Stránka 1 z 1

každý den nalezne AVG nově napadané soubory virem

Napsal: 15 zář 2010 09:44
od Honsiik
Dobrý den,
prosím o pomoc s odstraněním viru v PC , už s tím bojuji asi 2 týdny.
Děkuji

Re: každý den nalezne AVG nově napadané soubory virem

Napsal: 15 zář 2010 14:36
od motji
Hezké odpoledne :)
Poprosím Vás o log ze Rsitu s názvem log.txt, viz můj podpis:)

Re: každý den nalezne AVG nově napadané soubory virem

Napsal: 16 zář 2010 10:27
od Honsiik
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-09-16 11:22:40
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (14%) free of 38 GB
Total RAM: 1527 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:22:58, on 16.9.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Vivotek\ST3402\Launcher_VV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Documents and Settings\Administrator\Data aplikací\csrss.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\ChateauXP\apache\apache.exe
C:\Documents and Settings\Administrator\Šablony\Windows_Dns_redirect.exe
C:\Documents and Settings\Administrator\Data aplikací\Microsoft\svhost.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\ChateauXP\apache\apache.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Vivotek\Installation Wizard\InstallationWizard.exe
C:\PROGRA~1\MICROS~2\Office12\OUTLOOK.EXE
C:\Program Files\Miranda IM\miranda32.exe
C:\Program Files\Vivotek\Installation Wizard\InstallationWizard.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Y0A32BVO\RSIT[1].exe
C:\Program Files\trend micro\Administrator.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe,C:\Documents and Settings\Administrator\Local Settings\Temp\svchost.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSCRM] "C:\Program Files\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe" /uninstallpst /uninstallabp /deactivateaddin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [ChtSvr] C:\Program Files\ChateauXP\ChtSvr.exe
O4 - HKLM\..\Run: [HKLM] C:\WINDOWS\update2\updater.exe
O4 - HKLM\..\Run: [rbrp8g5WyHUssLZlJ] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LKL5O.exe
O4 - HKLM\..\Run: [MSDOSUpdate] C:\%WINDIR%\Microsoft.com
O4 - HKLM\..\Run: [csrss] C:\Documents and Settings\Administrator\Data aplikací\csrss.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [ChateauXP] C:\Program Files\ChateauXP\ChateauXP.exe
O4 - HKCU\..\Run: [HKCU] C:\WINDOWS\update2\updater.exe
O4 - HKCU\..\Run: [Sun Java] C:\Documents and Settings\Administrator\Local Settings\Temp\javaupdate.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [FRjgO0lRRc7xW1jk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LKL5O.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Microsoft Configuration] C:\Documents and Settings\Administrator\Local Settings\Temp\msconfig.exe
O4 - HKCU\..\Run: [msnupdate] C:\Documents and Settings\Administrator\Šablony\Windows_Dns_redirect.exe
O4 - HKCU\..\Run: [systemupdate] C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Windows_Dns_redirect.exe
O4 - HKCU\..\Run: [Adobeupdate] C:\Documents and Settings\Administrator\Šablony\svhost.exe
O4 - HKCU\..\Run: [csrss] C:\Documents and Settings\Administrator\Data aplikací\csrss.exe
O4 - HKLM\..\Policies\Explorer\Run: [KFC8F] C:\WINDOWS\update2\updater.exe
O4 - HKLM\..\Policies\Explorer\Run: [csrss] C:\Documents and Settings\Administrator\Data aplikací\csrss.exe
O4 - HKCU\..\Policies\Explorer\Run: [KFC8F] C:\WINDOWS\update2\updater.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} (System Requirements Lab) - http://intel-drv-cdn.systemrequirements ... b_srlx.cab
O16 - DPF: {2F0D96B4-7D9D-4767-A657-F7ECC9114887} (EDIMAX IPCamPluginDMPT Control) - http://90.177.110.208:8888/IPCamPluginDMPT.cab
O16 - DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} (RtspVaPgCtrl Class) - http://169.254.105.236/RtspVaPgDec.cab
O16 - DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} (Active602XMLFiller Control) - https://www.czebox.cz/static/install/ca ... ctivex.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 3396472546
O16 - DPF: {7B40618E-CC3D-4E7C-800A-E0306DD8BD48} (AMCCtrl Class) - http://192.168.2.15/AVC_AX_757.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {8214B72E-B0CD-466E-A44D-1D54D926038D} (CV781Object Object) - http://82.99.178.12:8877/AVC_AX_724.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/ ... erCtrl.cab
O16 - DPF: {9B479D7B-916A-45B0-B042-D42865A60E21} (DvrOcx Control) - http://192.168.90.77/DvrOcx.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {D67DB088-70B4-4006-B052-57F614FD3AA8} (ChtIEx Control) - http://www.vguard.net/myasp/chtIEx.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E62D1A95-8299-4B94-85D0-731DC125A60D} (IMMP4Control Control) - http://192.168.1.126/ocx/IMMP4.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sekuras.local
O17 - HKLM\Software\..\Telephony: DomainName = sekuras.local
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SQLSenet - Unknown owner - c:\PROGRA~1\Senet\SQLSenet\bin\mysqld-nt.exe (file missing)
O23 - Service: Vivotek ST3402 Launcher (Vivotek_ST3402) - Vivotek Inc. - C:\Program Files\Vivotek\ST3402\Launcher_VV.exe

--
End of file - 13284 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-573735546-1801674531-500Core.job
C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-573735546-1801674531-500UA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-21 1619296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-10 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-06-10 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\SMTray.exe [2003-07-30 143360]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2007-01-13 131072]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2007-01-13 163840]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2007-01-13 135168]
"MSCRM"=C:\Program Files\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe [2007-12-07 62488]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-11-11 417792]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-07-18 2065760]
"NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2007-03-01 153136]
"NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2007-09-20 1836328]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
"openvpn-gui"=C:\Program Files\OpenVPN\bin\openvpn-gui.exe [2005-08-18 99328]
"ChtSvr"=C:\Program Files\ChateauXP\ChtSvr.exe [2008-08-01 98304]
"HKLM"=C:\WINDOWS\update2\updater.exe [2005-05-27 69632]
"rbrp8g5WyHUssLZlJ"=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LKL5O.exe []
"IP surveillance"= []
"MSDOSUpdate"=C:\C:\WINDOWS\Microsoft.com []
"csrss"=C:\Documents and Settings\Administrator\Data aplikací\csrss.exe [2010-09-14 512000]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"KFC8F"=C:\WINDOWS\update2\updater.exe [2005-05-27 69632]
"csrss"=C:\Documents and Settings\Administrator\Data aplikací\csrss.exe [2010-09-14 512000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe [2007-09-20 202024]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]
"ChateauXP"=C:\Program Files\ChateauXP\ChateauXP.exe [2009-05-21 2584576]
"HKCU"=C:\WINDOWS\update2\updater.exe [2005-05-27 69632]
"Sun Java"=C:\Documents and Settings\Administrator\Local Settings\Temp\javaupdate.exe [2010-09-09 655049]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-09-15 2424560]
"FRjgO0lRRc7xW1jk"=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\LKL5O.exe []
"Google Update"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe [2010-09-02 136176]
"Microsoft Configuration"=C:\Documents and Settings\Administrator\Local Settings\Temp\msconfig.exe []
"msnupdate"=C:\Documents and Settings\Administrator\Šablony\Windows_Dns_redirect.exe [2010-09-07 159744]
"systemupdate"=C:\Documents and Settings\Administrator\Data aplikací\Microsoft\Windows_Dns_redirect.exe [2010-09-07 159744]
"Adobeupdate"=C:\Documents and Settings\Administrator\Šablony\svhost.exe [2010-09-08 160768]
"csrss"=C:\Documents and Settings\Administrator\Data aplikací\csrss.exe [2010-09-14 512000]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"KFC8F"=C:\WINDOWS\update2\updater.exe [2005-05-27 69632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-05-13 26192168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-07-18 12536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2007-01-13 204800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NOFOLDEROPTIONS"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoFolderOptions"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\VideoViewer\VideoViewer.exe"="C:\Program Files\VideoViewer\VideoViewer.exe:*:Enabled:VideoViewer"
"C:\Program Files\Video Server E\Video Server E.exe"="C:\Program Files\Video Server E\Video Server E.exe:*:Enabled:Video Server E"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Documents and Settings\Administrator\Local Settings\Temp\Rar$EX00.484\StrongDC.exe"="C:\Documents and Settings\Administrator\Local Settings\Temp\Rar$EX00.484\StrongDC.exe:*:Enabled:StrongDC++"
"C:\swsetup\sdc230\StrongDC.exe"="C:\swsetup\sdc230\StrongDC.exe:*:Enabled:StrongDC++"
"D:\IPSearcher\IPSearcher.exe"="D:\IPSearcher\IPSearcher.exe:*:Enabled:IPSearcher"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\ChateauXP\ChtSvr.exe"="C:\Program Files\ChateauXP\ChtSvr.exe:*:Disabled:Chateau Server"
"C:\Program Files\ChateauXP\Apache\Apache.exe"="C:\Program Files\ChateauXP\Apache\Apache.exe:*:Disabled:Apache"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Miranda IM\miranda32.exe"="C:\Program Files\Miranda IM\miranda32.exe:*:Enabled:Miranda IM"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\swsetup\sdc230\StrongDC.exe"="C:\swsetup\sdc230\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Program Files\VideoViewer\VideoViewer.exe"="C:\Program Files\VideoViewer\VideoViewer.exe:*:Enabled:VideoViewer"
"C:\Program Files\Video Server E\Video Server E.exe"="C:\Program Files\Video Server E\Video Server E.exe:*:Enabled:Video Server E"
"D:\IPSearcher\IPSearcher.exe"="D:\IPSearcher\IPSearcher.exe:*:Enabled:IPSearcher"
"C:\Program Files\MultiWindow\MultiWindow.exe"="C:\Program Files\MultiWindow\MultiWindow.exe:*:Enabled:IP Camera Player"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\MultiWindow\PlayBackServer.exe"="C:\Program Files\MultiWindow\PlayBackServer.exe:*:Enabled:IP Camera Server"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Microsoft Dynamics NAV\CSIDE Client\AtDebug.exe"="C:\Program Files\Microsoft Dynamics NAV\CSIDE Client\AtDebug.exe:*:Enabled:Microsoft Dynamics NAV Debugger"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\ChateauXP\ChateauXPServer.exe"="C:\Program Files\ChateauXP\ChateauXPServer.exe:*:Enabled:ChateauXPServer"
"C:\Program Files\OpenVPN Technologies\OpenVPN Client\prism\openvpn-client.exe"="C:\Program Files\OpenVPN Technologies\OpenVPN Client\prism\openvpn-client.exe:*:Enabled:OpenVPN Client"
"C:\Program Files\ChateauXP\ChateauXP.exe"="C:\Program Files\ChateauXP\ChateauXP.exe:*:Enabled:Win32 Application"
"C:\Program Files\ChateauXP\ChtSvr.exe"="C:\Program Files\ChateauXP\ChtSvr.exe:*:Enabled:Chateau Server"
"C:\Program Files\ChateauXP\Apache\Apache.exe"="C:\Program Files\ChateauXP\Apache\Apache.exe:*:Enabled:Apache"
"C:\Program Files\Vivotek\Installation Wizard\InstallationWizard.exe"="C:\Program Files\Vivotek\Installation Wizard\InstallationWizard.exe:*:Enabled:Installation Wizard"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

======List of files/folders created in the last 1 months======

2010-09-16 11:22:41 ----D---- C:\Program Files\trend micro
2010-09-16 11:22:40 ----D---- C:\rsit
2010-09-15 13:33:00 ----D---- C:\WINDOWS\LastGood
2010-09-14 15:05:10 ----A---- C:\Documents and Settings\Administrator\Data aplikací\csrss.exe
2010-09-02 15:10:09 ----D---- C:\%APPDATA%
2010-09-01 11:49:17 ----D---- C:\STLog
2010-09-01 11:49:17 ----D---- C:\log
2010-09-01 11:48:59 ----D---- C:\VrmssDB_V
2010-09-01 11:48:01 ----D---- C:\Program Files\Vivotek
2010-09-01 09:39:11 ----N---- C:\iTunesUpdater.com
2010-08-25 13:58:42 ----D---- C:\%WINDIR%
2010-08-25 11:37:47 ----D---- C:\Explorer
2010-08-25 10:18:58 ----D---- C:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-08-25 10:18:58 ----D---- C:\Documents and Settings\Administrator\Data aplikací\SUPERAntiSpyware.com
2010-08-25 10:18:35 ----D---- C:\Program Files\SUPERAntiSpyware
2010-08-25 09:22:07 ----A---- C:\WINDOWS\system32\logg.txt
2010-08-25 09:22:05 ----A---- C:\WINDOWS\system32\net.vbs
2010-08-25 09:22:05 ----A---- C:\WINDOWS\system32\net.bat
2010-08-25 09:22:05 ----A---- C:\WINDOWS\system32\launch.vbs
2010-08-25 09:21:57 ----D---- C:\%PROGRAMFILES%

======List of files/folders modified in the last 1 months======

2010-09-16 11:22:53 ----D---- C:\WINDOWS\system32\drivers\etc
2010-09-16 11:22:41 ----RD---- C:\Program Files
2010-09-16 11:22:31 ----D---- C:\WINDOWS\Prefetch
2010-09-16 11:16:22 ----D---- C:\WINDOWS\Temp
2010-09-16 11:10:40 ----D---- C:\swsetup
2010-09-16 09:00:52 ----D---- C:\WINDOWS\system32\drivers\Avg
2010-09-15 23:55:38 ----D---- C:\WINDOWS\security
2010-09-15 17:57:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-15 13:33:41 ----HD---- C:\WINDOWS\inf
2010-09-15 13:33:01 ----HD---- C:\WINDOWS\$hf_mig$
2010-09-15 13:33:00 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-15 13:33:00 ----D---- C:\WINDOWS
2010-09-14 15:18:36 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Skype
2010-09-14 09:18:33 ----D---- C:\Documents and Settings\Administrator\Data aplikací\skypePM
2010-09-10 10:32:31 ----D---- C:\Database
2010-09-10 10:11:14 ----SHD---- C:\WINDOWS\CSC
2010-09-10 10:11:08 ----D---- C:\Program Files\Microsoft Silverlight
2010-09-09 03:01:30 ----SHD---- C:\WINDOWS\Installer
2010-09-08 13:20:03 ----SD---- C:\Documents and Settings\Administrator\Data aplikací\Microsoft
2010-09-06 10:27:10 ----D---- C:\Documents and Settings\Administrator\Data aplikací\AFMDir
2010-09-03 09:12:43 ----D---- C:\Documents and Settings\Administrator\Data aplikací\BitTorrent
2010-09-02 14:52:49 ----SD---- C:\WINDOWS\Tasks
2010-09-01 18:39:49 ----D---- C:\faktura
2010-09-01 16:49:09 ----A---- C:\WINDOWS\NeroDigital.ini
2010-09-01 16:07:18 ----D---- C:\WINDOWS\system32
2010-09-01 12:49:53 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-09-01 12:43:36 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-01 12:30:14 ----D---- C:\WINDOWS\system32\drivers
2010-09-01 11:47:48 ----D---- C:\WINDOWS\Downloaded Installations
2010-09-01 11:47:46 ----D---- C:\Program Files\Common Files\InstallShield
2010-08-27 08:56:13 ----D---- C:\Program Files\BitTorrent
2010-08-25 09:22:03 ----RSHD---- C:\WINDOWS\update2
2010-08-25 09:22:03 ----RD---- C:\WINDOWS\Web
2010-08-25 09:22:03 ----D---- C:\WINDOWS\WinSxS
2010-08-25 09:22:03 ----D---- C:\WINDOWS\WBEM
2010-08-25 09:22:03 ----D---- C:\WINDOWS\twain_32
2010-08-25 09:22:02 ----RD---- C:\WINDOWS\Offline Web Pages
2010-08-25 09:22:02 ----D---- C:\WINDOWS\system
2010-08-25 09:22:02 ----D---- C:\WINDOWS\Sun
2010-08-25 09:22:02 ----D---- C:\WINDOWS\srchasst
2010-08-25 09:22:02 ----D---- C:\WINDOWS\SQL9_KB970892_ENU
2010-08-25 09:22:02 ----D---- C:\WINDOWS\SoftwareDistribution
2010-08-25 09:22:02 ----D---- C:\WINDOWS\SHELLNEW
2010-08-25 09:22:02 ----D---- C:\WINDOWS\ServicePackFiles
2010-08-25 09:22:02 ----D---- C:\WINDOWS\Resources
2010-08-25 09:22:02 ----D---- C:\WINDOWS\repair
2010-08-25 09:22:02 ----D---- C:\WINDOWS\Registration
2010-08-25 09:22:02 ----D---- C:\WINDOWS\RegisteredPackages
2010-08-25 09:22:02 ----D---- C:\WINDOWS\pss
2010-08-25 09:22:02 ----D---- C:\WINDOWS\Provisioning
2010-08-25 09:22:02 ----D---- C:\WINDOWS\PeerNet
2010-08-25 09:22:02 ----D---- C:\WINDOWS\network diagnostic
2010-08-25 09:22:02 ----D---- C:\WINDOWS\mui
2010-08-25 09:22:01 ----RSD---- C:\WINDOWS\Fonts
2010-08-25 09:22:01 ----HDC---- C:\WINDOWS\ie8
2010-08-25 09:22:01 ----D---- C:\WINDOWS\msapps
2010-08-25 09:22:01 ----D---- C:\WINDOWS\msagent
2010-08-25 09:22:01 ----D---- C:\WINDOWS\l2schemas
2010-08-25 09:22:01 ----D---- C:\WINDOWS\java
2010-08-25 09:22:01 ----D---- C:\WINDOWS\ime
2010-08-25 09:22:01 ----D---- C:\WINDOWS\ie8updates
2010-08-25 09:22:01 ----D---- C:\WINDOWS\Help
2010-08-25 09:22:01 ----D---- C:\WINDOWS\ehome
2010-08-25 09:22:01 ----D---- C:\WINDOWS\Driver Cache
2010-08-25 09:22:00 ----RSD---- C:\WINDOWS\assembly
2010-08-25 09:22:00 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-25 09:22:00 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-25 09:22:00 ----D---- C:\WINDOWS\Debug
2010-08-25 09:22:00 ----D---- C:\WINDOWS\Cursors
2010-08-25 09:22:00 ----D---- C:\WINDOWS\Connection Wizard
2010-08-25 09:22:00 ----D---- C:\WINDOWS\Config
2010-08-25 09:22:00 ----D---- C:\WINDOWS\AppPatch
2010-08-25 09:22:00 ----D---- C:\WINDOWS\addins
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981793$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979309$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978695_WM9$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB976098-v2$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975467_0$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975025_0$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974571_0$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974455$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974112_0$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB973904$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB973869_0$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2010-08-25 09:21:59 ----HDC---- C:\WINDOWS\$NtUninstallKB973815_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973687$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973507_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973354_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971657_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971633_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971557_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971486_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB970238_0$
2010-08-25 09:21:58 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB969947$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB969059_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968537_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968389_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB967715_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961501_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960859_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960803_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960225_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB959426_0$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-08-25 09:21:57 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958687_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB957097_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956802_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956572_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955069_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2010-08-25 09:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952011$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952004_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB923561_0$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-08-25 09:21:55 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-08-25 09:21:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-25 09:21:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2115168$
2010-08-25 09:21:54 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-25 09:21:54 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2010-08-25 09:21:54 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-08-25 09:00:48 ----D---- C:\Documents and Settings\All Users\Data aplikací\NOS
2010-08-23 09:33:55 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-08-23 09:26:44 ----D---- C:\Program Files\Mozilla Firefox
2010-08-17 11:20:40 ----D---- C:\Program Files\ChateauCMS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2009-11-13 691696]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-07-18 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-06-03 29584]
R1 AvgTdiX;AVG Free Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-07-18 243024]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2003-10-23 100384]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-07-25 176640]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\igxpmp32.sys [2007-01-13 5672032]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-15 612416]
R3 tap0801;TAP-Win32 Adapter V8; C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S3 a8e2wqmx;a8e2wqmx; C:\WINDOWS\system32\drivers\a8e2wqmx.sys []
S3 Blfp;Broadcom Advanced Server Program Driver; C:\WINDOWS\system32\DRIVERS\baspxp32.sys [2008-06-06 98816]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-03-02 12160]
S3 tap0901;TAP-Win32 Adapter V9; C:\WINDOWS\system32\DRIVERS\tap0901.sys [2009-12-12 25984]
S3 tapoas;TAP-Win32 Adapter OAS; C:\WINDOWS\system32\DRIVERS\tapoas.sys [2010-07-11 26112]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-13 12800]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9wd;AVG Free WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-07-18 308136]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-06-10 153376]
R2 MSSQLSERVER;SQL Server (MSSQLSERVER); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-09-20 853288]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
R2 Vivotek_ST3402;Vivotek ST3402 Launcher; C:\Program Files\Vivotek\ST3402\Launcher_VV.exe [2006-09-29 430080]
R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2007-09-20 382248]
S2 SQLSenet;SQLSenet; c:\PROGRA~1\Senet\SQLSenet\bin\mysqld-nt --defaults-file=c:\PROGRA~1\Senet\SQLSenet\my.ini SQLSenet []
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-11-20 72704]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 OpenVPNService;OpenVPN Service; C:\Program Files\OpenVPN\bin\openvpnserv.exe [2006-10-01 16384]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Re: každý den nalezne AVG nově napadané soubory virem

Napsal: 16 zář 2010 13:52
od motji
:arcisit: :D krásně zavirovaný počítač, s tím se můžete prát hodně dlouho :D

:arrow: Stahněte Rkill z jednoho z odkazů, pokud by ho vir blokoval, zkuste stahnout jiný

Rkill EXE:
http://download.bleepingcomputer.com/grinler/rkill.exe

Rkill COM:
http://download.bleepingcomputer.com/grinler/rkill.com

Rkill SCR:
http://download.bleepingcomputer.com/grinler/rkill.scr

Rkill PIF:
http://download.bleepingcomputer.com/grinler/rkill.pif

-spusťte ho a nechejte pracovat. Sám se ukončí.

- :!: Ted nerestartujte počítač! :!:


arrow: Combofix stahněte takto:
- pravým myšítkem klikněte na odkaz combofixu --uložit jako.. ,a teď ho přejmenujte na Potvora.com a uložte.

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix

Re: každý den nalezne AVG nově napadané soubory virem

Napsal: 20 zář 2010 12:02
od Honsiik
ComboFix 10-09-19.03 - Administrator 20.09.2010 12:29:10.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1527.1008 [GMT 2:00]
Spuštěný z: c:\documents and settings\Administrator\Plocha\potvora.com.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\docume~1\ADMINI~1\LOCALS~1\Temp\svhost.exe
c:\documents and settings\Administrator\csrss.exe
c:\documents and settings\Administrator\logi.txt
c:\documents and settings\Administrator\logidylog.txt
C:\explorer
c:\explorer\MicrosoftUpdate.com
c:\windows\sp.htm
c:\windows\system32\launch.vbs
c:\windows\system32\logg.txt
c:\windows\system32\net.bat
c:\windows\system32\net.vbs

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-08-20 do 2010-09-20 )))))))))))))))))))))))))))))))
.

2010-09-16 15:58 . 2008-07-25 10:17 1172472 ----a-w- c:\documents and settings\Administrator\svhost.exe
2010-09-16 09:22 . 2010-09-16 09:22 -------- d-----w- c:\program files\trend micro
2010-09-16 09:22 . 2010-09-16 09:23 -------- d-----w- C:\rsit
2010-09-02 13:10 . 2010-09-10 08:37 -------- d-----w- C:\%APPDATA%
2010-09-01 14:07 . 2010-09-01 14:07 -------- d-----r- c:\documents and settings\LocalService\Oblíbené položky
2010-09-01 09:49 . 2010-09-01 10:15 -------- d-----w- C:\STLog
2010-09-01 09:49 . 2010-09-01 09:49 -------- d-----w- C:\log
2010-09-01 09:48 . 2010-09-01 10:43 -------- d-----w- C:\VrmssDB_V
2010-09-01 09:48 . 2010-09-01 10:41 -------- d-----w- c:\program files\Vivotek
2010-09-01 07:39 . 2010-08-31 17:28 663552 ------w- C:\iTunesUpdater.com
2010-08-31 02:22 . 2010-09-02 15:12 345306 ----a-w- C:\mom_naked.scr
2010-08-31 02:22 . 2010-09-02 15:12 345306 ----a-w- c:\windows\mom_naked.scr
2010-08-25 11:58 . 2010-09-10 08:37 -------- d-----w- C:\%WINDIR%
2010-08-25 08:18 . 2010-09-15 11:33 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-08-25 07:22 . 2010-08-25 07:21 345471 ----a-w- c:\windows\system32\ys.scr
2010-08-25 07:22 . 2010-08-25 07:21 345471 ----a-w- c:\windows\system\ys.scr
2010-08-25 07:21 . 2010-09-10 08:37 -------- d-----w- C:\%PROGRAMFILES%

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-10 08:11 . 2010-04-13 09:28 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-01 10:43 . 2009-11-02 11:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-01 09:47 . 2009-11-02 11:21 -------- d-----w- c:\program files\Common Files\InstallShield
2010-08-27 06:56 . 2010-06-01 08:50 -------- d-----w- c:\program files\BitTorrent
2010-08-17 09:20 . 2010-07-19 14:27 -------- d-----w- c:\program files\ChateauCMS
2010-08-12 01:15 . 2006-03-02 12:00 97294 ----a-w- c:\windows\system32\perfc005.dat
2010-08-12 01:15 . 2006-03-02 12:00 479380 ----a-w- c:\windows\system32\perfh005.dat
2010-08-11 04:40 . 2010-08-11 04:26 -------- d-----w- c:\program files\Amazing World for Pocket PC
2010-08-10 08:32 . 2009-11-18 13:35 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-08-07 18:41 . 2010-08-07 18:41 159810 ----a-w- c:\windows\Notová Osnova Uninstaller.exe
2010-08-07 18:41 . 2010-08-07 18:41 -------- d-----w- c:\program files\Notová Osnova
2010-08-04 03:53 . 2010-07-19 15:05 -------- d-----w- c:\program files\ChateauXP
2010-08-03 12:57 . 2009-12-15 13:26 -------- d-----w- c:\program files\VideoViewer
2010-07-18 13:45 . 2010-04-08 08:10 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-18 13:45 . 2009-11-20 09:18 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-18 13:45 . 2009-11-20 09:18 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-11 17:57 . 2010-07-11 17:57 26112 ----a-w- c:\windows\system32\drivers\tapoas.sys
2010-06-30 12:33 . 2006-03-02 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:27 . 2006-03-02 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2006-03-02 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2005-05-27 05:36 . 2005-05-27 05:36 69632 --sha-r- c:\windows\update2\updater.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2009-11-15 33120]
"ChateauXP"="c:\program files\ChateauXP\ChateauXP.exe" [2009-05-21 2584576]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-15 2424560]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe" [2010-09-02 136176]
"msnupdate"="c:\documents and settings\Administrator\Šablony\Windows_Dns_redirect.exe" [2010-09-07 159744]
"Adobeupdate"="c:\documents and settings\Administrator\Šablony\svhost.exe" [2010-09-08 160768]
"AdobeUpdate Client 36659"="c:\documents and settings\Administrator\Data aplikací\Adobe\Acrobat\9.0\upnYMm6Y4vqJ4g.exe" [2010-09-16 446604]
"svhost"="c:\documents and settings\Administrator\Data aplikací\svhost.exe" [2008-07-25 1172472]
"AviraUpdates"="c:\documents and settings\Administrator\Data aplikací\Microsoft\svhost.exe" [2010-09-08 160768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 143360]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"MSCRM"="c:\program files\Microsoft Dynamics CRM\Client\ConfigWizard\CrmForOutlookInstaller.exe" [2007-12-07 62488]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-18 2065760]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"ChtSvr"="c:\program files\ChateauXP\ChtSvr.exe" [2008-08-01 98304]
"svhost"="c:\documents and settings\Administrator\Data aplikací\svhost.exe" [2008-07-25 1172472]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"KFC8F"="c:\windows\update2\updater.exe" [2005-05-27 69632]
"svhost"="c:\documents and settings\Administrator\Data aplikací\svhost.exe" [2008-07-25 1172472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-18 13:45 12536 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 10:44 31072 -c--a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-05-13 14:12 26192168 ----a-r- c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Miranda IM\\miranda32.exe"=
"c:\\Program Files\\VideoViewer\\VideoViewer.exe"=
"c:\\Program Files\\Video Server E\\Video Server E.exe"=
"c:\\swsetup\\sdc230\\StrongDC.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\ChateauXP\\ChtSvr.exe"=
"c:\\Program Files\\ChateauXP\\Apache\\Apache.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [20.11.2009 11:18 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8.4.2010 10:10 243024]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [18.7.2010 15:45 308136]
R2 Vivotek_ST3402;Vivotek ST3402 Launcher;c:\program files\Vivotek\ST3402\Launcher_VV.exe [29.9.2006 13:22 430080]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [1.10.2006 14:37 26624]
S2 SQLSenet;SQLSenet;c:\progra~1\Senet\SQLSenet\bin\mysqld-nt --defaults-file=c:\progra~1\Senet\SQLSenet\my.ini SQLSenet --> c:\progra~1\Senet\SQLSenet\bin\mysqld-nt --defaults-file=c:\progra~1\Senet\SQLSenet\my.ini SQLSenet [?]
S3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\drivers\tapoas.sys [11.7.2010 19:57 26112]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13.11.2009 16:09 691696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3027QI43-652N-3LEA-0T83-W06P5WPCAX78}]
2005-05-27 05:36 69632 --sha-r- c:\windows\update2\updater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A9DF5B8C-8CDF-EA72-D5CF-AEBCE1FD92E7}]
2008-07-25 10:17 1172472 ----a-w- c:\documents and settings\Administrator\Data aplikací\svhost.exe

[HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{A9DF5B8C-8CDF-EA72-D5CF-AEBCE1FD92E7}]
2008-07-25 10:17 1172472 ----a-w- c:\documents and settings\Administrator\Data aplikací\svhost.exe
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: karpem.cz\crm2
Trusted Zone: karpem.cz\karpem.crm2
DPF: {2F0D96B4-7D9D-4767-A657-F7ECC9114887} - hxxp://90.177.110.208:8888/IPCamPluginDMPT.cab
DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} - hxxp://169.254.105.236/RtspVaPgDec.cab
DPF: {672EE252-D813-4F5E-81BB-5DD163DD4FA5} - hxxps://www.czebox.cz/static/install/cab/filleractivex.cab
DPF: {7B40618E-CC3D-4E7C-800A-E0306DD8BD48} - hxxp://192.168.2.15/AVC_AX_757.cab
DPF: {8214B72E-B0CD-466E-A44D-1D54D926038D} - hxxp://82.99.178.12:8877/AVC_AX_724.cab
DPF: {9B479D7B-916A-45B0-B042-D42865A60E21} - hxxp://192.168.90.77/DvrOcx.cab
DPF: {D67DB088-70B4-4006-B052-57F614FD3AA8} - hxxp://www.vguard.net/myasp/chtIEx.cab
DPF: {E62D1A95-8299-4B94-85D0-731DC125A60D} - hxxp://192.168.1.126/ocx/IMMP4.cab
FF - ProfilePath - c:\documents and settings\Administrator\Data aplikací\Mozilla\Firefox\Profiles\ywldyb1v.default\
FF - prefs.js: browser.startup.homepage - www.seznam.cz
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-IP surveillance - (no file)
HKLM-Run-MSDOSUpdate - c:\c:\WINDOWS\Microsoft.com
HKLM-Explorer_Run-csrss - c:\documents and settings\Administrator\Data aplikací\csrss.exe
ActiveSetup-{2162GEGR-376X-4Q4O-S2UD-QON213842B5M} - c:\c:\WINDOWS\Microsoft.com
ActiveSetup-{5D1FEAC9-5DEC-BBAB-CFED-B719BFEF5F4A} - c:\documents and settings\Administrator\Data aplikací\csrss.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-20 12:46
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SQLSenet]
"ImagePath"="c:\progra~1\Senet\SQLSenet\bin\mysqld-nt --defaults-file=c:\progra~1\Senet\SQLSenet\my.ini SQLSenet"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------

[HKEY_USERS\S-1-5-21-73586283-573735546-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,df,b3,9f,ca,63,93,d6,48,8b,b1,15,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c9,ae,b0,4d,71,8d,48,40,b2,b5,47,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,df,b3,9f,ca,63,93,d6,48,8b,b1,15,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(836)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Celkový čas: 2010-09-20 12:54:42
ComboFix-quarantined-files.txt 2010-09-20 10:54

Před spuštěním: 5 460 656 128
Po spuštění: 7 114 661 888

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 7B425312C4016E620945298D4E646C9F

Re: každý den nalezne AVG nově napadané soubory virem

Napsal: 20 zář 2010 12:40
od motji
Ještě to máte pořád krásně zavirováno :arcisit: :D , kde jste k tomuhle přišel?

:arrow: Znáte složky
C:\VrmssDB_V
C:\%APPDATA%
c:\%WINDIR%



:arrow: Dejte soubor otestovat na http://www.virustotal.com

c:\windows\update2\updater.exe
c:\program files\ChateauXP\ChtSvr.exe
c:\windows\system32\drivers\tapoas.sys
c:\windows\system32\ys.scr
c:\windows\system\ys.scr
C:\mom_naked.scr
c:\windows\mom_naked.scr

-Na virustotalu dáte procházet, a do spodního okénka nakopírujete přímo cestu k souboru a dáte odeslat
-z prohlížeče zkopírujete adresu ke stránce s výsledky
-pokud se Vás zeptá, dejte soubor otestovat znovu, tak aby to byl soubor z Vašeho počítače