Re: win32/Mebroot.K Trojan
Napsal: 15 kvě 2009 21:35
druhy log byl Extras.txt:
OTListIt Extras logfile created on: 15.5.2009 22:27:53 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Owner\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,44 Gb Available Physical Memory | 71,98% Memory free
3,85 Gb Paging File | 3,43 Gb Available in Paging File | 89,02% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 145,35 Gb Free Space | 62,41% Space Free | Partition Type: NTFS
Drive D: | 642,16 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DENDANEW
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 7 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_USERS\S-1-5-21-1417001333-630328440-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found -- C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
[2007.09.26 12:35:38 | 01,848,616 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Nero Web\SetupXu.exe:*:Enabled:Nero ProductSetup
[2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found -- C:\Program Files\FarStone\VirtualDrive\MGR.exe:*:Enabled:VirtualDrive MGR
[2009.02.28 16:44:09 | 00,075,064 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA
[2009.05.10 18:40:12 | 00,189,072 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB
[2003.12.24 11:34:26 | 00,221,184 | ---- | M] (Micro-Star International Co.,Ltd.) -- C:\Program Files\MSI\i-Speeder\i-Speeder.exe:*:Enabled:i-Speeder
[2008.05.31 20:25:11 | 00,219,952 | ---- | M] () -- C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
[2008.09.01 17:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.) -- C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6
[1999.09.21 17:46:58 | 00,938,496 | R--- | M] (Microsoft Corporation) -- C:\Hry\Age of Empires II\empires2.exe:*:Enabled:Age of Empires II
[2000.08.08 16:12:40 | 02,695,213 | R--- | M] (Microsoft Corporation) -- C:\Hry\Age of Empires II\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion
File not found -- C:\Hry\World of Warcraft\WoW-2.4.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader
[2002.01.12 04:57:56 | 01,519,616 | R--- | M] (Electronic Arts Inc.) -- C:\Hry\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault
[2003.08.08 20:30:00 | 01,527,808 | ---- | M] (Activision Inc) -- C:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer
[2003.09.02 21:39:44 | 07,106,560 | ---- | M] (Ensemble Studios) -- C:\Hry\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion
[2008.06.20 15:43:00 | 03,330,048 | ---- | M] () -- C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)
[2008.06.23 16:51:14 | 04,197,376 | ---- | M] (QIP) -- C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium
File not found -- C:\Hry\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Blizzard Launcher Temporary - 9bd93398\Launcher.exe:*:Enabled:Blizzard Launcher
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Blizzard Launcher Temporary - b540c5a8\Launcher.exe:*:Enabled:Blizzard Launcher
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Blizzard Launcher Temporary - 0cc53210\Launcher.exe:*:Enabled:Blizzard Launcher
[2009.04.23 06:13:43 | 02,172,400 | ---- | M] (Blizzard Entertainment) -- C:\Program Files\WoW\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader
[2009.04.23 06:13:43 | 03,798,624 | ---- | M] (Blizzard Entertainment) -- C:\Program Files\WoW\Launcher.exe:*:Enabled:Blizzard Launcher
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00CD72B3-E2DF-4DFC-BCC1-5CC4F564518D}" = Symantec Client Security
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0D994CC5-819F-4657-84DD-397B8FE1EA80}" = Star Wars Jedi Knight Jedi Academy
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0F33250B-7C59-5A14-6ED5-FCC251A962D0}" = Skins
"{14378007-ACD5-2482-33A1-F79289A452E7}" = Catalyst Control Center Graphics Full Existing
"{1E1CB0CC-50E9-2618-5D7C-03BE0A27E118}" = Catalyst Control Center Core Implementation
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{29C22873-B939-4EF9-B6E3-1EFE7FA391D1}" = ASUS nVidia Driver
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}" = ACDSee 6.0 PowerPack
"{3CAF8B75-2F1F-4B87-9071-5B838C408DBB}" = LEGO Star Wars
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4CA9EA31-65E6-00E2-3DBB-19AF01D51C8D}" = Catalyst Control Center Graphics Light
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5EF19AD3-1873-9072-D526-E8F4E6A9EE59}" = Catalyst Control Center Graphics Full New
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6
"{68C83D63-C661-C444-7E60-E0328D842ECB}" = ccc-core-preinstall
"{6EF72FC6-842E-4FE6-BF88-BFBF03C9DA74}" = Windows Workflow Foundation CS Language Pack
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72D07FDD-94B7-A4EE-8C28-888C55D33831}" = ccc-core-static
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7F947BFE-C2DF-4779-9909-5BEE746BD0C4}" = Microsoft .NET Framework 2.0 Language Pack - CSY
"{7FFC95A3-A514-E94D-72A1-B0FF80656519}" = CCC Help English
"{8423B39C-AC5F-45F3-AC90-204F891CBF3A}" = Heroes of Might and Magic® II
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8A232EC3-38F5-4827-910F-AD1F3BF7878F}" = ATI Parental Control & Encoder
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{97FA9DC8-B4AF-84EE-DA97-B13FE28381BA}" = ccc-utility
"{99D328E0-51DE-465E-9307-B85CA9511029}" = Nero 7 Essentials
"{9DE9E293-5D7B-4312-88C2-BDFAEC5310AE}" = Microsoft .NET Framework 3.0
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{AAB6D0F8-02B3-4E89-B24C-0BB153C21445}" = Windows Presentation Foundation Language Pack (CSY)
"{AC76BA86-7AD7-1029-7B44-A81200000003}" = Adobe Reader 8 - Czech
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6C1833E-6C94-4529-AE2F-E36E247314FA}" = ATI Catalyst Control Center
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D8979435-753B-40AE-9318-5E712C160A71}" = Windows Communication Foundation Language Pack - CSY
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{F73920B1-FD39-6893-4E9B-748311B666AF}" = Catalyst Control Center Graphics Previews Common
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB09515C-8E3E-4E0F-A1F2-032F38DEC185}" = Microsoft .NET Framework 3.0 Czech Language Pack
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"3FA1705966809259F916AF817C59B4F389F4572C" = Balíček ovladače systému Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"All ATI Software" = ATI - Software Uninstall Utility
"America" = America
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner (remove only)
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"Corel Uninstaller" = Corel Uninstaller
"CutePDF Writer Installation" = CutePDF Writer 2.2
"DVD Shrink_is1" = DVD Shrink 3.2
"EAX Unified" = EAX Unified
"GameParkClient_is1" = GamePark
"Hamachi" = Hamachi 1.0.2.5
"Heroes of Might and Magic III Complete" = Heroes of Might and Magic III Complete
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"Icewind Dale" = Icewind Dale
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InfoView" = InfoView
"InstallShield_{8423B39C-AC5F-45F3-AC90-204F891CBF3A}" = Heroes of Might and Magic® II
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"i-Speeder" = i-Speeder
"IWDCZ" = Icewind Dale(TM) - Čeština
"IZArc 3.4.1.6_is1" = IZArc 3.4.1.6
"Lexicon 3.0" = Lingea Lexicon 2000
"LiveUpdate" = LiveUpdate 2.0 (Symantec Corporation)
"Mafia Game" = Mafia Game
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - CSY" = Microsoft .NET Framework 2.0 Language Pack - CSY
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft .NET Framework 3.0 Czech Language Pack" = Microsoft .NET Framework 3.0 Czech Language Pack
"MobMap_is1" = MobMap 1.30
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSI Live Update 3" = MSI Live Update 3
"MV2Player" = MV2Player (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Qip Infium packverze: 9010 RC2 s IRC protokolem" = Qip Infium pack verze: 9010 RC2 s IRC protokolem
"Red Alert 2" = Command & Conquer Red Alert 2
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"World of Warcraft" = World of Warcraft
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1417001333-630328440-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3.5.2009 15:19:08 | Computer Name = DENDANEW | Source = MsiInstaller | ID = 11706
Description = Produkt: Heroes of Might and Magic® II - Chyba 1706. Instalační balíček
pro produkt Heroes of Might and Magic® II nebyl nalezen. Spusťte instalaci znovu
pomocí platného instalačního balíčku Heroes of Might and Magic II.msi.
Error - 3.5.2009 15:26:18 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\All Users\Nabídka Start\Programy\Po spuštění\uninstall.exe dle: Auto-Protect
prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné
: Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 15:52:04 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\All Users\Nabídka Start\Programy\Po spuštění\uninstall.exe dle: Auto-Protect
prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné
: Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 16:01:16 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\Owner\DoctorWeb\Quarantine\uninstall.exe dle: Auto-Protect prověření.
Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné : Přístup odepřen.
Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 16:03:49 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\All Users\Nabídka Start\Programy\Po spuštění\uninstall.exe dle: Auto-Protect
prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné
: Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 18:42:40 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\System Volume
Information\_restore{5F2022F1-E429-4A32-A393-D4B0771E0C30}\RP273\A0094871.exe dle:
Auto-Protect prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit
úspěšné : Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 19:20:03 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\System Volume
Information\_restore{5F2022F1-E429-4A32-A393-D4B0771E0C30}\RP273\A0095956.exe dle:
Auto-Protect prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit
úspěšné : Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 13.5.2009 17:42:49 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan Horse v souboru: C:\WINDOWS\system32\B0800F21.exe
dle: Auto-Protect prověření. Akce: Karanténa úspěšné : Přístup odepřen. Popis
akce: Soubor byl úspěšně izolován v karanténě.
Error - 13.5.2009 17:51:58 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan Horse v souboru: C:\WINDOWS\system32\84B9B207.exe
dle: Auto-Protect prověření. Akce: Karanténa úspěšné : Přístup odepřen. Popis
akce: Soubor byl úspěšně izolován v karanténě.
Error - 13.5.2009 17:52:17 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan Horse v souboru: C:\WINDOWS\system32\47A4C808.exe
dle: Auto-Protect prověření. Akce: Karanténa úspěšné : Přístup odepřen. Popis
akce: Soubor byl úspěšně izolován v karanténě.
[ System Events ]
Error - 12.5.2009 11:07:42 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12.5.2009 11:07:44 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12.5.2009 11:08:04 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12.5.2009 14:35:13 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 13.5.2009 14:28:38 | Computer Name = DENDANEW | Source = MRxSmb | ID = 8003
Description = Hlavní prohledávač přijal oznámení serveru od počítače MILDA, který
se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{14217C79-DF98-4835-881.
Hlavní
prohledávač bude ukončen nebo bude vyvolána volba.
Error - 13.5.2009 16:52:47 | Computer Name = DENDANEW | Source = MRxSmb | ID = 8003
Description = Hlavní prohledávač přijal oznámení serveru od počítače MILDA, který
se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{14217C79-DF98-4835-881.
Hlavní
prohledávač bude ukončen nebo bude vyvolána volba.
Error - 13.5.2009 17:42:49 | Computer Name = DENDANEW | Source = Service Control Manager | ID = 7000
Description = Služba B0800F21 neuspěla při spuštění v důsledku následující chyby:
%%2
Error - 13.5.2009 17:51:59 | Computer Name = DENDANEW | Source = Service Control Manager | ID = 7000
Description = Služba 84B9B207 neuspěla při spuštění v důsledku následující chyby:
%%2
Error - 13.5.2009 17:52:17 | Computer Name = DENDANEW | Source = Service Control Manager | ID = 7000
Description = Služba 47A4C808 neuspěla při spuštění v důsledku následující chyby:
%%2
Error - 13.5.2009 17:52:51 | Computer Name = DENDANEW | Source = MRxSmb | ID = 8003
Description = Hlavní prohledávač přijal oznámení serveru od počítače MILDA, který
se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{14217C79-DF98-4835-881.
Hlavní
prohledávač bude ukončen nebo bude vyvolána volba.
< End of report >
OTListIt Extras logfile created on: 15.5.2009 22:27:53 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Owner\Plocha
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d.M.yyyy
2,00 Gb Total Physical Memory | 1,44 Gb Available Physical Memory | 71,98% Memory free
3,85 Gb Paging File | 3,43 Gb Available in Paging File | 89,02% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 145,35 Gb Free Space | 62,41% Space Free | Partition Type: NTFS
Drive D: | 642,16 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DENDANEW
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 7 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_USERS\S-1-5-21-1417001333-630328440-725345543-1003\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3724:TCP" = 3724:TCP:*:Enabled:Blizzard Downloader: 3724
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found -- C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
[2007.09.26 12:35:38 | 01,848,616 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Nero Web\SetupX.exe:*:Enabled:Nero ProductSetup
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Nero Web\SetupXu.exe:*:Enabled:Nero ProductSetup
[2008.04.13 20:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found -- C:\Program Files\FarStone\VirtualDrive\MGR.exe:*:Enabled:VirtualDrive MGR
[2009.02.28 16:44:09 | 00,075,064 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA
[2009.05.10 18:40:12 | 00,189,072 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB
[2003.12.24 11:34:26 | 00,221,184 | ---- | M] (Micro-Star International Co.,Ltd.) -- C:\Program Files\MSI\i-Speeder\i-Speeder.exe:*:Enabled:i-Speeder
[2008.05.31 20:25:11 | 00,219,952 | ---- | M] () -- C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent
[2008.09.01 17:08:21 | 00,173,304 | ---- | M] (ICQ, Inc.) -- C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6
[1999.09.21 17:46:58 | 00,938,496 | R--- | M] (Microsoft Corporation) -- C:\Hry\Age of Empires II\empires2.exe:*:Enabled:Age of Empires II
[2000.08.08 16:12:40 | 02,695,213 | R--- | M] (Microsoft Corporation) -- C:\Hry\Age of Empires II\age2_x1\age2_x1.exe:*:Enabled:Age of Empires II Expansion
File not found -- C:\Hry\World of Warcraft\WoW-2.4.0-enGB-downloader.exe:*:Enabled:Blizzard Downloader
[2002.01.12 04:57:56 | 01,519,616 | R--- | M] (Electronic Arts Inc.) -- C:\Hry\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault
[2003.08.08 20:30:00 | 01,527,808 | ---- | M] (Activision Inc) -- C:\Program Files\LucasArts\Star Wars Jedi Knight Jedi Academy\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer
[2003.09.02 21:39:44 | 07,106,560 | ---- | M] (Ensemble Studios) -- C:\Hry\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion
[2008.06.20 15:43:00 | 03,330,048 | ---- | M] () -- C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)
[2008.06.23 16:51:14 | 04,197,376 | ---- | M] (QIP) -- C:\Program Files\QIP Infium\infium.exe:*:Enabled:QIP Infium
File not found -- C:\Hry\GameSpy Arcade\Aphex.exe:*:Enabled:GameSpy Arcade
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Blizzard Launcher Temporary - 9bd93398\Launcher.exe:*:Enabled:Blizzard Launcher
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Blizzard Launcher Temporary - b540c5a8\Launcher.exe:*:Enabled:Blizzard Launcher
File not found -- C:\Documents and Settings\Owner\Local Settings\Temp\Blizzard Launcher Temporary - 0cc53210\Launcher.exe:*:Enabled:Blizzard Launcher
[2009.04.23 06:13:43 | 02,172,400 | ---- | M] (Blizzard Entertainment) -- C:\Program Files\WoW\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader
[2009.04.23 06:13:43 | 03,798,624 | ---- | M] (Blizzard Entertainment) -- C:\Program Files\WoW\Launcher.exe:*:Enabled:Blizzard Launcher
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00CD72B3-E2DF-4DFC-BCC1-5CC4F564518D}" = Symantec Client Security
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0D994CC5-819F-4657-84DD-397B8FE1EA80}" = Star Wars Jedi Knight Jedi Academy
"{0DEA94ED-915A-4834-A87E-388D012C8E02}" = Medal of Honor Allied Assault
"{0F33250B-7C59-5A14-6ED5-FCC251A962D0}" = Skins
"{14378007-ACD5-2482-33A1-F79289A452E7}" = Catalyst Control Center Graphics Full Existing
"{1E1CB0CC-50E9-2618-5D7C-03BE0A27E118}" = Catalyst Control Center Core Implementation
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{29C22873-B939-4EF9-B6E3-1EFE7FA391D1}" = ASUS nVidia Driver
"{350C9405-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38A0BB97-772D-422E-BCCA-4BA2A5D81F42}" = ACDSee 6.0 PowerPack
"{3CAF8B75-2F1F-4B87-9071-5B838C408DBB}" = LEGO Star Wars
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}" = ATI HydraVision
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4CA9EA31-65E6-00E2-3DBB-19AF01D51C8D}" = Catalyst Control Center Graphics Light
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5EF19AD3-1873-9072-D526-E8F4E6A9EE59}" = Catalyst Control Center Graphics Full New
"{60DE4033-9503-48D1-A483-7846BD217CA9}" = ICQ6
"{68C83D63-C661-C444-7E60-E0328D842ECB}" = ccc-core-preinstall
"{6EF72FC6-842E-4FE6-BF88-BFBF03C9DA74}" = Windows Workflow Foundation CS Language Pack
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72D07FDD-94B7-A4EE-8C28-888C55D33831}" = ccc-core-static
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7F947BFE-C2DF-4779-9909-5BEE746BD0C4}" = Microsoft .NET Framework 2.0 Language Pack - CSY
"{7FFC95A3-A514-E94D-72A1-B0FF80656519}" = CCC Help English
"{8423B39C-AC5F-45F3-AC90-204F891CBF3A}" = Heroes of Might and Magic® II
"{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"{8A232EC3-38F5-4827-910F-AD1F3BF7878F}" = ATI Parental Control & Encoder
"{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"{97FA9DC8-B4AF-84EE-DA97-B13FE28381BA}" = ccc-utility
"{99D328E0-51DE-465E-9307-B85CA9511029}" = Nero 7 Essentials
"{9DE9E293-5D7B-4312-88C2-BDFAEC5310AE}" = Microsoft .NET Framework 3.0
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{AAB6D0F8-02B3-4E89-B24C-0BB153C21445}" = Windows Presentation Foundation Language Pack (CSY)
"{AC76BA86-7AD7-1029-7B44-A81200000003}" = Adobe Reader 8 - Czech
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B6C1833E-6C94-4529-AE2F-E36E247314FA}" = ATI Catalyst Control Center
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D8979435-753B-40AE-9318-5E712C160A71}" = Windows Communication Foundation Language Pack - CSY
"{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"{F73920B1-FD39-6893-4E9B-748311B666AF}" = Catalyst Control Center Graphics Previews Common
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB09515C-8E3E-4E0F-A1F2-032F38DEC185}" = Microsoft .NET Framework 3.0 Czech Language Pack
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"3FA1705966809259F916AF817C59B4F389F4572C" = Balíček ovladače systému Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0 CE" = Adobe Photoshop 7.0 CE
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"All ATI Software" = ATI - Software Uninstall Utility
"America" = America
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner (remove only)
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"Corel Uninstaller" = Corel Uninstaller
"CutePDF Writer Installation" = CutePDF Writer 2.2
"DVD Shrink_is1" = DVD Shrink 3.2
"EAX Unified" = EAX Unified
"GameParkClient_is1" = GamePark
"Hamachi" = Hamachi 1.0.2.5
"Heroes of Might and Magic III Complete" = Heroes of Might and Magic III Complete
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"Icewind Dale" = Icewind Dale
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InfoView" = InfoView
"InstallShield_{8423B39C-AC5F-45F3-AC90-204F891CBF3A}" = Heroes of Might and Magic® II
"InstallShield_{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
"InstallShield_{931C37FC-594D-43A9-B10F-A2F2B1F03498}" = Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
"InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}" = Call of Duty(R) 4 - Modern Warfare(TM)
"i-Speeder" = i-Speeder
"IWDCZ" = Icewind Dale(TM) - Čeština
"IZArc 3.4.1.6_is1" = IZArc 3.4.1.6
"Lexicon 3.0" = Lingea Lexicon 2000
"LiveUpdate" = LiveUpdate 2.0 (Symantec Corporation)
"Mafia Game" = Mafia Game
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - CSY" = Microsoft .NET Framework 2.0 Language Pack - CSY
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft .NET Framework 3.0 Czech Language Pack" = Microsoft .NET Framework 3.0 Czech Language Pack
"MobMap_is1" = MobMap 1.30
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSI Live Update 3" = MSI Live Update 3
"MV2Player" = MV2Player (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Qip Infium packverze: 9010 RC2 s IRC protokolem" = Qip Infium pack verze: 9010 RC2 s IRC protokolem
"Red Alert 2" = Command & Conquer Red Alert 2
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"World of Warcraft" = World of Warcraft
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1417001333-630328440-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3.5.2009 15:19:08 | Computer Name = DENDANEW | Source = MsiInstaller | ID = 11706
Description = Produkt: Heroes of Might and Magic® II - Chyba 1706. Instalační balíček
pro produkt Heroes of Might and Magic® II nebyl nalezen. Spusťte instalaci znovu
pomocí platného instalačního balíčku Heroes of Might and Magic II.msi.
Error - 3.5.2009 15:26:18 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\All Users\Nabídka Start\Programy\Po spuštění\uninstall.exe dle: Auto-Protect
prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné
: Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 15:52:04 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\All Users\Nabídka Start\Programy\Po spuštění\uninstall.exe dle: Auto-Protect
prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné
: Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 16:01:16 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\Owner\DoctorWeb\Quarantine\uninstall.exe dle: Auto-Protect prověření.
Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné : Přístup odepřen.
Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 16:03:49 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\Documents and
Settings\All Users\Nabídka Start\Programy\Po spuštění\uninstall.exe dle: Auto-Protect
prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit úspěšné
: Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 18:42:40 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\System Volume
Information\_restore{5F2022F1-E429-4A32-A393-D4B0771E0C30}\RP273\A0094871.exe dle:
Auto-Protect prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit
úspěšné : Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 3.5.2009 19:20:03 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan.Mebroot v souboru: C:\System Volume
Information\_restore{5F2022F1-E429-4A32-A393-D4B0771E0C30}\RP273\A0095956.exe dle:
Auto-Protect prověření. Akce: Čisté se nezdařil : Karanténa se nezdařil : Odstranit
úspěšné : Přístup odepřen. Popis akce: Soubor byl úspěšně odstraněn.
Error - 13.5.2009 17:42:49 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan Horse v souboru: C:\WINDOWS\system32\B0800F21.exe
dle: Auto-Protect prověření. Akce: Karanténa úspěšné : Přístup odepřen. Popis
akce: Soubor byl úspěšně izolován v karanténě.
Error - 13.5.2009 17:51:58 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan Horse v souboru: C:\WINDOWS\system32\84B9B207.exe
dle: Auto-Protect prověření. Akce: Karanténa úspěšné : Přístup odepřen. Popis
akce: Soubor byl úspěšně izolován v karanténě.
Error - 13.5.2009 17:52:17 | Computer Name = DENDANEW | Source = Symantec AntiVirus | ID = 16711685
Description = Nalezena hrozba!Hrozba: Trojan Horse v souboru: C:\WINDOWS\system32\47A4C808.exe
dle: Auto-Protect prověření. Akce: Karanténa úspěšné : Přístup odepřen. Popis
akce: Soubor byl úspěšně izolován v karanténě.
[ System Events ]
Error - 12.5.2009 11:07:42 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12.5.2009 11:07:44 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12.5.2009 11:08:04 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12.5.2009 14:35:13 | Computer Name = DENDANEW | Source = DCOM | ID = 10005
Description = Služba DCOM zjistila chybu %1084 při pokusu o spuštění služby EventSystem
s argumenty za účelem spuštění serveru: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 13.5.2009 14:28:38 | Computer Name = DENDANEW | Source = MRxSmb | ID = 8003
Description = Hlavní prohledávač přijal oznámení serveru od počítače MILDA, který
se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{14217C79-DF98-4835-881.
Hlavní
prohledávač bude ukončen nebo bude vyvolána volba.
Error - 13.5.2009 16:52:47 | Computer Name = DENDANEW | Source = MRxSmb | ID = 8003
Description = Hlavní prohledávač přijal oznámení serveru od počítače MILDA, který
se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{14217C79-DF98-4835-881.
Hlavní
prohledávač bude ukončen nebo bude vyvolána volba.
Error - 13.5.2009 17:42:49 | Computer Name = DENDANEW | Source = Service Control Manager | ID = 7000
Description = Služba B0800F21 neuspěla při spuštění v důsledku následující chyby:
%%2
Error - 13.5.2009 17:51:59 | Computer Name = DENDANEW | Source = Service Control Manager | ID = 7000
Description = Služba 84B9B207 neuspěla při spuštění v důsledku následující chyby:
%%2
Error - 13.5.2009 17:52:17 | Computer Name = DENDANEW | Source = Service Control Manager | ID = 7000
Description = Služba 47A4C808 neuspěla při spuštění v důsledku následující chyby:
%%2
Error - 13.5.2009 17:52:51 | Computer Name = DENDANEW | Source = MRxSmb | ID = 8003
Description = Hlavní prohledávač přijal oznámení serveru od počítače MILDA, který
se považuje za hlavní prohledávač domény pro přenos NetBT_Tcpip_{14217C79-DF98-4835-881.
Hlavní
prohledávač bude ukončen nebo bude vyvolána volba.
< End of report >