Stránka 1 z 1

Avira našla Malware - TR/Rootkit.Gen2

Napsal: 21 črc 2010 11:33
od BokyCZ
Dobrý den,
mohl by jste mi poradit mam v Notebooku Malware - TR/Rootkit.Gen2 (našla ho Avira)
A nevím jak ho odstranit, přikládam log z Rsit
Děkuji

****************************************************************************
Logfile of random's system information tool 1.08 (written by random/random)
Run by BokyCZ at 2010-07-21 12:13:21
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 210 GB (88%) free of 238 GB
Total RAM: 3070 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:13:49, on 21.7.2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Program files\P4G\BatteryLife.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
C:\Windows\AsScrPro.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\program files\avira\antivir desktop\avcenter.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\BokyCZ\Downloads\RSIT.exe
C:\Program Files\trend micro\BokyCZ.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.qip.ru/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mojebanka.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by QIP.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QipLI - {6B5863A0-C43F-4C0A-982B-CC0E9125783F} - C:\Users\BokyCZ\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Program Files\Internet Explorer\qipsearchbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [AsDIPM] C:\Preload\Others\Intel\IMSM_disable_oobe\XP32_Vista32_8.5.0.1032\Reg\AsDIPM.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [AmIcoSinglun] C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: FancyStart daemon.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: WikiKomentáře Google... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: QIP Infium - {4BE5A754-9C9C-4E64-8864-207D44EDEB6A} - C:\Program Files\QIP Infium\infium.exe (HKCU)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Avira FireWall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\partner.exe
O23 - Service: SRS Volume Sync Service (SRS_VolSync_Service) - SRS Labs, Inc. - C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe

--
End of file - 9596 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B5863A0-C43F-4C0A-982B-CC0E9125783F}]
QipLI Class - C:\Users\BokyCZ\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll [2010-05-28 48080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
Partner BHO Class - C:\ProgramData\Partner\partner.dll [2009-06-13 157168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Program Files\Internet Explorer\qipsearchbar.dll [2009-07-09 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-20 278192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll [2010-07-20 814648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-07-20 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-20 278192]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
"P2Go_Menu"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-14 210216]
"AsDIPM"=C:\Preload\Others\Intel\IMSM_disable_oobe\XP32_Vista32_8.5.0.1032\Reg\AsDIPM.exe []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2009-04-17 13605408]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2009-04-17 92704]
"HControlUser"=C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe [2008-08-18 98304]
"ETDWare"=C:\Program Files\Elantech\ETDCtrl.exe [2009-04-21 540576]
"ATKOSD2"=C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe [2009-03-04 8392704]
"AmIcoSinglun"=C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [2009-04-03 237568]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-04-14 7416352]
"Wireless Console 3"=C:\Program Files\ASUS\Wireless Console 3\wcourier.exe [2009-04-18 1593344]
"ATKMEDIA"=C:\Program Files\ASUS\ATK Media\DMedia.exe [2009-04-20 159744]
"ADSMTray"=C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe [2008-04-01 266240]
"ACMON"=C:\Program Files\ASUS\Splendid\ACMON.exe [2008-10-01 851968]
"ASUS Screen Saver Protector"=C:\Windows\AsScrPro.exe [2009-06-13 3054136]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-03 35184]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2010-03-02 282792]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
FancyStart daemon.lnk - C:\Windows\Installer\{A9FEB6D7-9C52-49FC-B956-7AB275B78890}\_5598CE641C54B66A23693F.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-07-21 12:10:01 ----D---- C:\Program Files\trend micro
2010-07-21 12:09:58 ----D---- C:\rsit
2010-07-21 11:23:40 ----D---- C:\Users\BokyCZ\AppData\Roaming\CyberLink
2010-07-21 10:56:14 ----A---- C:\Windows\system32\msonpmon.dll
2010-07-21 10:54:56 ----D---- C:\Program Files\Microsoft Works
2010-07-21 10:54:32 ----D---- C:\Program Files\Microsoft Visual Studio
2010-07-21 10:54:32 ----D---- C:\Program Files\Common Files\DESIGNER
2010-07-21 10:53:59 ----D---- C:\Program Files\Microsoft.NET
2010-07-21 10:50:19 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-07-21 10:49:41 ----D---- C:\Program Files\Microsoft Office
2010-07-21 10:49:19 ----RHD---- C:\MSOCache
2010-07-21 03:47:21 ----SHD---- C:\System Volume Information
2010-07-21 03:46:54 ----A---- C:\Pass.txt
2010-07-21 02:49:36 ----ASH---- C:\hiberfil.sys
2010-07-21 02:49:34 ----ASH---- C:\pagefile.sys
2010-07-20 23:16:55 ----D---- C:\Program Files\SMPlayer
2010-07-20 23:15:12 ----A---- C:\Windows\system32\drivers\pcouffin.sys
2010-07-20 23:15:12 ----A---- C:\Users\BokyCZ\AppData\Roaming\pcouffin.sys
2010-07-20 23:15:12 ----A---- C:\Users\BokyCZ\AppData\Roaming\inst.exe
2010-07-20 23:15:11 ----D---- C:\Users\BokyCZ\AppData\Roaming\Vso
2010-07-20 23:15:06 ----A---- C:\Windows\system32\wvc1dmod.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\vp7vfw.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\sipr3260.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\Pncrt.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\drv43260.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\drv33260.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\drv23260.dll
2010-07-20 23:15:06 ----A---- C:\Windows\system32\cook3260.dll
2010-07-20 23:15:04 ----D---- C:\Program Files\VSO
2010-07-20 23:14:12 ----D---- C:\Users\BokyCZ\AppData\Roaming\Ashampoo
2010-07-20 23:14:03 ----D---- C:\ProgramData\ashampoo
2010-07-20 23:13:58 ----D---- C:\Program Files\Ashampoo
2010-07-20 23:13:31 ----A---- C:\Windows\system32\drivers\sptd.sys
2010-07-20 23:13:30 ----D---- C:\Program Files\DAEMON Tools Lite
2010-07-20 23:13:06 ----D---- C:\Users\BokyCZ\AppData\Roaming\DAEMON Tools Lite
2010-07-20 23:13:03 ----D---- C:\ProgramData\DAEMON Tools Lite
2010-07-20 23:01:16 ----D---- C:\Users\BokyCZ\AppData\Roaming\Opera
2010-07-20 22:28:26 ----A---- C:\Windows\system32\occache.dll
2010-07-20 22:28:26 ----A---- C:\Windows\system32\mstime.dll
2010-07-20 22:28:26 ----A---- C:\Windows\system32\jsproxy.dll
2010-07-20 22:28:26 ----A---- C:\Windows\system32\iepeers.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\wininet.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\msfeedssync.exe
2010-07-20 22:28:25 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\msfeeds.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\ieui.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\iesetup.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\iernonce.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\iedkcs32.dll
2010-07-20 22:28:25 ----A---- C:\Windows\system32\ie4uinit.exe
2010-07-20 22:28:24 ----A---- C:\Windows\system32\urlmon.dll
2010-07-20 22:28:24 ----A---- C:\Windows\system32\ieUnatt.exe
2010-07-20 22:28:24 ----A---- C:\Windows\system32\iesysprep.dll
2010-07-20 22:28:24 ----A---- C:\Windows\system32\iertutil.dll
2010-07-20 22:28:23 ----A---- C:\Windows\system32\mshtml.dll
2010-07-20 22:28:23 ----A---- C:\Windows\system32\ieframe.dll
2010-07-20 22:28:09 ----HD---- C:\Windows\msdownld.tmp
2010-07-20 22:27:41 ----D---- C:\ProgramData\Seznam DVD 2008
2010-07-20 22:27:18 ----A---- C:\Windows\system32\mshtmled.dll
2010-07-20 22:27:18 ----A---- C:\Windows\system32\icardie.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\msls31.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\mshtmler.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\imgutil.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\ieakeng.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\dxtrans.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\dxtmsft.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\corpol.dll
2010-07-20 22:27:17 ----A---- C:\Windows\system32\admparse.dll
2010-07-20 22:27:16 ----A---- C:\Windows\system32\WinFXDocObj.exe
2010-07-20 22:27:16 ----A---- C:\Windows\system32\wextract.exe
2010-07-20 22:27:16 ----A---- C:\Windows\system32\webcheck.dll
2010-07-20 22:27:16 ----A---- C:\Windows\system32\msrating.dll
2010-07-20 22:27:16 ----A---- C:\Windows\system32\licmgr10.dll
2010-07-20 22:27:16 ----A---- C:\Windows\system32\inseng.dll
2010-07-20 22:27:16 ----A---- C:\Windows\system32\ieakui.dll
2010-07-20 22:27:16 ----A---- C:\Windows\system32\ieaksie.dll
2010-07-20 22:27:15 ----A---- C:\Windows\system32\vbscript.dll
2010-07-20 22:27:15 ----A---- C:\Windows\system32\url.dll
2010-07-20 22:27:15 ----A---- C:\Windows\system32\pngfilt.dll
2010-07-20 22:27:15 ----A---- C:\Windows\system32\jscript.dll
2010-07-20 22:27:15 ----A---- C:\Windows\system32\ieapfltr.dll
2010-07-20 22:27:15 ----A---- C:\Windows\system32\advpack.dll
2010-07-20 22:27:14 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2010-07-20 22:27:14 ----A---- C:\Windows\system32\SetDepNx.exe
2010-07-20 22:27:14 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2010-07-20 22:27:14 ----A---- C:\Windows\system32\PDMSetup.exe
2010-07-20 22:27:14 ----A---- C:\Windows\system32\mshta.exe
2010-07-20 22:27:14 ----A---- C:\Windows\system32\iexpress.exe
2010-07-20 22:26:44 ----D---- C:\Users\BokyCZ\AppData\Roaming\QipGuard
2010-07-20 22:25:47 ----D---- C:\Program Files\QIP Infium
2010-07-20 20:31:52 ----D---- C:\Program Files\JDownloader
2010-07-20 20:31:45 ----A---- C:\Windows\system32\javaws.exe
2010-07-20 20:31:45 ----A---- C:\Windows\system32\javaw.exe
2010-07-20 20:31:45 ----A---- C:\Windows\system32\java.exe
2010-07-20 20:31:45 ----A---- C:\Windows\system32\deploytk.dll
2010-07-20 20:31:39 ----D---- C:\Program Files\Java
2010-07-20 20:27:39 ----D---- C:\Users\BokyCZ\AppData\Roaming\GHISLER
2010-07-20 20:27:39 ----D---- C:\Program Files\Total commander
2010-07-20 20:27:39 ----A---- C:\Windows\UC.PIF
2010-07-20 20:27:39 ----A---- C:\Windows\RAR.PIF
2010-07-20 20:27:39 ----A---- C:\Windows\PKZIP.PIF
2010-07-20 20:27:39 ----A---- C:\Windows\PKUNZIP.PIF
2010-07-20 20:27:39 ----A---- C:\Windows\NOCLOSE.PIF
2010-07-20 20:27:39 ----A---- C:\Windows\LHA.PIF
2010-07-20 20:27:39 ----A---- C:\Windows\ARJ.PIF
2010-07-20 19:13:32 ----D---- C:\Users\BokyCZ\AppData\Roaming\Avira
2010-07-20 19:10:16 ----A---- C:\Windows\system32\drivers\ssmdrv.sys
2010-07-20 19:10:15 ----D---- C:\Program Files\Avira
2010-07-20 19:10:15 ----A---- C:\Windows\system32\drivers\avipbb.sys
2010-07-20 19:10:15 ----A---- C:\Windows\system32\drivers\avgntmgr.sys
2010-07-20 19:10:15 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2010-07-20 19:10:15 ----A---- C:\Windows\system32\drivers\avgntdd.sys
2010-07-20 19:10:15 ----A---- C:\Windows\system32\drivers\avfwot.sys
2010-07-20 19:10:15 ----A---- C:\Windows\system32\drivers\avfwim.sys
2010-07-20 19:04:49 ----D---- C:\Users\BokyCZ\AppData\Roaming\WinRAR
2010-07-20 19:04:37 ----D---- C:\Program Files\WinRAR
2010-07-20 18:56:02 ----D---- C:\Program Files\uTorrent
2010-07-20 18:55:32 ----D---- C:\Users\BokyCZ\AppData\Roaming\uTorrent
2010-07-20 18:50:56 ----D---- C:\ProgramData\LightScribe
2010-07-20 18:44:04 ----D---- C:\Users\BokyCZ\AppData\Roaming\Macromedia
2010-07-20 18:44:04 ----D---- C:\Users\BokyCZ\AppData\Roaming\Adobe
2010-07-20 18:40:43 ----D---- C:\ProgramData\Avira
2010-07-20 18:35:02 ----A---- C:\Windows\system32\wintrust.dll
2010-07-20 18:35:01 ----A---- C:\Windows\system32\cabview.dll
2010-07-20 18:33:51 ----D---- C:\Program Files\VS Revo Group
2010-07-20 18:22:52 ----D---- C:\Users\BokyCZ\AppData\Roaming\Mozilla
2010-07-20 18:22:46 ----D---- C:\Program Files\Mozilla Firefox
2010-07-20 18:21:28 ----N---- C:\Windows\system32\MpSigStub.exe
2010-07-20 18:17:38 ----D---- C:\Users\BokyCZ\AppData\Roaming\Google
2010-07-20 18:11:57 ----A---- C:\Windows\system32\wups2.dll
2010-07-20 18:11:57 ----A---- C:\Windows\system32\wucltux.dll
2010-07-20 18:11:57 ----A---- C:\Windows\system32\wuaueng.dll
2010-07-20 18:11:57 ----A---- C:\Windows\system32\wuauclt.exe
2010-07-20 18:11:51 ----A---- C:\Windows\system32\wups.dll
2010-07-20 18:11:51 ----A---- C:\Windows\system32\wudriver.dll
2010-07-20 18:11:51 ----A---- C:\Windows\system32\wuapi.dll
2010-07-20 18:11:49 ----A---- C:\Windows\system32\wuwebv.dll
2010-07-20 18:11:49 ----A---- C:\Windows\system32\wuapp.exe
2010-07-20 18:07:12 ----D---- C:\Users\BokyCZ\AppData\Roaming\Identities
2010-07-20 18:03:40 ----DC---- C:\Windows\system32\DRVSTORE
2010-07-20 18:03:40 ----A---- C:\Windows\system32\drivers\fssfltr.sys
2010-07-20 18:03:05 ----A---- C:\Windows\system32\d3dx9_32.dll
2010-07-20 18:03:01 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-07-20 18:02:09 ----D---- C:\Program Files\Microsoft
2010-07-20 18:01:55 ----D---- C:\Program Files\Windows Live SkyDrive
2010-07-20 18:01:50 ----D---- C:\Program Files\Windows Live
2010-07-20 18:01:01 ----D---- C:\Program Files\Common Files\Windows Live
2010-07-20 17:59:25 ----D---- C:\ProgramData\Adobe
2010-07-20 17:59:22 ----D---- C:\Program Files\Common Files\Adobe
2010-07-20 17:59:22 ----D---- C:\Program Files\Adobe
2010-07-20 17:57:22 ----D---- C:\Users\BokyCZ\AppData\Roaming\Media Center Programs
2010-07-20 17:57:21 ----SD---- C:\Users\BokyCZ\AppData\Roaming\Microsoft

======List of files/folders modified in the last 1 months======

2010-07-21 12:13:25 ----D---- C:\Windows\Temp
2010-07-21 12:10:01 ----RD---- C:\Program Files
2010-07-21 11:56:29 ----D---- C:\Windows\winsxs
2010-07-21 11:47:49 ----D---- C:\Windows\system32\catroot
2010-07-21 11:47:30 ----SHD---- C:\Windows\Installer
2010-07-21 11:47:00 ----D---- C:\Program Files\Common Files\microsoft shared
2010-07-21 11:39:27 ----D---- C:\Windows\Debug
2010-07-21 11:38:42 ----D---- C:\Windows\system32\catroot2
2010-07-21 11:38:33 ----HD---- C:\ProgramData
2010-07-21 11:33:02 ----RSD---- C:\Windows\assembly
2010-07-21 11:33:02 ----D---- C:\Windows\Microsoft.NET
2010-07-21 11:23:44 ----D---- C:\ProgramData\CyberLink
2010-07-21 10:56:24 ----D---- C:\ProgramData\Microsoft Help
2010-07-21 10:56:14 ----D---- C:\Windows\System32
2010-07-21 10:54:47 ----D---- C:\Program Files\MSBuild
2010-07-21 10:54:32 ----D---- C:\Program Files\Common Files
2010-07-21 10:54:30 ----D---- C:\Windows\ShellNew
2010-07-21 10:54:08 ----RSD---- C:\Windows\Fonts
2010-07-21 10:53:59 ----SD---- C:\ProgramData\Microsoft
2010-07-21 10:50:02 ----A---- C:\Windows\win.ini
2010-07-21 10:50:01 ----D---- C:\Program Files\Common Files\System
2010-07-21 09:34:07 ----D---- C:\Windows\inf
2010-07-21 09:34:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-07-21 09:30:37 ----D---- C:\Windows
2010-07-20 23:15:19 ----D---- C:\Windows\system32\drivers
2010-07-20 22:52:35 ----D---- C:\Program Files\Internet Explorer
2010-07-20 22:33:03 ----A---- C:\Windows\system32\acovcnt.exe
2010-07-20 22:30:34 ----D---- C:\Windows\system32\migration
2010-07-20 22:30:32 ----D---- C:\Windows\system32\en-US
2010-07-20 22:30:32 ----D---- C:\Windows\PolicyDefinitions
2010-07-20 19:05:46 ----D---- C:\Windows\system32\WDI
2010-07-20 18:43:52 ----D---- C:\Windows\Prefetch
2010-07-20 18:35:16 ----D---- C:\ProgramData\Norton
2010-07-20 18:29:18 ----D---- C:\Windows\system32\sk-SK
2010-07-20 18:29:18 ----D---- C:\Windows\system32\ro-RO
2010-07-20 18:29:18 ----D---- C:\Windows\system32\el-GR
2010-07-20 18:29:18 ----D---- C:\Windows\system32\cs-CZ
2010-07-20 18:27:48 ----D---- C:\Windows\Tasks
2010-07-20 18:27:48 ----D---- C:\Windows\system32\Tasks
2010-07-20 18:27:40 ----D---- C:\Program Files\Google
2010-07-20 18:21:52 ----D---- C:\Windows\system32\LogFiles
2010-07-20 18:12:06 ----D---- C:\Windows\SoftwareDistribution
2010-07-20 18:07:28 ----SHD---- C:\$RECYCLE.BIN
2010-07-20 17:57:21 ----RD---- C:\Users
2010-07-20 17:53:18 ----D---- C:\Windows\rescache
2010-07-02 12:39:06 ----A---- C:\Windows\system32\mrt.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AsDsm;AsDsm; C:\Windows\system32\drivers\AsDsm.sys [2009-06-13 30264]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2008-07-20 324120]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-07-20 691696]
R1 avfwot;avfwot; C:\Windows\system32\DRIVERS\avfwot.sys [2010-02-18 102856]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2010-03-01 124784]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2010-02-16 60936]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2009-02-18 1093632]
R3 avfwim;AvFw Packet Filter Miniport; C:\Windows\system32\DRIVERS\avfwim.sys [2010-02-15 79432]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2009-04-21 90112]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-04-14 2358560]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-11-03 13880]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C60x86.sys [2009-04-01 50176]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2009-01-22 52768]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-04-17 7549248]
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2010-07-20 47360]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-08-11 1752704]
R3 SRS_PremiumSound_Service;SRS Labs Premium Sound; C:\Windows\system32\drivers\srs_PremiumSound_i386.sys [2009-04-01 233128]
S1 SRTSP;SRTSP; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSP.SYS []
S1 SRTSPX;SRTSPX; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SRTSPX.SYS []
S3 aoh5b7dp;aoh5b7dp; C:\Windows\system32\drivers\aoh5b7dp.sys []
S3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-04-17 23040]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-04-17 507904]
S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-17 30208]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2008-07-09 81960]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2008-05-13 100392]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2008-05-13 17320]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVENG.SYS []
S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20080829.024\NAVEX15.SYS []
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-04-17 149504]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wimfltr.sys [2008-05-24 131000]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ADSMService;ADSM Service; C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe [2008-03-31 225280]
R2 AntiVirFirewallService;Avira FireWall; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [2010-04-01 536232]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [2010-03-30 337064]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-04-01 267432]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-04-01 405672]
R2 ASLDRService;ASLDR Service; C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe [2008-08-14 100920]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2008-07-30 522792]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-04-17 203296]
R2 SRS_VolSync_Service;SRS Volume Sync Service; C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe [2009-04-07 70880]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-07-20 135664]
S2 Norton Internet Security;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe /s Norton Internet Security /m C:\Program Files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll /prefetch:1 []
S3 fsssvc;Windows Live Zabezpečení rodiny; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2008-12-08 533344]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-07-20 182768]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 Partner Service;Partner Service; C:\ProgramData\Partner\partner.exe [2009-06-13 110576]

-----------------EOF-----------------

Re: Avira našla Malware - TR/Rootkit.Gen2

Napsal: 21 črc 2010 16:51
od 1danab
zdravím :)

http://www.esagelab.com/files/bootkit_remover.rar

stáhněte, rozbalte na plochu, spusťte

po spuštění klikněte pravým tlačítkem myši do okna, zvolte možnost Vybrat vše, CTRL+C a sem do odpovědi CTRL+V (tím mi sem vložíte log)

Re: Avira našla Malware - TR/Rootkit.Gen2

Napsal: 21 črc 2010 17:43
od BokyCZ
Děkuji za pomoc, vzhledem k tomu, že jsem systém mněl těsně po nové instalaci. Rozhodl jsem se, že systém nově reinstaluju. Pokud by později vznikl nějaký problém určitě se ozvu.

Re: Avira našla Malware - TR/Rootkit.Gen2

Napsal: 21 črc 2010 17:48
od 1danab
no moc jsem vám nepomohla :D
kdyby něco dejte vědět :wink:

Re: Avira našla Malware - TR/Rootkit.Gen2

Napsal: 21 črc 2010 17:55
od BokyCZ
Mohl bych se ještě zeptat jaké programy by jste mi doporučila, proti spywarům, malwarům, virům atd?? Děkuji

Re: Avira našla Malware - TR/Rootkit.Gen2

Napsal: 21 črc 2010 18:15
od 1danab
hlavně bych vám doporučila nainstalovat SP2

ideální je investovat a koupit si nějakou Internet Security od renomovaných výrobců (KIS, NIS, N360, ESS, Avira Internet Security, BitDefender Total Security, atd.)

pokud se chcete držet freeware, tak buď Microsoft Security Essentials nebo Avast (Avira ve free verzi nekontroluje emaily)

pamatujte však, že sebelepší antivirus vás neochrání pokud nebudete používat hlavu :wink: viz.návštěvy nedůvěryhodných stránek

opatrnosti není nikdy dost :wink: