:41 ----D---- C:\WINDOWS\system32\ZoneLabs
2010-03-23 16:07:41 ----A---- C:\WINDOWS\system32\vsxml.dll
2010-03-23 16:07:41 ----A---- C:\WINDOWS\system32\vspubapi.dll
2010-03-23 16:07:41 ----A---- C:\WINDOWS\system32\vsmonapi.dll
2010-03-23 16:07:37 ----D---- C:\Program Files\Zone Labs
2010-03-23 16:06:49 ----D---- C:\WINDOWS\Internet Logs
2010-03-23 16:06:48 ----A---- C:\WINDOWS\system32\vsutil.dll
2010-03-23 16:06:48 ----A---- C:\WINDOWS\system32\vsinit.dll
2010-03-23 16:06:48 ----A---- C:\WINDOWS\system32\vsdata.dll
2010-03-23 15:51:26 ----D---- C:\WINDOWS\ie8updates
2010-03-23 15:50:26 ----D---- C:\WINDOWS\WBEM
2010-03-23 15:48:55 ----HDC---- C:\WINDOWS\ie8
2010-03-23 14:17:32 ----D---- C:\rsit
2010-03-23 13:54:36 ----SD---- C:\Anubides
2010-03-23 03:21:15 ----SHD---- C:\RECYCLER
2010-03-23 03:16:05 ----D---- C:\Program Files\Avira
2010-03-23 03:16:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-03-23 02:58:35 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Mozilla
2010-03-23 02:55:04 ----D---- C:\WINDOWS\temp
2010-03-23 02:51:30 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Malwarebytes
2010-03-23 02:50:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-23 01:28:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-23 01:28:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-23 01:10:59 ----D---- C:\bb
2010-03-23 01:10:20 ----D---- C:\ndis
2010-03-23 00:26:27 ----A---- C:\Boot.bak
2010-03-23 00:26:21 ----RASHD---- C:\cmdcons
2010-03-22 21:52:32 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-03-22 21:52:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-22 21:47:39 ----A---- C:\WINDOWS\fn0oxom410fpdatx5xx447ni.ini
2010-03-22 21:20:57 ----D---- C:\Program Files\Mozilla Firefox
2010-03-22 21:19:17 ----D---- C:\Program Files\Trend Micro
2010-03-22 20:58:56 ----D---- C:\Program Files\CCleaner
2010-03-22 20:01:18 ----A---- C:\WINDOWS\system32\MRT.INI
2010-03-22 19:51:16 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-22 19:44:06 ----D---- C:\Program Files\a-squared Free
2010-03-21 01:15:53 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-11 03:01:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-02-25 11:08:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
======List of files/folders modified in the last 1 months======
2013-08-25 23:28:10 ----D---- C:\WINDOWS\system32\RTCOM
2013-08-25 23:27:39 ----A---- C:\WINDOWS\HideWin.exe
2013-08-13 03:29:47 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-09-18 10:32:30 ----D---- C:\WINDOWS\repair
2012-09-18 09:18:16 ----A---- C:\WINDOWS\oemver.txt
2011-09-11 16:59:53 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-23 22:01:03 ----D---- C:\WINDOWS\Prefetch
2010-03-23 21:57:24 ----D---- C:\WINDOWS
2010-03-23 21:32:07 ----SD---- C:\WINDOWS\Tasks
2010-03-23 21:12:27 ----RD---- C:\Program Files
2010-03-23 21:11:04 ----SHD---- C:\WINDOWS\Installer
2010-03-23 21:10:10 ----D---- C:\WINDOWS\system32
2010-03-23 21:09:37 ----D---- C:\WINDOWS\WinSxS
2010-03-23 21:09:31 ----D---- C:\Program Files\Common Files
2010-03-23 21:01:49 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-03-23 21:01:49 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-03-23 20:59:23 ----D---- C:\Program Files\Internet Explorer
2010-03-23 20:51:50 ----D---- C:\Program Files\Common Files\Java
2010-03-23 20:50:53 ----D---- C:\Program Files\Java
2010-03-23 20:48:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-03-23 20:47:55 ----D---- C:\Program Files\Adobe
2010-03-23 20:34:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-23 20:29:32 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-23 16:04:14 ----D---- C:\WINDOWS\Debug
2010-03-23 16:04:05 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-03-23 15:53:24 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-23 15:53:23 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-23 15:53:23 ----D---- C:\WINDOWS\Help
2010-03-23 15:52:13 ----HD---- C:\WINDOWS\inf
2010-03-23 15:51:51 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-23 15:50:33 ----D---- C:\WINDOWS\system32\config
2010-03-23 15:50:17 ----D---- C:\WINDOWS\Media
2010-03-23 14:14:02 ----D---- C:\WINDOWS\system32\Restore
2010-03-23 14:14:01 ----SHD---- C:\System Volume Information
2010-03-23 03:16:14 ----D---- C:\WINDOWS\system32\drivers
2010-03-23 03:15:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-23 02:51:09 ----A---- C:\WINDOWS\system.ini
2010-03-23 02:47:47 ----D---- C:\WINDOWS\AppPatch
2010-03-23 00:26:27 ----RASH---- C:\boot.ini
2010-03-22 21:12:28 ----D---- C:\Program Files\KaM - The Peasants Rebellion
2010-03-22 18:38:21 ----D---- C:\Documents and Settings
2010-03-20 05:34:20 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Skype
2010-03-20 00:04:26 ----D---- C:\Documents and Settings\Kacka\Data aplikací\skypePM
2010-03-19 20:05:57 ----D---- C:\WINDOWS\system
2010-03-11 03:02:45 ----A---- C:\WINDOWS\win.ini
2010-03-11 03:01:04 ----D---- C:\Program Files\Movie Maker
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-11-22 486280]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-08-19 991656]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-08-19 47272]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-08-12 4751360]
R3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2008-08-25 26112]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-03-11 36864]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2006-11-10 18688]
S3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-03 546976]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-22 21568]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2008-03-28 625024]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 uxkx1;ASUS My Cinema U3100 Mini DVBT; C:\WINDOWS\system32\DRIVERS\uxkx1.sys [2008-02-15 459264]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe [2009-10-01 1858144]
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-02 346720]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-23 153376]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-11-22 2384240]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 getPlusHelper;getPlus(R) Helper; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Logfile of random's system information tool 1.06 (written by random/random)
Run by Kacka at 2010-03-23 22:00:56
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 71 GB (86%) free of 82 GB
Total RAM: 1015 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:01:05, on 23.3.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Kacka\Plocha\Testovací programy\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Kacka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://eeepc.asus.com/global
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O4 - Global Startup: TMMonitor.lnk = C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat do zařízení Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 7363 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3086602011-2446779318-483012309-1006.job
C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-3086602011-2446779318-483012309-1006.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22BF413B-C6D2-4d91-82A9-A0F997BA588C}]
Skype add-on (mastermind) - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2008-02-12 1372160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Documents and Settings\All Users\Data aplikací\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2010-03-23 341600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-23 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-03-23 79648]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-11-22 1037192]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2010-03-23 202256]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-02-15 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
SuperHybridEngine.lnk - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
TMMonitor.lnk - C:\Program Files\ArcSoft\TotalMedia 3.5\TMMonitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-12-19 208896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe"="C:\Program Files\ArcSoft\TotalMedia 3.5\TotalMedia.exe:LocalSubNet:Enabled:ArcSoft TotalMedia 3.5"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aec5ceea-eb1f-11de-a6f7-00248c43b690}]
shell\AutoRun\command - F:\jedna/stvar.exe
shell\explore\command - F:\jedna/stvar.exe
shell\open\command - F:\jedna/stvar.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eb93b4-e567-11de-a6f2-00248c43b690}]
shell\AutoRun\command - F:\ime/moje.exe
shell\explore\command - F:\ime/moje.exe
shell\open\command - F:\ime/moje.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3ab9954-b8dc-11de-a6b0-00248c43b690}]
shell\AutoRun\command - F:\OPOP\severina.exe
shell\explore\command - F:\.////OPOP/\\\\severina.exe
shell\open\command - F:\OPOP/////\\\\severina.exe
======List of files/folders created in the last 1 months======
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2013-08-25 23:27:58 ----A---- C:\WINDOWS\SkyTel.exe
2013-08-25 23:27:58 ----A---- C:\WINDOWS\RtlUpd.exe
2013-08-25 23:27:57 ----A---- C:\WINDOWS\RTLCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\RTHDCPL.EXE
2013-08-25 23:27:55 ----A---- C:\WINDOWS\MicCal.exe
2013-08-25 23:27:54 ----D---- C:\Program Files\Realtek
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCWZRD.EXE
2013-08-25 23:27:54 ----A---- C:\WINDOWS\ALCMTR.EXE
2013-08-25 23:27:39 ----A---- C:\WINDOWS\RtlExUpd.dll
2013-08-17 21:22:50 ----A---- C:\WINDOWS\system32\DetectDevice.txt
2013-08-11 23:14:29 ----A---- C:\WINDOWS\system32\wmpns.dll
2013-08-11 23:12:48 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2012-09-18 09:11:00 ----A---- C:\WINDOWS\system32\btw_ci.dll
2012-09-18 09:10:54 ----D---- C:\Program Files\WIDCOMM
2011-09-11 16:59:53 ----D---- C:\Program Files\EeePC
2011-09-11 16:17:29 ----D---- C:\Program Files\Elantech
2010-03-23 21:12:27 ----D---- C:\Program Files\IrfanView
2010-03-23 21:10:10 ----D---- C:\Program Files\QuickTime
2010-03-23 21:10:08 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-03-23 21:09:31 ----D---- C:\Program Files\Common Files\Apple
2010-03-23 21:09:04 ----D---- C:\Program Files\Apple Software Update
2010-03-23 21:09:04 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple
2010-03-23 21:03:34 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-03-23 21:03:22 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-03-23 21:03:22 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-03-23 21:03:07 ----D---- C:\Program Files\Common Files\xing shared
2010-03-23 21:01:49 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-03-23 21:01:45 ----D---- C:\Program Files\Common Files\Real
2010-03-23 21:01:44 ----D---- C:\Documents and Settings\All Users\Data aplikací\Real
2010-03-23 21:01:43 ----D---- C:\Program Files\Real
2010-03-23 21:00:59 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Real
2010-03-23 20:58:23 ----D---- C:\WINDOWS\system32\Adobe
2010-03-23 20:51:54 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-03-23 20:51:26 ----A---- C:\WINDOWS\system32\javaws.exe
2010-03-23 20:51:26 ----A---- C:\WINDOWS\system32\deploytk.dll
2010-03-23 20:51:25 ----A---- C:\WINDOWS\system32\javaw.exe
2010-03-23 20:51:25 ----A---- C:\WINDOWS\system32\java.exe
2010-03-23 20:47:55 ----D---- C:\Program Files\Common Files\Adobe
2010-03-23 20:45:45 ----SHD---- C:\Config.Msi
2010-03-23 20:43:32 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-03-23 20:42:32 ----D---- C:\Program Files\NOS
2010-03-23 20:42:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\NOS
2010-03-23 16:33:38 ----D---- C:\Program Files\Defraggler
2010-03-23 16:07:55 ----A---- C:\WINDOWS\system32\vsregexp.dll
2010-03-23 16:07:51 ----A---- C:\WINDOWS\system32\zlcommdb.dll
2010-03-23 16:07:51 ----A---- C:\WINDOWS\system32\zlcomm.dll
2010-03-23 16:07:44 ----A---- C:\WINDOWS\system32\vswmi.dll
2010-03-23 16:07:42 ----A---- C:\WINDOWS\system32\zpeng25.dll
2010-03-23 16:07:41 ----D---- C:\WINDOWS\system32\ZoneLabs
2010-03-23 16:07:41 ----A---- C:\WINDOWS\system32\vsxml.dll
2010-03-23 16:07:41 ----A---- C:\WINDOWS\system32\vspubapi.dll
2010-03-23 16:07:41 ----A---- C:\WINDOWS\system32\vsmonapi.dll
2010-03-23 16:07:37 ----D---- C:\Program Files\Zone Labs
2010-03-23 16:06:49 ----D---- C:\WINDOWS\Internet Logs
2010-03-23 16:06:48 ----A---- C:\WINDOWS\system32\vsutil.dll
2010-03-23 16:06:48 ----A---- C:\WINDOWS\system32\vsinit.dll
2010-03-23 16:06:48 ----A---- C:\WINDOWS\system32\vsdata.dll
2010-03-23 15:51:26 ----D---- C:\WINDOWS\ie8updates
2010-03-23 15:50:26 ----D---- C:\WINDOWS\WBEM
2010-03-23 15:48:55 ----HDC---- C:\WINDOWS\ie8
2010-03-23 14:17:32 ----D---- C:\rsit
2010-03-23 13:54:36 ----SD---- C:\Anubides
2010-03-23 03:21:15 ----SHD---- C:\RECYCLER
2010-03-23 03:16:05 ----D---- C:\Program Files\Avira
2010-03-23 03:16:05 ----D---- C:\Documents and Settings\All Users\Data aplikací\Avira
2010-03-23 02:58:35 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Mozilla
2010-03-23 02:55:04 ----D---- C:\WINDOWS\temp
2010-03-23 02:51:30 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Malwarebytes
2010-03-23 02:50:44 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-03-23 01:28:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-23 01:28:17 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-03-23 01:10:59 ----D---- C:\bb
2010-03-23 01:10:20 ----D---- C:\ndis
2010-03-23 00:26:27 ----A---- C:\Boot.bak
2010-03-23 00:26:21 ----RASHD---- C:\cmdcons
2010-03-22 21:52:32 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-03-22 21:52:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-03-22 21:47:39 ----A---- C:\WINDOWS\fn0oxom410fpdatx5xx447ni.ini
2010-03-22 21:20:57 ----D---- C:\Program Files\Mozilla Firefox
2010-03-22 21:19:17 ----D---- C:\Program Files\Trend Micro
2010-03-22 20:58:56 ----D---- C:\Program Files\CCleaner
2010-03-22 20:01:18 ----A---- C:\WINDOWS\system32\MRT.INI
2010-03-22 19:51:16 ----A---- C:\WINDOWS\system32\MRT.exe
2010-03-22 19:44:06 ----D---- C:\Program Files\a-squared Free
2010-03-21 01:15:53 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-03-11 03:01:03 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-02-25 11:08:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
======List of files/folders modified in the last 1 months======
2013-08-25 23:28:10 ----D---- C:\WINDOWS\system32\RTCOM
2013-08-25 23:27:39 ----A---- C:\WINDOWS\HideWin.exe
2013-08-13 03:29:47 ----D---- C:\WINDOWS\system32\ReinstallBackups
2012-09-18 10:32:30 ----D---- C:\WINDOWS\repair
2012-09-18 09:18:16 ----A---- C:\WINDOWS\oemver.txt
2011-09-11 16:59:53 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-03-23 22:01:03 ----D---- C:\WINDOWS\Prefetch
2010-03-23 21:57:24 ----D---- C:\WINDOWS
2010-03-23 21:32:07 ----SD---- C:\WINDOWS\Tasks
2010-03-23 21:12:27 ----RD---- C:\Program Files
2010-03-23 21:11:04 ----SHD---- C:\WINDOWS\Installer
2010-03-23 21:10:10 ----D---- C:\WINDOWS\system32
2010-03-23 21:09:37 ----D---- C:\WINDOWS\WinSxS
2010-03-23 21:09:31 ----D---- C:\Program Files\Common Files
2010-03-23 21:01:49 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-03-23 21:01:49 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-03-23 20:59:23 ----D---- C:\Program Files\Internet Explorer
2010-03-23 20:51:50 ----D---- C:\Program Files\Common Files\Java
2010-03-23 20:50:53 ----D---- C:\Program Files\Java
2010-03-23 20:48:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-03-23 20:47:55 ----D---- C:\Program Files\Adobe
2010-03-23 20:34:23 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-03-23 20:29:32 ----D---- C:\WINDOWS\system32\CatRoot2
2010-03-23 16:04:14 ----D---- C:\WINDOWS\Debug
2010-03-23 16:04:05 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-03-23 15:53:24 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-23 15:53:23 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-03-23 15:53:23 ----D---- C:\WINDOWS\Help
2010-03-23 15:52:13 ----HD---- C:\WINDOWS\inf
2010-03-23 15:51:51 ----HD---- C:\WINDOWS\$hf_mig$
2010-03-23 15:50:33 ----D---- C:\WINDOWS\system32\config
2010-03-23 15:50:17 ----D---- C:\WINDOWS\Media
2010-03-23 14:14:02 ----D---- C:\WINDOWS\system32\Restore
2010-03-23 14:14:01 ----SHD---- C:\System Volume Information
2010-03-23 03:16:14 ----D---- C:\WINDOWS\system32\drivers
2010-03-23 03:15:00 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-03-23 02:51:09 ----A---- C:\WINDOWS\system.ini
2010-03-23 02:47:47 ----D---- C:\WINDOWS\AppPatch
2010-03-23 00:26:27 ----RASH---- C:\boot.ini
2010-03-22 21:12:28 ----D---- C:\Program Files\KaM - The Peasants Rebellion
2010-03-22 18:38:21 ----D---- C:\Documents and Settings
2010-03-20 05:34:20 ----D---- C:\Documents and Settings\Kacka\Data aplikací\Skype
2010-03-20 00:04:26 ----D---- C:\Documents and Settings\Kacka\Data aplikací\skypePM
2010-03-19 20:05:57 ----D---- C:\WINDOWS\system
2010-03-11 03:02:45 ----A---- C:\WINDOWS\win.ini
2010-03-11 03:01:04 ----D---- C:\Program Files\Movie Maker
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2009-11-22 486280]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-11-25 56816]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-04-14 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-04-14 55936]
R3 AsusACPI;ASUS ACPI Driver; C:\WINDOWS\system32\DRIVERS\ASUSACPI.sys [2008-04-08 10752]
R3 BTDriver;Ovladač virtuálních komunikací Bluetooth; C:\WINDOWS\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumenátor sběrnice Bluetooth; C:\WINDOWS\system32\DRIVERS\btkrnl.sys [2008-08-19 991656]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2008-08-19 47272]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-12-19 5854688]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-08-12 4751360]
R3 Ktp;Elantech Smart-Pad; C:\WINDOWS\system32\DRIVERS\ETD.sys [2008-08-25 26112]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-03-11 36864]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2006-11-10 18688]
S3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-05-03 546976]
S3 btaudio;Zvukové zařízení Bluetooth; C:\WINDOWS\system32\drivers\btaudio.sys [2008-05-30 534568]
S3 BTWDNDIS;Server pro přístup k síti LAN Bluetooth; C:\WINDOWS\system32\DRIVERS\btwdndis.sys [2008-07-24 156816]
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-10-22 21568]
S3 MPE;Filtr MPE BDA; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-13 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 RT80x86;Ralink 802.11n Wireless Driver; C:\WINDOWS\system32\DRIVERS\RT2860.sys [2008-03-28 625024]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 uxkx1;ASUS My Cinema U3100 Mini DVBT; C:\WINDOWS\system32\DRIVERS\uxkx1.sys [2008-02-15 459264]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 a2free;a-squared Free Service; C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe [2009-10-01 1858144]
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2009-09-28 109056]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-09-02 346720]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-03-23 153376]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2009-11-22 2384240]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 getPlusHelper;getPlus(R) Helper; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
Re: Total XP Security - Jak ho zničit!??
Flešku ještě doladíme, ale ještě bych poprosila o tohle:
stáhněte MBR
http://www2.gmer.net/mbr/mbr.exe
-uložte ho na plochu a spusťte
-vytvoří se log s názvem mbr.log, vložte ho zde
Stáhněte
http://rootrepeal.googlepages.com/RootRepeal.zip
-Stáhněte,rozbalte a spusťte
-vyberte záložku drivers, pak Files, klikněte na Scan,
-proběhne sken, po něm klikněte na Save Report , tím se uloží log, který zkopírujete sem

http://www2.gmer.net/mbr/mbr.exe
-uložte ho na plochu a spusťte
-vytvoří se log s názvem mbr.log, vložte ho zde

http://rootrepeal.googlepages.com/RootRepeal.zip
-Stáhněte,rozbalte a spusťte
-vyberte záložku drivers, pak Files, klikněte na Scan,
-proběhne sken, po něm klikněte na Save Report , tím se uloží log, který zkopírujete sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
- Anubides
- Vzorný návštěvník
- Příspěvky: 142
- Registrován: 22 bře 2010 22:13
- Bydliště: Praha
- Kontaktovat uživatele:
Re: Total XP Security - Jak ho zničit!??
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
RootRepeal také zamrzl...Pochybuju že by to bylo frekvencí CPU 1,6Ghz a 1GB Ramkou
V tom bude něco jinyho...
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
RootRepeal také zamrzl...Pochybuju že by to bylo frekvencí CPU 1,6Ghz a 1GB Ramkou

Re: Total XP Security - Jak ho zničit!??
Zkuste ho v nouzovém režimu.
že by virem?
Občas některé notásky s tím mají problém, nevím proč 
že by virem?


Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.