Stránka 1 z 2

Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 13:36
od vapno13
Moj PC posiela velke mnozstvo spamu. Uz som pouzil NOD, Eset online scanner, Spyware Terminator, AdAware, pricom najdene infiltracie som vymazal alebo ulozil do karanteny. Mam k PC pripojeny este 1TB externy HDD, aj ten mi preskenovali vyssie uvedene programy. Aj napriek tomu mi po zapnuti spamu zacne PC posielat kopec spamu. Chcel by preto som poprosit o kontrologu logu z RSIT. Vopred dakujem.

Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-19 14:16:26
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (8%) free of 118 GB
Total RAM: 2047 MB (68% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:16:40, on 19.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 9488 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-11-16 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2

C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe

C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-06-19 14:16:26 ----D---- C:\rsit
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:52:50 ----A---- C:\ComboFix.txt
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 13:37:14 ----A---- C:\WINDOWS\zip.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWSC.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\SWREG.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\sed.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\PEV.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\NIRCMD.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\MBR.exe
2010-06-19 13:37:14 ----A---- C:\WINDOWS\grep.exe
2010-06-19 13:37:03 ----D---- C:\WINDOWS\ERDNT
2010-06-19 13:34:30 ----AD---- C:\Qoobox
2010-06-19 12:05:37 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia

======List of files/folders modified in the last 1 months======

2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:50:08 ----D---- C:\WINDOWS
2010-06-19 13:50:08 ----A---- C:\WINDOWS\system.ini
2010-06-19 13:49:46 ----D---- C:\WINDOWS\Temp
2010-06-19 13:49:24 ----D---- C:\WINDOWS\system32
2010-06-19 13:48:12 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-19 13:46:35 ----D---- C:\WINDOWS\system32\drivers
2010-06-19 13:46:35 ----D---- C:\WINDOWS\AppPatch
2010-06-19 13:46:32 ----D---- C:\Program Files\Common Files
2010-06-19 13:43:01 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:37:49 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-19 13:21:37 ----D---- C:\Program Files\ArsClip
2010-06-19 13:18:12 ----SHD---- C:\WINDOWS\Installer
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:57:23 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 12:05:25 ----D---- C:\WINDOWS\system32\config
2010-06-19 11:39:18 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 11:37:08 ----D---- C:\WINDOWS\Debug
2010-06-19 11:37:07 ----D---- C:\WINDOWS\Minidump
2010-06-19 11:25:45 ----D---- C:\WINDOWS\Prefetch
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-19 11:03:42 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-17 00:06:52 ----HD---- C:\WINDOWS\inf
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\Restore
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 catchme;catchme; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\catchme.sys []
S3 mbr;mbr; \??\C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys []
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-11-10 774144]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]

-----------------EOF-----------------

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 13:42
od Caroprd111
Zdravím :)

Obrázek Vložte sem log C:\ComboFix.txt

Nedoporučuji používat ComboFix z vlastní iniciativy, může dojít k poškození systému!

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 13:44
od vapno13
Nech sa paci:

ComboFix 10-06-18.03 - mam-desktop 19.06.2010 13:43:23.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1305 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Local Settings\Application Data\Opera\Opera\temporary_downloads\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\fjhdyfhsn.bat
c:\windows\system32\office.exe
I:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.

2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-19 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 11:48 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
2010-05-22 10:29 . 2010-05-22 10:26 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 11:50 . 2010-02-09 10:34 741376 ----a-w- c:\windows\system32\drivers\qizefsf.sys
2010-06-19 11:48 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-19 11:21 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-19 10:57 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 09:39 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]

c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]

--- Other Services/Drivers In Memory ---

*Deregistered* - qizefsf

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-Wdf01000.sys
MSConfigStartUp-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
MSConfigStartUp-Ovi Files Update - c:\program files\Ovi Files\updater.exe
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
AddRemove-Nokia Ovi Suite - c:\documents and settings\All Users\Application Data\OviInstallerCache\{DEE1E2E5-B553-4F88-9DE7-23CBEA5D739C}\Nokia_Ovi_Suite_webinstaller_ALL.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-19 13:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qizefsf]

.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abcecigninajfgncahjnknkolinkmdjdfm"=hex:65,62,63,65,6a,6a,64,6b,6f,69,68,63,
6e,66,67,70,65,6e,64,6f,6b,6a,6c,67,63,6d,6a,68,65,6c,64,6d,62,6c,70,6c,65,\
"bbcecigninajfgncahgnjkgigagcolkmnpjf"=hex:61,62,68,67,6a,65,6d,6e,68,6c,67,6e,
6d,6e,64,61,68,6d,6a,63,62,6e,66,6f,68,61,6a,6a,62,6a,68,62,63,69,00,6c
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\DkWLNP.dll
.
Completion time: 2010-06-19 13:52:49
ComboFix-quarantined-files.txt 2010-06-19 11:52

Pre-Run: 6 998 347 776 bytes free
Post-Run: 9 400 561 664 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /bootlogo

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 0B2CE0E4DCA546CFE513A02EF2749335

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 13:54
od Caroprd111
Obrázek Pokud nemáte, přesuňte Combofix na plochu
  • Otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.

Kód: Vybrat vše

File::
c:\windows\system32\drivers\qizefsf.sys


Driver::
qizefsf

RegLock::
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
  • Uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
  • Po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:

    Obrázek
  • Po aplikaci na Vás vypadne další log,vložte ho sem
Může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 14:28
od vapno13
ComboFix 10-06-18.03 - mam-desktop 19.06.2010 15:03:17.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1308 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mam-desktop\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

FILE ::
"c:\windows\system32\drivers\qizefsf.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\qizefsf.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_QIZEFSF
-------\Service_qizefsf


((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.

2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- C:\rsit
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- c:\program files\trend micro
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-19 13:15 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 11:48 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 13:14 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-19 13:11 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-19 12:41 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 10:57 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-22 10:26 . 2010-05-22 10:29 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]

c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [16.6.2010 19:18 142592]
R2 DkVcm;Datakey's Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [23.11.2004 10:33 122880]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28.1.2009 13:34 634488]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25.9.2009 23:32 189736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [16.3.2004 3:04 18536]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-19 15:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abcecigninajfgncahjnknkolinkmdjdfm"=hex:65,62,63,65,6a,6a,64,6b,6f,69,68,63,
6e,66,67,70,65,6e,64,6f,6b,6a,6c,67,63,6d,6a,68,65,6c,64,6d,62,6c,70,6c,65,\
"bbcecigninajfgncahgnjkgigagcolkmnpjf"=hex:61,62,68,67,6a,65,6d,6e,68,6c,67,6e,
6d,6e,64,61,68,6d,6a,63,62,6e,66,6f,68,61,6a,6a,62,6a,68,62,63,69,00,6c
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(924)
c:\windows\system32\DkWLNP.dll

- - - - - - - > 'explorer.exe'(572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\windows\System32\drprov.dll
c:\windows\System32\davclnt.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\DkLog.exe
c:\windows\system32\SCardSvr.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\System32\dkcktkn.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\SpeedProject\SpeedCommander 12\SpeedCommander.exe
.
**************************************************************************
.
Completion time: 2010-06-19 15:21:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-19 13:21
ComboFix2.txt 2010-06-19 11:52

Pre-Run: 9 396 215 808 bytes free
Post-Run: 9 291 743 232 bytes free

- - End Of File - - 07D52D694205E150841019A3AD8D820C

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 14:40
od Caroprd111
Obrázek Odinstalujte všechny emulátory virtuálních mechanik.

Obrázek Stáhněte SPTD http://www.duplexsecure.com/en/downloads
  • Vyberte verzi podle svého operačního systému (64 & 32b). Uložte na plochu a spusťte.
  • zvolte možnost Uninstall a restartujte PC.

Obrázek Stáhněte a spusťte http://www.jpshortstuff.247fixes.com/Defogger.exe
  • Klikněte na "Disable" a restartujte PC.

Obrázek Stáhněte MBR na plochu http://www2.gmer.net/mbr/mbr.exe

Obrázek Start > Spustit (Win + R)
  • Vyskočí okénko, zkopírujte do něj:

Kód: Vybrat vše

"%userprofile%\desktop\mbr" -t
  • Klikněte na OK
  • Vytvoří se log s názvem mbr.log, vložte ho sem.

Obrázek Dejte log z Gmer http://www.viry.cz/forum/viewtopic.php?f=29&t=62878

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 15:13
od vapno13
Prikladam log z mbr:

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK



a log z gmer:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-06-19 16:11:49
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\pwldipow.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)

---- EOF - GMER 1.0.15 ----

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 15:14
od Caroprd111
OK, ještě druhý log z Gmeru.

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 19 čer 2010 23:25
od vapno13
tu prikladam druhy log z GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-20 00:23:31
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\pwldipow.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xB837F88E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xB837F0EC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xB837EDCE]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xB8380938]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xB837EED8]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xB837EFC2]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xB837FBBC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xB837F3F4]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetInformationFile [0xB837F526]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xB837EBFC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xB837FB04]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xB837F70C]

---- Kernel code sections - GMER 1.0.15 ----

? C:\DOCUME~1\MAM-DE~1\LOCALS~1\Temp\mbr.sys Systém nemôže nájsť zadaný súbor. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1704] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs eBoost.sys (eBoostr Filter Driver/eBoostr.com)
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Ip epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\Udp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)
AttachedDevice \Driver\Tcpip \Device\RawIp epfwtdi.sys (Eset Personal Firewall TDI filter/ESET)

---- Registry - GMER 1.0.15 ----

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}@abcecigninajfgncahjnknkolinkmdjdfm 0x65 0x62 0x63 0x65 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}@bbcecigninajfgncahgnjkgigagcolkmnpjf 0x61 0x62 0x68 0x67 ...

---- EOF - GMER 1.0.15 ----

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 20 čer 2010 09:30
od Caroprd111
Znovu aplikujte skript do CF s tímto obsahem:

Kód: Vybrat vše

RegNull::
[HKEY_USERS\S-1-5-21-606747145-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{48C03611-322E-9349-A051-029CC71B93EC}*]
Jak se chová PC :???:

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 20 čer 2010 12:24
od vapno13
PC sa chova teraz uplne v pohode. Po restarte sa nezacne posielat spam, ako predtym (videl som to vo Firewall NODu, kde som videl ako service.exe posiela nieco a ked som to rozklikol, tak tam bolo asi 20-30 IP adries, s tym, ze vo vlastnostiach bolo ze sa jedna o SMTP, niektore IP adresy mali aj mena a boli to rozne mail.nieco a pod.. Posielalo to kopec MB, aj 500 MB za 15 min.).

Teraz to teda uz vobec nerobi a vsetko sa chova kludne a vo firewalle sa objavuju len veci, ktore viem co su (opera, spyware terminator a pod.). Dakujem Vam, zachranili ste ma pred dalsim odpojenim zo strany mojho providera. Fakt super pomoc, nema to chybu. Ste machri. Este raz dakujem.

Tu posielam log po aplikovani scriptu:

ComboFix 10-06-18.03 - mam-desktop 20.06.2010 13:06:59.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.421.1033.18.2047.1399 [GMT 2:00]
Running from: c:\documents and settings\mam-desktop\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mam-desktop\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.

((((((((((((((((((((((((( Files Created from 2010-05-20 to 2010-06-20 )))))))))))))))))))))))))))))))
.

2010-06-20 10:06 . 2010-06-20 10:06 -------- d-----w- C:\spoolerlogs
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- C:\rsit
2010-06-19 12:16 . 2010-06-19 12:16 -------- d-----w- c:\program files\trend micro
2010-06-19 10:05 . 2010-05-07 16:06 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-06-19 10:05 . 2010-05-07 16:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-06-19 10:04 . 2010-06-19 10:04 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 10:02 . 2010-06-19 10:06 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-06-19 10:01 . 2010-06-19 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-06-19 09:59 . 2010-06-19 09:59 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 09:25 . 2010-06-19 09:25 -------- d-----w- c:\program files\CCleaner
2010-06-16 18:25 . 2010-06-19 10:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 17:46 . 2010-06-16 17:46 -------- d-----w- c:\documents and settings\LocalService\Pracovná plocha
2010-06-16 17:29 . 2010-06-16 17:27 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-16 17:19 . 2010-06-19 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-16 17:18 . 2010-06-16 17:18 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-16 17:18 . 2010-06-16 17:18 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-16 17:18 . 2010-06-16 17:18 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-06-16 17:17 . 2010-06-19 10:05 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-19 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-06-16 17:17 . 2010-06-17 18:07 -------- d-----w- c:\program files\Spyware Terminator
2010-06-16 14:58 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-31 10:54 . 2010-06-20 11:15 -------- d-----w- c:\documents and settings\All Users\Application Data\eboostr
2010-05-31 10:54 . 2010-05-31 12:45 -------- d-----w- c:\program files\eBoostr
2010-05-28 09:05 . 2010-05-28 09:05 -------- d-----w- c:\program files\ICQ6Toolbar
2010-05-28 09:04 . 2010-05-28 09:05 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-05-28 09:04 . 2010-06-19 14:06 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\ICQ
2010-05-28 09:04 . 2010-05-28 09:04 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\AOL
2010-05-28 09:04 . 2010-06-19 11:07 -------- d-----w- c:\program files\ICQ7.1
2010-05-25 14:12 . 2010-05-25 14:12 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 14:02 . 2010-05-25 14:16 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-25 13:56 . 2010-05-31 11:47 -------- d-----w- c:\program files\Windows Desktop Search
2010-05-25 13:54 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-05-25 13:54 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-05-25 13:54 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-05-25 06:29 . 2010-05-25 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ODIR
2010-05-24 15:25 . 2010-05-24 15:25 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 15:13 . 2010-05-24 15:23 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\Nokia
2010-05-24 15:13 . 2010-06-01 16:02 -------- d-----w- c:\documents and settings\mam-desktop\Local Settings\Application Data\NokiaAccount
2010-05-24 14:57 . 2010-05-24 15:20 -------- d-----w- c:\windows\system32\drivers\UMDF
2010-05-23 19:40 . 2010-06-19 09:14 -------- d-----w- c:\program files\7-Zip
2010-05-22 10:33 . 2010-05-22 10:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Nokia
2010-05-22 10:32 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-05-22 10:32 . 2010-05-22 10:32 -------- d-----w- c:\program files\PC Connectivity Solution
2010-05-22 10:31 . 2010-02-26 12:21 8320 ----a-w- c:\windows\system32\drivers\nmwcdnsuc.sys
2010-05-22 10:31 . 2010-02-26 12:21 137344 ----a-w- c:\windows\system32\drivers\nmwcdnsu.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-05-22 10:31 . 2010-02-26 12:32 8192 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-05-22 10:31 . 2010-02-26 12:32 22528 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-05-22 10:31 . 2010-02-26 12:32 662016 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-05-22 10:31 . 2010-02-26 12:32 18176 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-05-22 10:31 . 2010-02-26 12:19 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
2010-05-22 10:29 . 2010-06-06 19:22 -------- d-----w- c:\program files\Common Files\Nokia
2010-05-22 10:29 . 2010-05-22 10:26 35790800 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\NokiaSoftwareUpdaterSetup_sk.exe
2010-05-22 10:27 . 2010-05-22 10:27 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\msxml6Exec.exe
2010-05-22 10:27 . 2010-05-22 10:27 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\Sleep.exe
2010-05-22 10:26 . 2010-05-22 10:26 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{09C468CA-2940-466A-AAE8-DCC0C6E9323C}\Installer\CommonCustomActions\vcredistExec.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-20 11:16 . 2010-01-15 16:11 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Skype
2010-06-20 11:03 . 2009-12-16 20:16 -------- d-----w- c:\program files\ArsClip
2010-06-20 06:07 . 2010-01-15 16:17 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\skypePM
2010-06-19 13:58 . 2009-04-11 19:34 -------- d-----w- c:\program files\Common Files\Ahead
2010-06-19 12:41 . 2009-07-14 20:37 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Media Player Classic
2010-06-19 09:13 . 2009-02-03 18:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-16 19:40 . 2009-02-03 18:56 -------- d-----w- c:\program files\ESET
2010-06-02 17:12 . 2009-04-16 20:10 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-06-02 16:47 . 2010-03-02 11:40 -------- d-----w- c:\program files\Efficasoft Mobile Express
2010-05-24 22:57 . 2009-04-17 20:10 162816 ----a-w- c:\windows\system32\fmod.dll
2010-05-24 15:26 . 2010-05-24 15:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-05-24 15:25 . 2010-05-24 15:25 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-05-24 15:25 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\Nokia
2010-05-24 15:22 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\PC Suite
2010-05-24 15:20 . 2009-08-30 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2010-05-24 15:10 . 2009-08-30 17:36 -------- d-----w- c:\program files\Nokia
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf
2010-05-24 10:35 . 2010-05-24 10:35 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-05-22 10:26 . 2009-08-30 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-05-19 10:04 . 2010-05-19 10:04 -------- d-----w- c:\program files\DWD
2010-05-19 10:03 . 2009-08-29 08:16 -------- d-----w- c:\program files\SAMSUNG
2010-05-17 08:31 . 2010-05-17 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QSign
2010-05-17 08:30 . 2009-03-11 20:03 -------- d-----w- c:\program files\Ardaco
2010-05-17 08:24 . 2009-03-11 20:03 -------- d-----w- c:\documents and settings\mam-desktop\Application Data\QSign
2010-05-10 22:02 . 2010-05-10 22:02 -------- d-----w- c:\program files\I.CA
2010-05-09 15:40 . 2009-02-03 18:30 -------- d-----w- c:\program files\Opera
2010-05-06 10:41 . 2004-08-04 01:07 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 01:07 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-22 22:06 . 2010-02-03 15:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-20 05:30 . 2004-08-04 01:07 285696 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-06-19_11.50.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-20 11:03 . 2010-06-20 11:03 16384 c:\windows\Temp\Perflib_Perfdata_348.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"ICQ"="c:\program files\ICQ7.1\ICQ.exe" [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-01 1443072]
"DkAutoReg.exe"="c:\program files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe" [2004-11-23 245760]
"DkStartup"="c:\program files\SafeNet\iKey 2000 Series Software\DkStartup.exe" [2004-11-23 217088]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\mam-desktop\Start Menu\Programs\Startup\
ArsClip.lnk - c:\program files\ArsClip\ArsClip.exe [2009-12-16 1180672]
Vtlac.lnk - c:\lib\Vtlac.exe [2009-4-28 135168]

c:\documents and settings\All Users\Ponuka ćtart\Programy\Pri spustenˇ\
eBoostr Control Panel.lnk - c:\program files\eBoostr\eBoostrCP.exe [2009-1-28 1406584]
QSign 3.4.lnk - c:\program files\Ardaco\QSign\zepapp.exe [2009-12-14 5314048]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DkWLNP]
2004-11-23 08:33 57344 ----a-w- c:\windows\system32\DkWLNP.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Ovi Files Connector.lnk
backup=c:\windows\pss\Ovi Files Connector.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
path=c:\documents and settings\All Users\Ponuka Štart\Programy\Pri spustení\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2004-12-14 10:12 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
2009-10-28 03:40 257440 ----a-w- c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 12:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
2008-12-16 01:41 1040384 ----a-w- c:\program files\Efficasoft Mobile Express\MobileExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-06-16 17:18 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
2008-04-14 00:12 136704 ----a-w- c:\windows\system32\sti_ci.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
2007-07-19 19:04 110139 ----a-w- c:\windows\XPize\XPizeReloader.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NBService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ABBYY.Licensing.FineReader.Professional.9.0"=2 (0x2)
"WSearch"=2 (0x2)
"Themes"=2 (0x2)
"RDSessMgr"=3 (0x3)
"wscsvc"=2 (0x2)
"helpsvc"=2 (0x2)
"SysmonLog"=3 (0x3)
"CiSvc"=3 (0x3)
"ERSvc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ardaco\\QSign\\zepapp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\ESET\\ESET Smart Security\\egui.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ICQ7.1\\ICQ.exe"=
"c:\\Program Files\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"1100:TCP"= 1100:TCP:dc++
"1101:UDP"= 1101:UDP:dc++
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 eBoost;eBoostr caching filter driver;c:\windows\system32\drivers\eBoost.sys [28.1.2009 13:34 125544]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [16.6.2010 19:18 142592]
R2 DkVcm;Datakey's Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [23.11.2004 10:33 122880]
R2 EBOOSTRSVC;eBoostr Service;c:\program files\eBoostr\EBstrSvc.exe [28.1.2009 13:34 634488]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [21.12.2007 8:21 468224]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25.9.2009 23:32 189736]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [7.5.2010 18:04 1051976]
R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [16.3.2004 3:04 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [16.3.2004 3:04 17928]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [25.2.2010 11:18 10064]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [22.5.2010 12:31 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [22.5.2010 12:31 8320]
S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [16.3.2004 3:04 18536]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [6.12.2007 21:03 660768]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.obcan.sk/
uInternet Settings,ProxyServer = proxy-01-07:8080
IE: Download with Mipony - file://c:\program files\MiPony\Browser\IEContext.htm
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Převést cíl vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést cíl vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Převést vybrané vazby do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Převést vybrané vazby do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Převést výběr do Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Převést výběr do existujícího PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - c:\program files\ICQ7.1\ICQ.exe
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748450} - {CC963627-B1DC-40E0-B52A-CF21EE748450} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748451} - {CC963627-B1DC-40E0-B52A-CF21EE748451} - c:\progra~1\PCTRAN~1\webie.dll
IE: {{CC963627-B1DC-40E0-B52A-CF21EE748452} - {CC963627-B1DC-40E0-B52A-CF21EE748452} - c:\progra~1\PCTRAN~1\webie.dll
DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} - hxxp://download.ica.cz/icapki.cab
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-20 13:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(804)
c:\windows\system32\DkWLNP.dll

- - - - - - - > 'explorer.exe'(2380)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\System32\drprov.dll
c:\windows\System32\davclnt.dll
.
Completion time: 2010-06-20 13:18:57
ComboFix-quarantined-files.txt 2010-06-20 11:18
ComboFix2.txt 2010-06-19 13:21
ComboFix3.txt 2010-06-19 11:52

Pre-Run: 9 464 238 080 bytes free
Post-Run: 9 467 666 432 bytes free

- - End Of File - - AACFBC8104F1F998E5FC6D5A1D4CDE04

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 20 čer 2010 12:27
od Caroprd111
Ještě dočistíme po použitých nástrojích. :)


Obrázek Odinstalujte ComboFix přes:
Start >> Spustit, zkopírujte do okénka:

ComboFix /Uninstall

stiskněte Enter



Obrázek Stáhněte T-Cleaner http://sweb.cz/Marinus/T-Cleaner.exe
  • Spusťte, pro potvrzení volby mačkejte klávesu A, Enter
  • Po použití program vymažte. Pozor, antiviry ho mohou falešně označit za vir.

Obrázek Stáhněte TFC http://oldtimer.geekstogo.com/TFC.exe
  • Spusťte.
  • Klikněte na "Start". Potvrďte hlášku kliknutím na "Ok" (Bude následovat restart)

Obrázek Stáhněte OTC http://oldtimer.geekstogo.com/OTC.exe
  • Spusťte.
  • Klikněte na "CleanUp!". Potvrďte hlášky kliknutím na "Yes" (Bude následovat restart)


Obrázek Stáhněte Ccleaner http://viry.cz/forum/viewtopic.php?t=7478
  • Nainstalujte a v průběhu instalace odškrtněte, že chcete instalovat yahoo toolbar.

    Obrázek Záložka Čistič
  • Dejte analyzovat, po dokončení dejte Spustit Ccleaner.

    Obrázek Záložka Registry
  • Klikněte na Hledej problémy, po dokončení klikněte na Opravit problémy, zálohu dělat nemusíte, potom dejte Opravit všechny problémy.
    Obrázek OK Obrázek Zavřít

Obrázek Dejte nový log z RSIT.

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 20 čer 2010 13:51
od vapno13
Logfile of random's system information tool 1.07 (written by random/random)
Run by mam-desktop at 2010-06-20 14:50:35
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 11 GB (9%) free of 118 GB
Total RAM: 2047 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:42, on 20.6.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ICQ7.1\ICQ.exe
C:\Program Files\eBoostr\eBoostrCP.exe
C:\Program Files\Ardaco\QSign\zepapp.exe
C:\Program Files\ArsClip\ArsClip.exe
C:\Lib\Vtlac.exe
C:\WINDOWS\system32\dkvcm.exe
C:\Program Files\eBoostr\EBstrSvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\mam-desktop\Desktop\RSIT.exe
C:\Program Files\trend micro\mam-desktop.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.obcan.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy-01-07:8080
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DkAutoReg.exe] C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe
O4 - HKLM\..\Run: [DkStartup] C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ArsClip.lnk = C:\Program Files\ArsClip\ArsClip.exe
O4 - Startup: Vtlac.lnk = C:\Lib\Vtlac.exe
O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
O4 - Global Startup: QSign 3.4.lnk = C:\Program Files\Ardaco\QSign\zepapp.exe
O8 - Extra context menu item: Download with Mipony - file://C:\Program Files\MiPony\Browser\IEContext.htm
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Převést vybrané vazby do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést vybrané vazby do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést výběr do Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Převést výběr do existujícího PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: WebTran - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\PROGRA~1\PCTRAN~1\webie.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4C3CEE0B-4F2F-44C3-9586-4368F3200143} (ICApki Class) - http://download.ica.cz/icapki.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: DkWLNP - DkWLNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Datakey's Virtual Channel Monitor (DkVcm) - Datakey, Inc. - C:\WINDOWS\system32\dkvcm.exe
O23 - Service: eBoostr Service (EBOOSTRSVC) - eBoostr.com - C:\Program Files\eBoostr\EBstrSvc.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe

--
End of file - 9709 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-04-04 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\PROGRA~1\PCTRAN~1\webie.dll [2004-05-13 319488]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2008-03-01 1443072]
"DkAutoReg.exe"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkAutoReg.exe [2004-11-23 245760]
"DkStartup"=C:\Program Files\SafeNet\iKey 2000 Series Software\DkStartup.exe [2004-11-23 217088]
"MaxMenuMgr"=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2009-09-25 185640]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-16 2176512]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2010-04-29 1090952]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2009-10-09 25623336]
"ICQ"=C:\Program Files\ICQ7.1\ICQ.exe [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-04-04 36272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FlashPlayerUpdate]
C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe [2009-10-28 257440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileExpress]
C:\Program Files\Efficasoft Mobile Express\MobileExpress.exe [2008-12-16 1040384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-06-16 3037696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
C:\WINDOWS\system32\sti_ci.dll [2008-04-14 136704]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XPize Reloader]
C:\WINDOWS\XPize\XPizeReloader.exe [2007-07-19 110139]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Ovi Files Connector.lnk]
C:\PROGRA~1\OVIFIL~1\OVIFIL~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Ponuka Štart^Programy^Pri spustení^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2
"ose"=3
"odserv"=3
"NBService"=3
"JavaQuickStarterService"=2
"ABBYY.Licensing.FineReader.Professional.9.0"=2
"WSearch"=2
"Themes"=2
"RDSessMgr"=3
"wscsvc"=2
"helpsvc"=2
"SysmonLog"=3
"CiSvc"=3
"ERSvc"=2

C:\Documents and Settings\All Users\Ponuka Štart\Programy\Pri spustení
eBoostr Control Panel.lnk - C:\Program Files\eBoostr\eBoostrCP.exe
QSign 3.4.lnk - C:\Program Files\Ardaco\QSign\zepapp.exe

C:\Documents and Settings\mam-desktop\Start Menu\Programs\Startup
ArsClip.lnk - C:\Program Files\ArsClip\ArsClip.exe
Vtlac.lnk - C:\Lib\Vtlac.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\DkWLNP]
C:\WINDOWS\system32\DkWLNP.dll [2004-11-23 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Ardaco\QSign\zepapp.exe"="C:\Program Files\Ardaco\QSign\zepapp.exe:*:Enabled:QSign"
"C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\Program Files\ESET\ESET Smart Security\egui.exe"="C:\Program Files\ESET\ESET Smart Security\egui.exe:*:Enabled:ESET Smart Security"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\ICQ7.1\ICQ.exe"="C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"C:\Program Files\ICQ7.1\aolload.exe"="C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"

======List of files/folders created in the last 1 months======

2010-06-20 14:50:35 ----D---- C:\rsit
2010-06-20 14:50:03 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-20 14:42:38 ----SHD---- C:\RECYCLER
2010-06-20 12:06:11 ----D---- C:\spoolerlogs
2010-06-19 15:52:34 ----D---- C:\Config.Msi
2010-06-19 14:16:26 ----D---- C:\Program Files\trend micro
2010-06-19 13:41:03 ----A---- C:\Boot.bak
2010-06-19 13:40:59 ----RASHD---- C:\cmdcons
2010-06-19 12:05:23 ----A---- C:\WINDOWS\system32\TURegOpt.exe
2010-06-19 12:05:13 ----A---- C:\WINDOWS\system32\uxtuneup.dll
2010-06-19 12:04:16 ----D---- C:\Documents and Settings\mam-desktop\Application Data\TuneUp Software
2010-06-19 12:02:55 ----D---- C:\Program Files\TuneUp Utilities 2010
2010-06-19 12:01:59 ----D---- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2010-06-19 11:59:01 ----SHD---- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-06-19 11:25:16 ----D---- C:\Program Files\CCleaner
2010-06-16 21:03:51 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-16 21:02:45 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-16 21:01:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-16 20:25:14 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-06-16 20:15:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-16 20:14:52 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-16 20:14:04 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-16 19:19:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-06-16 19:17:59 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Spyware Terminator
2010-06-16 19:17:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-06-16 19:17:25 ----D---- C:\Program Files\Spyware Terminator
2010-06-02 11:16:18 ----A---- C:\WINDOWS\ModemLog_Nokia E63 USB Modem #3.txt
2010-05-31 12:54:57 ----D---- C:\Documents and Settings\All Users\Application Data\eboostr
2010-05-31 12:54:41 ----D---- C:\Program Files\eBoostr
2010-05-28 11:05:05 ----D---- C:\Program Files\ICQ6Toolbar
2010-05-28 11:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\ICQ
2010-05-28 11:04:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\ICQ
2010-05-28 11:04:12 ----D---- C:\Program Files\ICQ7.1
2010-05-27 10:17:54 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-05-27 10:16:07 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-05-25 16:12:31 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Windows Desktop Search
2010-05-25 15:56:41 ----D---- C:\Program Files\Windows Desktop Search
2010-05-25 15:55:51 ----HDC---- C:\WINDOWS\$NtUninstallKB940157$
2010-05-25 15:55:10 ----HDC---- C:\WINDOWS\$NtUninstallKB915800-v4$
2010-05-25 08:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\ODIR
2010-05-25 00:32:33 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-05-25 00:31:34 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-05-24 17:25:19 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia Ovi Suite
2010-05-24 17:22:23 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-05-24 17:21:03 ----HDC---- C:\WINDOWS\$NtUninstallWudf01007$
2010-05-24 16:58:57 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-05-24 16:57:24 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-05-24 12:35:08 ----HDC---- C:\WINDOWS\$NtUninstallWdf01009$
2010-05-23 21:40:54 ----D---- C:\Program Files\7-Zip
2010-05-22 12:33:15 ----D---- C:\Documents and Settings\All Users\Application Data\Nokia
2010-05-22 12:32:19 ----D---- C:\Program Files\PC Connectivity Solution
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2010-05-22 12:31:01 ----A---- C:\WINDOWS\system32\nmwcdcocls.dll
2010-05-22 12:29:32 ----D---- C:\Program Files\Common Files\Nokia

======List of files/folders modified in the last 1 months======

2010-06-20 14:50:41 ----D---- C:\WINDOWS\Prefetch
2010-06-20 14:50:03 ----D---- C:\WINDOWS
2010-06-20 14:47:37 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Media Player Classic
2010-06-20 14:47:36 ----D---- C:\WINDOWS\Debug
2010-06-20 14:47:35 ----D---- C:\WINDOWS\Minidump
2010-06-20 14:47:04 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Skype
2010-06-20 14:45:27 ----D---- C:\WINDOWS\Temp
2010-06-20 14:45:05 ----D---- C:\Program Files\ArsClip
2010-06-20 14:44:12 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-06-20 14:42:38 ----D---- C:\WINDOWS\system32
2010-06-20 14:40:32 ----SHD---- C:\System Volume Information
2010-06-20 14:40:32 ----D---- C:\WINDOWS\system32\Restore
2010-06-20 14:26:17 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-20 13:16:15 ----A---- C:\WINDOWS\system.ini
2010-06-20 13:13:40 ----D---- C:\WINDOWS\system32\drivers
2010-06-20 13:13:40 ----D---- C:\WINDOWS\AppPatch
2010-06-20 13:13:37 ----D---- C:\Program Files\Common Files
2010-06-20 08:07:26 ----D---- C:\Documents and Settings\mam-desktop\Application Data\skypePM
2010-06-19 15:58:47 ----SHD---- C:\WINDOWS\Installer
2010-06-19 15:58:13 ----D---- C:\Program Files\Common Files\Ahead
2010-06-19 15:46:12 ----HD---- C:\WINDOWS\inf
2010-06-19 15:08:52 ----D---- C:\WINDOWS\system32\config
2010-06-19 14:53:16 ----A---- C:\WINDOWS\NeroDigital.ini
2010-06-19 14:16:26 ----RD---- C:\Program Files
2010-06-19 13:51:43 ----SD---- C:\WINDOWS\Tasks
2010-06-19 13:41:03 ----RASH---- C:\boot.ini
2010-06-19 13:17:47 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-06-19 12:55:38 ----D---- C:\Program Files\Internet Explorer
2010-06-19 12:28:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-06-19 12:28:07 ----D---- C:\WINDOWS\system32\inetsrv
2010-06-19 11:13:18 ----HD---- C:\Program Files\InstallShield Installation Information
2010-06-18 06:05:01 ----D---- C:\PU
2010-06-18 00:05:13 ----D---- C:\Lib
2010-06-17 04:51:58 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-17 04:49:35 ----RSD---- C:\WINDOWS\assembly
2010-06-16 21:40:20 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-06-16 21:40:08 ----D---- C:\Program Files\ESET
2010-06-16 21:04:00 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-16 21:02:36 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-16 20:58:34 ----D---- C:\WINDOWS\ie8updates
2010-06-16 20:13:38 ----D---- C:\WINDOWS\system32\CatRoot
2010-06-16 20:05:08 ----D---- C:\WINDOWS\WinSxS
2010-06-08 11:38:05 ----D---- C:\PUA
2010-06-06 21:22:41 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-06-06 21:22:22 ----D---- C:\WINDOWS\security
2010-06-06 21:20:39 ----A---- C:\WINDOWS\win.ini
2010-06-06 21:16:16 ----D---- C:\WINDOWS\Help
2010-06-06 16:07:54 ----D---- C:\WINDOWS\pss
2010-06-04 15:18:23 ----A---- C:\WINDOWS\wdict32.INI
2010-06-02 19:34:36 ----HD---- C:\WINDOWS\XPize
2010-06-02 19:34:05 ----D---- C:\Program Files\WinRAR
2010-06-02 19:34:05 ----D---- C:\Program Files\Windows Media Player
2010-06-02 19:34:05 ----D---- C:\Program Files\Outlook Express
2010-06-02 19:34:05 ----D---- C:\Program Files\Common Files\System
2010-06-02 19:34:04 ----D---- C:\WINDOWS\system32\usmt
2010-06-02 19:22:47 ----D---- C:\Program Files\Adobe
2010-06-02 19:12:09 ----D---- C:\Program Files\Microsoft ActiveSync
2010-06-02 18:47:34 ----D---- C:\Program Files\Efficasoft Mobile Express
2010-05-28 21:37:34 ----A---- C:\WINDOWS\system32\MRT.exe
2010-05-28 14:35:21 ----SD---- C:\Documents and Settings\mam-desktop\Application Data\Microsoft
2010-05-28 11:04:47 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Mozilla
2010-05-25 15:56:48 ----D---- C:\WINDOWS\system32\en-US
2010-05-25 15:56:40 ----HD---- C:\WINDOWS\system32\GroupPolicy
2010-05-25 15:56:40 ----D---- C:\WINDOWS\system32\wbem
2010-05-25 00:57:16 ----A---- C:\WINDOWS\system32\fmod.dll
2010-05-24 17:25:10 ----D---- C:\Documents and Settings\mam-desktop\Application Data\Nokia
2010-05-24 17:22:55 ----D---- C:\Documents and Settings\mam-desktop\Application Data\PC Suite
2010-05-24 17:20:27 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
2010-05-24 17:10:32 ----D---- C:\Program Files\Nokia
2010-05-24 16:57:39 ----D---- C:\WINDOWS\system32\LogFiles
2010-05-22 12:28:25 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-05-22 12:26:25 ----D---- C:\Documents and Settings\All Users\Application Data\Installations

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-01 29704]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2008-03-01 54280]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WS2IFSL;Prostredie podpory poskytovateľa služby Windows Socket 2.0 Non-IFS Service; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
R2 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [1997-12-22 23936]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-01 39944]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2008-03-01 71176]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2008-03-01 30728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 iKeyEnum;Rainbow iKey Enumerator; C:\WINDOWS\system32\DRIVERS\ikeyenum.sys [2004-03-16 11464]
R3 iKeyIFD;Rainbow iKey Virtual Reader; C:\WINDOWS\system32\DRIVERS\ikeyifd.sys [2004-03-16 17928]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-04 5888]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS\system32\drivers\vinyl97.sys [2005-04-08 179968]
S3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2010-02-26 18176]
S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2010-02-26 22528]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2010-02-26 8320]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 RnbToken;Rainbow iKey Token Service; C:\WINDOWS\system32\DRIVERS\rnbtoken.sys [2004-03-16 18536]
S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2010-02-26 8192]
S3 usb_rndisx;USB RNDIS Adapter; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2010-02-26 8192]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]
S3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2009-07-14 444136]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 DkTknSrv;Datakey's Token Service; C:\WINDOWS\System32\dkcktkn.exe [2004-11-23 638976]
R2 DkVcm;Datakey's Virtual Channel Monitor; C:\WINDOWS\system32\dkvcm.exe [2004-11-23 122880]
R2 EBOOSTRSVC;eBoostr Service; C:\Program Files\eBoostr\EBstrSvc.exe [2010-05-31 634488]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-25 189736]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-16 488960]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-05-07 1051976]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 DkLogger;Datakey's Log Service; C:\WINDOWS\System32\DkLog.exe [2004-11-23 102400]
S2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2008-03-01 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-04-27 611840]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2010-06-19 435016]
S4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service; C:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S4 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]

-----------------EOF-----------------

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 20 čer 2010 13:55
od Caroprd111
Log je v pořádku. :)

Re: Prosim o kontrolu logu-PC posiela SPAM

Napsal: 20 čer 2010 13:58
od vapno13
Jeeeej, super, faktazia. Strasne ste mi pomohli. Dakujem Vam aj vsetkym kto maju na svedomi tento web. Este raz velka vdaka.