Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Náhodné popupy v Mozilla Firefox

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
jaCUBE
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 26 dub 2006 12:42

Náhodné popupy v Mozilla Firefox

#1 Příspěvek od jaCUBE »

Zdravím,
nedávno jsem instaloval pofidérní soubor z hlubin Internetu. Po spuštění toho EXE jsem se zhrozil, když NOD32 pochytal asi 12 virů, nicméně přinejmenším jeden mu zřejmě unikl. Teď když procházím weby přes můj Firefox 3.6.8, občas mi vyskočí popupy. Dělá mi to nezávisle na doméně (včetně VIRY.CZ :) ), takže je problém určitě u mě. Počítač jsem proscanoval pomocí NOD32 a Spybota, ale ani jeden mi nepomohl. Zkusil jsem vymazat cookies i cache ve Firefox, opět bez úspěchu.

Vše co bylo pochytáno:
Obrázek

Otravné popupy vždy směřují na stejnou adresu, jejíž obsah už však NOD32 blokuje:
Obrázek

Všem předem děkuji za rady. ;)

__________________________

Logfile of random's system information tool 1.08 (written by random/random)
Run by jaCUBE at 2010-08-27 09:07:12
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 83 GB (22%) free of 382 GB
Total RAM: 3327 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:07:17, on 27.8.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AMD\OverDrive\AODAssist.exe
C:\AppServ\Apache2.2\bin\httpd.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\AppServ\MySQL\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\AppServ\Apache2.2\bin\httpd.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\WhatPulse\WhatPulse.exe
C:\Program Files\Seznam.cz\postak.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre6\bin\javaw.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Software Disc\Ostatní\HijackThis 2.0.4\HijackThis.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\jaCUBE\Plocha\RSIT.exe
C:\Program Files\trend micro\jaCUBE.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ukazatel S-Rank - {EA837F48-5AD1-443E-AE34-FFE03CBF3099} - C:\Program Files\Seznam.cz\core.2.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [Seznam Postak] "C:\Program Files\Seznam.cz\postak.exe" -s
O4 - HKCU\..\Run: [WindowBlinds] C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBInstall32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: ST6UNST Uninstaller.LNK = C:\WINDOWS\ST6UNST.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: ST6UNST Uninstaller.LNK = C:\WINDOWS\ST6UNST.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PC Atomic Sync.lnk = C:\Program Files\BrigSoft\BSAtomic\BSAtomic.exe
O8 - Extra context menu item: &Stáhnout &vše FlashGetem - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastavit překladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra 'Tools' menuitem: Přeložit &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AODService - Unknown owner - C:\Program Files\AMD\OverDrive\AODAssist.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\AppServ\Apache2.2\bin\httpd.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Dragon Age: Prameny - aktualizace obsahu (DAUpdaterSvc) - BioWare - C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: mysql - Unknown owner - C:\AppServ\MySQL\bin\mysqld-nt.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe

--
End of file - 9969 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Automatic troubleshooting.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-12-11 798771]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5A1691B-D188-4419-AD02-90002030B8EE}]
FlashFXP Helper for Internet Explorer - C:\PROGRA~1\FlashFXP\IEFlash.dll [2008-06-16 191096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-06-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Ukazatel S-Rank - C:\Program Files\Seznam.cz\core.2.dll [2010-05-19 1117976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - C:\Documents and Settings\All Users\Data aplikací\LangSoft\WebIE.dll [2009-12-11 798771]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-05-27 98304]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2010-04-07 2145000]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2010-07-06 19556968]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"WhatPulse"=C:\Program Files\WhatPulse\WhatPulse.exe [2009-04-08 2814976]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-05-19 462104]
"WindowBlinds"=C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBInstall32.exe [2007-09-12 99752]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PC Atomic Sync.lnk - C:\Program Files\BrigSoft\BSAtomic\BSAtomic.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wbsys.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2010-07-07 159744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll [2010-01-22 184320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - C:\Program Files\Stardock\Object Desktop\IconPackager\iprepair.dll [2009-11-18 70960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0x00000000
"NoSharedDocuments"=0x01000000

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe"="C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:*:Enabled:Battlefield 2"
"C:\Program Files\Bohemia Interactive\ArmA 2\arma2.exe"="C:\Program Files\Bohemia Interactive\ArmA 2\arma2.exe:*:Enabled:ArmA 2"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\Program Files\Dragon Age\bin_ship\daorigins.exe"="C:\Program Files\Dragon Age\bin_ship\daorigins.exe:*:Enabled:Dragon Age Prameny Hra"
"C:\Program Files\Dragon Age\DAOriginsLauncher.exe"="C:\Program Files\Dragon Age\DAOriginsLauncher.exe:*:Enabled:Dragon Age Prameny Spustit"
"$INSTDIR\FlvDetector.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlvDetector.exe:*:Enabled:FGFlvDetector"
"C:\Program Files\Codemasters\DiRT2\dirt2_game.exe"="C:\Program Files\Codemasters\DiRT2\dirt2_game.exe:*:Enabled:DiRT2"
"C:\Program Files\FlashGet\FlashGet.exe"="C:\Program Files\FlashGet\FlashGet.exe:*:Enabled:Flashget"
"C:\DOCUME~1\jaCUBE\LOCALS~1\Temp\IMC.exe"="C:\DOCUME~1\jaCUBE\LOCALS~1\Temp\IMC.exe:*:Enabled:test"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe"="C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords.exe"="C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords.exe:*:Enabled:Sid Meier's Civilization 4 Warlords"
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords_PitBoss.exe"="C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Warlords\Civ4Warlords_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Pitboss"
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe"="C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe"="C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe"="C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe"="C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\HPWUCli.exe"="C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\Steam\Steam.exe"="C:\Program Files\Steam\Steam.exe:*:Enabled:Steam"
"C:\Program Files\UBISOFT\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\UBISOFT\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\UBISOFT\Assassin's Creed II\AssassinsCreedIIGame.exe"="C:\Program Files\UBISOFT\Assassin's Creed II\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II"
"C:\Program Files\UBISOFT\Assassin's Creed II\AssassinsCreedII.exe"="C:\Program Files\UBISOFT\Assassin's Creed II\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update"
"C:\Program Files\UBISOFT\Assassin's Creed II\UPlayBrowser.exe"="C:\Program Files\UBISOFT\Assassin's Creed II\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay"
"C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Game.exe"="C:\Program Files\Electronic Arts\Battlefield Bad Company 2\BFBC2Game.exe:*:Enabled:Battlefield: Bad Company™ 2"
"C:\Program Files\Java\jre6\bin\javaw.exe"="C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
"C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe"="C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe:*:Enabled:Dragon Age Origins Aktualizovat"
"C:\Program Files\Codemasters\GRID\GRID.exe"="C:\Program Files\Codemasters\GRID\GRID.exe:*:Enabled:GRID"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\UBISOFT\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe"="C:\Program Files\UBISOFT\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2"
"C:\Program Files\UBISOFT\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe"="C:\Program Files\UBISOFT\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:*:Enabled:Tom Clancy's Rainbow Six Vegas 2 Update"
"C:\Program Files\GSC World Publishing\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe"="C:\Program Files\GSC World Publishing\S.T.A.L.K.E.R. - Call of Pripyat\bin\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Call of Pripyat (CLI)"
"C:\Program Files\GSC World Publishing\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe"="C:\Program Files\GSC World Publishing\S.T.A.L.K.E.R. - Call of Pripyat\bin\dedicated\xrEngine.exe:*:Enabled:S.T.A.L.K.E.R. - Call of Pripyat (SRV)"
"D:\Grand Theft Auto IV\LaunchGTAIV.exe"="D:\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV"
"C:\Program Files\EA GAMES\Mirror's Edge\Binaries\MirrorsEdge.exe"="C:\Program Files\EA GAMES\Mirror's Edge\Binaries\MirrorsEdge.exe:*:Enabled:Mirror's Edge™"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfcCopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe"="C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe:*:Enabled:hpqphotocrm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe:*:Enabled:hpqgplgtupl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe:*:Enabled:hpqgpc01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe:*:Enabled:hpqusgm.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe:*:Enabled:hpqusgh.exe"
"C:\Program Files\HP\HP Software Update\HPWUCli.exe"="C:\Program Files\HP\HP Software Update\HPWUCli.exe:*:Enabled:hpwucli.exe"
"C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe"="C:\Program Files\HP\Digital Imaging\smart web printing\SmartWebPrintExe.exe:*:Enabled:smartwebprintexe.exe"

======File associations======

.txt - open - notepad.exe %1

======List of files/folders created in the last 1 months======

2010-08-27 08:44:31 ----D---- C:\rsit
2010-08-27 08:44:31 ----D---- C:\Program Files\trend micro
2010-08-27 06:33:29 ----D---- C:\Program Files\Winamp Detect
2010-08-26 08:47:02 ----D---- C:\Miranda IM
2010-08-25 17:42:34 ----D---- C:\Program Files\NVIDIA Corporation
2010-08-23 20:43:14 ----D---- C:\CoH
2010-08-15 20:57:26 ----D---- C:\Program Files\Open Transport Tycoon 1.0.3
2010-08-13 10:04:16 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\The Creative Assembly
2010-08-12 22:07:40 ----D---- C:\Documents and Settings\All Users\Data aplikací\ATI
2010-08-12 21:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-12 21:59:24 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-08-12 21:59:14 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-12 21:59:04 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-12 21:55:50 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-12 21:55:44 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-12 21:53:54 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-12 21:53:36 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-08-12 21:53:35 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-12 18:29:03 ----D---- C:\Program Files\The Witcher Enhanced Edition
2010-08-04 21:08:00 ----D---- C:\WINDOWS\E4D153288C89484BB9AAF5BE9EA6D01C.TMP
2010-08-03 23:37:48 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\HD Tune Pro
2010-08-03 23:37:43 ----D---- C:\Program Files\HD Tune Pro
2010-08-03 15:05:27 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-08-02 18:09:44 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\GRETECH
2010-08-01 03:52:02 ----D---- C:\Program Files\OO Software
2010-07-31 11:19:58 ----A---- C:\WINDOWS\BlendSettings.ini
2010-07-30 15:42:25 ----D---- C:\Program Files\Supreme Commander 2
2010-07-30 14:05:54 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\Need for Speed World
2010-07-29 23:20:23 ----A---- C:\WINDOWS\system32\drivers\cpuz134_x32.sys
2010-07-29 20:53:20 ----A---- C:\WINDOWS\system32\drivers\usbfilter.sys
2010-07-29 18:41:07 ----A---- C:\WINDOWS\system32\drivers\AmdPPM.sys
2010-07-29 18:34:25 ----RA---- C:\WINDOWS\system32\RTNUninst32.dll
2010-07-29 18:34:25 ----RA---- C:\WINDOWS\system32\RtNicProp32.dll
2010-07-29 18:34:25 ----RA---- C:\WINDOWS\system32\drivers\Rtenicxp.sys
2010-07-29 18:31:43 ----D---- C:\Program Files\Marvell
2010-07-29 18:14:48 ----ASH---- C:\hiberfil.sys
2010-07-29 18:06:28 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\InstallShield
2010-07-28 17:42:29 ----A---- C:\WINDOWS\system32\drivers\wmiacpi.sys

======List of files/folders modified in the last 1 months======

2010-08-27 09:07:12 ----D---- C:\WINDOWS\Temp
2010-08-27 08:49:55 ----D---- C:\WINDOWS\Prefetch
2010-08-27 08:44:31 ----D---- C:\Program Files
2010-08-27 08:39:02 ----D---- C:\Program Files\FlashGet
2010-08-27 08:38:44 ----D---- C:\Downloads
2010-08-27 08:28:12 ----D---- C:\WINDOWS\system32\drivers\etc
2010-08-27 07:28:13 ----D---- C:\WINDOWS
2010-08-27 07:21:27 ----SHD---- C:\WINDOWS\Installer
2010-08-27 07:21:27 ----SHD---- C:\Config.Msi
2010-08-27 07:21:24 ----D---- C:\Program Files\Common Files\Adobe
2010-08-27 07:21:17 ----D---- C:\WINDOWS\system32
2010-08-27 07:05:01 ----D---- C:\WINDOWS\system32\inetsrv
2010-08-27 06:41:03 ----D---- C:\Program Files\Winamp
2010-08-27 06:38:59 ----A---- C:\LOGFILE.TXT
2010-08-26 18:18:44 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\LangSoft
2010-08-26 17:17:38 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\Xfire
2010-08-26 15:43:04 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-08-26 09:38:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-26 08:50:39 ----D---- C:\Program Files\Steam
2010-08-25 19:16:20 ----D---- C:\Program Files\JDownloader
2010-08-25 17:42:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-08-25 17:20:31 ----D---- C:\Program Files\Seznam.cz
2010-08-25 17:17:17 ----D---- C:\Program Files\2K Games
2010-08-23 06:34:10 ----D---- C:\Program Files\Miranda IM
2010-08-22 11:49:04 ----D---- C:\Documents and Settings\jaCUBE\Data aplikací\TeamViewer
2010-08-22 11:48:55 ----D---- C:\Program Files\TeamViewer
2010-08-22 06:50:04 ----A---- C:\WINDOWS\IE4 Error Log.txt
2010-08-20 05:55:41 ----D---- C:\WINDOWS\system32\drivers
2010-08-19 06:55:44 ----D---- C:\Program Files\Toribash-3.88
2010-08-15 20:39:51 ----D---- C:\Program Files\Rockstar Games
2010-08-15 20:39:50 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-15 20:14:36 ----AD---- C:\Documents and Settings\All Users\Data aplikací\TEMP
2010-08-13 01:26:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\BOINC
2010-08-13 01:12:19 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-13 01:11:55 ----RSD---- C:\WINDOWS\assembly
2010-08-12 22:11:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-12 22:08:48 ----HD---- C:\WINDOWS\inf
2010-08-12 22:02:43 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-12 22:02:29 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-12 21:59:30 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-12 21:59:28 ----A---- C:\WINDOWS\imsins.BAK
2010-08-12 21:58:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-08-12 21:58:19 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-12 21:57:58 ----D---- C:\WINDOWS\WinSxS
2010-08-12 21:56:08 ----D---- C:\Program Files\Internet Explorer
2010-08-12 21:53:57 ----D---- C:\Program Files\Movie Maker
2010-08-12 21:03:54 ----A---- C:\WINDOWS\win.ini
2010-08-12 18:47:05 ----D---- C:\WINDOWS\system32\DirectX
2010-08-11 05:54:53 ----D---- C:\WINDOWS\system32\config
2010-08-10 03:04:17 ----D---- C:\!MUSiC
2010-08-09 15:02:40 ----D---- C:\Program Files\Real Alternative
2010-08-09 14:43:58 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-09 06:55:34 ----D---- C:\Program Files\Orbiter
2010-08-04 21:55:22 ----D---- C:\WINDOWS\Minidump
2010-08-04 21:08:53 ----D---- C:\Program Files\EA GAMES
2010-08-03 20:09:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-08-03 13:08:47 ----D---- C:\Documents and Settings\All Users\Data aplikací\DFX
2010-08-02 18:09:23 ----D---- C:\Program Files\GRETECH
2010-08-01 03:54:34 ----D---- C:\WINDOWS\system32\oodag
2010-07-31 11:11:34 ----D---- C:\Program Files\Bethesda Softworks
2010-07-30 19:40:26 ----D---- C:\Program Files\Common Files
2010-07-30 19:40:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-07-30 16:52:21 ----D---- C:\Program Files\Electronic Arts
2010-07-30 12:26:37 ----D---- C:\Program Files\Karen's Power Tools
2010-07-30 12:04:38 ----D---- C:\Program Files\ATI
2010-07-30 12:04:13 ----D---- C:\Program Files\ATI Technologies
2010-07-30 12:01:12 ----D---- C:\Program Files\SpeedFan
2010-07-30 09:37:45 ----D---- C:\Program Files\Xfire
2010-07-29 23:38:10 ----D---- C:\Program Files\AMD
2010-07-29 18:41:03 ----RSH---- C:\boot.ini
2010-07-29 18:34:17 ----D---- C:\Program Files\Realtek

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-10-07 721904]
R1 AmdPPM;Ovladač procesoru HwPState AMD; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792]
R1 atitray;atitray; \??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys []
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2010-04-07 114984]
R1 epfwtdi;epfwtdi; C:\WINDOWS\system32\DRIVERS\epfwtdi.sys [2010-04-07 55232]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2010-07-26 230736]
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2009-10-08 279712]
R2 eamon;eamon; C:\WINDOWS\system32\DRIVERS\eamon.sys [2010-04-07 139192]
R2 epfw;epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [2010-04-07 134488]
R2 irda;Protokol IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2008-04-14 88192]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2009-10-08 25888]
R2 MaVctrl;MaVctrl; C:\WINDOWS\system32\DRIVERS\MaVc2K.sys [2007-01-16 11986]
R3 AODDriver2;AODDriver2; \??\C:\Program Files\AMD\OverDrive\i386\AODDriver2.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2010-07-07 5069312]
R3 Epfwndis;Eset Personal Firewall; C:\WINDOWS\system32\DRIVERS\Epfwndis.sys [2010-04-07 32584]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 HDAudBus;Ovladač Microsoft UAA pro sběrnici High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2010-07-06 6088296]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2009-11-27 177152]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys []
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2009-11-18 1691480]
S3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys []
S3 awc9e1sy;awc9e1sy; C:\WINDOWS\system32\drivers\awc9e1sy.sys []
S3 cpuxp;cpuxp; \??\D:\Software Disc\Multimediální Přehrávače\WinAMP 5.556\DFX 9.012\Keymaker-CORE\cpuxp.sys []
S3 cpuz130;cpuz130; \??\C:\DOCUME~1\STANDA~1.JAC\LOCALS~1\Temp\cpuz130\cpuz_x32.sys []
S3 DualCoreCenter;DualCoreCenter; \??\C:\Program Files\MSI\OverclockingCenter\NTGLM7X.sys []
S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys []
S3 GMSIPCI;GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS []
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2008-10-28 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2008-10-28 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2008-10-28 21568]
S3 irsir;Microsoft Serial Infrared Driver; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
S3 mamotou;mamotou; C:\WINDOWS\system32\DRIVERS\mamotou.sys [2007-02-02 49377]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2009-11-18 1395800]
S3 motmodem;Motorola USB CDC ACM Driver; C:\WINDOWS\system32\DRIVERS\motmodem.sys [2006-12-13 20992]
S3 MSICPL;MSICPL; \??\F:\install4\MSICPL.sys []
S3 NTACCESS;NTACCESS; \??\F:\NTACCESS.sys []
S3 RushTopDevice_J;RushTopDevice_J; \??\C:\Program Files\MSI\OverclockingCenter\RushJ.sys []
S3 RushTopDevice2;RushTopDevice2; \??\C:\Program Files\MSI\OverclockingCenter\RushTop.sys []
S3 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\F:\NTGLM7X.sys []
S3 teamviewervpn;TeamViewer VPN Adapter; C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AODService;AODService; C:\Program Files\AMD\OverDrive\AODAssist.exe [2010-04-23 136616]
R2 Apache2.2;Apache2.2; C:\AppServ\Apache2.2\bin\httpd.exe [2008-01-17 24635]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2010-04-07 810120]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 IISADMIN;Správa služby IIS; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15872]
R2 mysql;mysql; C:\AppServ\MySQL\bin\mysqld-nt --defaults-file=C:\AppServ\MySQL\my.ini mysql []
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2009-10-09 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-08-26 218808]
R2 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-24 133104]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2010-03-18 35160]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-07 79360]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu; C:\Program Files\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [2009-12-15 25832]
S3 EhttpSrv;ESET HTTP Server; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [2010-04-07 33560]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-03-06 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S3 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2008-09-04 1295616]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe [2009-12-19 435016]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; C:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2010-07-07 602112]
S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2009-08-13 593920]
S4 HPSLPSVC;HP Network Devices Support; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 Irmon;Sledování infračerveného přenosu; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-06-04 153376]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2009-09-23 935208]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service; C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-11-17 1021256]
S4 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S4 W3SVC;Publikování na webu; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15872]

-----------------EOF-----------------

Uživatelský avatar
Tempest
VIP
VIP
Příspěvky: 193
Registrován: 05 čer 2005 08:18

Re: Náhodné popupy v Mozilla Firefox

#2 Příspěvek od Tempest »

Zdravím,

Použij ComboFix podle tohoto návodu: http://www.bleepingcomputer.com/combofi ... t-combofix
Log z něj vlož sem.

jaCUBE
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 26 dub 2006 12:42

Re: Náhodné popupy v Mozilla Firefox

#3 Příspěvek od jaCUBE »

Zrovna v době Tvé odpovědi jsem psal svůj příspěvek o tom, jak jsem vše za pomoci ComboFixu po pár restartech vyřešil (používal jsem ho bez návodu, dokážu si zničit systém sám :) ). Zřejmě se jednalo o nějaký TDSS (Alureon) rootkit. Havěť vskutku odolná, ale ComboFix je moc šikovná utilitka. :) Každopádně děkuji za pomoc, příště použiji Google dřív, abych sem zbytečně nepsal. Přeji hezký den. ;)

__________________________
ComboFix 10-08-26.02 - jaCUBE 27.08.2010 10:19:00.1.4 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.3327.2764 [GMT 2:00]
Spuštěný z: C:\Documents and Settings\jaCUBE\Plocha\ComboFix.exe
AV: ESET Smart Security 4.2 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Avira FireWall *disabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
FW: ESET personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Rezidentní štít AV je zapnutý

.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\jaCUBE\Local Settings\Temporary Internet Files\SLOVA.WAV
C:\Program Files\FlashGet Network
C:\Program Files\FlashGet Network\FlashGet 3\dat\Appsetting.cfg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\1.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\1.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\2.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\3.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\btn1.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\btn2.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\cig.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\cig1.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_1_2.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_1_9.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_111_1.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_2_2.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_321321321.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_43253355.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_4325355.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_icon01.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_icon03.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_icon04.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_kblogo.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\client_WuBiaoTi-3_2.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\dian.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\directui_new_1259294262.zip
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\down.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\game.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\game.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\game1.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\gameall.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\gametop.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\ico01.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\ico02.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\line.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\movie.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\movie1.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\new_rescenter.txt
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\newgame.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\newmovie.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p1.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p2.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p3.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p4.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p5.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p6.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p7.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\p8.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\pic_bg.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\preview.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\reom.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\reom.jpg1
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\rescenter.txt
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\soft.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\soft_zhan.jpg
C:\Program Files\FlashGet Network\FlashGet 3\dat\directui\tab.gif
C:\Program Files\FlashGet Network\FlashGet 3\dat\FlashGet3db.bak
C:\Program Files\FlashGet Network\FlashGet 3\dat\FlashGet3db.db
C:\Program Files\FlashGet Network\FlashGet 3\dat\stat\advertisement\adconfig.ini
C:\Program Files\FlashGet Network\FlashGet 3\dat\stat\advertisement\port.ini
C:\Program Files\FlashGet Network\FlashGet 3\dat\torrent\3885968_[isoHunt] SteamUp__2.1.4_-_REVOLUTiON.5171771.TPB.torrent
C:\Program Files\FlashGet Network\FlashGet 3\P2PCfg.ini
C:\WINDOWS\Downloaded Program Files\IDropPTB.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\secushr.dat
C:\WINDOWS\system32\secustat.dat

Nakažená kopie C:\WINDOWS\system32\drivers\rdpcdd.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CPUXP
-------\Legacy_NPF
-------\Service_cpuxp


((((((((((((((((((((((((( Soubory vytvořené od 2010-07-27 do 2010-08-27 )))))))))))))))))))))))))))))))
.

2010-08-27 07:27:57 . 2010-08-27 07:29:50 -------- d-----w- C:\Program Files\DAEMON Tools Lite
2010-08-27 06:44:31 . 2010-08-27 07:07:13 -------- d-----w- C:\Program Files\trend micro
2010-08-27 06:44:31 . 2010-08-27 06:44:38 -------- d-----w- C:\rsit
2010-08-27 04:33:29 . 2010-08-27 04:35:27 -------- d-----w- C:\Program Files\Winamp Detect
2010-08-26 06:47:02 . 2010-08-26 06:47:03 -------- d-----w- C:\Miranda IM
2010-08-25 15:42:34 . 2010-08-25 15:42:34 -------- d-----w- C:\Program Files\NVIDIA Corporation
2010-08-23 18:43:14 . 2010-08-23 18:43:14 -------- d-----w- C:\CoH
2010-08-15 18:57:26 . 2010-08-19 00:30:12 -------- d-----w- C:\Program Files\Open Transport Tycoon 1.0.3
2010-08-12 16:29:03 . 2010-08-12 16:37:51 -------- d-----w- C:\Program Files\The Witcher Enhanced Edition
2010-08-04 19:08:00 . 2010-08-04 19:08:00 -------- d-----w- C:\WINDOWS\E4D153288C89484BB9AAF5BE9EA6D01C.TMP
2010-08-03 21:37:43 . 2010-08-04 19:03:06 -------- d-----w- C:\Program Files\HD Tune Pro
2010-08-01 01:52:02 . 2010-08-01 01:52:02 -------- d-----w- C:\Program Files\OO Software
2010-07-30 13:42:25 . 2010-07-30 13:47:55 -------- d-----w- C:\Program Files\Supreme Commander 2
2010-07-29 21:20:23 . 2010-07-09 11:18:54 20328 ----a-w- C:\WINDOWS\system32\drivers\cpuz134_x32.sys
2010-07-29 18:53:20 . 2009-12-22 00:26:36 30392 ----a-w- C:\WINDOWS\system32\drivers\usbfilter.sys
2010-07-29 16:41:07 . 2007-04-16 14:46:34 33792 ----a-w- C:\WINDOWS\system32\drivers\AmdPPM.sys
2010-07-29 16:34:25 . 2009-11-27 07:20:06 177152 ----a-r- C:\WINDOWS\system32\drivers\Rtenicxp.sys
2010-07-29 16:34:25 . 2009-05-26 11:30:42 73728 ----a-r- C:\WINDOWS\system32\RTNUninst32.dll
2010-07-29 16:34:25 . 2009-03-03 12:18:04 73728 ----a-r- C:\WINDOWS\system32\RtNicProp32.dll
2010-07-29 16:31:43 . 2010-07-29 16:31:43 -------- d-----w- C:\Program Files\Marvell
2010-07-28 15:42:29 . 2008-04-13 22:06:40 8832 -c--a-w- C:\WINDOWS\system32\dllcache\wmiacpi.sys
2010-07-28 15:42:29 . 2008-04-13 22:06:40 8832 ----a-w- C:\WINDOWS\system32\drivers\wmiacpi.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-27 07:28:23 . 2009-10-07 12:39:25 691696 ----a-w- C:\WINDOWS\system32\drivers\sptd.sys
2010-08-27 06:39:02 . 2009-12-13 19:05:47 -------- d-----w- C:\Program Files\FlashGet
2010-08-27 05:21:24 . 2010-06-24 19:15:02 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-08-27 04:41:03 . 2009-10-07 13:00:13 -------- d-----w- C:\Program Files\Winamp
2010-08-26 13:43:04 . 2009-10-09 09:48:31 218808 ----a-w- C:\WINDOWS\system32\PnkBstrB.exe
2010-08-26 12:03:43 . 2009-10-09 09:48:40 137256 ----a-w- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2010-08-26 06:50:39 . 2010-04-28 20:14:39 -------- d-----w- C:\Program Files\Steam
2010-08-25 17:16:20 . 2010-06-28 19:19:13 -------- d-----w- C:\Program Files\JDownloader
2010-08-25 15:42:34 . 2009-10-17 09:22:36 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard
2010-08-25 15:20:31 . 2009-12-03 14:47:54 -------- d-----w- C:\Program Files\Seznam.cz
2010-08-25 15:17:17 . 2010-07-21 23:26:46 -------- d-----w- C:\Program Files\2K Games
2010-08-23 04:34:10 . 2010-04-03 15:36:43 -------- d-----w- C:\Program Files\Miranda IM
2010-08-22 09:48:55 . 2009-10-23 20:39:25 -------- d-----w- C:\Program Files\TeamViewer
2010-08-19 04:55:44 . 2010-05-13 04:08:15 -------- d-----w- C:\Program Files\Toribash-3.88
2010-08-15 18:39:51 . 2010-07-18 19:49:30 -------- d-----w- C:\Program Files\Rockstar Games
2010-08-15 18:39:50 . 2009-10-07 12:28:26 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2010-08-12 19:58:19 . 2001-10-25 14:00:00 582144 ----a-w- C:\WINDOWS\system32\perfh005.dat
2010-08-12 19:58:19 . 2001-10-25 14:00:00 131136 ----a-w- C:\WINDOWS\system32\perfc005.dat
2010-08-10 01:08:34 . 2009-11-28 20:41:13 46072 ----a-w- C:\Program Files\FileUploader5.nast
2010-08-09 13:02:40 . 2009-10-08 22:37:10 -------- d-----w- C:\Program Files\Real Alternative
2010-08-09 04:55:34 . 2010-05-01 21:59:56 -------- d-----w- C:\Program Files\Orbiter
2010-08-04 19:08:53 . 2010-03-08 14:12:18 -------- d-----w- C:\Program Files\EA GAMES
2010-08-04 02:20:12 . 2009-08-14 04:27:00 5243392 ----a-w- C:\WINDOWS\system32\drivers\ati2mtag.sys
2010-08-04 01:59:10 . 2009-08-14 01:21:04 53248 ----a-w- C:\WINDOWS\system32\aticalrt.dll
2010-08-04 01:59:00 . 2009-08-14 01:20:50 53248 ----a-w- C:\WINDOWS\system32\aticalcl.dll
2010-08-04 01:57:40 . 2009-08-14 01:19:10 4358144 ----a-w- C:\WINDOWS\system32\aticaldd.dll
2010-08-04 01:53:22 . 2009-08-14 01:47:56 15900672 ----a-w- C:\WINDOWS\system32\atioglxx.dll
2010-08-04 01:47:50 . 2009-08-14 02:00:10 311296 ----a-w- C:\WINDOWS\system32\atiiiexx.dll
2010-08-04 01:47:00 . 2009-08-14 02:28:26 450560 ----a-w- C:\WINDOWS\system32\ATIDEMGX.dll
2010-08-04 01:46:04 . 2009-08-14 02:27:20 300544 ----a-w- C:\WINDOWS\system32\ati2dvag.dll
2010-08-04 01:41:40 . 2009-08-14 01:58:06 3901280 ----a-w- C:\WINDOWS\system32\ati3duag.dll
2010-08-04 01:31:16 . 2009-08-14 02:10:18 208896 ----a-w- C:\WINDOWS\system32\atipdlxx.dll
2010-08-04 01:31:04 . 2009-08-14 02:10:00 155648 ----a-w- C:\WINDOWS\system32\Oemdspif.dll
2010-08-04 01:30:56 . 2009-08-14 02:09:46 26112 ----a-w- C:\WINDOWS\system32\Ati2mdxx.exe
2010-08-04 01:30:50 . 2010-02-03 21:48:08 43520 ----a-w- C:\WINDOWS\system32\ati2edxx.dll
2010-08-04 01:30:38 . 2009-08-14 02:09:22 159744 ----a-w- C:\WINDOWS\system32\ati2evxx.dll
2010-08-04 01:29:26 . 2010-02-03 21:48:08 606208 ----a-w- C:\WINDOWS\system32\ati2evxx.exe
2010-08-04 01:28:12 . 2009-08-14 02:06:30 53248 ----a-w- C:\WINDOWS\system32\ATIDDC.DLL
2010-08-04 01:28:06 . 2009-08-14 01:42:42 2537728 ----a-w- C:\WINDOWS\system32\ativvaxx.dll
2010-08-04 01:27:38 . 2010-07-17 19:31:15 887724 ----a-w- C:\WINDOWS\system32\ativva6x.dat
2010-08-04 01:27:38 . 2010-07-17 19:31:15 3 ----a-w- C:\WINDOWS\system32\ativva5x.dat
2010-08-04 01:27:20 . 2010-02-24 19:31:37 143360 ----a-w- C:\WINDOWS\system32\atiapfxx.exe
2010-08-04 01:24:04 . 2009-08-14 01:21:18 610304 ----a-w- C:\WINDOWS\system32\atikvmag.dll
2010-08-04 01:23:52 . 2009-08-14 01:17:02 393216 ----a-w- C:\WINDOWS\system32\atiok3x2.dll
2010-08-04 01:22:28 . 2009-08-14 01:19:06 188416 ----a-w- C:\WINDOWS\system32\atiadlxx.dll
2010-08-04 01:22:08 . 2009-08-14 01:18:42 17408 ----a-w- C:\WINDOWS\system32\atitvo32.dll
2010-08-04 01:16:50 . 2009-08-14 01:12:18 700416 ----a-w- C:\WINDOWS\system32\ati2cqag.dll
2010-08-04 01:15:20 . 2009-08-14 01:25:46 65024 ----a-w- C:\WINDOWS\system32\atimpc32.dll
2010-08-04 01:15:20 . 2009-08-14 01:25:46 65024 ----a-w- C:\WINDOWS\system32\amdpcom32.dll
2010-08-04 01:14:38 . 2009-08-14 01:17:58 53248 ----a-w- C:\WINDOWS\system32\drivers\ati2erec.dll
2010-08-02 16:09:23 . 2010-02-22 16:11:14 -------- d-----w- C:\Program Files\GRETECH
2010-07-31 09:11:34 . 2010-07-17 11:07:20 -------- d-----w- C:\Program Files\Bethesda Softworks
2010-07-30 14:52:21 . 2009-10-07 18:10:59 -------- d-----w- C:\Program Files\Electronic Arts
2010-07-30 10:26:37 . 2010-03-01 13:38:04 -------- d-----w- C:\Program Files\Karen's Power Tools
2010-07-30 10:04:38 . 2010-03-21 18:22:08 -------- d-----w- C:\Program Files\ATI
2010-07-30 10:04:13 . 2009-10-07 12:31:03 -------- d-----w- C:\Program Files\ATI Technologies
2010-07-30 10:01:12 . 2010-01-22 11:53:35 -------- d-----w- C:\Program Files\SpeedFan
2010-07-30 07:37:45 . 2010-04-23 00:25:24 -------- d-----w- C:\Program Files\Xfire
2010-07-29 21:38:10 . 2009-10-07 12:28:26 -------- d-----w- C:\Program Files\AMD
2010-07-29 20:55:50 . 2010-02-25 15:04:29 1324 ----a-w- C:\WINDOWS\system32\d3d9caps.dat
2010-07-29 20:55:48 . 2010-03-21 18:16:57 1100 ----a-w- C:\WINDOWS\system32\d3d8caps.dat
2010-07-29 16:34:17 . 2009-10-07 13:10:21 -------- d-----w- C:\Program Files\Realtek
2010-07-26 03:56:48 . 2010-03-12 02:16:54 230736 ----a-w- C:\WINDOWS\system32\drivers\truecrypt.sys
2010-07-25 10:06:28 . 2010-07-25 04:41:37 -------- d-----w- C:\Program Files\BOINC
2010-07-21 23:34:58 . 2010-07-21 23:34:57 -------- d-----w- C:\Program Files\DIFX
2010-07-20 22:42:04 . 2010-07-20 22:42:04 -------- d-----w- C:\Program Files\GSC World Publishing
2010-07-20 08:46:41 . 2010-07-20 05:39:37 2337865 ----a-w- C:\WINDOWS\system32\pbsvc.exe
2010-07-20 05:31:33 . 2009-10-25 22:43:50 -------- d-----w- C:\Program Files\UBISOFT
2010-07-18 04:08:58 . 2010-07-18 04:08:58 107888 ----a-w- C:\WINDOWS\system32\CmdLineExt.dll
2010-07-17 19:28:15 . 2010-07-17 19:28:15 -------- d-----w- C:\Program Files\TNod User & Password Finder
2010-07-17 19:18:59 . 2010-02-22 17:10:30 -------- d-----w- C:\Program Files\K-Lite Codec Pack
2010-07-16 14:31:03 . 2010-07-13 14:30:13 61144431 ----a-w- C:\Program Files\Miranda IM.rar
2010-07-14 08:00:00 . 2010-07-17 19:19:01 108032 ----a-w- C:\WINDOWS\system32\ff_vfw.dll
2010-07-11 20:29:10 . 2009-10-08 19:11:05 -------- d-----w- C:\Program Files\Last.fm
2010-07-09 19:04:40 . 2010-07-09 19:04:40 41872 ----a-w- C:\WINDOWS\system32\xfcodec.dll
2010-07-06 16:27:06 . 2009-10-07 13:10:23 84584 ----a-w- C:\WINDOWS\SOUNDMAN.EXE
2010-07-06 16:27:06 . 2009-10-07 13:10:23 359016 ----a-w- C:\WINDOWS\vncutil.exe
2010-07-06 16:27:00 . 2009-10-07 13:10:23 1833576 ----a-w- C:\WINDOWS\SkyTel.exe
2010-07-06 16:27:00 . 2009-10-07 13:10:23 1489512 ----a-w- C:\WINDOWS\RtlUpd.exe
2010-07-06 16:26:54 . 2009-10-07 13:10:23 9721960 ----a-w- C:\WINDOWS\RTLCPL.EXE
2010-07-06 16:26:54 . 2009-10-07 13:10:23 6088296 ----a-w- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2010-07-06 16:26:48 . 2009-10-07 13:10:23 53864 ----a-w- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-07-06 16:26:48 . 2009-10-07 13:10:22 129640 ----a-w- C:\WINDOWS\RtkAudioService.exe
2010-07-06 16:26:42 . 2009-10-07 13:10:22 19556968 ----a-w- C:\WINDOWS\RTHDCPL.EXE
2010-07-06 16:26:36 . 2009-10-07 13:10:22 2180712 ----a-w- C:\WINDOWS\MicCal.exe
2010-07-06 16:26:36 . 2009-10-07 13:10:21 2815592 ----a-w- C:\WINDOWS\ALCWZRD.EXE
2010-07-06 16:26:30 . 2009-10-07 13:10:21 64104 ----a-w- C:\WINDOWS\ALCMTR.EXE
2010-07-05 19:20:21 . 2010-07-05 19:20:21 56 ---ha-w- C:\WINDOWS\system32\ezsidmv.dat
2010-07-05 13:01:15 . 2009-12-04 13:19:40 -------- d-----w- C:\Program Files\Unlocker
2010-07-01 21:44:11 . 2009-12-22 19:22:22 -------- d-----w- C:\Program Files\Im Gonna Serve You 4
2010-07-01 11:26:58 . 2010-07-01 11:26:58 828160 ----a-w- C:\WINDOWS\boinc.scr
2010-06-30 12:33:04 . 2008-04-14 06:51:56 149504 ----a-w- C:\WINDOWS\system32\schannel.dll
2010-06-30 07:07:36 . 2010-06-30 07:06:43 -------- d-----w- C:\Program Files\DFX
2010-06-24 12:27:28 . 2008-04-14 06:52:06 916480 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-06-24 09:13:10 . 2009-10-07 13:09:59 1251944 ----a-w- C:\WINDOWS\RtlExUpd.dll
2010-06-24 09:02:48 . 2008-04-14 05:45:36 1851904 ----a-w- C:\WINDOWS\system32\win32k.sys
2010-06-22 10:11:36 . 2010-06-22 09:45:19 201088 ----a-w- C:\Program Files\FileUploader553.nast
2010-06-22 09:56:50 . 2010-06-22 09:56:50 247 ----a-w- C:\Program Files\FileUploader553.log
2010-06-22 09:42:31 . 2010-06-22 09:42:12 1009152 ----a-w- C:\Program Files\FileUploader553.exe
2010-06-21 15:27:11 . 2008-04-13 22:45:12 354304 ----a-w- C:\WINDOWS\system32\drivers\srv.sys
2009-10-19 16:59:44 . 2010-05-25 23:08:15 47104 ----a-w- C:\Program Files\mozilla firefox\components\FFComm.dll
.

------- Sigcheck -------

[7] 2008-06-20 11:59:02 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51:12 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WhatPulse"="C:\Program Files\WhatPulse\WhatPulse.exe" [2009-04-08 20:51:34 2814976]
"Seznam Postak"="C:\Program Files\Seznam.cz\postak.exe" [2010-05-19 09:02:02 462104]
"WindowBlinds"="C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBInstall32.exe" [2007-09-12 16:58:26 99752]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 09:16:20 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-05-27 10:34:34 98304]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2010-04-07 19:07:04 2145000]
"RTHDCPL"="RTHDCPL.EXE" [2010-07-06 16:26:42 19556968]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 08:06:38 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 06:52:18 15360]

C:\Documents and Settings\jaCUBE\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ST6UNST Uninstaller.LNK - C:\WINDOWS\ST6UNST.EXE [2010-6-19 73216]

C:\Documents and Settings\jaCUBE\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ST6UNST Uninstaller.LNK - C:\WINDOWS\ST6UNST.EXE [2010-6-19 73216]

C:\Documents and Settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
PC Atomic Sync.lnk - C:\Program Files\BrigSoft\BSAtomic\BSAtomic.exe [2009-10-12 905216]

C:\Documents and Settings\jaCUBE\Nabˇdka Start\Programy\Po spuçtŘnˇ\
ST6UNST Uninstaller.LNK - C:\WINDOWS\ST6UNST.EXE [2010-6-19 73216]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2010-01-22 16:09:53 184320 ----a-w- C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\wbsys.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"OEXPRESS"=C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"AtiTrayTools"="C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
"Steam"="c:\program files\steam\steam.exe" -silent
"Fraps"=C:\PROGRAM FILES\FRAPS\FRAPS.EXE
"RGSC"=C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"Flashget"=C:\Program Files\FlashGet\flashget.exe /min
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
"ATICustomerCare"="C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"LogMeIn Hamachi Ui"="C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"boinctray"="C:\Program Files\BOINC\boinctray.exe"
"boincmgr"="C:\Program Files\BOINC\boincmgr.exe" /a /s
"OODefragTray"=C:\WINDOWS\system32\oodtray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"C:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"C:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"$INSTDIR\\FlvDetector.exe"= C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlvDetector.exe
"C:\\Program Files\\Codemasters\\DiRT2\\dirt2_game.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Updater.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"C:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\UBISOFT\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"C:\\Program Files\\UBISOFT\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"C:\\Program Files\\UBISOFT\\Assassin's Creed II\\AssassinsCreedII.exe"=
"C:\\Program Files\\UBISOFT\\Assassin's Creed II\\UPlayBrowser.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield Bad Company 2\\BFBC2Game.exe"=
"C:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"C:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"C:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"C:\\Program Files\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"C:\\Program Files\\UBISOFT\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"C:\\Program Files\\GSC World Publishing\\S.T.A.L.K.E.R. - Call of Pripyat\\bin\\xrEngine.exe"=
"C:\\Program Files\\GSC World Publishing\\S.T.A.L.K.E.R. - Call of Pripyat\\bin\\dedicated\\xrEngine.exe"=
"D:\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"C:\\Program Files\\EA GAMES\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"C:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 atitray;atitray;C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [25.11.2009 14:11:20 19232]
R1 ehdrv;ehdrv;C:\WINDOWS\system32\drivers\ehdrv.sys [7.4.2010 21:07:08 114984]
R2 AODService;AODService;C:\Program Files\AMD\OverDrive\AODAssist.exe [23.4.2010 5:39:00 136616]
R2 Apache2.2;Apache2.2;C:\AppServ\Apache2.2\bin\httpd.exe [17.1.2008 19:37:26 24635]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\ekrn.exe [7.4.2010 21:07:24 810120]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 11:16:12 1107336]
R3 AODDriver2;AODDriver2;C:\Program Files\AMD\OverDrive\i386\AODDriver2.sys [23.4.2010 5:33:12 36864]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16:28 130384]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [24.10.2009 20:10:38 133104]
S3 Ambfilt;Ambfilt;C:\WINDOWS\system32\drivers\Ambfilt.sys [7.10.2009 15:10:21 1691480]
S3 cpuz130;cpuz130;\??\C:\DOCUME~1\STANDA~1.JAC\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> C:\DOCUME~1\STANDA~1.JAC\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 DAUpdaterSvc;Dragon Age: Prameny - aktualizace obsahu;C:\Program Files\Dragon Age\bin_ship\daupdatersvc.service.exe [15.12.2009 22:07:16 25832]
S3 DualCoreCenter;DualCoreCenter;\??\C:\Program Files\MSI\OverclockingCenter\NTGLM7X.sys --> C:\Program Files\MSI\OverclockingCenter\NTGLM7X.sys [?]
S3 mamotou;mamotou;C:\WINDOWS\system32\drivers\mamotou.sys [11.12.2009 3:08:59 49377]
S3 RushTopDevice_J;RushTopDevice_J;\??\C:\Program Files\MSI\OverclockingCenter\RushJ.sys --> C:\Program Files\MSI\OverclockingCenter\RushJ.sys [?]
S3 RushTopDevice2;RushTopDevice2;\??\C:\Program Files\MSI\OverclockingCenter\RushTop.sys --> C:\Program Files\MSI\OverclockingCenter\RushTop.sys [?]
S3 SBRE;SBRE;\??\C:\WINDOWS\system32\drivers\SBREdrv.sys --> C:\WINDOWS\system32\drivers\SBREdrv.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\F:\NTGLM7X.sys --> F:\NTGLM7X.sys [?]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\WINDOWS\system32\drivers\teamviewervpn.sys [25.1.2008 11:12:34 25088]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14.10.2009 8:24:44 10064]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16:28 753504]
S4 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [7.10.2009 14:39:25 691696]
S4 TuneUp.UtilitiesSvc;TuneUp Utilities Service;C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17.11.2009 11:15:36 1021256]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPService REG_MULTI_SZ HPSLPSVC
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'

2010-08-27 C:\WINDOWS\Tasks\Automatic troubleshooting.job
- C:\Program Files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-11-17 09:20:56 . 2009-11-17 09:20:56]

2010-08-27 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-24 18:10:38 . 2009-10-24 18:10:37]

2010-08-27 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2009-10-24 18:10:38 . 2009-10-24 18:10:37]
.

Uživatelský avatar
Tempest
VIP
VIP
Příspěvky: 193
Registrován: 05 čer 2005 08:18

Re: Náhodné popupy v Mozilla Firefox

#4 Příspěvek od Tempest »

Ano, byl to TDL3 rootkit.
OK, nezapomeň ale, že ComboFix je program vytvořený pro rádce, ne pro uživatele. Pokud použiješ ComboFix sám od sebe, ztratíš nárok na podporu.

Používáš Aviru firewall? Pokud ne, spusť Poznámkový blok přes Start - Programy - Příslušenství a zkopíruj do něj celý tento text:

Kód: Vybrat vše

SecCenter::
{11638345-E4FC-4BEE-BB73-EC754659C5F6}
Zvol možnost Uložit soubor jako, pojmenuj soubor CFScript.txt a zvol Uložit jako typ Všechny soubory. Ulož soubor na plochu.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
  • Obrázek
Automaticky se spustí ComboFix a provede skriptem zadaný úkon.

Až budeš s ComboFixem hotov, jdi přes Start - Spustit a do volného řádku zkopíruj tento příkaz a potvrď: ComboFix /Uninstall - tohle ho odinstaluje.

Pěkný den i tobě :)

Odpovědět