

Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Prosím o kontrolu logu.
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Re: Prosím o kontrolu logu.
No, boh so mnou, idem na to. 

- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu.
Myslím si, že sa mi to na prvý krát nepodarilo, vypla som antivir ale nie firewall, ten sa ma stále niečo pýtal, dala som povoliť, povoliť, zrazu comp vyplo, v podstate ho reštartlo, ten CFScript mi ostal na ploche...ešte raz a vypnem firewall? Net stále rovnako.
Naposledy upravil(a) Yanina dne 15 úno 2010 21:47, celkem upraveno 1 x.
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
- Caroprd111
- VIP
- Příspěvky: 13492
- Registrován: 22 bře 2009 20:48
- Bydliště: Třebíč
- Kontaktovat uživatele:
Re: Prosím o kontrolu logu.
Som spať, combofix ok, ten script z plochy zmizol, ale nič sa nezmenilo..je to na depresiu toto.Tu je log.
ComboFix 10-02-12.01 - Gretka 15.02.2010 21:58:13.8.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.511.89 [GMT 1:00]
Running from: c:\documents and settings\Gretka\Plocha\ComboFix.exe
Command switches used :: c:\documents and settings\Gretka\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\tcpip.sys --> c:\windows\system32\drivers\TCPIP.SYS
c:\ndis.sys --> c:\windows\system32\drivers\ndis.sys
.
((((((((((((((((((((((((( Files Created from 2010-01-15 to 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-02-15 21:07 . 2010-02-15 21:07 53248 ----a-w- c:\temp\catchme.dll
2010-02-15 20:59 . 2010-02-15 20:59 -------- d-----w- c:\temp\WPDNSE
2010-02-15 20:41 . 2010-02-15 20:41 16384 ----atw- c:\temp\Perflib_Perfdata_13cc.dat
2010-02-15 20:41 . 2010-02-15 20:41 16384 ----atw- c:\temp\Perflib_Perfdata_137c.dat
2010-02-15 20:34 . 2010-02-15 20:34 16384 ----atw- c:\temp\Perflib_Perfdata_708.dat
2010-02-15 20:20 . 2009-08-17 14:26 361600 ------w- C:\tcpip.sys
2010-02-15 20:20 . 2009-08-17 14:26 182656 ------w- C:\ndis.sys
2010-02-15 20:02 . 2010-02-15 21:06 -------- d-----w- c:\temp\plugtmp-1
2010-02-15 20:02 . 2010-02-15 21:06 -------- d-----w- c:\temp\hsperfdata_Gretka
2010-02-15 18:18 . 2010-02-15 18:18 -------- d-----w- c:\temp\msohtmlclip1
2010-02-15 18:18 . 2010-02-15 18:18 -------- d-----w- c:\temp\msohtmlclip
2010-02-15 14:58 . 2010-02-15 14:58 -------- d-----w- c:\temp\VBE
2010-02-15 13:33 . 2010-02-15 13:50 -------- d-----w- c:\temp\plugtmp
2010-02-15 12:47 . 2010-02-15 12:47 -------- d-----w- c:\temp\Google Quick Search Box
2010-02-15 01:39 . 2010-02-15 21:06 -------- d-----w- c:\temp\CDIResData
2010-02-15 01:36 . 2010-02-15 01:36 -------- d-----w- c:\temp\Comodo
2010-02-15 01:21 . 2010-02-15 21:06 -------- d-----w- c:\temp\Google Toolbar
2010-02-15 01:03 . 2010-02-15 01:03 7168 ----a-w- c:\windows\system32\drivers\utqwodiy.sys
2010-02-14 21:06 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\82825202.sys
2010-02-14 21:06 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\8282520.sys
2010-02-14 21:06 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\82825201.sys
2010-02-14 18:58 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\37670712.sys
2010-02-14 18:58 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\3767071.sys
2010-02-14 18:58 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\37670711.sys
2010-02-14 17:47 . 2010-02-14 17:45 171552 ----a-w- c:\windows\system32\guard32.dll
2010-02-14 17:47 . 2010-02-14 17:45 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-02-14 17:47 . 2010-02-14 17:45 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-02-14 17:47 . 2010-02-14 17:45 134344 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-02-14 17:46 . 2010-02-14 17:46 -------- d-----w- c:\program files\COMODO
2010-02-14 14:51 . 2010-02-14 14:51 -------- d-----w- c:\windows\ie8updates
2010-02-14 14:49 . 2010-02-14 14:49 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2010-02-14 12:55 . 2009-12-21 19:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-14 12:55 . 2009-12-21 19:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-02-14 12:53 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-02-14 12:50 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-02-14 12:50 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-02-14 12:48 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-02-14 12:48 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-02-14 12:48 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-02-14 12:48 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-02-14 12:48 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-02-14 12:48 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-02-14 12:48 . 2009-02-09 10:56 728064 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-02-14 12:48 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-02-14 12:47 . 2009-02-09 10:56 709632 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-02-14 12:47 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-02-14 12:43 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-02-14 12:37 . 2008-04-21 21:15 216576 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-02-13 14:52 . 2010-02-13 14:53 -------- d-----w- c:\program files\Ultimate Process Manager
2010-02-13 00:39 . 2010-02-13 00:39 -------- d-----w- c:\program files\Languages
2010-02-13 00:39 . 2010-02-13 00:39 -------- d-----w- c:\program files\Helps
2010-02-12 22:46 . 2010-02-12 22:46 -------- d-----w- c:\program files\VS Revo Group
2010-02-11 22:23 . 2010-02-11 22:23 -------- d---a-w- c:\windows\VDLL.DLL
2010-02-11 22:23 . 2010-02-11 22:23 -------- d---a-w- c:\windows\RUNDL132.EXE
2010-02-11 22:23 . 2010-02-11 22:23 -------- d---a-w- c:\windows\logo_1.exe
2010-02-11 22:21 . 2010-02-11 22:21 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-02-11 15:14 . 2010-02-11 15:14 21840 ----a-w- c:\windows\system32\SIntfNT.dll
2010-02-11 15:14 . 2010-02-11 15:14 17212 ----a-w- c:\windows\system32\SIntf32.dll
2010-02-10 00:56 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-10 00:56 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-10 00:56 . 2010-02-10 00:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 12:27 . 2010-01-30 12:27 -------- d-----w- c:\windows\system32\TVUAx
2010-01-27 21:41 . 2010-01-28 17:42 -------- d-----w- c:\program files\SopCast
2010-01-27 19:29 . 2010-01-27 19:30 -------- dc-h--w- c:\windows\ie8
2010-01-20 20:59 . 2010-01-20 21:18 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-20 20:58 . 2010-01-20 20:59 -------- d-----w- c:\program files\Quick Hit
2010-01-20 20:55 . 2010-01-20 21:00 -------- d--h--w- c:\program files\Zero G Registry
2010-01-20 20:55 . 2010-01-20 20:55 -------- d-----w- c:\program files\Quick Hit Football
2010-01-20 20:55 . 2010-01-20 20:55 -------- d--h--w- c:\documents and settings\Gretka\InstallAnywhere
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-15 01:44 . 2006-01-11 07:53 -------- d-----w- c:\program files\ESET
2010-02-14 15:24 . 2003-04-16 12:00 90526 ----a-w- c:\windows\system32\perfc005.dat
2010-02-14 15:24 . 2003-04-16 12:00 452932 ----a-w- c:\windows\system32\perfh005.dat
2010-02-14 15:19 . 2008-09-03 05:23 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-14 14:45 . 2010-02-14 14:45 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2010-02-13 17:55 . 2006-01-10 07:55 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-13 00:34 . 2006-01-10 07:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-12 22:37 . 2006-01-10 08:11 -------- d-----w- c:\program files\Java
2010-02-11 19:00 . 2008-01-08 08:01 -------- d-----w- c:\program files\Opera
2010-02-09 22:04 . 2006-01-10 07:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-27 22:05 . 2006-01-10 08:11 -------- d-----w- c:\program files\Common Files\Java
2010-01-17 19:42 . 2006-01-10 08:08 -------- d-----w- c:\program files\Advanced Disk Catalog
2010-01-14 20:18 . 2010-01-14 20:18 1124 ----a-w- c:\windows\system32\ezdigsgn.dat
2010-01-14 18:55 . 2010-01-14 18:55 -------- d-----w- c:\program files\Common Files\Skype
2010-01-14 18:55 . 2006-09-23 15:18 -------- d-----r- c:\program files\Skype
2010-01-13 21:14 . 2006-01-12 21:49 -------- d-----w- c:\program files\Common Files\Ahead
2010-01-13 21:14 . 2006-01-10 07:55 -------- d-----w- c:\program files\Ahead
2010-01-09 21:56 . 2010-01-05 17:17 -------- d-----w- c:\program files\Sandboxie
2009-12-31 16:50 . 2003-04-16 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 13:26 . 2006-01-10 08:06 -------- d-----w- c:\program files\Winamp
2009-12-21 19:08 . 2003-04-16 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 16:14 . 2008-12-04 16:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-04 18:22 . 2003-04-16 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-21 16:03 . 2003-04-16 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2004-03-11 12:27 . 2008-01-12 11:31 40960 ----a-w- c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-02-14_15.50.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-15 20:35 . 2010-02-15 20:35 16384 c:\windows\temp\Perflib_Perfdata_9d4.dat
+ 2010-02-15 01:45 . 2010-02-15 01:45 10134 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\callmsi.exe
- 2010-01-27 17:59 . 2010-01-27 17:59 10134 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\callmsi.exe
+ 2003-04-16 12:00 . 2009-08-17 14:26 361600 c:\windows\system32\dllcache\tcpip.sys
- 2010-02-14 14:45 . 2010-02-14 14:45 361600 c:\windows\system32\dllcache\TCPIP.SYS
+ 2003-04-16 12:00 . 2009-08-17 14:26 182656 c:\windows\system32\dllcache\ndis.sys
+ 2010-02-15 01:45 . 2010-02-15 01:45 101480 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\egui.exe
- 2010-01-27 17:59 . 2010-01-27 17:59 101480 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\egui.exe
+ 2010-02-14 17:11 . 2010-02-14 17:11 270336 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\00b636165dfd8d53749dfd3b0ab56bb3\WindowsFormsIntegration.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 483328 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\3dc953d3accc829459af32501a6df959\UIAutomationClient.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 655360 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\d38cc7087b8514d15dd8372ba76a2033\System.Messaging.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 262144 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\32efc2695961d84de94a1b1dfd4231ac\sysglobl.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 274432 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7eaa587643ab1a7c68f67fd363a0987e\PresentationFramework.Royale.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 552960 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\55f2cc40b78198234c2ff2b2701e1b6e\PresentationFramework.Luna.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 393216 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\20fba841361711fe7631a2cc65a6e74b\PresentationFramework.Aero.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 241664 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1071cb7519a625d70c35873fbb4ed757\PresentationFramework.Classic.ni.dll
+ 2010-02-15 01:45 . 2010-02-15 01:45 1138688 c:\windows\Installer\e1319.msi
+ 2010-02-14 17:11 . 2010-02-14 17:11 1118208 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\88cc2a947bfc123757f3c4a772a09ac6\UIAutomationClientsideProviders.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 2109440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\e950a5bcc279f7702d8cc86968f7588c\System.Workflow.Runtime.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 4591616 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\da6ee48ef14dfafc0a58dcbca6fc35ca\System.Workflow.ComponentModel.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 2994176 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\92c19a64f4700a744dd0ebe02632b132\System.Workflow.Activities.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 2342912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\b7092e8403b56e3913488855e45a35ff\System.Web.Mobile.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 2039808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\3167d73ec4a0018a4253333ca6d2414c\System.Speech.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 1118208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\df9b271999fe3dad7a6a1730bdaaf105\System.Printing.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 2416640 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\c36ab5d31fe5f61859369aa7bd1f7899\ReachFramework.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 1986560 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\19e195258d51a1d2b72848efdc3add0a\PresentationUI.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 14663680 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\eb12f53c35af550915029fa84f193ce9\PresentationFramework.ni.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"="c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE" [2009-04-05 26624]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-22 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 67584]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 86960]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-11-22 122880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-14 1800464]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Gretka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
setup_9.0.0.722_14.02.2010_19-27.lnk - c:\documents and settings\Gretka\Plocha\Virus Removal Tool1\setup_9.0.0.722_14.02.2010_19-27\startup.exe [2010-2-14 72208]
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\NVIDIA\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AvRack\\rtlrack.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3902:TCP"= 3902:TCP:*:Disabled:SopClient
"3902:UDP"= 3902:UDP:*:Disabled:sopcast.exe
"3903:TCP"= 3903:TCP:*:Disabled:sop
R0 37670712;37670712 Boot Guard Driver;c:\windows\system32\drivers\37670712.sys [14.2.2010 19:58 37392]
R0 82825202;82825202 Boot Guard Driver;c:\windows\system32\drivers\82825202.sys [14.2.2010 22:06 37392]
R1 37670711;37670711;c:\windows\system32\drivers\37670711.sys [14.2.2010 19:58 128016]
R1 82825201;82825201;c:\windows\system32\drivers\82825201.sys [14.2.2010 22:06 128016]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [14.2.2010 18:47 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [14.2.2010 18:47 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 9:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 9:06 96408]
R1 setup_9.0.0.722_14.02.2010_19-27drv;setup_9.0.0.722_14.02.2010_19-27drv;c:\windows\system32\drivers\8282520.sys [14.2.2010 22:06 315408]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 9:04 735960]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 cpuz132;cpuz132;\??\c:\temp\cpuz132\cpuz132_x32.sys --> c:\temp\cpuz132\cpuz132_x32.sys [?]
S3 utqwodiy;AVZ Kernel Driver;c:\windows\system32\drivers\utqwodiy.sys [15.2.2010 2:03 7168]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.5.2006 17:50 717296]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.sk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Pobierz z &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: {{7e6a20fb-153f-402c-a84b-1a64e1955d3d} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
FF - ProfilePath - c:\documents and settings\Gretka\Data aplikací\Mozilla\Firefox\Profiles\3tvabsnb.default\
FF - component: c:\documents and settings\Gretka\Data aplikací\Mozilla\Firefox\Profiles\3tvabsnb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
FF - component: c:\documents and settings\Gretka\Data aplikací\Mozilla\Firefox\Profiles\3tvabsnb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\TV JOJ Media Player\npplugin_netscape.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-15 22:07
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-117609710-1960408961-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-117609710-1960408961-725345543-1003\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-117609710-1960408961-725345543-1003)
@Allowed: (Read) (S-1-5-21-117609710-1960408961-725345543-1003)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(504)
c:\windows\system32\guard32.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(560)
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(3744)
c:\documents and settings\All Users\Data aplikací\LangSoft\TrnOEH.dll
c:\program files\Google\Quick Search Box\bin\1.2.1151.245\qsb.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-15 22:11:29
ComboFix-quarantined-files.txt 2010-02-15 21:11
ComboFix2.txt 2010-02-14 17:13
ComboFix3.txt 2010-02-14 15:54
Pre-Run: Volných bajtů: 32 200 601 600
Post-Run: Volných bajtů: 32 181 342 208
- - End Of File - - 30BF647E4EF959C87041C5A255035914
ComboFix 10-02-12.01 - Gretka 15.02.2010 21:58:13.8.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1029.18.511.89 [GMT 1:00]
Running from: c:\documents and settings\Gretka\Plocha\ComboFix.exe
Command switches used :: c:\documents and settings\Gretka\Plocha\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\tcpip.sys --> c:\windows\system32\drivers\TCPIP.SYS
c:\ndis.sys --> c:\windows\system32\drivers\ndis.sys
.
((((((((((((((((((((((((( Files Created from 2010-01-15 to 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-02-15 21:07 . 2010-02-15 21:07 53248 ----a-w- c:\temp\catchme.dll
2010-02-15 20:59 . 2010-02-15 20:59 -------- d-----w- c:\temp\WPDNSE
2010-02-15 20:41 . 2010-02-15 20:41 16384 ----atw- c:\temp\Perflib_Perfdata_13cc.dat
2010-02-15 20:41 . 2010-02-15 20:41 16384 ----atw- c:\temp\Perflib_Perfdata_137c.dat
2010-02-15 20:34 . 2010-02-15 20:34 16384 ----atw- c:\temp\Perflib_Perfdata_708.dat
2010-02-15 20:20 . 2009-08-17 14:26 361600 ------w- C:\tcpip.sys
2010-02-15 20:20 . 2009-08-17 14:26 182656 ------w- C:\ndis.sys
2010-02-15 20:02 . 2010-02-15 21:06 -------- d-----w- c:\temp\plugtmp-1
2010-02-15 20:02 . 2010-02-15 21:06 -------- d-----w- c:\temp\hsperfdata_Gretka
2010-02-15 18:18 . 2010-02-15 18:18 -------- d-----w- c:\temp\msohtmlclip1
2010-02-15 18:18 . 2010-02-15 18:18 -------- d-----w- c:\temp\msohtmlclip
2010-02-15 14:58 . 2010-02-15 14:58 -------- d-----w- c:\temp\VBE
2010-02-15 13:33 . 2010-02-15 13:50 -------- d-----w- c:\temp\plugtmp
2010-02-15 12:47 . 2010-02-15 12:47 -------- d-----w- c:\temp\Google Quick Search Box
2010-02-15 01:39 . 2010-02-15 21:06 -------- d-----w- c:\temp\CDIResData
2010-02-15 01:36 . 2010-02-15 01:36 -------- d-----w- c:\temp\Comodo
2010-02-15 01:21 . 2010-02-15 21:06 -------- d-----w- c:\temp\Google Toolbar
2010-02-15 01:03 . 2010-02-15 01:03 7168 ----a-w- c:\windows\system32\drivers\utqwodiy.sys
2010-02-14 21:06 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\82825202.sys
2010-02-14 21:06 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\8282520.sys
2010-02-14 21:06 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\82825201.sys
2010-02-14 18:58 . 2009-10-22 11:54 37392 ----a-w- c:\windows\system32\drivers\37670712.sys
2010-02-14 18:58 . 2009-10-09 21:31 315408 ----a-w- c:\windows\system32\drivers\3767071.sys
2010-02-14 18:58 . 2009-09-25 15:59 128016 ----a-w- c:\windows\system32\drivers\37670711.sys
2010-02-14 17:47 . 2010-02-14 17:45 171552 ----a-w- c:\windows\system32\guard32.dll
2010-02-14 17:47 . 2010-02-14 17:45 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-02-14 17:47 . 2010-02-14 17:45 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-02-14 17:47 . 2010-02-14 17:45 134344 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-02-14 17:46 . 2010-02-14 17:46 -------- d-----w- c:\program files\COMODO
2010-02-14 14:51 . 2010-02-14 14:51 -------- d-----w- c:\windows\ie8updates
2010-02-14 14:49 . 2010-02-14 14:49 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2010-02-14 12:55 . 2009-12-21 19:08 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-14 12:55 . 2009-12-21 19:08 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-02-14 12:53 . 2009-11-21 16:03 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-02-14 12:50 . 2009-10-15 16:32 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-02-14 12:50 . 2009-10-15 16:32 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-02-14 12:48 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2010-02-14 12:48 . 2009-03-06 14:23 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2010-02-14 12:48 . 2009-02-09 11:25 111104 -c----w- c:\windows\system32\dllcache\services.exe
2010-02-14 12:48 . 2009-02-09 10:56 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2010-02-14 12:48 . 2009-02-09 10:56 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2010-02-14 12:48 . 2009-02-09 10:56 684032 -c----w- c:\windows\system32\dllcache\advapi32.dll
2010-02-14 12:48 . 2009-02-09 10:56 728064 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2010-02-14 12:48 . 2009-02-09 10:56 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-02-14 12:47 . 2009-02-09 10:56 709632 -c----w- c:\windows\system32\dllcache\ntdll.dll
2010-02-14 12:47 . 2009-06-21 21:48 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-02-14 12:43 . 2009-07-10 13:28 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-02-14 12:37 . 2008-04-21 21:15 216576 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-02-13 14:52 . 2010-02-13 14:53 -------- d-----w- c:\program files\Ultimate Process Manager
2010-02-13 00:39 . 2010-02-13 00:39 -------- d-----w- c:\program files\Languages
2010-02-13 00:39 . 2010-02-13 00:39 -------- d-----w- c:\program files\Helps
2010-02-12 22:46 . 2010-02-12 22:46 -------- d-----w- c:\program files\VS Revo Group
2010-02-11 22:23 . 2010-02-11 22:23 -------- d---a-w- c:\windows\VDLL.DLL
2010-02-11 22:23 . 2010-02-11 22:23 -------- d---a-w- c:\windows\RUNDL132.EXE
2010-02-11 22:23 . 2010-02-11 22:23 -------- d---a-w- c:\windows\logo_1.exe
2010-02-11 22:21 . 2010-02-11 22:21 34048 ----a-w- c:\windows\system32\eEmpty.exe
2010-02-11 15:14 . 2010-02-11 15:14 21840 ----a-w- c:\windows\system32\SIntfNT.dll
2010-02-11 15:14 . 2010-02-11 15:14 17212 ----a-w- c:\windows\system32\SIntf32.dll
2010-02-10 00:56 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-10 00:56 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-10 00:56 . 2010-02-10 00:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 12:27 . 2010-01-30 12:27 -------- d-----w- c:\windows\system32\TVUAx
2010-01-27 21:41 . 2010-01-28 17:42 -------- d-----w- c:\program files\SopCast
2010-01-27 19:29 . 2010-01-27 19:30 -------- dc-h--w- c:\windows\ie8
2010-01-20 20:59 . 2010-01-20 21:18 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-20 20:58 . 2010-01-20 20:59 -------- d-----w- c:\program files\Quick Hit
2010-01-20 20:55 . 2010-01-20 21:00 -------- d--h--w- c:\program files\Zero G Registry
2010-01-20 20:55 . 2010-01-20 20:55 -------- d-----w- c:\program files\Quick Hit Football
2010-01-20 20:55 . 2010-01-20 20:55 -------- d--h--w- c:\documents and settings\Gretka\InstallAnywhere
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-15 01:44 . 2006-01-11 07:53 -------- d-----w- c:\program files\ESET
2010-02-14 15:24 . 2003-04-16 12:00 90526 ----a-w- c:\windows\system32\perfc005.dat
2010-02-14 15:24 . 2003-04-16 12:00 452932 ----a-w- c:\windows\system32\perfh005.dat
2010-02-14 15:19 . 2008-09-03 05:23 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-14 14:45 . 2010-02-14 14:45 361600 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2010-02-13 17:55 . 2006-01-10 07:55 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-13 00:34 . 2006-01-10 07:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-12 22:37 . 2006-01-10 08:11 -------- d-----w- c:\program files\Java
2010-02-11 19:00 . 2008-01-08 08:01 -------- d-----w- c:\program files\Opera
2010-02-09 22:04 . 2006-01-10 07:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-27 22:05 . 2006-01-10 08:11 -------- d-----w- c:\program files\Common Files\Java
2010-01-17 19:42 . 2006-01-10 08:08 -------- d-----w- c:\program files\Advanced Disk Catalog
2010-01-14 20:18 . 2010-01-14 20:18 1124 ----a-w- c:\windows\system32\ezdigsgn.dat
2010-01-14 18:55 . 2010-01-14 18:55 -------- d-----w- c:\program files\Common Files\Skype
2010-01-14 18:55 . 2006-09-23 15:18 -------- d-----r- c:\program files\Skype
2010-01-13 21:14 . 2006-01-12 21:49 -------- d-----w- c:\program files\Common Files\Ahead
2010-01-13 21:14 . 2006-01-10 07:55 -------- d-----w- c:\program files\Ahead
2010-01-09 21:56 . 2010-01-05 17:17 -------- d-----w- c:\program files\Sandboxie
2009-12-31 16:50 . 2003-04-16 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 13:26 . 2006-01-10 08:06 -------- d-----w- c:\program files\Winamp
2009-12-21 19:08 . 2003-04-16 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-12-17 16:14 . 2008-12-04 16:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-04 18:22 . 2003-04-16 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-21 16:03 . 2003-04-16 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2004-03-11 12:27 . 2008-01-12 11:31 40960 ----a-w- c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-02-14_15.50.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-15 20:35 . 2010-02-15 20:35 16384 c:\windows\temp\Perflib_Perfdata_9d4.dat
+ 2010-02-15 01:45 . 2010-02-15 01:45 10134 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\callmsi.exe
- 2010-01-27 17:59 . 2010-01-27 17:59 10134 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\callmsi.exe
+ 2003-04-16 12:00 . 2009-08-17 14:26 361600 c:\windows\system32\dllcache\tcpip.sys
- 2010-02-14 14:45 . 2010-02-14 14:45 361600 c:\windows\system32\dllcache\TCPIP.SYS
+ 2003-04-16 12:00 . 2009-08-17 14:26 182656 c:\windows\system32\dllcache\ndis.sys
+ 2010-02-15 01:45 . 2010-02-15 01:45 101480 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\egui.exe
- 2010-01-27 17:59 . 2010-01-27 17:59 101480 c:\windows\Installer\{60F53518-1D76-447F-8E2C-A696B00E18DC}\egui.exe
+ 2010-02-14 17:11 . 2010-02-14 17:11 270336 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\00b636165dfd8d53749dfd3b0ab56bb3\WindowsFormsIntegration.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 483328 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\3dc953d3accc829459af32501a6df959\UIAutomationClient.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 655360 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\d38cc7087b8514d15dd8372ba76a2033\System.Messaging.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 262144 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\32efc2695961d84de94a1b1dfd4231ac\sysglobl.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 274432 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7eaa587643ab1a7c68f67fd363a0987e\PresentationFramework.Royale.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 552960 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\55f2cc40b78198234c2ff2b2701e1b6e\PresentationFramework.Luna.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 393216 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\20fba841361711fe7631a2cc65a6e74b\PresentationFramework.Aero.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 241664 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\1071cb7519a625d70c35873fbb4ed757\PresentationFramework.Classic.ni.dll
+ 2010-02-15 01:45 . 2010-02-15 01:45 1138688 c:\windows\Installer\e1319.msi
+ 2010-02-14 17:11 . 2010-02-14 17:11 1118208 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\88cc2a947bfc123757f3c4a772a09ac6\UIAutomationClientsideProviders.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 2109440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\e950a5bcc279f7702d8cc86968f7588c\System.Workflow.Runtime.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 4591616 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\da6ee48ef14dfafc0a58dcbca6fc35ca\System.Workflow.ComponentModel.ni.dll
+ 2010-02-14 17:11 . 2010-02-14 17:11 2994176 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\92c19a64f4700a744dd0ebe02632b132\System.Workflow.Activities.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 2342912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\b7092e8403b56e3913488855e45a35ff\System.Web.Mobile.ni.dll
+ 2010-02-14 17:10 . 2010-02-14 17:10 2039808 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\3167d73ec4a0018a4253333ca6d2414c\System.Speech.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 1118208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\df9b271999fe3dad7a6a1730bdaaf105\System.Printing.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 2416640 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\c36ab5d31fe5f61859369aa7bd1f7899\ReachFramework.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 1986560 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\19e195258d51a1d2b72848efdc3add0a\PresentationUI.ni.dll
+ 2010-02-14 17:09 . 2010-02-14 17:09 14663680 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\eb12f53c35af550915029fa84f193ce9\PresentationFramework.ni.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"="c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE" [2009-04-05 26624]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-22 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2007-01-05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 67584]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 86960]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-04-17 98616]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-11-22 122880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-14 1800464]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Gretka\Nabˇdka Start\Programy\Po spuçtŘnˇ\
setup_9.0.0.722_14.02.2010_19-27.lnk - c:\documents and settings\Gretka\Plocha\Virus Removal Tool1\setup_9.0.0.722_14.02.2010_19-27\startup.exe [2010-2-14 72208]
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\NVIDIA\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AvRack\\rtlrack.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3902:TCP"= 3902:TCP:*:Disabled:SopClient
"3902:UDP"= 3902:UDP:*:Disabled:sopcast.exe
"3903:TCP"= 3903:TCP:*:Disabled:sop
R0 37670712;37670712 Boot Guard Driver;c:\windows\system32\drivers\37670712.sys [14.2.2010 19:58 37392]
R0 82825202;82825202 Boot Guard Driver;c:\windows\system32\drivers\82825202.sys [14.2.2010 22:06 37392]
R1 37670711;37670711;c:\windows\system32\drivers\37670711.sys [14.2.2010 19:58 128016]
R1 82825201;82825201;c:\windows\system32\drivers\82825201.sys [14.2.2010 22:06 128016]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [14.2.2010 18:47 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [14.2.2010 18:47 25160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 9:03 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 9:06 96408]
R1 setup_9.0.0.722_14.02.2010_19-27drv;setup_9.0.0.722_14.02.2010_19-27drv;c:\windows\system32\drivers\8282520.sys [14.2.2010 22:06 315408]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 9:04 735960]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 cpuz132;cpuz132;\??\c:\temp\cpuz132\cpuz132_x32.sys --> c:\temp\cpuz132\cpuz132_x32.sys [?]
S3 utqwodiy;AVZ Kernel Driver;c:\windows\system32\drivers\utqwodiy.sys [15.2.2010 2:03 7168]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.5.2006 17:50 717296]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.sk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ICQ Toolbar Search - c:\program files\ICQToolbar\toolbaru.dll/SEARCH.HTML
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Pobierz z &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: {{7e6a20fb-153f-402c-a84b-1a64e1955d3d} - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748449} - {CC963627-B1DC-40E0-B52A-CF21EE748449} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
IE: {{cc963627-b1dc-40e0-b52a-cf21ee748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\documents and settings\All Users\Data aplikací\LangSoft\WebIE.dll
FF - ProfilePath - c:\documents and settings\Gretka\Data aplikací\Mozilla\Firefox\Profiles\3tvabsnb.default\
FF - component: c:\documents and settings\Gretka\Data aplikací\Mozilla\Firefox\Profiles\3tvabsnb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
FF - component: c:\documents and settings\Gretka\Data aplikací\Mozilla\Firefox\Profiles\3tvabsnb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\TV JOJ Media Player\npplugin_netscape.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-15 22:07
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-117609710-1960408961-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-117609710-1960408961-725345543-1003\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-117609710-1960408961-725345543-1003)
@Allowed: (Read) (S-1-5-21-117609710-1960408961-725345543-1003)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(504)
c:\windows\system32\guard32.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(560)
c:\windows\system32\guard32.dll
- - - - - - - > 'explorer.exe'(3744)
c:\documents and settings\All Users\Data aplikací\LangSoft\TrnOEH.dll
c:\program files\Google\Quick Search Box\bin\1.2.1151.245\qsb.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-15 22:11:29
ComboFix-quarantined-files.txt 2010-02-15 21:11
ComboFix2.txt 2010-02-14 17:13
ComboFix3.txt 2010-02-14 15:54
Pre-Run: Volných bajtů: 32 200 601 600
Post-Run: Volných bajtů: 32 181 342 208
- - End Of File - - 30BF647E4EF959C87041C5A255035914
Naposledy upravil(a) Yanina dne 15 úno 2010 22:18, celkem upraveno 1 x.
Re: Prosím o kontrolu logu.
Záskok za kolegu
Zkuste se podívat na disk C, zda tam nebude log - C:\ComboFix.txt, nevím po kolikáté jste combofix spouštěla, ale ten s nejvyšším číslem, např combofix3.txt
Já zatím zkusím projít těch 11 stran

Zkuste se podívat na disk C, zda tam nebude log - C:\ComboFix.txt, nevím po kolikáté jste combofix spouštěla, ale ten s nejvyšším číslem, např combofix3.txt
Já zatím zkusím projít těch 11 stran

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu.
Ok, dobrý večer, pozriem to, ten posledný(ostatný je že vraj správne) je nad vami.
Aha, teraz mi doplo, práve tento ste chcela..tak tu je. 


Naposledy upravil(a) Yanina dne 15 úno 2010 22:20, celkem upraveno 1 x.
Re: Prosím o kontrolu logu.
Aha, tak jste ho našla
Ano, soubory se i vyměnily
dejte mi 20 minut, než trochu zjistím, co jste dělali
. Budete tu ještě, nebo budeme pokračovat zítra? 


dejte mi 20 minut, než trochu zjistím, co jste dělali


Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu.
Ano, to by bolo fajn..ak by ste si zajtra našli čas.
Budem ešte tu, kolko len budete chcieť..
Najprv by som si mala dočítať, čo ste napísali a až potom reagovať, sa mi zdá. Prepáčte, asi mám "vysoko" adrenalin. 



Re: Prosím o kontrolu logu.
Já jsem to tu ještě nečetla celé a vidím to na déle. Ale vidím v logu comodo, zkoušela jste ho vypnout? Jestli ho třeba nemáte špatně nastavené.
Necháme to na zítra, já tu budu průběžně a večer určitě od 6-7 hodin, zatím si to celé nastuduji
.
Necháme to na zítra, já tu budu průběžně a večer určitě od 6-7 hodin, zatím si to celé nastuduji

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu.
Jasná vec, zítra..ok, budem tu.
Comodo mám len od včera nainštalovaný, mala som Windows firewall, tam som naotvárala porty..možno mi uškodili kadejaké sopcasty a iné P2P..

Re: Prosím o kontrolu logu.
Víte co, ještě mi sem ted vložte log ze Rsitu a zítra začneme uplně od začátku
.
Dobrou noc

Dobrou noc

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Prosím o kontrolu logu.
Dobrou noc.
Logfile of random's system information tool 1.06 (written by random/random)
Run by Gretka at 2010-02-15 22:43:11
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 31 GB (27%) free of 114 GB
Total RAM: 511 MB (19% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:43:56, on 15.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Gretka\Plocha\RSIT.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\trend micro\Gretka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2db66063-bb98-466a-aa0d-3e7acf5ed853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: setup_9.0.0.722_14.02.2010_19-27.lnk = C:\Documents and Settings\Gretka\Plocha\Virus Removal Tool1\setup_9.0.0.722_14.02.2010_19-27\startup.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O8 - Extra context menu item: Pobierz z &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7e6a20fb-153f-402c-a84b-1a64e1955d3d} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Translator Settings - {cc963627-b1dc-40e0-b52a-cf21ee748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Dictionary - {cc963627-b1dc-40e0-b52a-cf21ee748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Translate Marked Text - {cc963627-b1dc-40e0-b52a-cf21ee748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Translate Web Page - {cc963627-b1dc-40e0-b52a-cf21ee748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=www.google.sk
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4621484218
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.vexcast.com/download/vexcast.cab
O17 - HKLM\System\CS3\Services\Tcpip\..\{1853E7AD-4547-4D2A-A351-B14E0C6E3832}: NameServer = 192.168.200.17,213.151.233.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
--
End of file - 11674 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2db66063-bb98-466a-aa0d-3e7acf5ed853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-04-05 520192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-24 263280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-24 764912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-11 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-04-05 520192]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-24 263280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-06-18 67584]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-12 45056]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-05-16 86960]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2008-04-17 98616]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-11-22 122880]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-02-14 1800464]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"=C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE [2009-04-05 26624]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-22 39408]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2007-01-05 204288]
C:\Documents and Settings\Gretka\Nabídka Start\Programy\Po spuštění
setup_9.0.0.722_14.02.2010_19-27.lnk - C:\Documents and Settings\Gretka\Plocha\Virus Removal Tool1\setup_9.0.0.722_14.02.2010_19-27\startup.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-10-29 47616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\AvRack\rtlrack.exe"="C:\Program Files\AvRack\rtlrack.exe:*:Enabled:AvRack"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Disabled:SopCast Main Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-02-15 22:43:16 ----D---- C:\Program Files\trend micro
2010-02-15 22:43:11 ----D---- C:\rsit
2010-02-15 22:11:30 ----A---- C:\ComboFix.txt
2010-02-15 20:25:16 ----A---- C:\WINDOWS\resetlog.txt
2010-02-14 19:34:39 ----A---- C:\WINDOWS\cfplogvw.INI
2010-02-14 18:47:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo
2010-02-14 18:47:11 ----A---- C:\WINDOWS\system32\guard32.dll
2010-02-14 18:46:01 ----D---- C:\Program Files\COMODO
2010-02-14 16:43:11 ----A---- C:\WINDOWS\zip.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\SWSC.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\SWREG.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\sed.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\PEV.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\MBR.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\grep.exe
2010-02-14 16:43:03 ----D---- C:\WINDOWS\ERDNT
2010-02-14 16:42:58 ----D---- C:\Qoobox
2010-02-14 16:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-14 16:16:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-02-14 16:16:20 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2010-02-14 16:12:52 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-02-14 16:12:22 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-02-14 16:09:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-02-14 16:09:40 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-02-14 16:09:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-02-14 16:09:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-02-14 16:08:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-02-14 16:07:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-14 16:07:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-02-14 16:04:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-02-14 16:00:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-02-14 16:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-02-14 15:56:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-02-14 15:51:59 ----D---- C:\WINDOWS\ie8updates
2010-02-14 15:48:12 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-02-13 19:39:25 ----A---- C:\holka2.txt
2010-02-13 19:39:01 ----A---- C:\holka1.txt
2010-02-13 19:22:16 ----A---- C:\holka.txt
2010-02-13 18:58:35 ----A---- C:\1.txt
2010-02-13 17:19:48 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Mael
2010-02-13 15:52:39 ----D---- C:\Program Files\Ultimate Process Manager
2010-02-13 01:39:30 ----D---- C:\Program Files\Languages
2010-02-13 01:39:30 ----D---- C:\Program Files\Helps
2010-02-12 23:46:06 ----D---- C:\Program Files\VS Revo Group
2010-02-11 23:23:01 ----AD---- C:\WINDOWS\VDLL.DLL
2010-02-11 23:23:01 ----AD---- C:\WINDOWS\RUNDL132.EXE
2010-02-11 23:23:01 ----AD---- C:\WINDOWS\logo_1.exe
2010-02-11 23:21:09 ----A---- C:\WINDOWS\system32\eEmpty.exe
2010-02-11 16:14:25 ----A---- C:\WINDOWS\system32\SIntfNT.dll
2010-02-11 16:14:15 ----A---- C:\WINDOWS\system32\SIntf32.dll
2010-02-11 00:39:57 ----A---- C:\mwav.exe.dlm
2010-02-10 21:18:51 ----A---- C:\Resume download for mwav.exe.html
2010-02-10 21:18:13 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Download Manager
2010-02-10 14:44:17 ----A---- C:\Boot.bak
2010-02-10 14:44:10 ----RASHD---- C:\cmdcons
2010-02-10 01:56:56 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Malwarebytes
2010-02-10 01:56:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-02-10 01:56:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-09 22:25:01 ----D---- C:\WINDOWS\pss
2010-01-30 13:27:28 ----D---- C:\WINDOWS\system32\TVUAx
2010-01-27 23:05:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-01-27 23:03:40 ----A---- C:\WINDOWS\system32\javaws.exe
2010-01-27 23:03:40 ----A---- C:\WINDOWS\system32\javaw.exe
2010-01-27 23:03:39 ----A---- C:\WINDOWS\system32\java.exe
2010-01-27 22:41:48 ----D---- C:\Program Files\SopCast
2010-01-27 20:29:54 ----HDC---- C:\WINDOWS\ie8
2010-01-20 22:11:37 ----D---- C:\Documents and Settings\Gretka\Data aplikací\quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1
2010-01-20 21:59:13 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-01-20 21:58:44 ----D---- C:\Program Files\Quick Hit
2010-01-20 21:55:14 ----HD---- C:\Program Files\Zero G Registry
2010-01-20 21:55:14 ----D---- C:\Program Files\Quick Hit Football
2010-01-16 02:25:21 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
======List of files/folders modified in the last 1 months======
2010-02-15 22:43:37 ----D---- C:\Temp
2010-02-15 22:43:29 ----D---- C:\WINDOWS\temp
2010-02-15 22:43:16 ----D---- C:\Program Files
2010-02-15 22:07:26 ----D---- C:\WINDOWS
2010-02-15 22:07:26 ----A---- C:\WINDOWS\system.ini
2010-02-15 22:03:37 ----D---- C:\WINDOWS\system32\drivers
2010-02-15 22:03:37 ----D---- C:\WINDOWS\system32
2010-02-15 22:03:37 ----D---- C:\WINDOWS\AppPatch
2010-02-15 22:03:33 ----D---- C:\Program Files\Common Files
2010-02-15 21:58:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-15 21:57:45 ----A---- C:\WINDOWS\system32\mappings.txt
2010-02-15 21:57:31 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-15 21:57:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-15 21:34:36 ----SHD---- C:\WINDOWS\CSC
2010-02-15 02:45:30 ----SHD---- C:\WINDOWS\Installer
2010-02-15 02:45:11 ----D---- C:\Config.Msi
2010-02-15 02:45:03 ----HD---- C:\WINDOWS\inf
2010-02-15 02:44:08 ----D---- C:\Program Files\ESET
2010-02-14 20:07:02 ----D---- C:\WINDOWS\Minidump
2010-02-14 20:01:25 ----SHD---- C:\System Volume Information
2010-02-14 18:11:51 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-14 18:11:45 ----RSD---- C:\WINDOWS\assembly
2010-02-14 17:43:32 ----D---- C:\WINDOWS\system32\config
2010-02-14 16:43:18 ----D---- C:\WINDOWS\Prefetch
2010-02-14 16:39:30 ----D---- C:\WINDOWS\Debug
2010-02-14 16:24:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-14 16:19:29 ----D---- C:\WINDOWS\system32\wbem
2010-02-14 16:19:29 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-14 16:17:32 ----D---- C:\Program Files\Internet Explorer
2010-02-14 16:17:11 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-14 16:16:39 ----D---- C:\WINDOWS\WinSxS
2010-02-14 16:11:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-02-14 16:00:53 ----D---- C:\Program Files\Outlook Express
2010-02-14 14:57:28 ----D---- C:\WINDOWS\system32\Restore
2010-02-14 13:33:11 ----RASH---- C:\boot.ini
2010-02-14 13:33:10 ----A---- C:\WINDOWS\win.ini
2010-02-13 18:55:56 ----D---- C:\Program Files\Common Files\Adobe
2010-02-13 18:55:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-02-13 18:55:22 ----D---- C:\Program Files\Adobe
2010-02-13 18:14:17 ----D---- C:\Program Files\Mozilla Firefox
2010-02-13 01:34:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-12 23:37:41 ----D---- C:\Program Files\Java
2010-02-12 18:21:38 ----D---- C:\Translat
2010-02-12 01:37:37 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Skype
2010-02-12 00:01:55 ----D---- C:\Documents and Settings\Gretka\Data aplikací\skypePM
2010-02-11 20:47:41 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Mozilla
2010-02-11 20:01:21 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-02-11 20:00:47 ----D---- C:\Program Files\Opera
2010-02-11 01:58:08 ----D---- C:\WINDOWS\Help
2010-02-10 17:17:59 ----HDC---- C:\WINDOWS\$NtUninstallKB931836$
2010-02-10 14:53:51 ----SD---- C:\WINDOWS\Tasks
2010-02-10 02:45:15 ----HDC---- C:\WINDOWS\$NtUninstallKB924667$
2010-02-09 23:04:54 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-09 23:02:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-01 11:26:22 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-27 23:05:37 ----D---- C:\Program Files\Common Files\Java
2010-01-27 20:45:08 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-27 20:32:10 ----D---- C:\WINDOWS\Media
2010-01-27 20:30:59 ----D---- C:\WINDOWS\system32\en-US
2010-01-27 20:27:12 ----D---- C:\WINDOWS\system32\cs-cz
2010-01-27 01:30:26 ----D---- C:\WINDOWS\system32\nagasoft
2010-01-26 20:41:47 ----A---- C:\WINDOWS\iPlayer.INI
2010-01-20 22:11:24 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Adobe
2010-01-18 00:11:02 ----D---- C:\Documents and Settings\Gretka\Data aplikací\VoozieMaker
2010-01-17 20:42:01 ----D---- C:\Program Files\Advanced Disk Catalog
2010-01-16 02:25:32 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 37670711;37670711; C:\WINDOWS\system32\DRIVERS\37670711.sys [2009-09-25 128016]
R1 82825201;82825201; C:\WINDOWS\system32\DRIVERS\82825201.sys [2009-09-25 128016]
R1 AmdK8;AMD Athlon64 Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 35840]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-02-14 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-02-14 25160]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-11-16 96408]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 setup_9.0.0.722_14.02.2010_19-27drv;setup_9.0.0.722_14.02.2010_19-27drv; C:\WINDOWS\system32\DRIVERS\8282520.sys [2009-10-09 315408]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-21 626204]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-10-29 1391104]
R3 catchme;catchme; \??\c:\Temp\catchme.sys []
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-07-28 33024]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-07-28 12928]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 cpuz132;cpuz132; \??\c:\Temp\cpuz132\cpuz132_x32.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-13 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-13 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-13 21568]
S3 mbr;mbr; \??\c:\Temp\mbr.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2006-09-23 47360]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\WINDOWS\system32\DRIVERS\s116bus.sys [2007-04-03 83336]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [2007-04-03 15112]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [2007-04-03 108680]
S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s116mgmt.sys [2007-04-03 100488]
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:\WINDOWS\system32\DRIVERS\s116nd5.sys [2007-04-03 23176]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s116obex.sys [2007-04-03 98696]
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:\WINDOWS\system32\DRIVERS\s116unic.sys [2007-04-03 99080]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 utqwodiy;AVZ Kernel Driver; \??\C:\WINDOWS\system32\Drivers\utqwodiy.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-07-17 717296]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-04-17 102712]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-10-29 389120]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-02-14 723632]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 ForcewareWebInterface;Forceware Web Interface; C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2004-08-18 20543]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
R2 UTSCSI;CLCV0; C:\WINDOWS\system32\UTSCSI.EXE [2009-02-14 45056]
R2 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-10-28 520192]
S2 nSvcIp;ForceWare IP service; C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe [2004-08-19 110658]
S2 nSvcLog;ForceWare user log service; C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe [2004-08-19 53318]
S2 vvdsvc;VJVodClientServices; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-12-14 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-22 182768]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]
-----------------EOF-----------------

Logfile of random's system information tool 1.06 (written by random/random)
Run by Gretka at 2010-02-15 22:43:11
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 31 GB (27%) free of 114 GB
Total RAM: 511 MB (19% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:43:56, on 15.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Gretka\Plocha\RSIT.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\trend micro\Gretka.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2db66063-bb98-466a-aa0d-3e7acf5ed853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: setup_9.0.0.722_14.02.2010_19-27.lnk = C:\Documents and Settings\Gretka\Plocha\Virus Removal Tool1\setup_9.0.0.722_14.02.2010_19-27\startup.exe
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O8 - Extra context menu item: Pobierz z &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7e6a20fb-153f-402c-a84b-1a64e1955d3d} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Translator Settings - {cc963627-b1dc-40e0-b52a-cf21ee748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Dictionary - {cc963627-b1dc-40e0-b52a-cf21ee748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Translate Marked Text - {cc963627-b1dc-40e0-b52a-cf21ee748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {cc963627-b1dc-40e0-b52a-cf21ee748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Translate Web Page - {cc963627-b1dc-40e0-b52a-cf21ee748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=www.google.sk
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 4621484218
O16 - DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} (VodClient Control Class) - http://www.vexcast.com/download/vexcast.cab
O17 - HKLM\System\CS3\Services\Tcpip\..\{1853E7AD-4547-4D2A-A351-B14E0C6E3832}: NameServer = 192.168.200.17,213.151.233.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
--
End of file - 11674 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2db66063-bb98-466a-aa0d-3e7acf5ed853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-04-05 520192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-24 263280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2009-11-24 764912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-11 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-11 79648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-04-05 520192]
{E0E899AB-F487-11D5-8D29-0050BA6940E3}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-11-24 263280]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2004-06-18 67584]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-12 45056]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2007-08-24 33648]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2006-05-16 86960]
"ArcSoft Connection Service"=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [2008-04-17 98616]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-11-22 122880]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-02-14 1800464]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-11-16 2054360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OEXPRESS"=C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE [2009-04-05 26624]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-11-22 39408]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2007-01-05 204288]
C:\Documents and Settings\Gretka\Nabídka Start\Programy\Po spuštění
setup_9.0.0.722_14.02.2010_19-27.lnk - C:\Documents and Settings\Gretka\Plocha\Virus Removal Tool1\setup_9.0.0.722_14.02.2010_19-27\startup.exe
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-10-29 47616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\AvRack\rtlrack.exe"="C:\Program Files\AvRack\rtlrack.exe:*:Enabled:AvRack"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Disabled:SopCast Main Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2010-02-15 22:43:16 ----D---- C:\Program Files\trend micro
2010-02-15 22:43:11 ----D---- C:\rsit
2010-02-15 22:11:30 ----A---- C:\ComboFix.txt
2010-02-15 20:25:16 ----A---- C:\WINDOWS\resetlog.txt
2010-02-14 19:34:39 ----A---- C:\WINDOWS\cfplogvw.INI
2010-02-14 18:47:21 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo
2010-02-14 18:47:11 ----A---- C:\WINDOWS\system32\guard32.dll
2010-02-14 18:46:01 ----D---- C:\Program Files\COMODO
2010-02-14 16:43:11 ----A---- C:\WINDOWS\zip.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\SWSC.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\SWREG.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\sed.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\PEV.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\NIRCMD.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\MBR.exe
2010-02-14 16:43:11 ----A---- C:\WINDOWS\grep.exe
2010-02-14 16:43:03 ----D---- C:\WINDOWS\ERDNT
2010-02-14 16:42:58 ----D---- C:\Qoobox
2010-02-14 16:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-14 16:16:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-02-14 16:16:20 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2010-02-14 16:12:52 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-02-14 16:12:22 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-02-14 16:09:46 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-02-14 16:09:40 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-02-14 16:09:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-02-14 16:09:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-02-14 16:08:48 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-02-14 16:07:50 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-14 16:07:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-02-14 16:04:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-02-14 16:00:50 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-02-14 16:00:35 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-02-14 15:56:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-02-14 15:51:59 ----D---- C:\WINDOWS\ie8updates
2010-02-14 15:48:12 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-02-13 19:39:25 ----A---- C:\holka2.txt
2010-02-13 19:39:01 ----A---- C:\holka1.txt
2010-02-13 19:22:16 ----A---- C:\holka.txt
2010-02-13 18:58:35 ----A---- C:\1.txt
2010-02-13 17:19:48 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Mael
2010-02-13 15:52:39 ----D---- C:\Program Files\Ultimate Process Manager
2010-02-13 01:39:30 ----D---- C:\Program Files\Languages
2010-02-13 01:39:30 ----D---- C:\Program Files\Helps
2010-02-12 23:46:06 ----D---- C:\Program Files\VS Revo Group
2010-02-11 23:23:01 ----AD---- C:\WINDOWS\VDLL.DLL
2010-02-11 23:23:01 ----AD---- C:\WINDOWS\RUNDL132.EXE
2010-02-11 23:23:01 ----AD---- C:\WINDOWS\logo_1.exe
2010-02-11 23:21:09 ----A---- C:\WINDOWS\system32\eEmpty.exe
2010-02-11 16:14:25 ----A---- C:\WINDOWS\system32\SIntfNT.dll
2010-02-11 16:14:15 ----A---- C:\WINDOWS\system32\SIntf32.dll
2010-02-11 00:39:57 ----A---- C:\mwav.exe.dlm
2010-02-10 21:18:51 ----A---- C:\Resume download for mwav.exe.html
2010-02-10 21:18:13 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Download Manager
2010-02-10 14:44:17 ----A---- C:\Boot.bak
2010-02-10 14:44:10 ----RASHD---- C:\cmdcons
2010-02-10 01:56:56 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Malwarebytes
2010-02-10 01:56:46 ----D---- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
2010-02-10 01:56:32 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-02-09 22:25:01 ----D---- C:\WINDOWS\pss
2010-01-30 13:27:28 ----D---- C:\WINDOWS\system32\TVUAx
2010-01-27 23:05:43 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-01-27 23:03:40 ----A---- C:\WINDOWS\system32\javaws.exe
2010-01-27 23:03:40 ----A---- C:\WINDOWS\system32\javaw.exe
2010-01-27 23:03:39 ----A---- C:\WINDOWS\system32\java.exe
2010-01-27 22:41:48 ----D---- C:\Program Files\SopCast
2010-01-27 20:29:54 ----HDC---- C:\WINDOWS\ie8
2010-01-20 22:11:37 ----D---- C:\Documents and Settings\Gretka\Data aplikací\quickhit.football.QHFootball.4D5206CA741FBF5FD6AAD1A97F5076E917382B34.1
2010-01-20 21:59:13 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-01-20 21:58:44 ----D---- C:\Program Files\Quick Hit
2010-01-20 21:55:14 ----HD---- C:\Program Files\Zero G Registry
2010-01-20 21:55:14 ----D---- C:\Program Files\Quick Hit Football
2010-01-16 02:25:21 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
======List of files/folders modified in the last 1 months======
2010-02-15 22:43:37 ----D---- C:\Temp
2010-02-15 22:43:29 ----D---- C:\WINDOWS\temp
2010-02-15 22:43:16 ----D---- C:\Program Files
2010-02-15 22:07:26 ----D---- C:\WINDOWS
2010-02-15 22:07:26 ----A---- C:\WINDOWS\system.ini
2010-02-15 22:03:37 ----D---- C:\WINDOWS\system32\drivers
2010-02-15 22:03:37 ----D---- C:\WINDOWS\system32
2010-02-15 22:03:37 ----D---- C:\WINDOWS\AppPatch
2010-02-15 22:03:33 ----D---- C:\Program Files\Common Files
2010-02-15 21:58:18 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-15 21:57:45 ----A---- C:\WINDOWS\system32\mappings.txt
2010-02-15 21:57:31 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-15 21:57:09 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-15 21:34:36 ----SHD---- C:\WINDOWS\CSC
2010-02-15 02:45:30 ----SHD---- C:\WINDOWS\Installer
2010-02-15 02:45:11 ----D---- C:\Config.Msi
2010-02-15 02:45:03 ----HD---- C:\WINDOWS\inf
2010-02-15 02:44:08 ----D---- C:\Program Files\ESET
2010-02-14 20:07:02 ----D---- C:\WINDOWS\Minidump
2010-02-14 20:01:25 ----SHD---- C:\System Volume Information
2010-02-14 18:11:51 ----D---- C:\WINDOWS\Microsoft.NET
2010-02-14 18:11:45 ----RSD---- C:\WINDOWS\assembly
2010-02-14 17:43:32 ----D---- C:\WINDOWS\system32\config
2010-02-14 16:43:18 ----D---- C:\WINDOWS\Prefetch
2010-02-14 16:39:30 ----D---- C:\WINDOWS\Debug
2010-02-14 16:24:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-02-14 16:19:29 ----D---- C:\WINDOWS\system32\wbem
2010-02-14 16:19:29 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-14 16:17:32 ----D---- C:\Program Files\Internet Explorer
2010-02-14 16:17:11 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-14 16:16:39 ----D---- C:\WINDOWS\WinSxS
2010-02-14 16:11:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-02-14 16:00:53 ----D---- C:\Program Files\Outlook Express
2010-02-14 14:57:28 ----D---- C:\WINDOWS\system32\Restore
2010-02-14 13:33:11 ----RASH---- C:\boot.ini
2010-02-14 13:33:10 ----A---- C:\WINDOWS\win.ini
2010-02-13 18:55:56 ----D---- C:\Program Files\Common Files\Adobe
2010-02-13 18:55:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-02-13 18:55:22 ----D---- C:\Program Files\Adobe
2010-02-13 18:14:17 ----D---- C:\Program Files\Mozilla Firefox
2010-02-13 01:34:16 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-12 23:37:41 ----D---- C:\Program Files\Java
2010-02-12 18:21:38 ----D---- C:\Translat
2010-02-12 01:37:37 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Skype
2010-02-12 00:01:55 ----D---- C:\Documents and Settings\Gretka\Data aplikací\skypePM
2010-02-11 20:47:41 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Mozilla
2010-02-11 20:01:21 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-02-11 20:00:47 ----D---- C:\Program Files\Opera
2010-02-11 01:58:08 ----D---- C:\WINDOWS\Help
2010-02-10 17:17:59 ----HDC---- C:\WINDOWS\$NtUninstallKB931836$
2010-02-10 14:53:51 ----SD---- C:\WINDOWS\Tasks
2010-02-10 02:45:15 ----HDC---- C:\WINDOWS\$NtUninstallKB924667$
2010-02-09 23:04:54 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-02-09 23:02:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spybot - Search & Destroy
2010-02-01 11:26:22 ----A---- C:\WINDOWS\system32\MRT.exe
2010-01-27 23:05:37 ----D---- C:\Program Files\Common Files\Java
2010-01-27 20:45:08 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-01-27 20:32:10 ----D---- C:\WINDOWS\Media
2010-01-27 20:30:59 ----D---- C:\WINDOWS\system32\en-US
2010-01-27 20:27:12 ----D---- C:\WINDOWS\system32\cs-cz
2010-01-27 01:30:26 ----D---- C:\WINDOWS\system32\nagasoft
2010-01-26 20:41:47 ----A---- C:\WINDOWS\iPlayer.INI
2010-01-20 22:11:24 ----D---- C:\Documents and Settings\Gretka\Data aplikací\Adobe
2010-01-18 00:11:02 ----D---- C:\Documents and Settings\Gretka\Data aplikací\VoozieMaker
2010-01-17 20:42:01 ----D---- C:\Program Files\Advanced Disk Catalog
2010-01-16 02:25:32 ----D---- C:\WINDOWS\system32\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 37670711;37670711; C:\WINDOWS\system32\DRIVERS\37670711.sys [2009-09-25 128016]
R1 82825201;82825201; C:\WINDOWS\system32\DRIVERS\82825201.sys [2009-09-25 128016]
R1 AmdK8;AMD Athlon64 Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-05-08 35840]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-02-14 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-02-14 25160]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-11-16 108792]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-11-16 96408]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 setup_9.0.0.722_14.02.2010_19-27drv;setup_9.0.0.722_14.02.2010_19-27drv; C:\WINDOWS\system32\DRIVERS\8282520.sys [2009-10-09 315408]
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-04-16 12032]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-11-16 116520]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ALCXSENS;Service for WDM 3D Audio Driver; C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2004-02-24 400384]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-06-21 626204]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-10-29 1391104]
R3 catchme;catchme; \??\c:\Temp\catchme.sys []
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2004-07-28 33024]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2004-07-28 12928]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S3 cpuz132;cpuz132; \??\c:\Temp\cpuz132\cpuz132_x32.sys []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-13 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-13 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-13 21568]
S3 mbr;mbr; \??\c:\Temp\mbr.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys []
S3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2006-09-23 47360]
S3 s116bus;Sony Ericsson Device 116 driver (WDM); C:\WINDOWS\system32\DRIVERS\s116bus.sys [2007-04-03 83336]
S3 s116mdfl;Sony Ericsson Device 116 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s116mdfl.sys [2007-04-03 15112]
S3 s116mdm;Sony Ericsson Device 116 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s116mdm.sys [2007-04-03 108680]
S3 s116mgmt;Sony Ericsson Device 116 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s116mgmt.sys [2007-04-03 100488]
S3 s116nd5;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (NDIS); C:\WINDOWS\system32\DRIVERS\s116nd5.sys [2007-04-03 23176]
S3 s116obex;Sony Ericsson Device 116 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s116obex.sys [2007-04-03 98696]
S3 s116unic;Sony Ericsson Device 116 USB Ethernet Emulation SEMC116 (WDM); C:\WINDOWS\system32\DRIVERS\s116unic.sys [2007-04-03 99080]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 utqwodiy;AVZ Kernel Driver; \??\C:\WINDOWS\system32\Drivers\utqwodiy.sys []
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2008-03-27 503008]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688]
S4 dwshd;dwshd; C:\WINDOWS\System32\drivers\dwshd.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2008-07-17 717296]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-04-17 102712]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-10-29 389120]
R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-02-14 723632]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-11-16 735960]
R2 ForcewareWebInterface;Forceware Web Interface; C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2004-08-18 20543]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-17 153376]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
R2 UTSCSI;CLCV0; C:\WINDOWS\system32\UTSCSI.EXE [2009-02-14 45056]
R2 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-10-28 520192]
S2 nSvcIp;ForceWare IP service; C:\NVIDIA\NetworkAccessManager\bin\nSvcIp.exe [2004-08-19 110658]
S2 nSvcLog;ForceWare user log service; C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe [2004-08-19 53318]
S2 vvdsvc;VJVodClientServices; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-11-16 20680]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2007-12-14 654848]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-22 182768]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]
-----------------EOF-----------------