Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Modre smrti

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Modre smrti

#1 Příspěvek od rlipka »

Zdravim, mam problemy s mym notebookem....haze sem tam modre smrti :cry: podivejte se mi na to dik :)

Logfile of random's system information tool 1.06 (written by random/random)
Run by Robin at 2010-05-01 17:24:26
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 116 GB (51%) free of 230 GB
Total RAM: 3002 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:25:02, on 1.5.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Full-size Mouse\wh_exec.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Robin\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Robin\Desktop\RSIT.exe
C:\Program Files\trend micro\Robin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WheelMouse] C:\FULL-S~1\wh_exec.exe
O4 - HKLM\..\Run: [TQ566808] "E:\Setup.exe"
O4 - HKLM\..\Run: [Imation Button Manager] "C:\Program Files\Imation Button Manager\Imation Button Manager.exe" -A
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup\uBBMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.co ... 1.71.0.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Imation Button Manager Service (ImationButtonManagerService) - Imation Corp. - C:\Program Files\Imation Button Manager\Imation Button Manager Service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12646 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000UA.job
C:\Windows\tasks\HPCeeScheduleForRobin.job
C:\Windows\tasks\User_Feed_Synchronization-{D2314F70-64A9-4ECC-BBC8-CC32DFDAF9A4}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-03-07 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-03-07 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-07 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{D4027C7F-154A-4066-A1AD-4243D8127440} - Ask Toolbar - C:\Program Files\Ask.com\GenericAskToolbar.dll [2009-09-02 1175944]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-03-07 279664]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-17 1049896]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2008-09-23 468264]
"UpdateLBPShortCut"=C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePSTShortCut"=C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [2008-10-06 210216]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-12-24 222504]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-08-01 202032]
"UpdateP2GoShortCut"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"UpdatePDIRShortCut"=C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [2008-06-13 210216]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"WheelMouse"=C:\FULL-S~1\wh_exec.exe [2008-10-08 98304]
"TQ566808"=E:\Setup.exe []
"Imation Button Manager"=C:\Program Files\Imation Button Manager\Imation Button Manager.exe [2009-02-07 385536]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-02-20 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-02-20 175640]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-02-20 167960]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2009-11-09 180224]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-03-07 39408]
"Steam"=c:\program files\steam\steam.exe [2010-04-27 1238352]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Google Update"=C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-18 136176]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup\uBBMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-02-20 227328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
shell\AutoRun\command - F:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7d0d1b17-4311-11df-98cb-001f1665d60a}]
shell\AutoRun\command - H:\setupSNK.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-05-01 17:24:26 ----D---- C:\rsit
2010-05-01 17:24:26 ----D---- C:\Program Files\trend micro
2010-04-27 17:16:46 ----D---- C:\Program Files\Common Files\Adobe
2010-04-27 17:16:46 ----D---- C:\Program Files\Adobe
2010-04-26 21:57:05 ----SHD---- C:\Config.Msi
2010-04-25 20:25:39 ----D---- C:\Program Files\Microsoft Security Essentials
2010-04-23 16:05:21 ----D---- C:\Windows\Minidump
2010-04-23 15:17:12 ----D---- C:\Program Files\ZhyperMU
2010-04-20 16:41:51 ----D---- C:\Users\Robin\AppData\Roaming\Passware
2010-04-14 21:14:58 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-04-14 21:14:57 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-04-14 21:14:47 ----A---- C:\Windows\system32\vbscript.dll
2010-04-14 21:14:08 ----A---- C:\Windows\system32\iphlpsvc.dll
2010-04-14 17:28:07 ----A---- C:\Windows\system32\wintrust.dll
2010-04-14 17:28:04 ----A---- C:\Windows\system32\cabview.dll
2010-04-06 19:41:21 ----D---- C:\Program Files\Disc2Phone
2010-04-06 19:35:37 ----D---- C:\Windows\system32\URTTEMP
2010-04-05 16:23:35 ----D---- C:\ProgramData\TmForever
2010-04-05 16:17:58 ----D---- C:\Program Files\TmNationsForever
2010-04-03 19:14:39 ----A---- C:\Windows\system32\winhttp.dll
2010-04-02 22:31:20 ----A---- C:\Windows\system32\browserchoice.exe
2010-04-02 19:53:34 ----A---- C:\Windows\system32\schannel.dll
2010-04-02 19:53:34 ----A---- C:\Windows\system32\kerberos.dll

======List of files/folders modified in the last 1 months======

2010-05-01 17:24:59 ----D---- C:\Windows\Temp
2010-05-01 17:24:35 ----D---- C:\Users\Robin\AppData\Roaming\Skype
2010-05-01 17:24:26 ----RD---- C:\Program Files
2010-05-01 17:21:37 ----D---- C:\Windows\Prefetch
2010-05-01 17:12:28 ----D---- C:\Users\Robin\AppData\Roaming\skypePM
2010-05-01 17:12:11 ----SHD---- C:\System Volume Information
2010-05-01 17:11:20 ----D---- C:\Program Files\Steam
2010-05-01 13:41:24 ----A---- C:\ProgramData\hpqp.ini
2010-05-01 13:40:42 ----D---- C:\Windows
2010-05-01 12:58:25 ----D---- C:\Users\Robin\AppData\Roaming\vlc
2010-05-01 12:53:39 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-30 17:48:32 ----D---- C:\Windows\system32\catroot2
2010-04-28 21:49:50 ----D---- C:\Program Files\Common Files\Steam
2010-04-28 21:30:28 ----D---- C:\Windows\Debug
2010-04-28 21:28:43 ----D---- C:\Program Files\CCleaner
2010-04-28 20:09:34 ----D---- C:\Windows\system32\WDI
2010-04-28 16:55:13 ----RSD---- C:\Windows\Fonts
2010-04-28 16:37:11 ----D---- C:\Windows\winsxs
2010-04-28 15:44:38 ----D---- C:\Windows\system32\catroot
2010-04-27 19:52:56 ----D---- C:\Users\Robin\AppData\Roaming\dvdcss
2010-04-27 17:19:20 ----SHD---- C:\Windows\Installer
2010-04-27 17:17:36 ----D---- C:\Windows\System32
2010-04-27 17:16:57 ----D---- C:\ProgramData\Adobe
2010-04-27 17:16:46 ----D---- C:\Program Files\Common Files
2010-04-25 20:25:53 ----D---- C:\Windows\system32\drivers
2010-04-25 20:25:51 ----SD---- C:\ProgramData\Microsoft
2010-04-25 20:23:40 ----D---- C:\Program Files\ESET
2010-04-23 14:46:54 ----D---- C:\Program Files\Empire Interactive
2010-04-20 22:02:21 ----D---- C:\Users\Robin\AppData\Roaming\uTorrent
2010-04-20 16:44:22 ----SD---- C:\Users\Robin\AppData\Roaming\Microsoft
2010-04-20 16:24:12 ----D---- C:\Windows\system32\Tasks
2010-04-20 14:20:26 ----D---- C:\ProgramData\POPWWPROFILES
2010-04-17 22:43:10 ----D---- C:\Windows\SoftwareDistribution
2010-04-15 15:46:26 ----D---- C:\Program Files\Windows Mail
2010-04-14 22:09:26 ----D---- C:\ProgramData\Microsoft Help
2010-04-14 20:44:34 ----D---- C:\Program Files\ICQ7.0
2010-04-14 19:09:44 ----D---- C:\Windows\inf
2010-04-14 19:09:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-04-06 19:52:54 ----A---- C:\Windows\system32\mrt.exe
2010-04-06 19:39:35 ----D---- C:\Windows\Registration
2010-04-06 19:38:58 ----D---- C:\Program Files\Internet Explorer
2010-04-06 19:36:33 ----RSD---- C:\Windows\assembly
2010-04-05 16:29:34 ----D---- C:\ProgramData\TrackMania
2010-04-05 16:23:35 ----HD---- C:\ProgramData
2010-04-04 18:42:34 ----D---- C:\Windows\rescache
2010-04-04 12:02:49 ----D---- C:\Windows\system32\en-US
2010-04-04 12:02:49 ----D---- C:\Windows\system32\cs-CZ
2010-04-03 21:52:10 ----D---- C:\Program Files\Mozilla Firefox
2010-04-02 20:13:08 ----D---- C:\Program Files\TmUnitedForever

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-11-09 59388]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-18 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-27 909824]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-06-05 222208]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-11-01 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-11-01 208896]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-02-20 8726528]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-12-14 126976]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-06-10 123904]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-09-19 61952]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-17 199344]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 whfltr2k;WheelMouse USB Lower Filter Driver; C:\Windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-11-01 661504]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 LLRING0;LLRING0; \??\C:\Program Files\ZhyperMU\ZMU2010 GUARD R2\zhypermu muguard 2010 r2\MuGuard\llck2.sys [2010-04-07 4096]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 ImationButtonManagerService;Imation Button Manager Service; C:\Program Files\Imation Button Manager\Imation Button Manager Service.exe [2009-02-07 14336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 Recovery Service for Windows;Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [2008-10-06 365952]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-09-15 241734]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-01-12 185640]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-18 386560]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-07 135664]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-07 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-04-28 390952]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#2 Příspěvek od motji »

Hezký podvečer :)

Sem tam znamená co?

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#3 Příspěvek od rlipka »

Tak zde to je a předem diky :)
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4057

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904

1.5.2010 20:36:14
mbam-log-2010-05-01 (20-36-14).txt

Typ skenu: Rychlý sken
Skenované objekty: 122843
Uplynulý čas: 6 minuta(y), 10 sekunda(y)

Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 0
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 0

Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)

Infikované soubory:
(Žádné škodlivé položky nebyly zjištěny)

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#4 Příspěvek od rlipka »

používal jsem i uplny skener a napsalo to zadne hrozby :) ale ten sem omylem zastavil tak jsem tu poslal rychly nevadi to snad ze ne? (nebyl ale kompletni :D)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#5 Příspěvek od motji »

Nevadí. Ještě něco dočistíme, ale nejdřív se mrkněte do této složky
C:\Windows\Minidump
Pokud jsou tam nějaké soubory, pošlete je na www.leteckaposta.cz. Link vložte zde.
Při jaké činnosti jsou ty Modré smrti?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#6 Příspěvek od rlipka »

Žádné soubory tam nejsou,ale ty modré smrti jsou když jsem si stáhl klienta Mu online nainstaloval a zahrál si potom jsem ho vypnul a naráz mi to hodilo vždy při novém klientu jen poprvé

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#7 Příspěvek od motji »

Ještě pro jistotu

:arrow: Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe


- ComboFix je třeba spustit pod účtem s právy administrátora

- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary

- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano

- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna :!:

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#8 Příspěvek od rlipka »

ten klient byl Zhyper MU online nwm třeba to mají nějak buglé

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#9 Příspěvek od motji »

To je možné. Zkuste se s tímto problémem obrátit na nějaké herní forum :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#10 Příspěvek od rlipka »

ComboFix 10-05-01.01 - Robin 01.05.2010 21:11:24.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3002.1302 [GMT 2:00]
Spuštěný z: c:\users\Robin\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-3803943086-1902517587-741146281-500
c:\programdata\hpeED99.dll
c:\programdata\hpeFA46.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-01 do 2010-05-01 )))))))))))))))))))))))))))))))
.

2010-05-01 19:18 . 2010-05-01 19:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-01 16:43 . 2010-05-01 16:43 -------- d-----w- c:\users\Robin\AppData\Roaming\Malwarebytes
2010-05-01 16:43 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-01 16:43 . 2010-05-01 16:43 -------- d-----w- c:\programdata\Malwarebytes
2010-05-01 16:43 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-01 16:43 . 2010-05-01 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-01 15:24 . 2010-05-01 15:25 -------- d-----w- C:\rsit
2010-05-01 15:24 . 2010-05-01 15:25 -------- d-----w- c:\program files\trend micro
2010-04-27 15:16 . 2010-04-27 15:18 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-25 18:25 . 2010-04-25 18:26 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-04-25 18:24 . 2010-04-25 18:24 6404 ----a-w- c:\users\Robin\AppData\Local\d3d9caps.dat
2010-04-23 13:17 . 2010-05-01 10:53 -------- d-----w- c:\program files\ZhyperMU
2010-04-20 14:41 . 2010-04-20 14:41 -------- d-----w- c:\users\Robin\AppData\Roaming\Passware
2010-04-14 19:14 . 2010-02-18 14:07 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 19:14 . 2010-02-18 14:07 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 19:14 . 2010-02-23 11:10 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 19:14 . 2010-02-23 11:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 19:14 . 2010-02-23 11:10 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 19:14 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 19:14 . 2010-02-18 14:07 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 19:14 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 19:14 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 15:28 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 15:28 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-06 17:41 . 2010-04-06 17:41 -------- d-----w- c:\program files\Disc2Phone
2010-04-06 17:39 . 2010-04-08 13:29 -------- d-----w- c:\users\Robin\AppData\Local\ApplicationHistory
2010-04-06 17:39 . 2010-04-06 17:39 93 ----a-w- c:\users\Robin\AppData\Local\fusioncache.dat
2010-04-06 17:35 . 2010-04-06 17:35 -------- d-----w- c:\windows\system32\URTTEMP
2010-04-05 14:23 . 2010-04-05 14:27 -------- d-----w- c:\programdata\TmForever
2010-04-05 14:17 . 2010-04-05 14:23 -------- d-----w- c:\program files\TmNationsForever
2010-04-05 10:36 . 2010-04-05 10:36 -------- d-----w- c:\users\Robin\AppData\Local\NFS Underground 2
2010-04-03 17:14 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-04-02 20:31 . 2010-02-12 10:32 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-02 17:53 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-04-02 17:53 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 19:18 . 2010-03-07 17:36 -------- d-----w- c:\users\Robin\AppData\Roaming\Skype
2010-05-01 16:27 . 2010-03-13 13:24 -------- d-----w- c:\users\Robin\AppData\Roaming\vlc
2010-05-01 15:44 . 2010-03-07 19:03 -------- d-----w- c:\program files\Valve
2010-05-01 15:12 . 2010-03-07 17:37 -------- d-----w- c:\users\Robin\AppData\Roaming\skypePM
2010-05-01 15:11 . 2010-03-07 19:27 -------- d-----w- c:\program files\Steam
2010-05-01 10:53 . 2008-11-23 00:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-28 19:49 . 2010-03-07 19:28 -------- d-----w- c:\program files\Common Files\Steam
2010-04-28 19:28 . 2010-03-07 16:09 -------- d-----w- c:\program files\CCleaner
2010-04-27 17:52 . 2010-03-25 21:20 -------- d-----w- c:\users\Robin\AppData\Roaming\dvdcss
2010-04-25 18:23 . 2010-03-07 16:43 -------- d-----w- c:\program files\ESET
2010-04-23 12:46 . 2010-03-13 12:42 -------- d-----w- c:\program files\Empire Interactive
2010-04-20 20:02 . 2010-03-07 17:25 -------- d-----w- c:\users\Robin\AppData\Roaming\uTorrent
2010-04-20 12:20 . 2010-03-13 15:02 -------- d-----w- c:\programdata\POPWWPROFILES
2010-04-15 13:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-14 20:09 . 2010-03-21 13:10 -------- d-----w- c:\programdata\Microsoft Help
2010-04-14 18:44 . 2010-03-14 16:47 -------- d-----w- c:\program files\ICQ7.0
2010-04-14 17:09 . 2008-11-23 08:48 607526 ----a-w- c:\windows\system32\perfh005.dat
2010-04-14 17:09 . 2008-11-23 08:48 119944 ----a-w- c:\windows\system32\perfc005.dat
2010-04-05 14:29 . 2010-03-30 19:01 -------- d-----w- c:\programdata\TrackMania
2010-04-02 18:13 . 2010-03-13 16:03 -------- d-----w- c:\program files\TmUnitedForever
2010-03-31 16:22 . 2010-03-11 15:41 -------- d-----w- c:\program files\Counter-Strike Source
2010-03-30 17:50 . 2010-03-30 17:50 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-03-28 17:35 . 2010-03-14 16:47 -------- d-----w- c:\users\Robin\AppData\Roaming\ICQ
2010-03-27 18:46 . 2010-03-08 15:59 -------- d-----w- c:\program files\Ubisoft
2010-03-26 08:23 . 2010-03-07 15:22 107904 ----a-w- c:\users\Robin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-25 21:54 . 2010-03-07 15:18 -------- d-----w- c:\program files\Microsoft Works
2010-03-24 20:08 . 2010-03-24 18:39 -------- d-----w- c:\program files\PacSteamT
2010-03-24 18:39 . 2010-03-24 18:39 -------- d-----w- c:\program files\Common Files\Thraex Software
2010-03-23 15:18 . 2010-03-23 15:12 -------- d-----w- c:\program files\Sony Ericsson
2010-03-23 15:17 . 2010-03-23 15:17 -------- d-----w- c:\program files\Avanquest update
2010-03-23 15:16 . 2010-03-23 15:16 -------- d-----w- c:\programdata\BVRP Software
2010-03-23 15:12 . 2010-03-23 15:12 -------- d-----w- c:\programdata\Sony Ericsson
2010-03-21 20:32 . 2010-03-14 19:30 -------- d-----w- c:\program files\Warcraft III
2010-03-21 16:00 . 2010-03-21 15:31 -------- d-----w- c:\program files\Valve Hammer Editor
2010-03-21 13:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2010-03-21 13:14 . 2010-03-21 13:14 -------- d-----w- c:\program files\Microsoft.NET
2010-03-21 13:11 . 2010-03-21 13:11 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-03-18 20:27 . 2010-03-07 16:03 196640 ----a-w- c:\windows\War3Unin.dat
2010-03-18 20:27 . 2010-03-07 16:03 2829 ----a-w- c:\windows\War3Unin.pif
2010-03-18 20:27 . 2010-03-07 16:03 139264 ----a-w- c:\windows\War3Unin.exe
2010-03-18 19:35 . 2010-03-18 19:35 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-03-14 16:48 . 2010-03-14 16:48 -------- d-----w- c:\program files\ICQ6Toolbar
2010-03-14 16:48 . 2010-03-14 16:47 -------- d-----w- c:\programdata\ICQ
2010-03-13 15:54 . 2010-03-07 17:49 -------- d-----w- c:\users\Robin\AppData\Roaming\Ashampoo
2010-03-13 13:20 . 2010-03-13 13:20 -------- d-----w- c:\program files\VideoLAN
2010-03-13 12:48 . 2010-03-13 12:48 -------- d-----w- c:\programdata\InstallShield
2010-03-13 12:43 . 2008-11-23 00:39 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-12 22:04 . 2010-03-12 21:43 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-03-12 18:35 . 2010-03-12 18:35 -------- d-----w- c:\program files\Windows Portable Devices
2010-03-12 18:34 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-03-12 18:34 . 2010-03-12 18:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-03-12 18:33 . 2010-03-11 13:56 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-03-10 14:12 . 2008-11-23 01:58 588472 ----a-w- c:\windows\system32\ezsvc7x.dll
2010-03-09 13:27 . 2008-11-23 01:40 -------- d-----w- c:\programdata\CyberLink
2010-03-08 21:04 . 2010-03-08 21:04 -------- d-----w- c:\program files\MSXML 4.0
2010-03-08 17:27 . 2010-03-08 17:04 -------- d-----w- c:\users\Robin\AppData\Roaming\TeamViewer
2010-03-08 17:08 . 2010-03-08 17:08 -------- d-----w- c:\program files\PowerISO
2010-03-08 17:04 . 2010-03-08 17:04 -------- d-----w- c:\program files\TeamViewer
2010-03-08 17:02 . 2010-03-08 17:02 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-03-08 16:30 . 2010-03-08 16:30 -------- d-----w- c:\programdata\POP3Profiles
2010-03-07 20:12 . 2010-03-07 20:12 -------- d-----w- c:\program files\Common Files\Intel
2010-03-07 20:12 . 2010-03-07 14:53 -------- d-----w- c:\program files\Intel
2010-03-07 19:00 . 2010-03-07 19:00 -------- d-----w- c:\program files\ActiveX Control Pad
2010-03-07 19:00 . 2010-03-07 19:00 57344 ----a-w- c:\windows\system32\COMMTB32.DLL
2010-03-07 19:00 . 2010-03-07 19:00 169984 ----a-w- c:\windows\system32\P2D.DLL
2010-03-07 19:00 . 2010-03-07 19:00 161552 ----a-w- c:\windows\system32\ASYCPICT.DLL
2010-03-07 18:51 . 2010-03-07 18:51 -------- d-----w- c:\program files\uTorrent
2010-03-07 18:48 . 2008-11-23 01:59 -------- d-----w- c:\program files\Common Files\Java
2010-03-07 18:47 . 2010-03-07 18:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-07 18:47 . 2008-11-23 01:59 -------- d-----w- c:\program files\Java
2010-03-07 18:41 . 2010-03-07 18:41 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-07 18:30 . 2010-03-07 18:30 -------- d-----w- c:\programdata\Blizzard
2010-03-07 18:14 . 2010-03-07 18:14 -------- d-----w- c:\program files\Lavalys
2010-03-07 17:46 . 2010-03-07 17:46 -------- d-----w- c:\programdata\ashampoo
2010-03-07 17:46 . 2010-03-07 17:46 -------- d-----w- c:\programdata\page
2010-03-07 17:46 . 2010-03-07 17:46 -------- d-----w- c:\program files\Ashampoo
2010-03-07 17:33 . 2010-03-07 17:33 -------- d-----w- c:\program files\Google
2010-03-07 17:33 . 2010-03-07 17:32 -------- d-----r- c:\program files\Skype
2010-03-07 17:32 . 2010-03-07 17:32 -------- d-----w- c:\program files\Common Files\Skype
2010-03-07 17:32 . 2010-03-07 17:32 -------- d-----w- c:\programdata\Skype
2010-03-07 17:27 . 2010-03-07 17:27 -------- d-----w- c:\program files\Ask.com
2010-03-07 16:41 . 2010-03-07 16:41 -------- d-----w- c:\users\Robin\AppData\Roaming\ArcSoft
2010-03-07 16:40 . 2008-11-23 00:52 -------- d-----w- c:\programdata\Norton
2010-03-07 16:19 . 2008-11-23 00:52 -------- d-----w- c:\programdata\Symantec
2010-03-07 16:11 . 2010-03-07 16:11 -------- d-----w- c:\program files\Revo Uninstaller
2010-03-07 16:10 . 2010-03-07 16:10 -------- d-----w- c:\program files\Scorpions WinCheater
2010-03-07 16:08 . 2010-03-07 16:08 -------- d-----w- c:\program files\Imation Button Manager
2010-03-07 16:08 . 2010-03-07 16:08 -------- d-----w- c:\program files\ArcSoft
2010-03-07 15:21 . 2008-11-23 02:32 -------- d-----w- c:\program files\SMINST
2010-03-07 15:20 . 2010-03-07 15:20 -------- d-----w- c:\users\Robin\AppData\Roaming\Hewlett-Packard
2010-03-07 15:17 . 2010-03-07 15:17 -------- d-----w- c:\program files\MSN Messenger
2010-03-07 15:16 . 2010-03-07 15:16 0 --sha-r- c:\windows\system32\drivers\103C_HP_cNB_Presario CQ60 Notebook PC_Y5335KV_0U_Q2CE9055J8V_E508165-221_4A_I3612_SWistron_V09.48_F.32_T081120_WV3-1_L405_M3003_J250_7Intel_86FD_92.17_#100307_N10EC8136;168C001C_(NF200EA#AKB)_XMOBILE_CN10_Z.MRK
2010-03-07 15:15 . 2010-03-07 15:15 -------- d-sh--we c:\programdata\Šablony
2010-03-07 15:15 . 2010-03-07 15:15 -------- d-sh--we c:\programdata\Nabídka Start
2008-11-23 09:11 . 2008-11-23 08:53 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-09-02 13:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-07 39408]
"Steam"="c:\program files\steam\steam.exe" [2010-04-27 1238352]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Google Update"="c:\users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-18 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-06 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"WheelMouse"="c:\full-s~1\wh_exec.exe" [2008-10-08 98304]
"Imation Button Manager"="c:\program files\Imation Button Manager\Imation Button Manager.exe" [2009-02-07 385536]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-20 175640]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-20 167960]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup\uBBMonitor.exe [2010-3-7 315392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2a,5c,4b,94,97,c0,ca,01

R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 135664]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 LLRING0;LLRING0;c:\program files\ZhyperMU\ZMU2010 GUARD R2\zhypermu muguard 2010 r2\MuGuard\llck2.sys [2010-04-07 4096]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
S2 ImationButtonManagerService;Imation Button Manager Service;c:\program files\Imation Button Manager\Imation Button Manager Service.exe [2009-02-07 14336]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-01-12 185640]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-12-14 126976]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 17:33]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 17:33]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000Core.job
- c:\users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-29 19:43]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000UA.job
- c:\users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-29 19:43]

2010-04-06 c:\windows\Tasks\HPCeeScheduleForRobin.job
- c:\program files\Hewlett-Packard\SDP\ceement\HPCEE.exe [2008-11-23 16:34]

2010-05-01 c:\windows\Tasks\User_Feed_Synchronization-{D2314F70-64A9-4ECC-BBC8-CC32DFDAF9A4}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=cs_cz&c=91&bd=Presario&pf=cnnb
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\r77mwgfv.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=2.0.0.1&q=
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\Robin\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-TQ566808 - E:\Setup.exe
AddRemove-FlatOut Ultimate Carnage - c:\program files\Empire Interactive\FlatOut Ultimate Carnage\Uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 21:18
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-05-01 21:20:35
ComboFix-quarantined-files.txt 2010-05-01 19:20

Před spuštěním: Volných bajtů: 121 487 241 216
Po spuštění: Volných bajtů: 121 425 760 256

- - End Of File - - C82FB2C3A0637554A5B8C55E8C2C8A51

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#11 Příspěvek od motji »

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Folder::
c:\program files\Ask.com

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"=-
"UpdatePSTShortCut"=-
"UpdateP2GoShortCut"=-
"UpdatePDIRShortCut"=-
"SunJavaUpdateSched"=-

DDS::
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... io&pf=cnnb

Firefox::
FF - ProfilePath - c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\r77mwgfv.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.icq.com/
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... 2.0.0.1&q=
-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#12 Příspěvek od rlipka »

ComboFix 10-05-01.01 - Robin 01.05.2010 21:43:33.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.420.1029.18.3002.1337 [GMT 2:00]
Spuštěný z: c:\users\Robin\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Robin\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Ask.com
c:\program files\Ask.com\cobrand.ico
c:\program files\Ask.com\config.xml
c:\program files\Ask.com\favicon.ico
c:\program files\Ask.com\GenericAskToolbar.dll
c:\program files\Ask.com\mupcfg.xml
c:\program files\Ask.com\SaUpdate.exe
c:\program files\Ask.com\UpdateTask.exe

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-04-01 do 2010-05-01 )))))))))))))))))))))))))))))))
.

2010-05-01 19:49 . 2010-05-01 19:49 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-05-01 19:49 . 2010-05-01 19:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-01 16:43 . 2010-05-01 16:43 -------- d-----w- c:\users\Robin\AppData\Roaming\Malwarebytes
2010-05-01 16:43 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-01 16:43 . 2010-05-01 16:43 -------- d-----w- c:\programdata\Malwarebytes
2010-05-01 16:43 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-01 16:43 . 2010-05-01 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-01 15:24 . 2010-05-01 15:25 -------- d-----w- C:\rsit
2010-05-01 15:24 . 2010-05-01 15:25 -------- d-----w- c:\program files\trend micro
2010-04-27 15:16 . 2010-04-27 15:18 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-25 18:25 . 2010-04-25 18:26 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-04-25 18:24 . 2010-04-25 18:24 6404 ----a-w- c:\users\Robin\AppData\Local\d3d9caps.dat
2010-04-23 13:17 . 2010-05-01 10:53 -------- d-----w- c:\program files\ZhyperMU
2010-04-20 14:41 . 2010-04-20 14:41 -------- d-----w- c:\users\Robin\AppData\Roaming\Passware
2010-04-14 19:14 . 2010-02-18 14:07 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 19:14 . 2010-02-18 14:07 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 19:14 . 2010-02-23 11:10 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 19:14 . 2010-02-23 11:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 19:14 . 2010-02-23 11:10 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 19:14 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 19:14 . 2010-02-18 14:07 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 19:14 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 19:14 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 15:28 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 15:28 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-06 17:41 . 2010-04-06 17:41 -------- d-----w- c:\program files\Disc2Phone
2010-04-06 17:39 . 2010-04-08 13:29 -------- d-----w- c:\users\Robin\AppData\Local\ApplicationHistory
2010-04-06 17:39 . 2010-04-06 17:39 93 ----a-w- c:\users\Robin\AppData\Local\fusioncache.dat
2010-04-06 17:35 . 2010-04-06 17:35 -------- d-----w- c:\windows\system32\URTTEMP
2010-04-05 14:23 . 2010-04-05 14:27 -------- d-----w- c:\programdata\TmForever
2010-04-05 14:17 . 2010-04-05 14:23 -------- d-----w- c:\program files\TmNationsForever
2010-04-05 10:36 . 2010-04-05 10:36 -------- d-----w- c:\users\Robin\AppData\Local\NFS Underground 2
2010-04-03 17:14 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2010-04-02 20:31 . 2010-02-12 10:32 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-04-02 17:53 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2010-04-02 17:53 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-01 19:42 . 2010-03-07 17:36 -------- d-----w- c:\users\Robin\AppData\Roaming\Skype
2010-05-01 19:35 . 2010-03-07 16:43 -------- d-----w- c:\program files\ESET
2010-05-01 16:27 . 2010-03-13 13:24 -------- d-----w- c:\users\Robin\AppData\Roaming\vlc
2010-05-01 15:44 . 2010-03-07 19:03 -------- d-----w- c:\program files\Valve
2010-05-01 15:12 . 2010-03-07 17:37 -------- d-----w- c:\users\Robin\AppData\Roaming\skypePM
2010-05-01 15:11 . 2010-03-07 19:27 -------- d-----w- c:\program files\Steam
2010-05-01 10:53 . 2008-11-23 00:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-28 19:49 . 2010-03-07 19:28 -------- d-----w- c:\program files\Common Files\Steam
2010-04-28 19:28 . 2010-03-07 16:09 -------- d-----w- c:\program files\CCleaner
2010-04-27 17:52 . 2010-03-25 21:20 -------- d-----w- c:\users\Robin\AppData\Roaming\dvdcss
2010-04-23 12:46 . 2010-03-13 12:42 -------- d-----w- c:\program files\Empire Interactive
2010-04-20 20:02 . 2010-03-07 17:25 -------- d-----w- c:\users\Robin\AppData\Roaming\uTorrent
2010-04-20 12:20 . 2010-03-13 15:02 -------- d-----w- c:\programdata\POPWWPROFILES
2010-04-15 13:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-14 20:09 . 2010-03-21 13:10 -------- d-----w- c:\programdata\Microsoft Help
2010-04-14 18:44 . 2010-03-14 16:47 -------- d-----w- c:\program files\ICQ7.0
2010-04-14 17:09 . 2008-11-23 08:48 607526 ----a-w- c:\windows\system32\perfh005.dat
2010-04-14 17:09 . 2008-11-23 08:48 119944 ----a-w- c:\windows\system32\perfc005.dat
2010-04-05 14:29 . 2010-03-30 19:01 -------- d-----w- c:\programdata\TrackMania
2010-04-02 18:13 . 2010-03-13 16:03 -------- d-----w- c:\program files\TmUnitedForever
2010-03-31 16:22 . 2010-03-11 15:41 -------- d-----w- c:\program files\Counter-Strike Source
2010-03-30 17:50 . 2010-03-30 17:50 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-03-28 17:35 . 2010-03-14 16:47 -------- d-----w- c:\users\Robin\AppData\Roaming\ICQ
2010-03-27 18:46 . 2010-03-08 15:59 -------- d-----w- c:\program files\Ubisoft
2010-03-26 08:23 . 2010-03-07 15:22 107904 ----a-w- c:\users\Robin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-25 21:54 . 2010-03-07 15:18 -------- d-----w- c:\program files\Microsoft Works
2010-03-24 20:08 . 2010-03-24 18:39 -------- d-----w- c:\program files\PacSteamT
2010-03-24 18:39 . 2010-03-24 18:39 -------- d-----w- c:\program files\Common Files\Thraex Software
2010-03-23 15:18 . 2010-03-23 15:12 -------- d-----w- c:\program files\Sony Ericsson
2010-03-23 15:17 . 2010-03-23 15:17 -------- d-----w- c:\program files\Avanquest update
2010-03-23 15:16 . 2010-03-23 15:16 -------- d-----w- c:\programdata\BVRP Software
2010-03-23 15:12 . 2010-03-23 15:12 -------- d-----w- c:\programdata\Sony Ericsson
2010-03-21 20:32 . 2010-03-14 19:30 -------- d-----w- c:\program files\Warcraft III
2010-03-21 16:00 . 2010-03-21 15:31 -------- d-----w- c:\program files\Valve Hammer Editor
2010-03-21 13:16 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2010-03-21 13:14 . 2010-03-21 13:14 -------- d-----w- c:\program files\Microsoft.NET
2010-03-21 13:11 . 2010-03-21 13:11 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-03-18 20:27 . 2010-03-07 16:03 196640 ----a-w- c:\windows\War3Unin.dat
2010-03-18 20:27 . 2010-03-07 16:03 2829 ----a-w- c:\windows\War3Unin.pif
2010-03-18 20:27 . 2010-03-07 16:03 139264 ----a-w- c:\windows\War3Unin.exe
2010-03-18 19:35 . 2010-03-18 19:35 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-03-14 16:48 . 2010-03-14 16:48 -------- d-----w- c:\program files\ICQ6Toolbar
2010-03-14 16:48 . 2010-03-14 16:47 -------- d-----w- c:\programdata\ICQ
2010-03-13 15:54 . 2010-03-07 17:49 -------- d-----w- c:\users\Robin\AppData\Roaming\Ashampoo
2010-03-13 13:20 . 2010-03-13 13:20 -------- d-----w- c:\program files\VideoLAN
2010-03-13 12:48 . 2010-03-13 12:48 -------- d-----w- c:\programdata\InstallShield
2010-03-13 12:43 . 2008-11-23 00:39 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-12 22:04 . 2010-03-12 21:43 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-03-12 18:35 . 2010-03-12 18:35 -------- d-----w- c:\program files\Windows Portable Devices
2010-03-12 18:34 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-03-12 18:34 . 2010-03-12 18:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-03-12 18:33 . 2010-03-11 13:56 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-03-10 21:15 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-03-10 14:12 . 2008-11-23 01:58 588472 ----a-w- c:\windows\system32\ezsvc7x.dll
2010-03-09 13:27 . 2008-11-23 01:40 -------- d-----w- c:\programdata\CyberLink
2010-03-08 21:04 . 2010-03-08 21:04 -------- d-----w- c:\program files\MSXML 4.0
2010-03-08 17:27 . 2010-03-08 17:04 -------- d-----w- c:\users\Robin\AppData\Roaming\TeamViewer
2010-03-08 17:08 . 2010-03-08 17:08 -------- d-----w- c:\program files\PowerISO
2010-03-08 17:04 . 2010-03-08 17:04 -------- d-----w- c:\program files\TeamViewer
2010-03-08 17:02 . 2010-03-08 17:02 515848 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-03-08 16:30 . 2010-03-08 16:30 -------- d-----w- c:\programdata\POP3Profiles
2010-03-07 20:12 . 2010-03-07 20:12 -------- d-----w- c:\program files\Common Files\Intel
2010-03-07 20:12 . 2010-03-07 14:53 -------- d-----w- c:\program files\Intel
2010-03-07 19:00 . 2010-03-07 19:00 -------- d-----w- c:\program files\ActiveX Control Pad
2010-03-07 19:00 . 2010-03-07 19:00 57344 ----a-w- c:\windows\system32\COMMTB32.DLL
2010-03-07 19:00 . 2010-03-07 19:00 169984 ----a-w- c:\windows\system32\P2D.DLL
2010-03-07 19:00 . 2010-03-07 19:00 161552 ----a-w- c:\windows\system32\ASYCPICT.DLL
2010-03-07 18:51 . 2010-03-07 18:51 -------- d-----w- c:\program files\uTorrent
2010-03-07 18:48 . 2008-11-23 01:59 -------- d-----w- c:\program files\Common Files\Java
2010-03-07 18:47 . 2010-03-07 18:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-07 18:47 . 2008-11-23 01:59 -------- d-----w- c:\program files\Java
2010-03-07 18:41 . 2010-03-07 18:41 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-07 18:30 . 2010-03-07 18:30 -------- d-----w- c:\programdata\Blizzard
2010-03-07 18:14 . 2010-03-07 18:14 -------- d-----w- c:\program files\Lavalys
2010-03-07 17:46 . 2010-03-07 17:46 -------- d-----w- c:\programdata\ashampoo
2010-03-07 17:46 . 2010-03-07 17:46 -------- d-----w- c:\programdata\page
2010-03-07 17:46 . 2010-03-07 17:46 -------- d-----w- c:\program files\Ashampoo
2010-03-07 17:33 . 2010-03-07 17:33 -------- d-----w- c:\program files\Google
2010-03-07 17:33 . 2010-03-07 17:32 -------- d-----r- c:\program files\Skype
2010-03-07 17:32 . 2010-03-07 17:32 -------- d-----w- c:\program files\Common Files\Skype
2010-03-07 17:32 . 2010-03-07 17:32 -------- d-----w- c:\programdata\Skype
2010-03-07 16:41 . 2010-03-07 16:41 -------- d-----w- c:\users\Robin\AppData\Roaming\ArcSoft
2010-03-07 16:40 . 2008-11-23 00:52 -------- d-----w- c:\programdata\Norton
2010-03-07 16:19 . 2008-11-23 00:52 -------- d-----w- c:\programdata\Symantec
2010-03-07 16:11 . 2010-03-07 16:11 -------- d-----w- c:\program files\Revo Uninstaller
2010-03-07 16:10 . 2010-03-07 16:10 -------- d-----w- c:\program files\Scorpions WinCheater
2010-03-07 16:08 . 2010-03-07 16:08 -------- d-----w- c:\program files\Imation Button Manager
2010-03-07 16:08 . 2010-03-07 16:08 -------- d-----w- c:\program files\ArcSoft
2010-03-07 15:21 . 2008-11-23 02:32 -------- d-----w- c:\program files\SMINST
2010-03-07 15:20 . 2010-03-07 15:20 -------- d-----w- c:\users\Robin\AppData\Roaming\Hewlett-Packard
2010-03-07 15:17 . 2010-03-07 15:17 -------- d-----w- c:\program files\MSN Messenger
2010-03-07 15:16 . 2010-03-07 15:16 0 --sha-r- c:\windows\system32\drivers\103C_HP_cNB_Presario CQ60 Notebook PC_Y5335KV_0U_Q2CE9055J8V_E508165-221_4A_I3612_SWistron_V09.48_F.32_T081120_WV3-1_L405_M3003_J250_7Intel_86FD_92.17_#100307_N10EC8136;168C001C_(NF200EA#AKB)_XMOBILE_CN10_Z.MRK
2010-03-07 15:15 . 2010-03-07 15:15 -------- d-sh--we c:\programdata\Šablony
2010-03-07 15:15 . 2010-03-07 15:15 -------- d-sh--we c:\programdata\Nabídka Start
2010-03-07 15:15 . 2010-03-07 15:15 -------- d-sh--we c:\programdata\Plocha
2008-11-23 09:11 . 2008-11-23 08:53 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2010-05-01_19.18.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2010-03-07 14:48 . 2010-05-01 19:07 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-03-07 14:48 . 2010-05-01 19:21 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-03-07 14:48 . 2010-05-01 19:21 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-03-07 14:48 . 2010-05-01 19:07 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-03-07 14:48 . 2010-05-01 19:21 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-03-07 14:48 . 2010-05-01 19:07 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-07 39408]
"Steam"="c:\program files\steam\steam.exe" [2010-04-27 1238352]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Google Update"="c:\users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-18 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-23 468264]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"WheelMouse"="c:\full-s~1\wh_exec.exe" [2008-10-08 98304]
"Imation Button Manager"="c:\program files\Imation Button Manager\Imation Button Manager.exe" [2009-02-07 385536]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-02-20 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-02-20 175640]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-02-20 167960]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup\uBBMonitor.exe [2010-3-7 315392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):2a,5c,4b,94,97,c0,ca,01

R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 135664]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R3 LLRING0;LLRING0;c:\program files\ZhyperMU\ZMU2010 GUARD R2\zhypermu muguard 2010 r2\MuGuard\llck2.sys [2010-04-07 4096]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
S2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
S2 ImationButtonManagerService;Imation Button Manager Service;c:\program files\Imation Button Manager\Imation Button Manager Service.exe [2009-02-07 14336]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-01-12 185640]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-12-14 126976]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 17:33]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-07 17:33]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000Core.job
- c:\users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-29 19:43]

2010-05-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000UA.job
- c:\users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-29 19:43]

2010-04-06 c:\windows\Tasks\HPCeeScheduleForRobin.job
- c:\program files\Hewlett-Packard\SDP\ceement\HPCEE.exe [2008-11-23 16:34]

2010-05-01 c:\windows\Tasks\User_Feed_Synchronization-{D2314F70-64A9-4ECC-BBC8-CC32DFDAF9A4}.job
- c:\windows\system32\msfeedssync.exe [2010-03-31 04:54]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Hledání panelu &AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\cs-CZ\local\search.html
IE: WikiKomentáře Google... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\r77mwgfv.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\Robin\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-01 21:49
Windows 6.0.6002 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Celkový čas: 2010-05-01 21:51:52
ComboFix-quarantined-files.txt 2010-05-01 19:51
ComboFix2.txt 2010-05-01 19:20

Před spuštěním: Volných bajtů: 121 305 300 992
Po spuštění: Volných bajtů: 121 301 557 248

- - End Of File - - FEBA1A58C751FA27EB5A407F82AD5706

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#13 Příspěvek od motji »

:arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:

ComboFix /Uninstall

-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.


***********


:arrow: Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe

-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir



***********


:arrow: Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

Obrázekzáložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

Obrázekzáložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy :arrow: ok :arrow: zavřít

Obrázek Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.

Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.


***********



:arrow: Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech



***********

:arrow: Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

rlipka
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 01 kvě 2010 16:20

Re: Modre smrti

#14 Příspěvek od rlipka »

Tak vám děkuji za Vaši pomoc,počítač vypadá dobře a tu je ten log
Logfile of random's system information tool 1.06 (written by random/random)
Run by Robin at 2010-05-01 22:32:02
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 120 GB (52%) free of 230 GB
Total RAM: 3002 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:01, on 1.5.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Full-size Mouse\wh_exec.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Robin\AppData\Local\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Robin\Desktop\RSIT.exe
C:\Program Files\trend micro\Robin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\2.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WheelMouse] C:\FULL-S~1\wh_exec.exe
O4 - HKLM\..\Run: [Imation Button Manager] "C:\Program Files\Imation Button Manager\Imation Button Manager.exe" -A
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup\uBBMonitor.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Hledání panelu &AOL Toolbar - C:\ProgramData\AOL\ieToolbar\resources\cs-CZ\local\search.html
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} (SysInfo Class) - http://content.systemrequirementslab.co ... 1.71.0.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Imation Button Manager Service (ImationButtonManagerService) - Imation Corp. - C:\Program Files\Imation Button Manager\Imation Button Manager Service.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10177 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3803943086-1902517587-741146281-1000UA.job
C:\Windows\tasks\HPCeeScheduleForRobin.job
C:\Windows\tasks\User_Feed_Synchronization-{D2314F70-64A9-4ECC-BBC8-CC32DFDAF9A4}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}]
AOL Toolbar BHO - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-03-07 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-03-07 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-07 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{DE9C389F-3316-41A7-809B-AA305ED9D922} - AOL Toolbar - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll [2008-07-02 1185120]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-03-07 279664]
{855F3B16-6D32-4FE6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2010-01-03 1019128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2008-04-17 1049896]
"QPService"=C:\Program Files\HP\QuickPlay\QPService.exe [2008-09-23 468264]
"UCam_Menu"=C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [2007-12-24 222504]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"QlbCtrl.exe"=C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-08-01 202032]
"HP Health Check Scheduler"=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-10-09 75008]
"HP Software Update"=C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"hpWirelessAssistant"=C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2008-04-15 488752]
"WheelMouse"=C:\FULL-S~1\wh_exec.exe [2008-10-08 98304]
"Imation Button Manager"=C:\Program Files\Imation Button Manager\Imation Button Manager.exe [2009-02-07 385536]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-02-20 141848]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-02-20 175640]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-02-20 167960]
"PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2009-11-09 180224]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]
"MSSE"=c:\Program Files\Microsoft Security Essentials\msseces.exe [2010-02-21 1093208]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"=C:\Program Files\MSN Messenger\MsnMsgr.Exe [2007-01-19 5674352]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-03-07 39408]
"Steam"=c:\program files\steam\steam.exe [2010-04-27 1238352]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"Google Update"=C:\Users\Robin\AppData\Local\Google\Update\GoogleUpdate.exe [2010-03-18 136176]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup\uBBMonitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-02-20 227328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 months======

2010-05-01 22:32:01 ----D---- C:\rsit
2010-05-01 21:51:56 ----SHD---- C:\$RECYCLE.BIN
2010-05-01 21:51:54 ----D---- C:\Windows\temp
2010-05-01 21:09:53 ----D---- C:\Windows\ERDNT
2010-05-01 18:43:45 ----D---- C:\Users\Robin\AppData\Roaming\Malwarebytes
2010-05-01 18:43:29 ----D---- C:\ProgramData\Malwarebytes
2010-05-01 18:43:28 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-01 17:24:26 ----D---- C:\Program Files\trend micro
2010-04-27 17:16:46 ----D---- C:\Program Files\Common Files\Adobe
2010-04-27 17:16:46 ----D---- C:\Program Files\Adobe
2010-04-26 21:57:05 ----D---- C:\Config.Msi
2010-04-25 20:25:39 ----D---- C:\Program Files\Microsoft Security Essentials
2010-04-23 16:05:21 ----D---- C:\Windows\Minidump
2010-04-23 15:17:12 ----D---- C:\Program Files\ZhyperMU
2010-04-20 16:41:51 ----D---- C:\Users\Robin\AppData\Roaming\Passware
2010-04-14 21:14:58 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-04-14 21:14:57 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-04-14 21:14:47 ----A---- C:\Windows\system32\vbscript.dll
2010-04-14 21:14:08 ----A---- C:\Windows\system32\iphlpsvc.dll
2010-04-14 17:28:07 ----A---- C:\Windows\system32\wintrust.dll
2010-04-14 17:28:04 ----A---- C:\Windows\system32\cabview.dll
2010-04-06 19:41:21 ----D---- C:\Program Files\Disc2Phone
2010-04-06 19:35:37 ----D---- C:\Windows\system32\URTTEMP
2010-04-05 16:23:35 ----D---- C:\ProgramData\TmForever
2010-04-05 16:17:58 ----D---- C:\Program Files\TmNationsForever
2010-04-03 19:14:39 ----A---- C:\Windows\system32\winhttp.dll
2010-04-02 22:31:20 ----A---- C:\Windows\system32\browserchoice.exe
2010-04-02 19:53:34 ----A---- C:\Windows\system32\schannel.dll
2010-04-02 19:53:34 ----A---- C:\Windows\system32\kerberos.dll

======List of files/folders modified in the last 1 months======

2010-05-01 22:30:18 ----D---- C:\Program Files\Common Files\Steam
2010-05-01 22:30:17 ----A---- C:\ProgramData\hpqp.ini
2010-05-01 22:29:52 ----D---- C:\Program Files\Steam
2010-05-01 22:27:31 ----D---- C:\Users\Robin\AppData\Roaming\Skype
2010-05-01 22:24:31 ----D---- C:\Windows
2010-05-01 22:12:19 ----SHD---- C:\System Volume Information
2010-05-01 21:58:13 ----D---- C:\Users\Robin\AppData\Roaming\skypePM
2010-05-01 21:49:39 ----A---- C:\Windows\system.ini
2010-05-01 21:49:04 ----RD---- C:\Program Files
2010-05-01 21:46:13 ----D---- C:\Windows\system32\drivers
2010-05-01 21:46:13 ----D---- C:\Windows\System32
2010-05-01 21:46:13 ----D---- C:\Windows\AppPatch
2010-05-01 21:46:12 ----D---- C:\Program Files\Common Files
2010-05-01 21:35:50 ----D---- C:\Program Files\ESET
2010-05-01 21:17:39 ----D---- C:\ProgramData
2010-05-01 18:27:26 ----D---- C:\Users\Robin\AppData\Roaming\vlc
2010-05-01 17:44:25 ----D---- C:\Program Files\Valve
2010-05-01 17:21:37 ----D---- C:\Windows\Prefetch
2010-05-01 12:53:39 ----HD---- C:\Program Files\InstallShield Installation Information
2010-04-30 17:48:32 ----D---- C:\Windows\system32\catroot2
2010-04-28 21:30:28 ----D---- C:\Windows\Debug
2010-04-28 21:28:43 ----D---- C:\Program Files\CCleaner
2010-04-28 20:09:34 ----D---- C:\Windows\system32\WDI
2010-04-28 16:55:13 ----RSD---- C:\Windows\Fonts
2010-04-28 16:37:11 ----D---- C:\Windows\winsxs
2010-04-28 15:44:38 ----D---- C:\Windows\system32\catroot
2010-04-27 19:52:56 ----D---- C:\Users\Robin\AppData\Roaming\dvdcss
2010-04-27 17:19:20 ----SHD---- C:\Windows\Installer
2010-04-27 17:16:57 ----D---- C:\ProgramData\Adobe
2010-04-25 20:25:51 ----SD---- C:\ProgramData\Microsoft
2010-04-23 14:46:54 ----D---- C:\Program Files\Empire Interactive
2010-04-20 22:02:21 ----D---- C:\Users\Robin\AppData\Roaming\uTorrent
2010-04-20 16:44:22 ----SD---- C:\Users\Robin\AppData\Roaming\Microsoft
2010-04-20 16:24:12 ----D---- C:\Windows\system32\Tasks
2010-04-20 14:20:26 ----D---- C:\ProgramData\POPWWPROFILES
2010-04-17 22:43:10 ----D---- C:\Windows\SoftwareDistribution
2010-04-15 15:46:26 ----D---- C:\Program Files\Windows Mail
2010-04-14 22:09:26 ----D---- C:\ProgramData\Microsoft Help
2010-04-14 20:44:34 ----D---- C:\Program Files\ICQ7.0
2010-04-14 19:09:44 ----D---- C:\Windows\inf
2010-04-14 19:09:44 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-04-06 19:52:54 ----A---- C:\Windows\system32\mrt.exe
2010-04-06 19:39:35 ----D---- C:\Windows\Registration
2010-04-06 19:38:58 ----D---- C:\Program Files\Internet Explorer
2010-04-06 19:36:33 ----RSD---- C:\Windows\assembly
2010-04-05 16:29:34 ----D---- C:\ProgramData\TrackMania
2010-04-04 18:42:34 ----D---- C:\Windows\rescache
2010-04-04 12:02:49 ----D---- C:\Windows\system32\en-US
2010-04-04 12:02:49 ----D---- C:\Windows\system32\cs-CZ
2010-04-03 21:52:10 ----D---- C:\Program Files\Mozilla Firefox
2010-04-02 20:13:08 ----D---- C:\Program Files\TmUnitedForever

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-12-02 149040]
R1 SCDEmu;SCDEmu; C:\Windows\system32\drivers\SCDEmu.sys [2009-11-09 59388]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-18 8704]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-27 909824]
R3 CmBatt;Ovladač baterie Microsoft ACPI Control Method Battery; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT32.sys [2008-06-05 222208]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [2007-06-18 16768]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-11-01 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-11-01 208896]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2010-02-20 8726528]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-12-14 126976]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2008-06-10 123904]
R3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2008-09-19 61952]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2008-04-17 199344]
R3 usbvideo;Zobrazovací zařízení USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
R3 whfltr2k;WheelMouse USB Lower Filter Driver; C:\Windows\system32\DRIVERS\whfltr2k.sys [2007-01-25 6784]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-11-01 661504]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 LLRING0;LLRING0; \??\C:\Program Files\ZhyperMU\ZMU2010 GUARD R2\zhypermu muguard 2010 r2\MuGuard\llck2.sys [2010-04-07 4096]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ezSharedSvc;Easybits Shared Services for Windows; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-10-09 94208]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2010-01-03 246520]
R2 ImationButtonManagerService;Imation Button Manager Service; C:\Program Files\Imation Button Manager\Imation Button Manager Service.exe [2009-02-07 14336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2009-12-09 17904]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 Recovery Service for Windows;Recovery Service for Windows; C:\Program Files\SMINST\BLService.exe [2008-10-06 365952]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo.exe [2008-09-15 241734]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-01-12 185640]
R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-18 386560]
R3 Com4QLBEx;Com4QLBEx; C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R3 hpqwmiex;hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [2008-05-01 165192]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-03-07 135664]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-03-30 31048]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-07 182768]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2010-05-01 390952]
S3 usnjsvc;Služba Čtení deníku USN sdílených složek programu Messenger; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Modre smrti

#15 Příspěvek od motji »

:arrow: Otevřete si Poznámkový blok a zkopírujte do něj text

Kód: Vybrat vše

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=-
"Imation Button Manager"=-
"GrooveMonitor"=-
"Adobe Reader Speed Launcher"=-
"Adobe ARM"=-

 
-uložte jako (typ: všechny soubory) kde za název souboru zadáte "smazani.reg" bez uvozovek,
klikněte na uložit, pak na soubor standardně 2X klikněte a potvrďte dialogové okno.


:arrow: Pokud nejsou problémy, je to vše :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět