
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Avast5 hlásí Zablokován škodlivý URL
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Avast5 hlásí Zablokován škodlivý URL
Zdravím,
potřeboval bych poradit s následujícím problémem. Do počítače se mi dostalo 27 infikovaných souborů. Smazáno testem po restartu počítače, ale nespíš něco ještě zůstalo, jelikož mi rezidentní štít avast5 hlásí zablokovám škodlivý URL. Zkontroluje mi někdo LOG z RSIT prosím ?
Logfile of random's system information tool 1.07 (written by random/random)
Run by Uživatel at 2010-06-07 13:19:54
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 134 GB (88%) free of 153 GB
Total RAM: 2047 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:20:05, on 7.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\svc.exe
C:\WINDOWS\svw.exe
C:\WINDOWS\servicelayer.exe
C:\WINDOWS\ctfmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Documents and Settings\Uživatel\Plocha\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Reader 8.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [netc] C:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [netw] C:\WINDOWS\svw.exe
O4 - HKLM\..\Run: [servicelayer] C:\WINDOWS\servicelayer.exe
O4 - HKLM\..\Run: [ctfmon] C:\WINDOWS\ctfmon.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [QZAIB7KITK] C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\Ftq.exe
O4 - HKCU\..\Run: [12CFG214-K641-12SF-N85P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12327735-C4FF-499F-8B54-68D674F434AC}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{12327735-C4FF-499F-8B54-68D674F434AC}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{12327735-C4FF-499F-8B54-68D674F434AC}: NameServer = 192.168.1.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7520 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1caeeb44c73b6ba.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A765E925-112D-4537-B23D-854CD2E943F0}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{F351F816-E3FD-420F-AC24-A0BC2BBEAFED}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Reader 8.0\ActiveX\AcroIEHelper.dll [2006-08-10 71296]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-03-17 19520544]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
"netc"=C:\WINDOWS\svc.exe [2010-06-07 291840]
"netw"=C:\WINDOWS\svw.exe [2010-06-07 292352]
"servicelayer"=C:\WINDOWS\servicelayer.exe [2010-06-07 354304]
"ctfmon"=C:\WINDOWS\ctfmon.exe [2010-06-07 349696]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"nwiz"=nwiz.exe /installquiet []
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"QZAIB7KITK"=C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\Ftq.exe []
"12CFG214-K641-12SF-N85P"=C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-04-27 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\4_pinnew.exe"="C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\4_pinnew.exe:*:Enabled:Enabled"
"\"="C:\WINDOWS\system\dwm.exe:*:Enabled:KL"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-06-07 13:19:54 ----D---- C:\rsit
2010-06-07 13:19:54 ----D---- C:\Program Files\trend micro
2010-06-07 12:02:15 ----D---- C:\WINDOWS\pss
2010-06-07 11:56:45 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-07 11:45:11 ----A---- C:\WINDOWS\svc.exe
2010-06-07 11:45:10 ----A---- C:\WINDOWS\servicelayer.exe
2010-06-07 11:45:10 ----A---- C:\WINDOWS\ctfmon.exe
2010-05-30 20:00:28 ----A---- C:\WINDOWS\svw.exe
2010-05-30 20:00:08 ----SHD---- C:\WINDOWS\system32\lowsec
2010-05-26 10:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-12 15:12:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-11 19:08:43 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Real
2010-05-11 08:27:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-05-11 08:26:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-05-11 08:26:29 ----D---- C:\Program Files\MSXML 4.0
2010-05-10 18:42:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\WEBREG
2010-05-10 18:41:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\HPSSUPPLY
2010-05-10 18:39:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP Product Assistant
2010-05-10 18:39:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP
2010-05-10 18:39:41 ----D---- C:\Program Files\Common Files\HP
2010-05-10 18:39:20 ----D---- C:\Program Files\Hewlett-Packard
2010-05-10 18:39:06 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-05-10 18:38:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2010-05-10 18:38:01 ----RA---- C:\WINDOWS\system32\hpzids01.dll
2010-05-10 18:37:59 ----A---- C:\WINDOWS\system32\hpzll5ha.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hppldcoi.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hpowiax3.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hpovst10.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hpotscl3.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\difxapi.dll
2010-05-10 18:37:06 ----D---- C:\Program Files\HP
2010-05-10 18:36:54 ----HD---- C:\Config.Msi
2010-05-08 17:42:35 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\NVIDIA
2010-05-08 17:30:01 ----D---- C:\Program Files\Electronic Arts
2010-05-08 17:29:59 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-05-08 17:29:59 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-05-08 17:29:59 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-05-08 17:29:57 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-05-08 17:29:57 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-05-08 17:29:57 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-05-08 17:29:55 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-05-08 17:29:55 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-05-08 17:29:55 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-05-08 17:29:52 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2010-05-08 17:29:52 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-05-08 17:29:50 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2010-05-08 17:29:50 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2010-05-08 17:29:49 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2010-05-08 17:29:49 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2010-05-08 17:29:49 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-05-08 17:29:48 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2010-05-08 17:29:48 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2010-05-08 17:29:48 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-05-08 17:29:46 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-05-08 17:29:46 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-05-08 17:29:45 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-05-08 17:29:44 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-05-08 17:29:44 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-05-08 17:29:44 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-05-08 17:29:41 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2010-05-08 17:29:36 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2010-05-08 17:29:36 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-05-08 17:29:36 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-05-08 17:29:35 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-05-08 17:29:35 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-05-08 17:29:35 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2010-05-08 17:29:34 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-05-08 17:29:34 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-05-08 17:29:26 ----D---- C:\WINDOWS\Logs
2010-05-08 17:25:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-05-08 17:25:52 ----D---- C:\Program Files\Common Files\Adobe
2010-05-08 17:25:52 ----D---- C:\Program Files\Adobe
2010-05-08 17:10:04 ----D---- C:\temp
2010-05-08 17:09:56 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\WinRAR
2010-05-08 17:05:17 ----D---- C:\WINDOWS\ie8updates
2010-05-08 17:03:02 ----HDC---- C:\WINDOWS\ie8
2010-05-08 17:00:07 ----A---- C:\WINDOWS\ODBC.INI
2010-05-08 17:00:03 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-05-08 16:59:32 ----D---- C:\Program Files\Common Files\DESIGNER
2010-05-08 16:59:23 ----D---- C:\WINDOWS\SHELLNEW
2010-05-08 16:59:22 ----D---- C:\Program Files\Microsoft.NET
2010-05-08 16:59:22 ----D---- C:\Program Files\Microsoft Office
2010-05-08 16:58:15 ----RHD---- C:\MSOCache
2010-05-08 16:56:30 ----D---- C:\Program Files\Alcohol Soft
2010-05-08 16:54:13 ----D---- C:\Program Files\WinRAR
2010-05-08 16:52:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ahead
2010-05-08 16:51:32 ----D---- C:\Program Files\Nero
2010-05-08 16:51:32 ----D---- C:\Program Files\Common Files\Ahead
2010-05-08 16:51:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-05-08 16:50:00 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-05-08 16:50:00 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-05-08 16:46:21 ----A---- C:\WINDOWS\system32\unrar.dll
2010-05-08 16:46:21 ----A---- C:\WINDOWS\avisplitter.ini
2010-05-08 16:46:16 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\dpl100.dll
2010-05-08 16:46:14 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-05-08 16:46:14 ----A---- C:\WINDOWS\system32\divx.dll
2010-05-08 16:46:13 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-05-08 16:46:12 ----D---- C:\Program Files\K-Lite Codec Pack
2010-05-08 16:46:12 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-05-08 16:46:12 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-05-08 16:43:31 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Macromedia
2010-05-08 16:43:31 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Adobe
2010-05-08 16:41:09 ----D---- C:\totalcmd
2010-05-08 16:41:09 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\GHISLER
2010-05-08 16:40:38 ----RSHD---- C:\RECYCLER
2010-05-08 15:56:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-05-08 15:56:44 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-05-08 15:56:09 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-08 15:55:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-05-08 15:55:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-05-08 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-05-08 15:55:47 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-05-08 15:55:43 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-05-08 15:55:19 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-05-08 15:55:15 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-05-08 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-05-08 15:55:06 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-05-08 15:55:02 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-05-08 15:54:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-05-08 15:54:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-05-08 15:54:47 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-05-08 15:54:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-05-08 15:54:38 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-05-08 15:54:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-05-08 15:54:28 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-05-08 15:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-05-08 15:54:19 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-05-08 15:54:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-05-08 15:54:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-05-08 15:54:05 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-05-08 15:54:01 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-05-08 15:53:55 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-05-08 15:53:50 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-05-08 15:53:47 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-05-08 15:53:43 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-05-08 15:53:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-05-08 15:53:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-05-08 15:53:32 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-05-08 15:51:44 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-05-08 15:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-05-08 15:51:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-05-08 15:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-05-08 15:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-05-08 15:51:22 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-05-08 15:51:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-05-08 15:51:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-05-08 15:51:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-05-08 15:51:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-05-08 15:51:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-05-08 15:50:46 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-05-08 15:50:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-05-08 15:50:38 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-05-08 15:50:34 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-05-08 15:50:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-05-08 15:50:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-05-08 15:50:15 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-05-08 15:50:08 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-05-08 15:50:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-05-08 15:49:54 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-05-08 15:49:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-05-08 15:49:47 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-05-08 15:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-05-08 15:49:39 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-05-08 15:49:35 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-05-08 15:49:32 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2010-05-08 15:49:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-05-08 15:49:26 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-05-08 15:49:22 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-05-08 15:49:19 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-05-08 15:49:16 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-05-08 15:49:12 ----D---- C:\WINDOWS\ie7updates
2010-05-08 15:49:08 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-05-08 15:49:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-05-08 15:48:59 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-05-08 15:48:56 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-05-08 15:48:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-05-08 15:38:36 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-05-08 15:38:08 ----D---- C:\WINDOWS\system32\XPSViewer
2010-05-08 15:38:05 ----D---- C:\Program Files\MSBuild
2010-05-08 15:38:04 ----D---- C:\WINDOWS\system32\en-US
2010-05-08 15:38:00 ----D---- C:\Program Files\Reference Assemblies
2010-05-08 15:37:42 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-05-08 15:37:42 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-05-08 15:37:42 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-05-08 15:37:41 ----HD---- C:\43e2d4c8c576ee460894aaa9
2010-05-08 15:29:43 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-05-08 15:26:50 ----D---- C:\WINDOWS\system32\PreInstall
2010-05-08 15:26:49 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-05-08 15:26:48 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-05-08 15:22:48 ----D---- C:\Program Files\Google
2010-05-08 15:22:32 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-05-08 15:22:29 ----D---- C:\Program Files\Alwil Software
2010-05-08 15:22:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-05-08 15:19:23 ----D---- C:\Programy
2010-05-08 15:16:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-05-08 15:10:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2010-05-08 15:10:24 ----D---- C:\Program Files\NVIDIA Corporation
2010-05-08 15:10:08 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-05-08 15:10:08 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2010-05-08 15:10:07 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2010-05-08 15:10:07 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2010-05-08 15:10:07 ----A---- C:\WINDOWS\system32\nvcuda.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvcodins.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvcod.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvapi.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-05-08 15:09:58 ----D---- C:\NVIDIA
2010-05-08 15:09:07 ----D---- C:\WINDOWS\system32\Lang
2010-05-08 15:07:45 ----D---- C:\WINDOWS\system32\RTCOM
2010-05-08 15:07:44 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-05-08 15:07:39 ----A---- C:\WINDOWS\vncutil.exe
2010-05-08 15:07:39 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-05-08 15:07:39 ----A---- C:\WINDOWS\SkyTel.exe
2010-05-08 15:07:39 ----A---- C:\WINDOWS\RtlUpd.exe
2010-05-08 15:07:38 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-05-08 15:07:38 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-05-08 15:07:38 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-05-08 15:07:36 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-05-08 15:07:36 ----A---- C:\WINDOWS\MicCal.exe
2010-05-08 15:07:35 ----D---- C:\Program Files\Realtek
2010-05-08 15:07:35 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-05-08 15:07:35 ----A---- C:\WINDOWS\ALCMTR.EXE
2010-05-08 15:07:29 ----RA---- C:\WINDOWS\RtlExUpd.dll
2010-05-08 15:06:34 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-08 15:06:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-08 15:06:31 ----D---- C:\Program Files\AMD
2010-05-08 15:06:18 ----D---- C:\Program Files\Common Files\InstallShield
2010-05-08 15:01:54 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-08 15:00:37 ----RSD---- C:\WINDOWS\assembly
2010-05-08 15:00:21 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-08 15:00:05 ----D---- C:\Program Files\ATI
2010-05-08 14:59:42 ----D---- C:\Program Files\ATI Technologies
======List of files/folders modified in the last 1 months======
2010-06-07 13:20:01 ----D---- C:\WINDOWS\Prefetch
2010-06-07 13:19:56 ----D---- C:\WINDOWS\Temp
2010-06-07 13:19:54 ----RD---- C:\Program Files
2010-06-07 13:12:47 ----D---- C:\WINDOWS\system32
2010-06-07 13:12:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-07 13:11:36 ----SD---- C:\WINDOWS\Tasks
2010-06-07 13:11:35 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-07 13:08:09 ----D---- C:\WINDOWS
2010-06-07 12:23:56 ----RSH---- C:\boot.ini
2010-06-07 12:23:56 ----A---- C:\WINDOWS\win.ini
2010-06-07 12:23:56 ----A---- C:\WINDOWS\system.ini
2010-06-07 11:57:25 ----D---- C:\Documents and Settings
2010-06-07 11:46:57 ----HD---- C:\WINDOWS\inf
2010-06-03 13:49:08 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-02 21:23:46 ----D---- C:\WINDOWS\system32\wbem
2010-06-02 21:23:46 ----D---- C:\WINDOWS\system32\drivers
2010-06-02 19:54:17 ----D---- C:\WINDOWS\system
2010-05-30 20:02:48 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-19 18:26:12 ----SD---- C:\Documents and Settings\Uživatel\Data aplikací\Microsoft
2010-05-12 15:12:44 ----A---- C:\WINDOWS\imsins.BAK
2010-05-12 15:12:42 ----D---- C:\Program Files\Outlook Express
2010-05-12 15:02:40 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-11 08:26:35 ----SHD---- C:\WINDOWS\Installer
2010-05-11 08:26:34 ----D---- C:\WINDOWS\WinSxS
2010-05-10 18:39:41 ----D---- C:\Program Files\Common Files
2010-05-10 18:39:26 ----D---- C:\WINDOWS\twain_32
2010-05-09 06:22:19 ----D---- C:\WINDOWS\security
2010-05-08 17:36:20 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-08 17:30:01 ----D---- C:\WINDOWS\system32\DirectX
2010-05-08 17:06:29 ----D---- C:\WINDOWS\system32\cs-cz
2010-05-08 17:06:29 ----D---- C:\WINDOWS\Media
2010-05-08 17:06:29 ----D---- C:\WINDOWS\Help
2010-05-08 17:06:29 ----D---- C:\Program Files\Internet Explorer
2010-05-08 16:59:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-08 16:59:42 ----RSD---- C:\WINDOWS\Fonts
2010-05-08 15:58:27 ----D---- C:\WINDOWS\AppPatch
2010-05-08 15:55:21 ----D---- C:\Program Files\Movie Maker
2010-05-08 15:50:03 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-08 15:49:21 ----D---- C:\Program Files\Messenger
2010-05-08 15:37:48 ----D---- C:\WINDOWS\system32\spool
2010-05-08 15:36:19 ----D---- C:\WINDOWS\system32\mui
2010-05-08 15:27:31 ----D---- C:\WINDOWS\SoftwareDistribution
2010-05-08 15:18:52 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-08 14:57:39 ----A---- C:\WINDOWS\system32\RTNUninst32.dll
2010-05-08 14:57:39 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-05-06 100432]
R3 AR5211;TP-LINK Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-06-25 463168]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-05-06 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-03-17 5878304]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-27 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2010-05-08 202064]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 az46k9y2;az46k9y2; C:\WINDOWS\system32\drivers\az46k9y2.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-08 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
potřeboval bych poradit s následujícím problémem. Do počítače se mi dostalo 27 infikovaných souborů. Smazáno testem po restartu počítače, ale nespíš něco ještě zůstalo, jelikož mi rezidentní štít avast5 hlásí zablokovám škodlivý URL. Zkontroluje mi někdo LOG z RSIT prosím ?
Logfile of random's system information tool 1.07 (written by random/random)
Run by Uživatel at 2010-06-07 13:19:54
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 134 GB (88%) free of 153 GB
Total RAM: 2047 MB (72% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:20:05, on 7.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\svc.exe
C:\WINDOWS\svw.exe
C:\WINDOWS\servicelayer.exe
C:\WINDOWS\ctfmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Documents and Settings\Uživatel\Plocha\RSIT.exe
C:\Program Files\trend micro\Uživatel.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Reader 8.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [netc] C:\WINDOWS\svc.exe
O4 - HKLM\..\Run: [netw] C:\WINDOWS\svw.exe
O4 - HKLM\..\Run: [servicelayer] C:\WINDOWS\servicelayer.exe
O4 - HKLM\..\Run: [ctfmon] C:\WINDOWS\ctfmon.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [QZAIB7KITK] C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\Ftq.exe
O4 - HKCU\..\Run: [12CFG214-K641-12SF-N85P] C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12327735-C4FF-499F-8B54-68D674F434AC}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{12327735-C4FF-499F-8B54-68D674F434AC}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{12327735-C4FF-499F-8B54-68D674F434AC}: NameServer = 192.168.1.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7520 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1caeeb44c73b6ba.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{A765E925-112D-4537-B23D-854CD2E943F0}.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{F351F816-E3FD-420F-AC24-A0BC2BBEAFED}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Reader 8.0\ActiveX\AcroIEHelper.dll [2006-08-10 71296]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-03-17 19520544]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2010-04-03 110696]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2010-04-03 13670504]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-05-06 2815192]
"netc"=C:\WINDOWS\svc.exe [2010-06-07 291840]
"netw"=C:\WINDOWS\svw.exe [2010-06-07 292352]
"servicelayer"=C:\WINDOWS\servicelayer.exe [2010-06-07 354304]
"ctfmon"=C:\WINDOWS\ctfmon.exe [2010-06-07 349696]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2006-11-03 866584]
"nwiz"=nwiz.exe /installquiet []
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2007-06-27 152872]
"QZAIB7KITK"=C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\Ftq.exe []
"12CFG214-K641-12SF-N85P"=C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[]
C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-04-27 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"=C:\PROGRA~1\WIFD1F~1\MpShHook.dll [2006-11-03 83224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\4_pinnew.exe"="C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\4_pinnew.exe:*:Enabled:Enabled"
"\"="C:\WINDOWS\system\dwm.exe:*:Enabled:KL"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-06-07 13:19:54 ----D---- C:\rsit
2010-06-07 13:19:54 ----D---- C:\Program Files\trend micro
2010-06-07 12:02:15 ----D---- C:\WINDOWS\pss
2010-06-07 11:56:45 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-07 11:45:11 ----A---- C:\WINDOWS\svc.exe
2010-06-07 11:45:10 ----A---- C:\WINDOWS\servicelayer.exe
2010-06-07 11:45:10 ----A---- C:\WINDOWS\ctfmon.exe
2010-05-30 20:00:28 ----A---- C:\WINDOWS\svw.exe
2010-05-30 20:00:08 ----SHD---- C:\WINDOWS\system32\lowsec
2010-05-26 10:32:41 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-12 15:12:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-05-11 19:08:43 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Real
2010-05-11 08:27:08 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-05-11 08:26:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-05-11 08:26:29 ----D---- C:\Program Files\MSXML 4.0
2010-05-10 18:42:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\WEBREG
2010-05-10 18:41:19 ----D---- C:\Documents and Settings\All Users\Data aplikací\HPSSUPPLY
2010-05-10 18:39:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP Product Assistant
2010-05-10 18:39:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\HP
2010-05-10 18:39:41 ----D---- C:\Program Files\Common Files\HP
2010-05-10 18:39:20 ----D---- C:\Program Files\Hewlett-Packard
2010-05-10 18:39:06 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2010-05-10 18:38:11 ----D---- C:\Documents and Settings\All Users\Data aplikací\Hewlett-Packard
2010-05-10 18:38:01 ----RA---- C:\WINDOWS\system32\hpzids01.dll
2010-05-10 18:37:59 ----A---- C:\WINDOWS\system32\hpzll5ha.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hppldcoi.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hpowiax3.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hpovst10.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\hpotscl3.dll
2010-05-10 18:37:47 ----RA---- C:\WINDOWS\system32\difxapi.dll
2010-05-10 18:37:06 ----D---- C:\Program Files\HP
2010-05-10 18:36:54 ----HD---- C:\Config.Msi
2010-05-08 17:42:35 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\NVIDIA
2010-05-08 17:30:01 ----D---- C:\Program Files\Electronic Arts
2010-05-08 17:29:59 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2010-05-08 17:29:59 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2010-05-08 17:29:59 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2010-05-08 17:29:58 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2010-05-08 17:29:57 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2010-05-08 17:29:57 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2010-05-08 17:29:57 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2010-05-08 17:29:56 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2010-05-08 17:29:55 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2010-05-08 17:29:55 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2010-05-08 17:29:55 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2010-05-08 17:29:54 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2010-05-08 17:29:53 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2010-05-08 17:29:52 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2010-05-08 17:29:52 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2010-05-08 17:29:51 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2010-05-08 17:29:50 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2010-05-08 17:29:50 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2010-05-08 17:29:49 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2010-05-08 17:29:49 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2010-05-08 17:29:49 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2010-05-08 17:29:48 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2010-05-08 17:29:48 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2010-05-08 17:29:48 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2010-05-08 17:29:47 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2010-05-08 17:29:46 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2010-05-08 17:29:46 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2010-05-08 17:29:45 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2010-05-08 17:29:44 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2010-05-08 17:29:44 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2010-05-08 17:29:44 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2010-05-08 17:29:43 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2010-05-08 17:29:42 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-05-08 17:29:41 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2010-05-08 17:29:36 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2010-05-08 17:29:36 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2010-05-08 17:29:36 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2010-05-08 17:29:35 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2010-05-08 17:29:35 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2010-05-08 17:29:35 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2010-05-08 17:29:34 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-05-08 17:29:34 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-05-08 17:29:26 ----D---- C:\WINDOWS\Logs
2010-05-08 17:25:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-05-08 17:25:52 ----D---- C:\Program Files\Common Files\Adobe
2010-05-08 17:25:52 ----D---- C:\Program Files\Adobe
2010-05-08 17:10:04 ----D---- C:\temp
2010-05-08 17:09:56 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\WinRAR
2010-05-08 17:05:17 ----D---- C:\WINDOWS\ie8updates
2010-05-08 17:03:02 ----HDC---- C:\WINDOWS\ie8
2010-05-08 17:00:07 ----A---- C:\WINDOWS\ODBC.INI
2010-05-08 17:00:03 ----A---- C:\WINDOWS\system32\mdimon.dll
2010-05-08 16:59:32 ----D---- C:\Program Files\Common Files\DESIGNER
2010-05-08 16:59:23 ----D---- C:\WINDOWS\SHELLNEW
2010-05-08 16:59:22 ----D---- C:\Program Files\Microsoft.NET
2010-05-08 16:59:22 ----D---- C:\Program Files\Microsoft Office
2010-05-08 16:58:15 ----RHD---- C:\MSOCache
2010-05-08 16:56:30 ----D---- C:\Program Files\Alcohol Soft
2010-05-08 16:54:13 ----D---- C:\Program Files\WinRAR
2010-05-08 16:52:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Ahead
2010-05-08 16:51:32 ----D---- C:\Program Files\Nero
2010-05-08 16:51:32 ----D---- C:\Program Files\Common Files\Ahead
2010-05-08 16:51:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\Nero
2010-05-08 16:50:00 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2010-05-08 16:50:00 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\pndx5032.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\pndx5016.dll
2010-05-08 16:46:22 ----A---- C:\WINDOWS\system32\pncrt.dll
2010-05-08 16:46:21 ----A---- C:\WINDOWS\system32\unrar.dll
2010-05-08 16:46:21 ----A---- C:\WINDOWS\avisplitter.ini
2010-05-08 16:46:16 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\xvidcore.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2010-05-08 16:46:15 ----A---- C:\WINDOWS\system32\dpl100.dll
2010-05-08 16:46:14 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2010-05-08 16:46:14 ----A---- C:\WINDOWS\system32\divx.dll
2010-05-08 16:46:13 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2010-05-08 16:46:12 ----D---- C:\Program Files\K-Lite Codec Pack
2010-05-08 16:46:12 ----A---- C:\WINDOWS\system32\msvcr71.dll
2010-05-08 16:46:12 ----A---- C:\WINDOWS\system32\msvcp71.dll
2010-05-08 16:43:31 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Macromedia
2010-05-08 16:43:31 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\Adobe
2010-05-08 16:41:09 ----D---- C:\totalcmd
2010-05-08 16:41:09 ----D---- C:\Documents and Settings\Uživatel\Data aplikací\GHISLER
2010-05-08 16:40:38 ----RSHD---- C:\RECYCLER
2010-05-08 15:56:48 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-05-08 15:56:44 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-05-08 15:56:09 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-08 15:55:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-05-08 15:55:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-05-08 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-05-08 15:55:47 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-05-08 15:55:43 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-05-08 15:55:19 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-05-08 15:55:15 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-05-08 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-05-08 15:55:06 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-05-08 15:55:02 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-05-08 15:54:57 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-05-08 15:54:52 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-05-08 15:54:47 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-05-08 15:54:43 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-05-08 15:54:38 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-05-08 15:54:33 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-05-08 15:54:28 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-05-08 15:54:24 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-05-08 15:54:19 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-05-08 15:54:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-05-08 15:54:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-05-08 15:54:05 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-05-08 15:54:01 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-05-08 15:53:55 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-05-08 15:53:50 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-05-08 15:53:47 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-05-08 15:53:43 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-05-08 15:53:39 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-05-08 15:53:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-05-08 15:53:32 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-05-08 15:51:44 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-05-08 15:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-05-08 15:51:37 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-05-08 15:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-05-08 15:51:30 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-05-08 15:51:22 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-05-08 15:51:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-05-08 15:51:16 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-05-08 15:51:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-05-08 15:51:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-05-08 15:51:01 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-05-08 15:50:46 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-05-08 15:50:42 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-05-08 15:50:38 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-05-08 15:50:34 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-05-08 15:50:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-05-08 15:50:20 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-05-08 15:50:15 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-05-08 15:50:08 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-05-08 15:50:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-05-08 15:49:54 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-05-08 15:49:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-05-08 15:49:47 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-05-08 15:49:43 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-05-08 15:49:39 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-05-08 15:49:35 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-05-08 15:49:32 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2010-05-08 15:49:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-05-08 15:49:26 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-05-08 15:49:22 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-05-08 15:49:19 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-05-08 15:49:16 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-05-08 15:49:12 ----D---- C:\WINDOWS\ie7updates
2010-05-08 15:49:08 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-05-08 15:49:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-05-08 15:48:59 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-05-08 15:48:56 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-05-08 15:48:51 ----HDC---- C:\WINDOWS\$NtUninstallKB950760$
2010-05-08 15:38:36 ----N---- C:\WINDOWS\system32\browserchoice.exe
2010-05-08 15:38:08 ----D---- C:\WINDOWS\system32\XPSViewer
2010-05-08 15:38:05 ----D---- C:\Program Files\MSBuild
2010-05-08 15:38:04 ----D---- C:\WINDOWS\system32\en-US
2010-05-08 15:38:00 ----D---- C:\Program Files\Reference Assemblies
2010-05-08 15:37:42 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-05-08 15:37:42 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-05-08 15:37:42 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-05-08 15:37:41 ----HD---- C:\43e2d4c8c576ee460894aaa9
2010-05-08 15:29:43 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2010-05-08 15:26:50 ----D---- C:\WINDOWS\system32\PreInstall
2010-05-08 15:26:49 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-05-08 15:26:48 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-05-08 15:22:48 ----D---- C:\Program Files\Google
2010-05-08 15:22:32 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-05-08 15:22:29 ----D---- C:\Program Files\Alwil Software
2010-05-08 15:22:29 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-05-08 15:19:23 ----D---- C:\Programy
2010-05-08 15:16:38 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2010-05-08 15:10:32 ----D---- C:\Documents and Settings\All Users\Data aplikací\NVIDIA Corporation
2010-05-08 15:10:24 ----D---- C:\Program Files\NVIDIA Corporation
2010-05-08 15:10:08 ----A---- C:\WINDOWS\system32\OpenCL.dll
2010-05-08 15:10:08 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2010-05-08 15:10:07 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2010-05-08 15:10:07 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2010-05-08 15:10:07 ----A---- C:\WINDOWS\system32\nvcuda.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvcodins.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvcod.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nvapi.dll
2010-05-08 15:10:06 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-05-08 15:09:58 ----D---- C:\NVIDIA
2010-05-08 15:09:07 ----D---- C:\WINDOWS\system32\Lang
2010-05-08 15:07:45 ----D---- C:\WINDOWS\system32\RTCOM
2010-05-08 15:07:44 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-05-08 15:07:39 ----A---- C:\WINDOWS\vncutil.exe
2010-05-08 15:07:39 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-05-08 15:07:39 ----A---- C:\WINDOWS\SkyTel.exe
2010-05-08 15:07:39 ----A---- C:\WINDOWS\RtlUpd.exe
2010-05-08 15:07:38 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-05-08 15:07:38 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-05-08 15:07:38 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-05-08 15:07:36 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-05-08 15:07:36 ----A---- C:\WINDOWS\MicCal.exe
2010-05-08 15:07:35 ----D---- C:\Program Files\Realtek
2010-05-08 15:07:35 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-05-08 15:07:35 ----A---- C:\WINDOWS\ALCMTR.EXE
2010-05-08 15:07:29 ----RA---- C:\WINDOWS\RtlExUpd.dll
2010-05-08 15:06:34 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-05-08 15:06:31 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-08 15:06:31 ----D---- C:\Program Files\AMD
2010-05-08 15:06:18 ----D---- C:\Program Files\Common Files\InstallShield
2010-05-08 15:01:54 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-05-08 15:00:37 ----RSD---- C:\WINDOWS\assembly
2010-05-08 15:00:21 ----D---- C:\WINDOWS\Microsoft.NET
2010-05-08 15:00:05 ----D---- C:\Program Files\ATI
2010-05-08 14:59:42 ----D---- C:\Program Files\ATI Technologies
======List of files/folders modified in the last 1 months======
2010-06-07 13:20:01 ----D---- C:\WINDOWS\Prefetch
2010-06-07 13:19:56 ----D---- C:\WINDOWS\Temp
2010-06-07 13:19:54 ----RD---- C:\Program Files
2010-06-07 13:12:47 ----D---- C:\WINDOWS\system32
2010-06-07 13:12:47 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-07 13:11:36 ----SD---- C:\WINDOWS\Tasks
2010-06-07 13:11:35 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-07 13:08:09 ----D---- C:\WINDOWS
2010-06-07 12:23:56 ----RSH---- C:\boot.ini
2010-06-07 12:23:56 ----A---- C:\WINDOWS\win.ini
2010-06-07 12:23:56 ----A---- C:\WINDOWS\system.ini
2010-06-07 11:57:25 ----D---- C:\Documents and Settings
2010-06-07 11:46:57 ----HD---- C:\WINDOWS\inf
2010-06-03 13:49:08 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-02 21:23:46 ----D---- C:\WINDOWS\system32\wbem
2010-06-02 21:23:46 ----D---- C:\WINDOWS\system32\drivers
2010-06-02 19:54:17 ----D---- C:\WINDOWS\system
2010-05-30 20:02:48 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-05-19 18:26:12 ----SD---- C:\Documents and Settings\Uživatel\Data aplikací\Microsoft
2010-05-12 15:12:44 ----A---- C:\WINDOWS\imsins.BAK
2010-05-12 15:12:42 ----D---- C:\Program Files\Outlook Express
2010-05-12 15:02:40 ----HD---- C:\WINDOWS\$hf_mig$
2010-05-11 08:26:35 ----SHD---- C:\WINDOWS\Installer
2010-05-11 08:26:34 ----D---- C:\WINDOWS\WinSxS
2010-05-10 18:39:41 ----D---- C:\Program Files\Common Files
2010-05-10 18:39:26 ----D---- C:\WINDOWS\twain_32
2010-05-09 06:22:19 ----D---- C:\WINDOWS\security
2010-05-08 17:36:20 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-05-08 17:30:01 ----D---- C:\WINDOWS\system32\DirectX
2010-05-08 17:06:29 ----D---- C:\WINDOWS\system32\cs-cz
2010-05-08 17:06:29 ----D---- C:\WINDOWS\Media
2010-05-08 17:06:29 ----D---- C:\WINDOWS\Help
2010-05-08 17:06:29 ----D---- C:\Program Files\Internet Explorer
2010-05-08 16:59:44 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-08 16:59:42 ----RSD---- C:\WINDOWS\Fonts
2010-05-08 15:58:27 ----D---- C:\WINDOWS\AppPatch
2010-05-08 15:55:21 ----D---- C:\Program Files\Movie Maker
2010-05-08 15:50:03 ----D---- C:\WINDOWS\system32\CatRoot
2010-05-08 15:49:21 ----D---- C:\Program Files\Messenger
2010-05-08 15:37:48 ----D---- C:\WINDOWS\system32\spool
2010-05-08 15:36:19 ----D---- C:\WINDOWS\system32\mui
2010-05-08 15:27:31 ----D---- C:\WINDOWS\SoftwareDistribution
2010-05-08 15:18:52 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-05-08 14:57:39 ----A---- C:\WINDOWS\system32\RTNUninst32.dll
2010-05-08 14:57:39 ----A---- C:\WINDOWS\system32\RtNicProp32.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-05-06 28880]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 42496]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-05-06 164048]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-05-06 46672]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-05-06 19024]
R2 aswMon2;aswMon2; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-05-06 100432]
R3 AR5211;TP-LINK Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-06-25 463168]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-05-06 23376]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-03-17 5878304]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-27 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2010-04-04 10232128]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2010-05-08 202064]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 az46k9y2;az46k9y2; C:\WINDOWS\system32\drivers\az46k9y2.sys []
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2010-04-03 154216]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968]
R2 WinDefend;Windows Defender; C:\Program Files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-05-06 40384]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-08 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Re: Avast5 hlásí Zablokován škodlivý URL
Hezké odpoledne
Combofix stahněte takto:
- pravým myšítkem klikněte na odkaz combofixu --uložit jako.. ,a teď ho přejmenujte na Potvora.com a uložte.
Stáhněte na plochu, ukončete všechna aktivní okna a spusťte ComboFix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-souhlaste s instalací konzole pro zotavení
- ComboFix je třeba spustit pod účtem s právy administrátora
- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary
- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano
- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna
- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem




- pravým myšítkem klikněte na odkaz combofixu --uložit jako.. ,a teď ho přejmenujte na Potvora.com a uložte.

-souhlaste s instalací konzole pro zotavení
- ComboFix je třeba spustit pod účtem s právy administrátora
- Před použitím vypněte všechny rezidentní bezpečnostní programy - antiviry, firewally, antispywary
- Po spuštění se zobrazí podmínky užití, potvrďte je stiskem tlačítka Ano
- Dále postupujte dle pokynů, během aplikování ComboFixu neklikejte do zobrazujícího se okna

- Po dokončení skenování, trvajícího maximálně 10 minut, by měl program vytvořit log - C:\ComboFix.txt, zkopírujte celý jeho obsah sem
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Avast5 hlásí Zablokován škodlivý URL
ComboFix 10-06-06.04 - Uživatel 07.06.2010 13:54:20.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1675 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\potvora.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\data
c:\data\WINDOWSDEFENDER.EXE
c:\docume~1\UIVATE~1\LOCALS~1\Temp\install_flash_player.exe
c:\docume~1\UIVATE~1\LOCALS~1\Temp\q1.exe
c:\windows\ctfmon.exe
c:\windows\servicelayer.exe
c:\windows\svc.exe
c:\windows\svw.exe
c:\windows\system32\3455645844.dat
c:\windows\system32\AutoRun.inf
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
Nakažená kopie c:\windows\system32\drivers\AmdK8.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty had a snack :p
c:\windows\system32\grpconv.exe chyběl.
Obnovena kopie z - c:\system volume information\_restore{FEB5C763-E432-4E40-998F-D9909713F305}\RP30\A0005181.exe
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DARKNESS
-------\Legacy_SSHNAS
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-07 do 2010-06-07 )))))))))))))))))))))))))))))))
.
2010-06-07 11:58 . 2008-04-14 08:52 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-07 11:58 . 2008-04-14 08:52 39424 ----a-w- c:\windows\system32\grpconv.exe
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- C:\rsit
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- c:\program files\trend micro
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-06-07 09:59 . 2010-06-07 09:59 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-05-30 18:02 . 2008-04-13 20:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-05-30 18:01 . 2010-05-30 18:01 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-30 18:00 . 2010-05-30 18:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-05-11 06:26 . 2010-05-11 06:26 -------- d-----w- c:\program files\MSXML 4.0
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\HP
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Hewlett-Packard
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-05-10 16:38 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\hpzipr12.sys
2010-05-10 16:38 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\hpzid412.sys
2010-05-10 16:38 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\hpzius12.sys
2010-05-10 16:38 . 2007-03-30 15:07 267864 ----a-r- c:\windows\system32\hpzids01.dll
2010-05-10 16:37 . 2007-03-28 12:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2010-05-10 16:37 . 2007-03-28 11:57 274944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5ha.dll
2010-05-10 16:37 . 2007-03-17 16:11 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2010-05-10 16:37 . 2007-03-17 16:11 303104 ----a-r- c:\windows\system32\hpovst10.dll
2010-05-10 16:37 . 2007-03-17 16:11 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2010-05-10 16:37 . 2007-03-08 04:20 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-05-10 16:37 . 2007-03-08 04:20 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-05-10 16:37 . 2008-04-13 20:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-10 16:37 . 2008-04-13 20:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-10 16:37 . 2010-05-10 16:41 -------- d-----w- c:\program files\HP
2010-05-10 16:35 . 2010-05-10 16:42 158092 ----a-w- c:\windows\hpoins14.dat
2010-05-10 16:35 . 2007-06-05 23:07 2000 ------w- c:\windows\hpomdl14.dat
2010-05-10 16:25 . 2008-04-13 20:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-10 16:25 . 2008-04-13 20:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-08 15:30 . 2010-05-08 15:30 -------- d-----w- c:\program files\Electronic Arts
2010-05-08 15:25 . 2010-05-08 15:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-08 15:10 . 2005-06-25 17:46 463168 ----a-w- c:\windows\system32\drivers\ar5211.sys
2010-05-08 15:10 . 2005-06-25 17:46 463168 ----a-w- c:\windows\system32\ar5211.sys
2010-05-08 15:10 . 2010-05-08 15:10 -------- d-----w- C:\temp
2010-05-08 15:05 . 2010-02-25 06:18 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-05-08 15:05 . 2010-02-25 06:18 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-08 15:05 . 2010-05-11 06:27 -------- d-----w- c:\windows\ie8updates
2010-05-08 15:05 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-05-08 15:03 . 2010-05-08 15:04 -------- dc-h--w- c:\windows\ie8
2010-05-08 15:00 . 2003-06-18 23:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-05-08 15:00 . 2003-06-18 23:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2010-05-08 14:59 . 2010-05-08 14:59 -------- d-----w- c:\windows\SHELLNEW
2010-05-08 14:59 . 2010-05-08 14:59 -------- d-----w- c:\program files\Microsoft.NET
2010-05-08 14:58 . 2010-05-08 14:58 -------- d-----r- C:\MSOCache
2010-05-08 14:56 . 2010-05-08 14:56 -------- d-----w- c:\program files\Alcohol Soft
2010-05-08 14:54 . 2010-05-08 14:54 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-08 14:51 . 2010-05-08 14:52 -------- d-----w- c:\program files\Common Files\Ahead
2010-05-08 14:51 . 2010-05-08 14:51 -------- d-----w- c:\program files\Nero
2010-05-08 14:41 . 2010-05-08 14:41 -------- d-----w- C:\totalcmd
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\UC.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\RAR.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\PKZIP.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\LHA.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\ARJ.PIF
2010-05-08 13:41 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-05-08 13:41 . 2008-06-14 17:35 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-05-08 13:40 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-08 13:38 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\windows\system32\XPSViewer
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\MSBuild
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\Reference Assemblies
2010-05-08 13:37 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-05-08 13:37 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-05-08 13:37 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-05-08 13:37 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-05-08 13:37 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-05-08 13:37 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-05-08 13:37 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-05-08 13:37 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-05-08 13:37 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-05-08 13:37 . 2010-05-08 13:37 -------- d-----w- C:\43e2d4c8c576ee460894aaa9
2010-05-08 13:35 . 2010-02-17 12:09 2192128 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-05-08 13:35 . 2010-02-16 19:08 2148352 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-08 13:35 . 2010-02-16 19:08 2026496 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-08 13:29 . 2010-05-12 09:21 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 13:26 . 2009-01-07 16:20 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-05-08 13:22 . 2010-05-08 13:23 -------- d-----w- c:\program files\Google
2010-05-08 13:22 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-08 13:22 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-08 13:22 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-08 13:22 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-08 13:22 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-08 13:22 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-08 13:22 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-08 13:22 . 2010-05-06 20:59 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-08 13:22 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-08 13:22 . 2010-05-08 13:22 -------- d-----w- c:\program files\Alwil Software
2010-05-08 13:19 . 2010-05-10 16:34 -------- d-----w- C:\Programy
2010-05-08 13:09 . 2008-04-13 20:15 6272 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2010-05-08 13:09 . 2008-04-13 20:15 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-05-08 13:09 . 2010-05-08 13:09 -------- d-----w- C:\NVIDIA
2010-05-08 13:09 . 2008-04-13 20:45 60800 -c--a-w- c:\windows\system32\dllcache\sysaudio.sys
2010-05-08 13:09 . 2008-04-13 20:45 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys
2010-05-08 13:09 . 2008-04-13 20:47 83072 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-05-08 13:09 . 2008-04-13 20:47 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-05-08 13:09 . 2010-05-08 13:09 -------- d-----w- c:\windows\system32\Lang
2010-05-08 13:06 . 2010-05-08 15:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\AMD
2010-05-08 13:06 . 2005-03-09 13:53 42496 ----a-w- c:\windows\system32\drivers\AmdK8.sys
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 13:01 . 2010-05-10 16:37 -------- dc----w- c:\windows\system32\DRVSTORE
2010-05-08 13:00 . 2010-05-08 13:00 -------- d-----w- c:\program files\ATI
2010-05-08 12:59 . 2010-05-08 12:59 -------- d-----w- c:\program files\ATI Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-07 12:02 . 2001-10-25 16:00 77872 ----a-w- c:\windows\system32\perfc005.dat
2010-06-07 12:02 . 2001-10-25 16:00 428750 ----a-w- c:\windows\system32\perfh005.dat
2010-05-08 14:46 . 2010-05-08 14:46 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-08 13:10 . 2010-05-08 13:10 -------- d-----w- c:\program files\NVIDIA Corporation
2010-05-08 13:07 . 2010-05-08 13:07 -------- d-----w- c:\program files\Realtek
2010-05-08 12:57 . 2010-01-21 20:11 202064 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys
2010-05-08 12:57 . 2010-01-12 11:35 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2010-05-08 12:57 . 2010-01-12 11:35 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2010-05-07 17:33 . 2010-05-07 17:03 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-07 17:33 . 2010-05-07 17:03 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-05-07 17:32 . 2010-05-07 17:03 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-05-07 17:11 . 2010-05-07 17:11 -------- d-----w- c:\program files\Windows Defender
2010-05-07 17:05 . 2010-05-07 17:05 -------- d-----w- c:\program files\microsoft frontpage
2010-05-07 17:01 . 2010-05-07 17:01 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-07 17:00 . 2010-05-07 17:00 -------- d-----w- c:\program files\Windows Media Connect 2
2010-04-16 18:00 . 2010-05-08 14:46 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-04-03 22:55 . 2010-05-08 13:10 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-04-03 22:55 . 2010-05-08 13:10 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2010-05-08 13:10 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-04-03 22:55 . 2010-05-08 13:10 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2010-05-08 13:10 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2010-05-08 13:10 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2010-05-08 13:10 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2010-05-08 13:10 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2010-05-08 13:10 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-04-03 22:55 . 2010-05-08 13:10 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-17 14:52 . 2010-05-08 13:07 84512 ----a-w- c:\windows\SOUNDMAN.EXE
2010-03-17 14:52 . 2010-05-08 13:07 358944 ----a-w- c:\windows\vncutil.exe
2010-03-17 14:52 . 2010-05-08 13:07 1833504 ----a-w- c:\windows\SkyTel.exe
2010-03-17 14:52 . 2010-05-08 13:07 1489440 ----a-w- c:\windows\RtlUpd.exe
2010-03-17 14:52 . 2010-05-08 13:07 9721888 ----a-w- c:\windows\RTLCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 51232 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-03-17 14:52 . 2010-05-08 13:07 129568 ----a-w- c:\windows\RtkAudioService.exe
2010-03-17 14:52 . 2010-05-08 13:07 19520544 ----a-w- c:\windows\RTHDCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2177568 ----a-w- c:\windows\MicCal.exe
2010-03-17 14:52 . 2010-05-08 13:07 64032 ----a-w- c:\windows\ALCMTR.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2815520 ----a-w- c:\windows\ALCWZRD.EXE
2010-03-17 14:40 . 2010-05-08 13:07 5878304 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-03-15 09:31 . 2010-05-08 14:46 165376 ----a-w- c:\windows\system32\unrar.dll
2010-03-10 06:17 . 2008-04-27 10:10 420352 ----a-w- c:\windows\system32\vbscript.dll
.
------- Sigcheck -------
[-] 2008-04-27 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-17 19520544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-8-11 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-8-10 741987]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1\LOCALS~1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1\LOCALS~1\Temp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\windows\TEMP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.5.2010 15:22 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.5.2010 15:22 19024]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.5.2010 15:22 133104]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8.5.2010 16:54 685816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore1caeeb44c73b6ba.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{A765E925-112D-4537-B23D-854CD2E943F0}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{F351F816-E3FD-420F-AC24-A0BC2BBEAFED}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {12327735-C4FF-499F-8B54-68D674F434AC} = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-nwiz - nwiz.exe
MSConfigStartUp-ope96 - c:\docume~1\UIVATE~1\LOCALS~1\Temp\ope96.exe
MSConfigStartUp-ope47 - c:\windows\TEMP\ope47.exe
MSConfigStartUp-ope65 - c:\windows\TEMP\ope65.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-07 14:00
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.EXE'(1960)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2010-06-07 14:03:05 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-06-07 12:03
Před spuštěním: Volných bajtů: 140 824 453 120
Po spuštění: Volných bajtů: 141 617 815 552
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - 26D485EE26695902272F6A0641BD3BA5
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1675 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\potvora.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Vytvořen nový Bod Obnovení
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\data
c:\data\WINDOWSDEFENDER.EXE
c:\docume~1\UIVATE~1\LOCALS~1\Temp\install_flash_player.exe
c:\docume~1\UIVATE~1\LOCALS~1\Temp\q1.exe
c:\windows\ctfmon.exe
c:\windows\servicelayer.exe
c:\windows\svc.exe
c:\windows\svw.exe
c:\windows\system32\3455645844.dat
c:\windows\system32\AutoRun.inf
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
Nakažená kopie c:\windows\system32\drivers\AmdK8.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty had a snack :p
c:\windows\system32\grpconv.exe chyběl.
Obnovena kopie z - c:\system volume information\_restore{FEB5C763-E432-4E40-998F-D9909713F305}\RP30\A0005181.exe
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DARKNESS
-------\Legacy_SSHNAS
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-07 do 2010-06-07 )))))))))))))))))))))))))))))))
.
2010-06-07 11:58 . 2008-04-14 08:52 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-07 11:58 . 2008-04-14 08:52 39424 ----a-w- c:\windows\system32\grpconv.exe
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- C:\rsit
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- c:\program files\trend micro
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-06-07 09:59 . 2010-06-07 09:59 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-05-30 18:02 . 2008-04-13 20:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-05-30 18:01 . 2010-05-30 18:01 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-30 18:00 . 2010-05-30 18:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-05-11 06:26 . 2010-05-11 06:26 -------- d-----w- c:\program files\MSXML 4.0
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\HP
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Hewlett-Packard
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-05-10 16:38 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\hpzipr12.sys
2010-05-10 16:38 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\hpzid412.sys
2010-05-10 16:38 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\hpzius12.sys
2010-05-10 16:38 . 2007-03-30 15:07 267864 ----a-r- c:\windows\system32\hpzids01.dll
2010-05-10 16:37 . 2007-03-28 12:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2010-05-10 16:37 . 2007-03-28 11:57 274944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5ha.dll
2010-05-10 16:37 . 2007-03-17 16:11 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2010-05-10 16:37 . 2007-03-17 16:11 303104 ----a-r- c:\windows\system32\hpovst10.dll
2010-05-10 16:37 . 2007-03-17 16:11 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2010-05-10 16:37 . 2007-03-08 04:20 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-05-10 16:37 . 2007-03-08 04:20 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-05-10 16:37 . 2008-04-13 20:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-10 16:37 . 2008-04-13 20:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-10 16:37 . 2010-05-10 16:41 -------- d-----w- c:\program files\HP
2010-05-10 16:35 . 2010-05-10 16:42 158092 ----a-w- c:\windows\hpoins14.dat
2010-05-10 16:35 . 2007-06-05 23:07 2000 ------w- c:\windows\hpomdl14.dat
2010-05-10 16:25 . 2008-04-13 20:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-10 16:25 . 2008-04-13 20:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-08 15:30 . 2010-05-08 15:30 -------- d-----w- c:\program files\Electronic Arts
2010-05-08 15:25 . 2010-05-08 15:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-08 15:10 . 2005-06-25 17:46 463168 ----a-w- c:\windows\system32\drivers\ar5211.sys
2010-05-08 15:10 . 2005-06-25 17:46 463168 ----a-w- c:\windows\system32\ar5211.sys
2010-05-08 15:10 . 2010-05-08 15:10 -------- d-----w- C:\temp
2010-05-08 15:05 . 2010-02-25 06:18 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-05-08 15:05 . 2010-02-25 06:18 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-08 15:05 . 2010-05-11 06:27 -------- d-----w- c:\windows\ie8updates
2010-05-08 15:05 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-05-08 15:03 . 2010-05-08 15:04 -------- dc-h--w- c:\windows\ie8
2010-05-08 15:00 . 2003-06-18 23:31 18944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-05-08 15:00 . 2003-06-18 23:31 17920 ----a-w- c:\windows\system32\mdimon.dll
2010-05-08 14:59 . 2010-05-08 14:59 -------- d-----w- c:\windows\SHELLNEW
2010-05-08 14:59 . 2010-05-08 14:59 -------- d-----w- c:\program files\Microsoft.NET
2010-05-08 14:58 . 2010-05-08 14:58 -------- d-----r- C:\MSOCache
2010-05-08 14:56 . 2010-05-08 14:56 -------- d-----w- c:\program files\Alcohol Soft
2010-05-08 14:54 . 2010-05-08 14:54 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-08 14:51 . 2010-05-08 14:52 -------- d-----w- c:\program files\Common Files\Ahead
2010-05-08 14:51 . 2010-05-08 14:51 -------- d-----w- c:\program files\Nero
2010-05-08 14:41 . 2010-05-08 14:41 -------- d-----w- C:\totalcmd
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\UC.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\RAR.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\PKZIP.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\LHA.PIF
2010-05-08 14:41 . 2009-09-09 05:50 545 ----a-w- c:\windows\ARJ.PIF
2010-05-08 13:41 . 2008-06-14 17:35 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-05-08 13:41 . 2008-06-14 17:35 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-05-08 13:40 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-08 13:38 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\windows\system32\XPSViewer
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\MSBuild
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\Reference Assemblies
2010-05-08 13:37 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-05-08 13:37 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-05-08 13:37 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-05-08 13:37 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-05-08 13:37 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-05-08 13:37 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-05-08 13:37 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-05-08 13:37 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-05-08 13:37 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-05-08 13:37 . 2010-05-08 13:37 -------- d-----w- C:\43e2d4c8c576ee460894aaa9
2010-05-08 13:35 . 2010-02-17 12:09 2192128 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-05-08 13:35 . 2010-02-16 19:08 2148352 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-08 13:35 . 2010-02-16 19:08 2026496 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-08 13:29 . 2010-05-12 09:21 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 13:26 . 2009-01-07 16:20 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-05-08 13:22 . 2010-05-08 13:23 -------- d-----w- c:\program files\Google
2010-05-08 13:22 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-08 13:22 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-08 13:22 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-08 13:22 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-08 13:22 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-08 13:22 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-08 13:22 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-08 13:22 . 2010-05-06 20:59 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-08 13:22 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-08 13:22 . 2010-05-08 13:22 -------- d-----w- c:\program files\Alwil Software
2010-05-08 13:19 . 2010-05-10 16:34 -------- d-----w- C:\Programy
2010-05-08 13:09 . 2008-04-13 20:15 6272 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2010-05-08 13:09 . 2008-04-13 20:15 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-05-08 13:09 . 2010-05-08 13:09 -------- d-----w- C:\NVIDIA
2010-05-08 13:09 . 2008-04-13 20:45 60800 -c--a-w- c:\windows\system32\dllcache\sysaudio.sys
2010-05-08 13:09 . 2008-04-13 20:45 60800 ----a-w- c:\windows\system32\drivers\sysaudio.sys
2010-05-08 13:09 . 2008-04-13 20:47 83072 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-05-08 13:09 . 2008-04-13 20:47 83072 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2010-05-08 13:09 . 2010-05-08 13:09 -------- d-----w- c:\windows\system32\Lang
2010-05-08 13:06 . 2010-05-08 15:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\AMD
2010-05-08 13:06 . 2005-03-09 13:53 42496 ----a-w- c:\windows\system32\drivers\AmdK8.sys
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 13:01 . 2010-05-10 16:37 -------- dc----w- c:\windows\system32\DRVSTORE
2010-05-08 13:00 . 2010-05-08 13:00 -------- d-----w- c:\program files\ATI
2010-05-08 12:59 . 2010-05-08 12:59 -------- d-----w- c:\program files\ATI Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-07 12:02 . 2001-10-25 16:00 77872 ----a-w- c:\windows\system32\perfc005.dat
2010-06-07 12:02 . 2001-10-25 16:00 428750 ----a-w- c:\windows\system32\perfh005.dat
2010-05-08 14:46 . 2010-05-08 14:46 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-08 13:10 . 2010-05-08 13:10 -------- d-----w- c:\program files\NVIDIA Corporation
2010-05-08 13:07 . 2010-05-08 13:07 -------- d-----w- c:\program files\Realtek
2010-05-08 12:57 . 2010-01-21 20:11 202064 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys
2010-05-08 12:57 . 2010-01-12 11:35 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2010-05-08 12:57 . 2010-01-12 11:35 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2010-05-07 17:33 . 2010-05-07 17:03 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-07 17:33 . 2010-05-07 17:03 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-05-07 17:32 . 2010-05-07 17:03 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-05-07 17:11 . 2010-05-07 17:11 -------- d-----w- c:\program files\Windows Defender
2010-05-07 17:05 . 2010-05-07 17:05 -------- d-----w- c:\program files\microsoft frontpage
2010-05-07 17:01 . 2010-05-07 17:01 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-07 17:00 . 2010-05-07 17:00 -------- d-----w- c:\program files\Windows Media Connect 2
2010-04-16 18:00 . 2010-05-08 14:46 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-04-03 22:55 . 2010-05-08 13:10 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-04-03 22:55 . 2010-05-08 13:10 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2010-05-08 13:10 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-04-03 22:55 . 2010-05-08 13:10 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2010-05-08 13:10 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2010-05-08 13:10 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2010-05-08 13:10 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2010-05-08 13:10 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2010-05-08 13:10 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-04-03 22:55 . 2010-05-08 13:10 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-17 14:52 . 2010-05-08 13:07 84512 ----a-w- c:\windows\SOUNDMAN.EXE
2010-03-17 14:52 . 2010-05-08 13:07 358944 ----a-w- c:\windows\vncutil.exe
2010-03-17 14:52 . 2010-05-08 13:07 1833504 ----a-w- c:\windows\SkyTel.exe
2010-03-17 14:52 . 2010-05-08 13:07 1489440 ----a-w- c:\windows\RtlUpd.exe
2010-03-17 14:52 . 2010-05-08 13:07 9721888 ----a-w- c:\windows\RTLCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 51232 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-03-17 14:52 . 2010-05-08 13:07 129568 ----a-w- c:\windows\RtkAudioService.exe
2010-03-17 14:52 . 2010-05-08 13:07 19520544 ----a-w- c:\windows\RTHDCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2177568 ----a-w- c:\windows\MicCal.exe
2010-03-17 14:52 . 2010-05-08 13:07 64032 ----a-w- c:\windows\ALCMTR.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2815520 ----a-w- c:\windows\ALCWZRD.EXE
2010-03-17 14:40 . 2010-05-08 13:07 5878304 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-03-15 09:31 . 2010-05-08 14:46 165376 ----a-w- c:\windows\system32\unrar.dll
2010-03-10 06:17 . 2008-04-27 10:10 420352 ----a-w- c:\windows\system32\vbscript.dll
.
------- Sigcheck -------
[-] 2008-04-27 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-08-01 222592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-17 19520544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-8-11 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-8-10 741987]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1\LOCALS~1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1\LOCALS~1\Temp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\windows\TEMP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.5.2010 15:22 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.5.2010 15:22 19024]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.5.2010 15:22 133104]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8.5.2010 16:54 685816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore1caeeb44c73b6ba.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{A765E925-112D-4537-B23D-854CD2E943F0}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{F351F816-E3FD-420F-AC24-A0BC2BBEAFED}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {12327735-C4FF-499F-8B54-68D674F434AC} = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-nwiz - nwiz.exe
MSConfigStartUp-ope96 - c:\docume~1\UIVATE~1\LOCALS~1\Temp\ope96.exe
MSConfigStartUp-ope47 - c:\windows\TEMP\ope47.exe
MSConfigStartUp-ope65 - c:\windows\TEMP\ope65.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-07 14:00
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'Explorer.EXE'(1960)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2010-06-07 14:03:05 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-06-07 12:03
Před spuštěním: Volných bajtů: 140 824 453 120
Po spuštění: Volných bajtů: 141 617 815 552
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - 26D485EE26695902272F6A0641BD3BA5
Re: Avast5 hlásí Zablokován škodlivý URL

c:\windows\system32\dllcache\grpconv.exe
c:\windows\system32\grpconv.exe
c:\windows\system32\sfcfiles.dll
-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.


-vyberte verzi podle svého operačního systému. SPTD for Windows (32 bit) nebo (64b)
-uložte na plochu a spusťte
- zvolte možnost Uninstall
- restart PC
- spusťte gmer

- rozbalte a spusťte
-proběhne sken, po skončení se otevře okno s výsledky, kliknete na Save a tím si uložíte log,který sem vložíte
-Podle návodu v odkazu proveďte druhý sken a log sem také vložte.

http://www2.gmer.net/mbr/mbr.exe
-uložte ho na plochu

do okénka zkopírujte
Kód: Vybrat vše
"%userprofile%\plocha\mbr" -t


-Nainstalujte,dejte úplný sken
NIC NEMAZAT

-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Avast5 hlásí Zablokován škodlivý URL
Soubory otestovány u všech výsledek: 0/40 (0%)
Re: Avast5 hlásí Zablokován škodlivý URL
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-06-07 19:20:40
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\uxtdrpow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB0806AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB08068EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB0806A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
Rootkit quick scan 2010-06-07 19:20:40
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\uxtdrpow.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB0806AC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB08068EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB0806A24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
Re: Avast5 hlásí Zablokován škodlivý URL
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-07 20:01:19
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\uxtdrpow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB07EEC7A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB07EEB36]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB07EF0EA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB07EF014]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB07EE70C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB07EEC10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB07EE64C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB07EE6B0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB07EED30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB07EF1B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB07EECF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB07EEE70]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB07FBAC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB07FB8EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB07FBA24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2CCC 80504568 4 Bytes JMP 54B07EF0
PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP B07FBA28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP B07FB8EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP B07F7536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP B07F8EC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B07FBACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB33E3380, 0x566445, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x57 0x54 0xDE 0x1B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x57 0x54 0xDE 0x1B ...
---- EOF - GMER 1.0.15 ----
Rootkit scan 2010-06-07 20:01:19
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\UIVATE~1\LOCALS~1\Temp\uxtdrpow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB07EEC7A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB07EEB36]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB07EF0EA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB07EF014]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB07EE70C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB07EEC10]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB07EE64C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB07EE6B0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB07EED30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB07EF1B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB07EECF0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB07EEE70]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB07FBAC6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB07FB8EA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB07FBA24]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2CCC 80504568 4 Bytes JMP 54B07EF0
PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP B07FBA28 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP B07FB8EE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP B07F7536 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP B07F8EC2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B07FBACA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB33E3380, 0x566445, 0xE8000020]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x57 0x54 0xDE 0x1B ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x57 0x54 0xDE 0x1B ...
---- EOF - GMER 1.0.15 ----
Re: Avast5 hlásí Zablokován škodlivý URL
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
Re: Avast5 hlásí Zablokován škodlivý URL
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Verze databáze: 4176
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7.6.2010 20:35:41
mbam-log-2010-06-07 (20-35-41).txt
Typ skenu: Úplný sken (C:\|)
Skenované objekty: 157138
Uplynulý čas: 18 minuta(y), 6 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 6
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 2
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
C:\Documents and Settings\Uživatel\Data aplikací\avdrn.dat (Malware.Trace) -> No action taken.
C:\clean.cmd (Trojan.Agent) -> No action taken.
www.malwarebytes.org
Verze databáze: 4176
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
7.6.2010 20:35:41
mbam-log-2010-06-07 (20-35-41).txt
Typ skenu: Úplný sken (C:\|)
Skenované objekty: 157138
Uplynulý čas: 18 minuta(y), 6 sekunda(y)
Infikované procesy v paměti: 0
Infikované moduly v paměti: 0
Infikované klíče registru: 6
Infikované hodnoty registru: 0
Infikované datové položky registru: 0
Infikované složky: 0
Infikované soubory: 2
Infikované procesy v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)
Infikované klíče registru:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> No action taken.
Infikované hodnoty registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)
Infikované složky:
(Žádné škodlivé položky nebyly zjištěny)
Infikované soubory:
C:\Documents and Settings\Uživatel\Data aplikací\avdrn.dat (Malware.Trace) -> No action taken.
C:\clean.cmd (Trojan.Agent) -> No action taken.
Re: Avast5 hlásí Zablokován škodlivý URL
Počítači už konečně funguje klávesnice, ale ještě to určitě není ono občas vytuhne přibližně na 5 minut a pak je to zase dobré.
Re: Avast5 hlásí Zablokován škodlivý URL
Co našel mbam, smažte.
Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Podívejte se do správce zařízení, zda tam nemáte nějaké žluté otazníky.

-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka
Kód: Vybrat vše
Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\DOCUME~1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1\LOCALS~1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\docume~1\UIVATE~1\LOCALS~1\Temp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\windows\TEMP]
Restore::
c:\windows\system32\dllcache\grpconv.exe
Dirlook::
c:\windows\system32\Lang
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

-po aplikaci na Vás vypadne další log,vložte ho sem
Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Avast5 hlásí Zablokován škodlivý URL
ComboFix 10-06-06.04 - Uživatel 07.06.2010 21:20:17.2.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1567 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\potvora.exe
Použité ovládací přepínače :: c:\documents and settings\Uživatel\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
Nakažená kopie c:\windows\system32\dllcache\grpconv.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\grpconv.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-07 do 2010-06-07 )))))))))))))))))))))))))))))))
.
2010-06-07 18:08 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-07 18:08 . 2010-06-07 18:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-07 18:08 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-07 11:58 . 2008-04-14 08:52 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-07 11:58 . 2008-04-14 08:52 39424 ----a-w- c:\windows\system32\grpconv.exe
2010-06-07 11:43 . 2010-06-07 12:03 -------- d-----w- C:\potvora
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- C:\rsit
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- c:\program files\trend micro
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-06-07 09:59 . 2010-06-07 09:59 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-05-30 18:02 . 2008-04-13 20:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-05-30 18:01 . 2010-05-30 18:01 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-30 18:00 . 2010-05-30 18:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-05-11 06:26 . 2010-05-11 06:26 -------- d-----w- c:\program files\MSXML 4.0
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\HP
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Hewlett-Packard
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-05-10 16:38 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\hpzipr12.sys
2010-05-10 16:38 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\hpzid412.sys
2010-05-10 16:38 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\hpzius12.sys
2010-05-10 16:38 . 2007-03-30 15:07 267864 ----a-r- c:\windows\system32\hpzids01.dll
2010-05-10 16:37 . 2007-03-28 12:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2010-05-10 16:37 . 2007-03-28 11:57 274944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5ha.dll
2010-05-10 16:37 . 2007-03-17 16:11 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2010-05-10 16:37 . 2007-03-17 16:11 303104 ----a-r- c:\windows\system32\hpovst10.dll
2010-05-10 16:37 . 2007-03-17 16:11 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2010-05-10 16:37 . 2007-03-08 04:20 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-05-10 16:37 . 2007-03-08 04:20 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-05-10 16:37 . 2008-04-13 20:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-10 16:37 . 2008-04-13 20:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-10 16:37 . 2010-05-10 16:41 -------- d-----w- c:\program files\HP
2010-05-10 16:35 . 2010-05-10 16:42 158092 ----a-w- c:\windows\hpoins14.dat
2010-05-10 16:35 . 2007-06-05 23:07 2000 ------w- c:\windows\hpomdl14.dat
2010-05-10 16:25 . 2008-04-13 20:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-10 16:25 . 2008-04-13 20:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-07 19:19 . 2001-10-25 16:00 77872 ----a-w- c:\windows\system32\perfc005.dat
2010-06-07 19:19 . 2001-10-25 16:00 428750 ----a-w- c:\windows\system32\perfh005.dat
2010-05-21 12:14 . 2010-05-08 13:29 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 15:30 . 2010-05-08 15:30 -------- d-----w- c:\program files\Electronic Arts
2010-05-08 15:26 . 2010-05-08 15:25 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-08 15:10 . 2010-05-08 13:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-08 14:59 . 2010-05-08 14:59 -------- d-----w- c:\program files\Microsoft.NET
2010-05-08 14:56 . 2010-05-08 14:56 -------- d-----w- c:\program files\Alcohol Soft
2010-05-08 14:52 . 2010-05-08 14:51 -------- d-----w- c:\program files\Common Files\Ahead
2010-05-08 14:51 . 2010-05-08 14:51 -------- d-----w- c:\program files\Nero
2010-05-08 14:46 . 2010-05-08 14:46 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\MSBuild
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\Reference Assemblies
2010-05-08 13:23 . 2010-05-08 13:22 -------- d-----w- c:\program files\Google
2010-05-08 13:22 . 2010-05-08 13:22 -------- d-----w- c:\program files\Alwil Software
2010-05-08 13:10 . 2010-05-08 13:10 -------- d-----w- c:\program files\NVIDIA Corporation
2010-05-08 13:07 . 2010-05-08 13:07 -------- d-----w- c:\program files\Realtek
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\AMD
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 13:00 . 2010-05-08 13:00 -------- d-----w- c:\program files\ATI
2010-05-08 12:59 . 2010-05-08 12:59 -------- d-----w- c:\program files\ATI Technologies
2010-05-08 12:57 . 2010-01-21 20:11 202064 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys
2010-05-08 12:57 . 2010-01-12 11:35 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2010-05-08 12:57 . 2010-01-12 11:35 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2010-05-07 17:33 . 2010-05-07 17:03 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-07 17:33 . 2010-05-07 17:03 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-05-07 17:32 . 2010-05-07 17:03 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-05-07 17:11 . 2010-05-07 17:11 -------- d-----w- c:\program files\Windows Defender
2010-05-07 17:05 . 2010-05-07 17:05 -------- d-----w- c:\program files\microsoft frontpage
2010-05-07 17:01 . 2010-05-07 17:01 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-07 17:00 . 2010-05-07 17:00 -------- d-----w- c:\program files\Windows Media Connect 2
2010-05-06 20:59 . 2010-05-08 13:22 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2010-05-08 13:22 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-05-08 13:22 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-05-08 13:22 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-05-08 13:22 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-05-08 13:22 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-05-08 13:22 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-05-08 13:22 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-05-08 13:22 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-16 18:00 . 2010-05-08 14:46 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-04-03 22:55 . 2010-05-08 13:10 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-04-03 22:55 . 2010-05-08 13:10 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2010-05-08 13:10 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-04-03 22:55 . 2010-05-08 13:10 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2010-05-08 13:10 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2010-05-08 13:10 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2010-05-08 13:10 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2010-05-08 13:10 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2010-05-08 13:10 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-04-03 22:55 . 2010-05-08 13:10 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-17 14:52 . 2010-05-08 13:07 84512 ----a-w- c:\windows\SOUNDMAN.EXE
2010-03-17 14:52 . 2010-05-08 13:07 358944 ----a-w- c:\windows\vncutil.exe
2010-03-17 14:52 . 2010-05-08 13:07 1833504 ----a-w- c:\windows\SkyTel.exe
2010-03-17 14:52 . 2010-05-08 13:07 1489440 ----a-w- c:\windows\RtlUpd.exe
2010-03-17 14:52 . 2010-05-08 13:07 9721888 ----a-w- c:\windows\RTLCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 51232 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-03-17 14:52 . 2010-05-08 13:07 129568 ----a-w- c:\windows\RtkAudioService.exe
2010-03-17 14:52 . 2010-05-08 13:07 19520544 ----a-w- c:\windows\RTHDCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2177568 ----a-w- c:\windows\MicCal.exe
2010-03-17 14:52 . 2010-05-08 13:07 64032 ----a-w- c:\windows\ALCMTR.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2815520 ----a-w- c:\windows\ALCWZRD.EXE
2010-03-17 14:40 . 2010-05-08 13:07 5878304 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-03-15 09:31 . 2010-05-08 14:46 165376 ----a-w- c:\windows\system32\unrar.dll
2010-03-10 06:17 . 2008-04-27 10:10 420352 ----a-w- c:\windows\system32\vbscript.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\Lang ----
------- Sigcheck -------
[-] 2008-04-27 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-06-07_12.00.36 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-10-25 16:00 . 2010-06-07 11:57 67312 c:\windows\system32\perfc009.dat
+ 2001-10-25 16:00 . 2010-06-07 19:19 67312 c:\windows\system32\perfc009.dat
+ 2001-10-25 16:00 . 2010-06-07 19:19 432356 c:\windows\system32\perfh009.dat
- 2001-10-25 16:00 . 2010-06-07 11:57 432356 c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-17 19520544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-8-11 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-8-10 741987]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.5.2010 15:22 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.5.2010 15:22 19024]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.5.2010 15:22 133104]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore1caeeb44c73b6ba.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{A765E925-112D-4537-B23D-854CD2E943F0}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{F351F816-E3FD-420F-AC24-A0BC2BBEAFED}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {12327735-C4FF-499F-8B54-68D674F434AC} = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-07 21:24
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(3224)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2010-06-07 21:26:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-06-07 19:26
ComboFix2.txt 2010-06-07 12:03
Před spuštěním: Volných bajtů: 141 456 744 448
Po spuštění: Volných bajtů: 141 474 885 632
- - End Of File - - B467465DB554BEC44D2336272427705E
PS: Ve správci zařízení žádný vykřičník není vše je dobře nainstalováno s aktuálními ovladači staženými před 14 dny za stránek výrobců.
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2047.1567 [GMT 2:00]
Spuštěný z: c:\documents and settings\Uživatel\Plocha\potvora.exe
Použité ovládací přepínače :: c:\documents and settings\Uživatel\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
Nakažená kopie c:\windows\system32\dllcache\grpconv.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\system32\grpconv.exe
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-05-07 do 2010-06-07 )))))))))))))))))))))))))))))))
.
2010-06-07 18:08 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-07 18:08 . 2010-06-07 18:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-07 18:08 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-07 11:58 . 2008-04-14 08:52 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-07 11:58 . 2008-04-14 08:52 39424 ----a-w- c:\windows\system32\grpconv.exe
2010-06-07 11:43 . 2010-06-07 12:03 -------- d-----w- C:\potvora
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- C:\rsit
2010-06-07 11:19 . 2010-06-07 11:20 -------- d-----w- c:\program files\trend micro
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2010-06-07 10:01 . 2010-06-07 10:01 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-06-07 09:59 . 2010-06-07 09:59 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-05-30 18:02 . 2008-04-13 20:10 34688 -c--a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:10 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-05-30 18:02 . 2008-04-13 20:11 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-05-30 18:01 . 2010-05-30 18:01 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-30 18:00 . 2010-05-30 18:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-05-11 06:26 . 2010-05-11 06:26 -------- d-----w- c:\program files\MSXML 4.0
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\HP
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Hewlett-Packard
2010-05-10 16:39 . 2010-05-10 16:39 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-05-10 16:38 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\hpzipr12.sys
2010-05-10 16:38 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\hpzid412.sys
2010-05-10 16:38 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\hpzius12.sys
2010-05-10 16:38 . 2007-03-30 15:07 267864 ----a-r- c:\windows\system32\hpzids01.dll
2010-05-10 16:37 . 2007-03-28 12:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2010-05-10 16:37 . 2007-03-28 11:57 274944 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5ha.dll
2010-05-10 16:37 . 2007-03-17 16:11 675840 ----a-r- c:\windows\system32\hpowiax3.dll
2010-05-10 16:37 . 2007-03-17 16:11 303104 ----a-r- c:\windows\system32\hpovst10.dll
2010-05-10 16:37 . 2007-03-17 16:11 569344 ----a-r- c:\windows\system32\hpotscl3.dll
2010-05-10 16:37 . 2007-03-08 04:20 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2010-05-10 16:37 . 2007-03-08 04:20 309760 ----a-r- c:\windows\system32\difxapi.dll
2010-05-10 16:37 . 2008-04-13 20:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-10 16:37 . 2008-04-13 20:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-10 16:37 . 2010-05-10 16:41 -------- d-----w- c:\program files\HP
2010-05-10 16:35 . 2010-05-10 16:42 158092 ----a-w- c:\windows\hpoins14.dat
2010-05-10 16:35 . 2007-06-05 23:07 2000 ------w- c:\windows\hpomdl14.dat
2010-05-10 16:25 . 2008-04-13 20:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-10 16:25 . 2008-04-13 20:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-07 19:19 . 2001-10-25 16:00 77872 ----a-w- c:\windows\system32\perfc005.dat
2010-06-07 19:19 . 2001-10-25 16:00 428750 ----a-w- c:\windows\system32\perfh005.dat
2010-05-21 12:14 . 2010-05-08 13:29 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-08 15:30 . 2010-05-08 15:30 -------- d-----w- c:\program files\Electronic Arts
2010-05-08 15:26 . 2010-05-08 15:25 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-08 15:10 . 2010-05-08 13:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-08 14:59 . 2010-05-08 14:59 -------- d-----w- c:\program files\Microsoft.NET
2010-05-08 14:56 . 2010-05-08 14:56 -------- d-----w- c:\program files\Alcohol Soft
2010-05-08 14:52 . 2010-05-08 14:51 -------- d-----w- c:\program files\Common Files\Ahead
2010-05-08 14:51 . 2010-05-08 14:51 -------- d-----w- c:\program files\Nero
2010-05-08 14:46 . 2010-05-08 14:46 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\MSBuild
2010-05-08 13:38 . 2010-05-08 13:38 -------- d-----w- c:\program files\Reference Assemblies
2010-05-08 13:23 . 2010-05-08 13:22 -------- d-----w- c:\program files\Google
2010-05-08 13:22 . 2010-05-08 13:22 -------- d-----w- c:\program files\Alwil Software
2010-05-08 13:10 . 2010-05-08 13:10 -------- d-----w- c:\program files\NVIDIA Corporation
2010-05-08 13:07 . 2010-05-08 13:07 -------- d-----w- c:\program files\Realtek
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\AMD
2010-05-08 13:06 . 2010-05-08 13:06 -------- d-----w- c:\program files\Common Files\InstallShield
2010-05-08 13:00 . 2010-05-08 13:00 -------- d-----w- c:\program files\ATI
2010-05-08 12:59 . 2010-05-08 12:59 -------- d-----w- c:\program files\ATI Technologies
2010-05-08 12:57 . 2010-01-21 20:11 202064 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys
2010-05-08 12:57 . 2010-01-12 11:35 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2010-05-08 12:57 . 2010-01-12 11:35 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2010-05-07 17:33 . 2010-05-07 17:03 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-07 17:33 . 2010-05-07 17:03 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-05-07 17:32 . 2010-05-07 17:03 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-05-07 17:11 . 2010-05-07 17:11 -------- d-----w- c:\program files\Windows Defender
2010-05-07 17:05 . 2010-05-07 17:05 -------- d-----w- c:\program files\microsoft frontpage
2010-05-07 17:01 . 2010-05-07 17:01 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-07 17:00 . 2010-05-07 17:00 -------- d-----w- c:\program files\Windows Media Connect 2
2010-05-06 20:59 . 2010-05-08 13:22 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-05-06 20:59 . 2010-05-08 13:22 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-05-08 13:22 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-05-08 13:22 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-05-08 13:22 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-05-08 13:22 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-05-08 13:22 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-05-08 13:22 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-05-08 13:22 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-16 18:00 . 2010-05-08 14:46 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-04-03 22:55 . 2010-05-08 13:10 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-04-03 22:55 . 2010-05-08 13:10 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2010-05-08 13:10 10232128 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-04-03 22:55 . 2010-05-08 13:10 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2010-05-08 13:10 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2010-05-08 13:10 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2010-05-08 13:10 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2010-05-08 13:10 227944 ----a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2010-05-08 13:10 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2010-05-08 13:10 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-04-03 22:55 . 2010-05-08 13:10 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-04-03 17:23 . 2010-04-03 17:23 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-04-03 17:23 . 2010-04-03 17:23 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-04-03 17:23 . 2010-04-03 17:23 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-04-03 17:23 . 2010-04-03 17:23 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-04-03 17:23 . 2010-04-03 17:23 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-04-03 17:22 . 2010-04-03 17:22 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-17 14:52 . 2010-05-08 13:07 84512 ----a-w- c:\windows\SOUNDMAN.EXE
2010-03-17 14:52 . 2010-05-08 13:07 358944 ----a-w- c:\windows\vncutil.exe
2010-03-17 14:52 . 2010-05-08 13:07 1833504 ----a-w- c:\windows\SkyTel.exe
2010-03-17 14:52 . 2010-05-08 13:07 1489440 ----a-w- c:\windows\RtlUpd.exe
2010-03-17 14:52 . 2010-05-08 13:07 9721888 ----a-w- c:\windows\RTLCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 51232 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-03-17 14:52 . 2010-05-08 13:07 129568 ----a-w- c:\windows\RtkAudioService.exe
2010-03-17 14:52 . 2010-05-08 13:07 19520544 ----a-w- c:\windows\RTHDCPL.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2177568 ----a-w- c:\windows\MicCal.exe
2010-03-17 14:52 . 2010-05-08 13:07 64032 ----a-w- c:\windows\ALCMTR.EXE
2010-03-17 14:52 . 2010-05-08 13:07 2815520 ----a-w- c:\windows\ALCWZRD.EXE
2010-03-17 14:40 . 2010-05-08 13:07 5878304 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-03-15 09:31 . 2010-05-08 14:46 165376 ----a-w- c:\windows\system32\unrar.dll
2010-03-10 06:17 . 2008-04-27 10:10 420352 ----a-w- c:\windows\system32\vbscript.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\Lang ----
------- Sigcheck -------
[-] 2008-04-27 . 1E603EA2A3FDBAE9E5B88A8CB3C03124 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-06-07_12.00.36 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-10-25 16:00 . 2010-06-07 11:57 67312 c:\windows\system32\perfc009.dat
+ 2001-10-25 16:00 . 2010-06-07 19:19 67312 c:\windows\system32\perfc009.dat
+ 2001-10-25 16:00 . 2010-06-07 19:19 432356 c:\windows\system32\perfh009.dat
- 2001-10-25 16:00 . 2010-06-07 11:57 432356 c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-03-17 19520544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-03 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-03 13670504]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-8-11 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-8-10 741987]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8.5.2010 15:22 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8.5.2010 15:22 19024]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [3.11.2006 19:19 13592]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.5.2010 15:22 133104]
S4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore1caeeb44c73b6ba.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-08 13:22]
2010-06-07 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{A765E925-112D-4537-B23D-854CD2E943F0}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
2010-06-07 c:\windows\Tasks\User_Feed_Synchronization-{F351F816-E3FD-420F-AC24-A0BC2BBEAFED}.job
- c:\windows\system32\msfeedssync.exe [2008-04-27 02:31]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {12327735-C4FF-499F-8B54-68D674F434AC} = 192.168.1.1
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKCU-Run-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-07 21:24
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'explorer.exe'(3224)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Celkový čas: 2010-06-07 21:26:53 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-06-07 19:26
ComboFix2.txt 2010-06-07 12:03
Před spuštěním: Volných bajtů: 141 456 744 448
Po spuštění: Volných bajtů: 141 474 885 632
- - End Of File - - B467465DB554BEC44D2336272427705E
PS: Ve správci zařízení žádný vykřičník není vše je dobře nainstalováno s aktuálními ovladači staženými před 14 dny za stránek výrobců.
Re: Avast5 hlásí Zablokován škodlivý URL
Jak to vypadá s počítačem ted?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Re: Avast5 hlásí Zablokován škodlivý URL
Zdá se to být v pohodě po dokončení Combofixu pracuje jako vždy, mockrát děkuji za pomoc !
Re: Avast5 hlásí Zablokován škodlivý URL
arrow: Odinstalujte combofix přes Start - Spustit
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********
Stáhněte T-Cleaner
http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********
Z mého podpisu stahněte Ccleaner
- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru
záložka čistič
- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner
záložka Registry
- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy
ok
zavřít
Záložka Nástroje
- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********
Stahněte OTC a použijte
http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********
Vložte nový log ze RSIT a řekněte co počítač, jak se chová, už je vše v pořádku?
- zkopírujte do okénka:
ComboFix /Uninstall
-stiskněte Enter
-To odinstaluje ComboFix a smaže s ním související soubory a složky.
***********

http://sweb.cz/Marinus/T-Cleaner.exe
-Spusťte,pro potvrzení volby mačkejte klávesu A, Enter
-po použití prográmek vymažte.Pozor,antiviry ho mohou falešně označit za vir
***********

- nainstalujte, při výběru, co se má nainstalovat, dejte pryč fajfku u instalace yahoo toolbaru

- nechejte v levém sloupečku zatrhnuté vše jak je, klikněte na analyzovat
- po analýze klikněte na Spustit Ccleaner

- klikněte na hledej problémy
- pak klikněte na opravit vybrané problémy -- udělat zálohu registrů - nemusíte
- kliknete opravit všechny problémy



- zde můžete odinstalovat programy. Je to důkladnější odinstalace než u přidat/odebrat programy ve Windows.
Ccleaner - čistič doporučuji používat, krásně pročistí pc od dočasných souborů.
Registry pročistí třeba po odinstalaci nějakého programu.
***********

http://oldtimer.geekstogo.com/OTC.exe
-vyčistí tempy a po použitých programech
***********

Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data
Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.
Vždy před odvirováním počítače zazálohujte důležitá data

Chcete podpořit naše forum? Informace zde

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.