Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Lubov PC - Odosielanie vyrusu cez skype

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Jozo309
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 24 úno 2008 09:40
Bydliště: Mesiac
Kontaktovat uživatele:

Lubov PC - Odosielanie vyrusu cez skype

#1 Příspěvek od Jozo309 »

Zdravím vas vedenie ...moj kamos tu hodi log..a prosim pomozte mu v tomto..je este laik a nikdy nerobil s logmy atd atd..

Popis jeho problemu ? ...skype mu odosiela link na niejaky subot na ktory ked kliknete chce aby sa to stiahlo a predpokladam ze je to niejake ruske porno...pozrite sa nato :-) Ďakujem ...

Prvy log sem vlozi ..poviem mu ako ..dalsie mu poradte vy a sry za spam :-D

Jozo309
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 24 úno 2008 09:40
Bydliště: Mesiac
Kontaktovat uživatele:

Re: Lubov PC - Odosielanie vyrusu cez skype

#2 Příspěvek od Jozo309 »

Takze tu je log :


Logfile of random's system information tool 1.08 (written by random/random)
Run by Lubo at 2010-10-05 22:57:15
Systém Microsoft Windows XP Professional Service Pack 2
System drive C: has 14 GB (69%) free of 20 GB
Total RAM: 511 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:57:23, on 5.10.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe
C:\WINDOWS\nvsvc32.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Lubo\Plocha\RSIT.exe
C:\Program Files\trend micro\Lubo.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fullarticles.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NVIDIA driver monitor] C:\WINDOWS\nvsvc32.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [NVIDIA driver monitor] C:\WINDOWS\nvsvc32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: forteManager.lnk = ?
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 7075 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055FD26D-3A88-4e15-963D-DC8493744B1D}]
XTTBPos00 Class - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 37808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQ Toolbar - C:\PROGRA~1\ICQTOO~1\toolbaru.dll [2006-12-25 701952]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-03-13 1443072]
"ATICCC"=C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2005-08-12 45056]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2003-06-09 28672]
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"Jet Detection"=C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe [2001-11-29 28672]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [2004-04-17 196608]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2007-08-31 1037736]
"DivXUpdate"=C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2010-09-01 1164584]
"VX3000"=C:\WINDOWS\vVX3000.exe [2010-05-20 762736]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2010-05-20 119152]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"NVIDIA driver monitor"=C:\WINDOWS\nvsvc32.exe [2010-09-21 59392]
"LogMeIn Hamachi Ui"=C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [2010-03-30 1820040]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-17 15360]
"Orb"=C:\Program Files\Winamp Remote\bin\OrbTray.exe [2008-04-01 507904]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"NVIDIA driver monitor"=C:\WINDOWS\nvsvc32.exe [2010-09-21 59392]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
e:\steam\steam.exe [2010-09-20 1242448]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
forteManager.lnk - C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-12-12 47104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-08-24 133120]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\ICQ6\ICQ.exe"="C:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Microsoft LifeCam\LifeCam.exe"="C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"C:\Program Files\Microsoft LifeCam\LifeEnC2.exe"="C:\Program Files\Microsoft LifeCam\LifeEnC2.exe:*:Enabled:LifeEnC2.exe"
"C:\Program Files\Microsoft LifeCam\LifeExp.exe"="C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"C:\Program Files\Microsoft LifeCam\LifeTray.exe"="C:\Program Files\Microsoft LifeCam\LifeTray.exe:*:Enabled:LifeTray.exe"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"E:\Battlefield2\BF2.exe"="E:\Battlefield2\BF2.exe:*:Enabled:Battlefield 2"
"E:\Warcraft III\Warcraft III.exe"="E:\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Documents and Settings\Lubo\Dokumenty\Stažené soubory\P12576574.JPG-www.facebook.exe"="C:\WINDOWS\nvsvc32.exe:*:Enabled:NVIDIA driver monitor"
"C:\Documents and Settings\Lubo\Data aplikací\S-2535-6853-2745\winrsvn.exe"="C:\Documents and Settings\Lubo\Data aplikací\S-2535-6853-2745\winrsvn.exe:*:Enabled:Windows Boot Control"
"E:\Steam\SteamApps\exitus203\counter-strike\hl.exe"="E:\Steam\SteamApps\exitus203\counter-strike\hl.exe:*:Enabled:Counter-Strike"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-10-05 22:49:25 ----D---- C:\Program Files\trend micro
2010-10-05 22:49:24 ----D---- C:\rsit
2010-10-05 14:15:50 ----A---- C:\WINDOWS\{00000005-00000000-00000007-00001102-00000002-80671102}.BAK
2010-10-05 10:05:50 ----D---- C:\Program Files\Common Files\Skype
2010-10-05 10:05:46 ----RD---- C:\Program Files\Skype
2010-10-05 10:00:46 ----D---- C:\WINDOWS\system32\appmgmt
2010-10-01 00:37:35 ----AH---- C:\WINDOWS\system32\hamachi.sys
2010-10-01 00:37:31 ----D---- C:\Program Files\LogMeIn Hamachi
2010-10-01 00:28:52 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Ventrilo
2010-10-01 00:27:28 ----D---- C:\Program Files\TeamSpeak 3 Client
2010-10-01 00:26:53 ----D---- C:\Program Files\Ventrilo
2010-10-01 00:26:34 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-09-29 14:47:46 ----A---- C:\d1d.exe
2010-09-28 00:26:37 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Opera
2010-09-27 11:26:54 ----AH---- C:\WINDOWS\system32\winrtsnr.txt
2010-09-27 11:26:49 ----RSHD---- C:\Documents and Settings\Lubo\Data aplikací\S-2535-6853-2745
2010-09-25 15:58:20 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2010-09-24 16:22:50 ----A---- C:\89712das094bdad.exe
2010-09-24 16:15:37 ----A---- C:\89712094bdad.exe
2010-09-24 16:13:05 ----A---- C:\WINDOWS\89712094bdad.exe
2010-09-21 23:15:17 ----A---- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2010-09-21 23:12:45 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2010-09-21 23:12:35 ----D---- C:\WINDOWS\system32\LogFiles
2010-09-21 23:12:35 ----A---- C:\WINDOWS\system32\PnkBstrA.exe
2010-09-21 13:59:52 ----RSH---- C:\WINDOWS\nvsvc32.exe
2010-09-20 23:03:19 ----D---- C:\Program Files\Common Files\Java
2010-09-20 23:02:58 ----A---- C:\WINDOWS\system32\javaws.exe
2010-09-20 23:02:58 ----A---- C:\WINDOWS\system32\javaw.exe
2010-09-20 23:02:58 ----A---- C:\WINDOWS\system32\java.exe
2010-09-20 18:26:29 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Apple Computer
2010-09-20 18:19:48 ----D---- C:\Documents and Settings\Lubo\Data aplikací\ICQ Toolbar
2010-09-20 18:19:01 ----D---- C:\Program Files\QuickTime
2010-09-20 18:18:44 ----D---- C:\Program Files\Apple Software Update
2010-09-20 18:18:37 ----D---- C:\Documents and Settings\All Users\Data aplikací\Apple Computer
2010-09-20 03:41:02 ----A---- C:\WINDOWS\system32\wmpns.dll
2010-09-20 02:57:29 ----D---- C:\Program Files\GrandBilliards
2010-09-20 01:01:02 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2010-09-20 01:01:01 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2010-09-20 00:54:11 ----D---- C:\Documents and Settings\Lubo\Data aplikací\DAEMON Tools Pro
2010-09-20 00:52:03 ----D---- C:\Program Files\CCleaner
2010-09-20 00:48:10 ----D---- C:\Documents and Settings\All Users\Data aplikací\DAEMON Tools Lite
2010-09-20 00:47:58 ----D---- C:\Program Files\DAEMON Tools Toolbar
2010-09-20 00:47:52 ----D---- C:\Program Files\DAEMON Tools Lite
2010-09-20 00:44:10 ----A---- C:\WINDOWS\system32\drivers\sptd.sys
2010-09-20 00:44:06 ----D---- C:\Documents and Settings\Lubo\Data aplikací\DAEMON Tools Lite
2010-09-19 19:53:08 ----D---- C:\WINDOWS\Sun
2010-09-19 19:52:53 ----D---- C:\Documents and Settings\All Users\Data aplikací\Sun
2010-09-19 19:52:33 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-09-19 19:52:21 ----D---- C:\Program Files\Java
2010-09-19 19:50:47 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Sun
2010-09-18 13:01:32 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2010-09-18 13:01:02 ----D---- C:\Program Files\Winamp Detect
2010-09-18 13:00:52 ----D---- C:\Documents and Settings\All Users\Data aplikací\OrbNetworks
2010-09-18 13:00:48 ----D---- C:\Program Files\Winamp Remote
2010-09-18 12:56:18 ----D---- C:\Program Files\WinRAR
2010-09-18 12:50:10 ----D---- C:\Documents and Settings\Lubo\Data aplikací\WinRAR
2010-09-18 02:41:21 ----A---- C:\WINDOWS\VX3000.ini
2010-09-18 02:41:21 ----A---- C:\WINDOWS\VX3000.dll
2010-09-18 02:41:21 ----A---- C:\WINDOWS\vVX3000.exe
2010-09-18 02:41:21 ----A---- C:\WINDOWS\vVX3000.dll
2010-09-18 02:41:21 ----A---- C:\WINDOWS\system32\LCCoin32.dll
2010-09-18 02:41:21 ----A---- C:\WINDOWS\system32\drivers\VX3000.sys
2010-09-18 02:41:21 ----A---- C:\WINDOWS\system32\cVX3000.dll
2010-09-18 02:41:05 ----D---- C:\Program Files\Microsoft LifeCam
2010-09-18 02:41:01 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2010-09-18 02:41:00 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2010-09-18 02:40:57 ----D---- C:\WINDOWS\Logs
2010-09-18 02:40:47 ----D---- C:\WINDOWS\system32\drivers\umdf
2010-09-18 02:40:38 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-09-18 02:35:00 ----N---- C:\WINDOWS\system32\spmsg2.dll
2010-09-18 02:34:57 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$
2010-09-18 02:34:46 ----D---- C:\WINDOWS\system32\cs-CZ
2010-09-18 02:33:19 ----D---- C:\WINDOWS\system32\XPSViewer
2010-09-18 02:33:16 ----D---- C:\Program Files\MSBuild
2010-09-18 02:33:15 ----D---- C:\WINDOWS\system32\en-US
2010-09-18 02:33:11 ----D---- C:\Program Files\Reference Assemblies
2010-09-18 02:32:43 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-09-18 02:32:43 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-09-18 02:32:43 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-09-18 02:30:50 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2010-09-18 02:30:48 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2010-09-18 02:22:05 ----A---- C:\WINDOWS\system32\drivers\USBAUDIO.sys
2010-09-18 02:18:09 ----D---- C:\Program Files\ICQToolbar
2010-09-18 02:17:46 ----D---- C:\Documents and Settings\Lubo\Data aplikací\ICQ
2010-09-18 02:17:20 ----D---- C:\Program Files\ICQ6
2010-09-18 02:14:58 ----D---- C:\Program Files\Winamp
2010-09-18 02:14:58 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Winamp
2010-09-18 02:10:52 ----D---- C:\Documents and Settings\Lubo\Data aplikací\DivX
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\vxblock.dll
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxwave.dll
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxsfs.dll
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxinsi64.exe
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxdrv.dll
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxcpyi64.exe
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\pxafs.dll
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\drivers\PxHelp20.sys
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\drivers\cdralw2k.sys
2010-09-18 02:10:35 ----N---- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2010-09-18 02:10:34 ----N---- C:\WINDOWS\system32\pxmas.dll
2010-09-18 02:10:34 ----N---- C:\WINDOWS\system32\px.dll
2010-09-18 02:10:11 ----D---- C:\Program Files\Common Files\DivX Shared
2010-09-18 02:04:29 ----D---- C:\Program Files\DivX
2010-09-18 02:03:28 ----D---- C:\Documents and Settings\All Users\Data aplikací\DivX
2010-09-18 01:59:39 ----D---- C:\Documents and Settings\Lubo\Data aplikací\skypePM
2010-09-18 01:58:54 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Skype
2010-09-18 01:58:40 ----D---- C:\Program Files\Google
2010-09-18 01:58:16 ----D---- C:\Documents and Settings\All Users\Data aplikací\Skype
2010-09-18 01:49:14 ----D---- C:\Program Files\Opera
2010-09-18 01:44:40 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-09-18 01:44:40 ----A---- C:\WINDOWS\system32\drivers\point32.sys
2010-09-18 01:44:17 ----D---- C:\Program Files\Microsoft IntelliPoint
2010-09-18 01:44:00 ----D---- C:\Program Files\MSXML 6.0
2010-09-18 01:43:38 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2010-09-18 01:37:38 ----D---- C:\Documents and Settings\All Users\Data aplikací\InstallShield
2010-09-18 01:37:38 ----A---- C:\WINDOWS\system32\LgExport.dll
2010-09-18 01:37:38 ----A---- C:\WINDOWS\system32\LGDispDrv.dll
2010-09-18 01:37:30 ----D---- C:\Program Files\LG Soft India
2010-09-18 01:29:43 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Creative
2010-09-18 01:26:20 ----N---- C:\WINDOWS\system32\PFMODNT.SYS
2010-09-18 01:26:06 ----D---- C:\WINDOWS\Profiles
2010-09-18 01:26:03 ----D---- C:\WINDOWS\system32\Adobe
2010-09-18 01:26:03 ----D---- C:\Program Files\Common Files\Adobe
2010-09-18 01:26:03 ----D---- C:\Program Files\Adobe
2010-09-18 01:26:03 ----D---- C:\Documents and Settings\Lubo\Data aplikací\InterTrust
2010-09-18 01:25:50 ----A---- C:\WINDOWS\IsUninst.exe
2010-09-18 01:21:25 ----N---- C:\WINDOWS\Updreg.EXE
2010-09-18 01:21:24 ----N---- C:\WINDOWS\CTRES.DLL
2010-09-18 01:21:24 ----N---- C:\WINDOWS\CTCCW.DLL
2010-09-18 01:21:24 ----N---- C:\WINDOWS\AC3API.INI
2010-09-18 01:21:23 ----N---- C:\WINDOWS\system32\SFCVRT32.DLL
2010-09-18 01:21:23 ----N---- C:\WINDOWS\system32\MFCUIA32.DLL
2010-09-18 01:21:23 ----N---- C:\WINDOWS\system32\MFCANS32.DLL
2010-09-18 01:21:23 ----N---- C:\WINDOWS\system32\CTWFLT32.DLL
2010-09-18 01:21:23 ----N---- C:\WINDOWS\system32\CTL3D.DLL
2010-09-18 01:21:19 ----D---- C:\WINDOWS\system32\Defaults
2010-09-18 01:21:08 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-09-18 01:20:46 ----D---- C:\WINDOWS\system32\Data
2010-09-18 01:20:46 ----A---- C:\WINDOWS\system32\Emu10kx.ini
2010-09-18 01:20:46 ----A---- C:\WINDOWS\system32\ctzapxx.ini
2010-09-18 01:20:46 ----A---- C:\WINDOWS\INRES.DLL
2010-09-18 01:20:42 ----A---- C:\WINDOWS\system32\drivers\HAP16V2K.SYS
2010-09-18 01:20:42 ----A---- C:\WINDOWS\system32\drivers\ha10kx2k.sys
2010-09-18 01:20:41 ----A---- C:\WINDOWS\system32\drivers\EMUPIA2K.SYS
2010-09-18 01:20:41 ----A---- C:\WINDOWS\system32\drivers\CTSFM2K.SYS
2010-09-18 01:20:41 ----A---- C:\WINDOWS\system32\drivers\CTPRXY2K.SYS
2010-09-18 01:20:41 ----A---- C:\WINDOWS\system32\drivers\ctoss2k.sys
2010-09-18 01:20:40 ----A---- C:\WINDOWS\system32\drivers\ctaud2k.sys
2010-09-18 01:20:40 ----A---- C:\WINDOWS\system32\drivers\CTAC32K.SYS
2010-09-18 01:20:39 ----A---- C:\WINDOWS\system32\SFMS32.DLL
2010-09-18 01:20:39 ----A---- C:\WINDOWS\system32\sfman32.dll
2010-09-18 01:20:39 ----A---- C:\WINDOWS\system32\REGPLIB.EXE
2010-09-18 01:20:39 ----A---- C:\WINDOWS\READREG.EXE
2010-09-18 01:20:39 ----A---- C:\WINDOWS\PSCONV.EXE
2010-09-18 01:20:39 ----A---- C:\WINDOWS\CTDCRES.DLL
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\PIAPROXY.DLL
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\OPENAL32.DLL
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\KILLAPPS.EXE
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\KILL.INI
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\ENSDEF.INI
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\ENSDEF.EXE
2010-09-18 01:20:38 ----A---- C:\WINDOWS\system32\EAXAC3.DLL
2010-09-18 01:20:38 ----A---- C:\WINDOWS\MIDIDEF.EXE
2010-09-18 01:20:38 ----A---- C:\WINDOWS\DEVREG.DLL
2010-09-18 01:20:37 ----A---- C:\WINDOWS\system32\CTSPKHLP.DLL
2010-09-18 01:20:37 ----A---- C:\WINDOWS\system32\CTSCAL.DLL
2010-09-18 01:20:37 ----A---- C:\WINDOWS\system32\CTSBLFX.DLL
2010-09-18 01:20:37 ----A---- C:\WINDOWS\system32\CTOSUSER.DLL
2010-09-18 01:20:37 ----A---- C:\WINDOWS\system32\CTHELPER.EXE
2010-09-18 01:20:37 ----A---- C:\WINDOWS\system32\CTEMUPIA.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTDPROXY.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTDCIFCE.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTDC0001.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTDC0000.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTAUDFX.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTASIO.DLL
2010-09-18 01:20:34 ----A---- C:\WINDOWS\system32\CTAGENT.DLL
2010-09-18 01:20:33 ----A---- C:\WINDOWS\system32\COMMONFX.DLL
2010-09-18 01:20:33 ----A---- C:\WINDOWS\system32\AC3API.DLL
2010-09-18 01:20:33 ----A---- C:\WINDOWS\system32\a3d.dll
2010-09-18 01:20:20 ----A---- C:\WINDOWS\SBWIN.INI
2010-09-18 01:19:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Creative
2010-09-18 01:19:05 ----A---- C:\WINDOWS\system32\CTMERes.DLL
2010-09-18 01:19:05 ----A---- C:\WINDOWS\system32\CTIntRes.dll
2010-09-18 01:19:05 ----A---- C:\WINDOWS\system32\CTDrmRes.dll
2010-09-18 01:19:04 ----D---- C:\Media
2010-09-18 01:19:03 ----N---- C:\WINDOWS\system32\Inetwh32.dll
2010-09-18 01:19:03 ----N---- C:\WINDOWS\system32\CTMedEng.dll
2010-09-18 01:19:03 ----N---- C:\WINDOWS\system32\CTDRMUI.dll
2010-09-18 01:18:58 ----A---- C:\WINDOWS\system32\CTSVCCTL.EXE
2010-09-18 01:18:58 ----A---- C:\WINDOWS\system32\CTDetres.dll
2010-09-18 01:18:57 ----A---- C:\WINDOWS\system32\CTSVCCDA.EXE
2010-09-18 01:18:40 ----A---- C:\WINDOWS\system32\AHQCpURes.dll
2010-09-18 01:17:28 ----N---- C:\WINDOWS\system32\drivers\PFMODNT.SYS
2010-09-18 01:17:28 ----D---- C:\Program Files\Creative
2010-09-18 01:11:59 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Macromedia
2010-09-18 01:11:59 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Adobe
2010-09-17 15:28:05 ----SHD---- C:\RECYCLER
2010-09-15 03:40:45 ----A---- C:\WINDOWS\system32\h323log.txt
2010-09-15 03:38:59 ----A---- C:\WINDOWS\system32\drivers\MSTEE.sys
2010-09-15 03:38:46 ----A---- C:\WINDOWS\system32\drivers\SLIP.sys
2010-09-15 03:38:45 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2010-09-15 03:38:43 ----A---- C:\WINDOWS\system32\drivers\NdisIP.sys
2010-09-15 03:38:42 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2010-09-15 03:38:41 ----A---- C:\WINDOWS\system32\drivers\NABTSFEC.sys
2010-09-15 03:38:40 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2010-09-15 03:38:39 ----A---- C:\WINDOWS\system32\drivers\CCDECODE.sys
2010-09-15 03:38:38 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2010-09-15 03:38:37 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2010-09-15 03:38:35 ----A---- C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2010-09-15 03:38:34 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2010-09-15 03:38:33 ----A---- C:\WINDOWS\system32\drivers\StreamIP.sys
2010-09-15 03:38:31 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2010-09-15 03:38:30 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010-09-15 03:38:29 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2010-09-15 03:38:27 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2010-09-15 03:38:26 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010-09-15 03:38:22 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2010-09-15 03:37:49 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2010-09-15 03:37:49 ----A---- C:\WINDOWS\system32\drivers\usbvideo.sys
2010-09-15 03:37:33 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2010-09-15 03:37:14 ----A---- C:\WINDOWS\system32\drivers\RTL8139.sys
2010-09-15 03:37:13 ----A---- C:\WINDOWS\system32\drivers\enum1394.sys
2010-09-15 03:37:07 ----A---- C:\WINDOWS\system32\drivers\ctljystk.sys
2010-09-15 03:37:04 ----A---- C:\WINDOWS\system32\drivers\gameenum.sys
2010-09-15 03:37:03 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-09-15 03:37:03 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2010-09-15 03:37:03 ----A---- C:\WINDOWS\system32\drivers\msmpu401.sys
2010-09-15 03:37:03 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2010-09-15 03:36:42 ----A---- C:\WINDOWS\system32\usbui.dll
2010-09-15 03:35:38 ----SHD---- C:\WINDOWS\Installer
2010-09-15 03:35:38 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-09-15 03:35:37 ----D---- C:\Program Files\Common Files\ODBC
2010-09-15 03:35:37 ----A---- C:\WINDOWS\ODBCINST.INI
2010-09-15 03:35:34 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-09-15 03:35:33 ----RD---- C:\Program Files
2010-09-15 03:35:33 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-09-15 03:35:33 ----D---- C:\Program Files\Common Files
2010-09-15 03:35:30 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-09-15 03:35:29 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-09-15 03:35:29 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-09-15 03:35:27 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-09-15 03:35:25 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-09-15 03:35:23 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-09-15 03:35:23 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-09-15 03:35:23 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-09-15 03:35:23 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-09-15 03:35:23 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdycl.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdsl1.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdsl.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdro.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdpl1.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdpl.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdhu1.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdhu.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\kbdcr.dll
2010-09-15 03:35:19 ----A---- C:\WINDOWS\system32\KBDAL.DLL
2010-09-15 03:35:18 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-09-15 03:35:18 ----A---- C:\WINDOWS\system32\irclass.dll
2010-09-15 03:35:18 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-09-15 03:35:18 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-09-15 03:35:18 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-09-15 03:35:16 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-09-15 03:35:15 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2010-09-15 03:35:15 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2010-09-15 03:35:15 ----A---- C:\WINDOWS\system32\batt.dll
2010-09-15 03:35:15 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-09-15 03:35:14 ----A---- C:\WINDOWS\system32\storprop.dll
2010-09-15 03:35:07 ----ASH---- C:\Documents and Settings\All Users\Data aplikací\desktop.ini
2010-09-15 03:35:04 ----RA---- C:\WINDOWS\SET8.tmp
2010-09-15 03:35:01 ----RA---- C:\WINDOWS\SET4.tmp
2010-09-15 03:35:00 ----RA---- C:\WINDOWS\SET3.tmp
2010-09-15 03:34:55 ----D---- C:\WINDOWS\system32\CatRoot2
2010-09-15 03:34:55 ----D---- C:\WINDOWS\system32\CatRoot
2010-09-15 03:34:49 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-09-15 03:34:25 ----D---- C:\Documents and Settings
2010-09-15 03:34:24 ----SHD---- C:\System Volume Information
2010-09-15 03:33:09 ----SH---- C:\boot.ini
2010-09-15 03:28:27 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-09-15 03:28:27 ----RSD---- C:\WINDOWS\Fonts
2010-09-15 03:28:27 ----RD---- C:\WINDOWS\Web
2010-09-15 03:28:27 ----HD---- C:\WINDOWS\inf
2010-09-15 03:28:27 ----D---- C:\WINDOWS\WinSxS
2010-09-15 03:28:27 ----D---- C:\WINDOWS\twain_32
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Temp
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\wins
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\wbem
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\usmt
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\spool
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\ShellExt
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\Setup
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\ras
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\oobe
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\npp
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\mui
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\inetsrv
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\IME
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\icsxml
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\ias
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\export
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\drivers\etc
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\drivers\disdn
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\drivers
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\dhcp
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\config
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\3com_dmi
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\3076
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\2052
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1054
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1042
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1041
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1037
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1033
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1031
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1029
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1028
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32\1025
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system32
2010-09-15 03:28:27 ----D---- C:\WINDOWS\system
2010-09-15 03:28:27 ----D---- C:\WINDOWS\security
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Resources
2010-09-15 03:28:27 ----D---- C:\WINDOWS\repair
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Provisioning
2010-09-15 03:28:27 ----D---- C:\WINDOWS\pchealth
2010-09-15 03:28:27 ----D---- C:\WINDOWS\PeerNet
2010-09-15 03:28:27 ----D---- C:\WINDOWS\mui
2010-09-15 03:28:27 ----D---- C:\WINDOWS\msapps
2010-09-15 03:28:27 ----D---- C:\WINDOWS\msagent
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Media
2010-09-15 03:28:27 ----D---- C:\WINDOWS\java
2010-09-15 03:28:27 ----D---- C:\WINDOWS\ime
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Help
2010-09-15 03:28:27 ----D---- C:\WINDOWS\ehome
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Driver Cache
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Debug
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Cursors
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Connection Wizard
2010-09-15 03:28:27 ----D---- C:\WINDOWS\Config
2010-09-15 03:28:27 ----D---- C:\WINDOWS\AppPatch
2010-09-15 03:28:27 ----D---- C:\WINDOWS\addins
2010-09-15 03:28:27 ----D---- C:\WINDOWS
2010-09-15 03:28:27 ----ASH---- C:\pagefile.sys
2010-09-15 02:16:53 ----D---- C:\Documents and Settings\Lubo\Data aplikací\ATI
2010-09-15 02:15:12 ----D---- C:\Program Files\My Company Name
2010-09-15 02:14:54 ----A---- C:\WINDOWS\system32\drivers\Bravo_n.sys
2010-09-15 02:14:54 ----A---- C:\WINDOWS\system32\drivers\atkkbnt.sys
2010-09-15 02:14:54 ----A---- C:\WINDOWS\ATKKBService.exe
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\drivers\Bravo_a.sys
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\ATKOSDMini.DLL
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\atkid.ini
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\ATKDispCPL.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\ATKDISP.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\asrussian.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\askorean.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\asjapan.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\aschs.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\asgerman.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\asfrench.dll
2010-09-15 02:14:53 ----A---- C:\WINDOWS\system32\aseng.dll
2010-09-15 02:14:52 ----A---- C:\WINDOWS\system32\ATKOSDX32.dll
2010-09-15 02:14:52 ----A---- C:\WINDOWS\system32\ATKOGL32.dll
2010-09-15 02:14:52 ----A---- C:\WINDOWS\system32\ASCHT.dll
2010-09-15 02:12:38 ----RA---- C:\WINDOWS\system32\atiiiexx.dll
2010-09-15 02:12:16 ----D---- C:\Program Files\ATI Technologies
2010-09-15 02:12:14 ----HD---- C:\Program Files\InstallShield Installation Information
2010-09-15 02:11:46 ----D---- C:\Program Files\Common Files\InstallShield
2010-09-15 02:10:42 ----RSD---- C:\WINDOWS\assembly
2010-09-15 02:10:42 ----D---- C:\WINDOWS\Microsoft.NET
2010-09-15 02:10:41 ----D---- C:\WINDOWS\system32\URTTemp
2010-09-15 02:09:54 ----RA---- C:\WINDOWS\system32\drivers\EIO.sys
2010-09-15 02:00:42 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Mozilla
2010-09-15 01:57:57 ----D---- C:\Program Files\ESET
2010-09-15 01:57:57 ----D---- C:\Documents and Settings\All Users\Data aplikací\ESET
2010-09-15 01:57:05 ----D---- C:\Program Files\Mozilla Firefox
2010-09-15 01:56:10 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2010-09-15 01:52:24 ----D---- C:\Documents and Settings\Lubo\Data aplikací\Identities
2010-09-15 01:52:23 ----HD---- C:\Program Files\Uninstall Information
2010-09-15 01:52:20 ----ASH---- C:\Documents and Settings\Lubo\Data aplikací\desktop.ini
2010-09-15 01:52:19 ----SD---- C:\Documents and Settings\Lubo\Data aplikací\Microsoft
2010-09-15 01:50:43 ----D---- C:\WINDOWS\SoftwareDistribution
2010-09-15 01:50:35 ----D---- C:\WINDOWS\Prefetch
2010-09-15 01:50:34 ----SD---- C:\WINDOWS\system32\Microsoft
2010-09-15 01:50:34 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-09-15 01:46:52 ----D---- C:\WINDOWS\system32\xircom
2010-09-15 01:46:52 ----D---- C:\Program Files\xerox
2010-09-15 01:46:52 ----D---- C:\Program Files\microsoft frontpage
2010-09-15 01:46:36 ----RASH---- C:\MSDOS.SYS
2010-09-15 01:46:36 ----RASH---- C:\IO.SYS
2010-09-15 01:46:36 ----A---- C:\WINDOWS\control.ini
2010-09-15 01:46:36 ----A---- C:\CONFIG.SYS
2010-09-15 01:46:36 ----A---- C:\AUTOEXEC.BAT
2010-09-15 01:46:18 ----A---- C:\WINDOWS\system32\mapi32.dll
2010-09-15 01:45:19 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-09-15 01:45:19 ----RD---- C:\WINDOWS\Offline Web Pages
2010-09-15 01:45:19 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2010-09-15 01:45:13 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2010-09-15 01:45:09 ----HD---- C:\Program Files\WindowsUpdate
2010-09-15 01:45:06 ----D---- C:\Program Files\Online Services
2010-09-15 01:44:52 ----D---- C:\WINDOWS\system32\DirectX
2010-09-15 01:44:32 ----A---- C:\WINDOWS\system32\atrace.dll
2010-09-15 01:44:30 ----A---- C:\WINDOWS\system32\desktop.ini
2010-09-15 01:44:30 ----A---- C:\WINDOWS\desktop.ini
2010-09-15 01:44:23 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2010-09-15 01:44:22 ----A---- C:\WINDOWS\system32\acctres.dll
2010-09-15 01:44:21 ----D---- C:\Program Files\Common Files\Services
2010-09-15 01:44:19 ----SD---- C:\WINDOWS\Tasks
2010-09-15 01:44:19 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2010-09-15 01:44:18 ----D---- C:\Program Files\Common Files\MSSoap
2010-09-15 01:44:13 ----D---- C:\WINDOWS\srchasst
2010-09-15 01:44:12 ----D---- C:\WINDOWS\system32\Macromed
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuweb.dll
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wups.dll
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wucltui.dll
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuauserv.dll
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuaueng.dll
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuauclt.exe
2010-09-15 01:44:09 ----A---- C:\WINDOWS\system32\wuapi.dll
2010-09-15 01:44:08 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2010-09-15 01:44:08 ----A---- C:\WINDOWS\system32\qmgr.dll
2010-09-15 01:44:08 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2010-09-15 01:44:08 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2010-09-15 01:44:04 ----D---- C:\Program Files\Movie Maker
2010-09-15 01:44:00 ----A---- C:\WINDOWS\system32\safrslv.dll
2010-09-15 01:44:00 ----A---- C:\WINDOWS\system32\safrdm.dll
2010-09-15 01:44:00 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2010-09-15 01:44:00 ----A---- C:\WINDOWS\system32\racpldlg.dll
2010-09-15 01:43:56 ----A---- C:\WINDOWS\system32\fltMc.exe
2010-09-15 01:43:56 ----A---- C:\WINDOWS\system32\fltlib.dll
2010-09-15 01:43:56 ----A---- C:\WINDOWS\system32\drivers\fltMgr.sys
2010-09-15 01:43:55 ----D---- C:\WINDOWS\system32\Restore
2010-09-15 01:43:55 ----A---- C:\WINDOWS\system32\srsvc.dll
2010-09-15 01:43:55 ----A---- C:\WINDOWS\system32\srrstr.dll
2010-09-15 01:43:55 ----A---- C:\WINDOWS\system32\srclient.dll
2010-09-15 01:43:55 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2010-09-15 01:43:55 ----A---- C:\WINDOWS\system32\ils.dll
2010-09-15 01:43:55 ----A---- C:\WINDOWS\system32\drivers\sr.sys
2010-09-15 01:43:54 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2010-09-15 01:43:54 ----A---- C:\WINDOWS\system32\msconf.dll
2010-09-15 01:43:54 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2010-09-15 01:43:54 ----A---- C:\WINDOWS\system32\mnmdd.dll
2010-09-15 01:43:51 ----D---- C:\Program Files\NetMeeting
2010-09-15 01:43:51 ----A---- C:\WINDOWS\system32\msoert2.dll
2010-09-15 01:43:51 ----A---- C:\WINDOWS\system32\msoeacct.dll
2010-09-15 01:43:50 ----A---- C:\WINDOWS\system32\inetres.dll
2010-09-15 01:43:50 ----A---- C:\WINDOWS\system32\inetcomm.dll
2010-09-15 01:43:48 ----D---- C:\Program Files\Outlook Express
2010-09-15 01:43:48 ----A---- C:\WINDOWS\system32\schedsvc.dll
2010-09-15 01:43:47 ----A---- C:\WINDOWS\system32\mstinit.exe
2010-09-15 01:43:47 ----A---- C:\WINDOWS\system32\mstask.dll
2010-09-15 01:43:47 ----A---- C:\WINDOWS\system32\isign32.dll
2010-09-15 01:43:47 ----A---- C:\WINDOWS\system32\inetcfg.dll
2010-09-15 01:43:47 ----A---- C:\WINDOWS\system32\icwphbk.dll
2010-09-15 01:43:47 ----A---- C:\WINDOWS\system32\icwdial.dll
2010-09-15 01:43:41 ----D---- C:\Program Files\Common Files\System
2010-09-15 01:43:40 ----D---- C:\Program Files\Internet Explorer
2010-09-15 01:43:08 ----D---- C:\Program Files\ComPlus Applications
2010-09-15 01:43:07 ----A---- C:\WINDOWS\vbaddin.ini
2010-09-15 01:43:07 ----A---- C:\WINDOWS\vb.ini
2010-09-15 01:43:03 ----D---- C:\WINDOWS\Registration
2010-09-15 01:42:57 ----D---- C:\Program Files\Windows Media Player
2010-09-15 01:42:52 ----D---- C:\Program Files\Messenger
2010-09-15 01:42:48 ----D---- C:\Program Files\MSN Gaming Zone
2010-09-15 01:42:48 ----A---- C:\WINDOWS\system32\write.exe
2010-09-15 01:42:40 ----A---- C:\WINDOWS\system32\sndvol32.exe
2010-09-15 01:42:40 ----A---- C:\WINDOWS\system32\hticons.dll
2010-09-15 01:42:40 ----A---- C:\WINDOWS\system32\avwav.dll
2010-09-15 01:42:40 ----A---- C:\WINDOWS\system32\avtapi.dll
2010-09-15 01:42:40 ----A---- C:\WINDOWS\system32\avmeter.dll
2010-09-15 01:42:39 ----A---- C:\WINDOWS\system32\winchat.exe
2010-09-15 01:42:33 ----A---- C:\WINDOWS\system32\charmap.exe
2010-09-15 01:42:33 ----A---- C:\WINDOWS\system32\getuname.dll
2010-09-15 01:42:32 ----A---- C:\WINDOWS\system32\winmine.exe
2010-09-15 01:42:32 ----A---- C:\WINDOWS\system32\sol.exe
2010-09-15 01:42:32 ----A---- C:\WINDOWS\system32\mshearts.exe
2010-09-15 01:42:32 ----A---- C:\WINDOWS\system32\calc.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\tslabels.ini
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\tskill.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\tscon.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\shadow.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\rwinsta.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\reset.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\regini.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\qwinsta.exe
2010-09-15 01:42:31 ----A---- C:\WINDOWS\system32\freecell.exe
2010-09-15 01:42:30 ----A---- C:\WINDOWS\system32\qappsrv.exe
2010-09-15 01:42:30 ----A---- C:\WINDOWS\system32\msg.exe
2010-09-15 01:42:30 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2010-09-15 01:42:30 ----A---- C:\WINDOWS\system32\logoff.exe
2010-09-15 01:42:30 ----A---- C:\WINDOWS\system32\cdmodem.dll
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\stclient.dll
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\mtxex.dll
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\mtxdm.dll
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\comrepl.dll
2010-09-15 01:42:29 ----A---- C:\WINDOWS\system32\comaddin.dll
2010-09-15 01:42:28 ----A---- C:\WINDOWS\system32\comsnap.dll
2010-09-15 01:42:24 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2010-09-15 01:42:23 ----A---- C:\WINDOWS\system32\sndrec32.exe
2010-09-15 01:42:23 ----A---- C:\WINDOWS\system32\mplay32.exe
2010-09-15 01:42:23 ----A---- C:\WINDOWS\system32\accwiz.exe
2010-09-15 01:42:22 ----D---- C:\Program Files\Windows NT
2010-09-15 01:42:22 ----A---- C:\WINDOWS\system32\mspaint.exe
2010-09-15 01:42:22 ----A---- C:\WINDOWS\system32\hypertrm.dll
2010-09-15 01:42:22 ----A---- C:\WINDOWS\system32\clipbrd.exe
2010-09-15 01:42:21 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2010-09-15 01:42:21 ----A---- C:\WINDOWS\system32\spider.exe
2010-09-15 01:42:21 ----A---- C:\WINDOWS\system32\drivers\tdtcp.sys
2010-09-15 01:42:21 ----A---- C:\WINDOWS\system32\drivers\tdpipe.sys
2010-09-15 01:42:21 ----A---- C:\WINDOWS\system32\drivers\rdpwd.sys
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\sessmgr.exe
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\remotepg.dll
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\rdshost.exe
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\rdchost.dll
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\mstscax.dll
2010-09-15 01:42:20 ----A---- C:\WINDOWS\system32\mstsc.exe
2010-09-15 01:42:19 ----D---- C:\WINDOWS\system32\MsDtc
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\termsrv.dll
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\rdpclip.exe
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\qprocess.exe
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\icaapi.dll
2010-09-15 01:42:19 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2010-09-15 01:42:18 ----A---- C:\WINDOWS\system32\xolehlp.dll
2010-09-15 01:42:18 ----A---- C:\WINDOWS\system32\mtxoci.dll
2010-09-15 01:42:18 ----A---- C:\WINDOWS\system32\msdtctm.dll
2010-09-15 01:42:18 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2010-09-15 01:42:17 ----A---- C:\WINDOWS\system32\msdtclog.dll
2010-09-15 01:42:17 ----A---- C:\WINDOWS\system32\msdtc.exe
2010-09-15 01:42:16 ----D---- C:\WINDOWS\system32\Com
2010-09-15 01:42:16 ----A---- C:\WINDOWS\system32\colbact.dll
2010-09-15 01:42:16 ----A---- C:\WINDOWS\system32\clbcatex.dll
2010-09-15 01:42:16 ----A---- C:\WINDOWS\system32\catsrvut.dll
2010-09-15 01:42:16 ----A---- C:\WINDOWS\system32\catsrvps.dll
2010-09-15 01:42:16 ----A---- C:\WINDOWS\system32\catsrv.dll
2010-09-15 01:42:15 ----A---- C:\WINDOWS\system32\comuid.dll
2010-09-15 01:42:15 ----A---- C:\WINDOWS\system32\comsvcs.dll
2010-09-15 01:42:15 ----A---- C:\WINDOWS\system32\clbcatq.dll
2010-09-15 01:42:09 ----A---- C:\WINDOWS\system32\servdeps.dll
2010-09-15 01:42:09 ----A---- C:\WINDOWS\system32\mmfutil.dll
2010-09-15 01:42:09 ----A---- C:\WINDOWS\system32\licwmi.dll
2010-09-15 01:42:09 ----A---- C:\WINDOWS\system32\cmprops.dll
2010-09-15 01:42:08 ----A---- C:\WINDOWS\system32\drivers\termdd.sys
2010-09-15 01:42:08 ----A---- C:\WINDOWS\system32\drivers\rdpdr.sys

======List of files/folders modified in the last 1 months======

2010-09-15 03:35:32 ----A---- C:\WINDOWS\system.ini
2010-09-15 01:46:36 ----A---- C:\WINDOWS\win.ini
2010-09-15 01:46:09 ----ASH---- C:\WINDOWS\fonts\desktop.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 ohci1394;Hostitelský řadič IEEE 1394 dle standardu OHCI Texas Instruments; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2004-08-03 61056]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2010-08-12 45648]
R0 sptd;sptd; C:\WINDOWS\System32\Drivers\sptd.sys [2010-09-20 721904]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-13 29704]
R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
R2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-13 40456]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 PfModNT;PfModNT; \??\C:\WINDOWS\system32\drivers\PfModNT.sys []
R3 Arp1394;Protokol 1394 ARP Client; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-17 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2005-12-12 1414656]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\System32\drivers\ctac32k.sys [2003-06-09 186068]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2003-06-09 494384]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\System32\drivers\ctprxy2k.sys [2003-06-09 6144]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\System32\drivers\ctsfm2k.sys [2003-06-09 136448]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\System32\drivers\emupia2k.sys [2003-06-09 116416]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2003-06-09 819984]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-17 61824]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2003-06-09 113840]
R3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2007-08-21 21760]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
R3 usbaudio;Ovladač zvukové karty USB (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 VX3000;VX-3000; C:\WINDOWS\system32\DRIVERS\VX3000.sys [2010-05-20 1961328]
S3 am8sxwrt;am8sxwrt; C:\WINDOWS\system32\drivers\am8sxwrt.sys []
S3 CCDECODE;Dekodér Closed Caption; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-04 17024]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\System32\drivers\ctdvda2k.sys []
S3 ctljystk;Game port pro zařízení Creative SB Live!; C:\WINDOWS\system32\DRIVERS\ctljystk.sys [2001-08-17 3712]
S3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\System32\drivers\hap16v2k.sys [2003-06-09 135696]
S3 LGDDCDevice;LGDDCDevice; \??\C:\Program Files\LG Soft India\forteManager\bin\I2CDriver.sys []
S3 LGII2CDevice;LGII2CDevice; \??\C:\Program Files\LG Soft India\forteManager\bin\PII2CDriver.sys []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-04 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-04 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-04 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-04 15360]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 usbvideo;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2004-08-04 78464]
S3 WSTCODEC;Dálnopisný kodek světového standardu; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-12-12 393216]
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2005-10-18 241152]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.exe [1999-12-13 44032]
R2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2010-03-30 1107336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2010-05-20 139632]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2010-09-21 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2010-10-05 215128]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [2000-06-26 53520]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-18 136176]
S2 NOD32FiXTemDono;Eset Nod32 Boot; C:\WINDOWS\system32\regedt32.exe [2001-10-25 3584]
S2 SSHNAS;SSHNAS; C:\WINDOWS\system32\svchost.exe [2004-08-17 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-03-13 19200]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

:worship:

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Lubov PC - Odosielanie vyrusu cez skype

#3 Příspěvek od motji »

Ahoj Jožo :D , Tys už tu taky dlouho nebyl :D
Nádherně zavirované :arcisit: :arcisit: .

Ale v prvé řadě vyhoďte ten nelegální eset :roll: . Cracklý antivir nebude zrovna to pravé ořechové, co se bezpečnosti týče :roll: .


:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

hromiii
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 05 říj 2010 21:36

Re: Lubov PC - Odosielanie vyrusu cez skype

#4 Příspěvek od hromiii »

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verze databáze: 4780

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

8.10.2010 22:49:37
mbam-log-2010-10-08 (22-49-37).txt

Typ skenu: Úplný sken (C:\|D:\|E:\|)
Skenované objekty: 188053
Uplynulý čas: 48 minuta(y), 15 sekunda(y)

Infikované procesy v paměti: 1
Infikované moduly v paměti: 0
Infikované klíče registru: 6
Infikované hodnoty registru: 2
Infikované datové položky registru: 0
Infikované složky: 1
Infikované soubory: 17

Infikované procesy v paměti:
C:\WINDOWS\nvsvc32.exe (Trojan.Agent) -> No action taken.

Infikované moduly v paměti:
(Žádné škodlivé položky nebyly zjištěny)

Infikované klíče registru:
HKEY_CURRENT_USER\SOFTWARE\3FWHZQA3LT (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SMH2B46TDP (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{055fd26d-3a88-4e15-963d-dc8493744b1d} (Trojan.BHO) -> No action taken.

Infikované hodnoty registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvidia driver monitor (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nvidia driver monitor (Trojan.Agent) -> No action taken.

Infikované datové položky registru:
(Žádné škodlivé položky nebyly zjištěny)

Infikované složky:
C:\Documents and Settings\Lubo\Data aplikací\S-2535-6853-2745 (Worm.Slenping) -> No action taken.

Infikované soubory:
C:\Documents and Settings\Lubo\Dokumenty\Stažené soubory\P12576574.JPG-www.facebook.exe (Worm.Palevo) -> No action taken.
C:\Documents and Settings\Lubo\Local Settings\Temp\19A.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Lubo\Local Settings\Temp\3FD.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Lubo\Local Settings\Temp\5BF.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Lubo\Local Settings\Temp\D0F.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Lubo\Local Settings\Temp\E262.tmp (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Lubo\Local Settings\Temp\EE6.tmp (Rootkit.TDSS) -> No action taken.
D:\bf2\bf20\generatorCDKEY\vtl-bf2k.exe (Trojan.Agent) -> No action taken.
E:\System Volume Information\_restore{2FB59FB8-45A1-4652-A9BC-80B182DA258E}\RP129\A0044461.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Lubo\Data aplikací\chrtmp (Malware.Trace) -> No action taken.
C:\h.exe (Trojan.Agent) -> No action taken.
C:\t.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\winrtsnr.txt (Malware.Trace) -> No action taken.
C:\WINDOWS\nvsvc32.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.
C:\Program Files\ICQToolbar\toolbaru.dll (Trojan.BHO) -> No action taken.

hromiii
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 05 říj 2010 21:36

Re: Lubov PC - Odosielanie vyrusu cez skype

#5 Příspěvek od hromiii »

Nazdar,,,tu mas logg,tak sa nato kukni :) dakujem

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Lubov PC - Odosielanie vyrusu cez skype

#6 Příspěvek od motji »

No nazdrar :D ,
kdes k tomu přišel?

V mbamu vše smaž a pokračujeme :) . Doufám že ten nelegal Nod už máš z pc pryč :roll: .

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

hromiii
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 05 říj 2010 21:36

Re: Lubov PC - Odosielanie vyrusu cez skype

#7 Příspěvek od hromiii »

ComboFix 10-10-07.02 - Lubo 09.10.2010 23:43:06.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.511.285 [GMT 2:00]
Spuštěný z: c:\documents and settings\Lubo\Plocha\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\winrtsnr.txt

Nakažená kopie c:\windows\system32\drivers\termdd.sys byla nalezena a vyléčena.
Obnovena kopie z - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS


((((((((((((((((((((((((( Soubory vytvořené od 2010-09-09 do 2010-10-09 )))))))))))))))))))))))))))))))
.

2010-10-08 19:46 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-08 19:46 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-08 19:46 . 2010-10-08 19:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-07 20:16 . 2010-10-07 20:16 225280 ----a-w- C:\kj32.exe
2010-10-07 19:43 . 2010-10-07 19:43 225280 --sh--r- c:\documents and settings\Lubo\Data aplikací\C-76947-8457-2745\wincdrsvn.exe
2010-10-05 20:49 . 2010-10-05 20:57 -------- d-----w- c:\program files\trend micro
2010-10-05 20:49 . 2010-10-05 20:58 -------- d-----w- C:\rsit
2010-10-05 16:32 . 2010-10-05 16:32 56765 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-10-05 16:32 . 2010-10-05 16:32 84038 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\TransferWizard\Uninstaller.exe
2010-10-05 08:05 . 2010-10-05 08:05 -------- d-----w- c:\program files\Common Files\Skype
2010-10-05 08:05 . 2010-10-05 08:05 -------- d-----r- c:\program files\Skype
2010-10-02 09:16 . 2010-10-02 09:16 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-30 22:37 . 2010-02-03 13:56 26176 ---ha-w- c:\windows\system32\hamachi.sys
2010-09-30 22:37 . 2010-09-30 22:37 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-09-30 22:27 . 2010-09-30 22:27 -------- d-----w- c:\program files\TeamSpeak 3 Client
2010-09-30 22:26 . 2010-09-30 22:28 -------- d-----w- c:\program files\Ventrilo
2010-09-30 22:26 . 2010-09-30 22:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-09-29 12:47 . 2010-09-29 12:49 39680 ----a-w- C:\d1d.exe
2010-09-25 13:58 . 2004-08-03 21:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-09-25 13:58 . 2004-08-03 21:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-09-24 14:22 . 2010-09-24 14:22 421888 ----a-w- C:\89712das094bdad.exe
2010-09-24 14:15 . 2010-09-24 14:15 52930 ----a-w- C:\89712094bdad.exe
2010-09-24 14:13 . 2010-09-24 14:41 52930 ----a-w- c:\windows\89712094bdad.exe
2010-09-21 21:15 . 2010-10-05 13:43 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-09-21 21:12 . 2010-10-05 13:40 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-09-21 21:12 . 2010-09-21 21:12 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-09-21 21:12 . 2010-09-21 21:12 -------- d-----w- c:\windows\system32\LogFiles
2010-09-20 21:03 . 2010-09-20 21:03 -------- d-----w- c:\program files\Common Files\Java
2010-09-20 16:20 . 2010-09-20 16:20 -------- d-s---w- c:\documents and settings\Lubo\UserData
2010-09-20 16:19 . 2010-09-20 16:19 -------- d-----w- c:\program files\QuickTime
2010-09-20 16:18 . 2010-09-20 16:18 -------- d-----w- c:\program files\Apple Software Update
2010-09-20 01:41 . 2004-08-17 13:49 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-09-20 00:57 . 2010-09-20 00:57 40 ----a-w- c:\windows\system32\d3d9prs.dat
2010-09-20 00:57 . 2010-09-20 00:57 -------- d-----w- c:\program files\GrandBilliards
2010-09-19 22:52 . 2010-09-19 22:52 -------- d-----w- c:\program files\CCleaner
2010-09-19 22:47 . 2010-09-19 22:47 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-09-19 22:47 . 2010-09-19 22:47 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-09-19 22:44 . 2010-09-19 22:44 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-19 22:14 . 2010-09-19 22:14 15872 ----a-r- c:\documents and settings\Lubo\Data aplikací\Microsoft\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C9.exe
2010-09-19 17:53 . 2010-09-19 17:53 -------- d-----w- c:\windows\Sun
2010-09-19 17:52 . 2010-09-19 17:52 503808 ----a-w- c:\documents and settings\Lubo\Data aplikací\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5307fc4c-n\msvcp71.dll
2010-09-19 17:52 . 2010-09-19 17:52 499712 ----a-w- c:\documents and settings\Lubo\Data aplikací\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5307fc4c-n\jmc.dll
2010-09-19 17:52 . 2010-09-19 17:52 348160 ----a-w- c:\documents and settings\Lubo\Data aplikací\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5307fc4c-n\msvcr71.dll
2010-09-19 17:52 . 2010-09-19 17:52 61440 ----a-w- c:\documents and settings\Lubo\Data aplikací\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1534b33d-n\decora-sse.dll
2010-09-19 17:52 . 2010-09-19 17:52 12800 ----a-w- c:\documents and settings\Lubo\Data aplikací\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1534b33d-n\decora-d3d.dll
2010-09-19 17:52 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-19 17:52 . 2010-09-20 21:02 -------- d-----w- c:\program files\Java
2010-09-18 11:01 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2010-09-18 11:01 . 2010-09-18 11:01 -------- d-----w- c:\program files\Winamp Detect
2010-09-18 11:00 . 2010-09-18 11:00 -------- d-----w- c:\program files\Winamp Remote
2010-09-18 00:41 . 2010-05-20 13:27 762736 ----a-w- c:\windows\vVX3000.exe
2010-09-18 00:41 . 2010-05-20 13:27 677232 ----a-w- c:\windows\system32\LCCoin32.dll
2010-09-18 00:41 . 2010-05-20 13:27 227696 ----a-w- c:\windows\vVX3000.dll
2010-09-18 00:41 . 2010-05-20 13:27 1961328 ----a-w- c:\windows\system32\drivers\VX3000.sys
2010-09-18 00:41 . 2010-05-20 13:27 175472 ----a-w- c:\windows\system32\cVX3000.dll
2010-09-18 00:41 . 2010-05-20 13:27 101232 ----a-w- c:\windows\VX3000.dll
2010-09-18 00:41 . 2010-09-18 00:41 -------- d-----w- c:\program files\Microsoft LifeCam
2010-09-18 00:41 . 2009-09-04 15:29 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2010-09-18 00:41 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-09-18 00:40 . 2010-09-18 00:40 -------- d-----w- c:\windows\Logs
2010-09-18 00:40 . 2010-09-18 00:40 -------- d-----w- c:\windows\system32\drivers\umdf
2010-09-18 00:35 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2010-09-18 00:34 . 2010-09-18 00:34 -------- d-----w- c:\windows\system32\cs-CZ
2010-09-18 00:33 . 2010-09-18 00:34 -------- d-----w- c:\windows\system32\XPSViewer
2010-09-18 00:33 . 2010-09-18 00:33 -------- d-----w- c:\program files\MSBuild
2010-09-18 00:33 . 2010-09-18 00:33 -------- d-----w- c:\program files\Reference Assemblies
2010-09-18 00:32 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-09-18 00:32 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-09-18 00:32 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-09-18 00:32 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-09-18 00:32 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2010-09-18 00:32 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-09-18 00:32 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-09-18 00:32 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-09-18 00:32 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-09-18 00:30 . 2007-11-30 11:18 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-09-18 00:22 . 2004-08-03 21:07 59264 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-09-18 00:22 . 2004-08-03 21:07 59264 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-09-18 00:18 . 2010-10-04 21:57 -------- d-----w- c:\program files\ICQToolbar
2010-09-18 00:17 . 2010-09-21 17:26 -------- d-----w- c:\program files\ICQ6
2010-09-18 00:14 . 2010-09-18 11:02 -------- d-----w- c:\program files\Winamp
2010-09-18 00:13 . 2010-10-05 16:33 57344 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-18 00:11 . 2010-10-05 16:30 193832 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\Setup\finishPlugin.dll
2010-09-18 00:11 . 2010-10-05 16:29 1062184 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\Setup\Resource.dll
2010-09-18 00:11 . 2010-10-05 16:28 876824 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\Setup\DivXSetup.exe
2010-09-18 00:11 . 2010-09-18 00:11 56997 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\WebPlayer\Uninstaller.exe
2010-09-18 00:04 . 2010-10-05 16:32 -------- d-----w- c:\program files\DivX
2010-09-18 00:03 . 2010-10-05 16:29 144696 ----a-w- c:\documents and settings\All Users\Data aplikací\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-17 23:59 . 2010-09-17 23:59 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-09-17 23:58 . 2010-09-18 00:01 -------- d-----w- c:\program files\Google
2010-09-17 23:49 . 2010-09-17 23:49 61440 ----a-r- c:\documents and settings\Lubo\Data aplikací\Microsoft\Installer\{3303E88E-C09C-44FD-9D15-3A0265DB938A}\ARPPRODUCTICON.exe
2010-09-17 23:49 . 2010-09-27 22:26 -------- d-----w- c:\program files\Opera
2010-09-17 23:45 . 2010-10-09 21:46 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000005-00000000-00000007-00001102-00000002-80671102}.dat
2010-09-17 23:45 . 2010-10-09 21:46 288 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000007-00001102-00000002-80671102}.dat
2010-09-17 23:44 . 2010-09-18 00:41 -------- dc----w- c:\windows\system32\DRVSTORE
2010-09-17 23:44 . 2007-08-21 08:12 21760 ----a-w- c:\windows\system32\drivers\point32.sys
2010-09-17 23:44 . 2010-09-17 23:44 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-09-17 23:44 . 2010-09-17 23:44 -------- d-----w- c:\program files\MSXML 6.0
2010-09-17 23:37 . 2007-12-28 15:58 2944 ----a-w- c:\windows\system32\LgExport.dll
2010-09-17 23:37 . 2007-12-28 15:57 25216 ----a-w- c:\windows\system32\LGDispDrv.dll
2010-09-17 23:37 . 2010-09-17 23:37 -------- d-----w- c:\program files\LG Soft India
2010-09-17 23:26 . 2002-10-08 15:09 10477 ------w- c:\windows\system32\PFMODNT.SYS
2010-09-17 23:26 . 2010-09-17 23:26 -------- d-----w- c:\windows\Profiles
2010-09-17 23:26 . 2010-09-17 23:33 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-17 23:26 . 2010-09-17 23:26 -------- d-----w- c:\windows\system32\Adobe
2010-09-17 23:25 . 1998-10-29 12:45 306688 ----a-w- c:\windows\IsUninst.exe
2010-09-17 23:21 . 2000-05-10 23:00 90112 ------w- c:\windows\Updreg.EXE
2010-09-17 23:21 . 1996-05-23 02:24 24976 ------w- c:\windows\CTRES.DLL
2010-09-17 23:21 . 1994-12-05 03:11 53552 ------w- c:\windows\CTCCW.DLL
2010-09-17 23:21 . 1998-06-05 02:00 84992 ------w- c:\windows\system32\SFCVRT32.DLL
2010-09-17 23:21 . 1998-01-08 01:00 1048576 ------w- c:\windows\system32\SFMAN.DAT
2010-09-17 23:21 . 1995-08-30 02:02 82432 ------w- c:\windows\system32\CTWFLT32.DLL
2010-09-17 23:21 . 1995-07-13 02:01 26768 ------w- c:\windows\system32\CTL3D.DLL
2010-09-17 23:21 . 1995-01-13 06:10 149504 ------w- c:\windows\system32\MFCANS32.DLL
2010-09-17 23:21 . 1995-01-13 06:10 108032 ------w- c:\windows\system32\MFCUIA32.DLL
2010-09-17 23:21 . 2010-09-17 23:29 -------- d-----w- c:\windows\system32\Defaults
2010-09-17 23:19 . 2001-09-12 23:12 73728 ----a-w- c:\windows\system32\CTDrmRes.dll
2010-09-17 23:19 . 2001-05-04 08:29 28672 ----a-w- c:\windows\system32\CTIntRes.dll
2010-09-17 23:19 . 2000-04-19 23:00 24576 ----a-w- c:\windows\system32\CTMERes.DLL
2010-09-17 23:19 . 2010-09-17 23:19 -------- d-----w- C:\Media
2010-09-17 23:19 . 2002-02-20 03:00 331776 ------w- c:\windows\system32\CTMedEng.dll
2010-09-17 23:19 . 2002-01-22 01:12 163840 ------w- c:\windows\system32\CTDRMUI.dll
2010-09-17 23:19 . 1998-10-20 08:05 54784 ------w- c:\windows\system32\Inetwh32.dll
2010-09-17 23:18 . 2001-03-30 00:00 62976 ----a-w- c:\windows\system32\CTDetres.dll
2010-09-17 23:18 . 1999-11-17 23:00 25088 ----a-w- c:\windows\system32\CTSVCCTL.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-05 12:17 . 2010-09-14 23:57 -------- d-----w- c:\program files\ESET
2010-09-19 22:57 . 2010-09-15 00:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-19 18:35 . 2010-09-14 23:45 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-19 18:35 . 2010-09-14 23:45 2426 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2010-09-19 18:34 . 2010-09-14 23:46 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2010-09-18 00:33 . 2001-10-25 14:00 82552 ----a-w- c:\windows\system32\perfc005.dat
2010-09-18 00:33 . 2001-10-25 14:00 437832 ----a-w- c:\windows\system32\perfh005.dat
2010-09-17 23:37 . 2010-09-15 00:11 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-15 00:15 . 2010-09-15 00:15 -------- d-----w- c:\program files\My Company Name
2010-09-15 00:13 . 2010-09-15 00:12 -------- d-----w- c:\program files\ATI Technologies
2010-09-15 00:00 . 2010-09-15 00:00 0 ----a-w- c:\windows\nsreg.dat
2010-09-14 23:53 . 2010-09-14 23:53 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-09-14 23:46 . 2010-09-14 23:46 -------- d-----w- c:\program files\microsoft frontpage
2010-09-14 23:43 . 2010-09-14 23:43 21812 ----a-w- c:\windows\system32\emptyregdb.dat
2010-08-12 04:07 . 2010-09-18 00:10 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-08-12 04:07 . 2010-09-18 00:10 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-08-12 04:07 . 2010-09-18 00:10 45648 ----a-w- c:\windows\system32\drivers\PxHelp20.sys
2010-08-12 04:07 . 2010-09-18 00:10 133616 ------w- c:\windows\system32\pxafs.dll
2010-08-12 04:07 . 2010-09-18 00:10 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-08-12 04:07 . 2010-09-18 00:10 123888 ------w- c:\windows\system32\pxcpyi64.exe
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 507904]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"WindowsDriverControl"="c:\documents and settings\Lubo\Data aplikací\C-76947-8457-2745\wincdrsvn.exe" [2010-10-07 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"CTHelper"="CTHELPER.EXE" [2003-06-09 28672]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-28 28672]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2010-05-20 119152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
forteManager.lnk - c:\program files\LG Soft India\forteManager\bin\Monitor.exe [2010-9-18 1097728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-09-19 22:21 1242448 ----a-w- e:\steam\Steam.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"e:\\Battlefield2\\BF2.exe"=
"e:\\Warcraft III\\Warcraft III.exe"=
"e:\\Steam\\SteamApps\\exitus203\\counter-strike\\hl.exe"=
"c:\\Documents and Settings\\Lubo\\Data aplikací\\C-76947-8457-2745\\wincdrsvn.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30.3.2010 11:16 1107336]
S2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18.9.2010 1:58 136176]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [25.10.2001 16:00 3584]
S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [18.9.2010 1:37 14336]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [18.9.2010 1:37 13312]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20.9.2010 0:44 721904]
.
Obsah adresáře 'Naplánované úlohy'

2010-10-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 12:21]

2010-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-17 23:58]

2010-10-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-17 23:58]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://fullarticles.net
FF - ProfilePath - c:\documents and settings\Lubo\Data aplikací\Mozilla\Firefox\Profiles\pc55zpv1.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.sk
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(596)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(988)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\ATKKBService.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Celkový čas: 2010-10-09 23:55:40 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-10-09 21:55

Před spuštěním: Volných bajtů: 14 382 231 552
Po spuštění: Volných bajtů: 14 485 270 528

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 0C77A7097599A91DEFB7D62A1699C64E

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Lubov PC - Odosielanie vyrusu cez skype

#8 Příspěvek od motji »

:arrow: Otestujte na www.virustotal.com

C:\kj32.exe
C:\d1d.exe
C:\89712das094bdad.exe
C:\89712094bdad.exe
c:\windows\89712094bdad.exe


-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.


Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Lubov PC - Odosielanie vyrusu cez skype

#10 Příspěvek od motji »

:arrow: Pokud nemáte, přesuňte Combofix na plochu
-otevřete si Poznámkový blok
-Do něj zkopírujte text z tohoto okénka

Kód: Vybrat vše

Collect::
C:\kj32.exe
C:\d1d.exe
C:\89712das094bdad.exe
C:\89712094bdad.exe
c:\windows\89712094bdad.exe
c:\documents and settings\Lubo\Data aplikací\C-76947-8457-2745\wincdrsvn.exe

-uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
-po uložení uchopte vámi vytvořený skript levým myšítkem a -přesuňte ho nad ikonu Combofixu, kde ho upustíte:

Obrázek


-po aplikaci na Vás vypadne další log,vložte ho sem

Upozornění : může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci



:arrow: Tuto stránku znáte?
uStart Page = hxxp://fullarticles.net
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

hromiii
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 05 říj 2010 21:36

Re: Lubov PC - Odosielanie vyrusu cez skype

#11 Příspěvek od hromiii »

:) mam problem,,, vsetko som robil ako si tu pisal,,, do combofixu som vlozil ten text subor,,,vsetko robilo ako malo a po rr mi nechce nabehnut windows,,,nabehni mi len po kde mi pise spustit beznym sposobom, posledna konfiguracia,,,a stav nouze,,,,ked dam posledna konf. tak sa mi zase rr pc,,,co stym?

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Lubov PC - Odosielanie vyrusu cez skype

#12 Příspěvek od motji »

A stav nouze jde?
Pokud ne, zkus ještě obnovu systému.
Jinak Ti do nouzového režimu.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

hromiii
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 05 říj 2010 21:36

Re: Lubov PC - Odosielanie vyrusu cez skype

#13 Příspěvek od hromiii »

stav nouze nejde,,, taze dat obnovit system?,,,,,,,,,,,nouzovy rezim nejde

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Lubov PC - Odosielanie vyrusu cez skype

#14 Příspěvek od motji »

Takže se nikam nedostaneš? Ano dej obnovu systému, a pokud Ti nepujde, tak opravu z inst.cd.
Pokud ho nemáš, tak jsou i další možnosti, třeba přes nějaké live cd obnovit registry ze zálohy combofixu, takže nepanikař :) .


Já tu budu večer :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

hromiii
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 05 říj 2010 21:36

Re: Lubov PC - Odosielanie vyrusu cez skype

#15 Příspěvek od hromiii »

ale mna do windosu nepusti,,,,kde mam obnovit system v biose?

Odpovědět