Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

pro Motji

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 říj 2010 09:59

pro Motji

#1 Příspěvek od kolariktomas1 »

Logfile of random's system information tool 1.08 (written by random/random)
Run by rodina at 2010-10-22 15:47:03
Systém Microsoft Windows XP Professional Service Pack 3
System drive E: has 18 GB (46%) free of 38 GB
Total RAM: 759 MB (45% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:47:58, on 22.10.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Google\Update\GoogleUpdate.exe
E:\Program Files\CyberLink\Shared Files\RichVideo.exe
E:\WINDOWS\System32\tcpsvcs.exe
E:\WINDOWS\System32\snmp.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Citrix\ICA Client\ssonsvr.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\System32\igfxtray.exe
E:\WINDOWS\System32\hkcmd.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
E:\Program Files\lg_fwupdate\fwupdate.exe
E:\Program Files\Winamp\winampa.exe
E:\WINDOWS\PixArt\PAC207\Monitor.exe
E:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe
E:\Program Files\Search Settings\SearchSettings.exe
E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
E:\Program Files\Citrix\ICA Client\concentr.exe
E:\Program Files\DynamicUSBTool\DynamicUSB.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Common Files\Java\Java Update\jusched.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
E:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
E:\Program Files\Nikon\NkView6\NkvMon.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Citrix\ICA Client\WFCRUN32.EXE
E:\Program Files\Mozilla Firefox\firefox.exe
E:\PROGRA~1\Crawler\CToolbar.exe
E:\Program Files\Mozilla Firefox\plugin-container.exe
E:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\rodina\Dokumenty\Stažené soubory\RSIT.exe
E:\Program Files\trend micro\rodina.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.theprizeday.com/today.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_custo ... TbId=60076
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - E:\Program Files\Search Settings\kb128\SearchSettings.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - E:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - E:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - E:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - E:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - E:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - E:\Program Files\Search Settings\kb128\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - E:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: BS.Player ControlBar - {2C688203-7EB3-4327-9995-1CB417BA23F9} - E:\Program Files\BS.Player ControlBar\BSToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - E:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: &Crawler lišta - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - E:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [IgfxTray] E:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] E:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "E:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "E:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [WinampAgent] "E:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PAC207_Monitor] E:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [Monitor] E:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [DC1300 Monitor] E:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SearchSettings] E:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [OM2_Monitor] "E:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" /OM
O4 - HKLM\..\Run: [ConnectionCenter] "E:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [DynamicUSB] "E:\Program Files\DynamicUSBTool\DynamicUSB.exe"
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [OM2_Monitor] "E:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NkvMon.exe.lnk = E:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Google Sidewiki... - res://E:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - E:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - E:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/f ... wflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - E:\PROGRA~1\Crawler\ctbr.dll
O20 - Winlogon Notify: !SASWinLogon - E:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Proces mezipaměti kategorií součástí - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\PROGRA~1\ALWILS~1\Avast4\ashMaiSv.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - E:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - E:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - E:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11298 bytes

======Scheduled tasks folder======

E:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - E:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll [2007-03-02 1298024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
HP Print Clips - E:\Program Files\HP\Smart Web Printing\hpswp_framework.dll [2007-03-02 177768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}]
E:\PROGRA~1\Crawler\ctbr.dll [2010-09-02 1241448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
Winamp Toolbar Loader - E:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-12 278192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype add-on for Internet Explorer - E:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08 804136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - E:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll [2010-10-16 842296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-04 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
SearchSettings Class - E:\Program Files\Search Settings\kb128\SearchSettings.dll [2009-04-09 1091584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-04 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{32099AAC-C132-4136-9E9A-4E364A424E17} - DAEMON Tools Toolbar - E:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll [2008-10-14 863688]
{2C688203-7EB3-4327-9995-1CB417BA23F9} - BS.Player ControlBar - E:\Program Files\BS.Player ControlBar\BSToolbar.dll [2008-10-08 859592]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - E:\Program Files\Winamp Toolbar\winamptb.dll [2009-05-06 1262888]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - E:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-07-12 278192]
{4B3803EA-5230-4DC3-A7FC-33638F3D3542} - &Crawler lišta - E:\PROGRA~1\Crawler\ctbr.dll [2010-09-02 1241448]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=E:\WINDOWS\System32\igfxtray.exe [2002-06-19 155648]
"HotKeysCmds"=E:\WINDOWS\System32\hkcmd.exe [2002-06-19 114688]
"HP Software Update"=E:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-03-11 49152]
"RemoteControl"=E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
"LanguageShortcut"=E:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
"LGODDFU"=E:\Program Files\lg_fwupdate\fwupdate.exe [2010-07-18 557056]
"WinampAgent"=E:\Program Files\Winamp\winampa.exe [2010-01-14 37888]
"PAC207_Monitor"=E:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"Monitor"=E:\WINDOWS\PixArt\PAC207\Monitor.exe [2006-11-03 319488]
"DC1300 Monitor"=E:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe [2009-03-04 45056]
"NeroFilterCheck"=E:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"SearchSettings"=E:\Program Files\Search Settings\SearchSettings.exe [2009-04-09 970240]
"Adobe Reader Speed Launcher"=E:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-20 35760]
"Adobe ARM"=E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
"OM2_Monitor"=E:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe [2009-11-25 54672]
"ConnectionCenter"=E:\Program Files\Citrix\ICA Client\concentr.exe [2009-09-12 103768]
"DynamicUSB"=E:\Program Files\DynamicUSBTool\DynamicUSB.exe [2007-03-02 94208]
"avast!"=E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
"SunJavaUpdateSched"=E:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=E:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"swg"=E:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-03-08 39408]
"OM2_Monitor"=E:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe [2009-11-25 95632]

E:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
McAfee Security Scan Plus.lnk - E:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
Microsoft Office.lnk - E:\Program Files\Microsoft Office\Office\OSA9.EXE
NkvMon.exe.lnk - E:\Program Files\Nikon\NkView6\NkvMon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
E:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
E:\WINDOWS\system32\igfxsrvc.dll [2002-06-19 307200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
E:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - E:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=E:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\Program Files\ICQ6\ICQ.exe"="E:\Program Files\ICQ6\ICQ.exe:*:Enabled:ICQ6"
"E:\Program Files\uTorrent\uTorrent.exe"="E:\Program Files\uTorrent\uTorrent.exe:*:Disabled:µTorrent"
"E:\WINDOWS\system32\dpvsetup.exe"="E:\WINDOWS\system32\dpvsetup.exe:*:Disabled:Microsoft DirectPlay Voice Test"
"E:\WINDOWS\system32\rundll32.exe"="E:\WINDOWS\system32\rundll32.exe:*:Disabled:Run a DLL as an App"
"E:\WINDOWS\system32\sessmgr.exe"="E:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"E:\Program Files\ICQ6.5\ICQ.exe"="E:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"E:\Program Files\Skype\Plugin Manager\skypePM.exe"="E:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Documents and Settings\tom\Dokumenty\Stažené soubory\BULANCI.EXE"="C:\Documents and Settings\tom\Dokumenty\Stažené soubory\BULANCI.EXE:*:Enabled:BULANCI"
"E:\WINDOWS\system32\dplaysvr.exe"="E:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"E:\Program Files\Skype\Phone\Skype.exe"="E:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

6169-11-24 00:54:03 ----D---- E:\Documents and Settings\All Users\Data aplikací\MSN6
6169-11-24 00:35:36 ----D---- E:\Netgear
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\vxblock.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxwave.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxmas.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxinsa64.exe
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxhpinst.exe
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxdrv.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\pxcpya64.exe
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\px.dll
6169-11-23 14:04:51 ----N---- E:\WINDOWS\system32\drivers\PxHelp20.sys
6169-11-23 14:04:33 ----D---- E:\Program Files\Winamp
6169-11-23 13:43:41 ----A---- E:\WINDOWS\system32\igfxres.dll
6169-11-23 13:33:36 ----A---- E:\WINDOWS\system32\drivers\ks.sys
6169-11-23 13:33:36 ----A---- E:\WINDOWS\system32\drivers\drmk.sys
6169-11-23 13:33:35 ----A---- E:\WINDOWS\system32\drivers\stream.sys
6169-11-23 13:33:35 ----A---- E:\WINDOWS\system32\drivers\portcls.sys
6169-11-23 13:33:34 ----A---- E:\WINDOWS\system32\ksuser.dll
2010-10-22 15:47:05 ----D---- E:\Program Files\trend micro
2010-10-22 15:47:03 ----D---- E:\rsit
2010-10-14 20:23:42 ----D---- E:\Documents and Settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-10-14 20:23:35 ----D---- E:\Program Files\SUPERAntiSpyware
2010-10-10 18:20:26 ----A---- E:\WINDOWS\mdm.ini
2010-10-10 17:15:27 ----D---- E:\Program Files\Microsoft Visual Studio
2010-09-28 18:10:17 ----A---- E:\WINDOWS\ntbtlog.txt
2010-09-27 13:54:08 ----SHD---- E:\WINDOWS\CSC

======List of files/folders modified in the last 1 months======

2010-10-22 15:47:06 ----D---- E:\WINDOWS\Prefetch
2010-10-22 15:47:05 ----RD---- E:\Program Files
2010-10-22 15:46:17 ----D---- E:\Program Files\Spyware Terminator
2010-10-22 15:46:11 ----D---- E:\Program Files\WinClamAVShield
2010-10-22 15:43:50 ----HDC---- E:\Documents and Settings\All Users\Data aplikací\~0
2010-10-22 15:43:47 ----HD---- E:\Config.Msi
2010-10-22 15:43:41 ----SHD---- E:\WINDOWS\Installer
2010-10-22 15:42:45 ----D---- E:\Documents and Settings\All Users\Data aplikací\Lavasoft
2010-10-22 15:42:43 ----DC---- E:\WINDOWS\system32\DRVSTORE
2010-10-22 15:42:32 ----D---- E:\WINDOWS\system32
2010-10-22 15:01:54 ----D---- E:\Program Files\Crawler
2010-10-22 15:01:39 ----D---- E:\Program Files\Mozilla Firefox
2010-10-22 14:12:26 ----A---- E:\WINDOWS\lgfwup.ini
2010-10-22 14:12:17 ----D---- E:\Program Files\lg_fwupdate
2010-10-22 14:09:13 ----D---- E:\WINDOWS\Temp
2010-10-21 23:04:48 ----A---- E:\WINDOWS\SchedLgU.Txt
2010-10-16 10:22:50 ----D---- E:\WINDOWS\system32\CatRoot2
2010-10-15 16:19:45 ----D---- E:\Documents and Settings\rodina\Data aplikací\Skype
2010-10-15 16:14:14 ----D---- E:\Documents and Settings\rodina\Data aplikací\skypePM
2010-10-15 06:45:27 ----A---- E:\WINDOWS\win.ini
2010-10-14 22:53:04 ----D---- E:\WINDOWS
2010-10-14 20:23:15 ----D---- E:\Program Files\Malwarebytes' Anti-Malware
2010-10-14 20:23:12 ----D---- E:\WINDOWS\system32\drivers
2010-10-13 20:41:53 ----D---- E:\WINDOWS\network diagnostic
2010-10-10 17:16:35 ----D---- E:\WINDOWS\Help
2010-10-10 17:15:40 ----D---- E:\Program Files\Common Files\Microsoft Shared
2010-09-30 17:30:24 ----D---- E:\WINDOWS\Microsoft.NET
2010-09-29 19:02:38 ----D---- E:\Documents and Settings\rodina\Data aplikací\IcaClient
2010-09-28 17:41:54 ----D---- E:\Documents and Settings
2010-09-28 17:39:38 ----D---- E:\WINDOWS\Debug
2010-09-28 17:23:13 ----D---- E:\WINDOWS\system32\XPSViewer
2010-09-28 17:23:09 ----RSD---- E:\WINDOWS\Fonts
2010-09-28 17:22:04 ----HD---- E:\WINDOWS\inf
2010-09-28 17:21:30 ----D---- E:\WINDOWS\system32\CatRoot
2010-09-28 17:18:40 ----A---- E:\WINDOWS\system32\PerfStringBackup.INI
2010-09-28 17:18:28 ----RSD---- E:\WINDOWS\assembly
2010-09-28 17:18:13 ----D---- E:\WINDOWS\WinSxS

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 PxHelp20;PxHelp20; E:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 sptd;sptd; E:\WINDOWS\System32\Drivers\sptd.sys [2008-10-21 717296]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; E:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
R1 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; E:\WINDOWS\system32\drivers\ialmsbw.sys [2002-06-21 90784]
R1 ctxusbm;Citrix USB Monitor Driver; E:\WINDOWS\system32\DRIVERS\ctxusbm.sys [2009-09-08 65584]
R1 intelppm;Řadič procesoru Intel; E:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 SASDIFSV;SASDIFSV; \??\E:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\E:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R1 Tcpip6;Ovladač protokolu Microsoft IPv6; E:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-06-20 225856]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; E:\WINDOWS\system32\drivers\ialmkchw.sys [2002-06-21 69792]
R3 aeaudio;aeaudio; E:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 E1000;Intel(R) PRO/1000 Adapter Driver; E:\WINDOWS\System32\DRIVERS\e1000325.sys [2002-05-06 99328]
R3 hidusb;Ovladač třídy standardu HID; E:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 ialm;ialm; E:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2002-06-21 78877]
R3 mouhid;Ovladač myši standardu HID; E:\WINDOWS\System32\DRIVERS\mouhid.sys [2002-09-23 12160]
R3 pfc;Padus ASPI Shell; E:\WINDOWS\system32\drivers\pfc.sys [2003-08-11 14604]
R3 smwdm;smwdm; E:\WINDOWS\system32\drivers\smwdm.sys [2002-07-08 553800]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; E:\WINDOWS\system32\DRIVERS\serscan.sys [2001-10-24 6784]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; E:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; E:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R4 sp_rsdrv2;Spyware Terminator Driver 2; \??\E:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
S3 a2q4z5xs;a2q4z5xs; E:\WINDOWS\system32\drivers\a2q4z5xs.sys []
S3 CCDECODE;Dekodér Closed Caption; E:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 CrystalSysInfo;CrystalSysInfo; \??\E:\Program Files\MediaCoder\SysInfo.sys []
S3 DC1300;DC 1300 WDM Video Capture; E:\WINDOWS\System32\Drivers\BSC504AV.SYS [2009-03-04 515365]
S3 hamachi;Hamachi Network Interface; E:\WINDOWS\system32\DRIVERS\hamachi.sys [2010-02-03 26176]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; E:\WINDOWS\system32\DRIVERS\HPZid412.sys [2007-03-08 49920]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; E:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2007-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; E:\WINDOWS\system32\DRIVERS\HPZius12.sys [2007-03-08 21568]
S3 INIDVD;Initio USB DVD Filter Driver; E:\WINDOWS\system32\DRIVERS\inidvd.sys [2007-11-07 7936]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; E:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; E:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 PAC207;e-Messenger 112; E:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-10-25 616064]
S3 SLIP;BDA Slip De-Framer; E:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; E:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 USBCamera;DC 1300 Still Image Capture; E:\WINDOWS\System32\Drivers\BscBulk.sys [2009-03-04 10986]
S3 usbccgp;Obecný nadřazený ovladač Microsoft USB; E:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Třída USB Printer; E:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Ovladač skeneru USB; E:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; E:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 WpdUsb;WpdUsb; E:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Dálnopisný kodek světového standardu; E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; E:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 6to4;Pomocná služba protokolu IPv6; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R2 JavaQuickStarterService;Java Quick Starter; E:\Program Files\Java\jre6\bin\jqs.exe [2010-07-17 153376]
R2 Net Driver HPZ12;Net Driver HPZ12; E:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; E:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); E:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-14 272024]
R2 SimpTcp;Jednoduché služby TCP/IP; E:\WINDOWS\System32\tcpsvcs.exe [2002-09-23 19456]
R2 SNMP;SNMP; E:\WINDOWS\System32\snmp.exe [2008-04-14 32768]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
R3 hpqcxs08;hpqcxs08; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S2 gupdate;Služba Google Update (gupdate); E:\Program Files\Google\Update\GoogleUpdate.exe [2010-02-22 135664]
S3 aspnet_state;ASP.NET State Service; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 avast! Mail Scanner;avast! Mail Scanner; E:\PROGRA~1\ALWILS~1\Avast4\ashMaiSv.exe [2009-08-17 254040]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; E:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Software Updater; E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-26 182768]
S3 idsvc;Windows CardSpace; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 McComponentHostService;McAfee Security Scan Component Host Service; E:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
S3 p2pgasvc;Ověřování v síti skupiny rovnocenných počítačů; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Správce identit sítě rovnocenných počítačů; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Síť rovnocenných počítačů; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Protokol PNRP; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 SNMPTRAP;Zachytávání pro službu SNMP; E:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704]
S3 WMPNetworkSvc;Služba Windows Media Player Network Sharing; E:\Program Files\Windows Media Player\WMPNetwk.exe [2007-01-05 913920]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; E:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 říj 2010 09:59

Re: pro Motji

#2 Příspěvek od kolariktomas1 »

info log:

info.txt logfile of random's system information tool 1.08 2010-10-22 15:48:13

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 E:\WINDOWS\INF\PCHealth.inf
2d3 SteadyMove for Adobe Premiere Pro-->MsiExec.exe /I{94118D5F-2D5D-4BF5-9F84-11FB8A97B566}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Adobe AIR-->E:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 ActiveX-->E:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->E:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_Plugin.exe -maintain plugin
Adobe Premiere Pro-->RunDll32 "E:\Program Files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll",LaunchSetup "E:\Program Files\InstallShield Installation Information\{084709F7-38C5-4609-B55F-2417939315EB}\setup.exe"
Adobe Reader 9.3.4-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A93000000001}
Aktualizace systému Windows XP (KB951072-v2)-->"E:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB951978)-->"E:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB955839)-->"E:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB967715)-->"E:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB968389)-->"E:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Aktualizace systému Windows XP (KB973815)-->"E:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB952069)-->"E:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB968816)-->"E:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player (KB973540)-->"E:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player 11 (KB936782)-->"E:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Aktualizace zabezpečení aplikace Windows Media Player 11 (KB954154)-->"E:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Aktualizace zabezpečení produktu Windows XP (KB941569)-->"E:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127)-->"E:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB938127-v2)-->"E:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB953838)-->"E:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB956390)-->"E:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 7 (KB969897)-->"E:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB971961)-->"E:\WINDOWS\ie8updates\KB971961-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows Internet Explorer 8 (KB972260)-->"E:\WINDOWS\ie8updates\KB972260-IE8\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB923561)-->"E:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB938464)-->"E:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB938464-v2)-->"E:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB946648)-->"E:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB950762)-->"E:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB950974)-->"E:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951066)-->"E:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951376-v2)-->"E:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951698)-->"E:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB951748)-->"E:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB952004)-->"E:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB952954)-->"E:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB953839)-->"E:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB954211)-->"E:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB954459)-->"E:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB954600)-->"E:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB955069)-->"E:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956391)-->"E:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956572)-->"E:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956744)-->"E:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956802)-->"E:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956803)-->"E:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956841)-->"E:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB956844)-->"E:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB957095)-->"E:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB957097)-->"E:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958644)-->"E:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB958687)-->"E:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB959426)-->"E:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960225)-->"E:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960803)-->"E:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB960859)-->"E:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961371-v2)-->"E:\WINDOWS\$NtUninstallKB961371-v2$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961373)-->"E:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB961501)-->"E:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB968537)-->"E:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB969898)-->"E:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB970238)-->"E:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971557)-->"E:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971633)-->"E:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB971657)-->"E:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973346)-->"E:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973354)-->"E:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973507)-->"E:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Aktualizace zabezpečení systému Windows XP (KB973869)-->"E:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
ALZip-->"E:\Program Files\ESTsoft\ALZip\unins000.exe"
Any Weblock 1.0.0-->"E:\Program Files\AnyUtils\Any Weblock\unins000.exe"
ArcSoft Panorama Maker 3.0-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{1CABB679-3958-44AA-BFFF-4E68A2684255}\Setup.exe" -l0x9 -uninst
Audacity 1.3.5 (Unicode)-->"E:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
Auto Gordian Knot 2.45-->E:\Program Files\AutoGK\uninst.exe
avast! Antivirus-->E:\Program Files\Alwil Software\Avast4\aswRunDll.exe "E:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
AviSynth 2.5-->"E:\Program Files\AviSynth 2.5\Uninstall.exe"
Booster 1.03-->"E:\Program Files\LG USB Booster\unins000.exe"
BS.Player ControlBar-->E:\Program Files\BS.Player ControlBar\uninst.exe
BS.Player FREE-->"E:\Program Files\Webteh\BSplayer\uninstall.exe"
CCleaner-->"E:\Program Files\CCleaner\uninst.exe"
Citrix online plug-in (HDX)-->MsiExec.exe /I{812424AC-A8B5-44E6-8D48-07E939D1AD9A}
Citrix online plug-in (SSON)-->MsiExec.exe /I{7C84DDDF-DEC9-4E02-8222-D86E73531CEB}
Citrix online plug-in (USB)-->MsiExec.exe /I{55392E52-1AAD-44C4-BE49-258FFE72434F}
Citrix online plug-in (Web)-->MsiExec.exe /I{0BCA9EFD-F2D6-4638-B053-8693BA0404BE}
Citrix online plug-in-->E:\Documents and Settings\All Users\Data aplikací\Citrix\Citrix online plug-in\TrolleyExpress.exe /uninstall /cleanup
Crawler Toolbar with Web Security Guard-->E:\PROGRA~1\Crawler\CToolbar.exe uninst
DAEMON Tools Toolbar-->E:\Program Files\DAEMON Tools Toolbar\uninst.exe
DC1300-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{B68AABF8-591C-4B1F-906E-DCEF6E18958A}\SETUP.EXE" -l0x9
Důležitá aktualizace aplikace Windows Media Player 11 (KB959772)-->"E:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
DVD Suite-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
DynamicUSBTool-->MsiExec.exe /I{85BC6E3A-E8D4-48B7-8EEE-13E46F65BA75}
e-Messenger 112-->"E:\Program Files\InstallShield Installation Information\{730C01C5-CAE4-46FE-BA13-8B3E637F8192}\setup.exe" -runfromtemp -l0x0005 -removeonly
Free The Pharaoh v1.0-->"E:\Program Files\Free The Pharaoh\unins000.exe"
Free WMA to MP3 Converter 1.16-->"E:\Program Files\Free WMA to MP3 Converter\unins000.exe"
FTP Commander-->E:\Program Files\FTP Commander\uninstall.exe
GamingHarbor Toolbar-->"E:\Documents and Settings\All Users\Data aplikací\{F444439B-B473-48E8-8DE5-4CB929C79A9F}\Setup.exe" REMOVE=TRUE MODIFY=FALSE
GamingHarbor Toolbar-->E:\Documents and Settings\All Users\Data aplikací\{F444439B-B473-48E8-8DE5-4CB929C79A9F}\Setup.exe
Google Toolbar for Internet Explorer-->"E:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_223E2B8E7BAD9544.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
GTK+ 2.6.9 runtime environment-->"E:\Program Files\Common Files\GTK\2.0\unins000.exe"
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->E:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"E:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Customer Participation Program 9.0-->E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Deskjet All-In-One Software 9.0-->E:\Program Files\HP\Digital Imaging\{FA8A44D7-3E8A-4034-9C4F-088FA6B72BC4}\setup\hpzscr01.exe -datfile hposcr14.dat
HP Imaging Device Functions 9.0-->E:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential 2.01-->E:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Smart Web Printing-->MsiExec.exe /X{415CDA53-9100-476F-A7B2-476691E117C7}
HP Solution Center 9.0-->E:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
HPSSupply-->MsiExec.exe /X{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}
ICQ6.5-->"E:\Program Files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly
Intel(R) Extreme Graphics Driver Software-->RUNDLL32.EXE E:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Intel(R) PRO Ethernet Adapter and Software-->Prounstl.exe
IrfanView (remove only)-->E:\Program Files\IrfanView\iv_uninstall.exe
Java(TM) 6 Update 21-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
KaraFun 1.16a-->"E:\Program Files\KaraFun\unins000.exe"
Kodek 0.16 CZ-->"E:\Program Files\Kodek CZ\unins000.exe"
LG ODD Auto Firmware Update-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{6179550A-3E7C-499E-BCC9-9E8113E0A285}\setup.exe"
Malwarebytes' Anti-Malware-->"E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee Security Scan Plus-->"E:\Program Files\McAfee Security Scan\uninstall.exe"
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->E:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"E:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"E:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs-->"E:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2000 SR-1 Professional-->MsiExec.exe /I{00010405-78E1-11D2-B60F-006097C998E7}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"E:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Mozilla Firefox (3.6.11)-->E:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 Parser and SDK-->MsiExec.exe /I{716E0306-8318-4364-8B8F-0CC4E9376BAC}
My Photo Index-->E:\Program Files\MyPhotoIndex\My Photo Index\Uninstall.exe
Nero Media Player-->E:\WINDOWS\UNNMP.exe /UNINSTALL
Nero OEM-->E:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
NeroVision Express 2-->E:\WINDOWS\UNNeroVision.exe /UNINSTALL
Nikon View 6-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{AAB84E83-C8DF-4752-9DFC-2E2A48EE5E9F}\setup.exe" UNINSTALL
Ogg Vorbis ACM Codec-->E:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_ACM 132 E:\WINDOWS\INF\Vorbis.inf
OLYMPUS Master 2-->MsiExec.exe /X{3A1AB8E6-748E-4B95-AA2D-FE9952EB3106}
Oprava hotfix aplikace Windows Media Player 11 (KB939683)-->"E:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Oprava Hotfix systému Windows XP (KB952287)-->"E:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Oprava Hotfix systému Windows XP (KB970653-v3)-->"E:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
PhotoFiltre-->"E:\Program Files\PhotoFiltre\Uninst.exe"
PowerDVD-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
QuickTime-->E:\WINDOWS\unvise32qt.exe E:\WINDOWS\System32\QuickTime\Uninstall.log
Search Settings 1.2.1-->MsiExec.exe /X{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
Skype Toolbars-->MsiExec.exe /I{981029E0-7FC9-4CF3-AB39-6F133621921A}
Skype™ 4.2-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
SoundMAX-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
SUPERAntiSpyware-->"E:\Program Files\SUPERAntiSpyware\Uninstall.exe"
TELL ME MORE-->"E:\Program Files\Auralog\TELL ME MORE SI PLUS\Bin\unsetup.exe" -file "E:\Program Files\Auralog\TELL ME MORE SI PLUS\unsetup.aui"
Tennis Critters Demo-->"E:\Program Files\TennisCrittersDemo\uninstall.exe"
The GIMP 2.2.8-->"E:\Program Files\GIMP-2.0\unins000.exe"
The Sims 2-->C:\ewa hra the Sims\EAUninstall.exe
visionapp OneTimePass-->MsiExec.exe /I{BFCF1FE9-C3B0-46EC-8DB5-F52447E7B665}
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->E:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
VLC media player 1.0.3-->E:\Program Files\VideoLAN\VLC\uninstall.exe
VobSub v2.23 (Remove Only)-->"E:\Program Files\Gabest\VobSub\uninstall.exe"
WebMate-->"E:\Program Files\InstallShield Installation Information\{40B6D0B4-301A-4020-869F-2E3936E02299}\setup.exe" -runfromtemp -l0x0005 -removeonly
Winamp Toolbar-->"E:\Program Files\Winamp Toolbar\uninstall.exe"
Windows Internet Explorer 8-->"E:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"E:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"E:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"E:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"E:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"E:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR-->E:\Program Files\WinRAR\uninstall.exe
Wise Registry Cleaner Free 5.02-->"E:\Program Files\Wise Registry Cleaner\unins000.exe"
XviD MPEG4 Video Codec (remove only)-->"E:\WINDOWS\system32\xvid-uninstall.exe"

======System event log======

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Správce vzdáleného přístupu byl změněn na: Spuštěno

Record Number: 356
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 7035
Message: Řídící příkaz Spuštěno byl službě Správce vzdáleného přístupu úspěšně odeslán.

Record Number: 355
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User: MY-KOL\tom

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Telefonní subsystém byl změněn na: Spuštěno

Record Number: 354
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Načítání obrázků (WIA) byl změněn na: Spuštěno

Record Number: 353
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 7036
Message: Stav služby Služba rozpoznávání pomocí protokolu SSDP byl změněn na: Spuštěno

Record Number: 352
Source Name: Service Control Manager
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

=====Application event log=====

Computer Name: MY-KOL
Event Code: 4097
Message: Aplikace E:\Program Files\Windows Media Player\wmplayer.exe vygenerovala aplikační chybu.
K chybě došlo dne 23. 11. 6169 v 12:29:57,734
Vygenerovaná výjimka: c0000005 na adrese 77C34848 (MSVCRT!Gettnames)

Record Number: 42
Source Name: DrWatson
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 1000
Message: Chybující aplikace wmplayer.exe, verze 8.0.0.4487, chybující modul msvcrt.dll, verze 7.0.2600.1106, adresa chyby 0x00034848.

Record Number: 41
Source Name: Application Error
Time Written: 19700513010148.000000+120
Event Type: Chyba
User:

Computer Name: MY-KOL
Event Code: 4097
Message: Aplikace E:\Program Files\Windows Media Player\wmplayer.exe vygenerovala aplikační chybu.
K chybě došlo dne 21. 11. 6169 v 13:43:27,406
Vygenerovaná výjimka: c0000005 na adrese 77C34848 (MSVCRT!Gettnames)

Record Number: 40
Source Name: DrWatson
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

Computer Name: MY-KOL
Event Code: 1000
Message: Chybující aplikace wmplayer.exe, verze 8.0.0.4487, chybující modul msvcrt.dll, verze 7.0.2600.1106, adresa chyby 0x00034848.

Record Number: 39
Source Name: Application Error
Time Written: 19700514132620.000000+120
Event Type: Chyba
User:

Computer Name: MY-KOL
Event Code: 4097
Message: Aplikace E:\Program Files\Windows Media Player\wmplayer.exe vygenerovala aplikační chybu.
K chybě došlo dne 21. 11. 6169 v 13:43:17,171
Vygenerovaná výjimka: c0000005 na adrese 77C34848 (MSVCRT!Gettnames)

Record Number: 38
Source Name: DrWatson
Time Written: 20320626145632.000000+120
Event Type: Informace
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;E:\Program Files\Common Files\GTK\2.0\bin;E:\Program Files\ESTsoft\ALZip\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0207
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: pro Motji

#3 Příspěvek od motji »

:arrow: Spusťte combofix podle tohoto návodu
http://www.bleepingcomputer.com/combofi ... t-combofix
- přejmenujte ho na cobra.com


A omlouvám se za pozdní odpověď, jste se mi tu ztatil v zodpovězených :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 říj 2010 09:59

Re: pro Motji

#4 Příspěvek od kolariktomas1 »

Vše proběhlo podle návodu. Věřím, že už je vše OK. Jste super a moc děkuji :) . Kdy byla ještě drobná rada jak nejlépe předejít bez větších nákladů podobné situaci bylo by to fajn. Díky za pomoc.
Obsah Combofix.txt
ComboFix 10-10-22.04 - tatka 23.10.2010 7:17.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.759.541 [GMT 2:00]
Spuštěný z: e:\documents and settings\tatka\Plocha\cobra.com.exe
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
e:\documents and settings\tatka\Data aplikací\Dealio
e:\documents and settings\tatka\Data aplikací\Dealio\res\widgets.xml
e:\documents and settings\tatka\Data aplikací\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml
e:\documents and settings\tom\Local Settings\Temporary Internet Files\_tm152.tmp
e:\documents and settings\tom\Local Settings\Temporary Internet Files\stb06759.tmp
e:\program files\Search Settings
e:\program files\Search Settings\kb128\SearchSettings.dll
e:\program files\Search Settings\kb128\SearchSettingsRes409.dll
e:\program files\Search Settings\SearchSettings.exe
e:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-09-23 do 2010-10-23 )))))))))))))))))))))))))))))))
.

6169-11-24 00:14 . 6169-11-24 00:14 -------- d-----w- e:\documents and settings\tatka\Local Settings\Data aplikací\Identities
6169-11-23 22:54 . 6169-11-23 22:54 -------- d-----w- e:\documents and settings\tatka\Data aplikací\MSN6
6169-11-23 22:54 . 6169-11-23 22:54 -------- d-----w- e:\documents and settings\All Users\Data aplikací\MSN6
6169-11-23 22:35 . 2009-10-04 06:18 -------- d-----w- E:\Netgear
6169-11-23 12:04 . 2009-04-28 20:20 44944 ------w- e:\windows\system32\drivers\PxHelp20.sys
6169-11-23 12:04 . 2010-04-06 16:45 -------- d-----w- e:\program files\Winamp
6169-11-23 11:43 . 2002-06-19 18:15 155648 ----a-w- e:\windows\system32\igfxres.dll
6169-11-23 11:33 . 2008-04-13 19:16 141056 -c--a-w- e:\windows\system32\dllcache\ks.sys
6169-11-23 11:33 . 2008-04-13 19:16 141056 ----a-w- e:\windows\system32\drivers\ks.sys
6169-11-23 11:33 . 2008-04-13 18:45 60160 -c--a-w- e:\windows\system32\dllcache\drmk.sys
6169-11-23 11:33 . 2008-04-13 18:45 60160 ----a-w- e:\windows\system32\drivers\drmk.sys
6169-11-23 11:33 . 2008-04-13 19:19 146048 -c--a-w- e:\windows\system32\dllcache\portcls.sys
6169-11-23 11:33 . 2008-04-13 19:19 146048 ----a-w- e:\windows\system32\drivers\portcls.sys
6169-11-23 11:33 . 2008-04-13 18:45 49408 -c--a-w- e:\windows\system32\dllcache\stream.sys
6169-11-23 11:33 . 2008-04-13 18:45 49408 ----a-w- e:\windows\system32\drivers\stream.sys
6169-11-23 11:33 . 2008-04-14 03:21 4096 -c--a-w- e:\windows\system32\dllcache\ksuser.dll
6169-11-23 11:33 . 2008-04-14 03:21 4096 ----a-w- e:\windows\system32\ksuser.dll
6169-11-23 11:33 . 2008-04-14 03:22 129536 ----a-w- e:\windows\system32\ksproxy.ax
2010-10-22 13:47 . 2010-10-22 13:47 -------- d-----w- e:\program files\trend micro
2010-10-22 13:47 . 2010-10-22 13:48 -------- d-----w- E:\rsit
2010-10-14 18:23 . 2010-10-14 18:23 -------- d-----w- e:\documents and settings\tom\Data aplikací\SUPERAntiSpyware.com
2010-10-14 18:23 . 2010-10-14 18:23 -------- d-----w- e:\documents and settings\All Users\Data aplikací\SUPERAntiSpyware.com
2010-10-14 18:23 . 2010-10-14 18:23 -------- d-----w- e:\program files\SUPERAntiSpyware
2010-10-09 08:24 . 2010-10-22 13:01 16856 ----a-w- e:\program files\Mozilla Firefox\plugin-container.exe
2010-10-09 08:23 . 2010-10-22 13:01 719832 ----a-w- e:\program files\Mozilla Firefox\mozcpp19.dll
2010-09-28 15:41 . 2010-09-28 15:41 -------- d-----w- e:\documents and settings\záloha reg

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 17:33 . 2010-09-01 17:33 1409 ----a-w- e:\windows\QTFont.for
2009-09-12 21:05 . 2009-09-12 21:05 124240 ----a-w- e:\program files\mozilla firefox\plugins\CCMSDK.dll
2009-09-12 21:06 . 2009-09-12 21:06 13136 ----a-w- e:\program files\mozilla firefox\plugins\cgpcfg.dll
2009-09-12 21:06 . 2009-09-12 21:06 70488 ----a-w- e:\program files\mozilla firefox\plugins\CgpCore.dll
2009-09-12 21:06 . 2009-09-12 21:06 91480 ----a-w- e:\program files\mozilla firefox\plugins\confmgr.dll
2009-09-12 21:06 . 2009-09-12 21:06 22360 ----a-w- e:\program files\mozilla firefox\plugins\ctxlogging.dll
2009-09-12 21:07 . 2009-09-12 21:07 255312 ----a-w- e:\program files\mozilla firefox\plugins\ctxmui.dll
2009-09-12 21:06 . 2009-09-12 21:06 31064 ----a-w- e:\program files\mozilla firefox\plugins\icafile.dll
2009-09-12 21:06 . 2009-09-12 21:06 40280 ----a-w- e:\program files\mozilla firefox\plugins\icalogon.dll
2009-08-14 11:33 . 2009-08-14 11:33 652640 ----a-w- e:\program files\mozilla firefox\plugins\sslsdk_b.dll
2009-09-12 21:06 . 2009-09-12 21:06 23896 ----a-w- e:\program files\mozilla firefox\plugins\TcpPServ.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-08 39408]
"OM2_Monitor"="e:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2009-11-25 95632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="e:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="e:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"HP Software Update"="e:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"RemoteControl"="e:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="e:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"LGODDFU"="e:\program files\lg_fwupdate\fwupdate.exe" [2010-07-18 557056]
"WinampAgent"="e:\program files\Winamp\winampa.exe" [2010-01-13 37888]
"PAC207_Monitor"="e:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"Monitor"="e:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"DC1300 Monitor"="e:\program files\DC1300\DCMnt1_0\DC1300mi.exe" [2009-03-04 45056]
"NeroFilterCheck"="e:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"OM2_Monitor"="e:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2009-11-25 54672]
"ConnectionCenter"="e:\program files\Citrix\ICA Client\concentr.exe" [2009-09-12 103768]
"DynamicUSB"="e:\program files\DynamicUSBTool\DynamicUSB.exe" [2007-03-02 94208]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

e:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
McAfee Security Scan Plus.lnk - e:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Microsoft Office.lnk - e:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
NkvMon.exe.lnk - e:\program files\Nikon\NkView6\NkvMon.exe [2002-8-28 233472]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- e:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\WINDOWS\\system32\\sessmgr.exe"=
"e:\\Program Files\\ICQ6.5\\ICQ.exe"=
"e:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Documents and Settings\\tom\\Dokumenty\\Stažené soubory\\BULANCI.EXE"=
"e:\\WINDOWS\\system32\\dplaysvr.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Skupiny sítě Peer-to-Peer
"3540:UDP"= 3540:UDP:Protokol PNRP (Peer Name Resolution Protocol)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 ctxusbm;Citrix USB Monitor Driver;e:\windows\system32\drivers\ctxusbm.sys [8.9.2009 18:13 65584]
R1 SASDIFSV;SASDIFSV;e:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;e:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10.5.2010 20:41 67656]
S2 gupdate;Služba Google Update (gupdate);e:\program files\Google\Update\GoogleUpdate.exe [22.2.2010 22:38 135664]
S3 DC1300;DC 1300 WDM Video Capture;e:\windows\system32\drivers\Bsc504av.sys [4.3.2009 21:54 515365]
S3 INIDVD;Initio USB DVD Filter Driver;e:\windows\system32\drivers\inidvd.sys [11.11.2008 18:41 7936]
S3 McComponentHostService;McAfee Security Scan Component Host Service;e:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15.1.2010 14:49 227232]
S3 PAC207;e-Messenger 112;e:\windows\system32\drivers\PFC027.SYS [17.1.2009 18:34 616064]
S4 sptd;sptd;e:\windows\system32\drivers\sptd.sys [21.10.2008 15:17 717296]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Obsah adresáře 'Naplánované úlohy'

2010-10-23 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-02-22 20:38]

2010-10-23 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-02-22 20:38]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.seznam.cz/
IE: &Winamp Search - e:\documents and settings\All Users\Data aplikací\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Crawler Search - tbr:iemenu
Trusted Zone: cpas.cz\czcscisa201
Trusted Zone: cpas.cz\moje
Trusted Zone: mojebanka.cz\www
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - e:\progra~1\Crawler\ctbr.dll
DPF: DirectAnimation Java Classes - file://e:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file:///E:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - e:\documents and settings\tatka\Data aplikací\Mozilla\Firefox\Profiles\9m90hyqr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://www.seznam.cz
FF - prefs.js: keyword.URL - hxxp://www.crawler.com/search/dispatcher.aspx? ... 60076&qkw=
FF - component: e:\documents and settings\tatka\Data aplikací\Mozilla\Firefox\Profiles\9m90hyqr.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: e:\program files\Crawler\firefox\components\xcomm.dll
FF - component: e:\program files\Crawler\firefox\components\xshared.dll
FF - component: e:\program files\Crawler\firefox\components\xsupport.dll
FF - component: e:\program files\Crawler\firefox\components\xwsg.dll
FF - plugin: e:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: e:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npwachk.dll

---- NASTAVENÍ FIREFOXU ----
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
e:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
e:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
e:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

Toolbar-Locked - (no file)
HKCU-Run-SpywareTerminatorUpdate - e:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
HKLM-Run-SearchSettings - e:\program files\Search Settings\SearchSettings.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-23 07:24
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\INIDVD]
"ImagePath"=multi:"system32\DRIVERS\inidvd.sys\00"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\INIDVD]
"ImagePath"=multi:"system32\DRIVERS\inidvd.sys\00"
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(724)
e:\program files\SUPERAntiSpyware\SASWINLO.DLL
e:\program files\Citrix\ICA Client\pnsson.dll
e:\windows\system32\vorbis.dll
e:\windows\system32\ogg.dll

- - - - - - - > 'lsass.exe'(780)
e:\windows\system32\vorbis.dll
e:\windows\system32\ogg.dll
.
Celkový čas: 2010-10-23 07:27:17
ComboFix-quarantined-files.txt 2010-10-23 05:27

Před spuštěním: Volných bajtů: 18 607 779 840
Po spuštění: Volných bajtů: 19 767 238 656

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 4DA0652CB0465AC97E61641D695A7B64

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: pro Motji

#5 Příspěvek od motji »

:o Máte nějaké divné datum, dělal jste s tím něco? Pro jistotu zkontroolijte pc ještě s mbamem. Jinak už je v pořádku? Které pc jste nechal připojené k síti?
6169-11-23 22:54 . 6169-11-23 22:54 -------- d-----w- e:\documents and settings\tatka\Data aplikací\MSN6

:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 říj 2010 09:59

Re: pro Motji

#6 Příspěvek od kolariktomas1 »

ne ne omlouvam se, odpovidal tatka, ktery si myslel, ze uz je vse v poradku, jeste je stim neco v spatne...
posilam log s mbam:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

23.10.2010 9:06:33
mbam-log-2010-10-23 (09-06-33).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 277506
Time elapsed: 1 hour(s), 1 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25b44baa-2a26-414b-9934-2033cdc4e16e}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

detokovalo ty opet tyhle dva trojske kone, ty se vraci opetovne. nekdy jsou tri.

od site mam odpojeny notebook protoze ten mam odvirovany jede vse v poradku ale s timto stolnim pc mam problem. po odpojeni od site bych nemohl komunikovat s vami a pouzivam ho i pracovne .... takze muzu vse zopakovat jeste vecer az uz nebude potreba byt pripojeny na net a nechat ho odpojeny pres nedeli....

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: pro Motji

#7 Příspěvek od motji »

V mbamu vše smažte.
Bylo by potřeba znovu nastavit připojení k internetu - IP adresy. Máte tam právě trojana, který Vám je přepisuje.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

kolariktomas1
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 15 říj 2010 09:59

Re: pro Motji

#8 Příspěvek od kolariktomas1 »

Toto je ma IP konfigurace ,
Jestli tomu dobře rozumím pak moje IP se generuje přes DHCP, sam umím pouze v připojení sítě spustit tzv. automatickou opravu připojení. Jsem připojen na místního providera, asi je potřeba změnu IP žádat u něho? Je to tak?

Fyzická adresa: 00-30-13-05-2C-47
Adresa IP: 192.168.1.3
Maska podsítě: 255.255.255.0
Výchozí brána: 192.168.1.1
Server DHCP: 192.168.1.1
Datum zapůjčení adresy IP: 25.10.2010 20:20:23
Zapůjčení adresy IP vyprší: 26.10.2010 16:32:56
Servery DNS: 85.255.112.174, 85.255.112.201
Server WINS:

Trojan se objevuje opakovaně v registru viz LOG. níže. Je nutno se odpojit při testování na VIRY vždy od sítě?

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

24.10.2010 12:50:20
mbam-log-2010-10-24 (12-50-20).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 275754
Time elapsed: 1 hour(s), 17 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{25b44baa-2a26-414b-9934-2033cdc4e16e}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.174 85.255.112.201 -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Děkuji za napovězení dalšího postupu Jirka Tomášův otec

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: pro Motji

#9 Příspěvek od motji »

V mbamu vše smažte.

Servery DNS: 85.255.112.174, 85.255.112.201
tohle určitě nejsou Vaše IP adresy, jedině že by jste měl providera na Ukrajině :D .

Ted jsem zapoměla, jak to máte s připojením - tuším přes router? Resetujte router do výchozího nastavení, odpojte kabel od pc a zase připojte. A pak se podívejte, zda se IP adresy změnili. Jestli to dobře chápu, tak by se Vám po vyresetování routeru měli sami automaticky načíst.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Odpovědět