Stránka 1 z 2

Prosim o preventivku

Napsal: 06 čer 2010 12:58
od ReZisten
Příde mi že počítač je pomalejší...
Zde je log z RSITu:
Logfile of random's system information tool 1.07 (written by random/random)
Run by Radka at 2010-06-06 13:56:39
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 7 GB (44%) free of 15 GB
Total RAM: 1015 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:56:51, on 6.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
C:\WINDOWS\system32\svchost.exe
D:\Programy\COMODO\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\ATK Hotkey\MsgTranAgt.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Firebird\bin\fbguard.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\Firebird\bin\fbserver.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ATK Hotkey\WDC.exe
D:\Programy\COMODO\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Programy\QIP\qip.exe
D:\Staženo\RSIT.exe
C:\Program Files\trend micro\Radka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HopSurf toolbar - {E9FAB13D-4600-49E1-90D1-EE961C859D39} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O4 - HKLM\..\Run: [ATKHOTKEY] "C:\Program Files\ATK Hotkey\Hcontrol.exe"
O4 - HKLM\..\Run: [MsgTranAgt] "C:\Program Files\ATK Hotkey\MsgTranAgt.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "D:\Programy\COMODO\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: HopSurf - {ED98F8D1-09AC-4107-B2FF-91DBE011B0C5} - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll
O9 - Extra button: QIP 2005 - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP\qip.exe (file missing) (HKCU)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlcdnet.asus.com/pub/ASUS/misc/d ... .2.5.0.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 2843863390
O17 - HKLM\System\CCS\Services\Tcpip\..\{34DAE7A0-17AC-4717-8461-29CF0002C457}: NameServer = 1.1.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8ED2E5D7-6A00-438C-96AD-2CDF05ADEB53}: NameServer = 156.154.70.22,156.154.71.22
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - D:\Programy\COMODO\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\bin\fbserver.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - Unknown owner - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe (file missing)
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 8212 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Automatic troubleshooting.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E9FAB13D-4600-49E1-90D1-EE961C859D39} - HopSurf toolbar - C:\Program Files\Comodo\HopSurfToolbar\HopSurfToolbar_IE.dll [2010-06-05 1331392]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"=C:\Program Files\ATK Hotkey\Hcontrol.exe [2007-11-28 229376]
"MsgTranAgt"=C:\Program Files\ATK Hotkey\MsgTranAgt.exe [2007-11-04 106496]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2007-10-17 7737344]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2006-05-25 786521]
"Power_Gear"=C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe [2006-07-26 90112]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-04-11 16861184]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-04 69632]
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-02-11 2756488]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2008-04-13 208952]
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2008-04-13 59392]
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-13 455168]
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2008-04-13 455168]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"NPSStartup"= []
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-11-08 141848]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-11-08 166424]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-11-08 137752]
"COMODO Internet Security"=D:\Programy\COMODO\COMODO\COMODO Internet Security\cfp.exe [2010-04-09 2029456]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
C:\WINDOWS\RTHDCPL.EXE [2008-04-11 16861184]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2007-11-21 1826816]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [2006-11-22 630784]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-09 148888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-10-30 208896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WINDOW~4\MpShHook.dll [2006-11-03 83224]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CLPSLS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoActiveDesktopChanges"=0
"NoActiveDesktop"=0x01000000
"NoNetworkConnections"=0x01000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet.exe"
"C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
"C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
"D:\Hry\WoW\World of Warcraft\BackgroundDownloader.exe"="D:\Hry\WoW\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"D:\Programy\QIP\qip.exe"="D:\Programy\QIP\qip.exe:*:Disabled:Quiet Internet Pager"
"D:\Programy\Xfire\Xfire.exe"="D:\Programy\Xfire\Xfire.exe:*:Enabled:Xfire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======File associations======

.ini - open - notepad.exe %1
.js - edit -
.js - open -
.txt - open - notepad.exe %1

======List of files/folders created in the last 1 months======

2010-06-06 13:55:24 ----D---- C:\Program Files\trend micro
2010-06-06 13:55:21 ----D---- C:\rsit
2010-06-05 15:42:10 ----HD---- C:\VritualRoot
2010-06-05 15:37:15 ----D---- C:\Documents and Settings\Radka\Data aplikací\Comodo
2010-06-05 15:36:39 ----D---- C:\Program Files\Comodo
2010-06-05 15:35:34 ----D---- C:\Documents and Settings\All Users\Data aplikací\Comodo Downloader
2010-06-05 15:26:31 ----D---- C:\Documents and Settings\All Users\Data aplikací\COMODO
2010-06-04 17:44:29 ----A---- C:\WINDOWS\system32\msxml4a.dll
2010-06-04 17:44:22 ----D---- C:\Program Files\Common Files\SourceTec
2010-06-04 17:43:57 ----D---- C:\Program Files\SourceTec
2010-06-04 16:58:54 ----D---- C:\Documents and Settings\Radka\Data aplikací\Opera
2010-06-01 19:21:52 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-06-01 19:21:44 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-29 16:30:36 ----A---- C:\WINDOWS\War3Unin.exe
2010-05-18 16:39:59 ----N---- C:\WINDOWS\system32\iyvu9_32.dll
2010-05-18 16:39:58 ----N---- C:\WINDOWS\system32\iacenc.dll
2010-05-16 14:08:42 ----D---- C:\Programy na odstranění virů
2010-05-16 11:58:50 ----A---- C:\WINDOWS\system32\igfxres.dll
2010-05-15 20:28:29 ----A---- C:\WINDOWS\system32\write.exe.lnk
2010-05-15 17:19:07 ----A---- C:\WINDOWS\system32\psisdecd.dll
2010-05-15 17:19:01 ----A---- C:\WINDOWS\system32\dxdllreg.exe
2010-05-15 16:58:56 ----A---- C:\WINDOWS\level.ini
2010-05-15 11:56:10 ----A---- C:\WINDOWS\system32\CmdLineExt.dll

======List of files/folders modified in the last 1 months======

2010-06-06 13:56:49 ----D---- C:\TEMP
2010-06-06 13:55:24 ----AD---- C:\Program Files
2010-06-06 13:39:57 ----D---- C:\Program Files\Mozilla Firefox
2010-06-06 10:59:55 ----D---- C:\WINDOWS
2010-06-06 09:36:23 ----SD---- C:\WINDOWS\Tasks
2010-06-06 09:34:18 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-05 23:17:00 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-06-05 19:15:49 ----D---- C:\WINDOWS\Prefetch
2010-06-05 16:36:00 ----D---- C:\WINDOWS\system32
2010-06-05 16:08:33 ----D---- C:\WINDOWS\Temp
2010-06-05 15:39:55 ----SHD---- C:\WINDOWS\Installer
2010-06-05 15:39:13 ----D---- C:\WINDOWS\system32\drivers
2010-06-05 15:37:07 ----HD---- C:\WINDOWS\inf
2010-06-05 15:20:57 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-05 15:09:10 ----D---- C:\Program Files\AIMP2
2010-06-05 11:25:51 ----D---- C:\WINDOWS\Debug
2010-06-04 17:44:22 ----D---- C:\Program Files\Common Files
2010-06-03 19:37:49 ----D---- C:\WINDOWS\security
2010-06-01 20:05:32 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-01 19:21:47 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-01 19:21:47 ----D---- C:\Program Files\Outlook Express
2010-06-01 17:53:41 ----D---- C:\WINDOWS\Minidump
2010-05-29 18:31:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-28 21:16:38 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-21 14:14:28 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-05-20 12:51:56 ----D---- C:\Documents and Settings\Radka\Data aplikací\DivX
2010-05-18 16:38:30 ----RSD---- C:\WINDOWS\Fonts
2010-05-16 11:56:58 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-15 17:19:51 ----D---- C:\WINDOWS\RegisteredPackages
2010-05-15 17:18:35 ----D---- C:\WINDOWS\system32\DirectX
2010-05-15 10:48:23 ----D---- C:\Documents and Settings
2010-05-14 15:22:35 ----RSD---- C:\WINDOWS\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-02-11 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2010-04-09 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-04-09 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-04-09 25240]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2004-08-09 53920]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-02-11 100432]
R2 rimmptsk;rimmptsk; C:\WINDOWS\system32\DRIVERS\rimmptsk.sys [2007-08-08 45568]
R2 rimsptsk;rimsptsk; C:\WINDOWS\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
R3 AR5211;Atheros Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2007-10-25 549184]
R3 ASNDIS5;ASNDIS5 Protocol Driver; \??\C:\PROGRA~1\ATKHOT~1\ASNDIS5.SYS []
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-02-11 23376]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-10-30 5851488]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-04-18 4707328]
R3 kbfiltr;Keyboard Filter; C:\WINDOWS\system32\DRIVERS\kbfiltr.sys [2007-01-24 5632]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ATKACPI.sys [2007-08-24 5760]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2008-06-27 10368]
R3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2007-07-12 96384]
R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2006-11-22 982272]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2006-05-25 193088]
R3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2009-10-14 32000]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
S3 arf16wew;arf16wew; C:\WINDOWS\system32\drivers\arf16wew.sys []
S3 GarenaPEngine;GarenaPEngine; \??\C:\Temp\THL1.tmp []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-03-31 25280]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2003-03-09 51024]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2003-03-09 16080]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2003-03-09 21456]
S3 NE2000;NE2000 Compatible PCMCIA; C:\WINDOWS\system32\DRIVERS\ne2000.sys [2001-08-17 15872]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 sffdisk;Ovladač třídy úložiště SFF; C:\WINDOWS\system32\DRIVERS\sffdisk.sys [2008-04-14 11904]
S3 sffp_sd;Ovladač protokolu úložiště SFF pro paměť sběrnici SDBus; C:\WINDOWS\system32\DRIVERS\sffp_sd.sys [2008-04-14 11008]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S3 XDva349;XDva349; \??\C:\WINDOWS\system32\XDva349.sys []
S4 exFat;exFat; C:\WINDOWS\system32\drivers\exFat.sys [2008-09-29 133632]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R2 CLPSLS;COMODO livePCsupport Service; C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe [2010-02-19 148744]
R2 cmdAgent;COMODO Internet Security Helper Service; D:\Programy\COMODO\COMODO\COMODO Internet Security\cmdagent.exe [2010-04-09 1769216]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files\Firebird\bin\fbguard.exe [2007-12-12 65536]
R2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-12-18 1044808]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files\Firebird\bin\fbserver.exe [2007-12-12 1531989]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-01 271920]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe []
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-09 152984]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-06-28 79136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: Prosim o preventivku

Napsal: 06 čer 2010 13:16
od 1danab
zdravím :)
stáhněte a uložte nejlépe na plochu ComboFix

spusťte aplikaci pod účtem s administrátorským oprávněním
po startu se zobrazí obrazovka s licenčními podmínkami, klikněte na tlačítko Ano:

Obrázek

může dojít k varování ohledně rezidentního štítu Vašeho antiviru a upozornění na nenainstalovanou konzoli pro zotavení; zatím jí neinstalujte

sken trvá cca 10 minut (může trvat i déle, podle množství souborů a rychlosti pc); během skenu nespouštějte žádné aplikace

během skenování může být Vaše pc restartováno, proto nepropadejte panice

upozornění: pokud používate antispyware s rezidentním štítem, deaktivujte jeho rezidentní štít, protože dochází při skenu a výmazu případného malware k nežádoucím kolizím Combofixu s rezidentem antispyware

po restartování vytvoří aplikace log, uložený na C:/Combofix.txt jeho obsah vložte sem

Re: Prosim o preventivku

Napsal: 06 čer 2010 13:43
od ReZisten
Jen připomínám, že poté co to došlo k fázy 50, tak to napsalo že konzole se zachvilku vypne, a bude log uložen, ale místo toho, se oběvilla modrá obrazovka, a že jestli je to poprvé co se zobrazila modrá obrazovka, tak at to vypnu a atd...
Zde je log:

ComboFix 10-06-05.02 - Radka 06.06.2010 14:28:15.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.579 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Radka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-05-06 do 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-06 11:55:24 . 2010-06-06 11:56:50 -------- d-----w- C:\Program Files\trend micro
2010-06-06 11:55:21 . 2010-06-06 11:55:53 -------- d-----w- C:\rsit
2010-06-06 11:51:14 . 2010-06-06 12:06:12 -------- d-----w- C:\temp\plugtmp-1
2010-06-05 14:50:09 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\{60807984-2F02-4DBE-B395-7BFCF0B3AACE}
2010-06-05 13:42:10 . 2010-06-05 13:42:10 -------- d-----w- C:\VritualRoot
2010-06-05 13:36:39 . 2010-06-05 13:37:35 -------- d-----w- C:\Program Files\Comodo
2010-06-05 13:36:39 . 2009-10-14 17:08:32 32000 ----a-w- C:\WINDOWS\system32\drivers\tap0901.sys
2010-06-05 13:35:34 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\{EC625D54-75D9-41AF-9F51-460F61DACF70}
2010-06-05 13:13:42 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\{040BA912-7D59-4EDB-82A8-691435384B61}
2010-06-05 11:16:35 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\plugtmp
2010-06-04 15:44:29 . 2007-09-27 06:00:00 44544 ----a-w- C:\WINDOWS\system32\msxml4a.dll
2010-06-04 15:44:22 . 2010-06-04 15:44:22 -------- d-----w- C:\Program Files\Common Files\SourceTec
2010-06-04 15:43:57 . 2010-06-04 15:43:57 -------- d-----w- C:\Program Files\SourceTec
2010-05-29 14:30:37 . 2010-05-29 16:14:13 79711 ----a-w- C:\WINDOWS\War3Unin.dat
2010-05-29 14:30:36 . 2010-05-29 14:38:54 2829 ----a-w- C:\WINDOWS\War3Unin.pif
2010-05-29 14:30:36 . 2010-05-29 14:38:54 139264 ----a-w- C:\WINDOWS\War3Unin.exe
2010-05-18 14:39:59 . 1997-06-13 15:56:08 56832 ------w- C:\WINDOWS\system32\iyvu9_32.dll
2010-05-18 14:39:58 . 1998-05-07 17:57:22 143872 ------w- C:\WINDOWS\system32\iacenc.dll
2010-05-16 12:08:42 . 2010-06-06 11:53:32 -------- d-----w- C:\Programy na odstranění virů
2010-05-16 09:58:50 . 2007-10-30 05:43:24 176128 ----a-w- C:\WINDOWS\system32\igfxres.dll
2010-05-15 15:18:59 . 2003-05-30 07:00:02 1189888 -c--a-w- C:\WINDOWS\system32\dllcache\dx8vb.dll
2010-05-15 09:56:10 . 2010-05-15 09:56:10 98304 ----a-w- C:\WINDOWS\system32\CmdLineExt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 12:18:40 . 2010-04-05 15:03:26 1474832 ----a-w- C:\WINDOWS\system32\drivers\sfi.dat
2010-06-05 13:20:57 . 2010-02-28 14:18:39 -------- d-----w- C:\Program Files\TuneUp Utilities 2010
2010-06-05 13:09:10 . 2010-02-28 14:10:51 -------- d-----w- C:\Program Files\AIMP2
2010-05-29 16:31:31 . 2008-06-26 16:13:02 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2010-05-21 12:14:28 . 2010-02-28 14:49:15 221568 ------w- C:\WINDOWS\system32\MpSigStub.exe
2010-04-26 14:29:26 . 2010-04-26 14:29:26 -------- d-----w- C:\Program Files\Common Files\Blizzard Entertainment
2010-04-19 17:57:55 . 2010-04-14 11:18:52 -------- d-----w- C:\Program Files\Common Files\Macromedia
2010-04-19 17:57:50 . 2010-04-14 11:18:52 -------- d-----w- C:\Program Files\Macromedia
2010-04-15 18:21:50 . 2010-04-15 18:20:09 -------- d-----w- C:\Program Files\DIFX
2010-04-15 18:21:29 . 2010-04-15 18:18:57 -------- d-----w- C:\Program Files\PC Connectivity Solution
2010-04-15 17:59:15 . 2010-04-15 17:59:15 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-04-08 23:26:12 . 2010-04-08 23:26:12 277240 ----a-w- C:\WINDOWS\system32\guard32.dll
2010-04-08 23:25:48 . 2010-04-08 23:25:48 86800 ----a-w- C:\WINDOWS\system32\drivers\inspect.sys
2010-04-08 23:25:46 . 2010-04-08 23:25:46 25240 ----a-w- C:\WINDOWS\system32\drivers\cmdhlp.sys
2010-04-08 23:25:46 . 2010-04-08 23:25:46 225344 ----a-w- C:\WINDOWS\system32\drivers\cmdGuard.sys
2010-04-08 23:25:44 . 2010-04-08 23:25:44 15464 ----a-w- C:\WINDOWS\system32\drivers\cmderd.sys
2010-04-08 09:13:52 . 2010-04-05 15:17:54 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2010-03-31 21:41:00 . 2010-03-31 21:41:00 25280 ----a-w- C:\WINDOWS\system32\drivers\hamachi.sys
2010-03-31 18:17:33 . 2006-03-02 12:00:00 90530 ----a-w- C:\WINDOWS\system32\perfc005.dat
2010-03-31 18:17:33 . 2006-03-02 12:00:00 472488 ----a-w- C:\WINDOWS\system32\perfh005.dat
2010-03-13 16:38:35 . 2010-01-16 15:37:50 691696 ----a-w- C:\WINDOWS\system32\drivers\sptd.sys
2010-03-13 16:19:19 . 2009-11-13 21:40:35 41 ----a-w- C:\Documents and Settings\Radka\jagex_runescape_preferences.dat
2010-03-13 16:19:17 . 2009-11-13 21:42:56 63 ----a-w- C:\Documents and Settings\Radka\jagex_runescape_preferences2.dat
2010-03-10 06:17:40 . 2006-03-02 12:00:00 420352 ----a-w- C:\WINDOWS\system32\vbscript.dll
.

------- Sigcheck -------

[-] 2010-02-28 18:05:55 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\system32\appmgmts.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"="C:\Program Files\ATK Hotkey\Hcontrol.exe" [2007-11-28 15:39:36 229376]
"MsgTranAgt"="C:\Program Files\ATK Hotkey\MsgTranAgt.exe" [2007-11-04 17:48:06 106496]
"ATKOSD2"="C:\Program Files\ATKOSD2\ATKOSD2.exe" [2007-10-17 17:04:00 7737344]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 12:02:04 786521]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 16:01:06 90112]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20:12 866584]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 23:52:00 16861184]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 16:31:26 630784]
"avast5"="C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 18:53:42 2756488]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 20:13:52 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-13 20:13:38 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 20:13:54 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 20:13:54 455168]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-11-08 13:56:42 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-11-08 07:56:12 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-11-08 07:56:20 137752]
"COMODO Internet Security"="D:\Programy\COMODO\COMODO\COMODO Internet Security\cfp.exe" [2010-04-08 23:26:02 2029456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 06:52:18 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoNetworkConnections"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\guard32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 06:52:18 15360 ----a-w- C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-04-10 23:52:00 16861184 ----a-w- C:\WINDOWS\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-11-21 01:15:00 1826816 ----a-w- C:\WINDOWS\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2006-11-22 16:31:26 630784 ----a-w- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 03:19:17 148888 ----a-w- C:\Program Files\Java\jre6\bin\jusched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="C:\Program Files\ICQ7.0\ICQ.exe" silent loginmode=4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Programy\\QIP\\qip.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19887:TCP"= 19887:TCP:BitComet 19887 TCP
"19887:UDP"= 19887:UDP:BitComet 19887 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 aswSP;aswSP;C:\WINDOWS\system32\drivers\aswSP.sys [27.6.2008 18:51:42 162512]
R1 cmderd;COMODO Internet Security Eradication Driver;C:\WINDOWS\system32\drivers\cmderd.sys [9.4.2010 1:25:44 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\system32\drivers\cmdGuard.sys [9.4.2010 1:25:46 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\WINDOWS\system32\drivers\cmdhlp.sys [9.4.2010 1:25:46 25240]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [27.6.2008 18:51:42 19024]
R2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\Comodo\COMODO livePCsupport\CLPSLS.exe [19.2.2010 17:00:24 148744]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;C:\Program Files\Firebird\bin\fbguard.exe -s --> C:\Program Files\Firebird\bin\fbguard.exe -s [?]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [15.4.2010 20:20:00 233472]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 1:12:10 1044808]
R2 WinDefend;Windows Defender;C:\Program Files\Windows Defender\MsMpEng.exe [3.11.2006 20:19:58 13592]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;C:\Program Files\Firebird\bin\fbserver.exe -s --> C:\Program Files\Firebird\bin\fbserver.exe -s [?]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [15.4.2010 20:20:00 36608]
S0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [16.1.2010 17:37:50 691696]
S3 GarenaPEngine;GarenaPEngine;\??\C:\Temp\THL1.tmp --> C:\Temp\THL1.tmp [?]
S3 NE2000;NE2000 Compatible PCMCIA;C:\WINDOWS\system32\drivers\ne2000.sys [23.10.2009 18:12:02 15872]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);C:\WINDOWS\system32\drivers\ss_bbus.sys [15.4.2010 20:21:04 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);C:\WINDOWS\system32\drivers\ss_bmdfl.sys [15.4.2010 20:21:04 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;C:\WINDOWS\system32\drivers\ss_bmdm.sys [15.4.2010 20:21:04 121856]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys --> C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [?]
S3 XDva349;XDva349;\??\C:\WINDOWS\system32\XDva349.sys --> C:\WINDOWS\system32\XDva349.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 10:47:34 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-06-06 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20:06 . 2006-11-03 18:20:06]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Office Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {34DAE7A0-17AC-4717-8461-29CF0002C457} = 1.1.1.1
TCP: {8ED2E5D7-6A00-438C-96AD-2CDF05ADEB53} = 156.154.70.22,156.154.71.22
FF - ProfilePath - C:\Documents and Settings\Radka\Data aplikací\Mozilla\Firefox\Profiles\m8you27d.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
.
------- Asociace souborů -------
.
.txt=UltraEdit.txt
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-NPSStartup - (no file)
AddRemove-Little Italy Park Mod 2 - Den - D:\Hry\Mafia\Odinstalovat Little Italy Park Mod 2-den.exe
AddRemove-QIP 2005 - C:\Program Files\QIP\unins000.exe

Re: Prosim o preventivku

Napsal: 06 čer 2010 14:04
od 1danab
ten log není celý...zkopírujte a vložte ho sem celý

Re: Prosim o preventivku

Napsal: 06 čer 2010 14:07
od ReZisten
Zde to je:

ComboFix 10-06-05.02 - Radka 06.06.2010 14:28:15.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.579 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\Radka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-05-06 do 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-06 11:55:24 . 2010-06-06 11:56:50 -------- d-----w- C:\Program Files\trend micro
2010-06-06 11:55:21 . 2010-06-06 11:55:53 -------- d-----w- C:\rsit
2010-06-06 11:51:14 . 2010-06-06 12:06:12 -------- d-----w- C:\temp\plugtmp-1
2010-06-05 14:50:09 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\{60807984-2F02-4DBE-B395-7BFCF0B3AACE}
2010-06-05 13:42:10 . 2010-06-05 13:42:10 -------- d-----w- C:\VritualRoot
2010-06-05 13:36:39 . 2010-06-05 13:37:35 -------- d-----w- C:\Program Files\Comodo
2010-06-05 13:36:39 . 2009-10-14 17:08:32 32000 ----a-w- C:\WINDOWS\system32\drivers\tap0901.sys
2010-06-05 13:35:34 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\{EC625D54-75D9-41AF-9F51-460F61DACF70}
2010-06-05 13:13:42 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\{040BA912-7D59-4EDB-82A8-691435384B61}
2010-06-05 11:16:35 . 2010-06-06 12:31:56 -------- d-----w- C:\temp\plugtmp
2010-06-04 15:44:29 . 2007-09-27 06:00:00 44544 ----a-w- C:\WINDOWS\system32\msxml4a.dll
2010-06-04 15:44:22 . 2010-06-04 15:44:22 -------- d-----w- C:\Program Files\Common Files\SourceTec
2010-06-04 15:43:57 . 2010-06-04 15:43:57 -------- d-----w- C:\Program Files\SourceTec
2010-05-29 14:30:37 . 2010-05-29 16:14:13 79711 ----a-w- C:\WINDOWS\War3Unin.dat
2010-05-29 14:30:36 . 2010-05-29 14:38:54 2829 ----a-w- C:\WINDOWS\War3Unin.pif
2010-05-29 14:30:36 . 2010-05-29 14:38:54 139264 ----a-w- C:\WINDOWS\War3Unin.exe
2010-05-18 14:39:59 . 1997-06-13 15:56:08 56832 ------w- C:\WINDOWS\system32\iyvu9_32.dll
2010-05-18 14:39:58 . 1998-05-07 17:57:22 143872 ------w- C:\WINDOWS\system32\iacenc.dll
2010-05-16 12:08:42 . 2010-06-06 11:53:32 -------- d-----w- C:\Programy na odstranění virů
2010-05-16 09:58:50 . 2007-10-30 05:43:24 176128 ----a-w- C:\WINDOWS\system32\igfxres.dll
2010-05-15 15:18:59 . 2003-05-30 07:00:02 1189888 -c--a-w- C:\WINDOWS\system32\dllcache\dx8vb.dll
2010-05-15 09:56:10 . 2010-05-15 09:56:10 98304 ----a-w- C:\WINDOWS\system32\CmdLineExt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 12:18:40 . 2010-04-05 15:03:26 1474832 ----a-w- C:\WINDOWS\system32\drivers\sfi.dat
2010-06-05 13:20:57 . 2010-02-28 14:18:39 -------- d-----w- C:\Program Files\TuneUp Utilities 2010
2010-06-05 13:09:10 . 2010-02-28 14:10:51 -------- d-----w- C:\Program Files\AIMP2
2010-05-29 16:31:31 . 2008-06-26 16:13:02 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2010-05-21 12:14:28 . 2010-02-28 14:49:15 221568 ------w- C:\WINDOWS\system32\MpSigStub.exe
2010-04-26 14:29:26 . 2010-04-26 14:29:26 -------- d-----w- C:\Program Files\Common Files\Blizzard Entertainment
2010-04-19 17:57:55 . 2010-04-14 11:18:52 -------- d-----w- C:\Program Files\Common Files\Macromedia
2010-04-19 17:57:50 . 2010-04-14 11:18:52 -------- d-----w- C:\Program Files\Macromedia
2010-04-15 18:21:50 . 2010-04-15 18:20:09 -------- d-----w- C:\Program Files\DIFX
2010-04-15 18:21:29 . 2010-04-15 18:18:57 -------- d-----w- C:\Program Files\PC Connectivity Solution
2010-04-15 17:59:15 . 2010-04-15 17:59:15 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-04-08 23:26:12 . 2010-04-08 23:26:12 277240 ----a-w- C:\WINDOWS\system32\guard32.dll
2010-04-08 23:25:48 . 2010-04-08 23:25:48 86800 ----a-w- C:\WINDOWS\system32\drivers\inspect.sys
2010-04-08 23:25:46 . 2010-04-08 23:25:46 25240 ----a-w- C:\WINDOWS\system32\drivers\cmdhlp.sys
2010-04-08 23:25:46 . 2010-04-08 23:25:46 225344 ----a-w- C:\WINDOWS\system32\drivers\cmdGuard.sys
2010-04-08 23:25:44 . 2010-04-08 23:25:44 15464 ----a-w- C:\WINDOWS\system32\drivers\cmderd.sys
2010-04-08 09:13:52 . 2010-04-05 15:17:54 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2010-03-31 21:41:00 . 2010-03-31 21:41:00 25280 ----a-w- C:\WINDOWS\system32\drivers\hamachi.sys
2010-03-31 18:17:33 . 2006-03-02 12:00:00 90530 ----a-w- C:\WINDOWS\system32\perfc005.dat
2010-03-31 18:17:33 . 2006-03-02 12:00:00 472488 ----a-w- C:\WINDOWS\system32\perfh005.dat
2010-03-13 16:38:35 . 2010-01-16 15:37:50 691696 ----a-w- C:\WINDOWS\system32\drivers\sptd.sys
2010-03-13 16:19:19 . 2009-11-13 21:40:35 41 ----a-w- C:\Documents and Settings\Radka\jagex_runescape_preferences.dat
2010-03-13 16:19:17 . 2009-11-13 21:42:56 63 ----a-w- C:\Documents and Settings\Radka\jagex_runescape_preferences2.dat
2010-03-10 06:17:40 . 2006-03-02 12:00:00 420352 ----a-w- C:\WINDOWS\system32\vbscript.dll
.

------- Sigcheck -------

[-] 2010-02-28 18:05:55 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\system32\appmgmts.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"="C:\Program Files\ATK Hotkey\Hcontrol.exe" [2007-11-28 15:39:36 229376]
"MsgTranAgt"="C:\Program Files\ATK Hotkey\MsgTranAgt.exe" [2007-11-04 17:48:06 106496]
"ATKOSD2"="C:\Program Files\ATKOSD2\ATKOSD2.exe" [2007-10-17 17:04:00 7737344]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 12:02:04 786521]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 16:01:06 90112]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20:12 866584]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 23:52:00 16861184]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 16:31:26 630784]
"avast5"="C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 18:53:42 2756488]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 20:13:52 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-13 20:13:38 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 20:13:54 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 20:13:54 455168]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-11-08 13:56:42 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-11-08 07:56:12 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-11-08 07:56:20 137752]
"COMODO Internet Security"="D:\Programy\COMODO\COMODO\COMODO Internet Security\cfp.exe" [2010-04-08 23:26:02 2029456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 06:52:18 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoNetworkConnections"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\guard32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 06:52:18 15360 ----a-w- C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-04-10 23:52:00 16861184 ----a-w- C:\WINDOWS\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-11-21 01:15:00 1826816 ----a-w- C:\WINDOWS\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2006-11-22 16:31:26 630784 ----a-w- C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 03:19:17 148888 ----a-w- C:\Program Files\Java\jre6\bin\jusched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="C:\Program Files\ICQ7.0\ICQ.exe" silent loginmode=4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"D:\\Programy\\QIP\\qip.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19887:TCP"= 19887:TCP:BitComet 19887 TCP
"19887:UDP"= 19887:UDP:BitComet 19887 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 aswSP;aswSP;C:\WINDOWS\system32\drivers\aswSP.sys [27.6.2008 18:51:42 162512]
R1 cmderd;COMODO Internet Security Eradication Driver;C:\WINDOWS\system32\drivers\cmderd.sys [9.4.2010 1:25:44 15464]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\WINDOWS\system32\drivers\cmdGuard.sys [9.4.2010 1:25:46 225344]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\WINDOWS\system32\drivers\cmdhlp.sys [9.4.2010 1:25:46 25240]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [27.6.2008 18:51:42 19024]
R2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\Comodo\COMODO livePCsupport\CLPSLS.exe [19.2.2010 17:00:24 148744]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;C:\Program Files\Firebird\bin\fbguard.exe -s --> C:\Program Files\Firebird\bin\fbguard.exe -s [?]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [15.4.2010 20:20:00 233472]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 1:12:10 1044808]
R2 WinDefend;Windows Defender;C:\Program Files\Windows Defender\MsMpEng.exe [3.11.2006 20:19:58 13592]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;C:\Program Files\Firebird\bin\fbserver.exe -s --> C:\Program Files\Firebird\bin\fbserver.exe -s [?]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [15.4.2010 20:20:00 36608]
S0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [16.1.2010 17:37:50 691696]
S3 GarenaPEngine;GarenaPEngine;\??\C:\Temp\THL1.tmp --> C:\Temp\THL1.tmp [?]
S3 NE2000;NE2000 Compatible PCMCIA;C:\WINDOWS\system32\drivers\ne2000.sys [23.10.2009 18:12:02 15872]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);C:\WINDOWS\system32\drivers\ss_bbus.sys [15.4.2010 20:21:04 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);C:\WINDOWS\system32\drivers\ss_bmdfl.sys [15.4.2010 20:21:04 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;C:\WINDOWS\system32\drivers\ss_bmdm.sys [15.4.2010 20:21:04 121856]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys --> C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [?]
S3 XDva349;XDva349;\??\C:\WINDOWS\system32\XDva349.sys --> C:\WINDOWS\system32\XDva349.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 10:47:34 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-06-06 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20:06 . 2006-11-03 18:20:06]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Office Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {34DAE7A0-17AC-4717-8461-29CF0002C457} = 1.1.1.1
TCP: {8ED2E5D7-6A00-438C-96AD-2CDF05ADEB53} = 156.154.70.22,156.154.71.22
FF - ProfilePath - C:\Documents and Settings\Radka\Data aplikací\Mozilla\Firefox\Profiles\m8you27d.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
.
------- Asociace souborů -------
.
.txt=UltraEdit.txt
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

HKLM-Run-NPSStartup - (no file)
AddRemove-Little Italy Park Mod 2 - Den - D:\Hry\Mafia\Odinstalovat Little Italy Park Mod 2-den.exe
AddRemove-QIP 2005 - C:\Program Files\QIP\unins000.exe

Re: Prosim o preventivku

Napsal: 06 čer 2010 14:21
od 1danab
log stále není celý, chybí Vám tam konec logu :)

Re: Prosim o preventivku

Napsal: 06 čer 2010 14:24
od ReZisten
Promiňte, ale nic víc mi to nevygenerovalo...

Re: Prosim o preventivku

Napsal: 06 čer 2010 14:28
od 1danab
udělejte to celé znovu, ale v nouzovém režimu :)

Re: Prosim o preventivku

Napsal: 06 čer 2010 15:37
od ReZisten
Zde to je:

ComboFix 10-06-05.02 - Radka 06.06.2010 16:26:48.3.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1250.420.1029.18.1015.675 [GMT 2:00]
Spuštěný z: c:\documents and settings\Radka\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning disabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.

((((((((((((((((((((((((( Soubory vytvořené od 2010-05-06 do 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-06 14:09 . 2010-06-06 14:29 -------- d-----w- c:\temp\plugtmp-3
2010-06-06 12:45 . 2010-06-06 12:45 -------- d-----w- c:\temp\Comodo
2010-06-06 12:39 . 2010-06-06 14:03 -------- d-----w- c:\temp\plugtmp-2
2010-06-06 11:55 . 2010-06-06 11:56 -------- d-----w- c:\program files\trend micro
2010-06-06 11:55 . 2010-06-06 11:55 -------- d-----w- C:\rsit
2010-06-06 11:51 . 2010-06-06 12:06 -------- d-----w- c:\temp\plugtmp-1
2010-06-05 14:50 . 2010-06-06 12:31 -------- d-----w- c:\temp\{60807984-2F02-4DBE-B395-7BFCF0B3AACE}
2010-06-05 13:42 . 2010-06-05 13:42 -------- d-----w- C:\VritualRoot
2010-06-05 13:36 . 2010-06-05 13:37 -------- d-----w- c:\program files\Comodo
2010-06-05 13:36 . 2009-10-14 17:08 32000 ----a-w- c:\windows\system32\drivers\tap0901.sys
2010-06-05 13:35 . 2010-06-06 12:31 -------- d-----w- c:\temp\{EC625D54-75D9-41AF-9F51-460F61DACF70}
2010-06-05 13:13 . 2010-06-06 12:31 -------- d-----w- c:\temp\{040BA912-7D59-4EDB-82A8-691435384B61}
2010-06-05 11:16 . 2010-06-06 12:31 -------- d-----w- c:\temp\plugtmp
2010-06-04 15:44 . 2007-09-27 06:00 44544 ----a-w- c:\windows\system32\msxml4a.dll
2010-06-04 15:44 . 2010-06-04 15:44 -------- d-----w- c:\program files\Common Files\SourceTec
2010-06-04 15:43 . 2010-06-04 15:43 -------- d-----w- c:\program files\SourceTec
2010-05-29 14:30 . 2010-05-29 16:14 79711 ----a-w- c:\windows\War3Unin.dat
2010-05-29 14:30 . 2010-05-29 14:38 2829 ----a-w- c:\windows\War3Unin.pif
2010-05-29 14:30 . 2010-05-29 14:38 139264 ----a-w- c:\windows\War3Unin.exe
2010-05-18 14:39 . 1997-06-13 15:56 56832 ------w- c:\windows\system32\iyvu9_32.dll
2010-05-18 14:39 . 1998-05-07 17:57 143872 ------w- c:\windows\system32\iacenc.dll
2010-05-16 12:08 . 2010-06-06 11:53 -------- d-----w- C:\Programy na odstranění virů
2010-05-16 09:58 . 2007-10-30 05:43 176128 ----a-w- c:\windows\system32\igfxres.dll
2010-05-15 15:18 . 2003-05-30 07:00 1189888 -c--a-w- c:\windows\system32\dllcache\dx8vb.dll
2010-05-15 09:56 . 2010-05-15 09:56 98304 ----a-w- c:\windows\system32\CmdLineExt.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 13:46 . 2010-04-05 15:03 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-06-05 13:20 . 2010-02-28 14:18 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-05 13:09 . 2010-02-28 14:10 -------- d-----w- c:\program files\AIMP2
2010-05-29 16:31 . 2008-06-26 16:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-21 12:14 . 2010-02-28 14:49 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-04-26 14:29 . 2010-04-26 14:29 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-04-19 17:57 . 2010-04-14 11:18 -------- d-----w- c:\program files\Common Files\Macromedia
2010-04-19 17:57 . 2010-04-14 11:18 -------- d-----w- c:\program files\Macromedia
2010-04-15 18:21 . 2010-04-15 18:20 -------- d-----w- c:\program files\DIFX
2010-04-15 18:21 . 2010-04-15 18:18 -------- d-----w- c:\program files\PC Connectivity Solution
2010-04-15 17:59 . 2010-04-15 17:59 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-08 23:26 . 2010-04-08 23:26 277240 ----a-w- c:\windows\system32\guard32.dll
2010-04-08 23:25 . 2010-04-08 23:25 86800 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-04-08 23:25 . 2010-04-08 23:25 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-04-08 23:25 . 2010-04-08 23:25 225344 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-04-08 23:25 . 2010-04-08 23:25 15464 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-04-08 09:13 . 2010-04-05 15:17 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-03-31 21:41 . 2010-03-31 21:41 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2010-03-31 18:17 . 2006-03-02 12:00 90530 ----a-w- c:\windows\system32\perfc005.dat
2010-03-31 18:17 . 2006-03-02 12:00 472488 ----a-w- c:\windows\system32\perfh005.dat
2010-03-13 16:38 . 2010-01-16 15:37 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-03-13 16:19 . 2009-11-13 21:40 41 ----a-w- c:\documents and settings\Radka\jagex_runescape_preferences.dat
2010-03-13 16:19 . 2009-11-13 21:42 63 ----a-w- c:\documents and settings\Radka\jagex_runescape_preferences2.dat
2010-03-10 06:17 . 2006-03-02 12:00 420352 ----a-w- c:\windows\system32\vbscript.dll
.

------- Sigcheck -------

[-] 2010-02-28 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180] . . c:\windows\system32\appmgmts.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKHOTKEY"="c:\program files\ATK Hotkey\Hcontrol.exe" [2007-11-28 229376]
"MsgTranAgt"="c:\program files\ATK Hotkey\MsgTranAgt.exe" [2007-11-04 106496]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2007-10-17 7737344]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 786521]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-07-26 90112]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-13 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 455168]
"NPSStartup"="" [BU]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-11-08 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-11-08 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-11-08 137752]
"COMODO Internet Security"="d:\programy\COMODO\COMODO\COMODO Internet Security\cfp.exe" [2010-04-08 2029456]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoNetworkConnections"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 06:52 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-04-10 23:52 16861184 ----a-w- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-11-21 01:15 1826816 ----a-w- c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2006-11-22 16:31 630784 ----a-w- c:\program files\Motorola\SMSERIAL\sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 03:19 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ICQ"="c:\program files\ICQ7.0\ICQ.exe" silent loginmode=4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Programy\\QIP\\qip.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19887:TCP"= 19887:TCP:BitComet 19887 TCP
"19887:UDP"= 19887:UDP:BitComet 19887 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows\system32\drivers\cmderd.sys [9.4.2010 1:25 15464]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9.4.2010 1:25 25240]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\Comodo\COMODO livePCsupport\CLPSLS.exe [19.2.2010 17:00 148744]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 20:19 13592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16.1.2010 17:37 691696]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [27.6.2008 18:51 162512]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [9.4.2010 1:25 225344]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27.6.2008 18:51 19024]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\bin\fbguard.exe -s --> c:\program files\Firebird\bin\fbguard.exe -s [?]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [15.4.2010 20:20 233472]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [18.12.2009 1:12 1044808]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\bin\fbserver.exe -s --> c:\program files\Firebird\bin\fbserver.exe -s [?]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [15.4.2010 20:20 36608]
S3 GarenaPEngine;GarenaPEngine;\??\c:\temp\THL1.tmp --> c:\temp\THL1.tmp [?]
S3 NE2000;NE2000 Compatible PCMCIA;c:\windows\system32\drivers\ne2000.sys [23.10.2009 18:12 15872]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [15.4.2010 20:21 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [15.4.2010 20:21 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [15.4.2010 20:21 121856]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;\??\c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys --> c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [?]
S3 XDva349;XDva349;\??\c:\windows\system32\XDva349.sys --> c:\windows\system32\XDva349.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 10:47 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Obsah adresáře 'Naplánované úlohy'

2010-06-06 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {34DAE7A0-17AC-4717-8461-29CF0002C457} = 1.1.1.1
TCP: {8ED2E5D7-6A00-438C-96AD-2CDF05ADEB53} = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\documents and settings\Radka\Data aplikací\Mozilla\Firefox\Profiles\m8you27d.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz/
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
.
------- Asociace souborů -------
.
.txt=UltraEdit.txt
.

**************************************************************************
skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\temp\THL1.tmp"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(1220)
c:\windows\system32\ac3filter.acm
.
Celkový čas: 2010-06-06 16:31:01
ComboFix-quarantined-files.txt 2010-06-06 14:30

Před spuštěním: 6 876 160 000
Po spuštění: 6 832 893 952

- - End Of File - - F6ACF6ECC3852A7E2BE39BA8CAF2F01B

Re: Prosim o preventivku

Napsal: 06 čer 2010 21:22
od 1danab
c:\windows\system32\appmgmts.dll
c:\windows\system32\XDva349.sys

otestujte na VIRUSTOTALu

jednoduchý návod: po načtení stránky, kliknout na Procházet, najít cestu k výše zmíněnému souboru a kliknout na tlačítko Odeslat soubor; pokud vyskočí hláška, že soubor byl už testován, ignorujte to a proveďte sken znova; po ukončení skenu sem vložte výsledky buď zkopírováním textu nebo vložením odkazu

Re: Prosim o preventivku

Napsal: 07 čer 2010 15:43
od ReZisten
Odkaz na appmgmts.dll : http://www.virustotal.com/cs/analisis/a ... 1275921436


A ten druhý soubor XDva349.sys jsem bohužel nenašel.. Skoušel jsem i vyhledávání a ani počítač nic nenašel :X

Re: Prosim o preventivku

Napsal: 07 čer 2010 19:26
od 1danab
ten první je ok...u toho druhého, máte zapnuté zobrazování skrytých a systémových souborů?

Re: Prosim o preventivku

Napsal: 10 čer 2010 16:51
od ReZisten
to nevim... a kde se to kdyžtak zapíná/vypíná?

Re: Prosim o preventivku

Napsal: 10 čer 2010 18:58
od 1danab
v průzkumníku - Nástroje-Možnosti složky, karta Zobrazení, najdete Zobrazovat skryté soubory a složky a zaskrtnete :)

Re: Prosim o preventivku

Napsal: 14 čer 2010 12:49
od ReZisten
celou dobu jsem to měl zaplé ;-)