Stránka 1 z 1

help

Napsal: 02 srp 2010 20:29
od matej7
Takze amm problem spomaleny net mozno je to providerom neviem lebo predtym som ho nemal tak spomaleny a caste vypadky netu tiez som to casto nemal a ked som im volal tak oni ze nevida ziadne moje vypadky na sieti a spomaleny PC !

Logfile of random's system information tool 1.08 (written by random/random)
Run by PC at 2010-08-02 21:28:38
Systém Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 27 GB (27%) free of 100 GB
Total RAM: 2047 MB (31% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:28:47, on 2.8.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
E:\Hry\CS\Steam.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\PC\Desktop\RSIT.exe
C:\Program Files\trend micro\PC.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/skins7/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programy\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKCU\..\Run: [Steam] "e:\hry\cs\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Programy\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ICQ] "E:\Programy\ICQ7.1\ICQ.exe" silent loginmode=4
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Prevzia cez IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Prevzia cez IDM všetky prepojenia - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Prevzia obsah FLV cez IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - E:\Programy\ICQ7.1\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - E:\Programy\ICQ7.1\ICQ.exe
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\Programy\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 7387854578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 0897011765
O17 - HKLM\System\CCS\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O17 - HKLM\System\CS1\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O17 - HKLM\System\CS2\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O17 - HKLM\System\CS3\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O17 - HKLM\System\CS4\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O17 - HKLM\System\CS5\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O17 - HKLM\System\CS6\Services\Tcpip\..\{092475B1-4D09-4DA2-AA69-BEE9A6F0E11E}: NameServer = 92.245.2.245,92.245.2.162
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 8037 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDMIEHlprObj Class - C:\Program Files\Internet Download Manager\IDMIECC.dll [2010-01-20 181680]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"=C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [2009-10-09 33677312]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-27 98304]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-06-28 2837864]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"QuickTime Task"=E:\Programy\QuickTime\qttask.exe [2010-03-17 421888]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-06-05 2176512]
"ATICustomerCare"=C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [2010-03-04 311296]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=e:\hry\cs\steam.exe [2010-05-07 1238352]
"DAEMON Tools Lite"=E:\Programy\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"ICQ"=E:\Programy\ICQ7.1\ICQ.exe [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
E:\Programy\QuickTime\QTTask.exe [2010-03-17 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
E:\Programy\Winamp\winampa.exe [2009-07-01 37888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
C:\PROGRA~1\WINDOW~4\WINDOW~1.EXE [2008-05-26 123904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-05-27 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system32\freecell.exe"="C:\WINDOWS\system32\freecell.exe:*:Enabled:FreeCell"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Documents and Settings\PC\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe"="C:\Documents and Settings\PC\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Program Files\LogMeIn Hamachi\hamachi-2.exe"="C:\Program Files\LogMeIn Hamachi\hamachi-2.exe:*:Enabled:hamachi-2"
"C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe"="C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe:*:Enabled:LogMeIn Hamachi"
"E:\Hry\Rise of nations\rise.exe"="E:\Hry\Rise of nations\rise.exe:*:Enabled:Rise of Nations"
"E:\Hry\CoD 2\CoD2MP_s.exe"="E:\Hry\CoD 2\CoD2MP_s.exe:*:Enabled:CoD2MP_s"
"E:\Hry\CS\Steam.exe"="E:\Hry\CS\Steam.exe:*:Enabled:Steam"
"E:\Programy\ICQ7.1\ICQ.exe"="E:\Programy\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"E:\Programy\ICQ7.1\aolload.exe"="E:\Programy\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"E:\Program Files\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe"="E:\Program Files\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Call of Pripyat (CLI)"
"E:\Program Files\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe"="E:\Program Files\bitComposer Games\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Call of Pripyat (SRV)"
"E:\Programy\BitLord\BitLord.exe"="E:\Programy\BitLord\BitLord.exe:*:Enabled:BitLord"
"E:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\server.exe"="E:\Hry\Ubisoft\Tom Clancy's Splinter Cell Conviction\server.exe:*:Enabled:server"
"C:\Program Files\BitLord\BitLord.exe"="C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord"
"C:\Documents and Settings\PC\Desktop\Splinter.Cell.Conviction.Crack.PROPER.SKIDRoW\DRM v4\server.exe"="C:\Documents and Settings\PC\Desktop\Splinter.Cell.Conviction.Crack.PROPER.SKIDRoW\DRM v4\server.exe:*:Enabled:server"
"C:\Documents and Settings\PC\Desktop\SCC Cracked\SCC Starting Crack\server.exe"="C:\Documents and Settings\PC\Desktop\SCC Cracked\SCC Starting Crack\server.exe:*:Enabled:server"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\server.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\server.exe:*:Enabled:server"
"E:\Hry\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="E:\Hry\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"E:\Hry\Black_Box\Tom Clancy's Splinter Cell - Conviction\src\system\conviction_game.exe"="E:\Hry\Black_Box\Tom Clancy's Splinter Cell - Conviction\src\system\conviction_game.exe:*:Enabled:conviction_game"
"E:\Programy\uTorrent\uTorrent.exe"="E:\Programy\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"C:\Program Files\Charles\Charles.exe"="C:\Program Files\Charles\Charles.exe:*:Enabled:Charles Web Debugging Proxy"
"C:\Documents and Settings\PC\Desktop\mlb2k10.exe"="C:\Documents and Settings\PC\Desktop\mlb2k10.exe:*:Enabled:2K Sports Major League Baseball 2K10"
"E:\Hry\TmNationsForever\TmForever.exe"="E:\Hry\TmNationsForever\TmForever.exe:*:Enabled:TmForever"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"E:\Hry\League of Legends\Air\LolClient.exe"="E:\Hry\League of Legends\Air\LolClient.exe:*:Enabled:League of Legends Lobby"
"E:\Hry\League of Legends\Game\League of Legends.exe"="E:\Hry\League of Legends\Game\League of Legends.exe:*:Enabled:League of Legends Game Client"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"E:\Hry\CS\SteamApps\camejko\counter-strike\hl.exe"="E:\Hry\CS\SteamApps\camejko\counter-strike\hl.exe:*:Enabled:Counter-Strike"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\Programy\ICQ7.1\ICQ.exe"="E:\Programy\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1"
"E:\Programy\ICQ7.1\aolload.exe"="E:\Programy\ICQ7.1\aolload.exe:*:Enabled:aolload.exe"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"

======List of files/folders created in the last 1 months======

2010-07-14 16:03:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-13 11:37:34 ----D---- C:\Documents and Settings\PC\Application Data\LolClient
2010-07-13 11:10:58 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2010-07-13 11:10:57 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2010-07-13 11:10:57 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2010-07-13 11:10:57 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2010-07-13 11:10:56 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2010-07-13 11:10:56 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2010-07-13 11:10:56 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2010-07-13 11:10:55 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2010-07-13 11:10:53 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2010-07-13 11:10:53 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2010-07-13 11:10:53 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2010-07-13 11:10:52 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2010-07-13 11:09:10 ----D---- C:\Program Files\Common Files\Adobe AIR
2010-07-13 10:53:04 ----D---- C:\Documents and Settings\All Users\Application Data\PMB Files
2010-07-13 10:52:50 ----D---- C:\Program Files\Pando Networks
2010-07-03 22:03:20 ----D---- C:\Documents and Settings\All Users\Application Data\TmForever

======List of files/folders modified in the last 1 months======

2010-08-02 21:28:47 ----D---- C:\WINDOWS\Prefetch
2010-08-02 21:28:39 ----D---- C:\Program Files\trend micro
2010-08-02 21:25:30 ----D---- C:\Documents and Settings\PC\Application Data\Skype
2010-08-02 20:43:30 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-02 18:59:11 ----D---- C:\Documents and Settings\PC\Application Data\skypePM
2010-08-02 18:57:12 ----D---- C:\WINDOWS\Temp
2010-08-02 18:26:47 ----D---- C:\Documents and Settings\PC\Application Data\DMCache
2010-08-02 16:10:53 ----A---- C:\ashampoo-acdw-log.txt
2010-08-02 15:34:47 ----D---- C:\WINDOWS
2010-08-02 15:34:16 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-02 14:20:07 ----D---- C:\Documents and Settings\PC\Application Data\vlc
2010-07-31 17:07:55 ----D---- C:\WINDOWS\system32\config
2010-07-30 11:30:34 ----D---- C:\Documents and Settings\PC\Application Data\Spyware Terminator
2010-07-30 09:58:29 ----D---- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2010-07-29 11:42:54 ----D---- C:\Documents and Settings\PC\Application Data\ICQ
2010-07-28 11:27:31 ----D---- C:\WINDOWS\system32\DirectX
2010-07-28 11:26:49 ----HD---- C:\WINDOWS\inf
2010-07-25 10:18:50 ----D---- C:\Program Files\Mozilla Firefox
2010-07-20 09:22:17 ----D---- C:\WINDOWS\Debug
2010-07-14 16:03:22 ----SHD---- C:\WINDOWS\Installer
2010-07-14 16:03:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-14 16:02:46 ----HD---- C:\WINDOWS\$hf_mig$
2010-07-14 16:02:35 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-07-13 11:11:13 ----D---- C:\Program Files\Adobe
2010-07-13 11:10:58 ----D---- C:\WINDOWS\system32
2010-07-13 11:10:01 ----D---- C:\Documents and Settings\PC\Application Data\Adobe
2010-07-13 11:10:01 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-07-13 11:09:10 ----D---- C:\Program Files\Common Files
2010-07-13 10:52:50 ----RD---- C:\Program Files
2010-07-08 09:40:01 ----D---- C:\Program Files\Spyware Terminator
2010-07-03 22:02:45 ----RSD---- C:\WINDOWS\assembly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-05-23 691696]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-06-28 28880]
R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-06-28 165456]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-06-28 46672]
R1 bbcap;bbcap; C:\WINDOWS\system32\DRIVERS\bbcap.sys [2010-06-21 2944]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-06-28 17744]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-06-28 100176]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2006-02-28 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2006-02-28 55936]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-06-28 23376]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-05-27 4830720]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2009-06-02 99856]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 KMWDFILTER;HIDUASDesc; C:\WINDOWS\system32\DRIVERS\KMWDFILTER.sys [2008-10-09 17408]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1c51x86.sys [2009-07-27 44032]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-02-28 12160]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\WINDOWS\system32\drivers\viahduaa.sys [2009-09-30 1418368]
S3 apngw6tu;apngw6tu; C:\WINDOWS\system32\drivers\apngw6tu.sys []
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2005-01-28 18944]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-05-27 602112]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-01-03 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-01-03 214520]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-06-05 488960]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-06-28 40384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: help

Napsal: 02 srp 2010 21:02
od Roli
Zdravím, tohle fixni v HJT :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/skins7/
R3 - URLSearchHook: (no name) - - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Programy\QuickTime\qttask.exe" -atboottime


HJT najdeš zde :

C:\Program Files\trend micro\PC.exe

Fix znamená že spustíš HJT Obrázek

v okně které se ti otevře klikneš na Do a system scan only

v dalším okně najdeš řádky které jsem ti vypsal,

vedle nich je čtvereček do kterého uděláš zatržítko,

pak klikneš na Fix checked které je vlevo dole,

program se ti zeptá zda opravdu ANO s tím samozřejmě souhlasíš a je hotovo.


Smaž nepotřebné soubory

pomocí CCleaneru

návod :

Čistič - tady vyčistíš PC od nepotřebných souborů a vysypeš Koš

Registry - tady vyčistíš registry (před použitím doporučuji udělat jejich zálohu kterou CCleaner nabízí)

Čištění registru je třeba několikrát zopakovat !


Nakonec použij Mbam z mého podpisu.

Re: help

Napsal: 02 srp 2010 21:36
od matej7
vsetko spravene vypis

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verzia databázy: 4382

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2.8.2010 22:36:23
mbam-log-2010-08-02 (22-36-23).txt

Typ kontroly: Rýchla kontrola
Objektov kontrolovaných: 131405
Uplynulý èas: 3 min, 47 sek

Infikované služby pamäte: 0
Infikované moduly pamäte: 0
Infikované registraèné k¾úèe: 0
Infikované registraèné hodnoty: 0
Infikované položky registraèných dát: 0
Infikované prieèinky: 0
Infikované súbory: 0

Infikované služby pamäte:
(Škodlivé položky neboli zistené)

Infikované moduly pamäte:
(Škodlivé položky neboli zistené)

Infikované registraèné k¾úèe:
(Škodlivé položky neboli zistené)

Infikované registraèné hodnoty:
(Škodlivé položky neboli zistené)

Infikované položky registraèných dát:
(Škodlivé položky neboli zistené)

Infikované prieèinky:
(Škodlivé položky neboli zistené)

Infikované súbory:
(Škodlivé položky neboli zistené)

Re: help

Napsal: 03 srp 2010 20:30
od Roli
Nyní použijeme větší kalibr tak že pozorně číst, protože tenhle softík netoleruje chyby.

Stáhni a ulož na plochu ComboFix,

spusť aplikaci jako Administrátor a povol instalaci Konzole pro zotavení - Recovery Console.

Poté se zobrazí okno s licenčními podmínkami které potvrdíš kliknutím na ANO,

pak ještě jednou klik na ANO a už to jede.

Celá akce trvá okolo 10 minut ale může i déle, během skenu se nepokoušej spouštět nic jiného.

Při skenovaní může být PC i restartováno nelekat se.

Upozornění: po dobu skenu vypni rezidentní štít Antiviru a AntiSpy programu,

protože Combofix se pokouší napadené soubory smazat a tyto programy mu můžou bránit.

Po dokončení skenu nebo následném restartu aplikace vytvoří log, uložený na C:/Combofix.txt

(při opakovaném použití jsou logy číslovány Combofix2.txt atd.), jeho obsah zkopíruj sem.

Re: help

Napsal: 07 srp 2010 09:51
od matej7
oukej bol som v zahranici ento test prevediem vecer

Re: help

Napsal: 07 srp 2010 09:55
od Roli
Dobře.

Re: help

Napsal: 07 srp 2010 10:40
od matej7
ComboFix 10-08-06.03 - PC 07.08.2010 11:33:05.5.3 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1670 [GMT 2:00]
Running from: c:\documents and settings\PC\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\regedit.com
c:\windows\system32\Ijl11.dll
c:\windows\system32\taskmgr.com
c:\windows\system32\Thumbs.db
c:\windows\system32\vbpng1.dll

.
((((((((((((((((((((((((( Files Created from 2010-07-07 to 2010-08-07 )))))))))))))))))))))))))))))))
.

2010-07-31 08:49 . 2010-02-17 16:18 3584 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\toucher-1002170-0-toucher.exe
2010-07-31 08:40 . 2010-07-16 09:38 836096 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\pmv307a-1007160-0-libOctoshapeClient.dll
2010-07-31 08:40 . 2010-02-17 16:19 71960 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll
2010-07-31 08:40 . 2010-02-17 16:19 420352 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-libOctoshapeClient.dll
2010-07-31 08:40 . 2010-02-17 16:19 124184 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-apoctoshape.dll
2010-07-23 10:46 . 2010-07-23 10:46 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-07-14 12:08 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 09:37 . 2010-07-13 09:37 -------- d-----w- c:\documents and settings\PC\Application Data\LolClient
2010-07-13 09:11 . 2010-07-13 09:10 53632 ----a-w- c:\documents and settings\PC\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-13 09:10 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-07-13 09:10 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-07-13 09:10 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-07-13 09:10 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-07-13 09:10 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-07-13 09:10 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-07-13 09:10 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-07-13 09:10 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-07-13 09:09 . 2010-07-13 09:11 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-13 08:53 . 2010-07-13 10:41 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\PMB Files
2010-07-13 08:53 . 2010-07-13 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-07-13 08:52 . 2010-07-13 08:52 -------- d-----w- c:\program files\Pando Networks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-07 09:29 . 2009-12-16 20:56 -------- d-----w- c:\documents and settings\PC\Application Data\Skype
2010-08-07 08:42 . 2009-12-16 20:57 -------- d-----w- c:\documents and settings\PC\Application Data\skypePM
2010-08-07 08:37 . 2010-06-05 20:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-08-02 20:29 . 2010-04-21 16:45 -------- d-----w- c:\program files\trend micro
2010-08-02 16:26 . 2010-04-27 14:11 -------- d-----w- c:\documents and settings\PC\Application Data\DMCache
2010-08-02 12:20 . 2009-12-23 09:00 -------- d-----w- c:\documents and settings\PC\Application Data\vlc
2010-07-30 09:30 . 2010-06-05 20:37 -------- d-----w- c:\documents and settings\PC\Application Data\Spyware Terminator
2010-07-29 09:42 . 2009-12-15 16:36 -------- d-----w- c:\documents and settings\PC\Application Data\ICQ
2010-07-08 07:40 . 2010-06-05 20:37 -------- d-----w- c:\program files\Spyware Terminator
2010-07-03 21:04 . 2010-07-03 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TmForever
2010-06-29 19:04 . 2010-06-29 19:04 -------- d-----w- c:\documents and settings\PC\Application Data\TeamViewer
2010-06-28 20:57 . 2010-06-29 09:48 38848 ----a-w- c:\windows\avastSS.scr
2010-06-28 20:57 . 2010-01-06 15:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-01-06 15:58 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-01-06 15:58 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-01-06 15:58 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-01-06 15:58 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2010-01-06 15:58 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2010-01-06 15:58 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2010-01-06 15:58 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-25 16:26 . 2010-06-25 16:26 -------- d-----w- c:\documents and settings\PC\Application Data\2K Sports
2010-06-24 20:27 . 2010-06-24 20:27 -------- d-----w- c:\program files\IObit
2010-06-22 19:29 . 2010-06-22 19:29 -------- d-----w- c:\documents and settings\PC\Application Data\Charles
2010-06-21 15:31 . 2010-06-21 15:21 -------- d-----w- c:\documents and settings\PC\Application Data\Blueberry
2010-06-21 15:21 . 2010-06-21 15:21 -------- d-----w- c:\documents and settings\PC\Application Data\LogSys
2010-06-21 15:21 . 2010-06-21 15:21 4608 ----a-w- c:\windows\system32\bbchlp.dll
2010-06-21 15:21 . 2010-06-21 15:21 2944 ----a-w- c:\windows\system32\drivers\bbcap.sys
2010-06-21 15:21 . 2010-06-21 15:21 27776 ----a-w- c:\windows\system32\bbcap.dll
2010-06-21 15:21 . 2010-06-21 15:21 -------- d-----w- c:\documents and settings\All Users\Application Data\LogSys
2010-06-20 10:47 . 2010-05-13 12:12 -------- d-----w- c:\documents and settings\PC\Application Data\uTorrent
2010-06-20 10:29 . 2010-06-20 10:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-06-20 10:27 . 2010-06-20 10:26 -------- d-----w- c:\program files\ATI
2010-06-20 10:26 . 2009-12-11 14:04 -------- d-----w- c:\program files\ATI Technologies
2010-06-20 07:58 . 2010-06-20 07:58 -------- d-----w- c:\program files\ICQ6Toolbar
2010-06-20 07:58 . 2010-06-20 07:58 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-06-14 14:31 . 2009-12-11 13:43 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-13 19:44 . 2009-12-23 09:00 -------- d-----w- c:\documents and settings\PC\Application Data\dvdcss
2010-06-05 20:37 . 2010-06-05 20:37 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-05 20:37 . 2010-06-05 20:37 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-05 20:37 . 2010-06-05 20:37 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-05-30 15:47 . 2010-05-30 15:47 32 ----a-w- c:\documents and settings\All Users\Application Data\ezsid.dat
2010-05-27 17:37 . 2009-08-14 04:27 4830720 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-05-27 17:12 . 2010-06-20 10:33 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-05-27 17:12 . 2010-06-20 10:33 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-05-27 17:10 . 2010-06-20 10:33 4071424 ----a-w- c:\windows\system32\aticaldd.dll
2010-05-27 17:05 . 2010-06-20 10:33 15208448 ----a-w- c:\windows\system32\atioglxx.dll
2010-05-27 17:02 . 2010-06-20 10:33 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-05-27 16:59 . 2010-06-20 10:33 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-05-27 16:58 . 2009-08-14 02:27 299520 ----a-w- c:\windows\system32\ati2dvag.dll
2010-05-27 16:54 . 2009-08-14 01:58 3699936 ----a-w- c:\windows\system32\ati3duag.dll
2010-05-27 16:46 . 2010-06-20 10:33 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-05-27 16:46 . 2010-06-20 10:33 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-05-27 16:45 . 2010-06-20 10:33 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-05-27 16:45 . 2010-06-20 10:33 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-05-27 16:45 . 2010-06-20 10:33 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-05-27 16:44 . 2010-06-20 10:33 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-05-27 16:43 . 2010-06-20 10:33 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-05-27 16:42 . 2010-06-20 10:33 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-05-27 16:41 . 2009-08-14 01:42 2256512 ----a-w- c:\windows\system32\ativvaxx.dll
2010-05-27 16:41 . 2010-06-20 10:33 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-05-27 16:41 . 2010-06-20 10:33 3 ----a-w- c:\windows\system32\ativva5x.dat
2010-05-27 16:39 . 2010-06-20 10:33 573440 ----a-w- c:\windows\system32\atikvmag.dll
2010-05-27 16:38 . 2010-06-20 10:33 184320 ----a-w- c:\windows\system32\atiadlxx.dll
2010-05-27 16:37 . 2010-06-20 10:33 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-05-27 16:35 . 2010-06-20 10:33 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-05-27 16:33 . 2009-08-14 01:12 692224 ----a-w- c:\windows\system32\ati2cqag.dll
2010-05-27 16:29 . 2010-06-20 10:33 65536 ----a-w- c:\windows\system32\atimpc32.dll
2010-05-27 16:29 . 2010-06-20 10:33 65536 ----a-w- c:\windows\system32\amdpcom32.dll
2010-05-27 16:28 . 2010-06-20 10:33 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-05-23 09:03 . 2010-05-23 09:03 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-22 20:09 . 2010-05-22 20:00 29058 ----a-w- c:\windows\DIIUnin.dat
2010-05-22 20:00 . 2010-05-22 20:00 2829 ----a-w- c:\windows\DIIUnin.pif
2010-05-22 20:00 . 2010-05-22 20:00 94208 ----a-w- c:\windows\DIIUnin.exe
2010-05-22 19:25 . 2010-05-22 19:25 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="e:\hry\cs\steam.exe" [2010-05-07 1238352]
"DAEMON Tools Lite"="e:\programy\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="e:\programy\ICQ7.1\ICQ.exe" [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-10-09 33677312]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-05 2176512]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt\0sprestrt

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- e:\programy\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 ----a-w- e:\programy\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\freecell.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Documents and Settings\\PC\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"e:\\Hry\\CS\\Steam.exe"=
"e:\\Programy\\ICQ7.1\\ICQ.exe"=
"e:\\Programy\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"e:\\Programy\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"e:\\Hry\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"e:\\Hry\\League of Legends\\Air\\LolClient.exe"=
"e:\\Hry\\League of Legends\\Game\\League of Legends.exe"=
"e:\\Hry\\CS\\SteamApps\\camejko\\counter-strike\\hl.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56658:TCP"= 56658:TCP:Pando Media Booster
"56658:UDP"= 56658:UDP:Pando Media Booster
"8394:TCP"= 8394:TCP:League of Legends Launcher
"8394:UDP"= 8394:UDP:League of Legends Launcher
"6884:TCP"= 6884:TCP:League of Legends Launcher
"6884:UDP"= 6884:UDP:League of Legends Launcher

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6.1.2010 17:58 165456]
R1 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [21.6.2010 17:21 2944]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [5.6.2010 22:37 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.1.2010 17:58 17744]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [11.12.2009 16:02 44032]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [11.12.2009 16:17 1418368]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.5.2010 11:03 691696]
.
Contents of the 'Scheduled Tasks' folder

2010-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do programu Microsoft Excel
IE: E&xportovat do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Prevzia cez IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Prevzia cez IDM všetky prepojenia - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Prevzia obsah FLV cez IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - e:\programy\ICQ7.1\ICQ.exe
TCP: {092475B1-4D09-4DA2-AA69-BEE9A6F0E11E} = 92.245.2.245,92.245.2.162
FF - ProfilePath - c:\documents and settings\PC\Application Data\Mozilla\Firefox\Profiles\8hwzxgix.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_results.php?ch_id=skins7&tb_ver=2.0.0.2&q=
FF - component: c:\documents and settings\PC\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\documents and settings\PC\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-07 11:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{510f2d05-44e9-466e-85f4-af28b881baac}]
@Denied: (Full) (Everyone)
"Model"=dword:000000d5
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):55,0d,d5,00,9b,73,d0,3b,5e,fd,d4,ee,f3,d8,2f,2c,5e,49,13,04,4f,
d8,c5,c4,05,d8,d6,b3,3b,c0,26,c6,76,27,35,84,ca,5a,50,a3,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2010-08-07 11:36:50
ComboFix-quarantined-files.txt 2010-08-07 09:36

Pre-Run: 30 556 168 192 bytes free
Post-Run: 30 537 990 144 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - C47035E03910647B3667C159E2E02F82

Re: help

Napsal: 07 srp 2010 18:55
od Roli
Pokud jsi tak ještě neučinil, přesuň Combofix na plochu

otevři si Poznámkový blok

do něj zkopíruj skript z následujícího okna:

Kód: Vybrat vše

Folder::
c:\program files\ICQ6Toolbar 

FireFox::
FF - ProfilePath - c:\documents and settings\PC\Application Data\Mozilla\Firefox\Profiles\8hwzxgix.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: keyword.URL - hxxp://search.icq.com/search/afe_result ... 2.0.0.2&q=
ulož Tebou vytvořený TXT soubor jako CFScript.txt na plochu,

po uložení uchop vytvořený skript levým myšítkem a přesuň ho nad ikonu Combofixu, kde ho upustíš:

Obrázek

Po aplikaci na Tebe vypadne další log, zkopíruj ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou,

v tom případě znovu restartuj a přitom mačkej F8 poté zvol Poslední známou funkční konfiguraci

Re: help

Napsal: 07 srp 2010 21:42
od matej7
ComboFix 10-08-07.01 - PC 07.08.2010 22:36:35.6.3 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1481 [GMT 2:00]
Running from: c:\documents and settings\PC\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\PC\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ICQ6Toolbar
c:\program files\ICQ6Toolbar\config.xml
c:\program files\ICQ6Toolbar\Icons.bmp
c:\program files\ICQ6Toolbar\ICQ Service.exe
c:\program files\ICQ6Toolbar\icq6Toolbar.ico
c:\program files\ICQ6Toolbar\ICQToolBar.dll
c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
c:\program files\ICQ6Toolbar\logo_small.gif
c:\program files\ICQ6Toolbar\ServiceStarter.exe
c:\program files\ICQ6Toolbar\short.wav
c:\program files\ICQ6Toolbar\Version.txt

.
((((((((((((((((((((((((( Files Created from 2010-07-07 to 2010-08-07 )))))))))))))))))))))))))))))))
.

2010-07-31 08:49 . 2010-02-17 16:18 3584 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\toucher-1002170-0-toucher.exe
2010-07-31 08:40 . 2010-07-16 09:38 836096 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\pmv307a-1007160-0-libOctoshapeClient.dll
2010-07-31 08:40 . 2010-02-17 16:19 71960 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll
2010-07-31 08:40 . 2010-02-17 16:19 420352 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-libOctoshapeClient.dll
2010-07-31 08:40 . 2010-02-17 16:19 124184 ----a-w- c:\documents and settings\PC\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-apoctoshape.dll
2010-07-23 10:46 . 2010-07-23 10:46 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-07-14 12:08 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-13 09:37 . 2010-07-13 09:37 -------- d-----w- c:\documents and settings\PC\Application Data\LolClient
2010-07-13 09:11 . 2010-07-13 09:10 53632 ----a-w- c:\documents and settings\PC\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-13 09:10 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-07-13 09:10 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-07-13 09:10 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-07-13 09:10 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-07-13 09:10 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-07-13 09:10 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2010-07-13 09:10 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2010-07-13 09:10 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2010-07-13 09:10 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2010-07-13 09:09 . 2010-07-13 09:11 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-13 08:53 . 2010-07-13 10:41 -------- d-----w- c:\documents and settings\PC\Local Settings\Application Data\PMB Files
2010-07-13 08:53 . 2010-07-13 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-07-13 08:52 . 2010-07-13 08:52 -------- d-----w- c:\program files\Pando Networks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-07 20:31 . 2009-12-16 20:56 -------- d-----w- c:\documents and settings\PC\Application Data\Skype
2010-08-07 14:05 . 2009-12-16 20:57 -------- d-----w- c:\documents and settings\PC\Application Data\skypePM
2010-08-07 09:44 . 2010-06-05 20:37 -------- d-----w- c:\documents and settings\PC\Application Data\Spyware Terminator
2010-08-07 08:37 . 2010-06-05 20:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-08-02 20:29 . 2010-04-21 16:45 -------- d-----w- c:\program files\trend micro
2010-08-02 16:26 . 2010-04-27 14:11 -------- d-----w- c:\documents and settings\PC\Application Data\DMCache
2010-08-02 12:20 . 2009-12-23 09:00 -------- d-----w- c:\documents and settings\PC\Application Data\vlc
2010-07-29 09:42 . 2009-12-15 16:36 -------- d-----w- c:\documents and settings\PC\Application Data\ICQ
2010-07-08 07:40 . 2010-06-05 20:37 -------- d-----w- c:\program files\Spyware Terminator
2010-07-03 21:04 . 2010-07-03 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\TmForever
2010-06-29 19:04 . 2010-06-29 19:04 -------- d-----w- c:\documents and settings\PC\Application Data\TeamViewer
2010-06-28 20:57 . 2010-06-29 09:48 38848 ----a-w- c:\windows\avastSS.scr
2010-06-28 20:57 . 2010-01-06 15:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-01-06 15:58 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-01-06 15:58 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-01-06 15:58 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-01-06 15:58 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2010-01-06 15:58 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2010-01-06 15:58 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2010-01-06 15:58 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-25 16:26 . 2010-06-25 16:26 -------- d-----w- c:\documents and settings\PC\Application Data\2K Sports
2010-06-24 20:27 . 2010-06-24 20:27 -------- d-----w- c:\program files\IObit
2010-06-22 19:29 . 2010-06-22 19:29 -------- d-----w- c:\documents and settings\PC\Application Data\Charles
2010-06-21 15:31 . 2010-06-21 15:21 -------- d-----w- c:\documents and settings\PC\Application Data\Blueberry
2010-06-21 15:21 . 2010-06-21 15:21 -------- d-----w- c:\documents and settings\PC\Application Data\LogSys
2010-06-21 15:21 . 2010-06-21 15:21 4608 ----a-w- c:\windows\system32\bbchlp.dll
2010-06-21 15:21 . 2010-06-21 15:21 2944 ----a-w- c:\windows\system32\drivers\bbcap.sys
2010-06-21 15:21 . 2010-06-21 15:21 27776 ----a-w- c:\windows\system32\bbcap.dll
2010-06-21 15:21 . 2010-06-21 15:21 -------- d-----w- c:\documents and settings\All Users\Application Data\LogSys
2010-06-20 10:47 . 2010-05-13 12:12 -------- d-----w- c:\documents and settings\PC\Application Data\uTorrent
2010-06-20 10:29 . 2010-06-20 10:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-06-20 10:27 . 2010-06-20 10:26 -------- d-----w- c:\program files\ATI
2010-06-20 10:26 . 2009-12-11 14:04 -------- d-----w- c:\program files\ATI Technologies
2010-06-20 07:58 . 2010-06-20 07:58 -------- d-----w- c:\documents and settings\All Users\Application Data\ICQ
2010-06-14 14:31 . 2009-12-11 13:43 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-13 19:44 . 2009-12-23 09:00 -------- d-----w- c:\documents and settings\PC\Application Data\dvdcss
2010-06-05 20:37 . 2010-06-05 20:37 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-06-05 20:37 . 2010-06-05 20:37 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-06-05 20:37 . 2010-06-05 20:37 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-05-30 15:47 . 2010-05-30 15:47 32 ----a-w- c:\documents and settings\All Users\Application Data\ezsid.dat
2010-05-27 17:37 . 2009-08-14 04:27 4830720 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-05-27 17:12 . 2010-06-20 10:33 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-05-27 17:12 . 2010-06-20 10:33 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-05-27 17:10 . 2010-06-20 10:33 4071424 ----a-w- c:\windows\system32\aticaldd.dll
2010-05-27 17:05 . 2010-06-20 10:33 15208448 ----a-w- c:\windows\system32\atioglxx.dll
2010-05-27 17:02 . 2010-06-20 10:33 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-05-27 16:59 . 2010-06-20 10:33 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-05-27 16:58 . 2009-08-14 02:27 299520 ----a-w- c:\windows\system32\ati2dvag.dll
2010-05-27 16:54 . 2009-08-14 01:58 3699936 ----a-w- c:\windows\system32\ati3duag.dll
2010-05-27 16:46 . 2010-06-20 10:33 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-05-27 16:46 . 2010-06-20 10:33 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-05-27 16:45 . 2010-06-20 10:33 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-05-27 16:45 . 2010-06-20 10:33 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-05-27 16:45 . 2010-06-20 10:33 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-05-27 16:44 . 2010-06-20 10:33 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-05-27 16:43 . 2010-06-20 10:33 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-05-27 16:42 . 2010-06-20 10:33 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-05-27 16:41 . 2009-08-14 01:42 2256512 ----a-w- c:\windows\system32\ativvaxx.dll
2010-05-27 16:41 . 2010-06-20 10:33 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-05-27 16:41 . 2010-06-20 10:33 3 ----a-w- c:\windows\system32\ativva5x.dat
2010-05-27 16:39 . 2010-06-20 10:33 573440 ----a-w- c:\windows\system32\atikvmag.dll
2010-05-27 16:38 . 2010-06-20 10:33 184320 ----a-w- c:\windows\system32\atiadlxx.dll
2010-05-27 16:37 . 2010-06-20 10:33 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-05-27 16:35 . 2010-06-20 10:33 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-05-27 16:33 . 2009-08-14 01:12 692224 ----a-w- c:\windows\system32\ati2cqag.dll
2010-05-27 16:29 . 2010-06-20 10:33 65536 ----a-w- c:\windows\system32\atimpc32.dll
2010-05-27 16:29 . 2010-06-20 10:33 65536 ----a-w- c:\windows\system32\amdpcom32.dll
2010-05-27 16:28 . 2010-06-20 10:33 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-05-23 09:03 . 2010-05-23 09:03 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-05-22 20:09 . 2010-05-22 20:00 29058 ----a-w- c:\windows\DIIUnin.dat
2010-05-22 20:00 . 2010-05-22 20:00 2829 ----a-w- c:\windows\DIIUnin.pif
2010-05-22 20:00 . 2010-05-22 20:00 94208 ----a-w- c:\windows\DIIUnin.exe
2010-05-22 19:25 . 2010-05-22 19:25 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-08-07_09.35.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-07 20:32 . 2010-08-07 20:32 16384 c:\windows\Temp\Perflib_Perfdata_1cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="e:\hry\cs\steam.exe" [2010-05-07 1238352]
"DAEMON Tools Lite"="e:\programy\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"ICQ"="e:\programy\ICQ7.1\ICQ.exe" [2010-06-08 133368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-10-09 33677312]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-06-05 2176512]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-02-28 44544]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt\0sprestrt

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-17 19:53 421888 ----a-w- e:\programy\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2009-07-01 16:37 37888 ----a-w- e:\programy\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\freecell.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Documents and Settings\\PC\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"e:\\Hry\\CS\\Steam.exe"=
"e:\\Programy\\ICQ7.1\\ICQ.exe"=
"e:\\Programy\\ICQ7.1\\aolload.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"e:\\Programy\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
"e:\\Hry\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"e:\\Hry\\League of Legends\\Air\\LolClient.exe"=
"e:\\Hry\\League of Legends\\Game\\League of Legends.exe"=
"e:\\Hry\\CS\\SteamApps\\camejko\\counter-strike\\hl.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56658:TCP"= 56658:TCP:Pando Media Booster
"56658:UDP"= 56658:UDP:Pando Media Booster
"8394:TCP"= 8394:TCP:League of Legends Launcher
"8394:UDP"= 8394:UDP:League of Legends Launcher
"6884:TCP"= 6884:TCP:League of Legends Launcher
"6884:UDP"= 6884:UDP:League of Legends Launcher
"6957:TCP"= 6957:TCP:League of Legends Launcher
"6957:UDP"= 6957:UDP:League of Legends Launcher

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6.1.2010 17:58 165456]
R1 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [21.6.2010 17:21 2944]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [5.6.2010 22:37 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6.1.2010 17:58 17744]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [11.12.2009 16:02 44032]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [11.12.2009 16:17 1418368]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23.5.2010 11:03 691696]
.
Contents of the 'Scheduled Tasks' folder

2010-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xportovat do programu Microsoft Excel
IE: E&xportovat do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Prevzia cez IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Prevzia cez IDM všetky prepojenia - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Prevzia obsah FLV cez IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: {{71BFC818-0CED-42D6-9C87-5142918957EE} - e:\programy\ICQ7.1\ICQ.exe
TCP: {092475B1-4D09-4DA2-AA69-BEE9A6F0E11E} = 92.245.2.245,92.245.2.162
FF - ProfilePath - c:\documents and settings\PC\Application Data\Mozilla\Firefox\Profiles\8hwzxgix.default\
FF - prefs.js: browser.startup.homepage - hxxp://sk.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:sk:official
FF - component: c:\documents and settings\PC\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\documents and settings\PC\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: e:\programy\QuickTime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-07 22:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{510f2d05-44e9-466e-85f4-af28b881baac}]
@Denied: (Full) (Everyone)
"Model"=dword:000000d5
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):55,0d,d5,00,9b,73,d0,3b,5e,fd,d4,ee,f3,d8,2f,2c,5e,49,13,04,4f,
d8,c5,c4,05,d8,d6,b3,3b,c0,26,c6,76,27,35,84,ca,5a,50,a3,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2010-08-07 22:40:27
ComboFix-quarantined-files.txt 2010-08-07 20:40
ComboFix2.txt 2010-08-07 09:36

Pre-Run: 30 424 420 352 bytes free
Post-Run: 30 408 249 344 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 42767E3C6622A0794B20CAEF81258376

Re: help

Napsal: 08 srp 2010 10:22
od Roli
Přes Start >> Spustit zkopíruj do okna:

ComboFix /Uninstall

a stiskni Enter

To odinstaluje ComboFix a smaže s ním související soubory a složky.


Pak dej vědět jaký je stav PC.