Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

přepsani souboru na připonu ENCODED

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#46 Příspěvek od stell »

:arrow: Zapnut zobrazovanie skrytych systemovych suborov a zloziek.
:arrow: Stiahnes>>OTMoveIt3 by OldTimer >.podla navodu vloz text a klik-Moveit>>log po restarte vloz sem.

Kód: Vybrat vše

:processes
explorer.exe

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění
C:\Documents and Settings\Administrator\Data aplikací\C-76947-8457-2745\wincdrsvn.exe
C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe
C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687\winsrvn.exe
C:\Documents and Settings\ACDC\uddbqt.exe
C:\Documents and Settings\ACDC\Data aplikací\Microsoft\svchost.exe 
C:\DOCUME~1\ACDC\LOCALS~1\Temp\Nl8.exe
C:\DOCUME~1\ACDC\LOCALS~1\Temp\Nlx.exe
C:\Documents and Settings\ACDC\rcq.exe
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"NeroFilterCheck"=-
"svchost"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsDriverControl"=-
"WindowsBootController"=-
"MSNUpdateServices"=-
"MSConfig"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJKUK66HMN]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMH2B46TDP]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^0238idj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^1lmh7jj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^1si8pff.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^3dttpff.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^5u0lwms.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^6tjz272.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^70souvg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^86k81wh.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^86k81wx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^9l0xiid.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^a6grc5yyt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^c5ouvgrmxit.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^cdjz26vwrc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^e1awwrii.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^eafbbc70o6.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^epav0871td.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^eza6qm6c.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^favbhhdt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^fwwriiduupg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ggr1dnyz3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^h0souvgrm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^hioe9vwh.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^id031q7272.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^j9uvl26y.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^jzzva6mm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^kfl66snjzk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^kfvwrx66uk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^m0oojaaq5h1.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^mh03ojp2.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^nj8p61r4.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^nooe3vw0m3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oojaavmc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oojafbbc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk.ENCODED]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^otz2fbm1cd.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oufk86mm1i.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^puvlghhyt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^q70rnii6u.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^r70njzzva3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^rndy5klmxi.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^s5j0pq1g3s.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^snojzqqlrn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^syy5klmxi.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tkkfbbxnnjz.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^to1kggbc70.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tpkk6ww7.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tzuvl26yjj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ufk86mm1i87.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^uu6gg6ss6ee.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^z66q81cn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zal6ccxy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ze870bxns.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zpa1qg0hdd2.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zqqlccxo.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zz3ggbssn.exe]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qvhmbpzl.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\qvhmbpzl.sys]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Documents and Settings\ACDC\Data aplikací\C-76947-8457-2745\wincdrsvn.exe"=-
"C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687\winsrvn.exe"=-
"C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe"=-
"C:\Documents and Settings\Administrator\Data aplikací\C-76947-8457-2745\wincdrsvn.exe"=-
[HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Explorer/Advanced]
"ShowSuperHidden"=dword:00000001 
 
:services
qvhmbpzl

:Commands
[emptytemp]
[EMPTYFLASH]
[start explorer]
[Reboot]
:arrow: klik start-tento pocitac-otvor disk C:\ a preklikaj sa do zlozky C:\Documents and Settings\ACDC\Nabídka Start\Programy\

v zlozke programy klikni v lavo hore na zalozku SUBOR>>NOVY>>ZLOZKA>.a pomenuj ju na Po spuštění [enter]

Potom pokracujeme, liecenie bude dlhe,tazke a bolestive. :James008:
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#47 Příspěvek od JayDee »

stell píše::arrow: Zapnut zobrazovanie skrytych systemovych suborov a zloziek.
:arrow: Stiahnes>>OTMoveIt3 by OldTimer >.podla navodu vloz text a klik-Moveit>>log po restarte vloz sem.

Kód: Vybrat vše

:processes
explorer.exe

:files
C:\WINDOWS\system32\*.tmp.dll /s
C:\WINDOWS\system32\SET*.tmp /s
C:\WINDOWS\*.tmp /s
C:\Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění
C:\Documents and Settings\Administrator\Data aplikací\C-76947-8457-2745\wincdrsvn.exe
C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe
C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687\winsrvn.exe
C:\Documents and Settings\ACDC\uddbqt.exe
C:\Documents and Settings\ACDC\Data aplikací\Microsoft\svchost.exe 
C:\DOCUME~1\ACDC\LOCALS~1\Temp\Nl8.exe
C:\DOCUME~1\ACDC\LOCALS~1\Temp\Nlx.exe
C:\Documents and Settings\ACDC\rcq.exe
:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-
"SunJavaUpdateSched"=-
"NeroFilterCheck"=-
"svchost"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsDriverControl"=-
"WindowsBootController"=-
"MSNUpdateServices"=-
"MSConfig"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJKUK66HMN]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMH2B46TDP]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^0238idj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^1lmh7jj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^1si8pff.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^3dttpff.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^5u0lwms.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^6tjz272.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^70souvg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^86k81wh.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^86k81wx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^9l0xiid.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^a6grc5yyt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^c5ouvgrmxit.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^cdjz26vwrc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^e1awwrii.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^eafbbc70o6.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^epav0871td.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^eza6qm6c.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^favbhhdt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^fwwriiduupg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ggr1dnyz3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^h0souvgrm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^hioe9vwh.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^id031q7272.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^j9uvl26y.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^jzzva6mm.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^kfl66snjzk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^kfvwrx66uk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^m0oojaaq5h1.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^mh03ojp2.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^nj8p61r4.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^nooe3vw0m3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oojaavmc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oojafbbc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk.ENCODED]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^otz2fbm1cd.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oufk86mm1i.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^puvlghhyt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^q70rnii6u.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^r70njzzva3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^rndy5klmxi.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^s5j0pq1g3s.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^snojzqqlrn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^syy5klmxi.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tkkfbbxnnjz.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^to1kggbc70.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tpkk6ww7.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tzuvl26yjj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ufk86mm1i87.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^uu6gg6ss6ee.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^z66q81cn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zal6ccxy.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ze870bxns.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zpa1qg0hdd2.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zqqlccxo.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zz3ggbssn.exe]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qvhmbpzl.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\qvhmbpzl.sys]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Documents and Settings\ACDC\Data aplikací\C-76947-8457-2745\wincdrsvn.exe"=-
"C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687\winsrvn.exe"=-
"C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe"=-
"C:\Documents and Settings\Administrator\Data aplikací\C-76947-8457-2745\wincdrsvn.exe"=-
[HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Explorer/Advanced]
"ShowSuperHidden"=dword:00000001 
 
:services
qvhmbpzl

:Commands
[emptytemp]
[EMPTYFLASH]
[start explorer]
[Reboot]
:arrow: klik start-tento pocitac-otvor disk C:\ a preklikaj sa do zlozky C:\Documents and Settings\ACDC\Nabídka Start\Programy\

v zlozke programy klikni v lavo hore na zalozku SUBOR>>NOVY>>ZLOZKA>.a pomenuj ju na Po spuštění [enter]

Potom pokracujeme, liecenie bude dlhe,tazke a bolestive. :James008:
Posílám log OTM po restartu. Nová složka Po spuštění nešla vytvořit, protože už tam taková složka je.
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\WINDOWS\system32\*.tmp.dll not found.
File/Folder C:\WINDOWS\system32\SET*.tmp not found.
File/Folder C:\WINDOWS\*.tmp not found.
C:\Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění folder moved successfully.
File/Folder C:\Documents and Settings\Administrator\Data aplikací\C-76947-8457-2745\wincdrsvn.exe not found.
File/Folder C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe not found.
File/Folder C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687\winsrvn.exe not found.
File/Folder C:\Documents and Settings\ACDC\uddbqt.exe not found.
File/Folder C:\Documents and Settings\ACDC\Data aplikací\Microsoft\svchost.exe not found.
File/Folder C:\DOCUME~1\ACDC\LOCALS~1\Temp\Nl8.exe not found.
File/Folder C:\DOCUME~1\ACDC\LOCALS~1\Temp\Nlx.exe not found.
File move failed. C:\Documents and Settings\ACDC\rcq.exe scheduled to be moved on reboot.
========== REGISTRY ==========
Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher scheduled to be deleted on reboot.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\svchost deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsDriverControl deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsBootController deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSNUpdateServices deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSConfig deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJKUK66HMN\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMH2B46TDP\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^0238idj.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^1lmh7jj.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^1si8pff.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^3dttpff.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^5u0lwms.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^6tjz272.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^70souvg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^86k81wh.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^86k81wx.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^9l0xiid.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^a6grc5yyt.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^c5ouvgrmxit.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^cdjz26vwrc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^e1awwrii.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^eafbbc70o6.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^epav0871td.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^eza6qm6c.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^favbhhdt.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^fwwriiduupg.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ggr1dnyz3.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^h0souvgrm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^hioe9vwh.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^id031q7272.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^j9uvl26y.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^jzzva6mm.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^kfl66snjzk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^kfvwrx66uk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^llhxxtjjfvv.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^m0oojaaq5h1.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^mh03ojp2.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^nj8p61r4.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^nooe3vw0m3.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oojaavmc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oojafbbc.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^OpenOffice.org 3.0.lnk.ENCODED\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^otz2fbm1cd.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^oufk86mm1i.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^puvlghhyt.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^q70rnii6u.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^r70njzzva3.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^rmm6yy6kk.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^rndy5klmxi.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^s5j0pq1g3s.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^snojzqqlrn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^syy5klmxi.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tkkfbbxnnjz.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^to1kggbc70.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tpkk6ww7.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^tzuvl26yjj.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ufk86mm1i87.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^uu6gg6ss6ee.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^z66q81cn.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zal6ccxy.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^ze870bxns.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zpa1qg0hdd2.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zqqlccxo.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^zz3ggbssn.exe\ deleted successfully.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qvhmbpzl.sys\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\qvhmbpzl.sys\ scheduled to be deleted on reboot.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\ACDC\Data aplikací\C-76947-8457-2745\wincdrsvn.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687\winsrvn.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\Administrator\Data aplikací\C-76947-8457-2745\wincdrsvn.exe deleted successfully.
HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Explorer/Advanced\\"ShowSuperHidden"|dword:00000001 /E :invalid edit format. No such root key.
========== SERVICES/DRIVERS ==========
Error: Unable to stop service qvhmbpzl!
Unable to delete service\driver key qvhmbpzl.
========== COMMANDS ==========

[EMPTYTEMP]

User: ACDC
->Temp folder emptied: 141370676 bytes
->Temporary Internet Files folder emptied: 1533329 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 819568 bytes
->Opera cache emptied: 2630145 bytes
->Flash cache emptied: 2182 bytes

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 131072 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 76549010 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 213,00 mb


OTM by OldTimer - Version 3.1.17.1 log created on 10262010_153540

Files moved on Reboot...
File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qvhmbpzl.sys\ scheduled to be deleted on reboot.
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\qvhmbpzl.sys\ scheduled to be deleted on reboot.

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#48 Příspěvek od stell »

ok, poracuj malwarebytes:
Stiahnes>>mbam-setup
Nainstalovat, aktualizovat, a spustit skan.
Spravit UPLNY skan, co najde daj zmazat,
Log vloz sem.
Podrobny Navod:
http://www.viry.cz/forum/viewtopic.php?f=29&t=67229
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#49 Příspěvek od JayDee »

Přikládám log, při odstranování se ntb zhroutil, ale zase naběhl. Teda, takovýho svinstva jsem ještě neviděl ( jedná se o ntb kamarádky).

Kód: Vybrat vše

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4953

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

26.10.2010 18:55:22
mbam-log-2010-10-26 (18-55-22).txt

Typ skenu: Úplný sken (C:\|)
Skenované objekty: 166744
Uplynulý čas: 1 hodina(y), 39 minuta(y), 7 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 1
Infikované klíče registru: 5
Infikované hodnoty registru: 3
Infikované datové položky registru: 0
Infikované složky: 1
Infikované soubory: 155

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
C:\WINDOWS\system32\cryptnet32.dll (Trojan.Lukicsel) -> No action taken.

Infikované klíče registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\qvhmbpzl (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\IJKUK66HMN (Trojan.FakeAlert) -> No action taken.

Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Worm.Palevo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Worm.Palevo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> No action taken.

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
C:\Documents and Settings\ACDC\Data aplikací\S-3685-5437-5687 (Trojan.Agent) -> No action taken.

Infikované soubory:
C:\WINDOWS\system32\cryptnet32.dll (Trojan.Lukicsel) -> No action taken.
C:\Documents and Settings\ACDC\buwaem.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\ACDC\Data aplikací\juzjf.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\ACDC\Local Settings\Temp\1154.exe (Trojan.Dropper) -> No action taken.
C:\Documents and Settings\ACDC\Local Settings\Temp\1752.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\ACDC\Local Settings\Temp\2868788.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\ACDC\Local Settings\Temp\4484.exe (Trojan.Dropper) -> No action taken.
C:\Documents and Settings\ACDC\Local Settings\Temp\7121808.exe (Trojan.Dropper) -> No action taken.
C:\Documents and Settings\Administrator\Data aplikací\juzjf.exe (Trojan.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-5256703078-5728240555-759657273-8411\yv8g67.exe (Trojan.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-6456158093-2047877126-327473686-7742\yv8g67.exe (Trojan.Agent) -> No action taken.
C:\RECYCLER\S-1-5-21-7735995142-3949916822-877521345-3515\yv8g67.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\Nfesec.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Nfesed.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Nfesee.exe (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\Nfesef.exe (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\Nfeseg.exe (Rootkit.TDSS) -> No action taken.
C:\WINDOWS\system32\drivers\qvhmbpzl.sys (Trojan.Agent) -> No action taken.
C:\WINDOWS\pss\0238idj.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\1lmh7jj.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\1si8pff.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\3dttpff.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\5u0lwms.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\6tjz272.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\70souvg.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\86k81wh.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\86k81wx.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\9l0xiid.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\a6grc5yyt.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\c5ouvgrmxit.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\cdjz26vwrc.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\e1awwrii.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\eafbbc70o6.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\epav0871td.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\vwxnnjzz.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\z66q81cn.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\zal6ccxy.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\ze870bxns.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\zpa1qg0hdd2.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\zqqlccxo.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\zz3ggbssn.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\snojzqqlrn.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\syy5klmxi.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\tkkfbbxnnjz.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\to1kggbc70.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\tpkk6ww7.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\tzuvl26yjj.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\ufk86mm1i87.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\otz2fbm1cd.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\oufk86mm1i.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\puvlghhyt.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\q70rnii6u.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\r70njzzva3.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\rmm6yy6kk.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\rndy5klmxi.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\s5j0pq1g3s.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\kfvwrx66uk.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\llhxxtjjfvv.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\m0oojaaq5h1.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\mh03ojp2.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\nj8p61r4.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\nooe3vw0m3.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\oojaavmc.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\oojafbbc.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\eza6qm6c.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\kfl66snjzk.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\uu6gg6ss6ee.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\favbhhdt.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\fwwriiduupg.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\ggr1dnyz3.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\h0souvgrm.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\hioe9vwh.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\id031q7272.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\j9uvl26y.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\WINDOWS\pss\jzzva6mm.exeStartup (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\uddbqt.exe (Trojan.Agent) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687\winsvnc32.exe (Worm.PushBot) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Data aplikací\Microsoft\svchost.exe (Trojan.Agent) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\favbhhdt.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\mh03ojp2.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\0238idj.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\1lmh7jj.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\1si8pff.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\3dttpff.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\5u0lwms.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\6tjz272.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\70souvg.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\86k81wh.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\86k81wx.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\9l0xiid.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\a6grc5yyt.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\c5ouvgrmxit.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\cdjz26vwrc.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\e1awwrii.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\eafbbc70o6.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\epav0871td.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\eza6qm6c.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\nj8p61r4.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\nooe3vw0m3.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\oojaavmc.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\oojafbbc.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\otz2fbm1cd.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\oufk86mm1i.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\puvlghhyt.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\q70rnii6u.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\r70njzzva3.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\rmm6yy6kk.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\rndy5klmxi.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\s5j0pq1g3s.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\snojzqqlrn.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\syy5klmxi.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\fwwriiduupg.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\ggr1dnyz3.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\h0souvgrm.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\hioe9vwh.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\id031q7272.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\j9uvl26y.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\jzzva6mm.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\kfl66snjzk.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\kfvwrx66uk.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\llhxxtjjfvv.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\m0oojaaq5h1.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\tkkfbbxnnjz.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\to1kggbc70.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\tpkk6ww7.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\tzuvl26yjj.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\ufk86mm1i87.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\uu6gg6ss6ee.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\vwxnnjzz.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\z66q81cn.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\zal6ccxy.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\ze870bxns.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\zpa1qg0hdd2.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\zqqlccxo.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\zz3ggbssn.exe (Trojan.Refroso.Gen) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_DOCUME~1\ACDC\LOCALS~1\Temp\Nl8.exe (Rootkit.TDSS) -> No action taken.
C:\_OTM\MovedFiles\10262010_152816\C_DOCUME~1\ACDC\LOCALS~1\Temp\Nlx.exe (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\ACDC\Data aplikací\wimknrncds.txt (Malware.Trace) -> No action taken.
C:\Documents and Settings\ACDC\Data aplikací\C-76947-8457-2745\wincdrsvn.exe (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\All Users\Data aplikací\common.data (Malware.Trace) -> No action taken.
C:\s.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\crt.dat (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\Drivers\ndisvvan.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\secupdat.dat (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\shimg.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\winrtsnr.txt (Malware.Trace) -> No action taken.
C:\Documents and Settings\ACDC\secupdat.dat (Worm.Autorun) -> No action taken.
C:\Documents and Settings\Administrator\secupdat.dat (Worm.Autorun) -> No action taken.
C:\Documents and Settings\All Users\secupdat.dat (Worm.Autorun) -> No action taken.
C:\Documents and Settings\Default User\secupdat.dat (Worm.Autorun) -> No action taken.
C:\Documents and Settings\LocalService\secupdat.dat (Worm.Autorun) -> No action taken.
C:\Documents and Settings\NetworkService\secupdat.dat (Worm.Autorun) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\secupdat.dat (Worm.Autorun) -> No action taken.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#50 Příspěvek od stell »

tak ani ja som to nevidel ja sa cudujem ze system este neskolaboval,
Zmaz vsetko co Malwarebytes nasiel.
A pokracujes combofixom
PROSIM CITAJTE POZORNE NAVOD!!!,

Použij ComboFix podle tohoto návodu: http://www.bleepingcomputer.com/combofi ... t-combofix
Log znej vloz sem.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#51 Příspěvek od JayDee »

Zkusil jsem vymazat co MBAM našel, pak systém spadnul ale naskočil. Havěť jsem pak našel v karanténě, mám jí odstranit i odtamtud ?

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#52 Příspěvek od stell »

mozes, aj nemusis, no budu tam Rootkity, este pred combofixom zmaz zlozku po spusteni, co som predtym pisal, a hned vytvor novu zlozku a pomenuj ju tak isto, a spust combofix,
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#53 Příspěvek od JayDee »

Posílám log z ComboFix

ComboFix 10-10-26.03 - ACDC 27.10.2010 13:33:12.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.721 [GMT 2:00]
Spuštěný z: c:\documents and settings\ACDC\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\ACDC\buwaem.exe
c:\documents and settings\ACDC\Data aplikací\C-76947-8457-2745
c:\documents and settings\ACDC\Data aplikací\C-76947-8457-2745\wincdrsvn.exe
c:\documents and settings\ACDC\Data aplikací\S-3685-5437-5687
c:\documents and settings\ACDC\Dokumenty\cc_20101026_010448.reg
c:\documents and settings\ACDC\secupdat.dat
c:\documents and settings\Administrator\Data aplikací\C-76947-8457-2745
c:\documents and settings\All Users\Dokumenty\Server\server.dat
C:\s.exe
c:\windows\system32\crt.dat
c:\windows\system32\cryptnet32.dll
c:\windows\system32\secupdat.dat
c:\windows\system32\shimg.dll
c:\windows\system32\winrtsnr.txt
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

c:\windows\system32\Drivers\qvhmbpzl.sys . . . je infikován!! . . . Failed to find a valid replacement.
c:\windows\explorer.exe . . . je infikován!!

c:\windows\system32\winlogon.exe . . . je infikován!!

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS
-------\Service_SSHNAS


((((((((((((((((((((((((( Soubory vytvořené od 2010-09-27 do 2010-10-27 )))))))))))))))))))))))))))))))
.

2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\documents and settings\ACDC\Data aplikací\Malwarebytes
2010-10-26 14:49 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-26 14:49 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-26 13:28 . 2010-10-26 13:28 -------- d-----w- C:\_OTM
2010-10-25 23:59 . 2010-10-25 23:59 -------- d-----w- c:\program files\trend micro
2010-10-25 23:59 . 2010-10-25 23:59 -------- d-----w- C:\rsit
2010-10-25 21:56 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-10-25 21:56 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-10-25 21:56 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-10-25 21:56 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-10-25 21:56 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-10-25 21:56 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-10-25 21:56 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-10-25 21:56 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-10-25 21:56 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-10-25 20:44 . 2010-10-25 20:44 -------- d-----w- c:\documents and settings\Administrator
2010-10-24 09:01 . 2010-10-24 08:56 270336 ----a-w- c:\windows\Nfeseg.exe
2010-10-23 21:26 . 2010-10-23 21:24 270336 ----a-w- c:\windows\Nfesef.exe
2010-10-23 16:36 . 2010-10-23 16:36 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2010-10-23 16:32 . 2010-10-24 20:38 -------- d-----w- c:\documents and settings\ACDC\Local Settings\Data aplikací\Temp
2010-10-23 16:32 . 2010-10-23 16:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2010-10-23 16:28 . 2010-10-23 16:54 -------- d-----w- c:\documents and settings\ACDC\Local Settings\Data aplikací\Google
2010-10-23 16:28 . 2010-10-23 16:50 -------- d-----w- c:\program files\Google
2010-10-23 16:17 . 2010-10-25 21:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2010-10-21 19:27 . 2010-10-26 13:29 -------- d-sh--r- c:\documents and settings\ACDC\Data aplikací\L-77685-67895-5687
2010-10-20 21:33 . 2010-10-20 20:11 237568 ----a-w- c:\windows\Nfesee.exe
2010-10-20 11:25 . 2010-10-20 11:25 40128 ----a-w- c:\windows\system32\drivers\qvhmbpzl.sys
2010-10-20 11:15 . 2010-10-20 11:15 93184 --sh--r- c:\documents and settings\ACDC\Data aplikací\juzjf.exe
2010-10-15 08:03 . 2010-10-15 08:02 200704 ----a-w- c:\windows\Nfesed.exe
2010-10-14 15:35 . 2010-10-14 11:43 204800 ----a-w- c:\windows\Nfesec.exe
2010-10-13 16:46 . 2010-10-13 16:46 88064 ----a-w- C:\amd64.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-17 13:17 . 2008-04-14 06:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
.

------- Sigcheck -------

[-] 2008-04-14 . AEC4B492320965D2C4308F20BEB65F2D . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . 2DEC5A80C8A9F2BD5076540A9813D3CF . 507904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe

[-] 2008-04-14 . 4524604192F0E942F11D37179A7E481D . 1034240 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2008-06-30 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-09-02 13351304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-20 88358]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-02-22 180224]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-02-22 2889216]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-01-11 516096]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 692315]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 77824]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2010-02-07 278264]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-07 1797880]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qvhmbpzl.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^vwxnnjzz.exe]
path=c:\documents and settings\ACDC\Nabídka Start\Programy\Po spuštění\vwxnnjzz.exe
backup=c:\windows\pss\vwxnnjzz.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
c:\documents and settings\ACDC\rcq.exe \u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [25.10.2010 23:56 165584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [7.2.2010 10:33 101776]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.2.2010 10:33 31504]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25.10.2010 23:56 17744]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [8.2.2010 18:58 246520]
S0 qvhmbpzl;qvhmbpzl;c:\windows\system32\drivers\qvhmbpzl.sys [20.10.2010 13:25 40128]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.10.2010 18:28 136176]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\adusbser.sys --> c:\windows\system32\DRIVERS\adusbser.sys [?]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [14.2.2010 20:40 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [22.3.2010 16:55 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [22.3.2010 16:57 38784]
.
Obsah adresáře 'Naplánované úlohy'

2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-23 16:28]

2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-23 16:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = http=127.0.0.1:50370
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
MSConfigStartUp-ICQ - c:\program files\ICQ6.5\ICQ.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-27 13:45
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.0 by Gmer, http://www.gmer.net
Windows 5.1.2600

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8566BEC5]<<
1 ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\Harddisk0\DR0[0x86550AB8]
2 ntkrnlpa[0x804EE130] -> CLASSPNP.SYS[0xF75E7FD7] -> \Device\Harddisk0\DR0[0x86550AB8]
3 CLASSPNP[0xF75E7FD7] -> ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\0000007d[0x865E28A8]
4 ntkrnlpa[0x804EE130] -> ACPI.sys[0xF745E620] -> \Device\0000007d[0x865E28A8]
5 ACPI[0xF745E620] -> ntkrnlpa!IofCallDriver[0x804EE130] -> [0x865E9B00]
[0x8544DDA0] -> IRP_MJ_CREATE -> 0x8566BEC5
6 ntkrnlpa[0x804EE130] -> UNKNOWN[0x8566BEC8] -> [0x865E9B00]
error: Read \Device\Ide\IdePort0 Systém nem??e nalézt uvedený soubor.
kernel: MBR read successfully
detected hooks:
\Device\Ide\IdeDeviceP1T0L0-6 -> \??\IDE#DiskHTS541040G9AT00_________________________MB2OA60A#5&de369e5&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
\Driver\Disk -> CLASSPNP.SYS @ 0xf75ebf28
\Driver\ACPI -> ACPI.sys @ 0xf745ecb8
\Driver\atapi DriverStartIo -> 0x8566BAEA
\Driver\atapi -> atapi.sys @ 0xf73f8852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
SecurityProcedure -> ntkrnlpa.exe @ 0x805791fa
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579014
SecurityProcedure -> ntkrnlpa.exe @ 0x805791fa
user & kernel MBR OK

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(2240)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\acer\eManager\anbmServ.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\windows\AGRSMMSG.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Celkový čas: 2010-10-27 13:51:14 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-27 11:51

Před spuštěním: Volných bajtů: 26 004 647 936
Po spuštění: Volných bajtů: 25 924 337 664

- - End Of File - - 16E58DE869C4070A97B0A65000AA0FE2
[/code]

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#54 Příspěvek od stell »

:arrow: Stiahnite si prosím TDSSKiller a uložte ho na plochu.

2x-klik na TDSSKiller.exe- spustiť aplikáciu, potom na Spustiť kontrolu-klik- Start Scan.
Ak je infikovaný súbor detekovaný, bude predvolená akcia Cure, kliknite na tlačidlo Continue.
Ak podozrivý[suspicious] súbor je detekovaný, bude predvolená akcia Skip, kliknite na Continue.
Môže vás požiadať, aby ste reštartovali počítač na dokončenie procesu. Kliknite na Reboot Now.
Ak nevyžaduje reštart, kliknite na tlačidlo Report. Log súbor by sa mal objaviť. Prosím, skopírujte a vložte obsah súboru tu.
Ak je vyžadované reštartovanie počítača, správa je k dispozícii vo vašom koreňovom adresári (zvyčajne C:\ zložka) vo forme "TDSSKiller. _log.txt". Prosím, skopírujte a vložte obsah súboru tu.

:arrow: Pri tejto akcii je nutné mať ComboFix na ploche.

Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.

Otvor Notepad (Poznámkový blok) a zkopíruj do neho celý zeleny tex:

Kód: Vybrat vše

KILLALL::
Registry::
[-HKLM\~\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštìní^vwxnnjzz.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\qvhmbpzl.sys]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"=-
Rootkit::
c:\documents and settings\ACDC\rcq.exe
c:\windows\system32\drivers\qvhmbpzl.sys 
Driver::
qvhmbpzl
File::
c:\documents and settings\ACDC\Nabídka Start\Programy\Po spuštìní\vwxnnjzz.exe
c:\windows\Nfesee.exe
c:\documents and settings\ACDC\Data aplikací\juzjf.exe
c:\windows\Nfesed.exe
c:\windows\Nfesec.exe
C:\amd64.exe
Folder::
c:\windows\pss
srpeek::
c:\windows\explorer.exe
c:\windows\system32\winlogon.exe
Potom klik na Subor -> Uložiť ako.. .. -> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *všetky súbory
A ulož ho na plochu.> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :
Obrázek

Po skonceni skenu vlož log čo ComboFix vytvorí
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#55 Příspěvek od JayDee »

Vkládám log z TDSSKiller, log z ComboFixu přiložím až bude hotov

2010/10/27 14:46:44.0031 TDSS rootkit removing tool 2.4.5.1 Oct 26 2010 11:28:49
2010/10/27 14:46:44.0031 ================================================================================
2010/10/27 14:46:44.0031 SystemInfo:
2010/10/27 14:46:44.0031
2010/10/27 14:46:44.0031 OS Version: 5.1.2600 ServicePack: 3.0
2010/10/27 14:46:44.0031 Product type: Workstation
2010/10/27 14:46:44.0031 ComputerName: ACER
2010/10/27 14:46:44.0031 UserName: ACDC
2010/10/27 14:46:44.0031 Windows directory: C:\WINDOWS
2010/10/27 14:46:44.0031 System windows directory: C:\WINDOWS
2010/10/27 14:46:44.0031 Processor architecture: Intel x86
2010/10/27 14:46:44.0031 Number of processors: 1
2010/10/27 14:46:44.0031 Page size: 0x1000
2010/10/27 14:46:44.0031 Boot type: Normal boot
2010/10/27 14:46:44.0031 ================================================================================
2010/10/27 14:46:44.0250 Initialize success
2010/10/27 14:46:52.0218 ================================================================================
2010/10/27 14:46:52.0218 Scan started
2010/10/27 14:46:52.0218 Mode: Manual;
2010/10/27 14:46:52.0218 ================================================================================
2010/10/27 14:46:53.0093 Aavmker4 (8d488938e2f7048906f1fbd3af394887) C:\WINDOWS\system32\drivers\Aavmker4.sys
2010/10/27 14:46:53.0187 ACPI (4fe34f1f3126b61fcc6b2043aa8112c9) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2010/10/27 14:46:53.0218 ACPIEC (afdff022a01f0b11c776f0860c3b282f) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
2010/10/27 14:46:53.0328 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2010/10/27 14:46:53.0406 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2010/10/27 14:46:53.0500 AgereSoftModem (c62f5fd87cbc94d6d345c30e8931324c) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
2010/10/27 14:46:53.0859 ALCXWDM (4e0aca5290b2966f24c45250a56c2da1) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2010/10/27 14:46:54.0031 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2010/10/27 14:46:54.0171 aswFsBlk (a0d86b8ac93ef95620420c7a24ac5344) C:\WINDOWS\system32\drivers\aswFsBlk.sys
2010/10/27 14:46:54.0296 aswMon2 (7d880c76a285a41284d862e2d798ec0d) C:\WINDOWS\system32\drivers\aswMon2.sys
2010/10/27 14:46:54.0328 aswRdr (69823954bbd461a73d69774928c9737e) C:\WINDOWS\system32\drivers\aswRdr.sys
2010/10/27 14:46:54.0375 aswSP (7ecc2776638b04553f9a85bd684c3abf) C:\WINDOWS\system32\drivers\aswSP.sys
2010/10/27 14:46:54.0421 aswTdi (095ed820a926aa8189180b305e1bcfc9) C:\WINDOWS\system32\drivers\aswTdi.sys
2010/10/27 14:46:54.0468 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2010/10/27 14:46:54.0515 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2010/10/27 14:46:54.0578 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2010/10/27 14:46:54.0656 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2010/10/27 14:46:54.0734 Axtmvflt (59629edd214c35a01e2527ac3b8a7fb3) C:\WINDOWS\system32\DRIVERS\Axtmvflt.sys
2010/10/27 14:46:54.0765 Axtmvmdm (37e23b1756eca768656097f72c0b458d) C:\WINDOWS\system32\DRIVERS\Axtmvmdm.sys
2010/10/27 14:46:54.0828 Axtmvprt (2c7170be24eacc0b432eb1832fee0ddc) C:\WINDOWS\system32\Drivers\Axtmvprt.sys
2010/10/27 14:46:54.0890 bcm4sbxp (cd4646067cc7dcba1907fa0acf7e3966) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
2010/10/27 14:46:54.0953 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2010/10/27 14:46:55.0125 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys
2010/10/27 14:46:55.0156 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys
2010/10/27 14:46:55.0218 BTHPORT (f338662a6c1fc11dd9508f6dff2c06a2) C:\WINDOWS\system32\Drivers\BTHport.sys
2010/10/27 14:46:55.0281 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys
2010/10/27 14:46:55.0328 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2010/10/27 14:46:55.0390 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2010/10/27 14:46:55.0453 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2010/10/27 14:46:55.0500 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2010/10/27 14:46:55.0593 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
2010/10/27 14:46:55.0656 cmdGuard (932d8df2277be80adcce71e2359f7ceb) C:\WINDOWS\system32\DRIVERS\cmdguard.sys
2010/10/27 14:46:55.0703 cmdHlp (a8add6dee129953763f19fe90a29a929) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
2010/10/27 14:46:55.0859 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
2010/10/27 14:46:55.0968 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2010/10/27 14:46:56.0000 DKbFltr (08d30af92c270f2e76787c81589dbad6) C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
2010/10/27 14:46:56.0125 dmboot (db5fd2bf5b07dc54bfcb3664ff05bd7c) C:\WINDOWS\system32\drivers\dmboot.sys
2010/10/27 14:46:56.0187 dmio (fff1720af51171f32f1ead5cf71f2810) C:\WINDOWS\system32\drivers\dmio.sys
2010/10/27 14:46:56.0234 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2010/10/27 14:46:56.0312 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2010/10/27 14:46:56.0406 DritekPortIO (ccdf6452c754bfa168176e9479f4b283) C:\PROGRA~1\LAUNCH~1\DPortIO.sys
2010/10/27 14:46:56.0562 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2010/10/27 14:46:56.0609 EMSCR (d3d0ef132eb8f7351e0f6e8072e26331) C:\WINDOWS\system32\DRIVERS\EMS7SK.sys
2010/10/27 14:46:56.0671 EpmPsd (d68564fcfbdfc04280cdbbb37cf7ef7f) C:\WINDOWS\system32\drivers\epm-psd.sys
2010/10/27 14:46:56.0703 EpmShd (50425cbd80468bf53ba90f0d7cc61805) C:\WINDOWS\system32\drivers\epm-shd.sys
2010/10/27 14:46:56.0734 ESDCR (a2effc588a8df44f45aa75528c5d2e9c) C:\WINDOWS\system32\DRIVERS\ESD7SK.sys
2010/10/27 14:46:56.0781 ESMCR (f7bdd947074d092cbfebfec9817cc8a0) C:\WINDOWS\system32\DRIVERS\ESM7SK.sys
2010/10/27 14:46:56.0875 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2010/10/27 14:46:56.0921 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
2010/10/27 14:46:56.0968 Fips (ac366695a0796560aa37215ad5762aaf) C:\WINDOWS\system32\drivers\Fips.sys
2010/10/27 14:46:57.0000 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2010/10/27 14:46:57.0046 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
2010/10/27 14:46:57.0203 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2010/10/27 14:46:57.0265 Ftdisk (4e664d8541db4a66b73a24257e322e1f) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2010/10/27 14:46:57.0328 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2010/10/27 14:46:57.0406 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2010/10/27 14:46:57.0500 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
2010/10/27 14:46:57.0609 i8042prt (c528e27945367191e7bae364930b6932) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2010/10/27 14:46:57.0718 ialm (737da0be27652c4482ac5cde099bfce9) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
2010/10/27 14:46:57.0906 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2010/10/27 14:46:58.0000 Inspect (fdca8008bfc7ca72b08151698cd24236) C:\WINDOWS\system32\DRIVERS\inspect.sys
2010/10/27 14:46:58.0031 IntelIde (57d928e548b38502abba7a77a6eb7312) C:\WINDOWS\system32\DRIVERS\intelide.sys
2010/10/27 14:46:58.0062 intelppm (27b290d632af2cf3cf40bfddb7370985) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2010/10/27 14:46:58.0125 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
2010/10/27 14:46:58.0171 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2010/10/27 14:46:58.0203 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2010/10/27 14:46:58.0265 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2010/10/27 14:46:58.0296 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2010/10/27 14:46:58.0375 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
2010/10/27 14:46:58.0421 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2010/10/27 14:46:58.0453 isapnp (cc9f8a2d60aed1a51a3ac34c59b987ae) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2010/10/27 14:46:58.0515 Kbdclass (1b6162fe7f66b1a71a4b70f941c4aa9b) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2010/10/27 14:46:58.0593 kbdhid (86c8f23616c6c6e5b2776901c17b945b) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2010/10/27 14:46:58.0937 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2010/10/27 14:46:59.0265 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
2010/10/27 14:46:59.0406 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2010/10/27 14:46:59.0484 Modem (44032b0c6d9954d3fd26438330b99ee7) C:\WINDOWS\system32\drivers\Modem.sys
2010/10/27 14:46:59.0546 Mouclass (4cb582831dbde63ce43b45d771218374) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2010/10/27 14:46:59.0609 mouhid (bb269eba740737ab749b214d568b6812) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2010/10/27 14:46:59.0656 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2010/10/27 14:46:59.0703 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2010/10/27 14:46:59.0781 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2010/10/27 14:46:59.0875 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2010/10/27 14:46:59.0921 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010/10/27 14:46:59.0968 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010/10/27 14:47:00.0000 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2010/10/27 14:47:00.0046 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2010/10/27 14:47:00.0093 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2010/10/27 14:47:00.0140 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2010/10/27 14:47:00.0203 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2010/10/27 14:47:00.0234 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2010/10/27 14:47:00.0265 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2010/10/27 14:47:00.0296 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2010/10/27 14:47:00.0328 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2010/10/27 14:47:00.0375 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2010/10/27 14:47:00.0468 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2010/10/27 14:47:00.0515 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2010/10/27 14:47:00.0578 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2010/10/27 14:47:00.0703 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2010/10/27 14:47:00.0750 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2010/10/27 14:47:00.0781 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2010/10/27 14:47:00.0828 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2010/10/27 14:47:00.0875 osaio (b270a30ae97524e7edb5eca7b2afb846) C:\WINDOWS\system32\drivers\osaio.sys
2010/10/27 14:47:00.0906 osanbm (3245bee5176697faf0744a2e1288dc77) C:\WINDOWS\system32\drivers\osanbm.sys
2010/10/27 14:47:00.0984 Parport (46f8db73b4a53e543f8e371dc7c75bae) C:\WINDOWS\system32\drivers\Parport.sys
2010/10/27 14:47:01.0031 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2010/10/27 14:47:01.0093 ParVdm (1fae19d0457176318bba4a8795656ebc) C:\WINDOWS\system32\drivers\ParVdm.sys
2010/10/27 14:47:01.0140 PCI (6ce351d149cb4befc702951e471e1730) C:\WINDOWS\system32\DRIVERS\pci.sys
2010/10/27 14:47:01.0187 PCIIde (2da4ec85e0ea7a45c6b2a05820492d5a) C:\WINDOWS\system32\drivers\PCIIde.sys
2010/10/27 14:47:01.0234 Pcmcia (4fc31e6c19a5ce5198b1abff94cae758) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
2010/10/27 14:47:01.0437 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2010/10/27 14:47:01.0468 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2010/10/27 14:47:01.0500 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2010/10/27 14:47:01.0687 qvhmbpzl (380a4fbac7125c2f54bbd95cac2bb72d) C:\WINDOWS\system32\Drivers\qvhmbpzl.sys
2010/10/27 14:47:01.0812 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2010/10/27 14:47:01.0890 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
2010/10/27 14:47:01.0921 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2010/10/27 14:47:01.0953 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2010/10/27 14:47:01.0968 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2010/10/27 14:47:02.0015 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2010/10/27 14:47:02.0078 RDPCDD (d61c538a1f2eac0375dfc7dc0ec3c5a1) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/10/27 14:47:02.0078 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\RDPCDD.sys. Real md5: d61c538a1f2eac0375dfc7dc0ec3c5a1, Fake md5: 4912d5b403614ce99c28420f75353332
2010/10/27 14:47:02.0093 RDPCDD - detected Rootkit.Win32.TDSS.tdl3 (0)
2010/10/27 14:47:02.0218 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2010/10/27 14:47:02.0265 redbook (611bfd220305be3a85ae876ea47d4aa5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2010/10/27 14:47:02.0328 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys
2010/10/27 14:47:02.0421 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
2010/10/27 14:47:02.0468 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2010/10/27 14:47:02.0562 Serial (b842729337c9b921615c40d3c1a1af96) C:\WINDOWS\system32\drivers\Serial.sys
2010/10/27 14:47:02.0625 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2010/10/27 14:47:02.0718 SMCIRDA (a8eb0aa07632a4c936ff6f8eda5bdead) C:\WINDOWS\system32\DRIVERS\smcirda.sys
2010/10/27 14:47:02.0796 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2010/10/27 14:47:02.0875 sr (94610c8653635e4459316a0050d55ce7) C:\WINDOWS\system32\DRIVERS\sr.sys
2010/10/27 14:47:02.0984 Srv (da852e3e0bf1cea75d756f9866241e57) C:\WINDOWS\system32\DRIVERS\srv.sys
2010/10/27 14:47:03.0046 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2010/10/27 14:47:03.0156 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2010/10/27 14:47:03.0312 SynTP (a63401d180863a2cefce51798542ae5f) C:\WINDOWS\system32\DRIVERS\SynTP.sys
2010/10/27 14:47:03.0406 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2010/10/27 14:47:03.0500 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2010/10/27 14:47:03.0593 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2010/10/27 14:47:03.0640 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2010/10/27 14:47:03.0703 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2010/10/27 14:47:03.0828 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2010/10/27 14:47:03.0937 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2010/10/27 14:47:04.0046 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2010/10/27 14:47:04.0156 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2010/10/27 14:47:04.0390 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2010/10/27 14:47:04.0453 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2010/10/27 14:47:04.0500 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2010/10/27 14:47:04.0562 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2010/10/27 14:47:04.0671 VolSnap (28a4b296b47782173c346e376cb374d1) C:\WINDOWS\system32\drivers\VolSnap.sys
2010/10/27 14:47:04.0843 w29n51 (f0608f3b5b6d16f4870e867f9d069b6b) C:\WINDOWS\system32\DRIVERS\w29n51.sys
2010/10/27 14:47:04.0968 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2010/10/27 14:47:05.0125 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2010/10/27 14:47:05.0234 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2010/10/27 14:47:05.0343 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2010/10/27 14:47:05.0390 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2010/10/27 14:47:05.0562 ================================================================================
2010/10/27 14:47:05.0578 Scan finished
2010/10/27 14:47:05.0578 ================================================================================
2010/10/27 14:47:05.0593 Detected object count: 1
2010/10/27 14:47:16.0015 RDPCDD (d61c538a1f2eac0375dfc7dc0ec3c5a1) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2010/10/27 14:47:16.0015 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\RDPCDD.sys. Real md5: d61c538a1f2eac0375dfc7dc0ec3c5a1, Fake md5: 4912d5b403614ce99c28420f75353332
2010/10/27 14:47:17.0718 Backup copy found, using it..
2010/10/27 14:47:17.0734 C:\WINDOWS\system32\DRIVERS\RDPCDD.sys - will be cured after reboot
2010/10/27 14:47:17.0734 Rootkit.Win32.TDSS.tdl3(RDPCDD) - User select action: Cure
2010/10/27 14:47:29.0156 Deinitialize success
[/code]

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#56 Příspěvek od stell »

ok, mal si tam Rootkit.Win32.TDSS.tdl3-Alureon
Nedavaj logy do code.
a potom vloz sem log z combofixu.
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#57 Příspěvek od JayDee »

Rozumím. Tak tady je log z combofixu:


ComboFix 10-10-26.03 - ACDC 27.10.2010 14:58:34.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.700 [GMT 2:00]
Spuštěný z: c:\documents and settings\ACDC\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\ACDC\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

FILE ::
"C:\amd64.exe"
"c:\documents and settings\ACDC\Data aplikací\juzjf.exe"
"c:\documents and settings\ACDC\Nabídka Start\Programy\Po spuštiní\vwxnnjzz.exe"
"c:\windows\Nfesec.exe"
"c:\windows\Nfesed.exe"
"c:\windows\Nfesee.exe"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\amd64.exe
c:\windows\Nfesec.exe
c:\windows\Nfesed.exe
c:\windows\Nfesee.exe

c:\windows\explorer.exe . . . je infikován!!

c:\windows\system32\winlogon.exe . . . je infikován!!

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_QVHMBPZL
-------\Service_qvhmbpzl


((((((((((((((((((((((((( Soubory vytvořené od 2010-09-27 do 2010-10-27 )))))))))))))))))))))))))))))))
.

2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\documents and settings\ACDC\Data aplikací\Malwarebytes
2010-10-26 14:49 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-26 14:49 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-26 13:28 . 2010-10-26 13:28 -------- d-----w- C:\_OTM
2010-10-25 23:59 . 2010-10-25 23:59 -------- d-----w- c:\program files\trend micro
2010-10-25 23:59 . 2010-10-25 23:59 -------- d-----w- C:\rsit
2010-10-25 21:56 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-10-25 21:56 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-10-25 21:56 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-10-25 21:56 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-10-25 21:56 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-10-25 21:56 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-10-25 21:56 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-10-25 21:56 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-10-25 21:56 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-10-25 20:44 . 2010-10-25 20:44 -------- d-----w- c:\documents and settings\Administrator
2010-10-24 09:01 . 2010-10-24 08:56 270336 ----a-w- c:\windows\Nfeseg.exe
2010-10-23 21:26 . 2010-10-23 21:24 270336 ----a-w- c:\windows\Nfesef.exe
2010-10-23 16:36 . 2010-10-23 16:36 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2010-10-23 16:32 . 2010-10-24 20:38 -------- d-----w- c:\documents and settings\ACDC\Local Settings\Data aplikací\Temp
2010-10-23 16:32 . 2010-10-23 16:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2010-10-23 16:28 . 2010-10-23 16:54 -------- d-----w- c:\documents and settings\ACDC\Local Settings\Data aplikací\Google
2010-10-23 16:28 . 2010-10-23 16:50 -------- d-----w- c:\program files\Google
2010-10-23 16:17 . 2010-10-25 21:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2010-10-21 19:27 . 2010-10-26 13:29 -------- d-sh--r- c:\documents and settings\ACDC\Data aplikací\L-77685-67895-5687
2010-10-20 11:25 . 2010-10-20 11:25 40128 ----a-w- c:\windows\system32\drivers\qvhmbpzl.sys
2010-10-20 11:15 . 2010-10-20 11:15 93184 --sh--r- c:\documents and settings\ACDC\Data aplikací\juzjf.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-27 12:47 . 2006-03-02 12:00 4224 ----a-w- c:\windows\system32\drivers\rdpcdd.sys
2010-08-17 13:17 . 2008-04-14 06:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))

c:\windows\system32\dllcache\explorer.exe [x]
[-] 4524604192F0E942F11D37179A7E481D 1034240 \RP1\A0000054.exe
.
------- Sigcheck -------

[-] 2008-04-14 . AEC4B492320965D2C4308F20BEB65F2D . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . 2DEC5A80C8A9F2BD5076540A9813D3CF . 507904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe

[-] 2008-04-14 . 4524604192F0E942F11D37179A7E481D . 1034240 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2008-06-30 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-10-27_11.45.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-27 13:09 . 2010-10-27 13:09 16384 c:\windows\temp\Perflib_Perfdata_734.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-09-02 13351304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-20 88358]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-02-22 180224]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-02-22 2889216]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-01-11 516096]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 692315]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 77824]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2010-02-07 278264]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-07 1797880]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^vwxnnjzz.exe]
path=c:\documents and settings\ACDC\Nabídka Start\Programy\Po spuštění\vwxnnjzz.exe
backup=c:\windows\pss\vwxnnjzz.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [25.10.2010 23:56 165584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [7.2.2010 10:33 101776]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.2.2010 10:33 31504]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25.10.2010 23:56 17744]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [8.2.2010 18:58 246520]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.10.2010 18:28 136176]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\adusbser.sys --> c:\windows\system32\DRIVERS\adusbser.sys [?]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [14.2.2010 20:40 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [22.3.2010 16:55 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [22.3.2010 16:57 38784]
.
Obsah adresáře 'Naplánované úlohy'

2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-23 16:28]

2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-23 16:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uInternet Settings,ProxyServer = http=127.0.0.1:50370
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-27 15:09
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(3904)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\acer\eManager\anbmServ.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rundll32.exe
c:\windows\AGRSMMSG.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Celkový čas: 2010-10-27 15:13:15 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-27 13:13
ComboFix2.txt 2010-10-27 11:51

Před spuštěním: Volných bajtů: 25 872 183 296
Po spuštění: Volných bajtů: 25 867 153 408

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 0038F38FAF6A7109F097D61271A78392

Uživatelský avatar
stell
VIP in memoriam
VIP in memoriam
Příspěvky: 5175
Registrován: 09 pro 2007 09:27
Bydliště: SK-REVUCA
Kontaktovat uživatele:

Re: přepsani souboru na připonu ENCODED

#58 Příspěvek od stell »

Pri tejto akcii je nutné mať ComboFix na ploche.

Vypni>FIREWALL>Antivir>Antispyware>vsetko rezidentne.

Otvor Notepad (Poznámkový blok) a zkopíruj do neho celý zeleny tex:

Kód: Vybrat vše

KILLALL::
File::
c:\windows\Nfeseg.exe
c:\windows\Nfesef.exe
c:\windows\system32\drivers\qvhmbpzl.sys
c:\documents and settings\ACDC\Data aplikací\juzjf.exe
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštìní^vwxnnjzz.exe]
DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:50370
Potom klik na Subor -> Uložiť ako.. .. -> Ako je Názov souboru tak do toho riadku napiš:CFScript.txt
Typ súboru tak tam vyberies *všetky súbory
A ulož ho na plochu.> Pozor CFScript.txt>Neotvarat a nemoze byt ani>CFScript.txt.txt A Urobis Toto :
Obrázek

Po skonceni skenu vlož log čo ComboFix vytvorí

:arrow: Stahni OTListIt2>> OTL
- spust
-zafajkni
-Scan all users.
-Lop check.
-Purity check.
-v sekciiExtra Registry>zaboduj>Use SafeList
-do okna Custom Scans/Fixes>vloz zeleny text a klik Run SCAN
-scan trva [10-15 min]>.potom vloz sem
-OTL.txt (bude na ploche).
-Extras.txt [bude dole na hlavnom panely]

Kód: Vybrat vše

msconfig
safebootminimal
activex
drivers32
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90
Dôležité informácie.
NEŠLAPE Vám počítač?
Je zavirovaný? Šlape pomalu? Nefunguje program? Problém s instalací?
Využíjte služby vzdálené pomoci!
Obrázek
e-mail: stell(zavináč)forum.viry.cz
Thanks! Vďaka!

Obrázek

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#59 Příspěvek od JayDee »

Log z combofixu:


ComboFix 10-10-26.03 - ACDC 27.10.2010 15:46:20.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.682 [GMT 2:00]
Spuštěný z: c:\documents and settings\ACDC\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\ACDC\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

FILE ::
"c:\documents and settings\ACDC\Data aplikací\juzjf.exe"
"c:\windows\Nfesef.exe"
"c:\windows\Nfeseg.exe"
"c:\windows\system32\drivers\qvhmbpzl.sys"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Nfesef.exe
c:\windows\Nfeseg.exe
c:\windows\system32\drivers\qvhmbpzl.sys

c:\windows\system32\winlogon.exe . . . je infikován!!

c:\windows\explorer.exe . . . je infikován!!

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-27 do 2010-10-27 )))))))))))))))))))))))))))))))
.

2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\documents and settings\ACDC\Data aplikací\Malwarebytes
2010-10-26 14:49 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-26 14:49 . 2010-10-26 14:49 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Malwarebytes
2010-10-26 14:49 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-26 13:28 . 2010-10-26 13:28 -------- d-----w- C:\_OTM
2010-10-25 23:59 . 2010-10-25 23:59 -------- d-----w- c:\program files\trend micro
2010-10-25 23:59 . 2010-10-25 23:59 -------- d-----w- C:\rsit
2010-10-25 21:56 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-10-25 21:56 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-10-25 21:56 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-10-25 21:56 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-10-25 21:56 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-10-25 21:56 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-10-25 21:56 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-10-25 21:56 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-10-25 21:56 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-10-25 20:44 . 2010-10-25 20:44 -------- d-----w- c:\documents and settings\Administrator
2010-10-23 16:36 . 2010-10-23 16:36 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Data aplikací\Google
2010-10-23 16:32 . 2010-10-24 20:38 -------- d-----w- c:\documents and settings\ACDC\Local Settings\Data aplikací\Temp
2010-10-23 16:32 . 2010-10-23 16:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Data aplikací\Google
2010-10-23 16:28 . 2010-10-23 16:54 -------- d-----w- c:\documents and settings\ACDC\Local Settings\Data aplikací\Google
2010-10-23 16:28 . 2010-10-23 16:50 -------- d-----w- c:\program files\Google
2010-10-23 16:17 . 2010-10-25 21:55 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Alwil Software
2010-10-21 19:27 . 2010-10-26 13:29 -------- d-sh--r- c:\documents and settings\ACDC\Data aplikací\L-77685-67895-5687
2010-10-20 11:15 . 2010-10-20 11:15 93184 --sh--r- c:\documents and settings\ACDC\Data aplikací\juzjf.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-27 12:47 . 2006-03-02 12:00 4224 ----a-w- c:\windows\system32\drivers\rdpcdd.sys
2010-08-17 13:17 . 2008-04-14 06:52 58880 ----a-w- c:\windows\system32\spoolsv.exe
.

------- Sigcheck -------

[-] 2008-04-14 . AEC4B492320965D2C4308F20BEB65F2D . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . 2DEC5A80C8A9F2BD5076540A9813D3CF . 507904 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\winlogon.exe

[-] 2008-04-14 . 4524604192F0E942F11D37179A7E481D . 1034240 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2008-06-30 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-10-27_11.45.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-27 13:52 . 2010-10-27 13:52 16384 c:\windows\temp\Perflib_Perfdata_49c.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-09-02 13351304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"AGRSMMSG"="AGRSMMSG.exe" [2004-12-20 88358]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-02-22 180224]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-02-22 2889216]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-01-11 516096]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 692315]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 77824]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2010-02-07 278264]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-07 1797880]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^vwxnnjzz.exe]
path=c:\documents and settings\ACDC\Nabídka Start\Programy\Po spuštění\vwxnnjzz.exe
backup=c:\windows\pss\vwxnnjzz.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ7.2\\ICQ.exe"=
"c:\\Program Files\\ICQ7.2\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [25.10.2010 23:56 165584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [7.2.2010 10:33 101776]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [7.2.2010 10:33 31504]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [25.10.2010 23:56 17744]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [8.2.2010 18:58 246520]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [23.10.2010 18:28 136176]
S3 adusbser;AnyDATA USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\adusbser.sys --> c:\windows\system32\DRIVERS\adusbser.sys [?]
S3 Axtmvflt;Axesstel USB Filter Service;c:\windows\system32\drivers\Axtmvflt.sys [14.2.2010 20:40 3456]
S3 Axtmvmdm;Axesstel USB Modem;c:\windows\system32\drivers\Axtmvmdm.sys [22.3.2010 16:55 40064]
S3 Axtmvprt;Axesstel Diagnostic Port;c:\windows\system32\drivers\Axtmvprt.sys [22.3.2010 16:57 38784]
.
Obsah adresáře 'Naplánované úlohy'

2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-23 16:28]

2010-10-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-23 16:28]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-27 15:52
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(2324)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\acer\eManager\anbmServ.exe
c:\windows\system32\rundll32.exe
c:\windows\AGRSMMSG.exe
c:\windows\SOUNDMAN.EXE
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Skype\Plugin Manager\SkypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-10-27 15:56:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-27 13:56
ComboFix2.txt 2010-10-27 13:13
ComboFix3.txt 2010-10-27 11:51

Před spuštěním: Volných bajtů: 25 873 584 128
Po spuštění: Volných bajtů: 25 861 009 408

- - End Of File - - 8B97C3F9C2FD34639EB3E5D7DC1D7AAE

JayDee
Návštěvník
Návštěvník
Příspěvky: 30
Registrován: 20 dub 2009 09:41

Re: přepsani souboru na připonu ENCODED

#60 Příspěvek od JayDee »

OTL log:


OTL logfile created on: 27.10.2010 16:01:59 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\ACDC\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 015,00 Mb Total Physical Memory | 622,00 Mb Available Physical Memory | 61,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,25 Gb Total Space | 24,11 Gb Free Space | 64,71% Space Free | Partition Type: NTFS

Computer Name: ACER | User Name: ACDC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010.10.27 15:40:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ACDC\Plocha\OTL.exe
PRC - [2010.09.07 17:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.09.07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.06.02 16:58:20 | 000,246,520 | ---- | M] () -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe
PRC - [2010.02.07 10:33:39 | 000,278,264 | ---- | M] (COMODO) -- C:\Program Files\COMODO\SafeSurf\cssurf.exe
PRC - [2010.02.07 10:33:12 | 000,618,232 | ---- | M] () -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.05.16 10:27:38 | 001,209,904 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
PRC - [2007.05.16 10:27:16 | 000,153,136 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2007.01.11 03:32:12 | 000,516,096 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2005.02.22 19:52:04 | 000,180,224 | ---- | M] (Acer Inc) -- C:\Acer\ePM\EPM-DM.exe
PRC - [2005.01.23 05:36:18 | 000,106,496 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\igfxext.exe
PRC - [2005.01.08 03:17:16 | 000,102,491 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2004.12.01 11:54:22 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2004.08.16 16:17:20 | 001,287,168 | ---- | M] (OSA Technologies Inc.) -- C:\Acer\eManager\anbmServ.exe


========== Modules (SafeList) ==========

MOD - [2010.10.27 15:40:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ACDC\Plocha\OTL.exe
MOD - [2005.01.08 03:17:08 | 000,069,723 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\SynTPFcs.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010.09.07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.09.07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.09.07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010.06.02 16:58:20 | 000,246,520 | ---- | M] () [Auto | Running] -- C:\Program Files\ICQ6Toolbar\ICQ Service.exe -- (ICQ Service)
SRV - [2010.02.07 10:33:12 | 000,618,232 | ---- | M] () [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2004.08.16 16:17:20 | 001,287,168 | ---- | M] (OSA Technologies Inc.) [Auto | Running] -- C:\Acer\eManager\anbmServ.exe -- (anbmService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\adusbser.sys -- (adusbser)
DRV - [2010.09.07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010.09.07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010.09.07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010.09.07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010.09.07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010.09.07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010.02.07 10:33:13 | 000,101,776 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdguard.sys -- (cmdGuard)
DRV - [2010.02.07 10:33:13 | 000,079,504 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2010.02.07 10:33:13 | 000,031,504 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2008.01.07 23:36:15 | 002,216,064 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\w29n51.sys -- (w29n51) Intel(R)
DRV - [2007.03.26 16:25:50 | 000,038,784 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Axtmvprt.sys -- (Axtmvprt)
DRV - [2007.03.26 16:25:30 | 000,040,064 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Axtmvmdm.sys -- (Axtmvmdm)
DRV - [2007.03.22 18:36:38 | 000,003,456 | ---- | M] (Axesstel) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Axtmvflt.sys -- (Axtmvflt)
DRV - [2007.01.30 12:12:06 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005.03.04 17:37:26 | 000,008,704 | ---- | M] (Avocent/OSA Technologies Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osaio.sys -- (osaio)
DRV - [2005.02.21 15:05:46 | 000,036,992 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESD7SK.sys -- (ESDCR)
DRV - [2005.01.26 12:41:50 | 000,330,368 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ESM7SK.sys -- (ESMCR)
DRV - [2005.01.14 16:57:16 | 000,004,010 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\osanbm.sys -- (osanbm)
DRV - [2005.01.13 11:04:18 | 000,057,984 | ---- | M] (ENE Technology Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\EMS7SK.sys -- (EMSCR)
DRV - [2005.01.08 03:03:42 | 000,191,456 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005.01.03 12:51:22 | 000,078,208 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-shd.sys -- (EpmShd)
DRV - [2004.12.20 10:10:00 | 001,271,463 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2004.12.14 23:22:08 | 000,010,240 | ---- | M] (Dritek System Inc.) [Kernel | Disabled | Running] -- C:\Program Files\Launch Manager\DPortIO.sys -- (DritekPortIO)
DRV - [2004.12.07 23:10:00 | 000,016,896 | ---- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\DKbFltr.SYS -- (DKbFltr)
DRV - [2004.12.01 16:40:08 | 002,300,928 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004.07.19 14:10:00 | 000,004,096 | ---- | M] (Acer Value Labs, USA) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\epm-psd.sys -- (EpmPsd)
DRV - [2004.06.16 12:19:58 | 000,046,080 | ---- | M] (SMSC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)


IE - HKU\.DEFAULT\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-682003330-776561741-1606980848-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
IE - HKU\S-1-5-21-682003330-776561741-1606980848-1004\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKU\S-1-5-21-682003330-776561741-1606980848-1004\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKU\S-1-5-21-682003330-776561741-1606980848-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010.02.07 10:33:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ACDC\Data aplikací\Mozilla\Firefox\extensions
[2010.02.07 10:33:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\ACDC\Data aplikací\Mozilla\Firefox\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}

O1 HOSTS File: ([2010.10.27 15:51:55 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ()
O4 - HKLM..\Run: [COMODO SafeSurf] C:\Program Files\COMODO\SafeSurf\cssurf.exe (COMODO)
O4 - HKLM..\Run: [EPM-DM] c:\Acer\ePM\EPM-DM.exe (Acer Inc)
O4 - HKLM..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe (Acer Value Labs, Taiwan)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKU\S-1-5-21-682003330-776561741-1606980848-1004..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-682003330-776561741-1606980848-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-682003330-776561741-1606980848-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-682003330-776561741-1606980848-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-682003330-776561741-1606980848-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O9 - Extra 'Tools' menuitem : ICQ7.2 - {72EFBFE4-C74F-4187-AEFD-73EA3BE968D6} - C:\Program Files\ICQ7.2\ICQ.exe (ICQ, LLC.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (Aktuální domovská stránka) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\ACDC\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\ACDC\Local Settings\Data aplikací\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010.01.23 19:09:05 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

MsConfig - StartUpFolder: C:^Documents and Settings^ACDC^Nabídka Start^Programy^Po spuštění^vwxnnjzz.exe - C:\Documents and Settings\ACDC\Nabídka Start\Programy\Po spuštění\vwxnnjzz.exe - File not found
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2

SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vykreslování vektorové grafiky (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Datové vazby jazyka DHTML pro jazyk Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Vylepšené vytváření obsahu
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - Třídy DirectAnimation jazyka Java
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.7
ActiveX: {5056b317-8d4c-43ee-8543-b9d1e234b8f4} - Aktualizace zabezpečení systému Windows XP (KB923789)
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7131646D-CD3C-40F4-97B9-CD9E4E6262EF} - .NET Framework
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {ACC563BC-4266-43f0-B6ED-9D38C4202C7E} -
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Plánovač úloh
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010.10.27 15:54:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010.10.27 15:50:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010.10.27 15:43:50 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ACDC\Plocha\OTL.exe
[2010.10.27 14:56:14 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010.10.27 14:46:17 | 001,317,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\ACDC\Plocha\tdsskiller.exe
[2010.10.27 13:26:45 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010.10.27 13:26:45 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010.10.27 13:26:45 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010.10.27 13:26:45 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010.10.27 13:26:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010.10.26 20:03:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010.10.26 16:49:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ACDC\Data aplikací\Malwarebytes
[2010.10.26 16:49:04 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010.10.26 16:49:02 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010.10.26 16:49:02 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010.10.26 16:49:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Malwarebytes
[2010.10.26 16:22:15 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\ACDC\Plocha\mbam-setup-1.46.exe
[2010.10.26 15:28:16 | 000,000,000 | ---D | C] -- C:\_OTM
[2010.10.26 11:23:37 | 000,519,168 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\ACDC\Plocha\OTM.exe
[2010.10.26 01:59:17 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2010.10.26 01:59:16 | 000,000,000 | ---D | C] -- C:\rsit
[2010.10.26 01:03:42 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\ACDC\Recent
[2010.10.25 23:56:43 | 000,017,744 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010.10.25 23:56:42 | 000,165,584 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2010.10.25 23:56:40 | 000,023,376 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2010.10.25 23:56:38 | 000,046,672 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2010.10.25 23:56:36 | 000,100,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2010.10.25 23:56:36 | 000,094,544 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2010.10.25 23:56:35 | 000,028,880 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2010.10.25 23:56:06 | 000,038,848 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2010.10.25 23:56:05 | 000,167,592 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2010.10.25 22:55:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010.10.23 18:36:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Data aplikací\Google
[2010.10.23 18:32:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ACDC\Local Settings\Data aplikací\Temp
[2010.10.23 18:32:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Data aplikací\Google
[2010.10.23 18:28:19 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2010.10.23 18:28:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\ACDC\Local Settings\Data aplikací\Google
[2010.10.23 18:17:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.10.21 21:27:46 | 000,000,000 | RHSD | C] -- C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687
[2010.10.20 19:33:00 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Dokumenty\Server

========== Files - Modified Within 30 Days ==========

[2010.10.27 15:52:00 | 000,000,932 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.10.27 15:51:55 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010.10.27 15:51:49 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.10.27 15:51:46 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.10.27 15:51:44 | 1064,812,544 | -HS- | M] () -- C:\hiberfil.sys
[2010.10.27 15:45:05 | 000,000,936 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.10.27 15:40:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ACDC\Plocha\OTL.exe
[2010.10.27 14:56:22 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2010.10.27 14:42:28 | 001,317,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\ACDC\Plocha\tdsskiller.exe
[2010.10.27 10:25:15 | 003,887,256 | R--- | M] () -- C:\Documents and Settings\ACDC\Plocha\ComboFix.exe
[2010.10.26 16:49:07 | 000,000,702 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.10.26 16:18:17 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\ACDC\Plocha\mbam-setup-1.46.exe
[2010.10.26 11:03:48 | 000,519,168 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\ACDC\Plocha\OTM.exe
[2010.10.26 02:30:22 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010.10.26 01:15:48 | 000,000,544 | -H-- | M] () -- C:\Documents and Settings\All Users\Data aplikací\common.data
[2010.10.26 01:02:34 | 000,000,862 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Comodo Personal Firewall.lnk
[2010.10.26 01:01:35 | 000,000,881 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Adobe Acrobat Reader 9.lnk
[2010.10.26 01:00:24 | 000,000,841 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Open Office 3.lnk
[2010.10.26 00:57:21 | 000,000,644 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Opera.lnk
[2010.10.26 00:56:45 | 000,000,728 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Skype.lnk
[2010.10.26 00:56:16 | 000,000,937 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Nero Start Smart.lnk
[2010.10.26 00:55:09 | 000,000,772 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Windows Media Player.lnk
[2010.10.26 00:39:03 | 000,000,641 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\ICQ 7.2.lnk
[2010.10.26 00:38:21 | 000,000,751 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Internet Explorer.lnk
[2010.10.26 00:36:48 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\CCleaner.lnk
[2010.10.26 00:22:42 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010.10.25 23:56:43 | 000,001,706 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2010.10.25 23:56:37 | 000,002,553 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010.10.25 22:16:10 | 000,079,872 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010.10.24 00:30:51 | 043,449,808 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\setup_av_free_cze.exe
[2010.10.23 18:52:40 | 000,001,819 | ---- | M] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2010.10.23 18:17:14 | 055,085,336 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\setup_av_free.exe
[2010.10.23 18:17:14 | 055,085,336 | ---- | M] () -- C:\Documents and Settings\ACDC\Dokumenty\setup_av_free.exe
[2010.10.23 17:35:54 | 000,000,156 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2010.10.21 23:09:53 | 000,026,684 | ---- | M] () -- C:\WINDOWS\Řeka Sumida.bmp.ENCODED
[2010.10.21 23:09:53 | 000,026,586 | ---- | M] () -- C:\WINDOWS\Zelený kámen.bmp.ENCODED
[2010.10.21 23:09:53 | 000,017,066 | ---- | M] () -- C:\WINDOWS\Zrnko kávy.bmp.ENCODED
[2010.10.21 23:09:53 | 000,009,526 | ---- | M] () -- C:\WINDOWS\Zapotec.bmp.ENCODED
[2010.10.21 23:09:52 | 002,359,354 | ---- | M] () -- C:\WINDOWS\Windows XP XII.BMP.ENCODED
[2010.10.21 23:09:52 | 000,048,684 | -HS- | M] () -- C:\WINDOWS\winnt256.bmp.ENCODED
[2010.10.21 23:09:52 | 000,048,684 | -HS- | M] () -- C:\WINDOWS\winnt.bmp.ENCODED
[2010.10.21 23:09:27 | 000,016,734 | ---- | M] () -- C:\WINDOWS\Textura peří.bmp.ENCODED
[2010.10.21 23:09:19 | 000,240,124 | ---- | M] () -- C:\WINDOWS\System32\setup.bmp.ENCODED
[2010.10.21 23:04:53 | 000,017,366 | ---- | M] () -- C:\WINDOWS\Rododendron.bmp.ENCODED
[2010.10.21 23:04:52 | 000,065,958 | ---- | M] () -- C:\WINDOWS\Prérijní vítr.bmp.ENCODED
[2010.10.21 23:04:29 | 000,065,982 | ---- | M] () -- C:\WINDOWS\Mýdlové bubliny.bmp.ENCODED
[2010.10.21 23:04:29 | 000,065,836 | ---- | M] () -- C:\WINDOWS\Omítka Santa Fe.bmp.ENCODED
[2010.10.21 23:04:29 | 000,017,340 | ---- | M] () -- C:\WINDOWS\Na rybách.bmp.ENCODED
[2010.10.21 23:04:29 | 000,001,276 | ---- | M] () -- C:\WINDOWS\Modrá krajka 16.bmp.ENCODED
[2010.10.21 23:04:21 | 000,082,948 | ---- | M] () -- C:\WINDOWS\clock.avi.ENCODED
[2010.10.21 22:54:21 | 014,305,041 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Michael Jackson - Satisfy You.mp3
[2010.10.21 22:54:11 | 002,998,070 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\Gipsy-Vaclav_pre petru zos z stretavi.mp3
[2010.10.21 22:36:30 | 003,992,425 | ---- | M] () -- C:\Documents and Settings\ACDC\Plocha\copycatz - infinity.mp3
[2010.10.21 22:28:04 | 000,240,617 | ---- | M] () -- C:\Documents and Settings\ACDC\Dokumenty\26082010191.jpg.ENCODED
[2010.10.21 22:28:04 | 000,203,608 | ---- | M] () -- C:\Documents and Settings\ACDC\Dokumenty\26082010190.jpg.ENCODED
[2010.10.20 13:15:42 | 000,093,184 | RHS- | M] () -- C:\Documents and Settings\ACDC\Data aplikací\juzjf.exe
[2010.10.16 13:20:32 | 000,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010.10.08 01:47:07 | 000,432,690 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.10.08 01:47:07 | 000,429,262 | ---- | M] () -- C:\WINDOWS\System32\perfh005.dat
[2010.10.08 01:47:07 | 000,078,250 | ---- | M] () -- C:\WINDOWS\System32\perfc005.dat
[2010.10.08 01:47:07 | 000,067,646 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2010.10.27 14:56:22 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010.10.27 14:56:17 | 000,261,312 | RHS- | C] () -- C:\cmldr
[2010.10.27 13:26:45 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010.10.27 13:26:45 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010.10.27 13:26:45 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010.10.27 13:26:45 | 000,079,872 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010.10.27 13:26:45 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010.10.27 13:23:49 | 003,887,256 | R--- | C] () -- C:\Documents and Settings\ACDC\Plocha\ComboFix.exe
[2010.10.26 16:49:07 | 000,000,702 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Malwarebytes' Anti-Malware.lnk
[2010.10.26 01:10:52 | 000,000,544 | -H-- | C] () -- C:\Documents and Settings\All Users\Data aplikací\common.data
[2010.10.26 01:01:56 | 000,000,862 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Comodo Personal Firewall.lnk
[2010.10.26 00:58:41 | 000,000,881 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Adobe Acrobat Reader 9.lnk
[2010.10.26 00:58:41 | 000,000,841 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Open Office 3.lnk
[2010.10.26 00:54:39 | 000,000,937 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Nero Start Smart.lnk
[2010.10.26 00:54:39 | 000,000,772 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Windows Media Player.lnk
[2010.10.26 00:54:39 | 000,000,728 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Skype.lnk
[2010.10.26 00:54:39 | 000,000,644 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Opera.lnk
[2010.10.26 00:38:40 | 000,000,641 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\ICQ 7.2.lnk
[2010.10.26 00:37:41 | 000,000,751 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\Internet Explorer.lnk
[2010.10.26 00:36:23 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\CCleaner.lnk
[2010.10.25 23:56:43 | 000,001,706 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\avast! Free Antivirus.lnk
[2010.10.25 22:49:30 | 1064,812,544 | -HS- | C] () -- C:\hiberfil.sys
[2010.10.24 00:29:51 | 043,449,808 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\setup_av_free_cze.exe
[2010.10.23 23:57:26 | 055,085,336 | ---- | C] () -- C:\Documents and Settings\ACDC\Dokumenty\setup_av_free.exe
[2010.10.23 18:52:40 | 000,001,819 | ---- | C] () -- C:\Documents and Settings\All Users\Plocha\Google Chrome.lnk
[2010.10.23 18:31:53 | 000,000,936 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010.10.23 18:31:51 | 000,000,932 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010.10.23 18:16:29 | 055,085,336 | ---- | C] () -- C:\Documents and Settings\ACDC\Plocha\setup_av_free.exe
[2010.10.23 17:37:18 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\ACDC\Data aplikací\wimk888h.txt
[2010.10.21 21:38:43 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\ACDC\Data aplikací\wimk888h.txt.ENCODED
[2010.10.20 14:32:14 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\ACDC\Data aplikací\wimknrncds.txt
[2010.10.20 13:15:45 | 000,093,184 | RHS- | C] () -- C:\Documents and Settings\ACDC\Data aplikací\juzjf.exe
[2010.10.16 13:20:32 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010.03.22 17:15:13 | 000,000,156 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010.02.07 13:29:49 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010.02.07 10:33:16 | 000,147,192 | ---- | C] () -- C:\WINDOWS\System32\guard32.dll
[2010.01.23 19:57:15 | 000,004,249 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010.01.23 19:47:57 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2010.01.23 19:47:56 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2010.01.23 19:30:24 | 000,356,352 | ---- | C] () -- C:\WINDOWS\EMCRI.dll
[2010.01.23 19:19:07 | 000,016,896 | ---- | C] () -- C:\Documents and Settings\ACDC\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2010.10.22 00:30:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ACDC\Data aplikací\ICQ
[2010.10.26 15:29:10 | 000,000,000 | RHSD | M] -- C:\Documents and Settings\ACDC\Data aplikací\L-77685-67895-5687
[2010.01.23 20:25:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ACDC\Data aplikací\OpenOffice.org
[2010.01.29 19:46:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\ACDC\Data aplikací\Opera
[2010.10.25 23:55:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
[2010.07.01 11:42:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\ICQ
[2010.02.07 10:57:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Data aplikací\Temp

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2008.04.14 08:52:24 | 001,034,240 | ---- | M] (Microsoft Corporation) MD5=4524604192F0E942F11D37179A7E481D -- C:\WINDOWS\explorer.exe

< MD5 for: WINLOGON.EXE >
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=2DEC5A80C8A9F2BD5076540A9813D3CF -- C:\WINDOWS\system32\dllcache\winlogon.exe
[2008.04.14 08:52:54 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=AEC4B492320965D2C4308F20BEB65F2D -- C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2010.01.23 19:55:01 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2010.01.23 19:55:01 | 001,069,056 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2010.01.23 19:55:01 | 000,487,424 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010.09.07 16:46:51 | 000,028,880 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aavmker4.sys
[2010.09.07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys
[2010.09.07 16:47:16 | 000,094,544 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswmon.sys
[2010.09.07 16:47:19 | 000,100,176 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswmon2.sys
[2010.09.07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswRdr.sys
[2010.09.07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswSP.sys
[2010.09.07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) -- C:\WINDOWS\system32\drivers\aswTdi.sys
[2010.10.27 14:47:58 | 000,004,224 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\rdpcdd.sys

< End of report >


Extras log:

OTL Extras logfile created on: 27.10.2010 16:01:59 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\ACDC\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy

1 015,00 Mb Total Physical Memory | 622,00 Mb Available Physical Memory | 61,00% Memory free
2,00 Gb Paging File | 2,00 Gb Available in Paging File | 88,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37,25 Gb Total Space | 24,11 Gb Free Space | 64,71% Space Free | Partition Type: NTFS

Computer Name: ACER | User Name: ACDC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-682003330-776561741-1606980848-1004\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
https [open] -- "C:\Program Files\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.)
"C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java(TM) 6 Update 17
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePowerManagement
"{6CDC748B-47B0-45EB-B740-681E8429F7F9}" = Opera 10.01
"{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2
"{827289F5-B44F-4E49-9993-840741585A62}" = Acer eManager for Notebook
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver for Mobile
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1029-7B44-A92000000001}" = Adobe Reader 9.2 - Czech
"{BE8BE32F-F595-4693-9F82-1E0A5A047BB6}" = OpenOffice.org 3.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D98C0C51-F9BB-4EE4-B791-22BF6EE31029}" = Nero 7 Ultra Edition
"{F1B8DB67-D30E-4FF9-A85F-3CEE51825AA2}" = SMSC IrCC V5.1.3600.5 SP2
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems AC'97 Modem
"Ask Toolbar_is1" = Ask Toolbar
"audcle" = Plus! MP3 Audio Converter LE
"avast5" = avast! Free Antivirus
"CCleaner" = CCleaner (remove only)
"COMODO Internet Security" = COMODO Internet Security
"COMODO SafeSurf" = COMODO SafeSurf
"drmtool.inf" = Personal License Update Wizard for Windows Media Player
"Google Chrome" = Google Chrome
"ICQToolbar" = ICQ Toolbar
"InstallShield_{827289F5-B44F-4E49-9993-840741585A62}" = Acer eManager for Notebook
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mmmusic" = Movie Maker Background Music Files
"mmsounds" = Movie Maker Sound Effects
"mmtitle" = Movie Maker Title Images
"mplibwiz.inf" = Media Library Management Wizard
"mpxlswiz.inf" = Windows Media Player Playlist Import to Excel Wizard
"mpxptray.inf" = Windows Media Player Tray Control
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"wa2wmp" = Windows Media Player Skin Importer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMBK2" = Windows Media Bonus Pack for Windows XP
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1.6.2010 14:23:19 | Computer Name = ACER | Source = CardSpace 3.0.0.0 | ID = 327949
Description = The Windows CardSpace service is too busy to process this request.
User has too many outstanding requests. Additional Information: at System.Environment.GetStackTrace(Exception
e, Boolean needFileInfo) at System.Environment.get_StackTrace() at Microsoft.InfoCards.Diagnostics.InfoCardTrace.BuildMessage(InfoCardBaseException
ie) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.TraceAndLogException(Exception
e) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.ThrowHelperError(Exception
e) at Microsoft.InfoCards.UIAgentMonitor.AddNewClient(UIAgentMonitorHandle handle)

at Microsoft.InfoCards.UIAgentMonitorHandle.CreateAgent(Int32 callerPid, WindowsIdentity
callerIdentity, Int32 tsSessionId) at Microsoft.InfoCards.RequestFactory.CreateClientRequestInstance(UIAgentMonitorHandle
monitorHandle, String reqName, IntPtr rpcHandle, Stream inStream, Stream outStream)

at Microsoft.InfoCards.RequestFactory.ProcessNewRequest(Int32 parentRequestHandle,
IntPtr rpcHandle, IntPtr inArgs, IntPtr& outArgs)

Error - 1.6.2010 14:23:19 | Computer Name = ACER | Source = CardSpace 3.0.0.0 | ID = 327949
Description = The Windows CardSpace service is too busy to process this request.
User has too many outstanding requests. Additional Information: at System.Environment.GetStackTrace(Exception
e, Boolean needFileInfo) at System.Environment.get_StackTrace() at Microsoft.InfoCards.Diagnostics.InfoCardTrace.BuildMessage(InfoCardBaseException
ie) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.TraceAndLogException(Exception
e) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.ThrowHelperError(Exception
e) at Microsoft.InfoCards.UIAgentMonitor.AddNewClient(UIAgentMonitorHandle handle)

at Microsoft.InfoCards.UIAgentMonitorHandle.CreateAgent(Int32 callerPid, WindowsIdentity
callerIdentity, Int32 tsSessionId) at Microsoft.InfoCards.RequestFactory.CreateClientRequestInstance(UIAgentMonitorHandle
monitorHandle, String reqName, IntPtr rpcHandle, Stream inStream, Stream outStream)

at Microsoft.InfoCards.RequestFactory.ProcessNewRequest(Int32 parentRequestHandle,
IntPtr rpcHandle, IntPtr inArgs, IntPtr& outArgs)

Error - 1.6.2010 14:23:19 | Computer Name = ACER | Source = CardSpace 3.0.0.0 | ID = 327949
Description = The Windows CardSpace service is too busy to process this request.
User has too many outstanding requests. Additional Information: at System.Environment.GetStackTrace(Exception
e, Boolean needFileInfo) at System.Environment.get_StackTrace() at Microsoft.InfoCards.Diagnostics.InfoCardTrace.BuildMessage(InfoCardBaseException
ie) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.TraceAndLogException(Exception
e) at Microsoft.InfoCards.Diagnostics.InfoCardTrace.ThrowHelperError(Exception
e) at Microsoft.InfoCards.UIAgentMonitor.AddNewClient(UIAgentMonitorHandle handle)

at Microsoft.InfoCards.UIAgentMonitorHandle.CreateAgent(Int32 callerPid, WindowsIdentity
callerIdentity, Int32 tsSessionId) at Microsoft.InfoCards.RequestFactory.CreateClientRequestInstance(UIAgentMonitorHandle
monitorHandle, String reqName, IntPtr rpcHandle, Stream inStream, Stream outStream)

at Microsoft.InfoCards.RequestFactory.ProcessNewRequest(Int32 parentRequestHandle,
IntPtr rpcHandle, IntPtr inArgs, IntPtr& outArgs)

Error - 3.6.2010 10:17:17 | Computer Name = ACER | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace SkypeSetup.exe, verze 4.2.0.169, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 3.6.2010 10:17:17 | Computer Name = ACER | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace SkypeSetup.exe, verze 4.2.0.169, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 3.6.2010 10:17:18 | Computer Name = ACER | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace SkypeSetup.exe, verze 4.2.0.169, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

Error - 6.6.2010 10:41:19 | Computer Name = ACER | Source = Application Error | ID = 1000
Description = Chybující aplikace icq.exe, verze 6.5.0.2024, chybující modul sipxtapi.dll,
verze 2.10.1.3779, adresa chyby 0x000769d9.

Error - 12.6.2010 10:15:17 | Computer Name = ACER | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 1.7.2010 6:17:10 | Computer Name = ACER | Source = PerfNet | ID = 2004
Description = Nelze otevřít službu serveru. Data o výkonu serveru nejsou k dispozici.
Vrácený chybový kód je v datech DWORD 0.

Error - 9.7.2010 16:38:50 | Computer Name = ACER | Source = Application Hang | ID = 1002
Description = Zablokovaná aplikace wmplayer.exe, verze 11.0.5721.5145, zablokovaný
modul hungapp, verze 0.0.0.0, adresa bloku 0x00000000.

[ System Events ]
Error - 27.10.2010 8:58:22 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba Java Quick Starter byla neočekávaně ukončena. Tento stav nastal
již 1krát.

Error - 27.10.2010 9:07:04 | Computer Name = ACER | Source = PlugPlayManager | ID = 11
Description = Zařízení Root\LEGACY_QVHMBPZL\0000 se již v systému nenachází, přestože
nebylo nejdříve připraveno k odebrání.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba ICQ Service byla neočekávaně ukončena. Tento stav nastal již
1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba NMIndexingService byla neočekávaně ukončena. Tento stav nastal
již 1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba Adaptér výkonu služby WMI byla neočekávaně ukončena. Tento
stav nastal již 1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba Zařazování tisku byla neočekávaně ukončena. Tento stav nastal
již 1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba COMODO Internet Security Helper Service byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba Služba brány aplikačního rozhraní byla neočekávaně ukončena.
Tento stav nastal již 1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba Notebook Manager Service byla neočekávaně ukončena. Tento stav
nastal již 1krát.

Error - 27.10.2010 9:46:16 | Computer Name = ACER | Source = Service Control Manager | ID = 7034
Description = Služba Java Quick Starter byla neočekávaně ukončena. Tento stav nastal
již 1krát.


< End of report >

Odpovědět