Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

killvbs.vbs

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#16 Příspěvek od kisuah »

PC1

chova se stabilne,killvbs uz jsem nenasel,takze moc dekuji :)

PC2

USBFIX
Update on 12/04/2010 by El Desaparecido , C_XX & Chimay8
Start at: 14:35:52 | 14.4.2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Celeron(R) CPU 2.40GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled

A:\ -> Disketová jednotka 3 1/2"
C:\ -> Místní pevný disk # 74,52 Go (60,06 Go free) [Místní disk] # NTFS
D:\ -> Disk CD-ROM
E:\ -> Vyměnitelný disk # 218,36 Mo (215,49 Mo free) # FAT32
S:\ -> Síťové připojení # 136,65 Go (121,17 Go free) # NTFS

################## | Files # Infected Folders |

Deleted ! C:\Recycler\S-1-5-21-2000478354-179605362-725345543-1003
Deleted ! C:\Recycler\S-1-5-21-3513792838-1905634403-1455478086-1114
Deleted ! E:\autorun.inf
Deleted ! E:\killVBS.vbs

################## | Registry |


################## | Mountpoints2 |


################## | Listing of the present files |

[27.02.2007 11:44|--a------|95] C:\AUTOEXEC.BAT
[13.04.2010 12:22|-rahs----|211] C:\boot.ini
[16.04.2003 14:00|-rahs----|4952] C:\Bootfont.bin
[07.09.2005 12:00|--a------|488729] C:\Ceska Logisticka 20050905.rar
[26.02.2003 13:37|--a------|0] C:\CONFIG.SYS
[26.02.2003 13:37|-rahs----|0] C:\IO.SYS
[26.02.2003 13:37|-rahs----|0] C:\MSDOS.SYS
[26.10.2004 10:43|-rahs----|47564] C:\NTDETECT.COM
[26.10.2004 10:43|-rahs----|250048] C:\ntldr
[?|?|?] C:\pagefile.sys
[19.10.2005 19:19|--a------|2124288] C:\Projekt MROZEK.ppt
[26.02.2003 13:50|--a------|90] C:\setup.log
[14.04.2010 14:42|--a------|1694] C:\UsbFix.txt

################## | Vaccination |

# C:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).
# E:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).
# S:\autorun.inf -> Autorun.inf created by UsbFix (El Desaparecido).

################## | Upload |

Please send the file : C:\UsbFix_Upload_Me_ENET.zip : http://chiquitine.changelog.fr/Sample/Upload.php
Thank you for your contribution .

################## | ! End of report # UsbFix V6.103 ! |


OTL

OTL logfile created on: 14.4.2010 14:50:20 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\MCI\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

239,00 Mb Total Physical Memory | 32,00 Mb Available Physical Memory | 13,00% Memory free
586,00 Mb Paging File | 410,00 Mb Available in Paging File | 70,00% Paging File free
Paging file location(s): C:\pagefile.sys 360 720 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 60,07 Gb Free Space | 80,60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 218,36 Mb Total Space | 215,50 Mb Free Space | 98,69% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 136,65 Gb Total Space | 121,17 Gb Free Space | 88,67% Space Free | Partition Type: NTFS

Computer Name: MILADA-CINKANIC
Current User Name: MCI
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010.04.14 14:49:28 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MCI\Plocha\OTL.exe
PRC - [2008.10.27 17:40:02 | 000,307,712 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2007.06.13 15:23:39 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002.09.20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


========== Modules (SafeList) ==========

MOD - [2010.04.14 14:49:28 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MCI\Plocha\OTL.exe
MOD - [2006.08.25 17:51:20 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2002.09.20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))


========== Driver Services (SafeList) ==========

DRV - [2010.02.17 10:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010.02.17 10:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.02.17 10:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2007.08.01 22:30:40 | 000,016,376 | ---- | M] (Gemfor s.r.o.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ethpdrv.sys -- (Ethpdrv)
DRV - [2005.06.02 20:28:38 | 000,171,008 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2005.02.09 13:59:00 | 000,014,165 | ---- | M] (Pinnacle Systems GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Pclepci.sys -- (PCLEPCI)
DRV - [2003.06.18 00:38:56 | 000,035,012 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SMBios.sys -- (SMBios) Intel (R)
DRV - [2003.05.09 06:00:56 | 000,033,248 | ---- | M] (Sonic Focus, Inc) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\sf.sys -- (sf)
DRV - [2002.09.20 19:53:34 | 000,235,100 | ---- | M] (Analog Devices Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.2enet.cz/"

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2008.10.27 17:40:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2008.10.27 17:40:10 | 000,000,000 | ---D | M]

[2008.09.02 15:21:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MCI\Data aplikací\Mozilla\Extensions
[2008.09.02 15:21:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MCI\Data aplikací\Mozilla\Firefox\Profiles\ldjv4u40.default\extensions
[2008.09.02 15:21:31 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008.03.31 21:06:24 | 000,000,638 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\jyxo-cz.xml
[2008.03.31 21:06:24 | 000,001,687 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\mall-cz.xml
[2008.01.27 11:57:20 | 000,001,367 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\seznam-cz.xml
[2008.01.27 11:57:20 | 000,000,654 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\slunecnice-cz.xml
[2008.03.31 21:06:24 | 000,001,179 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-cz.xml

O1 HOSTS File: ([2003.04.16 14:00:00 | 000,000,737 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [pdfSaver3] File not found
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\NPJPI150_09.dll (Sun Microsystems, Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in Tento počítač)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} http://ak.imgfarm.com/images/nocache/fu ... .0.0.8.cab (Reg Error: Key error.)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/Mi ... b31267.cab (Minesweeper Flags Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Me ... b31267.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} http://java.sun.com/products/plugin/aut ... s-i586.cab (Java Plug-in 1.4.2_06)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinsta ... s-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shoc ... wflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = enet.loc
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\MCI\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\MCI\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007.02.27 11:44:00 | 000,000,095 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 14:42:09 | 000,000,000 | RHSD | M] - C:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010.04.14 14:42:10 | 000,000,000 | RHSD | M] - E:\autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2010.04.14 14:22:25 | 000,000,000 | RHSD | M] - S:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010.04.14 14:49:27 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MCI\Plocha\OTL.exe
[2010.04.14 14:42:09 | 000,000,000 | RHSD | C] -- C:\autorun.inf
[2010.04.14 14:23:03 | 000,000,000 | ---D | C] -- C:\UsbFix
[2010.04.14 13:56:45 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.04.14 13:55:46 | 000,000,000 | ---D | C] -- C:\rsit
[2010.04.13 11:17:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
[2010.04.13 11:17:24 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010.04.13 11:17:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\MCI\Data aplikací\SUPERAntiSpyware.com
[2010.04.13 11:16:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010.04.13 10:49:04 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\MCI\Recent
[2010.04.13 10:47:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2010.04.13 10:42:13 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010.04.13 10:31:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Microsoft
[2010.04.13 10:21:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Microsoft
[2010.04.13 10:21:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Data aplikací\Microsoft
[2010.04.13 10:21:27 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Data aplikací\Microsoft
[2010.04.12 12:46:01 | 000,000,000 | -H-D | C] -- C:\$AVG
[2010.04.12 12:08:02 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010.01.12 15:27:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Temp
[2010.01.11 08:47:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2010.01.11 08:43:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2006.01.04 09:33:15 | 011,817,800 | ---- | C] (InstallShield Software Corporation) -- C:\Program Files\GoogleEarthSetup.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010.04.14 14:49:28 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MCI\Plocha\OTL.exe
[2010.04.14 14:43:27 | 000,893,178 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010.04.14 14:43:27 | 000,383,390 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.04.14 14:43:27 | 000,382,822 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.04.14 14:43:27 | 000,063,328 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.04.14 14:43:27 | 000,053,744 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.04.14 14:42:33 | 000,003,332 | ---- | M] () -- C:\UsbFix_Upload_Me_ENET.zip
[2010.04.14 14:35:47 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.04.14 14:29:36 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010.04.14 14:29:34 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.04.14 14:28:36 | 005,767,168 | -H-- | M] () -- C:\Documents and Settings\MCI\NTUSER.DAT
[2010.04.14 14:28:36 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\MCI\ntuser.ini
[2010.04.14 14:22:47 | 001,777,501 | ---- | M] () -- C:\Documents and Settings\MCI\Plocha\UsbFix.exe
[2010.04.13 12:22:44 | 000,000,583 | ---- | M] () -- C:\WINDOWS\win.ini
[2010.04.13 12:22:44 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010.04.13 12:22:44 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2010.04.13 10:42:16 | 000,001,559 | ---- | M] () -- C:\Documents and Settings\MCI\Plocha\CCleaner.lnk
[2010.04.12 16:21:28 | 000,007,486 | RHS- | M] () -- C:\WINDOWS\System32\killVBS.vbs
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010.04.14 14:42:33 | 000,003,332 | ---- | C] () -- C:\UsbFix_Upload_Me_ENET.zip
[2010.04.14 14:22:46 | 001,777,501 | ---- | C] () -- C:\Documents and Settings\MCI\Plocha\UsbFix.exe
[2010.04.13 10:42:16 | 000,001,559 | ---- | C] () -- C:\Documents and Settings\MCI\Plocha\CCleaner.lnk
[2007.07.27 11:31:38 | 000,002,810 | ---- | C] () -- C:\WINDOWS\wincmd.ini
[2007.02.27 11:44:00 | 000,000,022 | ---- | C] () -- C:\WINDOWS\VFO.INI
[2006.01.17 14:30:34 | 000,000,123 | ---- | C] () -- C:\Documents and Settings\MCI\Local Settings\Data aplikací\fusioncache.dat
[2006.01.17 14:04:02 | 112,103,520 | ---- | C] () -- C:\Program Files\SetupDWGTrueView2.exe
[2005.11.08 09:10:15 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\ntuser.dat
[2005.11.08 09:10:15 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\ntuser.dat.LOG
[2005.07.08 19:05:36 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\MCI\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.01.11 09:01:41 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2004.12.20 19:24:03 | 001,663,068 | ---- | C] () -- C:\WINDOWS\System32\libmmd.dll
[2004.11.19 17:37:24 | 000,038,473 | ---- | C] () -- C:\Documents and Settings\MCI\Data aplikací\Hodnoty oddělené čárkami (Windows).ADR
[2004.10.06 18:43:02 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\MCI\PUTTY.RND
[2004.06.03 14:29:14 | 000,002,412 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2004.06.03 14:01:09 | 000,178,277 | ---- | C] () -- C:\Documents and Settings\MCI\~
[2003.04.09 16:38:04 | 000,005,664 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2003.03.26 11:50:53 | 000,001,017 | ---- | C] () -- C:\Documents and Settings\MCI\intlname.ols
[2003.02.26 14:15:57 | 000,000,390 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003.02.26 13:48:08 | 000,126,976 | R--- | C] () -- C:\WINDOWS\System32\e1000msg.dll
[2003.02.26 13:43:19 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\MCI\ntuser.dat.LOG
[2003.02.26 13:43:19 | 000,000,272 | -HS- | C] () -- C:\Documents and Settings\MCI\ntuser.ini
[2003.02.26 13:43:18 | 005,767,168 | -H-- | C] () -- C:\Documents and Settings\MCI\NTUSER.DAT
[2002.05.03 18:40:32 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
< End of report >



OTL Extras logfile created on: 14.4.2010 14:50:20 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\MCI\Plocha
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

239,00 Mb Total Physical Memory | 32,00 Mb Available Physical Memory | 13,00% Memory free
586,00 Mb Paging File | 410,00 Mb Available in Paging File | 70,00% Paging File free
Paging file location(s): C:\pagefile.sys 360 720 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74,52 Gb Total Space | 60,07 Gb Free Space | 80,60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 218,36 Mb Total Space | 215,50 Mb Free Space | 98,69% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive S: | 136,65 Gb Total Space | 121,17 Gb Free Space | 88,67% Space Free | Partition Type: NTFS

Computer Name: MILADA-CINKANIC
Current User Name: MCI
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe" = C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager -- File not found
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe" = C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio -- File not found
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe" = C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile -- File not found
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe" = C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\MCI\Plocha\winbox.exe" = C:\Documents and Settings\MCI\Plocha\winbox.exe:*:Enabled:winbox -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{2CD6BBA0-17C8-4789-9B9B-B36F7E815F6A}" = DWG TrueView
"{3248F0A8-6813-11D6-A77B-00B0D0150050}" = J2SE Runtime Environment 5.0 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{7148F0A8-6813-11D6-A77B-00B0D0142060}" = Java 2 Runtime Environment, SE v1.4.2_06
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics Driver
"{91CA0405-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Small Business Edition 2003
"{97378FF6-03EB-11DA-BFBD-00065BBDC0B5}" = MSN Messenger 7.5
"{AC76BA86-1033-C470-7760-CE0000000001}" = Adobe Acrobat 6.0 CE Professional
"{BE38545B-08F7-4f80-95AE-752B99BF159C}" = Web'n'walk 4G software
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{E61CAE2E-6D6E-43C1-941B-17A69BC144C5}" = 602XML Filler
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"CCleaner" = CCleaner
"HijackThis" = HijackThis 2.0.2
"IrfanView" = IrfanView (remove only)
"Jakov A-Z ceník" = Jakov A-Z ceník
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.2)" = Mozilla Firefox (3.0.2)
"PROSet" = Intel(R) PRO Network Adapters and Drivers
"Totalcmd" = Total Commander (Remove or Repair)
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinRAR archiver" = WinRAR

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 13.4.2010 6:25:15 | Computer Name = MILADA-CINKANIC | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x8007054b). Zadaná doména neexistuje nebo není k dispozici.

Zápis nebude proveden.

Error - 13.4.2010 7:51:36 | Computer Name = MILADA-CINKANIC | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 13.4.2010 7:51:51 | Computer Name = MILADA-CINKANIC | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 13.4.2010 7:52:36 | Computer Name = MILADA-CINKANIC | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x8007054b). Zadaná doména neexistuje nebo není k dispozici.

Zápis nebude proveden.

Error - 14.4.2010 7:48:46 | Computer Name = MILADA-CINKANIC | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 14.4.2010 7:49:46 | Computer Name = MILADA-CINKANIC | Source = Userenv | ID = 1053
Description = Systém Windows nemůže určit jméno uživatele nebo název počítače. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 14.4.2010 7:50:05 | Computer Name = MILADA-CINKANIC | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x8007054b). Zadaná doména neexistuje nebo není k dispozici.

Zápis nebude proveden.

Error - 14.4.2010 8:30:12 | Computer Name = MILADA-CINKANIC | Source = Userenv | ID = 1054
Description = Systém Windows nemůže získat název řadiče domény vaší sítě. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


Error - 14.4.2010 8:31:13 | Computer Name = MILADA-CINKANIC | Source = AutoEnrollment | ID = 15
Description = Automatickému zápisu certifikátu pro Local System se nezdařilo kontaktovat
adresář Active Directory(0x8007054b). Zadaná doména neexistuje nebo není k dispozici.

Zápis nebude proveden.

Error - 14.4.2010 8:36:13 | Computer Name = MILADA-CINKANIC | Source = Userenv | ID = 1053
Description = Systém Windows nemůže určit jméno uživatele nebo název počítače. (Zadaná
doména neexistuje nebo není k dispozici. ). Zpracovávání zásad skupin bylo zastaveno.


[ System Events ]
Error - 13.4.2010 9:36:40 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 119 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 13.4.2010 11:36:40 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 239 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 14.4.2010 7:48:31 | Computer Name = MILADA-CINKANIC | Source = NETLOGON | ID = 5719
Description = V doméně ENET není k dispozici žádný řadič domény z důvodu: %%1311.

Přesvědčte
se, zda je počítač připojen k síti a akci opakujte. Pokud budou potíže trvat, obraťte
se na správce domény.

Error - 14.4.2010 7:48:35 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 14 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 14.4.2010 7:48:50 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 14 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 14.4.2010 8:03:53 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 29 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 14.4.2010 8:29:57 | Computer Name = MILADA-CINKANIC | Source = NETLOGON | ID = 5719
Description = V doméně ENET není k dispozici žádný řadič domény z důvodu: %%1311.

Přesvědčte
se, zda je počítač připojen k síti a akci opakujte. Pokud budou potíže trvat, obraťte
se na správce domény.

Error - 14.4.2010 8:30:01 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 14 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 14.4.2010 8:30:16 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 14 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.

Error - 14.4.2010 8:45:16 | Computer Name = MILADA-CINKANIC | Source = W32Time | ID = 39452701
Description = Klient NTP zprostředkovatele časových údajů je konfigurován pro získávání
časových údajů z jednoho nebo více zdrojů času. Žádný z těchto zdrojů však není
aktuálně k dispozici. Po dobu 29 minut nebude proveden žádný pokus o kontaktování
zdroje. Klient NTP nemá k dispozici žádný zdroj času.


< End of report >

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#17 Příspěvek od Caroprd111 »

PC1

Obrázek Poprosím o nový log z RSIT.

PC2

Obrázek Soubor C:\UsbFix_Upload_Me_ENET.zip prosím uložte na http://chiquitine.changelog.fr/Sample/Upload.php


Obrázek Podívám se na log a napíšu Vám další postup.
Obrázek

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#18 Příspěvek od kisuah »

Soubor ulozen...

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#19 Příspěvek od Caroprd111 »

PC1

Obrázek Poprosím o nový log z RSIT.



PC2

Obrázek Spusťte OTL a do spodního okna vložte následující skript.

Kód: Vybrat vše

:OTL
O4 - HKLM..\Run: [pdfSaver3] File not found
O15 - HKCU\..Trusted Domains: ([]msn in Tento počítač)
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2010.04.12 16:21:28 | 000,007,486 | RHS- | M] () -- C:\WINDOWS\System32\killVBS.vbs

:Commands
[EMPTYTEMP] 
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[CREATERESTOREPOINT]
[REBOOT]
Poté klikněte na Opravit, PC se restartuje, log vložte sem.
Obrázek

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#20 Příspěvek od kisuah »

PC1

Logfile of random's system information tool 1.06 (written by random/random)
Run by danhill at 2010-04-15 13:31:32
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 7 GB (18%) free of 38 GB
Total RAM: 247 MB (23% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:34:38, on 15. 4. 2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\MNMCtrl.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\danhill\Plocha\Zaloha\RSIT.exe
C:\Program Files\trend micro\danhill.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aktualne.cz/?ms=ae
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aktualne.cz/?ms=ae
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [MNM] "C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\\MNetMgr.exe" -SysTray
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Xchat.cz - {18750184-292F-4B5E-94D5-0A29DA01C817} - http://www.xchat.cz (file missing) (HKCU)
O9 - Extra button: Centrum.cz - {3F596729-F602-4BDE-8389-F75BF1EF5FCC} - http://www.centrum.cz (file missing) (HKCU)
O9 - Extra button: Slovníky - {48F8F5C8-5D69-4EA3-BA2F-4F0B048E82C3} - http://slovniky.centrum.cz (file missing) (HKCU)
O9 - Extra button: Aktuálně - {542A02D4-38EA-4F02-90A7-FBEBE583E550} - http://aktualne.centrum.cz (file missing) (HKCU)
O9 - Extra button: Bleskově - {6FE8EFEC-7287-4E27-82B0-2F17277D1C17} - http://www.bleskove.cz (file missing) (HKCU)
O9 - Extra button: Supermapy - {7260DC17-8F19-4584-A2AA-289E7ECEBA58} - http://www.supermapy.cz (file missing) (HKCU)
O9 - Extra button: Stahuj.cz - {88C7C56B-52A0-443E-A2BF-15E18956B4EC} - http://www.stahuj.cz (file missing) (HKCU)
O9 - Extra button: Fotoalba - {9F8EADC5-FFCA-4FAB-862C-18B945701F79} - http://www.fotoalba.cz (file missing) (HKCU)
O9 - Extra button: Žena.cz - {E506FD84-D67F-402D-8E7E-8BFD31EA5A75} - http://www.zena.cz (file missing) (HKCU)
O9 - Extra button: Počasí - {F337B35A-3372-4565-8570-D80E75BBD6AC} - http://pocasi.centrum.cz (file missing) (HKCU)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB0198A-56AA-463D-B649-EF1FDE15DAC5}: Domain = www
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: mnmwlxchain - C:\WINDOWS\SYSTEM32\NTGlobeBTA.dll
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 6661 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 184423]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-18 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2004-10-14 1388544]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2004-09-23 860160]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-11-16 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-11-16 126976]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2004-09-07 213054]
"MNM"=C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\\MNetMgr.exe [2002-11-20 864256]
"openvpn-gui"=C:\Program Files\OpenVPN\bin\openvpn-gui.exe [2005-08-18 99328]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
C:\WINDOWS\AGRSMMSG.exe [2004-08-24 88363]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CnxDslTaskBar]
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe [2004-11-12 790528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-08-06 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [2005-11-10 36975]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-02-18 2012912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-11-04 688218]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-11-04 98394]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\T-Mobile Communication Centre]
C:\Program Files\T-Mobile\web'n'walk Manager\Manager.exe [2007-02-21 928448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2004-10-26 184320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-11-16 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mnmwlxchain]
C:\WINDOWS\system32\NTGlobeBTA.dll [2002-11-20 106496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=255
"HonorAutoRunSetting"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\CesarFTP\Server.exe"="C:\Program Files\CesarFTP\Server.exe:*:Enabled:Server"
"C:\Documents and Settings\danhill\Dokumenty\Záloha notasu\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe"="C:\Documents and Settings\danhill\Dokumenty\Záloha notasu\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe:*:Enabled:PRO.11 Configuration Utility"
"C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe"="C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe:*:Enabled:PRO.11 Configuration Utility"
"C:\Program Files\X-Lite\X-Lite.exe"="C:\Program Files\X-Lite\X-Lite.exe:*:Enabled:X-Lite"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\inoteska\uniman\v8 sl\mnunia08.exe"="C:\inoteska\uniman\v8 sl\mnunia08.exe:*:Enabled:UniMan - release"
"C:\Documents and Settings\danhill\Plocha\winbox.exe"="C:\Documents and Settings\danhill\Plocha\winbox.exe:*:Enabled:winbox"
"C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\Martin\Instal\superscan4\SuperScan4.exe"="C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\Martin\Instal\superscan4\SuperScan4.exe:*:Enabled:SuperScan 4 Beta 1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Gecko Software\Track 'n Trade Live\TNT_LIVE.exe"="C:\Program Files\Gecko Software\Track 'n Trade Live\TNT_LIVE.exe:*:Enabled:Track 'n Trade Live"
"C:\Program Files\iperf-2.0.2\bin\iperf.exe"="C:\Program Files\iperf-2.0.2\bin\iperf.exe:*:Enabled:iperf"
"C:\Program Files\Kapanga Softphone\kapanga.exe"="C:\Program Files\Kapanga Softphone\kapanga.exe:*:Enabled:Kapanga Softphone"
"C:\Program Files\Attractel\Zoiper\Zoiper.exe"="C:\Program Files\Attractel\Zoiper\Zoiper.exe:*:Enabled:Zoiper"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\SJphone 1.65\SJphone.exe"="C:\Program Files\SJphone 1.65\SJphone.exe:*:Enabled:SJphone 1.65"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2010-04-15 09:29:34 ----D---- C:\WINDOWS\LastGood
2010-04-14 15:09:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-14 15:09:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-13 15:35:42 ----D---- C:\_OTL
2010-04-13 14:32:57 ----RASHD---- C:\autorun.inf
2010-04-13 14:29:36 ----A---- C:\UsbFix.txt
2010-04-13 14:26:58 ----D---- C:\UsbFix
2010-04-13 09:08:48 ----D---- C:\Program Files\trend micro
2010-04-13 09:08:37 ----D---- C:\rsit
2010-04-12 15:25:32 ----D---- C:\Documents and Settings\danhill\Data aplikací\Uniblue
2010-04-10 09:50:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-04-10 09:49:06 ----D---- C:\Program Files\SUPERAntiSpyware
2010-04-10 09:49:05 ----D---- C:\Documents and Settings\danhill\Data aplikací\SUPERAntiSpyware.com
2010-04-10 09:47:16 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\VDLL.DLL
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\system32\runouce.exe
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\rundll16.exe
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\logo1_.exe
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\logo_1.exe
2010-04-08 10:41:27 ----A---- C:\WINDOWS\system32\msvcr80.dll
2010-04-08 10:41:26 ----A---- C:\WINDOWS\system32\msvcp80.dll
2010-04-08 10:41:25 ----A---- C:\WINDOWS\system32\eEmpty.exe
2010-04-08 10:41:17 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2010-04-08 10:41:17 ----A---- C:\WINDOWS\system32\T.COM
2010-04-08 10:41:16 ----A---- C:\WINDOWS\R.COM
2010-04-08 10:41:14 ----D---- C:\Program Files\Common Files\MicroWorld
2010-04-08 10:41:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2010-04-06 15:23:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3
2010-04-06 15:20:57 ----D---- C:\Program Files\Alawar
2010-04-02 11:03:17 ----D---- C:\Program Files\Common Files\Apple
2010-04-02 11:02:46 ----D---- C:\Program Files\Apple Software Update
2010-04-02 11:02:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple

======List of files/folders modified in the last 1 months======

2010-04-15 13:31:36 ----D---- C:\WINDOWS\Prefetch
2010-04-15 09:30:41 ----HD---- C:\WINDOWS\inf
2010-04-15 09:29:59 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-15 09:29:58 ----D---- C:\WINDOWS
2010-04-15 09:28:42 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-15 09:14:22 ----D---- C:\WINDOWS\system32
2010-04-15 09:14:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-15 09:12:44 ----D---- C:\Program Files\Mozilla Firefox
2010-04-15 09:10:19 ----D---- C:\WINDOWS\Temp
2010-04-14 15:09:51 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-14 15:09:29 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-14 15:09:23 ----A---- C:\WINDOWS\imsins.BAK
2010-04-13 15:36:29 ----SHD---- C:\System Volume Information
2010-04-13 15:36:29 ----D---- C:\WINDOWS\system32\Restore
2010-04-13 14:32:52 ----SHD---- C:\RECYCLER
2010-04-13 10:05:26 ----A---- C:\WINDOWS\wincmd.ini
2010-04-13 10:05:24 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-04-13 09:08:48 ----RD---- C:\Program Files
2010-04-12 14:21:08 ----D---- C:\Poker
2010-04-10 20:34:48 ----SH---- C:\boot.ini
2010-04-10 20:34:47 ----A---- C:\WINDOWS\win.ini
2010-04-10 20:34:47 ----A---- C:\WINDOWS\system.ini
2010-04-10 09:49:25 ----SHD---- C:\WINDOWS\Installer
2010-04-10 09:49:25 ----HD---- C:\Config.Msi
2010-04-10 09:47:16 ----D---- C:\Program Files\Common Files
2010-04-08 09:27:25 ----D---- C:\Program Files\XTB-Trader
2010-04-08 09:26:07 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-04-06 15:22:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
2010-04-06 11:24:57 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-04-03 18:59:04 ----D---- C:\Documents and Settings\danhill\Data aplikací\Skype
2010-04-03 18:58:43 ----A---- C:\WINDOWS\ModemLog_Wireless Broadband Modem (WDM) #2.txt
2010-04-03 18:43:15 ----D---- C:\Documents and Settings\danhill\Data aplikací\skypePM
2010-04-03 17:04:52 ----A---- C:\WINDOWS\ModemLog_Agere Systems AC'97 Modem.txt
2010-04-02 11:05:16 ----D---- C:\Program Files\QuickTime
2010-04-02 11:04:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-04-02 11:03:29 ----D---- C:\WINDOWS\WinSxS
2010-03-31 12:08:45 ----D---- C:\WINDOWS\system32\cs-cz
2010-03-31 12:08:45 ----D---- C:\Program Files\Internet Explorer
2010-03-28 11:12:21 ----D---- C:\Program Files\Mozilla Thunderbird
2010-03-27 14:38:31 ----D---- C:\Program Files\Hry.cz

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-27 39936]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2004-08-04 8832]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2006-04-28 15781]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2004-11-08 127744]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-08-24 1268204]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-18 60800]
R3 BCM43XX;BCM 802.11b ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2004-10-29 342912]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2004-05-26 44928]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-04 14080]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-11-16 754909]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-18 61824]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-10-13 259840]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-11-04 186016]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 93440]
S3 CnxTgNW;Conexant AccessRunner ADSL WAN PPPoA Adapter Driver; C:\WINDOWS\system32\DRIVERS\CnxTgNW.sys []
S3 FTDIBUS;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2004-04-20 24209]
S3 FTSER2K;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2004-04-20 57404]
S3 ipw_bus;IPWireless; C:\WINDOWS\system32\DRIVERS\ipw_bus.sys [2005-09-27 58320]
S3 ipw_mdfl;Wireless Broadband Modem Filter; C:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys [2005-09-27 8272]
S3 ipw_mdm;Wireless Broadband Modem (WDM); C:\WINDOWS\system32\DRIVERS\ipw_mdm.sys [2005-09-27 95440]
S3 IpwP;IPWireless 3G Network Adapter; C:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2007-06-12 51040]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 PCMCARD;Billionton 10/100 Base FastEthernet PC Card; C:\WINDOWS\system32\DRIVERS\PCMCARD.sys [2006-04-28 16021]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2005-06-17 119424]
S3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2004-06-24 23552]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 Usblink;Usblink Driver; C:\WINDOWS\System32\Drivers\ulink.sys [2003-08-08 40788]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 WLTRYSVC;WLTRYSVC; C:\WINDOWS\System32\wltrysvc.exe [2004-10-29 57344]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe [2005-04-29 69632]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2005-08-25 16384]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\system32\snmptrap.exe [2004-08-18 8704]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#21 Příspěvek od Caroprd111 »

PC1


Obrázek Tohle otestujte na http://www.virustotal.com/cs/
C:\WINDOWS\SYSTEM32\NTGlobeBTA.dll

(Soubor nehledejte, jenom vložíte tučně označenou cestu, v případě hlášky "Soubor již byl testován" dejte otestovat znovu. Výsledek analýzy sem v podobě odkazu vložte.)


Obrázek Znovu spusťte UsbFix a zvolte možnost 6.


Obrázek Stáhněte a použijte http://oldtimer.geekstogo.com/TFC.exe


Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky stiskem "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít


Obrázek Doinstalujte SP3 http://www.viry.cz/forum/viewtopic.php?f=46&t=86100


Obrázek V logu nevidím antivir a firewall, doinstalujte :!: http://www.viry.cz/forum/viewtopic.php?f=29&t=6152 + http://www.viry.cz/forum/viewtopic.php?f=41&t=6523
Obrázek

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#22 Příspěvek od kisuah »

PC2

All processes killed
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\pdfSaver3 deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\ deleted successfully.
C:\WINDOWS\002396_.tmp deleted successfully.
C:\WINDOWS\msdownld.tmp folder deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET7.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\system32\killVBS.vbs moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 83 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: MCI
->Temp folder emptied: 112096278 bytes
->Temporary Internet Files folder emptied: 58769 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 62785816 bytes
->Flash cache emptied: 630 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: PC

User: RPS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 5529752 bytes
->Flash cache emptied: 300 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 21846915 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33726 bytes
RecycleBin emptied: 63808 bytes

Total Files Cleaned = 193,00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: MCI
->Flash cache emptied: 0 bytes

User: NetworkService

User: PC

User: RPS
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

Restore points cleared and new OTL Restore Point set!
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

OTL by OldTimer - Version 3.2.1.1 log created on 04152010_135659

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#23 Příspěvek od kisuah »

PC1

Soubor NTGlobeBTA.dll přijatý 2010.04.15 12:52:33 (UTC)
Současný stav: Čekejte ... Ve frontě Čekání Testování Dokončeno NENALEZENO ZASTAVENO
Výsledek: 0/40 (0%)
Načítám informace ze serveru...
Váš soubor čeká ve frontě na pozici: ___.
Odhadovaný čas začátku mezi ___ a ___ .
Nezavírejte toto okno dokud nebude test dokončen.
Právě testující program byl je zastaven, probíhá čekání na program.
Za chvíli bude proveden další pokus o otestování souboru.
Pokud budete čekat déle než-li pět minut odešlete Váš soubor znovu.
Váš soubor je nyní testován pomocí VirusTotal,
výsledky budou zobrazeny po dokončení.
Formátované Formátované
Vytisknout výsledky Vytisknout výsledky
Váš soubor není platný, nebo neexistuje.
Služba je pozastavena v tuto chvíli, váš soubor čeká na otestování (pozice: ) po nespecifikovanou dobu.

Nyní čekejte na odezvu webu (automatické obnovení), nebo napište email do pole a klikněte na "vyžádat" a systém Vám zašle email s výsledky až bude test hotov.
Email:

Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.04.15 -
AhnLab-V3 5.0.0.2 2010.04.15 -
AntiVir 7.10.6.108 2010.04.15 -
Antiy-AVL 2.0.3.7 2010.04.15 -
Authentium 5.2.0.5 2010.04.15 -
Avast 4.8.1351.0 2010.04.14 -
Avast5 5.0.332.0 2010.04.14 -
AVG 9.0.0.787 2010.04.15 -
BitDefender 7.2 2010.04.15 -
CAT-QuickHeal 10.00 2010.04.15 -
ClamAV 0.96.0.3-git 2010.04.15 -
Comodo 4606 2010.04.15 -
DrWeb 5.0.2.03300 2010.04.15 -
eSafe 7.0.17.0 2010.04.14 -
eTrust-Vet 35.2.7427 2010.04.15 -
F-Prot 4.5.1.85 2010.04.15 -
F-Secure 9.0.15370.0 2010.04.15 -
Fortinet 4.0.14.0 2010.04.15 -
GData 19 2010.04.15 -
Ikarus T3.1.1.80.0 2010.04.15 -
Jiangmin 13.0.900 2010.04.15 -
Kaspersky 7.0.0.125 2010.04.15 -
McAfee 5.400.0.1158 2010.04.15 -
McAfee-GW-Edition 6.8.5 2010.04.15 -
Microsoft 1.5605 2010.04.15 -
NOD32 5030 2010.04.15 -
Norman 6.04.11 2010.04.15 -
nProtect 2010-04-15.02 2010.04.15 -
Panda 10.0.2.7 2010.04.15 -
PCTools 7.0.3.5 2010.04.15 -
Prevx 3.0 2010.04.15 -
Rising 22.43.03.04 2010.04.15 -
Sophos 4.52.0 2010.04.15 -
Sunbelt 6179 2010.04.15 -
Symantec 20091.2.0.41 2010.04.15 -
TheHacker 6.5.2.0.262 2010.04.15 -
TrendMicro 9.120.0.1004 2010.04.15 -
VBA32 3.12.12.4 2010.04.15 -
ViRobot 2010.4.15.2278 2010.04.15 -
VirusBuster 5.0.27.0 2010.04.15 -
Rozšiřující informace
File size: 106496 bytes
MD5...: 3610e231fbd0ce1d9795da5504509af1
SHA1..: 8fb9664175bf6b84f03424eea0859e0ac21ce941
SHA256: 447852b576495682073328175474574e07ec4f59e410cad4bd18b23908168955
ssdeep: 1536:qo1jfDcwADedPyTJJV82hw2ujCQXVgrP6RSE:qsrDcwRxiJLwjCQXVgT6
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x5a2d
timedatestamp.....: 0x3ddb81d4 (Wed Nov 20 12:36:36 2002)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xa6c5 0xb000 6.33 5152b20734fb181f04ea028b1bfc38de
.rdata 0xc000 0x15f2 0x2000 4.21 b10ff4ad056a6970025d434f7eaf1654
.data 0xe000 0x7230 0x5000 2.96 622deb1055f5c8ce1d74507a8d398d71
.shared 0x16000 0x4 0x1000 0.00 620f0b67a91f7f74151bc5be745b7110
.rsrc 0x17000 0x36f8 0x4000 4.04 aed90ed8c5cfcab774eb28d225af2219
.reloc 0x1b000 0x17ac 0x2000 4.17 59ad3d048282b9b3626fa748bb5e0520

( 4 imports )
> KERNEL32.dll: LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, GetTimeFormatA, WriteFile, FlushFileBuffers, GetSystemTime, LocalAlloc, CreateMailslotA, CreateFileA, CloseHandle, Sleep, SetCurrentDirectoryA, GetDateFormatA, SetFilePointer, WideCharToMultiByte, GetSystemDirectoryA, CreateProcessA, MultiByteToWideChar, DisableThreadLibraryCalls, GetCommandLineA, GetCurrentProcessId, ReadFile, GetMailslotInfo, GetCurrentDirectoryA, LocalFree, LoadLibraryA, SetLastError, TlsFree, SetStdHandle, GetStringTypeW, GetStringTypeA, GetOEMCP, GetACP, IsBadCodePtr, IsBadReadPtr, SetUnhandledExceptionFilter, GetProcAddress, FreeLibrary, TlsGetValue, InterlockedDecrement, InterlockedIncrement, RtlUnwind, GetLastError, ResumeThread, CreateThread, TlsSetValue, ExitThread, GetVersion, HeapFree, HeapAlloc, LCMapStringA, LCMapStringW, DeleteCriticalSection, ExitProcess, GetCurrentThreadId, TlsAlloc, GetCPInfo, FreeEnvironmentStringsW, FreeEnvironmentStringsA, IsBadWritePtr, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, GetModuleFileNameA, HeapReAlloc, GetVersionExA, GetEnvironmentStrings, GetEnvironmentStringsW, GetModuleHandleA, GetEnvironmentVariableA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc
> USER32.dll: DialogBoxParamA, MessageBoxA, GetDesktopWindow, SendDlgItemMessageA, SetForegroundWindow, SetWindowPos, GetParent, GetSystemMetrics, GetWindowLongA, GetWindowRect, PostMessageA, EndDialog, GetDlgCtrlID, EnableWindow, LoadImageA, GetDlgItem, SendMessageA, SetTimer, LoadCursorA, SetCursor, KillTimer, SetClassLongA
> GDI32.dll: SetBkColor, DeleteObject, SetTextColor, CreateSolidBrush
> ADVAPI32.dll: RegEnumKeyA, SetSecurityDescriptorDacl, RegQueryValueExA, RegCloseKey, RegDeleteValueA, RegOpenKeyExA, RegSetValueExA, RegOpenKeyA, RegFlushKey, InitializeSecurityDescriptor

( 29 exports )
EnableLoging, FreeDependentDLLs, Invoke_POST_BTA, Invoke_PRE_BTA, LoadDependentDLLs, WLEventLogoff, WLEventLogon, WLEventShutdown, WLEventStartup, WlxActivateUserShell, WlxDisplayLockedNotice, WlxDisplayNotice, WlxDisplaySASNotice, WlxDisplayStatusMessage, WlxGetConsoleSwitchCredentials, WlxGetStatusMessage, WlxInitialize, WlxIsLockOk, WlxIsLogoffOk, WlxLoggedOnSAS, WlxLoggedOutSAS, WlxLogoff, WlxNegotiate, WlxNetworkProviderLoad, WlxRemoveStatusMessage, WlxScreenSaverNotify, WlxShutdown, WlxStartApplication, WlxWkstaLockedSAS
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (53.1%)
Windows Screen Saver (18.4%)
Win32 Executable Generic (12.0%)
Win32 Dynamic Link Library (generic) (10.6%)
Generic Win/DOS Executable (2.8%)
sigcheck:
publisher....: GlobeSoft AB
copyright....: Copyright (C) 2000
product......: NTGlobeBTA
description..: Boot Time Application for mnm
original name: NTGlobeBTA.DLL
internal name: NTGlobeBTA
file version.: 6, 3, 0, 4
comments.....: BTA (Boot Time Application)
signers......: -
signing date.: -
verified.....: Unsigned

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#24 Příspěvek od Caroprd111 »

PC2


Obrázek Jak to vypadá s PC :???:
Obrázek

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#25 Příspěvek od kisuah »

PC2
zasilam log....

Logfile of random's system information tool 1.06 (written by random/random)
Run by MCI at 2010-04-15 15:12:01
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 63 GB (82%) free of 76 GB
Total RAM: 239 MB (12% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:12:11, on 15.4.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\install\RSIT.exe
C:\Program Files\trend micro\MCI.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/fu ... .0.0.8.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = enet.loc
O17 - HKLM\Software\..\Telephony: DomainName = enet.loc
O17 - HKLM\System\CCS\Services\Tcpip\..\{222D6CCC-C91D-4CD4-888B-45E127A91C89}: NameServer = 82.202.112.130,213.235.146.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = enet.loc
O17 - HKLM\System\CS1\Services\Tcpip\..\{222D6CCC-C91D-4CD4-888B-45E127A91C89}: NameServer = 82.202.112.130,213.235.146.3
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4598 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\ActiveX\AcroIEHelper.dll [2003-05-12 50376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 434279]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
AcroIEToolbarHelper Class - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll [2003-05-12 147456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 6.0 CE\Acrobat\AcroIEFavClient.dll [2003-05-12 147456]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2003-05-29 790528]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2003-05-30 585728]
"IgfxTray"=C:\WINDOWS\System32\igfxtray.exe [2003-04-07 155648]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe [2003-04-07 114688]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-18 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
C:\PROGRA~1\AVG\AVG9\avgtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchList]
C:\Program Files\Pinnacle\Studio 10\LaunchList.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfSaver3]
C:\Program Files\PDF\pdfSaver\pdfSaver3.exe [2004-05-19 385024]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe [2006-10-12 49263]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-02-18 2012912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Acrobat Assistant.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0CE\Distillr\acrotray.exe [2003-07-17 217180]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Google Updater.lnk]
C:\PROGRA~1\Google\GOOGLE~3\GOOGLE~1.EXE -systray -startup []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2003-04-07 315392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=255
"HonorAutoRunSetting"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\Documents and Settings\MCI\Plocha\winbox.exe"="C:\Documents and Settings\MCI\Plocha\winbox.exe:*:Enabled:winbox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\Program Files\Pinnacle\Studio 10\programs\RM.exe"="C:\Program Files\Pinnacle\Studio 10\programs\RM.exe:*:Enabled:Render Manager"
"C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe"="C:\Program Files\Pinnacle\Studio 10\programs\Studio.exe:*:Enabled:Studio"
"C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe"="C:\Program Files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\Program Files\Pinnacle\Studio 10\programs\umi.exe"="C:\Program Files\Pinnacle\Studio 10\programs\umi.exe:*:Enabled:umi"

======File associations======

.scr - open - "C:\WINDOWS\system32\notepad.exe" "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-04-15 13:56:59 ----D---- C:\_OTL
2010-04-15 09:17:46 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 09:17:15 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 09:16:45 ----HDC---- C:\WINDOWS\$NtUninstallKB981350$
2010-04-15 09:13:54 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 09:13:23 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-15 09:10:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-15 09:06:46 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-15 09:02:41 ----A---- C:\WINDOWS\imsins.BAK
2010-04-15 09:02:07 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9L$
2010-04-14 14:42:09 ----RASHD---- C:\autorun.inf
2010-04-14 14:35:50 ----A---- C:\UsbFix.txt
2010-04-14 14:23:03 ----D---- C:\UsbFix
2010-04-14 13:56:45 ----D---- C:\Program Files\trend micro
2010-04-14 13:55:46 ----D---- C:\rsit
2010-04-13 11:17:39 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-04-13 11:17:24 ----D---- C:\Program Files\SUPERAntiSpyware
2010-04-13 11:17:23 ----D---- C:\Documents and Settings\MCI\Data aplikací\SUPERAntiSpyware.com
2010-04-13 11:16:54 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-04-13 10:47:33 ----D---- C:\WINDOWS\system32\appmgmt
2010-04-13 10:42:13 ----D---- C:\Program Files\CCleaner
2010-04-12 12:46:01 ----HD---- C:\$AVG
2010-04-12 12:08:02 ----D---- C:\Program Files\AVG
2010-04-07 11:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB980182$

======List of files/folders modified in the last 1 months======

2010-04-15 15:12:12 ----D---- C:\WINDOWS\Prefetch
2010-04-15 15:10:59 ----D---- C:\Program Files\Mozilla Firefox
2010-04-15 14:47:47 ----D---- C:\WINDOWS\system32
2010-04-15 14:47:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-15 14:46:39 ----D---- C:\WINDOWS\Temp
2010-04-15 14:04:23 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-15 13:57:47 ----SHD---- C:\System Volume Information
2010-04-15 13:57:47 ----D---- C:\WINDOWS\system32\Restore
2010-04-15 13:57:02 ----D---- C:\WINDOWS
2010-04-15 09:18:15 ----HD---- C:\WINDOWS\inf
2010-04-15 09:17:52 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-15 09:17:39 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-15 09:17:18 ----D---- C:\WINDOWS\system32\drivers
2010-04-15 09:14:24 ----D---- C:\WINDOWS\Debug
2010-04-15 09:12:57 ----SHD---- C:\WINDOWS\Installer
2010-04-15 07:42:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-14 14:42:02 ----SHD---- C:\RECYCLER
2010-04-14 13:56:45 ----RD---- C:\Program Files
2010-04-14 13:54:51 ----D---- C:\install
2010-04-13 12:22:44 ----RASH---- C:\boot.ini
2010-04-13 12:22:44 ----A---- C:\WINDOWS\win.ini
2010-04-13 12:22:44 ----A---- C:\WINDOWS\system.ini
2010-04-13 11:16:54 ----D---- C:\Program Files\Common Files
2010-04-13 11:15:45 ----D---- C:\Program Files\Google
2010-04-13 11:15:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Google
2010-04-13 11:15:41 ----SD---- C:\WINDOWS\Tasks
2010-04-12 12:06:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-04-12 12:06:39 ----D---- C:\WINDOWS\WinSxS
2010-04-07 11:33:06 ----D---- C:\Program Files\Internet Explorer
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-18 39936]
R1 PCLEPCI;PCLEPCI; \??\C:\WINDOWS\system32\drivers\pclepci.sys []
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 sf;SFI Service; C:\WINDOWS\system32\drivers\sf.sys [2003-05-09 33248]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2007-08-01 16376]
R3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-04-15 113504]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-04-15 78752]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2003-03-14 100224]
R3 E1000;Intel(R) PRO/1000 Adapter Driver; C:\WINDOWS\System32\DRIVERS\e1000325.sys [2003-05-21 121856]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2003-04-15 90907]
R3 MarvinBus;Pinnacle Marvin Bus; C:\WINDOWS\system32\DRIVERS\MarvinBus.sys [2005-06-02 171008]
R3 SMBios;Intel (R) System Managment BIOS Service; C:\WINDOWS\System32\DRIVERS\SMBios.sys [2003-06-18 35012]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-06-02 578304]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S3 ASAPIW2K;ASAPIW2K; \??\C:\WINDOWS\system32\Drivers\asapiW2k.sys []
S3 MidiSyn;MidiSyn; C:\WINDOWS\system32\drivers\MidiSyn.sys [2002-09-20 235100]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 usbprint;Třída USB Printer; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-04 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2004-08-04 25600]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe [2002-12-27 65536]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#26 Příspěvek od Caroprd111 »

PC2


Obrázek Znovu spusťte UsbFix a zvolte možnost 6.


Obrázek Stáhněte a použijte http://oldtimer.geekstogo.com/TFC.exe


Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky stiskem "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít


Obrázek Doinstalujte SP3 http://www.viry.cz/forum/viewtopic.php?f=46&t=86100


Obrázek V logu nevidím antivir a firewall, doinstalujte :!: http://www.viry.cz/forum/viewtopic.php?f=29&t=6152 + http://www.viry.cz/forum/viewtopic.php?f=41&t=6523


Obrázek Jak se chová PC :???:
Obrázek

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#27 Příspěvek od kisuah »

PC1
zasilam log po instalaci SP3,firewallu a antiviru,prosim o kontrolu..dekuji

Logfile of random's system information tool 1.06 (written by random/random)
Run by danhill at 2010-04-16 07:39:34
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (10%) free of 38 GB
Total RAM: 247 MB (13% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:39:51, on 16. 4. 2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\MNMCtrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\danhill\Plocha\Zaloha\RSIT.exe
C:\Program Files\trend micro\danhill.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aktualne.cz/?ms=ae
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aktualne.cz/?ms=ae
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [MNM] "C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\\MNetMgr.exe" -SysTray
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Xchat.cz - {18750184-292F-4B5E-94D5-0A29DA01C817} - http://www.xchat.cz (file missing) (HKCU)
O9 - Extra button: Centrum.cz - {3F596729-F602-4BDE-8389-F75BF1EF5FCC} - http://www.centrum.cz (file missing) (HKCU)
O9 - Extra button: Slovníky - {48F8F5C8-5D69-4EA3-BA2F-4F0B048E82C3} - http://slovniky.centrum.cz (file missing) (HKCU)
O9 - Extra button: Aktuálně - {542A02D4-38EA-4F02-90A7-FBEBE583E550} - http://aktualne.centrum.cz (file missing) (HKCU)
O9 - Extra button: Bleskově - {6FE8EFEC-7287-4E27-82B0-2F17277D1C17} - http://www.bleskove.cz (file missing) (HKCU)
O9 - Extra button: Supermapy - {7260DC17-8F19-4584-A2AA-289E7ECEBA58} - http://www.supermapy.cz (file missing) (HKCU)
O9 - Extra button: Stahuj.cz - {88C7C56B-52A0-443E-A2BF-15E18956B4EC} - http://www.stahuj.cz (file missing) (HKCU)
O9 - Extra button: Fotoalba - {9F8EADC5-FFCA-4FAB-862C-18B945701F79} - http://www.fotoalba.cz (file missing) (HKCU)
O9 - Extra button: Žena.cz - {E506FD84-D67F-402D-8E7E-8BFD31EA5A75} - http://www.zena.cz (file missing) (HKCU)
O9 - Extra button: Počasí - {F337B35A-3372-4565-8570-D80E75BBD6AC} - http://pocasi.centrum.cz (file missing) (HKCU)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b56986.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB0198A-56AA-463D-B649-EF1FDE15DAC5}: Domain = www
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: mnmwlxchain - C:\WINDOWS\SYSTEM32\NTGlobeBTA.dll
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 7207 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 184423]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-18 208952]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-18 455168]
"SoundMAXPnP"=C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe [2004-10-14 1388544]
"SoundMAX"=C:\Program Files\Analog Devices\SoundMAX\Smax4.exe [2004-09-23 860160]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2004-11-16 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2004-11-16 126976]
"Cpqset"=C:\Program Files\HPQ\Default Settings\cpqset.exe [2004-09-07 213054]
"MNM"=C:\Program Files\GlobeSoft\MultiNetwork Manager\NTx\\MNetMgr.exe [2002-11-20 864256]
"openvpn-gui"=C:\Program Files\OpenVPN\bin\openvpn-gui.exe [2005-08-18 99328]
"COMODO Firewall Pro"=C:\Program Files\Comodo\Firewall\CPF.exe [2010-04-15 1115728]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-02-18 2012912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
C:\WINDOWS\AGRSMMSG.exe [2004-08-24 88363]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CnxDslTaskBar]
C:\Program Files\ZyXEL\ADSL USB Modem\CnxDslTb.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe [2004-11-12 790528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-08-06 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2010-03-17 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [2005-11-10 36975]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-11-04 688218]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-11-04 98394]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\T-Mobile Communication Centre]
C:\Program Files\T-Mobile\web'n'walk Manager\Manager.exe [2007-02-21 928448]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2004-10-26 184320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2004-11-16 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mnmwlxchain]
C:\WINDOWS\system32\NTGlobeBTA.dll [2002-11-20 106496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=255
"NoDriveAutoRun"=255
"HonorAutoRunSetting"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\totalcmd\TOTALCMD.EXE"="C:\Program Files\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\CesarFTP\Server.exe"="C:\Program Files\CesarFTP\Server.exe:*:Enabled:Server"
"C:\Documents and Settings\danhill\Dokumenty\Záloha notasu\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe"="C:\Documents and Settings\danhill\Dokumenty\Záloha notasu\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe:*:Enabled:PRO.11 Configuration Utility"
"C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe"="C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\PRÁCE\Eridan net\PRO.11 Configuration Utility\brzmgr.exe:*:Enabled:PRO.11 Configuration Utility"
"C:\Program Files\X-Lite\X-Lite.exe"="C:\Program Files\X-Lite\X-Lite.exe:*:Enabled:X-Lite"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\inoteska\uniman\v8 sl\mnunia08.exe"="C:\inoteska\uniman\v8 sl\mnunia08.exe:*:Enabled:UniMan - release"
"C:\Documents and Settings\danhill\Plocha\winbox.exe"="C:\Documents and Settings\danhill\Plocha\winbox.exe:*:Enabled:winbox"
"C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\Martin\Instal\superscan4\SuperScan4.exe"="C:\Documents and Settings\danhill\Dokumenty\Duležité !!!\Martin\Instal\superscan4\SuperScan4.exe:*:Enabled:SuperScan 4 Beta 1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Gecko Software\Track 'n Trade Live\TNT_LIVE.exe"="C:\Program Files\Gecko Software\Track 'n Trade Live\TNT_LIVE.exe:*:Enabled:Track 'n Trade Live"
"C:\Program Files\iperf-2.0.2\bin\iperf.exe"="C:\Program Files\iperf-2.0.2\bin\iperf.exe:*:Enabled:iperf"
"C:\Program Files\Kapanga Softphone\kapanga.exe"="C:\Program Files\Kapanga Softphone\kapanga.exe:*:Enabled:Kapanga Softphone"
"C:\Program Files\Attractel\Zoiper\Zoiper.exe"="C:\Program Files\Attractel\Zoiper\Zoiper.exe:*:Enabled:Zoiper"
"C:\Program Files\TmNationsForever\TmForever.exe"="C:\Program Files\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\SJphone 1.65\SJphone.exe"="C:\Program Files\SJphone 1.65\SJphone.exe:*:Enabled:SJphone 1.65"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msncall.exe"="C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2010-04-16 07:39:34 ----D---- C:\rsit
2010-04-16 07:33:01 ----D---- C:\Documents and Settings\danhill\Data aplikací\Comodo
2010-04-16 07:32:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo
2010-04-16 07:32:33 ----A---- C:\WINDOWS\OEWABLog.txt
2010-04-16 07:29:47 ----D---- C:\WINDOWS\Prefetch
2010-04-15 18:50:22 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-04-15 18:50:06 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-04-15 18:47:29 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-04-15 18:47:20 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-04-15 18:47:03 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-04-15 17:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-04-15 17:56:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-04-15 17:55:06 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-04-15 17:53:07 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-04-15 17:51:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-04-15 17:49:26 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-04-15 17:47:27 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-04-15 17:45:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-04-15 17:43:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-04-15 17:41:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-04-15 17:39:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-04-15 17:38:05 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-04-15 17:36:22 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-04-15 17:34:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-04-15 17:32:45 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-04-15 17:30:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-04-15 17:29:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-04-15 17:27:08 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-04-15 17:25:24 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-04-15 17:23:40 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-04-15 17:21:46 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-04-15 17:19:48 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-04-15 17:18:03 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-04-15 17:16:16 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-04-15 17:14:29 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2010-04-15 17:12:29 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-04-15 17:10:33 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2010-04-15 17:08:50 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-04-15 17:07:06 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2010-04-15 17:04:37 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$
2010-04-15 17:02:54 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-04-15 17:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-04-15 16:58:26 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-04-15 16:56:26 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-04-15 16:54:33 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-04-15 16:52:36 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2010-04-15 16:50:43 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-04-15 16:48:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2010-04-15 16:46:53 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-04-15 16:44:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-04-15 16:42:50 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-04-15 16:40:52 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-04-15 16:38:55 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_1$
2010-04-15 16:36:57 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2010-04-15 16:35:03 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2010-04-15 16:33:11 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-04-15 16:31:13 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-04-15 16:29:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-04-15 16:27:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-04-15 16:25:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2010-04-15 16:23:44 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-04-15 16:21:54 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-04-15 16:20:00 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-04-15 16:18:07 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2010-04-15 16:15:45 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-04-15 16:14:52 ----D---- C:\WINDOWS\LastGood.Tmp
2010-04-15 16:10:22 ----A---- C:\WINDOWS\setuplog.txt
2010-04-15 16:08:42 ----N---- C:\WINDOWS\system32\msxml6r.dll
2010-04-15 16:08:42 ----N---- C:\WINDOWS\system32\msxml6.dll
2010-04-15 16:08:40 ----N---- C:\WINDOWS\system32\smtpapi.dll
2010-04-15 16:08:40 ----N---- C:\WINDOWS\system32\rwnh.dll
2010-04-15 16:08:40 ----N---- C:\WINDOWS\system32\comsdupd.exe
2010-04-15 16:08:34 ----N---- C:\WINDOWS\system32\ati2cqag.dll
2010-04-15 16:08:34 ----N---- C:\WINDOWS\system32\aaclient.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\azroles.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\ativvaxx.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\ativtmxx.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\ati3duag.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\ati3d1ag.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\ati2dvag.dll
2010-04-15 16:08:33 ----N---- C:\WINDOWS\system32\ati2dvaa.dll
2010-04-15 16:08:32 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2010-04-15 16:08:32 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2010-04-15 16:08:32 ----N---- C:\WINDOWS\system32\credssp.dll
2010-04-15 16:08:32 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\eapphost.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\eappgnui.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\eappcfg.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\eapolqec.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3ui.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3svc.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3msm.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dot3api.dll
2010-04-15 16:08:31 ----N---- C:\WINDOWS\system32\dimsroam.dll
2010-04-15 16:08:30 ----N---- C:\WINDOWS\system32\hsfcisp2.dll
2010-04-15 16:08:30 ----N---- C:\WINDOWS\system32\eapsvc.dll
2010-04-15 16:08:30 ----N---- C:\WINDOWS\system32\eapqec.dll
2010-04-15 16:08:30 ----N---- C:\WINDOWS\system32\eappprxy.dll
2010-04-15 16:08:28 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2010-04-15 16:08:28 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2010-04-15 16:08:28 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2010-04-15 16:08:27 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2010-04-15 16:08:27 ----N---- C:\WINDOWS\system32\kmsvc.dll
2010-04-15 16:08:27 ----N---- C:\WINDOWS\system32\kbdpash.dll
2010-04-15 16:08:26 ----N---- C:\WINDOWS\system32\mmcperf.exe
2010-04-15 16:08:26 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2010-04-15 16:08:26 ----N---- C:\WINDOWS\system32\mmcex.dll
2010-04-15 16:08:26 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2010-04-15 16:08:26 ----N---- C:\WINDOWS\system32\mdmxsdk.dll
2010-04-15 16:08:25 ----N---- C:\WINDOWS\system32\napstat.exe
2010-04-15 16:08:25 ----N---- C:\WINDOWS\system32\napmontr.dll
2010-04-15 16:08:25 ----N---- C:\WINDOWS\system32\napipsec.dll
2010-04-15 16:08:25 ----N---- C:\WINDOWS\system32\mtxparhd.dll
2010-04-15 16:08:25 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2010-04-15 16:08:25 ----N---- C:\WINDOWS\system32\mssha.dll
2010-04-15 16:08:24 ----N---- C:\WINDOWS\system32\onex.dll
2010-04-15 16:08:24 ----N---- C:\WINDOWS\system32\nv4_disp.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\s3gnb.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\rasqec.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\qutil.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\qcliprov.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\qagentrt.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\qagent.dll
2010-04-15 16:08:23 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2010-04-15 16:08:22 ----N---- C:\WINDOWS\system32\slserv.exe
2010-04-15 16:08:22 ----N---- C:\WINDOWS\system32\slrundll.exe
2010-04-15 16:08:22 ----N---- C:\WINDOWS\system32\slgen.dll
2010-04-15 16:08:22 ----N---- C:\WINDOWS\system32\slextspk.dll
2010-04-15 16:08:22 ----N---- C:\WINDOWS\system32\slcoinst.dll
2010-04-15 16:08:22 ----N---- C:\WINDOWS\system32\setupn.exe
2010-04-15 16:08:20 ----N---- C:\WINDOWS\system32\tspkg.dll
2010-04-15 16:08:20 ----N---- C:\WINDOWS\system32\tsgqec.dll
2010-04-15 16:08:19 ----N---- C:\WINDOWS\system32\wmphoto.dll
2010-04-15 16:08:19 ----N---- C:\WINDOWS\system32\wlanapi.dll
2010-04-15 16:08:19 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2010-04-15 16:08:19 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2010-04-15 16:08:17 ----N---- C:\WINDOWS\slrundll.exe
2010-04-15 16:08:15 ----D---- C:\WINDOWS\l2schemas
2010-04-15 16:08:14 ----D---- C:\WINDOWS\system32\cs
2010-04-15 16:08:13 ----D---- C:\WINDOWS\system32\bits
2010-04-15 15:57:25 ----A---- C:\WINDOWS\002785_.tmp
2010-04-15 15:57:22 ----A---- C:\WINDOWS\imsins.BAK
2010-04-15 15:52:57 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-04-15 15:19:57 ----A---- C:\boot.ini.comodofirewall
2010-04-15 15:19:34 ----D---- C:\Program Files\Comodo
2010-04-14 15:09:27 ----HDC---- C:\WINDOWS\$NtUninstallKB978601_0$
2010-04-14 15:09:12 ----HDC---- C:\WINDOWS\$NtUninstallKB979309_0$
2010-04-13 14:32:57 ----RASHD---- C:\autorun.inf
2010-04-13 14:26:58 ----D---- C:\UsbFix
2010-04-13 09:08:48 ----D---- C:\Program Files\trend micro
2010-04-12 15:25:32 ----D---- C:\Documents and Settings\danhill\Data aplikací\Uniblue
2010-04-10 09:50:09 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-04-10 09:49:06 ----D---- C:\Program Files\SUPERAntiSpyware
2010-04-10 09:49:05 ----D---- C:\Documents and Settings\danhill\Data aplikací\SUPERAntiSpyware.com
2010-04-10 09:47:16 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\VDLL.DLL
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\system32\runouce.exe
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\rundll16.exe
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\logo1_.exe
2010-04-08 10:45:28 ----AD---- C:\WINDOWS\logo_1.exe
2010-04-08 10:41:27 ----A---- C:\WINDOWS\system32\msvcr80.dll
2010-04-08 10:41:26 ----A---- C:\WINDOWS\system32\msvcp80.dll
2010-04-08 10:41:25 ----A---- C:\WINDOWS\system32\eEmpty.exe
2010-04-08 10:41:17 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2010-04-08 10:41:17 ----A---- C:\WINDOWS\system32\T.COM
2010-04-08 10:41:16 ----A---- C:\WINDOWS\R.COM
2010-04-08 10:41:14 ----D---- C:\Program Files\Common Files\MicroWorld
2010-04-08 10:41:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2010-04-06 15:23:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\FarmFrenzy3
2010-04-06 15:20:57 ----D---- C:\Program Files\Alawar
2010-04-02 11:03:17 ----D---- C:\Program Files\Common Files\Apple
2010-04-02 11:02:46 ----D---- C:\Program Files\Apple Software Update
2010-04-02 11:02:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple

======List of files/folders modified in the last 1 months======

2010-04-16 07:36:33 ----D---- C:\Program Files\Mozilla Firefox
2010-04-16 07:35:15 ----D---- C:\WINDOWS\system32
2010-04-16 07:35:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-04-16 07:32:54 ----D---- C:\WINDOWS\Temp
2010-04-16 07:32:33 ----D---- C:\WINDOWS
2010-04-16 07:31:27 ----D---- C:\WINDOWS\Debug
2010-04-16 07:30:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-04-16 07:28:51 ----D---- C:\WINDOWS\AppPatch
2010-04-16 07:28:50 ----D---- C:\WINDOWS\system32\Setup
2010-04-16 07:28:49 ----D---- C:\WINDOWS\system32\wbem
2010-04-16 07:28:46 ----RSD---- C:\WINDOWS\Fonts
2010-04-16 07:28:30 ----D---- C:\WINDOWS\system32\drivers
2010-04-15 18:51:03 ----D---- C:\WINDOWS\security
2010-04-15 18:50:58 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-04-15 18:50:32 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-04-15 18:50:22 ----HD---- C:\WINDOWS\inf
2010-04-15 18:50:19 ----HD---- C:\WINDOWS\$hf_mig$
2010-04-15 17:59:14 ----D---- C:\WINDOWS\system32\CatRoot
2010-04-15 17:44:25 ----D---- C:\Program Files\Movie Maker
2010-04-15 17:29:37 ----D---- C:\Program Files\Outlook Express
2010-04-15 16:20:36 ----D---- C:\Program Files\Messenger
2010-04-15 16:18:48 ----D---- C:\WINDOWS\WinSxS
2010-04-15 16:08:42 ----D---- C:\WINDOWS\ehome
2010-04-15 16:08:39 ----D---- C:\WINDOWS\system32\inetsrv
2010-04-15 16:08:38 ----D---- C:\WINDOWS\network diagnostic
2010-04-15 16:08:38 ----D---- C:\WINDOWS\ime
2010-04-15 16:08:38 ----D---- C:\WINDOWS\Help
2010-04-15 16:08:17 ----D---- C:\WINDOWS\system32\cs-cz
2010-04-15 16:08:16 ----D---- C:\WINDOWS\system32\usmt
2010-04-15 16:08:14 ----SHD---- C:\WINDOWS\Installer
2010-04-15 16:08:13 ----D---- C:\WINDOWS\PeerNet
2010-04-15 16:03:39 ----D---- C:\WINDOWS\system32\Restore
2010-04-15 16:03:38 ----D---- C:\WINDOWS\system32\npp
2010-04-15 16:03:36 ----D---- C:\WINDOWS\msagent
2010-04-15 16:03:34 ----D---- C:\WINDOWS\srchasst
2010-04-15 16:03:30 ----D---- C:\Program Files\NetMeeting
2010-04-15 16:03:28 ----D---- C:\WINDOWS\system32\Com
2010-04-15 16:03:25 ----D---- C:\Program Files\Windows NT
2010-04-15 16:03:25 ----D---- C:\Program Files\Windows Media Player
2010-04-15 16:03:21 ----D---- C:\Program Files\Common Files\System
2010-04-15 16:02:54 ----D---- C:\WINDOWS\system32\oobe
2010-04-15 16:02:52 ----D---- C:\WINDOWS\system
2010-04-15 15:45:03 ----SH---- C:\boot.ini
2010-04-15 15:45:03 ----A---- C:\WINDOWS\win.ini
2010-04-15 15:45:03 ----A---- C:\WINDOWS\system.ini
2010-04-15 15:19:34 ----RD---- C:\Program Files
2010-04-13 15:36:29 ----SHD---- C:\System Volume Information
2010-04-13 14:32:52 ----SHD---- C:\RECYCLER
2010-04-13 10:05:26 ----A---- C:\WINDOWS\wincmd.ini
2010-04-13 10:05:24 ----A---- C:\WINDOWS\wcx_ftp.ini
2010-04-12 14:21:08 ----D---- C:\Poker
2010-04-10 09:49:25 ----HD---- C:\Config.Msi
2010-04-10 09:47:16 ----D---- C:\Program Files\Common Files
2010-04-08 09:27:25 ----D---- C:\Program Files\XTB-Trader
2010-04-08 09:26:07 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-04-06 19:52:54 ----A---- C:\WINDOWS\system32\MRT.exe
2010-04-06 15:22:59 ----D---- C:\Documents and Settings\All Users\Data aplikací\AlawarWrapper
2010-04-06 11:24:57 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-04-03 18:59:04 ----D---- C:\Documents and Settings\danhill\Data aplikací\Skype
2010-04-03 18:58:43 ----A---- C:\WINDOWS\ModemLog_Wireless Broadband Modem (WDM) #2.txt
2010-04-03 18:43:15 ----D---- C:\Documents and Settings\danhill\Data aplikací\skypePM
2010-04-03 17:04:52 ----A---- C:\WINDOWS\ModemLog_Agere Systems AC'97 Modem.txt
2010-04-02 11:05:16 ----D---- C:\Program Files\QuickTime
2010-04-02 11:04:06 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-03-31 12:08:45 ----D---- C:\Program Files\Internet Explorer
2010-03-28 11:12:21 ----D---- C:\Program Files\Mozilla Thunderbird
2010-03-27 14:38:31 ----D---- C:\Program Files\Hry.cz

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 CmdMon;Comodo Application Engine; C:\WINDOWS\System32\DRIVERS\cmdmon.sys [2010-04-15 75520]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 Ethpdrv;Ethernet Packet Driver; C:\WINDOWS\system32\DRIVERS\ethpdrv.sys [2005-09-08 9728]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2006-04-28 15781]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2004-11-08 127744]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-08-24 1268204]
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 BCM43XX;BCM 802.11b ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2004-10-29 342912]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller; C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys [2004-05-26 44928]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2004-11-16 754909]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-10-13 259840]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-11-04 186016]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication; C:\WINDOWS\system32\DRIVERS\adusbser.sys [2006-10-23 93440]
S3 CnxTgNW;Conexant AccessRunner ADSL WAN PPPoA Adapter Driver; C:\WINDOWS\system32\DRIVERS\CnxTgNW.sys []
S3 FTDIBUS;USB Serial Converter Driver; C:\WINDOWS\system32\drivers\ftdibus.sys [2004-04-20 24209]
S3 FTSER2K;USB Serial Port Driver; C:\WINDOWS\system32\drivers\ftser2k.sys [2004-04-20 57404]
S3 ipw_bus;IPWireless; C:\WINDOWS\system32\DRIVERS\ipw_bus.sys [2005-09-27 58320]
S3 ipw_mdfl;Wireless Broadband Modem Filter; C:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys [2005-09-27 8272]
S3 ipw_mdm;Wireless Broadband Modem (WDM); C:\WINDOWS\system32\DRIVERS\ipw_mdm.sys [2005-09-27 95440]
S3 IpwP;IPWireless 3G Network Adapter; C:\WINDOWS\system32\DRIVERS\ipw3gnet.sys [2007-06-12 51040]
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\NSNDIS5.SYS []
S3 PCMCARD;Billionton 10/100 Base FastEthernet PC Card; C:\WINDOWS\system32\DRIVERS\PCMCARD.sys [2006-04-28 16021]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2005-06-17 119424]
S3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2004-06-24 23552]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 Usblink;Usblink Driver; C:\WINDOWS\System32\Drivers\ulink.sys [2003-08-08 40788]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CmdAgent;Comodo Application Agent; C:\Program Files\Comodo\Firewall\cmdagent.exe [2010-04-15 361040]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPZipm12.exe [2005-04-29 69632]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 WLTRYSVC;WLTRYSVC; C:\WINDOWS\System32\wltrysvc.exe [2004-10-29 57344]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2005-08-25 16384]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\system32\snmptrap.exe [2008-04-14 8704]

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#28 Příspěvek od Caroprd111 »

PC1

Obrázek Jaký jste nainstaloval antivir :???:
Obrázek

kisuah
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 12 dub 2010 13:18

Re: killvbs.vbs

#29 Příspěvek od kisuah »

SuperantiSpyware....bude to stacit? :(

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: killvbs.vbs

#30 Příspěvek od Caroprd111 »

Nebude, SAS je jen antispyware. Doinstalujte Aviru nebo Avast. Poté mi sem zkopírujte nový log z RSIT.
Obrázek

Odpovědět