NOD32 hlásí - Adresa byla zablokována
Napsal: 04 črc 2010 19:46
Prosim pomozte - uz nekolik dni mi NOD vyhazuje tohle okynko, kdyz spustim Firefox a vlezu na nejakou stranku. U IE to dela taky.

V nem se stridaly ruzne www adresy, ktere jsem posbiral a zatim v hosts souboru poslal na 127.0.0.0.
System jsem si projel nejnovejsim NODem, Spyware Terminatorem, Malwarebytes' Anti-Malware, Spybotem.
Jediny Malwarebytes' Anti-Malware nasel tohle (vypis z logu):
Infikované moduly v paměti:
C:\WINDOWS\CP1640.dll (Trojan.Agent.Gen) -> Delete on reboot.
Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xgomiqohuwude (Trojan.Agent.Gen) -> Delete on reboot.
Infikované soubory:
C:\WINDOWS\CP1640.dll (Trojan.Agent.Gen) -> Delete on reboot.
Bohuzel to bud nebylo ono, nebo se nesmazalo po rebootu vsechno a NOD porad vyskakoval, dokud jsem ty adresy v "hosts" nebloknul.
LOG z RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by bundaboy at 2010-07-04 20:14:10
Microsoft Windows XP Professional Service Pack 3
System drive C: has 24 GB (47%) free of 50 GB
Total RAM: 3007 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:15:14, on 4.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\BOINC\boinctray.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\GiPo@Utilities\JIT Scheduler\sched.exe
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\DVBViewer\dvbviewer.exe
C:\Program Files\PopTray\PopTray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\GiPo@Utilities\JIT Scheduler\schednt.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\BOINC\boinc.exe
Y:\mIRCczLite\mirc.exe
C:\Program Files\Firefox\firefox.exe
C:\Program Files\BOINC\Data\projects\www.worldcommunitygrid.org\wcg_hcmd2_maxdo_6.14_windows_intelx86
C:\Program Files\BOINC\Data\projects\www.freehal.net_freehal_at_home\freehalboinc_1.46_windows_intelx86.exe
C:\Program Files\BOINC\Data\projects\wuprop.boinc-af.org\data_collect_1.32_windows_intelx86__nci.exe
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\BOINC\Data\projects\www.worldcommunitygrid.org\wcg_hcmd2_maxdo_6.14_windows_intelx86
D:\prace\RSIT.exe
C:\Program Files\trend micro\bundaboy.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ussshreg] C:\PROGRA~1\ULEADS~1.0\Ussshreg.exe /r
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
O4 - HKLM\..\Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [TrueCrypt] "C:\Program Files\TrueCrypt\TrueCrypt.exe" /q preferences
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [JITScheduler] "C:\Program Files\GiPo@Utilities\JIT Scheduler\sched.exe"
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: DVBViewer Pro.lnk = C:\Program Files\DVBViewer\dvbviewer.exe
O4 - Startup: PopTray.lnk = C:\Program Files\PopTray\PopTray.exe
O4 - Global Startup: Total Commander.lnk = C:\Program Files\totalcmd\TOTALCMD.EXE
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: JIT Scheduler - Gibin Software House
http://www.gibinsoft.com - C:\Program Files\GiPo@Utilities\JIT Scheduler\schednt.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 6885 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-22 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-22 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-05-14 2029640]
"P17Helper"=Rundll32 SPIRun.dll,RunDLLEntry []
"DU Meter"=C:\Program Files\DU Meter\DUMeter.exe [2003-06-22 1297920]
"ussshreg"=C:\PROGRA~1\ULEADS~1.0\Ussshreg.exe [2000-04-20 32768]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2006-07-28 122880]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2009-09-23 1657448]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-09-27 86016]
"boincmgr"=C:\Program Files\BOINC\boincmgr.exe [2010-05-14 4825856]
"boinctray"=C:\Program Files\BOINC\boinctray.exe [2010-05-14 58112]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-07-04 2176512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TrueCrypt"=C:\Program Files\TrueCrypt\TrueCrypt.exe [2009-08-22 1369792]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"JITScheduler"=C:\Program Files\GiPo@Utilities\JIT Scheduler\sched.exe [2008-03-24 188416]
"RestoreDesktop"=C:\Program Files\Restore Desktop\RestoreDesktop.exe [2003-03-11 45056]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Total Commander.lnk - C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Documents and Settings\bundaboy\Start Menu\Programs\Startup
DVBViewer Pro.lnk - C:\Program Files\DVBViewer\dvbviewer.exe
PopTray.lnk - C:\Program Files\PopTray\PopTray.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=181
"NoSMHelp"=0x01000000
"NoDriveAutoRun"=0xDFFFFF03
"NoLogoff"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"Y:\mIRCczLite\mirc.exe"="Y:\mIRCczLite\mirc.exe:*:Enabled:mIRC"
"C:\Program Files\WinSCP4\WinSCP.exe"="C:\Program Files\WinSCP4\WinSCP.exe:*:Enabled:WinSCP: SFTP, FTP and SCP client"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\bundaboy\temp\TeamViewer\Version5\TeamViewer.exe"="C:\Documents and Settings\bundaboy\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Program Files\TeamViewer\TeamViewer.exe"="C:\Program Files\TeamViewer\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-07-04 20:14:10 ----D---- C:\rsit
2010-07-04 20:14:10 ----D---- C:\Program Files\trend micro
2010-07-04 14:11:31 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-07-04 14:11:31 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-04 13:55:26 ----D---- C:\Documents and Settings\bundaboy\Application Data\Malwarebytes
2010-07-04 13:55:04 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-07-04 13:55:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-04 11:42:27 ----D---- C:\Program Files\Crawler
2010-07-04 11:42:24 ----D---- C:\Documents and Settings\bundaboy\Application Data\Spyware Terminator
2010-07-04 11:42:23 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-07-04 11:42:21 ----D---- C:\Program Files\Spyware Terminator
2010-07-01 11:19:22 ----SHD---- C:\Config.Msi
2010-06-29 00:48:27 ----D---- C:\Program Files\CoreTemp
2010-06-28 17:11:13 ----D---- C:\Documents and Settings\bundaboy\Application Data\Unity
2010-06-27 21:52:08 ----D---- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2010-06-22 22:44:11 ----D---- C:\Documents and Settings\bundaboy\Application Data\AIMP
2010-06-22 22:43:24 ----D---- C:\Program Files\Aimp
2010-06-16 23:20:37 ----D---- C:\Program Files\DVR-Studio HD 2
2010-06-13 12:54:09 ----D---- C:\Program Files\Tools
2010-06-13 00:43:47 ----D---- C:\Program Files\TeamViewer
2010-06-13 00:07:07 ----D---- C:\Documents and Settings\bundaboy\Application Data\TeamViewer
2010-06-10 00:07:12 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-10 00:07:00 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-10 00:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-10 00:06:45 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 00:06:41 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-10 00:06:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-10 00:02:59 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-06-09 22:16:26 ----D---- C:\Documents and Settings\bundaboy\Application Data\queuelocks
2010-06-08 22:46:46 ----A---- C:\WINDOWS\system32\MediaInfo.dll
======List of files/folders modified in the last 1 months======
2010-07-04 20:14:11 ----D---- C:\WINDOWS\Temp
2010-07-04 20:14:10 ----RD---- C:\Program Files
2010-07-04 16:05:42 ----D---- C:\WINDOWS\system32
2010-07-04 16:05:41 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-04 16:01:51 ----D---- C:\Program Files\Firefox
2010-07-04 15:59:39 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-04 14:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2010-07-04 14:01:26 ----D---- C:\WINDOWS\system32\drivers
2010-07-04 14:01:26 ----D---- C:\WINDOWS
2010-07-03 11:55:04 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-02 23:59:57 ----A---- C:\WINDOWS\winamp.ini
2010-07-02 13:11:42 ----A---- C:\WINDOWS\WDICT32.INI
2010-07-01 11:19:56 ----SHD---- C:\WINDOWS\Installer
2010-06-30 22:59:18 ----HD---- C:\WINDOWS\inf
2010-06-30 22:58:54 ----RSD---- C:\WINDOWS\assembly
2010-06-30 22:58:42 ----D---- C:\WINDOWS\system32\DirectX
2010-06-29 17:18:43 ----D---- C:\WINDOWS\Minidump
2010-06-24 16:17:54 ----N---- C:\WINDOWS\win.ini
2010-06-24 12:25:15 ----D---- C:\Program Files\Grabovani
2010-06-23 12:03:10 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-23 11:51:02 ----D---- C:\WINDOWS\WinSxS
2010-06-22 22:44:57 ----D---- C:\Documents and Settings\bundaboy\Application Data\foobar2000
2010-06-15 22:19:53 ----D---- C:\Program Files\totalcmd
2010-06-13 12:55:23 ----D---- C:\WINDOWS\Prefetch
2010-06-11 18:39:09 ----D---- C:\Program Files\BOINC
2010-06-11 18:38:31 ----D---- C:\WINDOWS\Downloaded Installations
2010-06-10 00:07:13 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-10 00:07:12 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-10 00:07:03 ----A---- C:\WINDOWS\imsins.BAK
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-05-14 94360]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2009-08-22 217664]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2009-08-05 115856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2009-08-05 41424]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R3 AF15BDA;AF9015 BDA Filter; C:\WINDOWS\system32\DRIVERS\AF15BDA.sys [2008-01-24 327296]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-12-08 142336]
R3 CTUSFSYN;Creative SoundFont Synthesizer; C:\WINDOWS\system32\drivers\ctusfsyn.sys [2006-08-07 162176]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-27 7655872]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-12-08 114688]
R3 P17xfi;Sound Blaster X-Fi Xtreme Audio; C:\WINDOWS\system32\drivers\P17xfi.sys [2007-11-21 1174528]
R3 p17xfilt;p17xfilt; C:\WINDOWS\system32\drivers\p17xfilt.sys [2007-10-10 1664384]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-04-01 10368]
R3 TTUSB2BDA;TTUSB2BDA USB 2.0 Driver; C:\WINDOWS\system32\DRIVERS\ttusb2bda.sys [2007-08-31 571904]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2009-08-05 91472]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys [2009-08-05 99472]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-07-26 248832]
S1 bead;bead; \??\C:\WINDOWS\system32\bead.sys []
S3 ahp81go4;ahp81go4; C:\WINDOWS\system32\drivers\ahp81go4.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-22 153376]
R2 JIT Scheduler;JIT Scheduler; C:\Program Files\GiPo@Utilities\JIT Scheduler\schednt.exe [2008-03-24 176128]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2008-11-03 1332480]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-07-04 488960]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-05-14 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Dekuju predem za jakoukoliv radu.
EDIT: Jeste pridam vypis tech www adres z hosts, treba to pomuze:

V nem se stridaly ruzne www adresy, ktere jsem posbiral a zatim v hosts souboru poslal na 127.0.0.0.
System jsem si projel nejnovejsim NODem, Spyware Terminatorem, Malwarebytes' Anti-Malware, Spybotem.
Jediny Malwarebytes' Anti-Malware nasel tohle (vypis z logu):
Infikované moduly v paměti:
C:\WINDOWS\CP1640.dll (Trojan.Agent.Gen) -> Delete on reboot.
Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xgomiqohuwude (Trojan.Agent.Gen) -> Delete on reboot.
Infikované soubory:
C:\WINDOWS\CP1640.dll (Trojan.Agent.Gen) -> Delete on reboot.
Bohuzel to bud nebylo ono, nebo se nesmazalo po rebootu vsechno a NOD porad vyskakoval, dokud jsem ty adresy v "hosts" nebloknul.

LOG z RSIT:
Logfile of random's system information tool 1.07 (written by random/random)
Run by bundaboy at 2010-07-04 20:14:10
Microsoft Windows XP Professional Service Pack 3
System drive C: has 24 GB (47%) free of 50 GB
Total RAM: 3007 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:15:14, on 4.7.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\BOINC\boinctray.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\GiPo@Utilities\JIT Scheduler\sched.exe
C:\Program Files\Restore Desktop\RestoreDesktop.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\DVBViewer\dvbviewer.exe
C:\Program Files\PopTray\PopTray.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\GiPo@Utilities\JIT Scheduler\schednt.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\BOINC\boinc.exe
Y:\mIRCczLite\mirc.exe
C:\Program Files\Firefox\firefox.exe
C:\Program Files\BOINC\Data\projects\www.worldcommunitygrid.org\wcg_hcmd2_maxdo_6.14_windows_intelx86
C:\Program Files\BOINC\Data\projects\www.freehal.net_freehal_at_home\freehalboinc_1.46_windows_intelx86.exe
C:\Program Files\BOINC\Data\projects\wuprop.boinc-af.org\data_collect_1.32_windows_intelx86__nci.exe
C:\WINDOWS\system32\mstsc.exe
C:\Program Files\QIP\qip.exe
C:\Program Files\BOINC\Data\projects\www.worldcommunitygrid.org\wcg_hcmd2_maxdo_6.14_windows_intelx86
D:\prace\RSIT.exe
C:\Program Files\trend micro\bundaboy.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ussshreg] C:\PROGRA~1\ULEADS~1.0\Ussshreg.exe /r
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [boincmgr] "C:\Program Files\BOINC\boincmgr.exe" /a /s
O4 - HKLM\..\Run: [boinctray] "C:\Program Files\BOINC\boinctray.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [TrueCrypt] "C:\Program Files\TrueCrypt\TrueCrypt.exe" /q preferences
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [JITScheduler] "C:\Program Files\GiPo@Utilities\JIT Scheduler\sched.exe"
O4 - HKCU\..\Run: [RestoreDesktop] C:\Program Files\Restore Desktop\RestoreDesktop.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: DVBViewer Pro.lnk = C:\Program Files\DVBViewer\dvbviewer.exe
O4 - Startup: PopTray.lnk = C:\Program Files\PopTray\PopTray.exe
O4 - Global Startup: Total Commander.lnk = C:\Program Files\totalcmd\TOTALCMD.EXE
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: JIT Scheduler - Gibin Software House
http://www.gibinsoft.com - C:\Program Files\GiPo@Utilities\JIT Scheduler\schednt.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 6885 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-22 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-08-22 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll [2010-06-25 1241552]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2009-05-14 2029640]
"P17Helper"=Rundll32 SPIRun.dll,RunDLLEntry []
"DU Meter"=C:\Program Files\DU Meter\DUMeter.exe [2003-06-22 1297920]
"ussshreg"=C:\PROGRA~1\ULEADS~1.0\Ussshreg.exe [2000-04-20 32768]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2006-07-28 122880]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"nwiz"=C:\Program Files\NVIDIA Corporation\nView\nwiz.exe [2009-09-23 1657448]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-09-27 86016]
"boincmgr"=C:\Program Files\BOINC\boincmgr.exe [2010-05-14 4825856]
"boinctray"=C:\Program Files\BOINC\boinctray.exe [2010-05-14 58112]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-07-04 2176512]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"TrueCrypt"=C:\Program Files\TrueCrypt\TrueCrypt.exe [2009-08-22 1369792]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2006-11-12 157592]
"JITScheduler"=C:\Program Files\GiPo@Utilities\JIT Scheduler\sched.exe [2008-03-24 188416]
"RestoreDesktop"=C:\Program Files\Restore Desktop\RestoreDesktop.exe [2003-03-11 45056]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Total Commander.lnk - C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Documents and Settings\bundaboy\Start Menu\Programs\Startup
DVBViewer Pro.lnk - C:\Program Files\DVBViewer\dvbviewer.exe
PopTray.lnk - C:\Program Files\PopTray\PopTray.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=181
"NoSMHelp"=0x01000000
"NoDriveAutoRun"=0xDFFFFF03
"NoLogoff"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"Y:\mIRCczLite\mirc.exe"="Y:\mIRCczLite\mirc.exe:*:Enabled:mIRC"
"C:\Program Files\WinSCP4\WinSCP.exe"="C:\Program Files\WinSCP4\WinSCP.exe:*:Enabled:WinSCP: SFTP, FTP and SCP client"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\bundaboy\temp\TeamViewer\Version5\TeamViewer.exe"="C:\Documents and Settings\bundaboy\temp\TeamViewer\Version5\TeamViewer.exe:*:Enabled:TeamViewer"
"C:\Program Files\TeamViewer\TeamViewer.exe"="C:\Program Files\TeamViewer\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-07-04 20:14:10 ----D---- C:\rsit
2010-07-04 20:14:10 ----D---- C:\Program Files\trend micro
2010-07-04 14:11:31 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-07-04 14:11:31 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-04 13:55:26 ----D---- C:\Documents and Settings\bundaboy\Application Data\Malwarebytes
2010-07-04 13:55:04 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-07-04 13:55:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-04 11:42:27 ----D---- C:\Program Files\Crawler
2010-07-04 11:42:24 ----D---- C:\Documents and Settings\bundaboy\Application Data\Spyware Terminator
2010-07-04 11:42:23 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-07-04 11:42:21 ----D---- C:\Program Files\Spyware Terminator
2010-07-01 11:19:22 ----SHD---- C:\Config.Msi
2010-06-29 00:48:27 ----D---- C:\Program Files\CoreTemp
2010-06-28 17:11:13 ----D---- C:\Documents and Settings\bundaboy\Application Data\Unity
2010-06-27 21:52:08 ----D---- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2010-06-22 22:44:11 ----D---- C:\Documents and Settings\bundaboy\Application Data\AIMP
2010-06-22 22:43:24 ----D---- C:\Program Files\Aimp
2010-06-16 23:20:37 ----D---- C:\Program Files\DVR-Studio HD 2
2010-06-13 12:54:09 ----D---- C:\Program Files\Tools
2010-06-13 00:43:47 ----D---- C:\Program Files\TeamViewer
2010-06-13 00:07:07 ----D---- C:\Documents and Settings\bundaboy\Application Data\TeamViewer
2010-06-10 00:07:12 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-06-10 00:07:00 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-06-10 00:06:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-06-10 00:06:45 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-06-10 00:06:41 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-06-10 00:06:36 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-06-10 00:02:59 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-06-09 22:16:26 ----D---- C:\Documents and Settings\bundaboy\Application Data\queuelocks
2010-06-08 22:46:46 ----A---- C:\WINDOWS\system32\MediaInfo.dll
======List of files/folders modified in the last 1 months======
2010-07-04 20:14:11 ----D---- C:\WINDOWS\Temp
2010-07-04 20:14:10 ----RD---- C:\Program Files
2010-07-04 16:05:42 ----D---- C:\WINDOWS\system32
2010-07-04 16:05:41 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-04 16:01:51 ----D---- C:\Program Files\Firefox
2010-07-04 15:59:39 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-07-04 14:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB976325$
2010-07-04 14:01:26 ----D---- C:\WINDOWS\system32\drivers
2010-07-04 14:01:26 ----D---- C:\WINDOWS
2010-07-03 11:55:04 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-02 23:59:57 ----A---- C:\WINDOWS\winamp.ini
2010-07-02 13:11:42 ----A---- C:\WINDOWS\WDICT32.INI
2010-07-01 11:19:56 ----SHD---- C:\WINDOWS\Installer
2010-06-30 22:59:18 ----HD---- C:\WINDOWS\inf
2010-06-30 22:58:54 ----RSD---- C:\WINDOWS\assembly
2010-06-30 22:58:42 ----D---- C:\WINDOWS\system32\DirectX
2010-06-29 17:18:43 ----D---- C:\WINDOWS\Minidump
2010-06-24 16:17:54 ----N---- C:\WINDOWS\win.ini
2010-06-24 12:25:15 ----D---- C:\Program Files\Grabovani
2010-06-23 12:03:10 ----D---- C:\WINDOWS\Microsoft.NET
2010-06-23 11:51:02 ----D---- C:\WINDOWS\WinSxS
2010-06-22 22:44:57 ----D---- C:\Documents and Settings\bundaboy\Application Data\foobar2000
2010-06-15 22:19:53 ----D---- C:\Program Files\totalcmd
2010-06-13 12:55:23 ----D---- C:\WINDOWS\Prefetch
2010-06-11 18:39:09 ----D---- C:\Program Files\BOINC
2010-06-11 18:38:31 ----D---- C:\WINDOWS\Downloaded Installations
2010-06-10 00:07:13 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-06-10 00:07:12 ----HD---- C:\WINDOWS\$hf_mig$
2010-06-10 00:07:03 ----A---- C:\WINDOWS\imsins.BAK
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2009-05-14 107256]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2009-05-14 94360]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2009-08-22 217664]
R1 VBoxDrv;VirtualBox Service; C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys [2009-08-05 115856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver; C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys [2009-08-05 41424]
R1 vmm;Virtual Machine Monitor; \??\C:\WINDOWS\system32\Drivers\vmm.sys []
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2009-05-14 114472]
R3 AF15BDA;AF9015 BDA Filter; C:\WINDOWS\system32\DRIVERS\AF15BDA.sys [2008-01-24 327296]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2005-12-08 142336]
R3 CTUSFSYN;Creative SoundFont Synthesizer; C:\WINDOWS\system32\drivers\ctusfsyn.sys [2006-08-07 162176]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-27 7655872]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2005-12-08 114688]
R3 P17xfi;Sound Blaster X-Fi Xtreme Audio; C:\WINDOWS\system32\drivers\P17xfi.sys [2007-11-21 1174528]
R3 p17xfilt;p17xfilt; C:\WINDOWS\system32\drivers\p17xfilt.sys [2007-10-10 1664384]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2004-04-01 10368]
R3 TTUSB2BDA;TTUSB2BDA USB 2.0 Driver; C:\WINDOWS\system32\DRIVERS\ttusb2bda.sys [2007-08-31 571904]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp.sys [2009-08-05 91472]
R3 VBoxNetFlt;VBoxNetFlt Service; C:\WINDOWS\system32\DRIVERS\VBoxNetFlt.sys [2009-08-05 99472]
R3 VPCNetS2;Virtual Machine Network Services Driver; C:\WINDOWS\system32\DRIVERS\VMNetSrv.sys [2008-02-05 59960]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-07-26 248832]
S1 bead;bead; \??\C:\WINDOWS\system32\bead.sys []
S3 ahp81go4;ahp81go4; C:\WINDOWS\system32\drivers\ahp81go4.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MPE;BDA MPE Filter; C:\WINDOWS\system32\DRIVERS\MPE.sys [2008-04-14 15232]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-05-14 731840]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-08-22 153376]
R2 JIT Scheduler;JIT Scheduler; C:\Program Files\GiPo@Utilities\JIT Scheduler\schednt.exe [2008-03-24 176128]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100]
R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2008-11-03 1332480]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-07-04 488960]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2009-05-14 20680]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
Dekuju predem za jakoukoliv radu.
EDIT: Jeste pridam vypis tech www adres z hosts, treba to pomuze:
Kód: Vybrat vše
127.0.0.1 m01n83kjf7.com # spyware
127.0.0.1 clkh71yhks66.com # spyware
127.0.0.1 7gafd33ja90a.com # spyware
127.0.0.1 n1mo661s6cx0.com # spyware
127.0.0.1 j00k877x.cc # spyware
127.0.0.1 30xc1cjh91.com # spyware